GİZLİLİK POLİTİKASI (AYDINLATMA METNİ)
Son Güncelleme: 19 Haziran 2026 | Yürürlük Tarihi: 19 Haziran 2026
1. VERİ SORUMLUSU VE GİRİŞ
6698 Sayılı Kişisel Verilerin Korunması Kanunu ("KVKK") ve ilgili mevzuat uyarınca, Codenzi Labs ("biz", "bize" veya "bizim") olarak "Veri Sorumlusu" sıfatıyla, kullanıcılarımızın gizliliğine ve kişisel verilerinin korunmasına önem veriyoruz.
Bu Gizlilik Politikası, StudiCat mobil uygulamasını ("Uygulama") kullandığınızda kişisel bilgilerinizin nasıl toplandığını, işlendiğini, saklandığını ve korunduğunu açıklamaktadır.
Veri Sorumlusu: Codenzi Labs
E-posta: codenzilabs@gmail.com
13-17 Yaş Arası Kullanıcılar İçin Önemli Uyarı:
Uygulamamız 13 yaş ve üzeri kullanıcılara yöneliktir. 13 yaşın altındaki çocuklardan bilerek veri toplamıyoruz. 13-17 yaş arasındaysanız bu politikayı bir ebeveyn veya yasal vasinizle birlikte okumanızı tavsiye ederiz.
2. TOPLANAN KİŞİSEL VERİLER
2.1. Doğrudan Sağladığınız Bilgiler
- Kimlik ve İletişim: Ad, soyad, kullanıcı adı, e-posta adresi.
- Profil Tercihleri: Cinsiyet (isteğe bağlı), doğum tarihi (iOS'ta isteğe bağlı), öğrenme hedefi, hazırlandığınız sınav türü, avatar stili ve karakter tohumu.
- Üçüncü Taraf Kimlik Bilgisi: Google veya Apple ile giriş yapılması hâlinde ilgili platformdan gelen ad, soyad ve e-posta bilgisi.
2.2. Otomatik Olarak Toplanan Veriler
Kullanım ve Etkinlik Verileri
- Çalışma Oturumları: Pomodoro / odak seanslarının başlangıç-bitiş zamanları ve süresi (saniye cinsinden).
- Günlük Aktivite Takibi: Günlük ziyaret zaman damgaları, odak dakikaları, tamamlanan görev ve questler.
- Akademik Performans: Çözülen soru sayısı, doğru/yanlış oranı, deneme sınavı sonuçları, konu bazlı başarı oranları, haftalık performans raporları.
- İçerik Etkileşimi: Tamamlanan atölyeler/kurslar, kaydedilen içerikler, podcast dinleme sayıları, oluşturulan zihin haritaları.
- Sosyal Aktivite: Takip edilen ve takipçi listeleri, kullanıcı arama geçmişi, liderlik tablosu sıralaması.
- Başarı ve Rozetler: Kazanılan rozetler, streak, bağlılık puanı (engagement score), zorluk faktörü.
Cihaz ve Teknik Veriler
- Anonim Cihaz Tanımlayıcı: Cihaza özgü kimlik SHA-256 ile hashlenerek (geri döndürülemez biçimde) saklanır; ham cihaz kimliğiniz saklanmaz.
- Cihaz Bilgisi: Marka, model, işletim sistemi sürümü, uygulama sürümü ve derleme numarası.
- Ağ Durumu: İnternet bağlantısı tipi — yalnızca içerik kalitesini optimize etmek için.
- Bildirim Tokeni: Firebase Cloud Messaging (FCM) tokeni, anlık bildirim gönderilebilmesi için saklanır.
Kilitlenme ve Hata Verileri
- Firebase Crashlytics: Uygulama çöküşleri ve hataları otomatik olarak raporlanır. Bu raporlar kişisel içerik verisi barındırmaz; yalnızca hata türü, yığın izi ve cihaz bilgisini içerir. Geliştirme modunda devre dışıdır.
2.3. Yapay Zeka (AI) Hizmetlerine Gönderilen Veriler
Soru çözme, atölye oluşturma, podcast üretimi, zihin haritası ve motivasyon koçu özellikleri Google Gemini API'si aracılığıyla çalışır. Bu özellikler kullanıldığında aşağıdaki veriler Google'ın sunucularına iletilir:
- Çalışma konunuz, sınav türünüz ve zorluk düzeyiniz.
- Soru metni ve seçenekler (soru çözme özelliğinde).
- Önceki konuşma özeti (AI Koç bağlamı).
- Dil tercihiniz (Türkçe / İngilizce).
Veri Koruma Önlemi: AI yanıtlarında telefon numaraları, e-posta adresleri ve 11 haneli sayısal diziler otomatik olarak maskelenir. Ham mesaj içerikleri üçüncü taraf sunucularda kalıcı olarak saklanmaz.
Yasal Uyarı: AI tarafından üretilen içerikler tavsiye niteliğindedir. StudiCat, belirli bir sınav puanı veya başarı sonucu garanti etmez.
2.4. Kullanıcı Tarafından Yüklenen İçerikler
- Fotoğraf / Görüntü: Profil fotoğrafı veya soru çözme özelliği için kamera ya da galeriden seçilen görseller Firebase Storage'a yüklenir.
- Metin İçerikleri: Oluşturduğunuz zihin haritaları, kaydedilen çözümler ve notlar.
- Ses Dosyaları: AI tarafından oluşturulan podcast içerikleri Firebase Storage'da saklanır.
2.5. Herkese Açık Profil Verileri
Sosyal özellikler ve liderlik tablosu nedeniyle aşağıdaki bilgileriniz diğer kullanıcılar tarafından görülebilir:
- Kullanıcı adı ve avatar.
- Hazırlandığınız sınav kategorisi.
- Premium üyelik durumu.
- Takipçi / takip edilen sayıları.
- Toplam çözülen soru, net skoru, streak, bağlılık puanı ve rozetler.
Dikkat: Herkese açık profil verileri uygulama içinde aranabilir ve görüntülenebilir. Bu bilgilerin görünür olmasını istemiyorsanız hesabınızı silebilirsiniz.
3. VERİLERİN İŞLENME AMAÇLARI VE HUKUKİ DAYANAK
| İşleme Amacı |
İlgili Veri Kategorisi |
Hukuki Dayanak (KVKK m.5) |
| Hesap oluşturma ve kimlik doğrulama | Ad, e-posta, şifre, giriş yöntemi | Sözleşmenin ifası (m.5/2-c) |
| Kişiselleştirilmiş öğrenme hizmeti | Akademik performans, hedef, zorluk faktörü | Sözleşmenin ifası (m.5/2-c) |
| AI destekli içerik üretimi | Konu, sınav türü, soru içeriği | Sözleşmenin ifası (m.5/2-c) |
| Sosyal özellikler ve liderlik tablosu | Herkese açık profil verileri, takip listesi | Sözleşmenin ifası (m.5/2-c) / Meşru menfaat (m.5/2-f) |
| Abonelik ve ödeme yönetimi | Premium durumu, abonelik geçmişi | Sözleşmenin ifası (m.5/2-c) |
| Anlık bildirim gönderimi | FCM tokeni | Açık rıza (m.5/1) |
| Güvenlik doğrulaması (App Check) | Anonim cihaz doğrulama verisi | Meşru menfaat (m.5/2-f) |
| Uygulama stabilitesi (Crashlytics) | Kilitlenme raporu | Meşru menfaat (m.5/2-f) |
| Kullanım analizi ve hizmet geliştirme | Firebase Analytics olayları | Meşru menfaat (m.5/2-f) |
| iOS uygulama takibi (ATT) | IDFA — yalnızca onay verilirse | Açık rıza (m.5/1) |
Otomatik Karar Verme: Uygulama, akademik performansınıza dayalı olarak zorluk faktörünüzü otomatik ayarlar ve kişiselleştirilmiş içerik önerileri sunar. Bu işlem tamamen tavsiye niteliğindedir ve istediğiniz zaman hesabınızı silerek sona erdirebilirsiniz.
4. TALEP EDİLEN İZİNLER
Android İzinleri
- INTERNET: Veri senkronizasyonu ve AI hizmetleri için ağ erişimi.
- POST_NOTIFICATIONS: Anlık bildirim (Android 13+, kullanıcı onayı gerekir).
- WAKE_LOCK: Odak seansı sırasında ekranın kararmamasını önleme.
- FOREGROUND_SERVICE / MEDIA_PLAYBACK: Arka planda podcast oynatma.
iOS İzinleri
- Kamera: Soru fotoğrafı çekip AI ile çözmek için.
- Fotoğraf Kütüphanesi: Galeriden içerik veya profil fotoğrafı seçmek için.
- Bildirimler: Çalışma hatırlatıcıları ve güncellemeler için.
- Uygulama Takibi (ATT): Kullanım istatistikleri; onay vermemek işlevselliği etkilemez.
- Arka Plan / Uzak Bildirim: Anlık bildirim alınabilmesi için.
5. ÜÇÜNCÜ TARAF HİZMETLER VE VERİ AKTARIMI
| Hizmet Sağlayıcı |
SDK / Servis |
Amaç ve Aktarılan Veri |
Konum |
| Google LLC | Firebase Authentication | E-posta, OAuth tokeni — kimlik doğrulama | ABD / AB |
| Google LLC | Cloud Firestore | Tüm kullanıcı verileri, aktivite, sosyal bağlantılar | ABD / AB |
| Google LLC | Firebase Storage | Yüklenen görseller ve podcast ses dosyaları | ABD / AB |
| Google LLC | Cloud Functions | AI işlemleri, bildirim, silme, moderasyon | ABD / AB |
| Google LLC | Firebase Messaging | FCM tokeni — anlık bildirim | ABD / AB |
| Google LLC | Firebase Analytics | Anonim kullanım istatistikleri | ABD / AB |
| Google LLC | Firebase Crashlytics | Kilitlenme raporu (kişisel içerik verisi yok) | ABD / AB |
| Google LLC | Firebase App Check | Yetkisiz API erişimini engelleme — kişisel veri aktarılmaz | ABD / AB |
| Google LLC | Gemini API | Soru, konu, sınav türü — AI içerik üretimi | ABD / AB |
| RevenueCat Inc. | purchases_flutter | Abonelik durumu ve satın alım geçmişi. Kart bilgisi tarafımızca görülmez. | ABD |
| Apple Inc. | Sign in with Apple | Ad, e-posta — kimlik doğrulama | ABD |
| Google LLC | Google Sign-In | Ad, e-posta — kimlik doğrulama | ABD / AB |
Verileriniz Türkiye dışına (ABD ve AB) aktarılmaktadır. Uygulamayı kullanarak bu aktarımı kabul etmiş sayılırsınız.
6. VERİ SAKLAMA
Bulut Depolama
- Firestore: Kullanıcı profili, aktivite kayıtları, öğrenme verileri, sosyal bağlantılar — hesap aktif olduğu sürece.
- Firebase Storage: Yüklenen görseller ve podcast dosyaları — hesap aktif olduğu sürece.
Yerel Depolama (Cihaz Üzerinde)
- Hive Veritabanı: Kaydedilen çözümler, hafif yerel önbellek — hassas kişisel veri içermez.
- Shared Preferences: Uygulama tercihleri ve küçük ayar değerleri.
- Kimlik doğrulama tokenleri Firebase Auth SDK tarafından sistem güvenli deposunda yönetilir.
7. HESAP SİLME VE VERİ KALDIRILMASI
Hesabınızı sildiğinizde tüm kişisel verileriniz en geç 30 gün içinde sistemlerimizden kalıcı olarak kaldırılır.
- Uygulama üzerinden: Ayarlar > Hesabı Sil
- E-posta ile: codenzilabs@gmail.com — "Hesap Silme Talebi" konusuyla.
8. VERİ GÜVENLİĞİ
- Veriler Firebase altyapısında aktarım (TLS) ve depolama sırasında şifrelenir.
- Cihaz kimliği SHA-256 ile hashlenerek geri döndürülemez biçimde saklanır.
- Firebase App Check ile yalnızca yetkili uygulama kopyaları API'ye erişebilir.
- Firestore güvenlik kuralları ile verilerinize yalnızca kendi hesabınız üzerinden erişilebilir.
- AI promptlarında telefon numarası ve e-posta otomatik maskeleme uygulanır.
9. KVKK KAPSAMINDAKİ HAKLARINIZ
KVKK'nın 11. maddesi uyarınca:
- Kişisel verilerinizin işlenip işlenmediğini öğrenme.
- İşlenen veriler hakkında bilgi talep etme.
- İşleme amacını ve amaca uygunluğu öğrenme.
- Verilerin aktarıldığı üçüncü tarafları öğrenme.
- Eksik veya yanlış verilerin düzeltilmesini isteme.
- Verilerin silinmesini veya yok edilmesini isteme.
- İşleme itiraz etme ve zararın giderilmesini talep etme.
Talepleriniz en geç 30 gün içinde ücretsiz yanıtlanır. Başvuru için: codenzilabs@gmail.com
10. ÇEREZLER VE İZLEME TEKNOLOJİLERİ
- Firebase Analytics Oturum Tanımlayıcısı: Anonim kullanım analizi için.
- iOS IDFA: Yalnızca ATT izni verilmesi durumunda kullanılır.
- Hive / Shared Preferences: Cihazda yerel tercih saklama; sunucuya iletilmez.
11. ÇOCUKLARIN GİZLİLİĞİ
Uygulamamız 13 yaşın altındaki çocuklara yönelik değildir ve bu çocuklardan bilerek kişisel veri toplamıyoruz. Böyle bir durumdan haberdar olursak ilgili verileri derhal sileriz.
12. POLİTİKA DEĞİŞİKLİKLERİ
Bu politika periyodik olarak güncellenebilir. Önemli değişiklikler uygulama içi bildirim veya e-posta ile duyurulur. Değişiklikten sonra uygulamayı kullanmaya devam etmeniz güncel politikayı kabul ettiğiniz anlamına gelir.
13. İLETİŞİM
PRIVACY POLICY
Last Updated: June 19, 2026 | Effective Date: June 19, 2026
1. DATA CONTROLLER & INTRODUCTION
Codenzi Labs ("we", "us", or "our") acts as the Data Controller and is committed to protecting the privacy and personal data of our users.
This Privacy Policy explains how we collect, process, store, and protect your personal information when you use the StudiCat mobile application ("App").
Data Controller: Codenzi Labs
Email: codenzilabs@gmail.com
Important Notice for Users Aged 13–17:
Our App is intended for users aged 13 and above. We do not knowingly collect data from children under 13. If you are between 13–17, we recommend reading this policy together with a parent or legal guardian.
2. PERSONAL DATA WE COLLECT
2.1. Information You Provide Directly
- Identity & Contact: First name, last name, username, email address.
- Profile Preferences: Gender (optional), date of birth (optional on iOS), learning goal, exam type, avatar style and character seed.
- Third-Party Sign-In: When signing in via Google or Apple, we receive your name and email from those platforms.
2.2. Automatically Collected Data
Usage & Activity Data
- Study Sessions: Start/end timestamps and duration (in seconds) of Pomodoro / focus sessions.
- Daily Activity: Daily visit timestamps, focus minutes, completed tasks and quests.
- Academic Performance: Questions solved, correct/incorrect rates, practice exam results, subject-based success rates, weekly performance reports.
- Content Interaction: Completed workshops/courses, saved content, podcast play counts, created mind maps.
- Social Activity: Following/follower lists, user search history, leaderboard rankings.
- Achievements: Earned badges, streak, engagement score, difficulty factor.
Device & Technical Data
- Anonymous Device Identifier: A device-specific ID is hashed using SHA-256 (irreversible); the raw device ID is never stored.
- Device Info: Brand, model, OS version (Android API level or iOS version), app version and build number.
- Network Status: Connection type (Wi-Fi / mobile data) — used only to optimize content loading quality.
- Notification Token: Firebase Cloud Messaging (FCM) token, stored to enable push notifications.
Crash & Error Data
- Firebase Crashlytics: App crashes and errors are automatically reported. These reports contain no personal content — only error type, stack trace, and device info. Disabled in debug mode.
2.3. Data Sent to AI Services
AI-powered features (question solving, workshop generation, podcast creation, mind maps, motivation coach) are powered by the Google Gemini API. When using these features, the following data is sent to Google's servers:
- Your study topic, exam type, and difficulty level.
- Question text and answer choices (for the question solver).
- Previous conversation summary (AI Coach context).
- Your language preference (Turkish / English).
Privacy Safeguard: Phone numbers, email addresses, and 11-digit numeric sequences are automatically masked in AI responses. Raw message content is not permanently stored on third-party servers.
Legal Notice: AI-generated content is for guidance only. StudiCat does not guarantee any specific exam score or academic outcome.
2.4. User-Generated Content
- Photos / Images: Photos taken from camera or selected from gallery for profile pictures or question solving are uploaded to Firebase Storage.
- Text Content: Mind maps you create, saved solutions, and notes.
- Audio Files: AI-generated podcast content stored in Firebase Storage.
2.5. Publicly Visible Profile Data
Due to social features and the leaderboard, the following information is visible to other users:
- Username and avatar.
- Exam category you are preparing for.
- Premium membership status.
- Follower / following counts.
- Total questions solved, net score, streak, engagement score, and badges.
Note: Public profile data is searchable and viewable by other users within the app. If you do not want this information visible, you may delete your account.
3. PURPOSES & LEGAL BASIS FOR PROCESSING
| Purpose |
Data Category |
Legal Basis |
| Account creation & authentication | Name, email, password, login method | Performance of contract |
| Personalized learning service | Academic performance, goal, difficulty factor | Performance of contract |
| AI-powered content generation | Topic, exam type, question content | Performance of contract |
| Social features & leaderboard | Public profile data, follow list | Performance of contract / Legitimate interest |
| Subscription & payment management | Premium status, purchase history | Performance of contract |
| Push notifications | FCM token | Consent |
| Security verification (App Check) | Anonymous device attestation | Legitimate interest |
| App stability (Crashlytics) | Crash report | Legitimate interest |
| Usage analytics & improvement | Firebase Analytics events | Legitimate interest |
| iOS App Tracking (ATT) | IDFA — only if consent granted | Consent |
Automated Decision-Making: The app automatically adjusts your difficulty factor based on academic performance and offers personalized content recommendations. This is purely advisory and carries no legal consequences. You may stop this by deleting your account at any time.
4. PERMISSIONS REQUESTED
Android Permissions
- INTERNET: Network access for data sync and AI services.
- POST_NOTIFICATIONS: Push notifications (Android 13+, requires user consent).
- WAKE_LOCK: Prevents screen from turning off during focus sessions.
- FOREGROUND_SERVICE / MEDIA_PLAYBACK: Background podcast audio playback.
iOS Permissions
- Camera: To photograph questions and solve them with AI.
- Photo Library: To select images for content or profile photos.
- Notifications: Study reminders and important updates.
- App Tracking (ATT): For usage statistics; declining does not affect app functionality.
- Background / Remote Notification: To receive push notifications.
5. THIRD-PARTY SERVICES & DATA TRANSFERS
| Provider |
SDK / Service |
Purpose & Data Transferred |
Location |
| Google LLC | Firebase Authentication | Email, OAuth token — authentication | US / EU |
| Google LLC | Cloud Firestore | All user data, activity, social connections | US / EU |
| Google LLC | Firebase Storage | Uploaded images and podcast audio files | US / EU |
| Google LLC | Cloud Functions | AI processing, notifications, deletion, moderation | US / EU |
| Google LLC | Firebase Messaging | FCM token — push notifications | US / EU |
| Google LLC | Firebase Analytics | Anonymous usage statistics | US / EU |
| Google LLC | Firebase Crashlytics | Crash report (no personal content) | US / EU |
| Google LLC | Firebase App Check | Unauthorized API access prevention — no personal data | US / EU |
| Google LLC | Gemini API | Question, topic, exam type — AI content generation | US / EU |
| RevenueCat Inc. | purchases_flutter | Subscription status and purchase history. Payment card details are never seen by us. | US |
| Apple Inc. | Sign in with Apple | Name, email — authentication | US |
| Google LLC | Google Sign-In | Name, email — authentication | US / EU |
Your data may be transferred outside your country of residence (primarily to the US and EU). By using the App, you consent to such transfers.
6. DATA RETENTION
Cloud Storage
- Firestore: User profile, activity logs, learning data, social connections — retained while your account is active.
- Firebase Storage: Uploaded images and podcast files — retained while your account is active.
On-Device Local Storage
- Hive Database: Saved solutions in a lightweight local cache; contains no sensitive personal data.
- Shared Preferences: App settings and small preference values.
- Authentication tokens are managed by the Firebase Auth SDK in the secure system keystore; the app does not directly access them.
7. ACCOUNT DELETION & DATA REMOVAL
When you delete your account, all your personal data will be permanently removed from our systems within 30 days.
8. DATA SECURITY
- Data is encrypted in transit (TLS) and at rest on Firebase infrastructure.
- Device identifiers are irreversibly hashed using SHA-256.
- Firebase App Check (Play Integrity / DeviceCheck) ensures only authorized app instances can access our APIs.
- Firestore security rules restrict data access to the account owner only.
- AI prompts automatically mask phone numbers and email addresses.
In the event of a data breach, affected users will be notified within the legally required timeframe.
9. YOUR PRIVACY RIGHTS
Depending on your jurisdiction, you may have the right to:
- Know whether your personal data is being processed.
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your personal data.
- Object to or restrict processing.
- Know which third parties your data has been shared with.
- Data portability (where applicable under GDPR).
To exercise any of these rights, contact us at codenzilabs@gmail.com. We will respond within 30 days, free of charge.
10. COOKIES & TRACKING TECHNOLOGIES
- Firebase Analytics Session Identifier: Anonymous session ID for usage analysis.
- iOS IDFA (Advertising Identifier): Used only if App Tracking Transparency (ATT) consent is granted; disabled otherwise.
- Hive / Shared Preferences: Local on-device preference storage; not transmitted to any server.
11. CHILDREN'S PRIVACY
Our App is not directed to children under 13 and we do not knowingly collect personal data from them. If we become aware that a child under 13 has provided personal data, we will delete it immediately. If you are a parent and believe your child has submitted data, please contact us.
12. CHANGES TO THIS POLICY
This Privacy Policy may be updated periodically. Material changes will be communicated via in-app notification or email. Continued use of the App after changes constitutes acceptance of the updated policy. The "Last Updated" date at the top of this page reflects the most recent revision.
13. CONTACT