ScrollMint — Privacy Policy
Last Updated: July 11, 2026
Oner Teknoloji Sanayi ve Ticaret Limited Sirketi, a limited liability company registered in Turkey (MERSIS no. 0643037881900010), located at Maslak Mah. AOS 55. Sk. 42 Maslak B Blok No 4 Ic Kapi No 542, Sariyer, Istanbul, Turkey, operates the ScrollMint mobile application (the “App”) and the website at scrollmint.app (the “Website”) (together, the “Service”).
This Privacy Policy explains how we collect, use, share, and protect your personal information when you use the Service. We are committed to protecting your privacy in compliance with the EU General Data Protection Regulation (“GDPR”), the UK GDPR, the California Consumer Privacy Act (“CCPA”), and other applicable data-protection laws.
By using the Service, you agree to the data practices described below.
Privacy in one line: ScrollMint is built to keep almost everything on your device. Your camera frames and habit photos are processed on-device and never uploaded; we don’t require an account; and we don’t see what you do inside the apps you block.
1. Lawful Basis and Transparency
We process personal data on the following legal bases:
- Contract / performance of a service: to operate the App and manage your subscription and entitlements.
- Consent: for non-essential website cookies and optional communications.
- Legitimate interests: to keep the Service secure, stable, and functioning correctly, balanced against your rights.
- Legal obligation: to comply with applicable law (for example, tax and consumer-protection requirements).
We tell you about our data practices through this Privacy Policy, which is available on scrollmint.app and inside the App.
2. Information We Collect
We minimize what we collect and only collect what we need for a specific purpose.
a. No Account Required
ScrollMint does not require you to create an account, sign in, or give us your name or email to use the App. Your in-app data (earned minutes, history, goals, settings, and your blocked-apps selection) is stored on your device. Where a service provider needs an identifier (for example, to manage your subscription), it uses a randomly-generated, app-specific identifier rather than your real identity.
b. Camera and Photos — Processed On-Device, Never Uploaded
- Exercise (camera): During an exercise, your device’s camera is used to count repetitions in real time using on-device pose detection (Google’s MediaPipe, running locally). Camera frames are processed on the device and immediately discarded. No video is recorded, stored, or uploaded, and no frames ever leave your device.
- Habits (photos): When a habit asks for a photo (for example, a glass of water or time outside), the image is analyzed on your device (using Apple’s on-device Vision / image-analysis frameworks) to confirm the habit. The photo is not stored by us and is never uploaded.
- No biometrics: We do not perform facial recognition or identity verification, and we do not extract, store, or transmit face geometry, face templates, or any biometric identifiers. A habit photo may incidentally include your face, but it is never used to identify you and never leaves your device.
c. Screen Time / App-Blocking Data
The App uses Apple’s Screen Time (Family Controls) framework to lock the apps you choose. We store which apps and categories you selected to block, locally on your device, only so the block can be applied. Apple’s framework is privacy-preserving: we do not receive, and cannot see, your app-usage history or any content inside the apps you use. This data is not transmitted to us.
d. Analytics, Diagnostics, and Advertising Measurement
The App includes a small set of third-party SDKs used to understand product usage, measure the effectiveness of our advertising, and detect crashes:
- Mixpanel (product analytics): receives app interaction events we define (e.g., onboarding progress, feature usage, paywall views) tied to a random app-scoped identifier. We do not send Mixpanel your camera images, photos, precise location, or the list of apps you block.
- AppsFlyer (advertising attribution): receives install and app-milestone events, plus subscription lifecycle events forwarded server-side by RevenueCat, to determine which advertising campaign (if any) brought you to ScrollMint and to measure return on ad spend. Attribution uses Apple's privacy-preserving SKAdNetwork framework and — only if you allow tracking in the iOS prompt — the device advertising identifier (IDFA).
- Meta (Facebook), Google, and TikTok advertising SDKs / measurement: receive aggregated or privacy-thresholded campaign measurement signals (including via Apple's SKAdNetwork) so these platforms can report and optimize the ads we run there. We have disabled these SDKs' automatic in-app purchase logging; purchase measurement flows only through the RevenueCat → AppsFlyer path described above.
- Google Firebase Crashlytics (crash reporting) and Apple MetricKit (diagnostics): receive crash reports and device diagnostics (device model, OS version, stack traces) so we can find and fix defects. Crash data is not used for advertising.
What never leaves your device regardless of any setting: camera video and pose data from exercise sessions, habit-verification photos, and the identity of the specific apps you choose to block.
App Tracking Transparency: cross-app tracking identifiers are used only if you tap "Allow" in Apple's tracking permission dialog. If you decline (or never see the prompt), advertising measurement falls back to Apple's aggregate, non-identifying SKAdNetwork reports. You can change your choice anytime in iOS Settings → Privacy & Security → Tracking.
e. Subscription and Purchase Data
Subscriptions and any in-app purchases are processed by Apple. We use RevenueCat to manage and verify subscription status and entitlements. We never receive or store your payment card details. RevenueCat processes your transaction/receipt information and an anonymous app-user identifier.
f. Cookies (Website Only)
If you visit our Website, we use essential cookies (e.g., session IDs) for basic functionality. Non-essential cookies (e.g., analytics) are only set with your consent where required. You can disable cookies in your browser, though some features may not work.
3. Purpose and Data Minimization
We collect only the data necessary for the purposes declared above. Camera frames and habit photos are processed on-device for the sole purpose of counting reps and confirming habits, and are discarded. We do not process your data beyond these stated purposes.
4. Data Accuracy and Security
- Accuracy: Because most of your data lives on your device and you control it directly in the App, you can review and change it at any time. For other inquiries, contact us at contact@onerteknoloji.com.
- Security: We use industry-standard technical and organizational measures (such as encryption in transit and access controls) and rely on reputable processors with their own security programs. No system is fully secure, and you use the Service at your own risk.
5. Data Retention
- On-device data (earned minutes, history, goals, settings, blocked-apps selection) is retained on your device until you delete it. You can erase all of it at any time via Settings → About → Delete my account, which permanently removes it from your device.
- Subscription data held by Apple and RevenueCat is retained according to their policies for billing and entitlement purposes.
- Analytics and attribution events (Mixpanel, AppsFlyer) are retained per those providers' standard schedules and our configuration; we do not retain raw event data longer than needed for the purposes above.
- Anonymized or aggregated data that can no longer identify you may be retained indefinitely.
Note: Deleting your data in the App does not cancel your subscription. Apple manages subscriptions — cancel it from your App Store account settings.
6. Privacy by Design
We build privacy into the product:
- On-device processing of camera and photo data, with no uploads.
- No account or login requirement.
- Third-party SDKs are limited to the analytics, attribution, and crash-reporting providers listed in Section 2(d) — never advertising networks that show ads inside the App.
- A one-tap, complete local data erase inside the App.
7. Service Providers (Processors) and Sharing
We share information only as needed to run the Service. We do not sell your personal information, and we do not share habit photos or any biometric data with third parties for marketing, advertising, or cross-app tracking.
| Provider | Purpose | Reference |
|---|---|---|
| Apple | Subscription / in-app purchase processing; Screen Time framework | apple.com/legal/privacy |
| RevenueCat | Subscription management and entitlement verification (no payment details) | revenuecat.com/privacy |
| Mixpanel | Product analytics (event data, random app-scoped ID) | mixpanel.com/legal/privacy-policy |
| AppsFlyer | Advertising attribution and campaign measurement | appsflyer.com/legal/services-privacy-policy |
| Google (Firebase) | Crash reporting; Google Ads campaign measurement | policies.google.com/privacy |
| Meta Platforms | Ad campaign measurement for ads we run on Meta services | facebook.com/privacy/policy |
| TikTok | Ad campaign measurement for ads we run on TikTok | tiktok.com/legal/privacy-policy |
We may also disclose information if required to comply with law, respond to lawful requests by public authorities, or protect our rights, safety, and property. Our contracts with processors require appropriate security measures and the return or deletion of data when the relationship ends.
8. Your Rights
Depending on where you live, you have rights over your personal data, including the right to:
- Be informed about how your data is used (this Policy).
- Access a copy of your data.
- Rectify inaccurate data.
- Erase your data (e.g., the in-app account deletion).
- Restrict or object to certain processing.
- Data portability in a machine-readable format.
- Withdraw consent at any time where processing is based on consent (e.g., non-essential website cookies).
- Opt out of tracking: decline the iOS tracking prompt, or turn it off later in iOS Settings → Privacy & Security → Tracking. The App is fully functional either way.
- No solely-automated decisions with legal or similarly significant effects are made about you.
California residents (CCPA): You have the right to know, the right to delete, and the right to opt out of the “sale” of personal information. We do not sell personal information, so no opt-out is needed.
To exercise any right, use the in-app controls or email contact@onerteknoloji.com. We respond within the timeframe required by applicable law (generally one month under GDPR), and may extend for complex requests. We may decline requests where permitted by law (e.g., if we cannot verify your identity).
9. Contact and Data Controller
Oner Teknoloji Sanayi ve Ticaret Limited Sirketi is the data controller.
Oner Teknoloji Sanayi ve Ticaret Limited Sirketi
Maslak Mah. AOS 55. Sk. 42 Maslak B Blok No 4 Ic Kapi No 542
Sariyer, Istanbul, Turkey
Email: contact@onerteknoloji.com
For privacy inquiries, email contact@onerteknoloji.com.
- EU users may lodge a complaint with their local Data Protection Authority.
- UK users may contact the Information Commissioner’s Office (ico.org.uk).
- California residents may contact the California Attorney General.
10. International Data Transfers
We are based in Turkey, and some of our processors operate in the EU/EEA, the UK, and the US. When data is transferred internationally (for example, to a US-based subscription-management provider), we rely on appropriate safeguards such as Standard Contractual Clauses and the providers’ certifications, consistent with GDPR, UK GDPR, and CCPA where applicable.
11. Data Breach Notification
If a personal-data breach is likely to risk your rights and freedoms, we will notify the competent supervisory authority without undue delay (and within 72 hours where required by GDPR), and notify affected users without undue delay. Our processors are contractually required to notify us promptly of any breach.
12. Children
The Service is not directed to children under 13, and we do not knowingly collect personal data from them. Where required by local law, users between 13 and the age of digital consent need verifiable parental consent. If we learn that we have collected data from a child under 13, we will delete it promptly. To raise a concern, contact contact@onerteknoloji.com.
13. Changes to This Policy
We may update this Policy to reflect changes to the Service or the law. We will post updates on scrollmint.app and, for material changes, provide in-app notice where appropriate, before they take effect. Your continued use of the Service after an update constitutes acceptance of the revised Policy.