Privacy Policy
In short: OfferMed has no server. There is no account and no sign-in. Your agency details, your catalog, your templates, the offers you create and all offer content including the patient's name stay on your own device; none of it is sent to us or to anyone else. The only thing that leaves your device is the purchase information sent to Apple and RevenueCat to check whether your subscription is valid — that traffic carries no name, no email address and no patient data. There are no ads, no usage analytics and no tracking.
1. Data controller
The data controller is the party that decides why and how personal data is processed. For the OfferMed app and this website, that party is Çetin KOCATÜRK (Türkiye).
Contact: info@selhux.com
This applies to the operation of the app itself. For the patient data you enter into the app, you — the agency — are the controller; see §3.
2. What stays on your device
OfferMed has no backend server. Everything the app keeps lives in your iPhone's own storage, inside the app's protected area (the iOS sandbox):
- your agency profile (name, contact details, logo image),
- your treatment catalog, package templates and default texts,
- the offers you create — including the patient's name, country, language, selected procedures and prices,
- the PDF files the app generates,
- the last known state of your subscription and your free offer counter.
None of this is sent to us, made accessible to us, or backed up to any server. We cannot see it.
3. Patient data and GDPR/KVKK
OfferMed is a tool for agencies: you prepare the offer and you enter the patient's details. For that reason the agency is the controller of the patient data, not us. Informing the patient, obtaining consent where required, and storing or deleting their data in line with the law are the agency's obligations (GDPR in Europe; Law No. 6698 (KVKK) in Türkiye).
One technical fact makes this simpler: the patient data you enter never leaves your device. Because we do not process it, we are not a “processor” either, and no data processing agreement between us is needed.
When you send a generated PDF to a patient, a hospital or anyone else, you are the party making that transfer and it is your responsibility.
4. What leaves your device
The app makes network connections for two purposes only:
- Subscription validation. When the app launches and when a purchase is made, it asks Apple's and RevenueCat's servers whether your subscription is valid (§5).
- Sharing that you start. A generated PDF leaves the device only when you send it from the iOS share sheet. You choose where it goes; the app never uploads the file on its own and does not record where you sent it.
Beyond that the app makes no server requests at all: it downloads no content, fetches no updates and sends no telemetry.
5. Third parties
| Party | Purpose | Data processed |
|---|---|---|
| Apple (App Store / StoreKit) | App distribution, purchases and subscription billing | Your Apple account and payment details belong to Apple; we never see them. Only the “subscribed / not subscribed” result reaches us. |
| RevenueCat, Inc. (USA) | Validating the purchase receipt, reading subscription status, and the subscription statistics in RevenueCat's own dashboard (subscriber counts, plan mix, revenue charts) | An anonymous app user identifier generated by RevenueCat, purchase and receipt information, device and operating system information, app version, and the IP address inherent to the connection. |
The identifier sent to RevenueCat is anonymous: the app never asks you for a name, email address, phone number or any other account detail, so it has nothing of the kind to send. Patient data, offer content, your catalog and your PDFs are never part of this traffic. The app does nothing that falls under iOS App Tracking Transparency and does not read your advertising identifier.
RevenueCat processes data in the United States; this is an international transfer and it is limited to the subscription data listed above. RevenueCat's own privacy policy is at revenuecat.com/privacy.
6. Permissions we ask for
The app requests a single iOS permission: access to your photos. It is requested only on the Settings › Branding screen, to let you pick your agency logo. The image you choose is resized and copied into the app's own storage and stays there; your photo library is not scanned, no other image is read, and no image is ever sent anywhere.
The app does not request camera, microphone, location, contacts, calendar or health access — no feature uses them.
7. What we do not collect
None of the following exist in the app:
- accounts, registration or sign-in,
- usage analytics or event tracking that measures your behaviour inside the app — which screen you opened, what you tapped, how long you stayed,
- crash reporting,
- advertising or use of the advertising identifier,
- cookies, pixels or cross-device tracking,
- location tracking.
The one exception is the purchase data in §5: RevenueCat processes it for receipt validation and for the subscription statistics in its own dashboard. That is exactly why our App Store privacy declaration lists “Purchase History” under the Analytics and App Functionality purposes. Those statistics are about subscription data; they do not measure how you use the app.
8. Retention and deletion
Data on your device stays there until you delete it. There are two ways to delete it: remove individual records inside the app, or remove the app entirely.
If you delete the app or move to a new device, everything it holds — your agency profile, your catalog, your templates, your offer archive and the PDFs on disk — is lost and cannot be brought back. There is no copy on a server, no copy with us, and no backup we could restore. We recommend sharing the offers you want to keep as PDFs and sending them to yourself. For the subscription side of this, see Terms of Use §3.
Subscription records held by RevenueCat are kept for as long as the subscription relationship and statutory retention periods require, so that a purchase can be validated. You may request their deletion via info@selhux.com.
9. Children's privacy
OfferMed is a business tool for medical tourism agencies. It is not directed at children and does not knowingly collect data from them. In any case, the app collects no user data at all.
10. Your rights
Your rights under GDPR and KVKK Art. 11 (access, rectification, erasure, objection to processing, data portability) are unaffected. Because of how the app is built, you exercise most of them directly yourself: your data is on your device, so you can view, correct and delete it at any time — you do not need to ask us, because we hold no copy.
Only the subscription data in §5 may require contacting us: info@selhux.com. We respond within 30 days at the latest.
11. This website
This site is plain HTML and CSS. It sets no cookies, runs no JavaScript, loads no external fonts or scripts, contains no analytics, and its server keeps no access log. That restriction is also written into the server configuration as a Content Security Policy: if a tracker were ever added to the site, the browser would block it.
12. Changes
If this policy changes, the new version is published at this address and the “Last updated” date at the top of the page is revised. If an update materially changes how the app handles data, we will also announce it inside the app.
13. Contact
For any privacy question: info@selhux.com