Privacy Policy
Effective date: August 4, 2026 · v1.1.0
Last updated: August 4, 2026
This Privacy Policy explains how personal data is collected, used, stored, and protected through the Beni Tanı - Get to Know Me ("Beni Tanı", the "App") mobile application and the benitaniapp.com website.
It is designed to comply with the EU General Data Protection Regulation (GDPR), Türkiye's Personal Data Protection Law No. 6698 (KVKK), and the Apple App Store and Google Play Store policies. For KVKK-specific disclosures, see the KVKK Notice.
1. Data Controller
The App is operated jointly by the following individuals, who act as joint data controllers:
- Ramazan Sancar
- Batınay Ünsel
General contact / requests: [email protected] — legal notices: [email protected] (all requests are handled via email; there is no registered legal entity or physical address yet).
Note: Once the project is operated under a legal entity (company), controller status will transfer to that entity and this policy will be updated and communicated to you.
2. Personal Data We Collect
2.1. Data you provide (account and profile)
- Identity/account: username, email address, password (stored only as an irreversible cryptographic hash — we never see your plaintext password).
- Profile (optional): name/display name, profile picture (avatar), gender, phone number, date of birth, preferred language.
- Social login: when you sign in with Google or Apple, we receive only the basic information needed to verify your identity (e.g., email, name, provider user ID).
2.2. Content you create/share
- Messages and content you send in game rooms, friendships, and chat features.
- Media you upload (photos, etc.).
- Question card sets you create or interact with, and your preferences.
- Reports you file about other users and moderation records.
2.3. Automatically collected technical data
- Device info: operating system (iOS/Android), app version, build number, device model and model ID, OS version.
- Mandatory use (legitimate interest): error capture/diagnostics and aggregate statistics about service operation. This use is necessary for the secure operation of the service and is not subject to consent.
- Consent-based use: marketing and promotional analysis is performed only if you have opted in under the Explicit Consent Text.
- IP address and location: your IP is used to determine the country/region of the request. This lookup is performed locally on our server (MaxMind database); your IP is not sent to a third-party geolocation service for this purpose.
- Log data: request time, language and timezone preference, error and diagnostic logs.
- Notification tokens: a Firebase Cloud Messaging (FCM) device token to deliver push notifications.
2.4. Payment and subscription data
- Your subscription status, plan, and purchase history.
- Payments are processed exclusively via Apple App Store and Google Play in-app purchases. We do not see or store full payment instrument details (e.g., card numbers); these are processed entirely by Apple and Google. RevenueCat is used to track store subscription status.
3. Why We Process Your Data
- To create your account, authenticate you, and manage sessions.
- To provide core features (question cards, game rooms, friendships, chat).
- Age verification and content suitability: your date of birth is used to show age-appropriate content based on content ratings (SAFE/TEEN/MATURE/ADULT) and to gate adult content (see §7).
- To run region-appropriate pricing, subscriptions, and purchases.
- To send push notifications and necessary service announcements.
- For security, abuse prevention, moderation, and legal compliance.
- For diagnostics and service improvement (Sentry error monitoring; Umami / Microsoft Clarity usage analytics).
4. Legal Bases for Processing (GDPR / KVKK)
| Purpose | GDPR basis | KVKK basis |
|---|---|---|
| Providing the account/service, performing the Terms | Art. 6(1)(b) contract | Performance of a contract |
| Security, fraud/abuse prevention | Art. 6(1)(f) legitimate interest | Legitimate interest |
| Legal obligations (billing, responding to requests) | Art. 6(1)(c) legal obligation | Legal obligation |
| Adult content, marketing, analytics/cookies | Art. 6(1)(a) consent | Explicit consent |
You may withdraw consent-based processing at any time (see §10).
5. Who We Share Data With
We do not sell your personal data. We share only as needed to provide the service:
- Other users: your username, avatar, and shared content are visible to users you interact with.
- Authorities: where legally required.
- Service providers (processors): listed in the table below.
Third-Party Services We Use
Each provider processes your data under its own privacy/legal policies:
| Provider | Purpose | Privacy Policy |
|---|---|---|
| Apple (App Store) | In-app purchases, subscriptions | apple.com/legal/privacy |
| Google (Play Store) | In-app purchases, subscriptions | policies.google.com/privacy |
| RevenueCat | Subscription status management | revenuecat.com/privacy |
| Firebase Cloud Messaging (Google) | Push notifications | firebase.google.com/support/privacy |
| Sentry | Error and diagnostic monitoring | sentry.io/privacy |
| Umami Analytics | Usage analytics and session recording (privacy-friendly; app and website) | umami.is/privacy |
| Hotjar | Usage analytics (website only — not used in the mobile app) | hotjar.com/legal/policies/privacy |
| Microsoft Clarity | Usage/session analytics (app and website) | privacy.microsoft.com |
| Mailtrap | Email delivery (SMTP) | mailtrap.io/privacy-policy |
| MaxMind (GeoLite2) | IP → country lookup (local on our server; IP not sent out) | maxmind.com/en/privacy-policy |
| Hetzner Online GmbH | Server hosting (Germany) | hetzner.com/legal/privacy-policy |
Note: Analytics services (Umami, Hotjar, Clarity) are subject to your analytics consent; when you withdraw consent, collection through these services stops (see Explicit Consent Text). Some providers operate outside your country, so data may be transferred internationally (see §6).
6. Hosting Location and International Transfers
Our servers are hosted in Germany (Hetzner Online GmbH, Nuremberg — EU / eu-central region). Your personal data is therefore primarily processed and stored within the European Union. For users located in Türkiye, this constitutes an international transfer under KVKK.
Additionally, some providers (e.g., Apple, Google, Sentry) also operate servers outside the EU. Your data may be transferred internationally under GDPR Chapter V and KVKK Art. 9, subject to appropriate safeguards (e.g., Standard Contractual Clauses / adequacy decisions) and/or your explicit consent.
7. Age Limit and Children's Data
- You must be at least 13 years old to use the App and create an account.
- Content is rated across four tiers: SAFE (all ages), TEEN (13+), MATURE (16+), ADULT (adults only).
- Adult (ADULT) content is age-gated based on the age derived from your date of birth and the policy of your country/region. The minimum age for adult content varies by region (the default is 18, but some countries apply a higher threshold), and in some regions adult content is blocked entirely.
- Your region is determined from the country derived from your IP address. If no policy is defined for your country, the policy for its continent applies; failing that, a default policy applies.
- If no date of birth is on record, adult content access is not granted.
- We do not knowingly collect data from children under 13. If we learn of such data, we delete the account and data. If you become aware of this, contact [email protected].
8. Retention and Account Deletion
We retain your data while your account is active and as long as needed for the purposes described.
8.1. The account deletion flow
You can request deletion via the App's account deletion flow. Once you request it:
- A 30-day grace period begins. Your account is marked for deletion, but the request remains reversible.
- We send reminders 7, 3, and 1 day before the scheduled deletion date.
- You can cancel the request during the grace period and keep your account.
- When the period ends, your account is anonymized (see below).
8.2. Anonymization instead of erasure — what goes, what stays
To preserve system integrity (e.g., so that game rooms and conversations you took part in remain coherent for the other participants), your account record is not destroyed outright. Instead it is anonymized so that it can no longer be linked to you:
Data deleted or irreversibly replaced:
- Email address (replaced with a technical value that cannot be linked to you)
- Username and display name (replaced with an anonymous value)
- First and last name
- Phone number
- Profile picture (avatar)
- Social login identifiers (e.g., Google ID)
- Activation tokens
- Your date of birth is reduced to the birth year only (year-01-01), dropping day/month precision — because a full date of birth combined with gender and region could make you re-identifiable.
Data retained in anonymized form:
- Birth year (for age-range statistics), gender, country/region, currency and timezone preference, user type
- Referral code and loyalty point balance
- Content and messages you created — but attributed to "Anonymous User"
This data no longer identifies you. Data covered by legal retention obligations (e.g., financial records, store purchase records) is kept for the period required by applicable law.
If you want your data fully erased rather than anonymized, write to [email protected]; we will assess the request under GDPR Art. 17 and KVKK Art. 7, to the extent technically possible and legally permitted.
9. Security
Passwords are irreversibly hashed; access tokens are stored in the operating system's secure storage on your device (iOS Keychain / Android Keystore); all traffic between the app and our servers is encrypted with TLS. We also apply technical measures such as authorization checks, session management, and abuse/automated-scanning detection, alongside administrative measures such as restricting access rights.
No system is 100% secure. In the event of a personal data breach:
- Under GDPR: we notify the competent supervisory authority within 72 hours under Art. 33, and where the breach is likely to result in a high risk, we inform affected individuals without undue delay under Art. 34.
- Under KVKK: we notify the Turkish Personal Data Protection Board within 72 hours of becoming aware of the breach, and inform affected data subjects as soon as reasonably possible.
10. Your Rights
Under GDPR Arts. 15–22 and KVKK Art. 11, you have the rights to access, rectify, erase, restrict, port, and object to processing, and to withdraw consent you have given.
How to submit a request: email [email protected] from the address registered to your account. If a request arrives from another address, we may ask for additional information to verify your identity, so that we never disclose your data to an unauthorized person.
Please include: your name, the username or email address on your account, what you are requesting, and contact details for our reply.
Response time: we handle requests free of charge within one month under GDPR (extendable by two months for complex requests, with notice and reasons) and within 30 days under KVKK. Where KVKK processing entails an additional cost, a fee set out in the Board's tariff may apply.
Right to complain: if you are not satisfied with our response, you may lodge a complaint with the data protection supervisory authority of your country of residence, or with the Turkish Personal Data Protection Board under KVKK.
11. Cookies
Our website and web-based services may use cookies and similar technologies. See the Cookie Policy.
12. Changes
We may update this policy. For material changes, we notify you in-app and/or by email. The current version is always published in-app and on the website.
13. Contact
Questions: [email protected] — legal notices: [email protected].