Privacy Policy
Last updated: August 4, 2026
Halim Öztürk ("we," "our," or "us") publishes the Broomly app. This Privacy Policy explains exactly what the app collects, who processes it, and what we do not do. It is written to match, item for item, the App Privacy label shown on Broomly's App Store product page.
1. The most important thing: your photos never leave your device
Broomly needs access to your photo library, contacts and calendar to do its job. None of that content is ever uploaded to us or to anyone else. Every scan — duplicate detection, similar-photo grouping, blur detection, video compression, contact de-duplication and calendar clean-up — runs entirely on your iPhone or iPad.
Concretely, the app never transmits:
- your photos, videos, screenshots, or any image data;
- your contacts — no names, phone numbers, or e-mail addresses;
- your calendar events — no titles, dates, locations, or attendees.
Outside of the analytics and subscription providers named in section 4, the app makes no network requests at all. There is no Broomly server, and no account to sign in to.
2. What we do collect
These four categories are everything Broomly collects, and they correspond one-to-one with our App Store privacy label:
- Usage data (product interaction). Events describing how the app is used — which cleaning tool was opened, that a scan started or finished, that the paywall was shown. Used for analytics only.
- Identifiers (device ID). A random, per-install identifier generated by our analytics provider (Mixpanel's distinct ID) and an anonymous app-user ID generated by RevenueCat. These are not your name, e-mail, Apple ID, or advertising identifier, and deleting and reinstalling the app produces a new one. Used for app functionality and analytics.
- Approximate location (coarse). Derived from your IP address by our analytics provider — see section 3. Used for analytics only.
- Purchases (purchase history). Whether you have an active subscription or trial, and the related App Store transaction information. Used for app functionality and analytics.
2.1 The scan numbers we do send — and what they are not
So we can tell whether the app is actually helping people free up space, our analytics events carry aggregate counts and sizes, such as: how many assets a scan looked at (asset_count), how many duplicates it found (duplicate_count), how many contacts were examined (contact_count), how many past calendar events were found (past_event_count), how many items you deleted (deleted_count), and how many bytes were reclaimed (freed_bytes, total_size).
These are numbers, not content. "You had 412 duplicate photos and freed 1.8 GB" is the kind of thing we learn. Which photos, of what, of whom — we never see, because that data never leaves your device.
Some events also carry a price and currency property. To be unambiguous: these refer to the price of our own subscription as shown on the paywall. They have nothing to do with your finances.
3. Approximate location — how it actually works
Broomly never asks for, and never receives, your device's location. The app does not use Location Services or GPS, and it declares no location permission.
Our analytics provider, Mixpanel, nevertheless sees the IP address that every internet request carries, and derives an approximate city, region and country from it on its own servers. That IP-derived approximation is why "Coarse Location" appears on our App Store privacy label. It is city-level at best, and never precise.
4. Who processes data on our behalf
- Mixpanel — product analytics. Receives the usage events and aggregate counts described above, the per-install identifier, and the IP address from which the approximate location is derived. See Mixpanel's Privacy Policy.
- RevenueCat — subscription management and receipt validation. Receives an anonymous app-user ID and your subscription status. See RevenueCat's Privacy Policy.
- Apple — App Store payments and, if you enable it, iCloud sync. See Apple's Privacy Policy.
5. On-device storage and iCloud sync
Broomly stores its working data on your device using Apple's on-device database: your preferences, your scan-session history (type of scan, item counts, estimated reclaimable bytes, timestamps), and the fingerprints it computes so a repeat scan is fast — a perceptual hash and an Apple Vision feature print per asset, plus that asset's local Photos identifier and dimensions.
Those fingerprints are compact mathematical summaries used for matching; they are not your images, and they are never sent to us. If iCloud is available, this same working data syncs across your Apple devices through Apple's CloudKit, in your private iCloud database. That database belongs to your Apple Account — Halim Öztürk cannot access, read, or retrieve its contents. You can turn sync off in the app's settings.
6. Subscriptions and payments
Payments are processed entirely through Apple's App Store. We never see or store your card details, billing address, or Apple Account credentials. Subscription status is managed on our behalf by RevenueCat.
7. What we do NOT do
- We do not track you. Nothing we collect is linked to your identity or used to follow you across other companies' apps or websites — our App Store label's "Data Used to Track You" section is empty.
- We do not collect the advertising identifier (IDFA), and the app contains no advertising SDK. It therefore never shows an App Tracking Transparency prompt.
- We do not sell, rent, or trade your data, and we share nothing with advertisers or data brokers.
- We do not use a crash-reporting or diagnostics SDK, so we receive no crash logs or performance traces.
- We do not require an account, e-mail address, or login.
8. Data retention and deletion
Your scan data lives on your device and in your private iCloud, so you control it: deleting the app removes the local copy, and iCloud data can be cleared from your Apple Account settings. Analytics events held by Mixpanel and subscription records held by RevenueCat are retained only as long as needed for the purposes above, under those providers' retention practices. To ask us to delete the analytics records associated with your installation, contact us at the address below.
9. Data security
Because your photos, contacts and calendar never leave your device, they stay protected by your device's own security, including the Face ID / Touch ID lock Broomly supports. The limited analytics and subscription data described above travels over encrypted HTTPS connections. No method of storage or transmission is ever completely secure, but keeping your content on-device meaningfully reduces risk.
10. Your rights
Depending on where you live (for example under the GDPR or the CCPA) you may have the right to access, correct, delete, or port your personal data, and to object to its processing. Because we hold no account and no directly identifying information, we may be unable to link a request to a specific installation without further detail from you. We do not sell personal information. You can also disable iCloud sync at any time in the app's settings. Contact us and we will help where we can.
11. Children's privacy
Broomly is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us so we can promptly delete it.
12. International users
Broomly is available worldwide. Our providers may process the limited data described above in countries other than your own, subject to the safeguards set out in their respective privacy policies.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date, and material changes will also be reflected in the App Store privacy label.
14. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at: