Effective Date: July 16, 2026
Public materials describe JeoValid as a geology and drilling-data application that imports and validates collar, survey, lithology, and assay data; visualizes data in 2D and 3D; offers premium features through in-app purchases; and, importantly, says project files are primarily processed on the device rather than centrally stored by the developer. The official website also says no account is required to start using the app, and that location permission is used to match field coordinates with the device location for QA/QC purposes.
The main compliance issue is not the app's basic privacy posture, which appears relatively conservative, but the fact that JeoValid's public disclosures are not yet fully harmonized. The Google Play listing currently shows "No data collected" and "No data shared," while Google's own Data safety rules require declarations to reflect third-party SDK handling as well, and RevenueCat's official guidance says apps using RevenueCat should disclose purchase history in Google Play and Purchases in App Store Connect. JeoValid's current website privacy page also states more broadly that the app may collect uploaded datasets, device location, and in-app usage statistics, which is broader than the behavior now confirmed.
A second cleanup point is contact identity. The Play listing names jeovalid.destek@gmail.com as the support email, while the official website prominently uses destek@jeovalid.com. For privacy rights handling, it is better to publish one canonical support/privacy address and use it consistently in Play, on the website, and inside the policy.
The draft below is therefore written to fit the confirmed app behavior: no end-user account creation, no photo upload, no camera or microphone access, location permission used but location processed only on-device and not sent to servers, local file access for imports, Google Play Services and RevenueCat use, and no server-side storage of user project data. Where public sources still leave uncertainty, the report flags those items explicitly instead of guessing.
The Play listing presents JeoValid as a professional mobile tool for geological and drilling data verification, review, and visualization. It emphasizes dataset import and management, error detection, column matching, 2D/3D visualization, premium access, and on-device processing of user project files. The listing also shows the app was updated on April 20, 2026, includes in-app purchases, and currently declares "No data shared with third parties" and "No data collected."
The official website expands the feature set further. It says users can load project tables, run automatic validation, visualize results in 3D, export outputs such as DXF, use PRO subscriptions, and cancel subscriptions through the App Store or Google Play. The FAQ states that no account is needed, location permission is used for field coordinate matching and QA/QC, and support is available through destek@jeovalid.com or the contact page. The contact page includes a web form collecting name, email, subject, and message fields, which means the website itself likely processes at least some contact data even if the mobile app does not.
The website's current privacy page is legally thin and partly inconsistent with the stricter app behavior confirmed. It says JeoValid collects limited data including uploaded datasets, device location for quality control, and possible in-app usage statistics; it also says the website may use limited cookies for preferences and traffic analysis. That wording may be defensible for the website or for future analytics, but if JeoValid currently has no analytics/crash SDKs and does not upload project files or location to JeoValid servers, the policy should be narrowed and made much more precise. The Terms page is also effectively still blank as of July 15, 2026.
There is also a meaningful store-compliance gap around subscriptions. Google requires Data safety declarations to cover data handled through third-party SDKs and states that developers are responsible for complete and accurate disclosures. RevenueCat's own platform guidance says that apps using RevenueCat must disclose purchase history in Google Play and Purchases in App Store Connect. RevenueCat further explains that, by default, its SDK creates anonymous App User IDs, and that for Apple privacy disclosures purchase history may be marked as not linked to identity if only anonymous IDs are used and there is no separate way to identify the individual user.
For structure and tone, similar field-mapping and geology-adjacent apps provide useful benchmarks. QField's privacy policy separately identifies third-party services such as Google Play Services and Sentry and explains log-data handling, while the U.S. Bureau of Land Management's S1 Mobile policy distinguishes between automatically remembered local app state and analytics, and expressly notes that the app does not inherently collect personally identifiable information. JeoValid's finished policy follows that same pattern of separating local device processing, third-party provider processing, website processing, and user rights.
In practical terms, JeoValid appears to be a low-risk app for user project data because the core geology files and live location workflow are designed to remain on the device. The higher-sensitivity processing sits around subscriptions and the website contact channel, not the drilling/project content itself. That distinction is made explicit in the policy sections below and in store disclosures.
JeoValid is a mobile application for geological and drilling-data validation, review, and visualization, including local workflows for importing and processing field/project datasets. For purposes of applicable data-protection laws, the JeoValid developer/publisher is the "controller" of personal data processed through the JeoValid app and website, except where a third party acts as an independent controller under its own privacy terms. RevenueCat states that, in relation to end-user data handled on behalf of the app developer, it acts as a processor.
This Privacy Policy applies to the JeoValid Android app, the JeoValid website, and related support interactions. It is intended to explain what information is processed, how it is used, the legal bases relied on, who may receive it, how long it is kept, and what rights users have. Apple requires apps to make this information easily accessible both in App Store metadata and within the app, while Google Play requires developers to provide accurate privacy and Data safety disclosures.
JeoValid is designed so that geological/project data are primarily processed on the device. Public product materials state that user project files are not centrally stored by the developer, and the public FAQ states that users do not need an account to start using the app. Based on the developer-confirmed configuration used for this draft, JeoValid does not offer end-user account registration, does not use camera or microphone permissions, does not provide photo uploads, and does not send user project files or the app's location-based QA/QC data to JeoValid servers.
JeoValid may process the following categories of information:
First, project and file data that you choose to open in the app, such as geological/drilling datasets used for validation, review, visualization, and export. The Play listing and website describe workflows involving collar, survey, lithology, and assay datasets, including validation and 2D/3D review, and public materials emphasize on-device processing rather than central developer storage. Under the confirmed design assumptions for this draft, these files remain on your device unless you yourself export, share, or back them up using device or third-party tools outside JeoValid.
Second, device location data, if you grant location permission. The JeoValid FAQ explains that location permission is requested for matching field/geological coordinates with the device's location and for QA/QC workflows. Under the confirmed app behavior used for this draft, that location processing occurs on-device and is not transmitted to JeoValid's own servers. However, depending on implementation and device settings, Google Play Services may support location functions at the platform level. Google states that Play services can provide location APIs when apps have location permission, and that in many cases data can be accessed locally on the device without being collected off-device.
Third, subscription and purchase-related data for JeoValid PRO. JeoValid's website states that PRO is sold through in-app purchases via the relevant app store and that payment-card information is not shared with JeoValid. Because JeoValid uses RevenueCat, subscription handling may involve purchase history, entitlement status, and an anonymous or other app user identifier needed to restore and manage paid access. RevenueCat's official guidance says apps using RevenueCat should disclose purchase data in both Google Play and Apple privacy disclosures, and RevenueCat's documentation says its SDK generates anonymous App User IDs by default unless the developer provides a custom identifier.
Fourth, technical network or platform data processed by third-party platform services. Even where JeoValid itself does not upload project files or live location to its own servers, Google states that Google Play Services collects limited basic information on certified Android devices to support core device features and developer APIs, such as IP address and other device/service information, with exact collection depending on device settings, installed services, and account configuration. That processing is governed by Google's own privacy terms where applicable.
Under the app configuration described in this draft, JeoValid does not require end-user account creation, does not collect profile data for account registration, does not ask users to upload photos, does not use camera or microphone content, and does not store user project files on JeoValid-controlled servers. Public website FAQ content and the Play listing are broadly consistent with an account-free, on-device-workflow model. If any future version introduces analytics, crash reporting, cloud sync, AI APIs, team collaboration, server storage, or account login, this policy and the store disclosures would need to be updated before rollout.
If you use the JeoValid website rather than only the mobile app, additional information may be processed. The current website includes a contact form that requests name, email address, subject, and message content. The current website privacy page also says the site may use limited cookies for remembering preferences and analyzing traffic. For legal clarity, the final production site should distinguish essential cookies from optional analytics cookies and, where required by law, obtain consent before setting non-essential cookies.
We process data to provide the functions you request, including opening and handling local geological/drilling files; validating and visualizing project datasets; matching field coordinates using on-device location when you grant permission; managing premium access and restoring purchases; responding to support requests submitted through email or the website; maintaining security and preventing misuse; and meeting legal, tax, accounting, and consumer-protection obligations connected to purchases and support. These purposes are consistent with how JeoValid is described in the Play listing and on the official website.
Where GDPR applies, JeoValid would generally rely on: performance of a contract or steps taken at your request to provide app functionality and support; your consent where device permissions or optional communications are involved; compliance with legal obligations; and legitimate interests for fraud prevention, service security, and handling support or purchase disputes, insofar as those interests are not overridden by your rights. GDPR recognizes these legal bases and related user rights.
Where Türkiye's KVKK applies, JeoValid would generally rely on the corresponding grounds under Law No. 6698, including explicit consent where required, processing directly related to the establishment or performance of a contract, compliance with legal obligations, the establishment/exercise/protection of a right, and the controller's legitimate interests where such processing does not harm the fundamental rights and freedoms of the data subject.
JeoValid may request location access for field coordinate matching and QA/QC workflows. It may also require file or storage access, depending on Android version and the specific file-picker or storage framework used, so that users can import local datasets and exports. Based on the confirmed app behavior used for this draft, JeoValid does not request camera access for photo capture, does not request microphone access, and does not require end-user account permissions. Google Play policies also require developers to use sensitive permissions responsibly and accurately explain them.
JeoValid currently appears to rely at least on the following third parties:
Google Play Services. Google states that Play services are core system software on certified Android devices and may process limited basic and device-related information to support core functionality and developer APIs. Depending on the APIs JeoValid invokes and the user's settings, Google may process certain technical or location-related information under Google's own privacy framework. JeoValid should not describe such Google-controlled processing as if it were JeoValid's own storage or profiling activity.
RevenueCat. RevenueCat is used to manage in-app purchases and subscription entitlements. RevenueCat states that, for end-user personal data handled on behalf of app developers, it is a processor, and its own platform guidance says apps using RevenueCat should disclose purchase data in store privacy disclosures. RevenueCat documentation also explains that anonymous App User IDs are generated by default unless the developer supplies a custom user ID. If JeoValid uses only anonymous RevenueCat IDs and does not link them to names, email addresses, or accounts, Apple's privacy guidance for RevenueCat suggests purchase history may be disclosed as not linked to identity; that should still be verified before the App Store submission is finalized.
App Store / Google Play Billing. JeoValid's website states that purchases are processed through the relevant app store and that payment details are not shared with JeoValid. Subscription cancellation is also described as occurring through the store's subscription settings. Because store operators keep their own transaction records, deleting a user's RevenueCat-side subscriber record may not erase the store's own purchase history. RevenueCat's documentation expressly notes that deleting a user from RevenueCat does not delete Apple's purchase history and that restoring purchases can recreate the record. The same principle should be assumed for platform-controlled billing records generally.
The table below synthesizes what is publicly documented, what is required by platform guidance, and what still needs confirmation before publication.
| Data type | Main purpose | Stored on device | Stored on JeoValid server | Possible third parties | Notes |
|---|---|---|---|---|---|
| Geological/drilling project files (collar, survey, lithology, assay tables) | Import, validation, visualization, export | Yes | No, per the Play listing's on-device processing statement and the confirmed architecture | None identified from public sources | Public sources clearly support CSV/Excel-style table workflows; KML/GPX support was developer-confirmed but is not yet clearly described on the public site. |
| Device location | Field coordinate matching and QA/QC | Yes | No, per the confirmed architecture | Google Play Services may assist with location APIs depending on implementation | Google notes Play services can provide fused location when the app has permission, and in many cases data may be accessed locally without collection off-device. |
| Purchase/subscription history and entitlement status | Unlocking JeoValid PRO, validating purchases, restoring access | Not primary storage location | Not project-data storage, but subscription metadata may be processed by RevenueCat | RevenueCat, Google Play, and on iOS Apple's App Store | This is the clearest disclosure item that should be added to store/privacy materials. |
| Anonymous subscription identifier | Identifying the purchaser for entitlement management where no user accounts exist | SDK-generated or app-generated identifier may exist locally | May exist in RevenueCat systems | RevenueCat | RevenueCat says anonymous App User IDs are generated by default if the developer does not provide a custom user ID. |
| Website contact details (name, email, subject, message) | Responding to support and sales/contact requests | Browser/session dependent | Likely yes, at least in email inbox or website backend | Hosting/email providers | The current contact page publicly shows a form collecting these fields. |
| Website cookies or similar browser technologies | Site functionality and possibly preferences/traffic analysis | Browser storage | Depends on implementation | Website host and any analytics provider, if enabled | The current public website privacy page says the site may use limited cookies for preferences and traffic analysis, but exact implementation is still unconfirmed. |
For project files and local working data, JeoValid's stated design is local, device-based processing. Those files remain on your device until you delete them, remove the app, clear app storage, or move/export them elsewhere using device features or third-party tools. JeoValid does not, under the confirmed architecture used for this draft, keep a server-side copy of your project datasets.
For location data used in QA/QC, the intended model in this draft is on-device use without server-side retention by JeoValid. If any future version logs or transmits location off-device, the retention section must be updated before release.
For subscription and purchase metadata, retention may depend on the app store, RevenueCat, accounting obligations, fraud prevention, dispute resolution, and customer-support needs. JeoValid should keep only what is reasonably necessary for entitlement management, refunds/restores, legal compliance, and record-keeping. Because store operators and RevenueCat may retain purchase-related records under their own rules, JeoValid should avoid promising immediate or universal deletion of all billing history across all third parties. RevenueCat documentation specifically warns that deleting the user in RevenueCat does not delete Apple's purchase history and that restored purchases can recreate the record.
For support communications, JeoValid should retain emails, contact-form submissions, and related support records only for as long as needed to answer the request, maintain a reasonable support history, prevent abuse, and meet legal obligations or defend legal claims. This period should be stated internally in an operations schedule even if the public policy uses a reasonableness standard. Under KVKK and GDPR, retention should be limited to what is necessary for the stated purposes.
If JeoValid or its service providers process personal data outside the country where you are located, such transfers should rely on lawful safeguards. Under the GDPR, international transfers may rely on adequacy decisions, Standard Contractual Clauses, or other recognized safeguards. Under Türkiye's transfer rules, transfer abroad requires compliance with the relevant processing conditions and the applicable cross-border transfer framework. If JeoValid uses RevenueCat, Google, or infrastructure providers located outside Türkiye or the EEA, the final live policy should say so clearly and describe the chosen safeguards in practical terms.
JeoValid should describe security honestly and modestly. A defensible formulation is that the app uses reasonable technical and organizational measures appropriate to the nature of the data and the architecture of the service. In JeoValid's case, the strongest practical protective measure is that geological project data are processed locally on the device rather than centrally stored by the developer. Additional safeguards may include least-privilege permissions, secure transport for third-party purchase integrations, access control to support channels and admin panels, and regular review of SDKs and dependencies. No internet transmission or electronic storage system can be guaranteed to be perfectly secure. Public benchmark policies for field apps commonly use the same measured approach.
JeoValid is a professional geology/productivity app and is not directed to children. JeoValid does not intentionally seek to collect personal data from children. If you believe that a child has submitted personal data through the website contact form or another support channel, JeoValid should be contacted so the information can be reviewed and deleted where appropriate. This is consistent with standard app-policy practice reflected in comparable field-app privacy policies.
JeoValid provides technical validation, visualization, and analytical support for geological/drilling workflows. The public website presents the product as a tool to support technical evaluation, not as a system that makes legal or similarly significant automated decisions about individuals. Accordingly, JeoValid does not use personal data for solely automated decisions that produce legal effects or similarly significant effects on users. Validation outputs, anomaly flags, and analytical suggestions are decision-support tools and should be reviewed by the user.
Where applicable law grants them, you may have the right to request access to your personal data, correction of inaccurate data, deletion or erasure of data, restriction of processing, objection to certain processing, and data portability. GDPR expressly recognizes access, rectification, erasure, portability, and related rights, and Türkiye's Law No. 6698 gives data subjects rights to learn whether their personal data are processed, request information, learn processing purposes and recipients, request correction, request deletion/anonymization where conditions are met, and seek compensation for unlawful processing.
Because JeoValid is designed not to hold server-side copies of project files under the confirmed architecture used for this draft, many requests about app project data can be fulfilled most directly by deleting files and app storage on the user's own device. Requests concerning website contact records, subscription-support records, or RevenueCat-side subscriber metadata may still be made to JeoValid, subject to identity verification, applicable law, and the limits of data that JeoValid actually controls. RevenueCat also states that deletion requests relating to customer data may require contacting RevenueCat.
Under GDPR, controllers are generally expected to respond without undue delay and at the latest within one month. Under KVKK, the data controller must conclude the request as soon as possible and at the latest within thirty days, generally free of charge. JeoValid should adopt those timelines in its operational process, while reserving the right to request enough information to verify the requester's identity and understand the scope of the request.
JeoValid should offer a simple route such as an email to a dedicated privacy address. For clarity, users may submit requests by emailing the privacy/support contact with enough information to identify the relevant interaction, such as the approximate date of contact or purchase, the platform used, the device platform, and the email address used in contact correspondence if relevant. Türkiye's rules specifically recognize requests to controllers through written or electronic means.
A careful deletion clause for JeoValid should explain the difference between data controlled by JeoValid and data controlled by third parties. JeoValid can delete support emails, website contact records, and any subscriber metadata it controls or can instruct RevenueCat to delete on its behalf where appropriate. JeoValid cannot guarantee deletion of app store billing records held independently by Google or Apple, and deleting RevenueCat's copy may not prevent store-side purchase records from existing or later being restored. RevenueCat's documentation makes that limitation explicit.
Sample Data Deletion Request Form Text
Subject: Personal Data Access / Deletion Request
Hello JeoValid Privacy Team,
I am requesting the following action regarding my personal data: access / correction / deletion / portability / objection.
My details:
I understand that JeoValid may need additional information to verify my identity and locate the relevant records.
Thank you.
For the mobile app itself, traditional browser cookies are generally not relevant. For the website, JeoValid's current public privacy page says limited cookies may be used for preferences and traffic analysis. The final policy should distinguish essential cookies from analytics or marketing cookies; explain their purpose, duration, and provider where possible; and provide any banner or consent controls required by the user's jurisdiction. If no non-essential cookies are actually used, that section should be simplified accordingly.
JeoValid may update this Privacy Policy from time to time to reflect new features, changed legal requirements, or new service providers. Google Play and Apple both expect app privacy disclosures to stay aligned with actual practices, and Google specifically states that developers are responsible for complete and accurate declarations, including for data handled through third-party SDKs. If JeoValid introduces analytics, crash reporting, cloud sync, team workspaces, external AI services, or any new permissions, the policy and store disclosures should be updated before the relevant version is released.
JeoValid Privacy Contact
Email: destek@jeovalid.com
Support: destek@jeovalid.com
You can also reach us through the Contact page on our website.
These are short-form notices for store fields or summary boxes. They do not replace the full policy.
Recommended Google Play short notice
JeoValid processes geological project files and location-based QA/QC data primarily on the device to validate and visualize drilling/geology datasets. The developer does not store user project files or live location on its own servers. JeoValid does not require user accounts and does not use camera, microphone, or photo uploads. If JeoValid PRO is purchased, subscription-related purchase history and entitlement data are processed by the app store and RevenueCat to manage paid access.
Recommended App Store short notice
JeoValid does not require end-user accounts and is designed so project data and field-location workflows remain on-device. No camera, microphone, or photo-upload features are used. If PRO features are purchased, purchase information is processed by the relevant app store and RevenueCat to validate subscriptions and restore entitlements. If only anonymous RevenueCat app user IDs are used and no separate identifier links purchases to a person, JeoValid may be able to disclose Purchases as not linked to identity, but that should be verified before submission.
Before publishing the policy and updating store metadata, these items should be confirmed and then frozen in one release checklist.
jeovalid.destek@gmail.com and destek@jeovalid.com.The draft above is strong enough to use as a working production text, but the final release version should only be published after those confirmation points are checked against the actual shipping APK/AAB, the website implementation, and the live SDK inventory. That is exactly the kind of alignment Google Play and Apple expect, and it is also the safest way to stay consistent with GDPR and KVKK transparency duties.
This page is based on the "JeoValid Privacy Policy Research and Tailored Draft" research report. You can download the original PDF here: JeoValid Privacy Policy Research and Tailored Draft.pdf.