Legal
Effective 2 September 2026 · Zeki Tolunay Dönmez, sole proprietor, Türkiye
Also available in Türkçe.
This policy describes what Toneli collects, who processes it, how long it is kept, and what you can ask us to do with it. It describes what the app actually does, not what a template says an app might do.
Toneli is operated by Zeki Tolunay Dönmez, a sole proprietor established in Türkiye, acting as data controller. You can reach us at support@toneli.app for any question in this policy, including access and deletion requests.
| Data | Where it comes from |
|---|---|
| Email address, or your Apple or Google account identifier | Signing up or signing in |
| Display name and profile picture | Your profile, if you set one |
| Language and notification preference | Settings |
| Photographs you upload | Your photo library or camera |
| Edited results | Produced by the app or by an AI model |
| Thumbnails | Generated on your device |
| Published posts | Only when you choose to publish to the community |
| Text instructions you type | Prompt-based editing |
| Push notification token | Your device, if you enable notifications |
| Subscription and purchase status | Apple or Google Play, via RevenueCat |
| Reports you submit and blocks you set | Community moderation, and reporting an AI result to us |
We do not collect your contacts, your location, your browsing activity, or advertising identifiers. We do not sell personal data and we do not show advertising.
Photographs you keep private are stored in private storage and are readable only with a signed link generated for your account.
When you publish an edit to the community, a copy is placed in public storage. From that moment, anyone holding the link can open it. If you remove the post, that copy is deleted immediately, but a link somebody already copied cannot be recalled. Publish accordingly.
Editing happens on external AI infrastructure. Your photograph leaves our storage and is sent to the processor listed below for the duration of the edit. This is the part of this policy we most want you to read.
| Processor | What is sent | Why |
|---|---|---|
| fal.ai | The photograph | Running the editing, upscaling and background-removal models |
| Google Gemini, via OpenRouter | The photograph | Photo analysis and the content check applied before publishing |
| Groq | Text only, never an image | Translating your typed instruction into English for the model |
| Supabase | Account data, photographs, results | Hosting, authentication and storage |
| RevenueCat | Purchase events and an anonymous identifier | Managing subscriptions |
| Resend | Your email address and the sign-in code | Delivering sign-in and account emails |
| Expo | Device push token | Sending notifications you have enabled |
| Apple, or Google Play on Android | Payment details, handled entirely by the store | Purchases and subscriptions |
Except for email delivery, which is handled inside the European Economic Area, these processors operate outside Türkiye and outside the European Economic Area. Transfers are made because they are necessary to provide the service you have asked for, and we send only what the specific operation requires.
Colour and tone presets are applied entirely on your device, so no AI processor receives those photographs. The original and the result are still saved to your Toneli account in Supabase storage, like any other edit, and follow the retention periods below.
We process your account details and your photographs to perform the contract you enter into when you use the app. We process moderation data on the basis of our legitimate interest in keeping the community safe and in meeting the obligations app stores place on services that host user content. Where we ask for consent, notifications for example, you can withdraw it at any time in Settings.
Under Türkiye's Personal Data Protection Law (KVKK) and, where it applies to you, the EU General Data Protection Regulation, you may ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to a particular use.
You can delete your account from inside the app at any time: Profile → Settings → Delete Account. Deletion removes the account and everything linked to it. If you prefer, write to support@toneli.app from the address on your account and we will delete it for you within 30 days.
Toneli is not intended for children under 13, and under 16 in countries where that is the applicable age. We do not knowingly collect data from children. If you believe a child has an account, write to us and we will remove it.
Private photographs are stored in private buckets and served only through short-lived signed links. Access is enforced at the database level rather than only in the app, so a request that is not yours returns nothing. Payment card details never reach us; Apple or Google Play handles them.
If we change this policy we will update the effective date above, and we will tell you in the app when a change is material.
Contact
Email: support@toneli.app
Zeki Tolunay Dönmez, sole proprietor · Türkiye
We reply to every message.