JPY Converter (Yen Converter JPY Rate) — Last updated: 31 August 2026
This policy describes how the JPY Converter iOS app (“the App”) and the website at yenconverter.app handle your information.
In short: the App has no accounts and asks for no name, email address or login. Your conversion history stays on your device and we hold no copy of it. Price tags you scan are read entirely on your device — no photo is ever uploaded or saved. What does leave your device is limited, pseudonymous usage, crash and purchase data handled by three named providers, described in Sections 7 to 9. We do not show advertising, we do not track you across apps or websites, and we do not sell your data.
We want to be straightforward about one thing: pseudonymous data of that kind is still personal data under the GDPR, so this policy does not claim that we “collect no personal data”. It explains exactly what we do collect instead.
The controller for the processing described in this policy, within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR), is:
Muhammet Emre Yılmaz, trading as LuvleeLab
Hildesheimer Str. 120
30173 Hannover
Germany
luvleelab@gmail.com
Full provider details are in our Impressum. We are established in Germany, within the European Union, so the GDPR applies to us directly and no Article 27 representative is required. We are not required to appoint a Data Protection Officer under Article 37 GDPR; privacy enquiries go to the address above.
The App has no account system — no registration, no login, no password, and we never ask for your name, email address, phone number or date of birth. We cannot identify you as a person, and we hold nothing that would let us link one device to another or to you.
What we do receive is the following, all of it tied only to randomly generated identifiers that exist to keep one installation’s events apart from another’s:
We receive none of the following: your conversion history, the amounts you convert as exact figures, anything the camera sees, your location, your contacts, your photo library, your advertising identifier, or any health data. The App does not request permission for any of these except the camera, and the camera never sends anything anywhere (Section 5).
Article 13(1)(c) GDPR requires us to tell you the legal basis for each purpose:
| Purpose | Data | Legal basis |
|---|---|---|
| Converting currencies and keeping your history in the App | Amounts and currencies, on your device only | Art. 6(1)(b) — performance of the agreement with you. We never receive this data |
| Fetching exchange rates | The currency codes requested; your IP address is visible to the rate provider as a technical necessity of any internet request | Art. 6(1)(b) — performance of the agreement with you |
| Reading a price tag with the camera | The camera image, processed on your device and immediately discarded | Art. 6(1)(b), with the iOS camera permission prompt as the technical authorisation. You can revoke it at any time in iOS Settings |
| Providing and verifying a subscription | Anonymous identifier, Apple purchase receipt | Art. 6(1)(b) — performance of the agreement |
| Usage analytics | Pseudonymous app events (Section 7) | Art. 6(1)(f) — our legitimate interest in understanding which features are used and improving the App. You may object at any time (Section 16) |
| Crash and error reporting | Device model, OS and app version, error details | Art. 6(1)(f) — our legitimate interest in a stable, secure App |
| Answering your support email | Your email address and your message | Art. 6(1)(b) and Art. 6(1)(f) — responding to your enquiry |
| Meeting legal obligations | As required | Art. 6(1)(c) |
You are not required to provide any personal data to us, and there is nothing to provide — the App works without an account. The camera permission is optional: decline it and every other feature still works, you simply type amounts instead of scanning them. Analytics and crash reporting are the only processing you can object to, and objecting does not limit any feature.
Rates come from the Frankfurter API (api.frankfurter.dev), which republishes official reference rates from central banks, the European Central Bank among them. If that service is unavailable, the App falls back to the ECB’s own daily reference-rate file at www.ecb.europa.eu.
These requests carry only currency codes — for example a base currency and the list of currencies to quote. No identifier, no authentication token, no device information and no usage data is attached, and neither provider is told what amount you are converting or why. As with any request your device makes over the internet, the receiving server necessarily sees your IP address; we have no access to those logs and receive nothing back beyond the rates themselves.
Rates are cached on your device so the App keeps working offline, which also means it makes far fewer of these requests than one per conversion.
The App asks for camera access with the message: “JPY Converter uses the camera to scan price tags and convert amounts instantly.”
Scanning runs entirely on your device, using Apple’s built-in on-device text recognition (VisionKit). Concretely:
If you decline camera access, or revoke it later in iOS Settings, everything else in the App continues to work.
Your conversion history is stored in the App’s private container on your device (Core Data), and is capped at the 100 most recent conversions — older entries are dropped automatically. Cached exchange rates, your language choice, appearance setting and similar preferences are stored on the device as well.
There is no cloud sync. The App does not use iCloud, CloudKit or any other synchronisation service, so your history exists on that one device and nowhere else. Nothing is stored in the Keychain. We operate no server that stores your data.
An iCloud or local device backup made by iOS may include the App’s data, as it may for any app. That backup is governed by Apple’s terms, not by this policy, and we have no access to it.
We use Mixpanel to understand which parts of the App are used, configured with European data residency — events are sent to Mixpanel’s EU endpoint and stored on servers in the European Union.
Mixpanel is not given your device’s identifier. The App explicitly turns that off, so Mixpanel generates a random identifier for each installation instead. We make no identify call and set no user profile, so events are never attached to a name, an email address or an account — because there is no account. Reinstalling the App produces a new identifier with no link to the previous one.
The events are ordinary product analytics: the App being opened, onboarding finishing, a paywall being shown or dismissed, a purchase being started, completed, failed or restored, a conversion being performed, the conversion direction being swapped, a result being copied, history being viewed or cleared, settings being opened, the scanner being opened and its result used, a rate refresh succeeding or failing, and a currency or language being changed. Alongside them we record your selected language, your system language and which subscription offering you were shown.
Amounts are deliberately blunted before they are sent. When a conversion is recorded, the figure is rounded to the nearest ten and only that bucket is transmitted, together with the source currency — specifically so that the analytics cannot reconstruct what you actually converted. Exact amounts never leave your device.
This identifier is persistent within one installation, so we treat it as pseudonymous personal data rather than calling it anonymous. It contains nothing about who you are, but it can distinguish one installation from another, and under the GDPR that is enough for it to count. You can object to this processing at any time (Section 16).
We use Sentry to learn about crashes and errors, hosted in Sentry’s German (EU) region. What it receives is the technical context of a fault: the device model, the iOS version, the App version and the error itself.
The App is configured to reduce this further: it does not enable Sentry’s option to attach personally identifying information, it strips the user object from every event before sending, it removes any Authorization and Cookie headers, it disables performance tracing entirely, and it disables automatic session tracking. Because the identifying-information option is left off, your IP address is not attached to crash events.
No conversion history, no scanned text and no camera data is included in a crash report.
Subscriptions and the one-time lifetime purchase are sold and charged by Apple through the App Store. We never see your payment card, your billing address or your Apple ID.
We use RevenueCat to verify and restore purchases. RevenueCat receives your Apple purchase receipt, the product you bought and an anonymous user identifier that RevenueCat generates itself — we do not set an identifier of our own, so there is nothing on our side to connect a purchase to a person. No name and no email address is sent.
The App shows no advertising and contains no advertising SDK. There is no Google AdMob, no Meta SDK and no attribution or install-tracking service of any kind.
The App never asks for App Tracking Transparency permission, because it has nothing to ask for: it does not access your advertising identifier (IDFA) and does not track you across other companies’ apps or websites. Its App Store privacy manifest declares tracking as false with no tracking domains, matching that.
We chose European hosting wherever the provider offers it:
Your conversion history and everything the camera sees are not included in any transfer, because they never leave your device at all.
You may request a copy of the relevant transfer safeguards by writing to us.
On your device. Your conversion history stays until you delete it or it falls out of the 100-entry cap. You can delete a single conversion from the History screen, or use clear all there to remove the whole history at once. Deleting the App removes everything it stored locally, including cached rates and preferences.
With our processors. Where a period is set by the provider’s own platform policy rather than chosen by us, we say so, because we would rather be accurate than appear to offer a control we do not have.
Because the identifiers above are anonymous or randomly generated and we hold no account for you, we usually cannot tell which records belong to your device. If you want a specific installation’s data removed, write to us and we will ask for what we need to locate it — in practice this is straightforward for a purchase and difficult for analytics events, and we will tell you honestly which is which rather than promise more than we can do.
We take appropriate technical and organisational measures under Article 32 GDPR, proportionate to a design in which your data mostly does not leave the device:
No method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR.
The App does perform calculations — converting an amount at a published reference rate, and reading a number off a price tag. These are arithmetic and text recognition performed on your device. No decision is taken about you on their basis, we never receive the results, and they are not used to evaluate, predict or score you.
The App is intended for users aged 16 and over, matching the age of digital consent under Article 8 GDPR in Germany, where we are established. We do not knowingly collect personal information from children under that age. If you believe a child under 16 has used the App and data has reached us, please contact us and we will delete what we can identify.
Under the GDPR you have the following rights in respect of your personal data:
Over your conversion history these rights are immediate and do not require us: it is on your device, so you already have direct access, correction and deletion at any time through the App itself. For the limited data held by the processors in Sections 7 to 9, write to luvleelab@gmail.com. We respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. Exercising these rights is free of charge.
Right to lodge a complaint (Art. 77). If you believe we have handled your data unlawfully, you may complain to a supervisory authority. The authority responsible for us is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Hannover, Germany · lfd.niedersachsen.de
You may also complain to the supervisory authority in the EU or EEA country where you live or work, or where you believe the infringement took place. We would appreciate the chance to resolve the matter first, but you are not required to contact us before complaining.
This section applies if and to the extent that the California Consumer Privacy Act applies to us. We are a sole trader in Germany and do not presently expect to meet the CCPA’s thresholds for a covered “business”. We set out the position below so that California residents know where they stand either way.
In the twelve months before the date of this policy, the categories of personal information collected through the App were: identifiers (randomly generated per-installation identifiers), commercial information (whether you hold a subscription, and your Apple purchase receipt), and internet or other electronic network activity (in-app usage and crash events). These were collected from your device for the purposes described in Sections 7 to 9 and disclosed to the service providers named there.
We do not sell or share your personal information — not for money, and not for cross-context behavioural advertising. The App contains no advertising, requests no advertising identifier, and makes no ATT request, so there is no advertising disclosure to opt out of.
Your rights are to know what we collect and why, to access it, to correct it, to delete it, and not to be discriminated against for exercising any of them — the App’s features and pricing do not change because you exercised a privacy right. To exercise a right, write to luvleelab@gmail.com. We confirm receipt within 10 business days and respond within 45 days, extendable once by a further 45 days where reasonably necessary. Because we hold no account for you, we may need to ask for information to verify that a request relates to your device.
The website at yenconverter.app is a static site. It sets no cookies, runs no analytics, loads no external fonts and contains no advertising or tracking tags. We receive no server logs for it, store none and have no access to them, so there is no record of your visit on our side.
The site is served by Cloudflare Pages. Like any web host, Cloudflare processes the technical data needed to deliver a page and to protect the site from attacks — including your IP address, the page requested, the time and your browser’s user agent — under its own retention practices. The legal basis for that processing is Art. 6(1)(f) GDPR: our legitimate interest in operating a functioning, secure website.
One page feature does contact a third party, and we would rather name it than let you discover it. Some guide pages carry a small live currency converter. When such a page loads, your browser requests the current rate from api.frankfurter.dev, the same public rate service the App uses, and that request necessarily reveals your IP address to that provider. Nothing else is sent: no cookie, no identifier, no information about you, and no record of what you type into the widget — the calculation itself happens in your browser. The widget also stores the fetched rate in your browser’s local storage so the page does not re-request it on every visit. That entry holds a rate and a timestamp, nothing about you, and it is functional storage for the converter you came to use rather than a tracking mechanism. You can clear it at any time through your browser’s site-data controls. This is why you see no cookie banner: there is no tracking, profiling or advertising to consent to.
Links to external sources, such as the European Central Bank or the App Store, are ordinary hyperlinks. Nothing is requested from those sites until you click through, at which point their own privacy policies apply.
If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours of becoming aware of it where Article 33 GDPR requires, and we will inform affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by Article 34.
Because we maintain no server-side database of conversions, a breach of the provider dashboards we use could not expose one. Risks outside that boundary — your device itself, the operating system, and the software supply chain through which updates reach you — are real, and we address them through the measures in Section 13.
We may update this policy, for example when we add a feature or change a service provider. The date at the top of this page always shows the current version. If a change materially affects how we handle your data, we will say so in the App before it takes effect, and where a change requires your consent we will ask for it rather than assume it.
LuvleeLab — Muhammet Emre Yılmaz
Hildesheimer Str. 120, 30173 Hannover, Germany
luvleelab@gmail.com
Full provider details: Impressum.