Privacy Policy

Faay Tech · Effective 14 September 2026

English

Our apps are not alike. Some keep everything on your device and have no server at all. Others have accounts, show ads, or report crashes. A single policy that described all of them at once would be wrong about most of them, so this one is written by feature: every section says when it applies, and an app without that feature collects none of the data described in it.

The exact list for any one app is on that app's store page — App Privacy on the App Store and Data safety on Google Play. Those listings are per-app; read them together with this policy.

How to read this policy

This policy covers the mobile apps published by Faay Tech. Wherever it says some of our apps, the feature is optional and present only in the apps that need it.

Faay Tech is the data controller for the data described here. Contact details are at the end.

What you put into an app

The content you create in an app — entries, notes, lists, photos, settings, whatever the app is for — belongs to you. It is not sold, rented or shared for anyone else’s marketing, ever, by any of our apps.

Apps that work only on your device

some apps

Several of our apps store everything in a database on your phone and have no server behind them. In those apps nothing you enter is transmitted anywhere, there is no account to create, and uninstalling the app deletes the data with it. Where an app works this way, its store listing declares that it collects no data of that kind.

Accounts and sign-in

apps that offer an account

Some of our apps let you create an account, either with an e-mail address and password or through Sign in with Google or Sign in with Apple. Where an account exists we store the e-mail address and the display name attached to it, so the account can be identified and recovered. Signing in with Google or Apple sends us your e-mail address and name from that provider; it never gives us your password there, and Apple’s private-relay option lets you withhold your real address. Passwords we hold are stored only as salted hashes.

An app that does not offer an account asks for none of this.

Our own servers

apps with a server

The apps that do have a backend send it only what the feature needs: the content you chose to sync or publish, your account identifier, and ordinary server request logs (IP address, time, and the request itself) kept for a short period for security and debugging. Those apps run on infrastructure we rent; hosting providers process data on our instructions and for no purpose of their own.

Crash reporting

most apps

Most of our apps include Firebase Crashlytics. When an app crashes it sends Google a report containing the stack trace, the device model, the operating system version, the app version, the state of the app at the moment of the crash, and an installation identifier that lets repeated crashes on one install be counted once. It does not contain the content you created. We use it only to find and fix faults.

Analytics

some apps

Some of our apps include Google Analytics for Firebase, which records which screens are opened and which features are used, together with the device model, operating system, language, approximate region derived from the IP address, and an app-instance identifier. We use it in aggregate, to see which parts of an app people actually use. One app also sends purchase and subscription events to Adapty and to Meta for the same purpose. We do not use analytics to build advertising profiles, and we do not sell it.

Advertising

one app

One of our apps shows ads through Google AdMob. AdMob uses a device advertising identifier to choose and measure ads, and may personalise them unless you have turned personalisation off. On iOS the app cannot track you across other companies’ apps unless you grant permission when the system asks. You can reset or limit the advertising identifier in your device settings at any time. Our other apps show no ads.

Purchases and subscriptions

apps with a paid tier

Paid tiers are sold through the App Store and Google Play. Those stores take the payment and we never see your card number or billing address. The app is told only whether a purchase or subscription is currently active. Refunds and cancellations are handled by the store, under the store’s own terms.

On-device text recognition

apps that read text from a photo

Where an app reads text from a photo, the recognition runs on your device — Apple Vision on iOS, Google ML Kit on Android — and the photo is not uploaded for it.

The Android library has one consequence worth stating plainly. Google’s ML Kit sends Google its own diagnostic data: device model and operating system, app package name and version, device and installation identifiers, latency and performance metrics, event types and error codes. It does this from the moment the app starts, whether or not you ever use the feature. This is Google’s own telemetry inside their library; it contains none of your content, it goes to Google as the library’s provider rather than to us, and Google offers no way for us to switch it off. Google documents what it covers at ML Kit Android data disclosure. The iOS builds do not include ML Kit.

Camera, microphone and photos

apps that ask for them

An app asks for the camera, the microphone or your photo library only when a feature you started needs it, and your device will ask you first. What is captured is used for that feature. Unless a section above says otherwise, it is processed on the device and not uploaded. You can withdraw any of these permissions in your device settings, and the feature simply stops working.

Device lock and biometrics

apps with an app lock

Where an app can be locked with a PIN, a fingerprint or a face, the biometric check is performed by your operating system, which tells the app only whether it succeeded. Your fingerprint and face data never reach the app and never reach us. A PIN you set is kept on the device.

Notifications

apps that send them

Most notifications from our apps are local: your phone schedules and shows them, nothing is sent over the network, and no device token exists. One app also sends push notifications through Firebase Cloud Messaging, which requires a device token that we store for as long as the app is installed. Turning notifications off in your device settings stops both kinds.

Optional cloud backup

if you switch it on

An app may offer to back itself up to your own Google Drive. If you turn it on, you sign in to Google and the backup is written to the app-data folder of your Drive — a private area that only that app can read, which we cannot browse and which is not visible among your files. We request no access to the rest of your Drive. You can disconnect it in the app, or revoke access in your Google account, at any time.

Content from other sites

some apps

Some of our apps open pages from other organisations — reference sites, dictionaries, our own support pages — either in your browser or in a web view inside the app. Opening one sends that site whatever the address contains, which may include the word or item you looked up, along with the ordinary information any web request carries. Those sites are not operated by us and their own privacy policies apply.

Files you export yourself

Where an app can export a backup, a document or a sharing link, the file goes wherever you send it. From that moment it is covered by the privacy policy of the destination — the messaging app, the cloud drive, the mail provider — and not by this one.

Children

Our apps are general-audience apps and are not directed at children under 13. We do not knowingly collect personal information from a child under 13. If you believe a child has provided us with personal information, write to the address below and we will delete it.

Security

Data in transit is encrypted with HTTPS. Account passwords are stored as salted hashes, never in a readable form. Access to any server data is limited to what is needed to run the service. No system is perfectly secure, and we do not claim otherwise; if a breach ever affects your data we will tell you and the relevant authority as the law requires.

Keeping and deleting data

Data held only on your device lasts until you delete it or uninstall the app. Account data is kept while the account exists and is deleted when you delete the account. Server request logs are kept briefly and then discarded. Crash and analytics data is retained by Google under Firebase’s own retention settings.

To delete an account and everything attached to it, use the delete option inside the app where one is offered, or write to the address below. For an app that stores everything on your device, uninstalling it removes everything; there is nothing held elsewhere to delete.

Your rights

Depending on where you live — the GDPR in the EU and the UK, the KVKK in Türkiye, and comparable laws elsewhere — you may ask what data we hold about you, ask for a copy, ask for it to be corrected or deleted, object to a use of it, or complain to your data protection authority. Write to the address below and we will answer within the period the law allows. Where an app holds nothing about you, the honest answer will be that there is nothing to send.

Changes

If this policy changes, the new version is published at this address with a new effective date at the top. Material changes will also be surfaced in the apps they affect.

Effective: 14 September 2026

Contact

Questions about privacy, or a request under the section above: [email protected]


Türkçe

Uygulamalarımız birbirinin aynısı değil. Bazıları her şeyi cihazınızda tutar ve arkasında hiçbir sunucu yoktur. Bazılarında hesap vardır, reklam gösterir ya da çökme raporu gönderir. Hepsini tek seferde anlatan bir politika çoğu için yanlış olurdu; bu yüzden bu politika özellik bazlı yazıldı: her bölüm ne zaman geçerli olduğunu söyler ve o özelliği taşımayan bir uygulama, o bölümde anlatılan verilerin hiçbirini toplamaz.

Tek bir uygulama için kesin liste, o uygulamanın mağaza sayfasındadır — App Store'da Uygulama Gizliliği, Google Play'de Veri güvenliği. Bu listeler uygulama bazlıdır; bu politikayla birlikte okuyun.

Bu politika nasıl okunur

Bu politika Faay Tech tarafından yayımlanan mobil uygulamaları kapsar. Bazı uygulamalarımızda ifadesinin geçtiği her yerde, o özellik isteğe bağlıdır ve yalnızca ihtiyaç duyan uygulamalarda bulunur.

Burada anlatılan veriler bakımından veri sorumlusu Faay Tech'tir. İletişim bilgileri en altta.

Uygulamaya girdikleriniz

Bir uygulamada oluşturduğunuz içerik — kayıtlar, notlar, listeler, fotoğraflar, ayarlar, uygulama ne içinse o — size aittir. Uygulamalarımızın hiçbirinde, hiçbir zaman, başkasının pazarlaması için satılmaz, kiralanmaz veya paylaşılmaz.

Yalnızca cihazınızda çalışan uygulamalar

bazı uygulamalar

Uygulamalarımızın birkaçı her şeyi telefonunuzdaki bir veritabanında saklar ve arkalarında sunucu yoktur. Bu uygulamalarda girdiğiniz hiçbir şey hiçbir yere iletilmez, açılacak bir hesap yoktur ve uygulamayı kaldırmak veriyi de siler. Bir uygulama böyle çalışıyorsa, mağaza sayfasında o tür veri toplamadığı beyan edilir.

Hesaplar ve giriş

hesap sunan uygulamalar

Bazı uygulamalarımızda e-posta ve parolayla ya da Google ile giriş veya Apple ile giriş ile hesap açabilirsiniz. Hesap varsa, hesabın tanınabilmesi ve kurtarılabilmesi için e-posta adresini ve ona bağlı görünen adı saklarız. Google veya Apple ile giriş bize o sağlayıcıdan e-posta adresinizi ve adınızı iletir; oradaki parolanızı asla vermez ve Apple'ın özel aktarma seçeneği gerçek adresinizi gizlemenize izin verir. Tuttuğumuz parolalar yalnızca tuzlanmış özet (hash) olarak saklanır.

Hesap sunmayan bir uygulama bunların hiçbirini istemez.

Kendi sunucularımız

sunucusu olan uygulamalar

Arkasında sunucu olan uygulamalar sunucuya yalnızca özelliğin ihtiyaç duyduğunu gönderir: eşitlemeyi veya yayımlamayı seçtiğiniz içerik, hesap tanımlayıcınız ve olağan sunucu istek kayıtları (IP adresi, zaman ve isteğin kendisi) — bunlar güvenlik ve hata ayıklama için kısa süre tutulur. Bu uygulamalar kiraladığımız altyapıda çalışır; barındırma sağlayıcıları veriyi bizim talimatımızla ve kendi amaçları için olmaksızın işler.

Çökme raporlama

çoğu uygulama

Uygulamalarımızın çoğunda Firebase Crashlytics vardır. Uygulama çöktüğünde Google'a bir rapor gider: yığın izi, cihaz modeli, işletim sistemi sürümü, uygulama sürümü, çökme anındaki uygulama durumu ve aynı kurulumdaki tekrarlayan çökmelerin tek sayılmasını sağlayan bir kurulum tanımlayıcısı. Oluşturduğunuz içeriği içermez. Bunu yalnızca hataları bulup düzeltmek için kullanırız.

Analitik

bazı uygulamalar

Bazı uygulamalarımızda Firebase için Google Analytics bulunur; hangi ekranların açıldığını ve hangi özelliklerin kullanıldığını, cihaz modeli, işletim sistemi, dil, IP adresinden türetilen yaklaşık bölge ve bir uygulama örneği tanımlayıcısıyla birlikte kaydeder. Bunu toplu halde, bir uygulamanın hangi kısımlarının gerçekten kullanıldığını görmek için kullanırız. Bir uygulama ayrıca satın alma ve abonelik olaylarını aynı amaçla Adapty'ye ve Meta'ya gönderir. Analitiği reklam profili oluşturmak için kullanmayız ve satmayız.

Reklam

bir uygulama

Uygulamalarımızdan biri Google AdMob üzerinden reklam gösterir. AdMob reklamı seçmek ve ölçmek için bir cihaz reklam tanımlayıcısı kullanır ve kişiselleştirmeyi kapatmadıysanız reklamları kişiselleştirebilir. iOS'ta sistem sorduğunda izin vermediğiniz sürece uygulama sizi başka şirketlerin uygulamaları arasında izleyemez. Reklam tanımlayıcısını cihaz ayarlarınızdan istediğiniz zaman sıfırlayabilir ya da sınırlayabilirsiniz. Diğer uygulamalarımızda reklam yoktur.

Satın almalar ve abonelikler

ücretli kademesi olan uygulamalar

Ücretli kademeler App Store ve Google Play üzerinden satılır. Ödemeyi bu mağazalar alır; kart numaranızı veya fatura adresinizi hiç görmeyiz. Uygulamaya yalnızca bir satın almanın veya aboneliğin şu anda etkin olup olmadığı bildirilir. İadeler ve iptaller mağazanın kendi koşullarına göre mağaza tarafından yürütülür.

Cihaz üzerinde metin tanıma

fotoğraftan metin okuyan uygulamalar

Bir uygulama fotoğraftan metin okuyorsa tanıma cihazınızda çalışır — iOS'ta Apple Vision, Android'de Google ML Kit — ve fotoğraf bunun için hiçbir yere yüklenmez.

Android kitaplığının açıkça söylenmesi gereken bir sonucu var. Google'ın ML Kit'i Google'a kendi teşhis verisini gönderir: cihaz modeli ve işletim sistemi, uygulama paket adı ve sürümü, cihaz ve kurulum tanımlayıcıları, gecikme ve performans ölçümleri, olay türleri ve hata kodları. Bunu, siz o özelliği hiç kullanmasanız bile uygulama açılışından itibaren yapar. Bu, Google'ın kendi kitaplığı içindeki kendi telemetrisidir; içeriğinizden hiçbirini taşımaz, kitaplığın sağlayıcısı olarak Google'a gider, bize değil, ve Google bunu kapatmamız için bir yol sunmaz. Kapsamını Google ML Kit Android veri açıklaması sayfasında belgeliyor. iOS sürümlerinde ML Kit yoktur.

Kamera, mikrofon ve fotoğraflar

izin isteyen uygulamalar

Bir uygulama kamerayı, mikrofonu ya da fotoğraf kitaplığınızı yalnızca sizin başlattığınız bir özellik gerektirdiğinde ister ve cihazınız önce size sorar. Yakalanan şey o özellik için kullanılır. Yukarıdaki bir bölüm aksini söylemiyorsa cihazda işlenir ve hiçbir yere yüklenmez. Bu izinlerin herhangi birini cihaz ayarlarından geri alabilirsiniz; o özellik yalnızca çalışmaz olur.

Uygulama kilidi ve biyometri

kilit sunan uygulamalar

Bir uygulama PIN, parmak izi veya yüz ile kilitlenebiliyorsa, biyometrik doğrulamayı işletim sisteminiz yapar ve uygulamaya yalnızca başarılı olup olmadığını söyler. Parmak izi ve yüz verileriniz uygulamaya da bize de asla ulaşmaz. Belirlediğiniz PIN cihazda kalır.

Bildirimler

bildirim gönderen uygulamalar

Uygulamalarımızın bildirimlerinin çoğu yereldir: telefonunuz zamanlar ve gösterir, ağ üzerinden hiçbir şey gitmez ve cihaz jetonu oluşmaz. Bir uygulama ayrıca Firebase Cloud Messaging üzerinden push bildirim gönderir; bunun için uygulama kurulu olduğu sürece sakladığımız bir cihaz jetonu gerekir. Cihaz ayarlarından bildirimleri kapatmak her ikisini de durdurur.

İsteğe bağlı bulut yedekleme

siz açarsanız

Bir uygulama kendini sizin Google Drive'ınıza yedeklemeyi önerebilir. Açarsanız Google'a giriş yaparsınız ve yedek Drive'ınızın uygulama verisi klasörüne yazılır — yalnızca o uygulamanın okuyabildiği, bizim göremediğimiz ve dosyalarınızın arasında görünmeyen özel bir alan. Drive'ınızın geri kalanına erişim istemeyiz. Bağlantıyı uygulamadan kesebilir ya da Google hesabınızdan erişimi istediğiniz zaman iptal edebilirsiniz.

Başka sitelerden içerik

bazı uygulamalar

Bazı uygulamalarımız başka kuruluşların sayfalarını açar — başvuru siteleri, sözlükler, kendi destek sayfalarımız — tarayıcınızda ya da uygulama içindeki bir web görünümünde. Bir sayfayı açmak o siteye adresin içerdiği her şeyi iletir; buna aradığınız kelime veya öğe de dahil olabilir, ayrıca her web isteğinin taşıdığı olağan bilgiler gider. Bu siteleri biz işletmiyoruz ve kendi gizlilik politikaları geçerlidir.

Kendi dışa aktardığınız dosyalar

Bir uygulama yedek, belge veya paylaşım bağlantısı dışa aktarabiliyorsa, dosya sizin gönderdiğiniz yere gider. O andan itibaren bu politika değil, gittiği yerin gizlilik politikası geçerlidir — mesajlaşma uygulaması, bulut sürücüsü, e-posta sağlayıcısı.

Çocuklar

Uygulamalarımız genel kitleye yöneliktir ve 13 yaşın altındaki çocuklara yönelik değildir. 13 yaşın altındaki bir çocuktan bilerek kişisel bilgi toplamayız. Bir çocuğun bize kişisel bilgi verdiğini düşünüyorsanız aşağıdaki adrese yazın, sileriz.

Güvenlik

Aktarım hâlindeki veri HTTPS ile şifrelenir. Hesap parolaları okunabilir biçimde değil, tuzlanmış özet olarak saklanır. Sunucudaki veriye erişim hizmeti yürütmek için gerekenle sınırlıdır. Hiçbir sistem kusursuz güvenli değildir ve öyle olduğunu iddia etmiyoruz; bir ihlal verinizi etkilerse yasanın gerektirdiği şekilde size ve ilgili kuruma bildiririz.

Verilerin saklanması ve silinmesi

Yalnızca cihazınızda tutulan veri, siz silene ya da uygulamayı kaldırana kadar kalır. Hesap verisi hesap var olduğu sürece tutulur ve hesabı sildiğinizde silinir. Sunucu istek kayıtları kısa süre tutulup atılır. Çökme ve analitik verisi Google tarafından Firebase'in kendi saklama ayarlarına göre tutulur.

Bir hesabı ve ona bağlı her şeyi silmek için, sunulduğu yerde uygulama içindeki silme seçeneğini kullanın ya da aşağıdaki adrese yazın. Her şeyi cihazınızda saklayan bir uygulamada, kaldırmak her şeyi siler; başka bir yerde silinecek bir şey yoktur.

Haklarınız

Yaşadığınız yere göre — AB ve Birleşik Krallık'ta GDPR, Türkiye'de KVKK ve başka yerlerdeki benzer yasalar — hakkınızda hangi veriyi tuttuğumuzu sorabilir, bir kopyasını isteyebilir, düzeltilmesini ya da silinmesini isteyebilir, bir kullanıma itiraz edebilir veya veri koruma kurumunuza şikâyette bulunabilirsiniz. Aşağıdaki adrese yazın; yasanın tanıdığı süre içinde yanıtlarız. Bir uygulama hakkınızda hiçbir şey tutmuyorsa dürüst yanıt, gönderilecek bir şey olmadığıdır.

Değişiklikler

Bu politika değişirse yeni sürüm, üstünde yeni bir yürürlük tarihiyle bu adreste yayımlanır. Önemli değişiklikler ayrıca etkiledikleri uygulamalarda gösterilir.

Yürürlük: 14 Eylül 2026

İletişim

Gizlilikle ilgili sorular ya da yukarıdaki bölüm kapsamında bir talep: [email protected]