← Zaman Yolcusu · Türkçe sürüm
Privacy Policy
Last updated: September 13, 2026
Zaman Yolcusu ("the App") is developed by Dode Yazılım. This policy explains which personal data is processed when you use the App, for what purpose and with whom it is shared. It serves as the notice required under the Turkish Personal Data Protection Law (KVKK) and Article 13 GDPR.
Data we collect
- Photos: The photo you upload (a selfie or a family/group photo) is used only to generate the AI transformation you request. Photos and generated images are transmitted over encrypted connections, stored in private storage, and automatically deleted within 30 days.
- Your written description: The short text you write to create your own theme is sent to the AI provider to generate the image and is deleted together with the generation record within 30 days.
- Account information: The App can be used without signing in, with an anonymous identity. To buy credits or protect your account you can use Sign in with Apple, Sign in with Google or email. In that case your email address and any name shared by the provider (and, for Google sign-in, the link to your Google profile photo) are stored by our sign-in infrastructure; we do not show them in the app or send them to AI providers. For email sign-in we send a one-time code to verify the address. We never send marketing email. No phone number is collected.
- Purchase information: Credit pack purchases are processed by the App Store / Google Play and RevenueCat. We never access your payment card details.
- Content reports: When you report a result, we record the reason, the ID of the generation, and your account ID. We review reports within 24 hours; the reported image is hidden from your gallery in the meantime.
- Rejected requests: When a request is rejected under our content rules, we record your account ID, the time and the rejection category (description, photo or result) to prevent abuse and enforce the rules. The description text and the photo are not added to this record. These records are kept for up to 180 days and deleted immediately if you delete your account.
- Usage analytics: Pseudonymous product events linked to your account ID (PostHog, EU region). IP addresses are not stored and no location is derived. No advertising tracking, no IDFA, no behavioural profiling.
- Crash reports: Technical crash data for debugging (Sentry, EU region).
- Device identifier: Your device's vendor-provided identifier is stored to measure abuse of account sign-ups. It is never used for advertising, never shared with third parties, and never used for behavioural tracking.
How data is processed
What data is sent, to whom, and why: The photo you choose and the theme you select or the description you write are sent over an encrypted connection, solely to generate the image you requested and to check it against the content rules, to the following AI providers: OpenAI (image generation, content moderation and quality checks) and fal.ai (alternative image generation provider). Your name, email address and identity data are not sent to these services.
Content and quality checks: Before and after generation, the photo, the description and the generated image are checked automatically: compliance with the content rules, how many people are in the photo, whether a minor appears (only to apply stricter content rules; no age or identity record is kept), and whether the same people are preserved in the result. These checks are not identity recognition; they do not identify anyone and do not create or store face templates or biometric data.
Human review: Reported content, or content suspected of breaking the rules, may be reviewed by authorised staff solely for moderation and enforcement. It is not copied or used for any other purpose.
Your permission is obtained before sending: Before your photo is sent to an AI provider for the first time, the app clearly states in-app what will be sent, to whom, and why, and asks for your explicit consent. If you do not consent, your photo and description are never sent to these services. If other people appear in the photo, you confirm that you have their permission.
Provider obligations: Under these providers' API policies, submitted content is not used to train models; providers may retain content briefly to monitor abuse (up to 30 days for OpenAI). Your photo is never used for advertising or behavioural tracking. App data is stored on Supabase infrastructure (EU region).
Legal bases
- Performance of a contract (GDPR Art. 6(1)(b), KVKK Art. 5/2-c): generating the images you request, managing credits, account and purchases.
- Explicit consent (GDPR Art. 6(1)(a) and Art. 49(1)(a), KVKK Art. 5/1 and 9): transferring your photo and description to AI providers outside the EU/Türkiye. You can withdraw consent at any time; new generations are then not possible.
- Legitimate interests (GDPR Art. 6(1)(f), KVKK Art. 5/2-f): content safety, abuse prevention, debugging and product analytics.
- Legal obligation (GDPR Art. 6(1)(c), KVKK Art. 5/2-ç): legally required reports to competent authorities.
International transfers
OpenAI and fal.ai (USA) process data for image generation and content checks; RevenueCat (USA) for purchase validation. The transfer of your photo and description abroad is based on the explicit consent we obtain in the app; data processing agreements and standard contractual clauses apply with these providers. App data, analytics and crash reports are kept in the EU region.
Data sharing
Your data is never sold or shared for marketing. It is shared only with the service providers listed above, to the minimum extent required to operate the service, and with competent authorities where required by law.
Retention and deletion
Photos, generated images and descriptions are automatically deleted within 30 days. You can delete your account and app data (including records of rejected requests) in Profile → Delete my data; any email address you linked is deleted with it and, if you used Sign in with Apple, the app's authorisation on Apple's side is revoked. You can also remove that connection on your iPhone under Settings → Apple Account → Sign in with Apple. If you use the same sign-in account in another Dode Yazılım app, only this app's data is deleted and your shared sign-in identity is kept for that app. Unused credits are lost when the account is deleted. You can get a copy of your data (including the descriptions you wrote) with Download my data. For earlier deletion requests, contact us below; requests are fulfilled within 30 days.
Children's privacy
The App is not directed at children under 13 and does not knowingly collect account data from children. A parent may upload a family photo that includes their child; under the Terms of Use such photos may only be used for innocent, fully clothed scenes, and stricter content rules apply automatically when a child appears in the photo.
Your rights (GDPR / KVKK)
You have the right to access, rectify and delete your data, to object to or restrict processing, to data portability, to learn which third parties receive your data, and to withdraw consent. You may lodge a complaint with your local data protection authority. Contact: [email protected]
Contact
Data controller: Dode Yazılım · [email protected]