This Policy sets out the categories of personal data processed through the Gistleaf mobile application, the purposes and legal bases of that processing, the recipients to whom data is transferred, retention periods, and the rights of data subjects.
1. Controller
The Gistleaf application (“the Application”) is published and operated by Ailancer, established in the Republic of Türkiye (“the Controller”, “we”). The Controller is the data controller within the meaning of Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”) and of Regulation (EU) 2016/679 (“GDPR”).
All requests and notices under this Policy are to be addressed to dev@ailancer.com.
2. Scope
This Policy applies to personal data processed through the Application. It does not apply to the practices of the App Store or of websites reached from links displayed in the Application, which are governed by their own privacy notices.
3. Categories of personal data and purposes of processing
3.1 Account data. Use of the Application requires an account. The email address and the user identifier assigned by the service are processed in order to operate the account, to apply the monthly allowance of Section 3.4 to the account, and to make subscription status and, where enabled, backed-up notes available across the User's devices. Authentication is performed by Supabase on the Controller's behalf. Where the User signs in with Apple or Google, the identifier the provider assigns to the User is processed for the same purpose; where Sign in with Apple is used with the “Hide My Email” option, the Controller receives only the relay address assigned by Apple. Google additionally returns the User's display name and picture address, which the Application neither uses nor displays.
3.2 Recordings. A recording is transcribed on the User's device by the speech recognition of the operating system, set to on-device recognition only. Audio is neither written to storage nor transmitted to the Controller or to any other recipient, and no longer exists once the transcription is complete.
3.3 Notes and highlights. The text of notes, the highlights kept, skipped, pinned or written by the User, and their times and states are stored on the User's device. They are transmitted to and stored by the Controller only where the User has enabled the Back up and sync function, for the purpose of restoring the notes on a new device and keeping them in step between the User's devices. Stored notes are encrypted at rest by the storage provider; they are not end-to-end encrypted and can be read by the service.
3.4 Text submitted for highlights. Where the User has agreed within the Application to AI highlights and the function is switched on, the text of a note is transmitted through the Controller's server to the processor identified in Section 5, for the sole purpose of proposing highlights from it. The Controller's server does not store the text. A count of the extractions performed per account and calendar month is processed in order to apply the allowance of the User's plan.
3.5 Subscription status. Where the User purchases Premium, the state and expiry of the subscription and a record of the store events concerning it are processed, bound to the user identifier, in order to apply the allowance purchased and to comply with accounting obligations. Payment instrument details and receipts remain with Apple and are not disclosed to the Controller.
3.6 Data retained on the device only. The content shown by the Home Screen widgets, the widget and AI highlight preferences, the record of the consent given under Section 5, the sync switch, and a random identifier the Application generates for this installation for the purpose of synchronisation are stored on the User's device. The identifier is transmitted only as part of a synchronisation the User has enabled and is not a device identifier of the operating system.
4. Legal bases
- Explicit consent — KVKK Art. 5(1); GDPR Art. 6(1)(a): the transfer of note text to the processor identified in Section 5. Consent may be withdrawn at any time in accordance with Section 5.3.
- Performance of a contract — KVKK Art. 5(2)(c); GDPR Art. 6(1)(b): operation of the account, storage and synchronisation of notes where enabled, and delivery of the subscription.
- Legitimate interests — GDPR Art. 6(1)(f): application of the monthly allowance and of rate limits, prevention of abuse, and security of the service.
- Compliance with a legal obligation — KVKK Art. 5(2)(a); GDPR Art. 6(1)(c): retention of accounting records.
5. Transfer of note text to a processor
5.1 The proposal of highlights cannot be performed on the device alone. The text of a note is transferred to OpenAI, acting on the Controller's instructions and for the sole purpose of proposing highlights from that text. Data submitted through OpenAI's application programming interface is not used to train its models and is not retained by it beyond the period its terms provide for abuse monitoring. Recordings are never transferred. The Controller's server does not store the text and retains only the count referred to in Section 3.4.
5.2 No transfer under this Section takes place before the User has given explicit consent within the Application, and none takes place while the AI highlights function is switched off. Note text is not used for advertising, profiling or the training of any model, is not sold, and is not disclosed to any recipient other than the one identified in this Section.
5.3 Consent may be withdrawn at any time by switching AI highlights off under Account in the Application. Withdrawal takes effect immediately for every subsequent note. It does not affect the lawfulness of processing carried out before it and does not delete existing notes or highlights.
6. Other recipients
- Supabase — database and authentication, and storage of notes where Back up and sync is enabled.
- RevenueCat — verification and maintenance of subscription status; receives the user identifier and the store's subscription events.
- Apple — processing of payments through the App Store, and Sign in with Apple where the User chooses it.
- Google — Sign in with Google where the User chooses it.
7. International transfers
The processors identified in Sections 5 and 6 may process personal data outside the User's country of residence, including in the United States. Transfers from the European Economic Area or from Türkiye are carried out on the basis of the safeguards made available by those providers, including the Standard Contractual Clauses adopted by the European Commission.
8. Retention
Account data and subscription status are retained until the account is deleted in accordance with Section 9. Notes and highlights stored under Section 3.3 are retained until deleted by the User; a deleted note or highlight keeps no text on the Controller's systems from the moment of deletion, and the record of its deletion is removed after 90 days. The provider's backups of the database age out within 30 days. The counts referred to in Section 3.4 are retained for the calendar month to which they relate and deleted with the account. Records referred to in Section 3.5 are retained for the periods prescribed by applicable accounting and limitation legislation.
9. Deletion
9.1 Deletion of account. The Delete account function, under Account in the Application, is confirmed by a fresh sign-in and is carried out at once: the sign-in, the account, the counts, the subscription status and every note and highlight stored by the Controller are deleted, the Application's authorisations are revoked at Apple or Google where the User signed in with them, the subscription record held by RevenueCat is deleted, and the notes held on the device are removed. Only a ledger entry consisting of the user identifier and the dates of the request and its completion is retained, for 90 days, in order to answer questions about the deletion; it contains no email address. Deletion of an account is irreversible.
9.2 Deletion of an account does not cancel a subscription held with Apple; the User cancels it under Settings → Apple ID → Subscriptions.
9.3 A deletion request may alternatively be submitted to dev@ailancer.com from the email address associated with the account.
10. Age requirement
The Application is not intended for children under the age of 13. Where the Controller becomes aware that personal data of a child has been processed, that data will be deleted without undue delay.
11. Data not collected
The Application contains no analytics, advertising or third-party tracking software, does not use the advertising identifier, and does not track users across other applications or websites. It does not request access to location, contacts, calendar, photos or health data. The microphone and speech recognition permissions it requests serve recording and on-device transcription only; audio is not stored or transmitted.
12. Security
Notes on the device are held in the Application's private storage under the operating system's data protection, and the session in the device keychain. Notes stored by the Controller are encrypted at rest by the storage provider. Every request concerning an account is authenticated with the account's session; credentials for the processors identified in Sections 5 and 6 are held on the server and are not present in the Application.
13. Rights of the data subject
Under KVKK Art. 11 and GDPR Arts. 15 to 22, the User has the right to obtain confirmation as to whether personal data concerning them is processed, to access that data, to request its rectification or erasure, to object to processing, to request restriction of processing, and to receive the data in a portable format. Rectification and erasure may be exercised directly within the Application. Other requests are to be addressed to dev@ailancer.com and will be answered within thirty days.
The User also has the right to lodge a complaint with the Turkish Personal Data Protection Authority or with the supervisory authority of their place of residence. The Controller does not sell personal information within the meaning of the California Consumer Privacy Act.
14. Amendment
This Policy may be amended. The amended version is published on this page bearing a new effective date. Where an amendment materially alters the processing of note text, consent is requested again in accordance with Section 5.2.
15. Contact
Ailancer — dev@ailancer.com
Bu Politika, Gistleaf mobil uygulaması aracılığıyla işlenen kişisel veri kategorilerini, işleme amaçlarını ve hukuki sebeplerini, verilerin aktarıldığı tarafları, saklama sürelerini ve ilgili kişinin haklarını düzenler.
1. Veri sorumlusu
Gistleaf uygulaması (“Uygulama”), Türkiye Cumhuriyeti'nde yerleşik Ailancer (“Veri Sorumlusu”, “biz”) tarafından yayımlanmakta ve işletilmektedir. Veri Sorumlusu, 6698 sayılı Kişisel Verilerin Korunması Kanunu (“KVKK”) ve (AB) 2016/679 sayılı Genel Veri Koruma Tüzüğü (“GDPR”) anlamında veri sorumlusudur.
Bu Politika kapsamındaki tüm başvuru ve bildirimler dev@ailancer.com adresine yapılır.
2. Kapsam
Bu Politika, Uygulama aracılığıyla işlenen kişisel verilere uygulanır. App Store'un ve Uygulamada gösterilen bağlantılar üzerinden erişilen internet sitelerinin uygulamalarını kapsamaz; bunlar kendi aydınlatma metinlerine tabidir.
3. İşlenen kişisel veri kategorileri ve işleme amaçları
3.1 Hesap verileri. Uygulamanın kullanımı bir hesap gerektirir. E-posta adresi ve hizmetin atadığı kullanıcı kimliği; hesabın işletilmesi, 3.4 maddesindeki aylık hakkın hesaba uygulanması ile abonelik durumunun ve, açılmışsa, yedeklenen notların kullanıcının cihazları arasında erişilebilir kılınması amacıyla işlenir. Kimlik doğrulama, Veri Sorumlusu adına Supabase tarafından gerçekleştirilir. Kullanıcının Apple ya da Google ile giriş yapması hâlinde sağlayıcının kullanıcıya atadığı kimlik aynı amaçla işlenir; Apple ile Giriş'in “E-postamı Gizle” seçeneğiyle kullanılması hâlinde Veri Sorumlusuna yalnızca Apple tarafından atanan aktarma adresi ulaşır. Google ayrıca kullanıcının görünen adını ve profil görseli adresini iletir; Uygulama bunları kullanmaz ve göstermez.
3.2 Kayıtlar. Bir kayıt, işletim sisteminin yalnızca cihaz üzerinde tanıma olarak ayarlanmış konuşma tanımasıyla kullanıcının cihazında yazıya dökülür. Ses ne depoya yazılır ne de Veri Sorumlusuna ya da başka bir alıcıya iletilir; yazıya dökme tamamlandığında artık mevcut değildir.
3.3 Notlar ve öne çıkanlar. Notların metni, kullanıcının tuttuğu, geçtiği, sabitlediği ya da yazdığı öne çıkanlar ile bunların zamanları ve durumları kullanıcının cihazında saklanır. Bunlar yalnızca kullanıcının Yedekleme ve eşitleme işlevini açması hâlinde, notların yeni bir cihazda geri getirilmesi ve kullanıcının cihazları arasında aynı tutulması amacıyla Veri Sorumlusuna iletilir ve onun tarafından saklanır. Saklanan notlar depolama sağlayıcısı tarafından duran veri olarak şifrelenir; uçtan uca şifreli değildir ve hizmet tarafından okunabilir.
3.4 Öne çıkanlar için gönderilen metin. Kullanıcının Uygulama içinde yapay zekâ ile öne çıkanlara onay vermiş olması ve işlevin açık olması hâlinde, bir notun metni yalnızca ondan öne çıkanlar önerilmesi amacıyla Veri Sorumlusunun sunucusu üzerinden 5. maddede belirtilen işleyene iletilir. Veri Sorumlusunun sunucusu metni saklamaz. Hesap ve takvim ayı başına gerçekleştirilen çıkarım sayısı, kullanıcının planına ait hakkın uygulanması amacıyla işlenir.
3.5 Abonelik durumu. Kullanıcının Premium satın alması hâlinde aboneliğin durumu ve bitiş tarihi ile buna ilişkin mağaza olaylarının kaydı; satın alınan hakkın uygulanması ve muhasebe yükümlülüklerinin yerine getirilmesi amacıyla, kullanıcı kimliğine bağlı olarak işlenir. Ödeme aracına ilişkin bilgiler ve fişler Apple'da kalır; Veri Sorumlusuna açıklanmaz.
3.6 Yalnızca cihazda tutulan veriler. Ana Ekran widget'larının gösterdiği içerik, widget ve yapay zekâ ile öne çıkanlar tercihleri, 5. madde uyarınca verilen rızanın kaydı, eşitleme anahtarı ve Uygulamanın eşitleme amacıyla bu kurulum için ürettiği rastgele bir tanımlayıcı kullanıcının cihazında saklanır. Tanımlayıcı yalnızca kullanıcının açtığı bir eşitlemenin parçası olarak iletilir ve işletim sistemine ait bir cihaz tanımlayıcısı değildir.
4. Hukuki sebepler
- Açık rıza — KVKK m. 5/1; GDPR m. 6(1)(a): not metninin 5. maddede belirtilen işleyene aktarılması. Rıza, 5.3 maddesi uyarınca her zaman geri alınabilir.
- Sözleşmenin ifası — KVKK m. 5/2-c; GDPR m. 6(1)(b): hesabın işletilmesi, açılmışsa notların saklanması ve eşitlenmesi, aboneliğin sunulması.
- Meşru menfaat — GDPR m. 6(1)(f): aylık hakkın ve hız sınırlarının uygulanması, kötüye kullanımın önlenmesi ve hizmet güvenliği.
- Hukuki yükümlülük — KVKK m. 5/2-a; GDPR m. 6(1)(c): muhasebe kayıtlarının saklanması.
5. Not metninin işleyene aktarılması
5.1 Öne çıkanların önerilmesi yalnızca cihaz üzerinde yerine getirilemez. Bir notun metni, Veri Sorumlusunun talimatı doğrultusunda ve yalnızca o metinden öne çıkanlar önerilmesi amacıyla hareket eden OpenAI'a aktarılır. OpenAI'ın uygulama programlama arayüzü üzerinden iletilen veriler anılan sağlayıcının modellerinin eğitiminde kullanılmaz ve koşullarında kötüye kullanım denetimi için öngörülen sürenin ötesinde saklanmaz. Kayıtlar hiçbir zaman aktarılmaz. Veri Sorumlusunun sunucusu metni saklamaz; yalnızca 3.4 maddesinde belirtilen sayacı tutar.
5.2 Bu madde kapsamındaki aktarım, kullanıcının Uygulama içinde açık rızasını vermesinden önce gerçekleştirilmez ve yapay zekâ ile öne çıkanlar işlevi kapalıyken hiçbir aktarım yapılmaz. Not metni reklam, profilleme veya herhangi bir modelin eğitimi amacıyla kullanılmaz, satılmaz ve bu maddede belirtilen dışında hiçbir alıcıya açıklanmaz.
5.3 Rıza, Uygulamada Hesap altından yapay zekâ ile öne çıkanlar kapatılarak her zaman geri alınabilir. Geri alma, sonraki her not bakımından derhâl hüküm doğurur. Öncesinde gerçekleştirilen işlemenin hukuka uygunluğunu etkilemez ve mevcut notları ya da öne çıkanları silmez.
6. Diğer alıcılar
- Supabase — veri tabanı ve kimlik doğrulama; Yedekleme ve eşitleme açıksa notların depolanması.
- RevenueCat — abonelik durumunun doğrulanması ve sürdürülmesi; kullanıcı kimliğini ve mağazanın abonelik olaylarını alır.
- Apple — App Store üzerinden ödemelerin işlenmesi ve kullanıcının seçmesi hâlinde Apple ile Giriş.
- Google — kullanıcının seçmesi hâlinde Google ile Giriş.
7. Yurt dışına aktarım
5. ve 6. maddelerde belirtilen işleyenler, kişisel verileri kullanıcının yerleşik olduğu ülke dışında, Amerika Birleşik Devletleri dâhil olmak üzere işleyebilir. Avrupa Ekonomik Alanı'ndan veya Türkiye'den yapılan aktarımlar, anılan sağlayıcıların sunduğu güvenceler ile Avrupa Komisyonu tarafından kabul edilen Standart Sözleşme Maddeleri esas alınarak gerçekleştirilir.
8. Saklama süreleri
Hesap verileri ve abonelik durumu, hesap 9. madde uyarınca silinene kadar saklanır. 3.3 maddesi kapsamında saklanan notlar ve öne çıkanlar kullanıcı tarafından silinene kadar saklanır; silinen bir not ya da öne çıkan, silinme anından itibaren Veri Sorumlusunun sistemlerinde hiçbir metin bırakmaz ve silinme kaydı 90 gün sonra kaldırılır. Sağlayıcının veri tabanı yedekleri 30 gün içinde silinir. 3.4 maddesinde belirtilen sayaçlar ilgili oldukları takvim ayı boyunca saklanır ve hesapla birlikte silinir. 3.5 maddesinde belirtilen kayıtlar, ilgili muhasebe ve zamanaşımı mevzuatında öngörülen süreler boyunca saklanır.
9. Silme
9.1 Hesabın silinmesi. Uygulamada Hesap altındaki Hesabı sil işlevi yeni bir girişle onaylanır ve derhâl yerine getirilir: giriş, hesap, sayaçlar, abonelik durumu ve Veri Sorumlusunun sakladığı her not ve öne çıkan silinir; kullanıcı Apple ya da Google ile giriş yapmışsa Uygulamanın yetkileri o sağlayıcı nezdinde iptal edilir; RevenueCat'in tuttuğu abonelik kaydı silinir ve cihazdaki notlar kaldırılır. Yalnızca, silmeye ilişkin soruları yanıtlayabilmek amacıyla, kullanıcı kimliği ile talep ve tamamlanma tarihlerinden oluşan bir kayıt 90 gün tutulur; bu kayıt e-posta adresi içermez. Hesabın silinmesi geri alınamaz.
9.2 Hesabın silinmesi, Apple nezdindeki bir aboneliği iptal etmez; kullanıcı aboneliği Ayarlar → Apple Kimliği → Abonelikler altından iptal eder.
9.3 Silme talebi, hesapla ilişkili e-posta adresinden dev@ailancer.com adresine de iletilebilir.
10. Yaş şartı
Uygulama 13 yaşından küçükler için tasarlanmamıştır. Bir çocuğa ait kişisel verinin işlendiğinin öğrenilmesi hâlinde söz konusu veri gecikmeksizin silinir.
11. Toplanmayan veriler
Uygulamada analitik, reklam veya üçüncü taraf izleme yazılımı bulunmaz; reklam tanımlayıcısı kullanılmaz ve kullanıcılar başka uygulama veya internet sitelerinde izlenmez. Konum, kişiler, takvim, fotoğraflar ve sağlık verilerine erişim talep edilmez. Talep edilen mikrofon ve konuşma tanıma izinleri yalnızca kayıt ve cihazda yazıya dökme içindir; ses saklanmaz ve iletilmez.
12. Güvenlik
Cihazdaki notlar, işletim sisteminin veri koruması altında Uygulamanın özel depolamasında; oturum ise cihazın anahtar zincirinde tutulur. Veri Sorumlusunun sakladığı notlar depolama sağlayıcısı tarafından duran veri olarak şifrelenir. Bir hesaba ilişkin her talep hesabın oturumuyla doğrulanır; 5. ve 6. maddelerde belirtilen işleyenlere ait kimlik bilgileri sunucuda tutulur ve Uygulama içinde yer almaz.
13. İlgili kişinin hakları
KVKK m. 11 ile GDPR m. 15–22 uyarınca kullanıcı; kişisel verilerinin işlenip işlenmediğini öğrenme, bunlara erişme, düzeltilmesini veya silinmesini isteme, işlemeye itiraz etme, işlemenin kısıtlanmasını talep etme ve verilerini taşınabilir bir biçimde alma haklarına sahiptir. Düzeltme ve silme hakları doğrudan Uygulama içinden kullanılabilir. Diğer talepler dev@ailancer.com adresine iletilir ve otuz gün içinde sonuçlandırılır.
Kullanıcı ayrıca Kişisel Verileri Koruma Kurumu'na veya yerleşik olduğu ülkedeki denetim makamına şikâyette bulunma hakkına sahiptir. Veri Sorumlusu, California Tüketici Gizliliği Yasası anlamında kişisel bilgi satışı yapmaz.
14. Değişiklik
Bu Politika değiştirilebilir. Değiştirilmiş metin, yeni bir yürürlük tarihi taşıyacak şekilde bu sayfada yayımlanır. Değişikliğin not metninin işlenmesini esaslı olarak etkilemesi hâlinde 5.2 maddesi uyarınca rıza yeniden alınır.
15. İletişim
Ailancer — dev@ailancer.com