What this page is
KVKK is Türkiye’s data protection law. It gives anyone whose personal data is processed the right to know who is processing their data, what is being processed, and why. This page is that answer. The Privacy Policy covers the same ground in plainer language; if the two conflict, this text governs.
Data controller
Baran Şahin — independent developer (baransahin.com). There is no legal entity behind this: the data controller is Baran Şahin as a natural person. This text says "I" because that is literally one person.
How to reach me: Send requests under Article 11 to camur@baransahin.com. The Communiqué on Application Procedures accepts a request sent from the email address registered to your account — the address you signed up with satisfies that condition. I respond within 30 days at the latest.
Personal data processed
- Identity and contact: email address, username. If you signed in with Apple or Google, the email address that provider sends me.
- Profile data: your bio, and your Instagram handle if you added one.
- In-app content: titles of the work you save, your notes, your progress.
- Security records: session logs, error and crash reports.
Your password never reaches me in readable form; it is stored irreversibly by the authentication provider.
Purposes of processing
- Creating your account and verifying sign-in
- Providing the core features (progress, showcase, following)
- Operating the reporting and blocking mechanisms, and enforcing the community guidelines
- Finding and fixing bugs
- Providing you with support
- Serving non-personalised ads in the app
Legal grounds
Under Article 5 of KVKK:
- Performance of a contract (5/2-c): creating an account, delivering the service.
- Legal obligation (5/2-ç): the content-review and complaint processes required by the app stores.
- Legitimate interest (5/2-f): security, abuse prevention, debugging, and the non-personalised advertising that pays for the app.
- Explicit consent (5/1): only for processing that is not strictly necessary — in those cases I ask you separately.
Transfers and cross-border processing
Your data is hosted with the infrastructure providers the app needs in order to run. Nothing is sold or rented to anyone for advertising.
Advertising: the app serves non-personalised ads through Google AdMob. No profile is built, no interest category is assigned, and no data about your account or the content you make in the app is transferred to the ad network. What does reach it: IP address (for city-level location), device type and OS version, on Android the advertising ID (used only for frequency capping, aggregated reporting and fraud prevention), which ad slot was shown along with impression and click data, and basic technical and performance data. On iOS no IDFA is transferred, because the app never requests tracking permission. For that data the ad network acts as a separate data controller. The full list is in the Advertising section of the Privacy Policy.
| Provider | Purpose | Servers |
|---|---|---|
| Supabase | Database, account management, file storage | Germany · Frankfurt AWS eu-central-1 |
| Expo (EAS) | Notification delivery, app updates | USA |
| Google (Firebase Cloud Messaging) | Android notifications | USA |
| Apple (APNs) | iOS notifications | USA |
| Resend | Email delivery | USA |
| Google AdMob | Non-personalised ad serving | USA · Google infrastructure |
Every provider except the ad network acts as a data processor: they process the data only on my instructions, and none of them receives data for advertising. The ad network acts as a separate data controller under its own policy.
Retention
Your data is kept while your account exists. If you delete your account, the data tied to it is deleted; clearing backups takes a little longer.
- Account and content data: until you delete your account.
- Error logs: 60 days maximum.
- Device push token: deleted when you sign out.
Since I do not sell anything, there are no invoice-type records I am legally required to retain.
Your rights — Article 11
By applying to the data controller you may:
- Learn whether your personal data is processed, and request information if it is
- Learn the purpose of processing and whether it is used accordingly
- Know the third parties, in Turkey or abroad, that the data is transferred to
- Request correction if it is incomplete or inaccurate
- Request erasure or destruction
- Request that corrections and erasures be notified to third parties the data was transferred to
- Object to an adverse outcome produced solely by automated analysis
- Claim compensation for damage caused by unlawful processing
How to apply
Write to camur@baransahin.com. Your request will be answered within 30 days at the latest. Writing from the email address registered to your account is enough to verify your identity.
If you are not satisfied with the outcome, you retain the right to complain to the Turkish Personal Data Protection Board.