Back to legal documents

Data Protection Notice

Version 2

Last updated: 2026-07-20

This is a working draft. Before launch, a lawyer must verify the controller's full identity, address, transfer contracts and retention/deletion records.

1. Controller and contact

The controller for the Things to Say service is the individual or legal entity operating it. Contact: thingstosayapp@gmail.com. The controller's full legal identity and service address will be stated clearly in the final version. This notice is prepared for the Turkish Personal Data Protection Law (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR).

2. Categories of data

We may process:

  • **Account and identity data:** name, email address, email-verification state, sign-in method (email, Google or Apple), provider account subject identifier, language and timezone preference, and profile photo.
  • **Security and transaction records:** IP address or region/timezone derived from it, secure hashes of sessions and refresh tokens, verification and password-reset records, account status, and security or abuse records.
  • **Message and recipient data:** message title, recipient name, email/phone number, chosen channel, delivery time and timezone, delivery status, recurring settings and well-being check-in settings. Message body and media are encrypted on the device and sent to the server in encrypted form; they are not stored as plaintext in ordinary server operation.
  • **Encrypted content and technical key records:** encrypted message/media objects, wrapped message key, access-token hash and delivery-link records. Key material is never written to logs.
  • **Notification and device data:** push-device token, OneSignal user/device identifier, notification preferences and read state.
  • **Purchase and credit data:** Apple/Google transaction identifiers, product identifier, purchase type, subscription state, period dates, credit ledger entries and refund state. The Provider does not store your card number or payment-account details.
  • **Support records:** support, security or data-rights requests and related correspondence.

Encryption means that an authorised delivery workflow must unwrap a message key at delivery time and the recipient's browser must open the content. The service therefore does not promise strict end-to-end encryption or that no system component can ever unwrap a key.

3. Where data comes from

We usually collect account and message data from you. When you sign in with Google or Apple, the provider may send the identity data needed to verify the sign-in. Recipient contact details are usually entered by the sender. Before entering another person's data, the sender must have the necessary notice and lawful basis; recipients may also exercise their rights directly with us.

4. Purposes and legal bases

We process data to:

  • create accounts, verify identity and maintain sign-in: entering into or performing the contract;
  • schedule, encrypt and deliver messages, create recipient links and show delivery status: performing the contract;
  • verify credits, subscriptions, purchases and refunds: performing the contract and complying with legal obligations;
  • secure the service, prevent abuse, fraud and unauthorised access, and investigate incidents: legal obligations and, where necessary, legitimate interests;
  • keep accounting, financial, official-request and dispute records: legal obligations and the establishment, exercise or defence of legal claims;
  • operate the service, fix faults and maintain reliability: performing the contract and legitimate interests;
  • send optional marketing or run non-essential measurement only where a separate consent is required and obtained.

Consent does not replace a contract or legal obligation as the basis for processing that is necessary for the service, and unnecessary processing will not be made a condition of using the service. We do not currently profile users for marketing or personalised advertising.

5. Recipients and service providers

Where necessary for the stated purposes, data may be shared with Cloudflare Email Sending for email; Twilio for SMS and WhatsApp; OneSignal for push notifications; Cloudflare R2 and related Cloudflare services for encrypted media storage and infrastructure; a separate key-service Worker for key management; ip-api for region/timezone detection; Google and Apple for social sign-in; Apple App Store and Google Play for in-app purchase validation; and hosting, database, queue, security, backup and professional-adviser providers.

Transfers are limited to what the purpose requires and are subject to contractual and technical safeguards. International transfers must not be made without an applicable safeguard or exception under KVKK Article 9 and related rules. The exact transfer mechanism for each provider, including standard contracts, consent or another lawful basis where relevant, must be confirmed in the transfer inventory and provider agreements before launch.

6. Retention

  • Account and service records are kept while the account is active and for as long as needed to provide the service.
  • Scheduled and delivered messages may be kept until deleted by the sender or authorised recipient, or until account deletion and the erasure process complete. Unless the product's retention policy says otherwise, delivered messages may be retained indefinitely; this period must be confirmed against the necessity and deletion policy.
  • Purchase, credit, accounting, security, audit and dispute records are kept for the period required by law or needed to protect a right.
  • Password-reset and verification records are deleted when their short-term purpose ends.
  • Account deletion starts the erasure process. Records that must be retained are kept only for the required period and, where possible, in a limited or de-identified form. Consent records may survive as a limited audit record proving which document version was accepted and when.

7. Security

Message and media are encrypted on the device with AES-256-GCM. The server stores encrypted content and a wrapped message key; the master key is held behind a separate key-service Worker boundary. The fragment key in a delivery link is not sent to the API; the recipient's browser performs decryption. Logs do not contain message bodies, media, key material, access tokens or full recipient addresses. No technical measure is an absolute security guarantee, and users must protect their accounts and access links.

8. Your rights

Under KVKK Article 11, you may ask whether your personal data is processed, request information about the processing, its purposes and recipients, correction of inaccurate or incomplete data, deletion or destruction where the legal conditions apply, notice of corrections or deletion to recipients, object to an automated analysis, and claim compensation where you suffer damage.

Where GDPR applies, you may also have rights of access, rectification, erasure, restriction, portability and objection to processing based on legitimate interests. Where processing is based on consent, you may withdraw it; withdrawal does not affect processing that was lawful before withdrawal.

Send requests to thingstosayapp@gmail.com with enough information to verify your identity. KVKK requests are answered within the statutory period and, as a rule, no later than 30 days. GDPR requests are generally answered within one month; we will notify you if a lawful extension is needed because of complexity or volume. You may complain to the Turkish DPA (KVKK) or the competent supervisory authority where GDPR applies.

9. Children and automated decisions

The service is not directed at people under 18. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects. Rate limits, account suspensions and access controls used for security are operational safeguards and do not remove any rights provided by law.

10. Updates and contact

This notice may change when our processing or the law changes. The current version is published in the app and on the website; material changes will be notified or submitted for renewed acceptance where required by law. Before launch, the controller's final identity and address, retention/deletion policy and transfer inventory must be made consistent with this notice.

This is a working draft and requires KVKK/GDPR review and the controller's real legal identity and address.

Data Protection Notice — Things to Say