Patify Gizlilik Politikası

Yürürlük Tarihi: 19 Temmuz 2026 Son Güncelleme: 9 Ağustos 2026


1. Veri Sorumlusu

Patify uygulamasının ("Uygulama") veri sorumlusu Cihan Cengiz'dir.

BilgiDetay
Veri SorumlusuCihan Cengiz
E-postab.cihancengiz@gmail.com
UygulamaPatify (com.bcc.buschat)

Kişisel verilerinizle ilgili her türlü başvurunuzu, 6698 sayılı Kişisel Verilerin Korunması Kanunu'nun ("KVKK") 11. maddesi kapsamındaki haklarınızı kullanmak amacıyla yukarıdaki e-posta adresine iletebilirsiniz. Başvurular azami 30 gün içinde yanıtlanır.


2. Toplanan Veri Kategorileri

Patify, aşağıdaki kategorilerdeki kişisel verileri işlemektedir.

2.1 Hesap Verileri

  • E-posta adresi — kayıt ve kimlik doğrulama için.
  • Parola — yalnızca hash'lenmiş biçimde saklanır; düz metin hiçbir zaman işlenmez.
  • Kullanıcı adı — profil tanımlaması için.
  • Profil fotoğrafı — isteğe bağlı, kullanıcı tarafından yüklenir.
  • Sosyal medya URL'leri — isteğe bağlı, profil sayfasında gösterilir.
  • Telefon numarası — isteğe bağlı.
  • Doğum tarihi — yaş doğrulaması ve veli rızası akışı için (kayıt sırasında toplanır).

2.2 İçerik Verileri

Uygulamada oluşturduğunuz içerikler:

  • Gönderiler ve gönderi fotoğrafları/videoları
  • Yorumlar
  • Tartışma soruları ve yanıtları
  • Sahiplendirme ilanları
  • Doğrudan mesajlar (DM)
  • Oylar, beğeniler ve yer imleri
  • Takip edilen / takipçi ilişkileri

2.3 Cihaz ve Teknik Veriler

  • IP adresi — Sentry ve Supabase aracılığıyla; hata ayıklama ve güvenlik amacıyla.
  • İşletim sistemi sürümü — push bildirim hedefleme için.
  • Uygulama sürümü — hata izleme ve uyumluluk tespiti için.
  • Kilitlenme raporları — Sentry üzerinden; uygulama stabilitesi için.

2.4 Konum Verisi

  • Cihaz GPS konumu — yalnızca sahiplendirme ilanları akışında yakındaki ilanları göstermek için talep edilir; anlık olarak kullanılır, sunucularda saklanmaz.

2.5 Bildirim Verileri

  • OneSignal player_id — push bildirimlerinin gönderilmesini sağlamak için.

2.6 Reklam Ölçüm Verileri

Bu kategori yalnızca reklam ölçümü açık rızası verildiğinde işlenir. Rıza verilmediğinde toplama yapılmaz.

  • Reklam tanımlayıcısı (IDFA / GAID) — cihazınızın işletim sistemi tarafından atanan, sıfırlanabilir reklam kimliği; hangi reklam kampanyasının uygulama kurulumuyla sonuçlandığını ölçmek için Meta ile paylaşılır.
  • Uygulama olayları — kurulum, kayıt olma ve ilan oluşturma gibi önceden tanımlanmış olaylar. Serbest metin, konum koordinatı veya arama sorgusu içermez.

3. İşleme Amaçları ve Hukuki Dayanak

Kişisel verilerinizi aşağıdaki amaçlarla ve hukuki dayanaklara göre işliyoruz.

AmaçVeri KategorisiHukuki Dayanak
Hesap oluşturma ve yönetimiHesap verileriSözleşmenin ifası (GDPR Madde 6(1)(b)); açık rıza (KVKK m.5/1)
Sosyal içerik sunma ve etkileşimİçerik verileriSözleşmenin ifası (GDPR Madde 6(1)(b)); açık rıza (KVKK m.5/1)
Sahiplendirme ilanları için konum tabanlı aramaKonum verisiAçık rıza — kullanıcı her seferinde konum paylaşmayı seçer (GDPR Madde 6(1)(a); KVKK m.5/1)
Push bildirim gönderimiOneSignal player_idSözleşmenin ifası + açık rıza (GDPR Madde 6(1)(b)/(a))
Uygulama hatalarını izleme ve kararlılık sağlamaCihaz/teknik verilerMeşru menfaat (GDPR Madde 6(1)(f); KVKK m.5/2-f) — uygulamanın güvenli ve kararlı çalışması
Kullanım istatistikleri (Patify altyapısı)Uygulama içi davranış olayları (platform ve uygulama sürümü dahil)Açık rıza (GDPR Madde 6(1)(a); KVKK m.5/1)
Reklam kampanyası ölçümü ve kurulum ilişkilendirmesiReklam tanımlayıcısı (IDFA/GAID) + uygulama olayları (kurulum, kayıt, ilan oluşturma)Açık rıza (GDPR Madde 6(1)(a); KVKK m.5/1)

4. Saklama Süreleri

Veri TürüSaklama Süresi
Aktif hesap verileriHesap silinene kadar
Profil bilgileri (silme sonrası)Anonimleştirilmiş biçimde süresiz; kişisel tanımlayıcılar hesap silinme tarihinden itibaren 30 gün içinde kaldırılır
Gönderiler, sahiplendirme ilanları, medya dosyalarıHesap silinmesinden itibaren 30 gün içinde tamamen silinir
Mesajlar ve yorumlarİçerik korunur; kullanıcı adı anonimleştirilmiş yer tutucu ile değiştirilir
Kilitlenme ve hata raporları (Sentry)90 gün (Sentry varsayılan saklama politikası)
Kullanım istatistikleri (ham)90 gün; süre sonunda kalıcı olarak silinir. Bu süre boyunca bir kısmı, kişiye bağlanamayan toplu istatistiklere dönüştürülür
Kullanım istatistikleri (toplu/anonim)Anonimleştirilmiş biçimde süresiz saklanır — kişiye bağlanamaz
Push bildirim tokenleri (OneSignal player_id)Hesap silinince OneSignal çıkış (logout) işlemiyle temizlenir
Reklam ölçüm verileri (Meta'ya aktarılan)Meta'nın kendi saklama politikasına tabidir. Rıza geri çekildiğinde uygulama toplamayı durdurur ve Meta SDK'sındaki cihaz/kullanıcı tanımlayıcıları temizlenir
Audit kayıtlarıYasal yükümlülükler doğrultusunda tutulabilir

5. Veri İşleyenler (Alt İşleyiciler)

Patify, hizmetlerin yürütülmesi için aşağıdaki üçüncü taraf veri işleyenlerle çalışmaktadır. Bu işleyenlerle imzalanmış Veri İşleme Sözleşmeleri ("DPA") mevcuttur.

5.1 Supabase, Inc.

  • Konu: Kimlik doğrulama, veritabanı, dosya depolama
  • Konum: AWS altyapısı — ABD ve AB bölgeleri
  • DPA: Supabase standart DPA (https://supabase.com/legal/dpa)

5.2 Google LLC (Firebase)

5.3 OneSignal, Inc.

5.4 Sentry, Inc. (Functional Software, Inc.)

5.5 Google Sign-In

  • Konu: OAuth tabanlı kimlik doğrulama
  • Konum: Google altyapısı (ABD/AB)

5.6 Apple Sign-In

  • Konu: OAuth tabanlı kimlik doğrulama
  • Konum: Apple altyapısı (ABD/AB)

5.7 Meta Platforms, Inc. / Meta Platforms Ireland Ltd.

Yurt Dışı Veri Aktarımı (KVKK Madde 9)

Yukarıda listelenen işleyenler ağırlıklı olarak ABD'de faaliyet göstermektedir. KVKK'nın 9. maddesi uyarınca, yeterli korumanın bulunduğu ülkelere veya standart veri koruma sözleşmeleriyle güvence altına alınmış ülkelere veri aktarımı açık rızanıza dayanarak gerçekleştirilmektedir. Uygulamayı kullanarak bu aktarıma rıza göstermiş olursunuz. Bu rızanızı geri çekme hakkına sahipsiniz; ancak rızanın geri çekilmesi, uygulamanın işlevselliğini kısmen veya tamamen kısıtlayabilir.


6. Kullanıcı Hakları

KVKK'nın 11. maddesi ve GDPR'nin 15-22. maddeleri kapsamında aşağıdaki haklara sahipsiniz:

  1. Bilgi edinme hakkı: Kişisel verilerinizin işlenip işlenmediğini ve hangi kategorilerde işlendiğini öğrenebilirsiniz.
  2. Erişim hakkı: İşlenen kişisel verilerinizin bir kopyasını talep edebilirsiniz. Uygulama içinde Ayarlar > Verilerim > Verilerimi İndir yoluyla, hesabınıza bağlı verilerin bir kopyasını JSON formatında anında indirebilirsiniz.
  3. Düzeltme hakkı: Yanlış veya eksik verilerinizin düzeltilmesini talep edebilirsiniz. Profil bilgilerinizi uygulama içinden doğrudan düzenleyebilirsiniz.
  4. Silme hakkı (unutulma hakkı): Hesabınızı ve ilgili verilerinizi silmesini talep edebilirsiniz. Uygulama içindeki "Hesabı Sil" işlevi bu hakkı kullanmanızı sağlar.
  5. İşlemeye itiraz hakkı: Meşru menfaate dayanan işleme faaliyetlerine itiraz edebilirsiniz.
  6. İşlemenin kısıtlanması hakkı: Belirli koşullarda veri işlemenin kısıtlanmasını talep edebilirsiniz.
  7. Veri taşınabilirliği hakkı: Verilerinizin yapılandırılmış, makine tarafından okunabilir biçimde tarafınıza teslim edilmesini talep edebilirsiniz. Bu hak da aynı Ayarlar > Verilerim > Verilerimi İndir özelliğiyle karşılanır — indirilen dosya yapılandırılmış JSON formatındadır.
  8. Rızayı geri çekme hakkı: Rızanıza dayanan tüm işleme faaliyetleri için rızanızı her zaman geri çekebilirsiniz.

Başvuru Kanalı: Tüm talepler için b.cihancengiz@gmail.com adresine e-posta gönderiniz. Başvurular kimlik doğrulamasının ardından azami 30 gün içinde yanıtlanır. KVKK uyarınca yanıt ücretsizdir; aşırı veya tekrarlayan talepler için makul bir ücret alınabilir.


7. Yaş Kısıtlaması

Patify, 13 yaşın altındaki kişilerin kullanımına uygun değildir. 13 yaşın altındaki kullanıcıların kişisel verilerini bilerek toplamıyoruz.

13-16 yaş arası kullanıcılar (GDPR Madde 8 uyarınca): Bu yaş grubundaki kullanıcıların uygulamayı kullanabilmesi için ebeveyn veya vasi rızası gerekmektedir. Kayıt akışında doğum tarihi sorulmakta; sisteme tanımlanan yaş sınırının altında olduğu tespit edilen hesaplar askıya alınmaktadır.

13 yaşın altında bir çocuğun verilerini yanlışlıkla topladığımıza dair bilginiz varsa, lütfen b.cihancengiz@gmail.com adresinden bize ulaşın. Bu tür veriler derhal silinecektir.


8. Çerezler ve İzleyiciler

Patify, bir mobil uygulamadır ve tarayıcı çerezi kullanmamaktadır.

Bununla birlikte uygulama, aşağıdaki tanımlayıcıları kullanmaktadır:

  • Kullanım istatistikleri (Patify altyapısı): Hangi ekranların kullanıldığını ve kullanıcıların nerede takıldığını anlayabilmek için sınırlı sayıda uygulama içi kullanım olayı (ör. ekran görüntüleme, arama yapılması, ilan oluşturma adımları), Patify'nin kendi Supabase altyapısında kaydedilir. Bu kayıt yalnızca kullanıcının açık rızası alındıktan sonra ve hesabıyla ilişkilendirilerek yapılır; bu nedenle kişisel veri niteliğindedir ve KVKK m.5/1 uyarınca açık rızaya dayanır. Serbest metin, arama sorgusu, konum koordinatı veya cihaz tanımlayıcısı hiçbir zaman kaydedilmez — yalnızca önceden tanımlanmış, sınırlı bir değer kümesine sahip alanlar toplanır ve 90 gün sonunda silinir (bkz. Bölüm 4). Bu izni istediğiniz zaman Ayarlar > Kullanım istatistikleri üzerinden geri çekebilirsiniz; geri çekme işlemi hesabınıza bağlı ham kayıtları derhal siler.
  • Anonim ziyaretçi sayacı: Oturum açmamış (misafir) kullanıcıların uygulamayı nasıl kullandığına dair yalnızca günlük, toplu bir sayaç tutulur (ör. belirli bir ekranın kaç kez görüntülendiği). Bu sayaçta kullanıcı kimliği, cihaz tanımlayıcısı, oturum kimliği veya IP adresi bulunmaz ve herhangi bir kişiyle ilişkilendirilemez.
  • OneSignal: Push bildirimleri için cihaz düzeyinde player_id atanır. Bildirime abone olunması durumunda aktif olur; bildirimler devre dışı bırakıldığında veya hesap silindiğinde temizlenir.
  • Meta reklam ölçümü: Uygulama, yalnızca reklam ölçümü için açık rıza verdiğinizde, cihazınızın reklam tanımlayıcısını (IDFA/GAID) ve sınırlı sayıda uygulama olayını (kurulum, kayıt olma, ilan oluşturma) Meta (Facebook/Instagram) ile paylaşır. Bunun tek amacı, hangi reklam kampanyasının uygulama kurulumuyla sonuçlandığını ölçmektir. Rıza verilmediğinde Meta yazılım geliştirme kiti (SDK) varsayılan olarak kapalıdır ve hiçbir veri toplamaz; iOS'ta ayrıca sistem düzeyinde İzleme İzni (App Tracking Transparency) sorulur. Bu izni istediğiniz zaman Ayarlar > Kullanım istatistikleri üzerinden geri çekebilirsiniz; geri çekildiğinde toplama durur ve tanımlayıcılar temizlenir.

Bunun dışında, üçüncü taraf yeniden hedefleme (retargeting) veya reklam profilleme amacıyla herhangi bir izleyici kullanılmamaktadır.


9. Veri Güvenliği

Kişisel verilerinizin korunması için KVKK'nın 12. maddesi kapsamında aşağıdaki teknik ve idari tedbirler uygulanmaktadır:

  • Taşıma güvenliği: Tüm istemci-sunucu iletişimi TLS (HTTPS/WSS) ile şifrelenir.
  • Erişim kontrolü: Supabase Row Level Security (RLS) politikaları ile her kullanıcı yalnızca kendi verilerine erişebilir.
  • Parola güvenliği: Parolalar düz metin olarak saklanmaz; güvenli hash algoritmaları kullanılır.
  • Hata izleme: Sentry'e iletilen kilitlenme raporları hassas veri içermemeye özen gösterilerek yapılandırılmıştır.
  • Yetkilendirme: Üretim veritabanına erişim yalnızca yetkili geliştiricilerle sınırlıdır.

Hiçbir sistem %100 güvenli değildir. Bir güvenlik açığı keşfederseniz lütfen b.cihancengiz@gmail.com adresinden bize bildirin.


10. Politika Değişiklikleri

Bu Gizlilik Politikası zaman zaman güncellenebilir. Önemli değişiklikler yapılması durumunda:

  • Uygulama içinde bildirim gösterilecektir.
  • Politikanın üst kısmındaki "Son Güncelleme" tarihi yenilenecektir.

Değişikliğin yürürlüğe girmesinden sonra uygulamayı kullanmaya devam etmeniz, güncellenmiş politikayı kabul ettiğiniz anlamına gelir. Değişiklikleri kabul etmiyorsanız hesabınızı silebilirsiniz.


11. Yürürlük Tarihi

Bu Gizlilik Politikası ilk olarak 23 Mayıs 2026 tarihinde yürürlüğe girmiş; 19 Temmuz 2026 tarihinde, Firebase Analytics'in kaldırılıp Patify'nin kendi altyapısında yürütülen, açık rızaya dayalı kullanım istatistikleri sistemiyle değiştirilmesini yansıtacak şekilde güncellenmiştir. 9 Ağustos 2026 tarihinde, reklam kampanyalarının etkinliğini ölçmek amacıyla açık rızaya dayalı Meta (Facebook/Instagram) reklam ölçümü entegrasyonunu yansıtacak şekilde güncellenmiştir.


12. İletişim

Kişisel verilerinize ilişkin tüm sorularınız, talepleriniz veya şikâyetleriniz için:

E-posta: b.cihancengiz@gmail.com

KVKK kapsamındaki haklarınızı kullanmak için yukarıdaki adrese "KVKK Başvurusu" konusuyla e-posta gönderebilirsiniz. Talebinizde kimliğinizi doğrulayacak bilgileri (ad-soyad, kayıtlı e-posta adresi) eklemeniz yanıt sürecini hızlandıracaktır.

Başvurunuza 30 gün içinde yanıt verilmemesi halinde Kişisel Verileri Koruma Kurumu'na (KVKK) şikâyette bulunma hakkınız saklıdır.


Patify Privacy Policy

Effective Date: 19 July 2026 Last Updated: 9 August 2026


1. Data Controller

The data controller for the Patify application ("App") is Cihan Cengiz.

DetailValue
Data ControllerCihan Cengiz
Emailb.cihancengiz@gmail.com
AppPatify (com.bcc.buschat)

You may direct any requests regarding your personal data, including exercising your rights under the Turkish Personal Data Protection Law No. 6698 ("KVKK") Article 11 and GDPR Articles 15–22, to the email address above. Requests will be responded to within a maximum of 30 days.


2. Categories of Data Collected

Patify processes personal data in the following categories.

2.1 Account Data

  • Email address — for registration and authentication.
  • Password — stored only in hashed form; plaintext is never processed or stored.
  • Username — for profile identification.
  • Profile photo — optional, uploaded by the user.
  • Social media URLs — optional, displayed on the profile page.
  • Phone number — optional.
  • Date of birth — for age verification and parental consent flow (collected at registration).

2.2 Content Data

Content you create or interact with in the App:

  • Posts and associated photos/videos
  • Comments
  • Discussion questions and answers
  • Pet adoption listings
  • Direct messages (DMs)
  • Votes, likes, and bookmarks
  • Following / follower relationships

2.3 Device and Technical Data

  • IP address — via Sentry and Supabase; used for debugging and security purposes.
  • Operating system version — for push notification targeting.
  • App version — for error tracking and compatibility identification.
  • Crash reports — via Sentry; for application stability.

2.4 Location Data

  • Device GPS location — requested only within the pet adoption listings flow to surface nearby listings; used in-the-moment and not persisted to our servers.

2.5 Notification Data

  • OneSignal player_id — to enable delivery of push notifications to your device.

2.6 Advertising Measurement Data

This category is processed only when you have granted explicit consent for advertising measurement. No data is collected without that consent.

  • Advertising identifier (IDFA / GAID) — the resettable advertising ID assigned by your device's operating system; shared with Meta solely to measure which advertising campaign led to an app installation.
  • App events — a predefined set of events such as install, registration, and listing creation. Contains no free text, location coordinates, or search queries.

3. Purposes of Processing and Legal Basis

We process your personal data for the following purposes and on the following legal bases.

PurposeData CategoryLegal Basis
Account creation and managementAccount dataPerformance of a contract (GDPR Art. 6(1)(b)); explicit consent (KVKK Art. 5(1))
Delivering social content and interactionsContent dataPerformance of a contract (GDPR Art. 6(1)(b)); explicit consent (KVKK Art. 5(1))
Location-based search for adoption listingsLocation dataExplicit consent — user chooses to share on each occasion (GDPR Art. 6(1)(a); KVKK Art. 5(1))
Sending push notificationsOneSignal player_idPerformance of a contract + explicit consent (GDPR Art. 6(1)(b)/(a))
Crash and error monitoringDevice/technical dataLegitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)) — ensuring the App operates safely and stably
Usage statistics (Patify infrastructure)In-app behavioural events (including platform and app version)Explicit consent (GDPR Art. 6(1)(a); KVKK Art. 5(1))
Advertising campaign measurement and install attributionAdvertising identifier (IDFA/GAID) + app events (install, registration, listing creation)Explicit consent (GDPR Art. 6(1)(a); KVKK Art. 5(1))

4. Retention Periods

Data TypeRetention Period
Active account dataUntil the account is deleted
Profile information (post-deletion)Retained in anonymised form indefinitely; personal identifiers removed within 30 days of account deletion
Posts, adoption listings, and media filesPermanently deleted within 30 days of account deletion
Messages and commentsContent preserved; username replaced with an anonymised placeholder
Crash and error reports (Sentry)90 days (Sentry default retention policy)
Usage statistics (raw)90 days; permanently deleted at the end of this period. During this window, a subset is converted into aggregate statistics that cannot be linked back to a person
Usage statistics (aggregate/anonymised)Retained indefinitely in anonymised form — cannot be linked back to a person
Push notification tokens (OneSignal player_id)Cleared via OneSignal logout on account deletion
Advertising measurement data (transferred to Meta)Subject to Meta's own retention policy. When consent is withdrawn, the App stops collection and clears the device/user identifiers in the Meta SDK
Audit recordsMay be retained as required by applicable law

5. Sub-processors (Third-Party Data Processors)

Patify works with the following third-party data processors to deliver its services. Data Processing Agreements ("DPAs") are in place with each.

5.1 Supabase, Inc.

  • Purpose: Authentication, database, file storage
  • Location: AWS infrastructure — US and EU regions
  • DPA: Supabase standard DPA (https://supabase.com/legal/dpa)

5.2 Google LLC (Firebase)

5.3 OneSignal, Inc.

5.4 Sentry, Inc. (Functional Software, Inc.)

5.5 Google Sign-In

  • Purpose: OAuth-based authentication
  • Location: Google infrastructure (US/EU)

5.6 Apple Sign-In

  • Purpose: OAuth-based authentication
  • Location: Apple infrastructure (US/EU)

5.7 Meta Platforms, Inc. / Meta Platforms Ireland Ltd.

  • Purpose: Advertising campaign measurement and install attribution — only when explicit consent for advertising measurement has been granted
  • Location: United States and EU (Ireland)
  • DPA: Meta standard data processing terms (https://www.facebook.com/legal/terms/dataprocessing)

Cross-Border Data Transfers (KVKK Article 9 / GDPR Chapter V)

Several sub-processors listed above are based in the United States. Under KVKK Article 9 and GDPR Chapter V, data transfers to countries without an adequacy decision are carried out on the basis of your explicit consent and, where applicable, standard contractual clauses or other approved transfer mechanisms. By using the App, you consent to these transfers. You may withdraw consent at any time; however, withdrawal may limit or prevent your ability to use the App.


6. Your Rights

Under KVKK Article 11 and GDPR Articles 15–22, you have the following rights:

  1. Right to information: Learn whether your personal data is being processed and in which categories.
  2. Right of access: Request a copy of the personal data we hold about you. Within the App, Settings > My data > Download My Data lets you download a copy of the data linked to your account in JSON format immediately.
  3. Right to rectification: Request correction of inaccurate or incomplete data. You can edit your profile information directly within the App.
  4. Right to erasure (right to be forgotten): Request deletion of your account and associated personal data. The in-app "Delete Account" function enables you to exercise this right.
  5. Right to object: Object to processing based on legitimate interests.
  6. Right to restriction of processing: Request that processing be restricted in certain circumstances.
  7. Right to data portability: Request that your data be provided in a structured, machine-readable format. This right is also fulfilled by the same Settings > My data > Download My Data feature — the downloaded file is in structured JSON format.
  8. Right to withdraw consent: For any processing based on your consent, you may withdraw that consent at any time.

How to Submit a Request: Send an email to b.cihancengiz@gmail.com. Requests will be processed within a maximum of 30 days after identity verification. Responses are provided free of charge under KVKK; a reasonable fee may apply for manifestly unfounded or excessive requests.


7. Age Restriction

Patify is not intended for use by persons under the age of 13. We do not knowingly collect personal data from children under 13.

Users aged 13–16 (pursuant to GDPR Article 8): Users in this age range require verified parental or guardian consent to use the App. Date of birth is requested at registration; accounts identified as belonging to users below the applicable age threshold are suspended pending consent verification.

If you believe we have inadvertently collected data from a child under the age of 13, please contact us immediately at b.cihancengiz@gmail.com. Such data will be deleted promptly.


8. Cookies and Trackers

Patify is a mobile application and does not use browser cookies.

However, the App uses the following identifiers:

  • Usage statistics (Patify infrastructure): A limited set of in-app usage events (e.g. screen views, searches performed, listing-creation steps) is recorded on Patify's own Supabase infrastructure to understand which screens are used and where users get stuck. This is recorded only after the user's explicit consent has been obtained, and is linked to their account — it is therefore personal data and rests on explicit consent under KVKK Art. 5(1). Free text, search queries, location coordinates, or device identifiers are never recorded — only fields with a predefined, limited set of values are collected, and these are deleted after 90 days (see Section 4). You may withdraw this consent at any time via Settings > Usage statistics; withdrawal immediately deletes the raw records linked to your account.
  • Anonymous visitor counter: For users who are not signed in (guests), only a daily, aggregate counter is kept of how the App is used (e.g. how many times a given screen was viewed). This counter contains no user ID, device identifier, session ID, or IP address, and cannot be linked to any individual.
  • OneSignal: A device-level player_id is assigned for push notification delivery. This is active only when the user is subscribed to notifications and is cleared when notifications are disabled or the account is deleted.
  • Meta advertising measurement: Only when you have granted explicit consent for advertising measurement, the App shares your device's advertising identifier (IDFA/GAID) and a limited set of app events (install, registration, listing creation) with Meta (Facebook/Instagram). The sole purpose is to measure which advertising campaign led to an app installation. Without consent, the Meta SDK is disabled by default and collects nothing; on iOS, a system-level App Tracking Transparency prompt is also shown. You may withdraw this consent at any time via Settings > Usage statistics; withdrawal stops collection and clears the identifiers.

Other than the above, no third-party retargeting or advertising-profiling trackers are used.


9. Data Security

We apply the following technical and organisational measures to protect your personal data, in accordance with KVKK Article 12:

  • Transport security: All client–server communication is encrypted with TLS (HTTPS/WSS).
  • Access control: Supabase Row Level Security (RLS) policies ensure that each user can only access their own data.
  • Password security: Passwords are never stored in plaintext; industry-standard hashing algorithms are used.
  • Error monitoring configuration: Crash reports forwarded to Sentry are configured to minimise the inclusion of sensitive data.
  • Database access: Access to the production database is restricted to authorised personnel only.

No system is 100% secure. If you discover a security vulnerability, please report it responsibly to b.cihancengiz@gmail.com.


10. Changes to This Policy

This Privacy Policy may be updated from time to time. When material changes are made:

  • An in-app notification will be displayed to users.
  • The "Last Updated" date at the top of this Policy will be revised.

Continued use of the App after a change takes effect constitutes acceptance of the updated Policy. If you do not accept the changes, you may delete your account.


11. Effective Date

This Privacy Policy first entered into force on 23 May 2026 and was updated on 19 July 2026 to reflect the removal of Firebase Analytics and its replacement with a first-party, consent-based usage-statistics system operated on Patify's own infrastructure. It was updated on 9 August 2026 to reflect a consent-based Meta (Facebook/Instagram) advertising-measurement integration used to measure the effectiveness of advertising campaigns.


12. Contact

For any questions, requests, or complaints regarding your personal data:

Email: b.cihancengiz@gmail.com

To exercise your rights under KVKK, please send an email with the subject line "KVKK / Data Subject Request". Including your full name and the email address registered to your account will help us process your request efficiently.

If you are not satisfied with our response, you have the right to lodge a complaint with:

  • Turkey: Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu — KVKK), https://www.kvkk.gov.tr
  • EU/EEA residents: The supervisory authority in your country of residence.