This Policy sets out the categories of personal data processed through the Ootry mobile application, the purposes and legal bases of that processing, the recipients to whom data is transferred, retention periods, and the rights of data subjects.
1. Controller
The Ootry application (“the Application”) is developed and operated by Ailancer, established in the Republic of Türkiye (“the Controller”, “we”). The Controller is the data controller within the meaning of Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”) and of Regulation (EU) 2016/679 (“GDPR”).
All requests and notices under this Policy are to be addressed to dev@ailancer.com.
2. Scope
This Policy applies to personal data processed through the Application. It does not apply to the practices of third-party stores or websites reached from links displayed in the Application, which are governed by their own privacy notices.
3. Categories of personal data and purposes of processing
3.1 Installation identifier and device key. On first launch the Application generates a random identifier and a secret device key, both held in the device keychain. The identifier is processed in order to associate user content and credit balance with a device before an account exists. The device key is not transmitted; the Controller stores only its SHA-256 digest, which is processed in order to verify that requests concerning a user's library originate from the device entitled to make them.
3.2 Account data. Where the User elects to create an account, the user identifier and email address are processed in order to operate the account and to make credits, purchases and library content available across the User's devices. Authentication is performed by Supabase on the Controller's behalf. Where Sign in with Apple is used with the “Hide My Email” option, the Controller receives only the relay address assigned by Apple.
3.3 Profile data. Name, date of birth, height, weight and profile image may be provided at the User's option. Date of birth is processed in order to verify the minimum age requirement under Section 10; height and weight are processed in order to adapt generated output to the User's proportions.
3.4 Image data. Photographs of the User saved for try-on, garment images added to the wardrobe, output generated by the Application, crops submitted for product search, and the profile image are processed in order to provide the functions requested by the User. Image data is held in private storage and is accessible only by means of signed links which expire within minutes. No permanent public address is created for any image.
3.5 Device name and push notification token. The device name configured in the operating system and a push notification token are processed in order to distinguish the User's devices from one another and to notify the User of the completion of a generation the User has initiated.
3.6 Transaction records. Records of credits granted and spent, of search operations and of subscription status are processed in order to deliver purchased services, to apply rate limits, to prevent abuse, and to comply with accounting obligations.
3.7 Data retained on the device only. Product search history, language selection, notification preferences, the record of consent given under Section 5, and any cropping or colour correction applied by the User to output are stored solely on the User's device and are not transmitted to the Controller.
4. Legal bases
- Explicit consent — KVKK Art. 5(1); GDPR Art. 6(1)(a): the transfer of image data to the providers identified in Section 5. Consent may be withdrawn at any time in accordance with Section 5.3.
- Performance of a contract — KVKK Art. 5(2)(c); GDPR Art. 6(1)(b): operation of the account, storage and synchronisation of library content, and delivery of subscriptions and credits.
- Legitimate interests — GDPR Art. 6(1)(f): application of rate limits, prevention of abuse, and security of the service.
- Compliance with a legal obligation — KVKK Art. 5(2)(a); GDPR Art. 6(1)(c): retention of accounting records.
5. Transfer of image data to processors
5.1 The generation and search functions cannot be performed on the device alone. Image data is transferred to the following processors, each acting on the Controller's instructions and for the stated purpose only:
- OpenAI — the User's photograph and the garment image, for the purpose of generating try-on output, applying a retouch selected by the User, and determining the category, colours and style of a garment. Data submitted through OpenAI's application programming interface is not used to train its models.
- SerpApi, which in turn queries Google Lens — the crop submitted for product search, for the purpose of returning visually similar products. Photographs of the User do not form part of a product search.
5.2 No transfer under this Section takes place before the User has given explicit consent within the Application. Image data is not used for advertising, profiling or the training of any model, is not sold, and is not disclosed to any recipient other than those identified in this Policy.
5.3 Consent may be withdrawn at any time under Profile → Privacy in the Application. Withdrawal takes effect immediately and disables the try-on and product search functions. Withdrawal does not affect the lawfulness of processing carried out before it, and does not delete existing library content.
6. Other recipients
- Supabase — database, authentication and image storage.
- RevenueCat — verification and maintenance of subscription status; receives the installation identifier or, following sign-in, the user identifier.
- Apple or Google — processing of payments, according to the store from which the Application was obtained. Payment instrument details are not disclosed to the Controller.
- Sovrn or Skimlinks — where the User opens a shop from a search result, the destination address and the installation identifier are transmitted to the affiliate network for the sole purpose of attributing a click to a transaction. Name, email address and image data are not transmitted.
7. International transfers
The processors identified in Sections 5 and 6 may process personal data outside the User's country of residence, including in the United States. Transfers from the European Economic Area or from Türkiye are carried out on the basis of the safeguards made available by those providers, including the Standard Contractual Clauses adopted by the European Commission.
8. Retention
Image data, wardrobe content, generated output and profile data are retained until deleted by the User in accordance with Section 9. Records referred to in Section 3.6 are retained for the periods prescribed by applicable accounting and limitation legislation. Signed links to stored images expire within minutes of issue and are not reusable thereafter.
9. Deletion
9.1 Deletion of data. The Delete my data function removes saved photographs, wardrobe content, generated output, search crops and profile data from the Controller's systems and from the device. Credit balance and subscription status are not affected.
9.2 Deletion of account. The Delete my account function performs the deletion described in Section 9.1 in respect of every installation associated with the account, closes the credit wallet and deletes the authentication record. Deletion of an account is irreversible and any remaining credit balance is forfeited without refund.
9.3 A deletion request may alternatively be submitted to dev@ailancer.com from the email address associated with the account.
10. Age requirement
The Application is not intended for children under the age of 13, and a date of birth below that age is not accepted. Where the Controller becomes aware that personal data of a child has been processed, that data will be deleted without undue delay.
11. Data not collected
The Application contains no analytics, advertising or third-party tracking software, does not use the advertising identifier, and does not track users across other applications or websites. It does not request access to location, contacts, calendar, microphone or health data, and reads no data from Apple Health. The market used to order search results is derived from the language and region setting of the device and not from location data or IP address.
12. Security
Image data is held in private storage and is accessible only through signed links of limited duration. Requests concerning a user's library must be authenticated by means of the device key described in Section 3.1. Credentials for the providers identified in Section 5 are held on the server and are not present in the Application.
13. Rights of the data subject
Under KVKK Art. 11 and GDPR Arts. 15 to 22, the User has the right to obtain confirmation as to whether personal data concerning them is processed, to access that data, to request its rectification or erasure, to object to processing, to request restriction of processing, and to receive the data in a portable format. Rectification and erasure may be exercised directly within the Application. Other requests are to be addressed to dev@ailancer.com and will be answered within thirty days.
The User also has the right to lodge a complaint with the Turkish Personal Data Protection Authority or with the supervisory authority of their place of residence. The Controller does not sell personal information within the meaning of the California Consumer Privacy Act.
14. Amendment
This Policy may be amended. The amended version is published on this page bearing a new effective date. Where an amendment materially alters the processing of image data, consent is requested again in accordance with Section 5.2.
15. Contact
Ailancer — dev@ailancer.com
Bu Politika, Ootry mobil uygulaması aracılığıyla işlenen kişisel veri kategorilerini, işleme amaçlarını ve hukuki sebeplerini, verilerin aktarıldığı tarafları, saklama sürelerini ve ilgili kişinin haklarını düzenler.
1. Veri sorumlusu
Ootry uygulaması (“Uygulama”), Türkiye Cumhuriyeti'nde yerleşik Ailancer (“Veri Sorumlusu”) tarafından geliştirilmekte ve işletilmektedir. Veri Sorumlusu, 6698 sayılı Kişisel Verilerin Korunması Kanunu (“KVKK”) ve (AB) 2016/679 sayılı Genel Veri Koruma Tüzüğü (“GDPR”) anlamında veri sorumlusudur.
Bu Politika kapsamındaki tüm başvuru ve bildirimler dev@ailancer.com adresine yapılır.
2. Kapsam
Bu Politika, Uygulama aracılığıyla işlenen kişisel verilere uygulanır. Uygulamada gösterilen bağlantılar üzerinden erişilen üçüncü taraf mağaza ve internet sitelerinin uygulamalarını kapsamaz; bunlar kendi aydınlatma metinlerine tabidir.
3. İşlenen kişisel veri kategorileri ve işleme amaçları
3.1 Kurulum tanımlayıcısı ve cihaz anahtarı. Uygulama, ilk açılışta rastgele bir tanımlayıcı ve gizli bir cihaz anahtarı üretir; her ikisi de cihazın anahtar zincirinde saklanır. Tanımlayıcı, hesap bulunmadığı aşamada kullanıcı içeriğinin ve kredi bakiyesinin bir cihazla ilişkilendirilmesi amacıyla işlenir. Cihaz anahtarının kendisi iletilmez; Veri Sorumlusu yalnızca SHA-256 özetini saklar ve bu özet, kullanıcı kütüphanesine ilişkin taleplerin yetkili cihazdan geldiğinin doğrulanması amacıyla işlenir.
3.2 Hesap verileri. Kullanıcının hesap oluşturmayı tercih etmesi hâlinde kullanıcı kimliği ve e-posta adresi; hesabın işletilmesi ile kredilerin, satın alımların ve kütüphane içeriğinin kullanıcının cihazları arasında erişilebilir kılınması amacıyla işlenir. Kimlik doğrulama, Veri Sorumlusu adına Supabase tarafından gerçekleştirilir. Apple ile Giriş'in “E-postamı Gizle” seçeneğiyle kullanılması hâlinde Veri Sorumlusuna yalnızca Apple tarafından atanan aktarma adresi ulaşır.
3.3 Profil verileri. Ad, doğum tarihi, boy, kilo ve profil görseli kullanıcının tercihine bağlı olarak verilebilir. Doğum tarihi 10. maddedeki asgari yaş şartının denetlenmesi, boy ve kilo ise üretilen çıktının kullanıcının oranlarına uyarlanması amacıyla işlenir.
3.4 Görsel veriler. Deneme için kaydedilen kullanıcı fotoğrafları, gardıroba eklenen kıyafet görselleri, Uygulamanın ürettiği çıktılar, ürün araması için gönderilen kırpmalar ve profil görseli, kullanıcının talep ettiği işlevlerin yerine getirilmesi amacıyla işlenir. Görsel veriler özel depolamada tutulur ve yalnızca dakikalar içinde geçerliliğini yitiren imzalı bağlantılarla erişilebilir. Hiçbir görsel için kalıcı ve herkese açık bir adres oluşturulmaz.
3.5 Cihaz adı ve bildirim jetonu. İşletim sisteminde tanımlı cihaz adı ile bildirim jetonu; kullanıcının cihazlarının birbirinden ayırt edilmesi ve kullanıcının başlattığı üretimin tamamlandığının bildirilmesi amacıyla işlenir.
3.6 İşlem kayıtları. Tanımlanan ve harcanan kredilere, arama işlemlerine ve abonelik durumuna ilişkin kayıtlar; satın alınan hizmetlerin sunulması, hız sınırlarının uygulanması, kötüye kullanımın önlenmesi ve muhasebe yükümlülüklerinin yerine getirilmesi amacıyla işlenir.
3.7 Yalnızca cihazda tutulan veriler. Ürün arama geçmişi, dil seçimi, bildirim tercihleri, 5. madde uyarınca verilen rızanın kaydı ve kullanıcının çıktı üzerinde kendi yaptığı kırpma ile renk düzeltmeleri yalnızca kullanıcının cihazında saklanır ve Veri Sorumlusuna iletilmez.
4. Hukuki sebepler
- Açık rıza — KVKK m. 5/1; GDPR m. 6(1)(a): görsel verilerin 5. maddede belirtilen sağlayıcılara aktarılması. Rıza, 5.3 maddesi uyarınca her zaman geri alınabilir.
- Sözleşmenin ifası — KVKK m. 5/2-c; GDPR m. 6(1)(b): hesabın işletilmesi, kütüphane içeriğinin saklanması ve eşitlenmesi, abonelik ve kredilerin sunulması.
- Meşru menfaat — GDPR m. 6(1)(f): hız sınırlarının uygulanması, kötüye kullanımın önlenmesi ve hizmet güvenliği.
- Hukuki yükümlülük — KVKK m. 5/2-a; GDPR m. 6(1)(c): muhasebe kayıtlarının saklanması.
5. Görsel verilerin işleyenlere aktarılması
5.1 Üretim ve arama işlevleri yalnızca cihaz üzerinde yerine getirilemez. Görsel veriler, her biri Veri Sorumlusunun talimatı doğrultusunda ve yalnızca belirtilen amaçla hareket eden aşağıdaki işleyenlere aktarılır:
- OpenAI — deneme çıktısının üretilmesi, kullanıcının seçtiği rötuşun uygulanması ve bir kıyafetin kategorisi, renkleri ile stilinin belirlenmesi amacıyla kullanıcı fotoğrafı ve kıyafet görseli. OpenAI'ın uygulama programlama arayüzü üzerinden iletilen veriler, anılan sağlayıcının modellerinin eğitiminde kullanılmaz.
- SerpApi ve bu hizmetin sorguladığı Google Lens — görsel olarak benzer ürünlerin döndürülmesi amacıyla ürün araması için gönderilen kırpma. Kullanıcı fotoğrafları ürün aramasının konusu değildir.
5.2 Bu madde kapsamındaki aktarım, kullanıcının Uygulama içinde açık rızasını vermesinden önce gerçekleştirilmez. Görsel veriler reklam, profilleme veya herhangi bir modelin eğitimi amacıyla kullanılmaz, satılmaz ve bu Politikada belirtilenler dışında hiçbir alıcıya açıklanmaz.
5.3 Rıza, Uygulamada Profil → Gizlilik bölümünden her zaman geri alınabilir. Geri alma derhâl hüküm doğurur ve deneme ile ürün arama işlevlerini devre dışı bırakır. Geri alma, öncesinde gerçekleştirilen işlemenin hukuka uygunluğunu etkilemez ve mevcut kütüphane içeriğini silmez.
6. Diğer alıcılar
- Supabase — veri tabanı, kimlik doğrulama ve görsel depolama.
- RevenueCat — abonelik durumunun doğrulanması ve sürdürülmesi; kurulum tanımlayıcısını, giriş yapılması hâlinde kullanıcı kimliğini alır.
- Apple veya Google — Uygulamanın edinildiği mağazaya göre ödemelerin işlenmesi. Ödeme aracına ilişkin bilgiler Veri Sorumlusuna açıklanmaz.
- Sovrn veya Skimlinks — kullanıcının arama sonucundan bir mağaza açması hâlinde, yalnızca tıklamanın bir işlemle eşleştirilmesi amacıyla hedef adres ve kurulum tanımlayıcısı affiliate ağına iletilir. Ad, e-posta adresi ve görsel veriler iletilmez.
7. Yurt dışına aktarım
5. ve 6. maddelerde belirtilen işleyenler, kişisel verileri kullanıcının yerleşik olduğu ülke dışında, Amerika Birleşik Devletleri dâhil olmak üzere işleyebilir. Avrupa Ekonomik Alanı'ndan veya Türkiye'den yapılan aktarımlar, anılan sağlayıcıların sunduğu güvenceler ile Avrupa Komisyonu tarafından kabul edilen Standart Sözleşme Maddeleri esas alınarak gerçekleştirilir.
8. Saklama süreleri
Görsel veriler, gardırop içeriği, üretilen çıktılar ve profil verileri, 9. madde uyarınca kullanıcı tarafından silinene kadar saklanır. 3.6 maddesinde belirtilen kayıtlar, ilgili muhasebe ve zamanaşımı mevzuatında öngörülen süreler boyunca saklanır. Depolanan görsellere ilişkin imzalı bağlantılar düzenlenmelerinden itibaren dakikalar içinde geçerliliğini yitirir ve sonrasında yeniden kullanılamaz.
9. Silme
9.1 Verilerin silinmesi. Verilerimi sil işlevi; kaydedilmiş fotoğrafları, gardırop içeriğini, üretilen çıktıları, arama kırpmalarını ve profil verilerini Veri Sorumlusunun sistemlerinden ve cihazdan kaldırır. Kredi bakiyesi ve abonelik durumu bundan etkilenmez.
9.2 Hesabın silinmesi. Hesabımı sil işlevi, 9.1 maddesinde tanımlanan silmeyi hesapla ilişkili her kurulum bakımından gerçekleştirir, kredi cüzdanını kapatır ve kimlik doğrulama kaydını siler. Hesabın silinmesi geri alınamaz; kalan kredi bakiyesi iade edilmeksizin sona erer.
9.3 Silme talebi, hesapla ilişkili e-posta adresinden dev@ailancer.com adresine de iletilebilir.
10. Yaş şartı
Uygulama 13 yaşından küçükler için tasarlanmamıştır ve bu yaşın altındaki bir doğum tarihi kabul edilmez. Bir çocuğa ait kişisel verinin işlendiğinin öğrenilmesi hâlinde söz konusu veri gecikmeksizin silinir.
11. Toplanmayan veriler
Uygulamada analitik, reklam veya üçüncü taraf izleme yazılımı bulunmaz; reklam tanımlayıcısı kullanılmaz ve kullanıcılar başka uygulama veya internet sitelerinde izlenmez. Konum, kişiler, takvim, mikrofon ve sağlık verilerine erişim talep edilmez; Apple Sağlık'tan veri okunmaz. Arama sonuçlarının sıralanmasında esas alınan pazar bilgisi, konum verisinden veya IP adresinden değil, cihazın dil ve bölge ayarından türetilir.
12. Güvenlik
Görsel veriler özel depolamada tutulur ve yalnızca sınırlı süreli imzalı bağlantılarla erişilebilir. Kullanıcı kütüphanesine ilişkin talepler, 3.1 maddesinde tanımlanan cihaz anahtarı ile doğrulanır. 5. maddede belirtilen sağlayıcılara ait kimlik bilgileri sunucuda tutulur ve Uygulama içinde yer almaz.
13. İlgili kişinin hakları
KVKK m. 11 ile GDPR m. 15–22 uyarınca kullanıcı; kişisel verilerinin işlenip işlenmediğini öğrenme, bunlara erişme, düzeltilmesini veya silinmesini isteme, işlemeye itiraz etme, işlemenin kısıtlanmasını talep etme ve verilerini taşınabilir bir biçimde alma haklarına sahiptir. Düzeltme ve silme hakları doğrudan Uygulama içinden kullanılabilir. Diğer talepler dev@ailancer.com adresine iletilir ve otuz gün içinde sonuçlandırılır.
Kullanıcı ayrıca Kişisel Verileri Koruma Kurumu'na veya yerleşik olduğu ülkedeki denetim makamına şikâyette bulunma hakkına sahiptir. Veri Sorumlusu, California Tüketici Gizliliği Yasası anlamında kişisel bilgi satışı yapmaz.
14. Değişiklik
Bu Politika değiştirilebilir. Değiştirilmiş metin, yeni bir yürürlük tarihi taşıyacak şekilde bu sayfada yayımlanır. Değişikliğin görsel verilerin işlenmesini esaslı olarak etkilemesi hâlinde 5.2 maddesi uyarınca rıza yeniden alınır.
15. İletişim
Ailancer — dev@ailancer.com