Gistleaf
Gistleaf

Privacy Policy

Gistleaf

Effective date: 21 September 2026

This Policy sets out the categories of personal data processed through the Gistleaf mobile application, the purposes and legal bases of that processing, the recipients to whom data is transferred, retention periods, and the rights of data subjects.

1. Controller

The Gistleaf application (“the Application”) is published and operated by Ailancer, established in the Republic of Türkiye (“the Controller”, “we”). The Controller is the data controller within the meaning of Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”) and of Regulation (EU) 2016/679 (“GDPR”).

All requests and notices under this Policy are to be addressed to dev@ailancer.com.

2. Scope

This Policy applies to personal data processed through the Application. It does not apply to the practices of the App Store or of websites reached from links displayed in the Application, which are governed by their own privacy notices.

3. Categories of personal data and purposes of processing

3.1 Account data. Use of the Application requires an account. The email address and the user identifier assigned by the service are processed in order to operate the account, to apply the monthly allowance of Section 3.4 to the account, and to make subscription status and, where enabled, backed-up notes available across the User's devices. Authentication is performed by Supabase on the Controller's behalf. Where the User signs in with Apple or Google, the identifier the provider assigns to the User is processed for the same purpose; where Sign in with Apple is used with the “Hide My Email” option, the Controller receives only the relay address assigned by Apple. Google additionally returns the User's display name and picture address, which the Application neither uses nor displays.

3.2 Recordings. A recording is transcribed on the User's device by the speech recognition of the operating system, set to on-device recognition only. Audio is neither written to storage nor transmitted to the Controller or to any other recipient, and no longer exists once the transcription is complete.

3.3 Notes and highlights. The text of notes, the highlights kept, skipped, pinned or written by the User, and their times and states are stored on the User's device. They are transmitted to and stored by the Controller only where the User has enabled the Back up and sync function, for the purpose of restoring the notes on a new device and keeping them in step between the User's devices. Stored notes are encrypted at rest by the storage provider; they are not end-to-end encrypted and can be read by the service.

3.4 Text submitted for highlights. Where the User has agreed within the Application to AI highlights and the function is switched on, the text of a note is transmitted through the Controller's server to the processor identified in Section 5, for the sole purpose of proposing highlights from it. The Controller's server does not store the text. A count of the extractions performed per account and calendar month is processed in order to apply the allowance of the User's plan.

3.5 Subscription status. Where the User purchases Premium, the state and expiry of the subscription and a record of the store events concerning it are processed, bound to the user identifier, in order to apply the allowance purchased and to comply with accounting obligations. Payment instrument details and receipts remain with Apple and are not disclosed to the Controller.

3.6 Data retained on the device only. The content shown by the Home Screen widgets, the widget and AI highlight preferences, the record of the consent given under Section 5, the sync switch, and a random identifier the Application generates for this installation for the purpose of synchronisation are stored on the User's device. The identifier is transmitted only as part of a synchronisation the User has enabled and is not a device identifier of the operating system.

4. Legal bases

  • Explicit consent — KVKK Art. 5(1); GDPR Art. 6(1)(a): the transfer of note text to the processor identified in Section 5. Consent may be withdrawn at any time in accordance with Section 5.3.
  • Performance of a contract — KVKK Art. 5(2)(c); GDPR Art. 6(1)(b): operation of the account, storage and synchronisation of notes where enabled, and delivery of the subscription.
  • Legitimate interests — GDPR Art. 6(1)(f): application of the monthly allowance and of rate limits, prevention of abuse, and security of the service.
  • Compliance with a legal obligation — KVKK Art. 5(2)(a); GDPR Art. 6(1)(c): retention of accounting records.

5. Transfer of note text to a processor

5.1 The proposal of highlights cannot be performed on the device alone. The text of a note is transferred to OpenAI, acting on the Controller's instructions and for the sole purpose of proposing highlights from that text. Data submitted through OpenAI's application programming interface is not used to train its models and is not retained by it beyond the period its terms provide for abuse monitoring. Recordings are never transferred. The Controller's server does not store the text and retains only the count referred to in Section 3.4.

5.2 No transfer under this Section takes place before the User has given explicit consent within the Application, and none takes place while the AI highlights function is switched off. Note text is not used for advertising, profiling or the training of any model, is not sold, and is not disclosed to any recipient other than the one identified in this Section.

5.3 Consent may be withdrawn at any time by switching AI highlights off under Account in the Application. Withdrawal takes effect immediately for every subsequent note. It does not affect the lawfulness of processing carried out before it and does not delete existing notes or highlights.

6. Other recipients

  • Supabase — database and authentication, and storage of notes where Back up and sync is enabled.
  • RevenueCat — verification and maintenance of subscription status; receives the user identifier and the store's subscription events.
  • Apple — processing of payments through the App Store, and Sign in with Apple where the User chooses it.
  • Google — Sign in with Google where the User chooses it.

7. International transfers

The processors identified in Sections 5 and 6 may process personal data outside the User's country of residence, including in the United States. Transfers from the European Economic Area or from Türkiye are carried out on the basis of the safeguards made available by those providers, including the Standard Contractual Clauses adopted by the European Commission.

8. Retention

Account data and subscription status are retained until the account is deleted in accordance with Section 9. Notes and highlights stored under Section 3.3 are retained until deleted by the User; a deleted note or highlight keeps no text on the Controller's systems from the moment of deletion, and the record of its deletion is removed after 90 days. The provider's backups of the database age out within 30 days. The counts referred to in Section 3.4 are retained for the calendar month to which they relate and deleted with the account. Records referred to in Section 3.5 are retained for the periods prescribed by applicable accounting and limitation legislation.

9. Deletion

9.1 Deletion of account. The Delete account function, under Account in the Application, is confirmed by a fresh sign-in and is carried out at once: the sign-in, the account, the counts, the subscription status and every note and highlight stored by the Controller are deleted, the Application's authorisations are revoked at Apple or Google where the User signed in with them, the subscription record held by RevenueCat is deleted, and the notes held on the device are removed. Only a ledger entry consisting of the user identifier and the dates of the request and its completion is retained, for 90 days, in order to answer questions about the deletion; it contains no email address. Deletion of an account is irreversible.

9.2 Deletion of an account does not cancel a subscription held with Apple; the User cancels it under Settings → Apple ID → Subscriptions.

9.3 A deletion request may alternatively be submitted to dev@ailancer.com from the email address associated with the account.

10. Age requirement

The Application is not intended for children under the age of 13. Where the Controller becomes aware that personal data of a child has been processed, that data will be deleted without undue delay.

11. Data not collected

The Application contains no analytics, advertising or third-party tracking software, does not use the advertising identifier, and does not track users across other applications or websites. It does not request access to location, contacts, calendar, photos or health data. The microphone and speech recognition permissions it requests serve recording and on-device transcription only; audio is not stored or transmitted.

12. Security

Notes on the device are held in the Application's private storage under the operating system's data protection, and the session in the device keychain. Notes stored by the Controller are encrypted at rest by the storage provider. Every request concerning an account is authenticated with the account's session; credentials for the processors identified in Sections 5 and 6 are held on the server and are not present in the Application.

13. Rights of the data subject

Under KVKK Art. 11 and GDPR Arts. 15 to 22, the User has the right to obtain confirmation as to whether personal data concerning them is processed, to access that data, to request its rectification or erasure, to object to processing, to request restriction of processing, and to receive the data in a portable format. Rectification and erasure may be exercised directly within the Application. Other requests are to be addressed to dev@ailancer.com and will be answered within thirty days.

The User also has the right to lodge a complaint with the Turkish Personal Data Protection Authority or with the supervisory authority of their place of residence. The Controller does not sell personal information within the meaning of the California Consumer Privacy Act.

14. Amendment

This Policy may be amended. The amended version is published on this page bearing a new effective date. Where an amendment materially alters the processing of note text, consent is requested again in accordance with Section 5.2.

15. Contact

Ailancer — dev@ailancer.com