Privacy Policy
Last updated: 15 August 2026
History Lens photographs a museum piece, a monument or a historic place and narrates its history like an audio guide. This page describes what is collected while it does that, where it goes, and how to have it deleted.
The short version
No ads, no tracking, no analytics, no selling of data. An account is optional. The photograph you take is sent to OpenAI so the object can be recognised. If the object is new to the archive, your photograph becomes that object's archive image and is visible to everyone using the app. You can delete your account from inside the app in one step.
1. Who is responsible
History Lens is built and operated by Serdar Akın as an individual. For anything to do with privacy, the single point of contact is privacy@history-lens.com.
That person is the data controller for the purposes of the EU General Data Protection Regulation (GDPR) and the veri sorumlusu under Turkish law no. 6698 (KVKK).
2. What is collected
2.1 A device identifier
On first launch the app generates a random identifier and sends it with its requests. It is not the device's hardware identifier — it is a string we generate that matches nothing else. It exists so that someone without an account can still see their own journal, and so the daily usage limit can be applied. Deleting the app discards it, and with it any way of reaching the records attached to it.
2.2 An account — optional
The app works without one. If you create an account, these are stored: your email address,
a BCrypt hash of your password (the password itself is never stored
anywhere), your display name if you set one, your chosen language, and the date
the account was created. If you sign in with Google, Google's permanent account identifier
for you (sub) is stored as well; your Google password never reaches us.
To keep you signed in, your device is given a refresh token. Only a SHA-256 hash of it is held on the server, never the token itself.
2.3 Photographs
When you photograph an object or pick one from your library, the image is sent to our server and from there to OpenAI to be recognised. When the answer comes back, one of two things happens:
- If the object is already in the archive, your photograph is not stored. Only the fact that you saw that object is recorded.
- If the object is new to the archive, your photograph is stored on our server and becomes that object's archive image. That image is visible to everyone using the app.
The second case matters enough to say plainly: a photograph that enters the archive becomes part of the shared archive and stays there even if you delete your account. The archive keeps no record of who took it — there is no link between the photograph and you to delete. This is why the app is built for photographing objects rather than people. A frame with a person in it, or one taken somewhere private, should not end up in the archive; if one has, write to privacy@history-lens.com and it will be removed.
2.4 Your journal
Which object you saw, when, and from which device. That is what the app's journal shows. When you create an account, that device's records move onto it, so signing in does not read as losing your journal.
2.5 Daily usage counters
AI calls cost money, so the number of recognitions and narrations you make each day is counted. All that is kept is a number — no photographs and no content.
3. What is not collected
None of this exists in the app. It is not "switched off for now":
- Location — the app never asks for location permission.
- Contacts, calendar, search history, or the other apps on your device.
- An advertising identifier; there are no ads in the app at all.
- Analytics or tracking software. There is no third-party measurement SDK in the app, and this website sets no cookies and counts no visitors.
Your data is never sold and never shared for advertising.
4. Why, and on what legal basis
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Device identifier | Use without an account, the journal, and the usage limit | Performance of a contract (Art. 6(1)(b)) |
| Account details | Making sign-in work and carrying the journal between devices | Performance of a contract (Art. 6(1)(b)) |
| Photograph | Recognising the object and writing its story | Consent (Art. 6(1)(a)) — you are the one who sends it |
| Journal | The list of what you have seen | Performance of a contract (Art. 6(1)(b)) |
| Usage counters | Limiting abuse and cost | Legitimate interests (Art. 6(1)(f)) |
5. Who else sees it
Two third parties, each doing only its own job:
- OpenAI (United States) — the photograph you send and which language the narration should be in. OpenAI states that data sent through its API is not used to train its models by default and is retained for a limited period for abuse monitoring; the current terms are at openai.com/policies. Your identity, email address and account details are not sent with the photograph.
- Google (United States) — only if you tap "Continue with Google". Google verifies who you are and tells us your email address, your name and your permanent account identifier.
Both transfers leave your country. Sending the photograph to OpenAI is the precondition for the only thing the app can do; if you would rather it did not happen, do not send a photograph — browsing, reading and listening to the archive do not depend on it.
6. How long it is kept
| Data | How long |
|---|---|
| Account details | Until you delete them |
| Refresh token (session) | 60 days at most; void immediately when you sign out |
| Journal | Deleted with the account |
| Usage counters | Daily; deleted with the account |
| A photograph that entered the archive | Stays in the shared archive — see 2.3 |
7. Security
- Passwords are hashed with BCrypt; no plaintext password is held anywhere.
- Session tokens rotate on every use. If a spent one comes back, that is read as theft and every session on that account is ended.
- Tokens are held in the operating system's secure store (the keychain) on your phone.
- All traffic between the app and the server is over HTTPS.
No system is perfect. If you find a vulnerability, write to privacy@history-lens.com.
8. Your rights
Under GDPR Articles 15–22 and Article 11 of Turkish law no. 6698, you have the right to access your data, to have it corrected, to have it deleted, to object to its processing, and to receive it in a portable form.
Deletion needs no correspondence: in the app, go to Profile → Privacy and legal → Delete account and the account and everything attached to it goes immediately. The account deletion page has the detail, and what to do if you cannot reach the app.
For anything else, write to privacy@history-lens.com; requests are answered within 30 days. If you are not satisfied with the answer, you may complain to your national data protection authority in the EU, or to the Personal Data Protection Authority (KVKK) in Turkey.
9. Children
History Lens is not directed at children under 13 and does not knowingly collect data from them. If we learn that a child under 13 has created an account, it is deleted. You can tell us if you believe this has happened.
10. Changes to this policy
If this policy changes, the date on this page changes with it. For a change that affects what is collected or who it is shared with, the app tells you the next time you open it.