Legal
Privacy Policy
Carcine · Last updated 2026-09-15
Carcine turns photos of your own car into short, AI-generated cinematic videos. To do that we have to handle some personal data: your account e-mail, the photos you upload and, only if you choose to, a selfie. This page explains what we collect, why, who processes it for us, how long we keep it and how you can delete it. We have tried to write it in plain language.
1. Who we are
The data controller is Carcine, an independent app developed and operated by Anıl Ünkaya. There is no company behind it yet. Contact: anilunkaya@gmail.com
2. What we collect
| Data | Source | Purpose | Retention |
|---|---|---|---|
| E-mail address | You, at sign-in (e-mail code, Apple or Google) | Creating and signing in to your account | Until you delete your account |
| Car photos and the plate text on them | You, when you upload photos | Generating your videos; keeping your garage and past renders | Until you delete them or your account |
| Selfie (optional, biometric data) | You, only after explicit consent in the app; adults only | Placing you as the driver in your videos | Profile selfie until you delete it; the copy attached to a render 7 days |
| Generated videos and preview frames | Produced by the service | Showing and downloading your renders | Until you delete them or your account |
| Push notification token | Your device, if you allow notifications | Telling you when a render is ready | Until you sign out or delete your account |
| Purchase records (credits, Pro subscription) | Apple App Store / Google Play via RevenueCat | Granting credits, managing your subscription, preventing fraud | Until you delete your account; Apple/Google and RevenueCat keep their own purchase records |
| Usage analytics (no personal details) | The app, under a pseudonymous user id | Understanding which features are used and improving the product | Person record deleted with your account |
| Crash and error reports | The app, when something goes wrong | Finding and fixing bugs | Kept by our error service for a limited period; no personal details included |
We do not collect your precise location, your contacts or your address book. Analytics events never contain your e-mail, your photos or your plate.
3. Why we process it (legal bases)
- Performance of our contract with you — account, photos, renders, purchases and notifications are needed to deliver the service you asked for.
- Your explicit consent — the selfie is biometric data. We ask for consent on a dedicated screen before you take one, and you can withdraw it at any time by deleting your selfie in Profile.
- Our legitimate interest in keeping the app working and improving it — pseudonymous analytics and crash reports.
4. Who processes data for us
We use a small number of service providers. They process your data only to provide the service, under their own service terms and privacy policies. We do not sell your data.
| Provider | Role | Region |
|---|---|---|
| Supabase | Database, file storage, sign-in | EU (Ireland) |
| fal.ai (MiniMax model) | Video generation from your car photos and, if you opted in, your selfie | Provider's infrastructure; see fal.ai's policy |
| Anthropic (Claude) | Automated quality and safety review of photos and selfies (is there a face, is the person an adult, is the content appropriate) | Provider's infrastructure; see Anthropic's policy |
| RevenueCat | Subscription and credit purchase records | Provider's infrastructure |
| Apple App Store / Google Play | Payment processing; we never see your card details | Apple / Google |
| PostHog | Usage analytics, pseudonymous, no personal details | United States (us.i.posthog.com) |
| Sentry | Crash and error reports; personal details and session replay disabled | Provider's infrastructure |
| Resend | Sending the sign-in code e-mail | Provider's infrastructure |
| Trigger.dev | Running the render job queue | Provider's infrastructure |
| Expo | Delivering push notifications | Provider's infrastructure |
Some of these providers are outside Türkiye and the EU; transfers rely on the providers' contractual safeguards, and we are working to meet the transfer requirements of GDPR and KVKK.
5. Retention and deletion
- Profile selfie: kept until you delete it (Profile → Delete my selfie).
- Selfie copy attached to a render: deleted 7 days after the render.
- Car photos and renders: kept until you delete them or delete your account.
- Account deletion: available in the app (Profile → Delete account). It removes your account, photos, selfie, renders, credit history and your analytics person record. You do not need to e-mail us.
- Backups: backup copies are purged within our provider's normal backup cycle.
6. Your rights
Under the GDPR and Türkiye's data protection law (KVKK) you can ask us to:
- tell you whether we process your data and give you a copy (access);
- correct inaccurate data (rectification);
- delete your data (erasure) — the quickest way is in-app account deletion;
- restrict processing, or receive your data in a portable format;
- object to processing based on our legitimate interest;
- withdraw consent for your selfie at any time (Profile → Delete my selfie).
Write to anilunkaya@gmail.com from the e-mail address of your account. We answer within one month (30 days), or longer where the law allows. If you are unhappy with our answer, you may complain to your local data protection authority.
7. Children
Carcine is for people aged 13 and over. The selfie / driver feature is for adults (18+) only. Our automated review rejects faces that appear to belong to minors, and we delete such images. If you believe a child has given us data, e-mail us and we will remove it.
8. Security
- Every request is checked with row-level access rules, so you can only reach your own photos and renders.
- Files are served through short-lived signed links, not public URLs.
- All traffic is encrypted in transit (TLS). Keys for our AI providers never ship inside the app.
No system is perfectly secure. If we learn of a breach affecting your data, we will tell you and the authorities as the law requires.
9. Changes to this policy
When we change this page we update the date at the top. If a change matters for you (for example a new provider that receives your photos), we will also tell you in the app.