Privacy Policy

Effective date: August 4, 2026 · v1.1.0

Last updated: August 4, 2026

This Privacy Policy explains how personal data is collected, used, stored, and protected through the Beni Tanı - Get to Know Me ("Beni Tanı", the "App") mobile application and the benitaniapp.com website.

It is designed to comply with the EU General Data Protection Regulation (GDPR), Türkiye's Personal Data Protection Law No. 6698 (KVKK), and the Apple App Store and Google Play Store policies. For KVKK-specific disclosures, see the KVKK Notice.


1. Data Controller

The App is operated jointly by the following individuals, who act as joint data controllers:

  • Ramazan Sancar
  • Batınay Ünsel

General contact / requests: [email protected] — legal notices: [email protected] (all requests are handled via email; there is no registered legal entity or physical address yet).

Note: Once the project is operated under a legal entity (company), controller status will transfer to that entity and this policy will be updated and communicated to you.

2. Personal Data We Collect

2.1. Data you provide (account and profile)

  • Identity/account: username, email address, password (stored only as an irreversible cryptographic hash — we never see your plaintext password).
  • Profile (optional): name/display name, profile picture (avatar), gender, phone number, date of birth, preferred language.
  • Social login: when you sign in with Google or Apple, we receive only the basic information needed to verify your identity (e.g., email, name, provider user ID).

2.2. Content you create/share

  • Messages and content you send in game rooms, friendships, and chat features.
  • Media you upload (photos, etc.).
  • Question card sets you create or interact with, and your preferences.
  • Reports you file about other users and moderation records.

2.3. Automatically collected technical data

  • Device info: operating system (iOS/Android), app version, build number, device model and model ID, OS version.
  • Mandatory use (legitimate interest): error capture/diagnostics and aggregate statistics about service operation. This use is necessary for the secure operation of the service and is not subject to consent.
  • Consent-based use: marketing and promotional analysis is performed only if you have opted in under the Explicit Consent Text.
  • IP address and location: your IP is used to determine the country/region of the request. This lookup is performed locally on our server (MaxMind database); your IP is not sent to a third-party geolocation service for this purpose.
  • Log data: request time, language and timezone preference, error and diagnostic logs.
  • Notification tokens: a Firebase Cloud Messaging (FCM) device token to deliver push notifications.

2.4. Payment and subscription data

  • Your subscription status, plan, and purchase history.
  • Payments are processed exclusively via Apple App Store and Google Play in-app purchases. We do not see or store full payment instrument details (e.g., card numbers); these are processed entirely by Apple and Google. RevenueCat is used to track store subscription status.

3. Why We Process Your Data

  • To create your account, authenticate you, and manage sessions.
  • To provide core features (question cards, game rooms, friendships, chat).
  • Age verification and content suitability: your date of birth is used to show age-appropriate content based on content ratings (SAFE/TEEN/MATURE/ADULT) and to gate adult content (see §7).
  • To run region-appropriate pricing, subscriptions, and purchases.
  • To send push notifications and necessary service announcements.
  • For security, abuse prevention, moderation, and legal compliance.
  • For diagnostics and service improvement (Sentry error monitoring; Umami / Microsoft Clarity usage analytics).

4. Legal Bases for Processing (GDPR / KVKK)

PurposeGDPR basisKVKK basis
Providing the account/service, performing the TermsArt. 6(1)(b) contractPerformance of a contract
Security, fraud/abuse preventionArt. 6(1)(f) legitimate interestLegitimate interest
Legal obligations (billing, responding to requests)Art. 6(1)(c) legal obligationLegal obligation
Adult content, marketing, analytics/cookiesArt. 6(1)(a) consentExplicit consent

You may withdraw consent-based processing at any time (see §10).


5. Who We Share Data With

We do not sell your personal data. We share only as needed to provide the service:

  • Other users: your username, avatar, and shared content are visible to users you interact with.
  • Authorities: where legally required.
  • Service providers (processors): listed in the table below.

Third-Party Services We Use

Each provider processes your data under its own privacy/legal policies:

ProviderPurposePrivacy Policy
Apple (App Store)In-app purchases, subscriptionsapple.com/legal/privacy
Google (Play Store)In-app purchases, subscriptionspolicies.google.com/privacy
RevenueCatSubscription status managementrevenuecat.com/privacy
Firebase Cloud Messaging (Google)Push notificationsfirebase.google.com/support/privacy
SentryError and diagnostic monitoringsentry.io/privacy
Umami AnalyticsUsage analytics and session recording (privacy-friendly; app and website)umami.is/privacy
HotjarUsage analytics (website only — not used in the mobile app)hotjar.com/legal/policies/privacy
Microsoft ClarityUsage/session analytics (app and website)privacy.microsoft.com
MailtrapEmail delivery (SMTP)mailtrap.io/privacy-policy
MaxMind (GeoLite2)IP → country lookup (local on our server; IP not sent out)maxmind.com/en/privacy-policy
Hetzner Online GmbHServer hosting (Germany)hetzner.com/legal/privacy-policy
Note: Analytics services (Umami, Hotjar, Clarity) are subject to your analytics consent; when you withdraw consent, collection through these services stops (see Explicit Consent Text). Some providers operate outside your country, so data may be transferred internationally (see §6).

6. Hosting Location and International Transfers

Our servers are hosted in Germany (Hetzner Online GmbH, Nuremberg — EU / eu-central region). Your personal data is therefore primarily processed and stored within the European Union. For users located in Türkiye, this constitutes an international transfer under KVKK.

Additionally, some providers (e.g., Apple, Google, Sentry) also operate servers outside the EU. Your data may be transferred internationally under GDPR Chapter V and KVKK Art. 9, subject to appropriate safeguards (e.g., Standard Contractual Clauses / adequacy decisions) and/or your explicit consent.


7. Age Limit and Children's Data

  • You must be at least 13 years old to use the App and create an account.
  • Content is rated across four tiers: SAFE (all ages), TEEN (13+), MATURE (16+), ADULT (adults only).
  • Adult (ADULT) content is age-gated based on the age derived from your date of birth and the policy of your country/region. The minimum age for adult content varies by region (the default is 18, but some countries apply a higher threshold), and in some regions adult content is blocked entirely.
  • Your region is determined from the country derived from your IP address. If no policy is defined for your country, the policy for its continent applies; failing that, a default policy applies.
  • If no date of birth is on record, adult content access is not granted.
  • We do not knowingly collect data from children under 13. If we learn of such data, we delete the account and data. If you become aware of this, contact [email protected].

8. Retention and Account Deletion

We retain your data while your account is active and as long as needed for the purposes described.

8.1. The account deletion flow

You can request deletion via the App's account deletion flow. Once you request it:

  • A 30-day grace period begins. Your account is marked for deletion, but the request remains reversible.
  • We send reminders 7, 3, and 1 day before the scheduled deletion date.
  • You can cancel the request during the grace period and keep your account.
  • When the period ends, your account is anonymized (see below).

8.2. Anonymization instead of erasure — what goes, what stays

To preserve system integrity (e.g., so that game rooms and conversations you took part in remain coherent for the other participants), your account record is not destroyed outright. Instead it is anonymized so that it can no longer be linked to you:

Data deleted or irreversibly replaced:

  • Email address (replaced with a technical value that cannot be linked to you)
  • Username and display name (replaced with an anonymous value)
  • First and last name
  • Phone number
  • Profile picture (avatar)
  • Social login identifiers (e.g., Google ID)
  • Activation tokens
  • Your date of birth is reduced to the birth year only (year-01-01), dropping day/month precision — because a full date of birth combined with gender and region could make you re-identifiable.

Data retained in anonymized form:

  • Birth year (for age-range statistics), gender, country/region, currency and timezone preference, user type
  • Referral code and loyalty point balance
  • Content and messages you created — but attributed to "Anonymous User"

This data no longer identifies you. Data covered by legal retention obligations (e.g., financial records, store purchase records) is kept for the period required by applicable law.

If you want your data fully erased rather than anonymized, write to [email protected]; we will assess the request under GDPR Art. 17 and KVKK Art. 7, to the extent technically possible and legally permitted.


9. Security

Passwords are irreversibly hashed; access tokens are stored in the operating system's secure storage on your device (iOS Keychain / Android Keystore); all traffic between the app and our servers is encrypted with TLS. We also apply technical measures such as authorization checks, session management, and abuse/automated-scanning detection, alongside administrative measures such as restricting access rights.

No system is 100% secure. In the event of a personal data breach:

  • Under GDPR: we notify the competent supervisory authority within 72 hours under Art. 33, and where the breach is likely to result in a high risk, we inform affected individuals without undue delay under Art. 34.
  • Under KVKK: we notify the Turkish Personal Data Protection Board within 72 hours of becoming aware of the breach, and inform affected data subjects as soon as reasonably possible.

10. Your Rights

Under GDPR Arts. 15–22 and KVKK Art. 11, you have the rights to access, rectify, erase, restrict, port, and object to processing, and to withdraw consent you have given.

How to submit a request: email [email protected] from the address registered to your account. If a request arrives from another address, we may ask for additional information to verify your identity, so that we never disclose your data to an unauthorized person.

Please include: your name, the username or email address on your account, what you are requesting, and contact details for our reply.

Response time: we handle requests free of charge within one month under GDPR (extendable by two months for complex requests, with notice and reasons) and within 30 days under KVKK. Where KVKK processing entails an additional cost, a fee set out in the Board's tariff may apply.

Right to complain: if you are not satisfied with our response, you may lodge a complaint with the data protection supervisory authority of your country of residence, or with the Turkish Personal Data Protection Board under KVKK.


11. Cookies

Our website and web-based services may use cookies and similar technologies. See the Cookie Policy.


12. Changes

We may update this policy. For material changes, we notify you in-app and/or by email. The current version is always published in-app and on the website.


13. Contact

Questions: [email protected] — legal notices: [email protected].

Contact Us

If you have questions about this document, you can reach us at:

[email protected]

Stay Updated

Be the first to know about new card sets and updates. Join the waiting list!