Gizlilik Politikası ve Aydınlatma Metni

Yürürlük tarihi: 3 Ağustos 2026

Son güncelleme: 2 Eylül 2026

Bu metin, Takıl mobil uygulamasının kişisel verilerinizi nasıl işlediğini açıklar. 6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) kapsamında aydınlatma yükümlülüğümüzü ve Avrupa Birliği Genel Veri Koruma Tüzüğü (GDPR) kapsamındaki bilgilendirmeyi birlikte karşılar.


1. Veri Sorumlusu

Veri sorumlusu Barbaros Köklü (gerçek kişi)
İletişim destek@takil.app
Uygulama Takıl
Web takil.app

Ayrı bir veri koruma görevlisi (DPO) atanmamıştır; veri koruma ile ilgili tüm başvurular yukarıdaki adrese yapılır.

Takıl bir tüzel kişilik bünyesinde değil, şahsım adına yürütülmektedir. Bu durum değiştiğinde bu metin güncellenecektir.


2. Hangi Verileri İşliyoruz

2.1 Hesap ve kimlik doğrulama

2.2 Profil

Ad, profil fotoğrafı, kısa durum metni ("şu an" metni), biyografi, şehir, ilgi alanı etiketleri, bağlantı/sosyal medya adresleri, katılım amacı ("neden buradayım") ve bildirim tercihleri.

Bu alanların tamamı isteğe bağlıdır; doldurmadığın alanlar işlenmez.

2.3 Konum — nasıl işlediğini bilmen önemli

Takıl kesin konum koordinatlarını saklamaz.

Cihazının konumu, uygulama açıkken yaklaşık 150 metrelik bir ızgara hücresine yuvarlanır ve yalnızca bu hücre numarası (grid_x, grid_y) ile son güncelleme zamanı hesabında tutulur. Yani sunucuda "şu sokakta, şu binada" bilgisi bulunmaz; "şu 150 metrelik karede" bilgisi bulunur.

2.4 Etkinlik ve sosyal etkileşim

Katıldığın etkinlikler ve katılım durumun, etkinliğe giriş (check-in) zamanı, etkinlik sohbetlerindeki mesajların, yorumların, anket oyların, emoji tepkilerin, yüklediğin etkinlik fotoğrafları, beğenilerin, kaydettiğin kişiler ve kayıt notların, karşılıklı eşleşmeler, teşekkür notları ve topladığın puanlar.

2.5 Mesajlaşma

Kişiler arası mesajlarının içeriği, gönderen/alıcı bilgisi ve okunma zamanı.

2.6.1 Birebir Mesajlaşma ve Erişim Sınırı

Kullanıcılar arasındaki özel mesajlar ile kulüp ve etkinlik sohbetleri; etkinliklerin düzenlenmesi, katılımcılar arası iletişimin sürdürülebilmesi ve hizmetin ifası amacıyla (KVKK m. 5/2-c) Almanya'da (Avrupa Birliği) bulunan sunucularımızda saklanır. Bu mesajlar uçtan uca şifreli değildir; aktarım sırasında TLS ile korunur, veritabanında satır düzeyi güvenlik kurallarıyla (RLS) sınırlandırılır.

Veri sorumlusu, mesaj içeriklerini keyfi veya genel amaçla incelemez. Mesaj içeriklerine yalnızca aşağıdaki meşru ve zorunlu hâllerde erişilebilir:

Otomatik içerik filtresi: Gönderilen mesajlar, iletim anında sunucu tarafında otomatik bir içerik filtresinden geçirilir. Bu filtre yasaklı ifadeleri tespit ederek mesajın gönderilmesini engelleyebilir. Filtre otomatik çalışır; mesajın bir kişi tarafından okunması anlamına gelmez.

Mesaj verileri ve bunlara ilişkin işlem kayıtları, Veri Saklama ve İmha Politikamızda belirtilen süreler boyunca saklanır. Yasal saklama sürelerinin dolması, hesabın kapatılması veya geçerli bir silme talebi üzerine verileriniz; altı aylık periyodik imha süreleri dahilinde veya talep hâlinde en geç otuz gün içinde güvenli şekilde silinir, yok edilir ya da anonim hale getirilir.

2.7 Rehber eşleştirme (isteğe bağlı)

Ayrıntısı için bölüm 4'e bakınız.

2.8 Bildirimler

Cihazına ait push bildirim jetonu (token), platform bilgisi (iOS/Android) ve bildirim gönderim durumu. Kayıt sırasında hata oluşursa bu hata kaydı da tutulur.

Bildirim gönderilirken, bildirimde görünen başlık ve metin — mesaj bildirimlerinde gönderenin adı ve mesajın kendisi — bildirimi cihazına ileten servise aktarılır. Bu servis ve bulunduğu ülke Bölüm 5'te listelenmiştir. Cihazının sistem ayarlarından bildirim önizlemesini kapatarak içeriğin kilit ekranında görünmesini engelleyebilirsin; bu ayar bildirimin iletilme yöntemini değiştirmez.

2.9 Güvenlik ve moderasyon

Gönderdiğin şikâyetler, engellediğin kullanıcılar, otomatik içerik filtresinin ürettiği işaretler ve bunların çözüm durumu.

2.10 Teknik teşhis verisi

Uygulama çökerse; çökme yığın izi, cihaz modeli, işletim sistemi sürümü, uygulama sürümü ve çökmeden önceki eylem izleri toplanır. Ayrıca oturumların küçük bir bölümünde (%20) performans ölçümü yapılır. Bu veriler kimliğinle ilişkilendirilmez — kullanıcı kimliğini teşhis sağlayıcımıza göndermiyoruz.

2.11 Bağlantı tıklama istatistiği

Uygulama tanıtım bağlantılarına yapılan tıklamalarda; işletim sistemi, dil, kampanya etiketi ve IP adresinden türetilmiş kaba konum (ülke/bölge/şehir/ilçe) kaydedilir. Bu kayıt kullanıcı hesabıyla ilişkilendirilmez.

2.12 Erişim ve trafik kayıtları (5651)

5651 sayılı Kanun'un 5. maddesi uyarınca yer sağlayıcı sıfatıyla; oturum açma, oturum kapatma ve hesap silme işlemlerindeki bağlantı IP adresi, tarih-saat bilgisi, kullanıcı kimliği ve işlem türü kaydedilir. Bu kayıtlar genel veritabanından izole tutulur, kullanıcı erişimine kapalıdır, yalnızca yetkili adli ve idari mercilerin hukuka uygun talebi hâlinde kullanılır ve yasal saklama süresi olan 1 yıl boyunca muhafaza edilir.

2.13 İşlemediğimiz veriler


3. İşleme Amaçları ve Hukuki Sebepler

Toplama Yöntemi

Kişisel verileriniz; mobil uygulama üzerinden, elektronik ortamda, kısmen otomatik yollarla toplanır. Kaynakları şunlardır: (i) doğrudan sizin beyanınız (profil alanları, mesaj içerikleri, etkinlik katılımı), (ii) uygulamayı kullanmanız sırasında cihazınızın ürettiği veriler (yaklaşık konum ızgarası, bildirim jetonu, çökme kayıtları), (iii) Apple ve Google ile giriş sırasında bu sağlayıcılardan gelen kimlik bilgileri, (iv) izin vermeniz hâlinde cihazınızın rehberinden üretilen özetler.

Amaç İşlenen veri KVKK m.5 dayanağı GDPR m.6 dayanağı
Hesap oluşturma ve oturum yönetimi Kimlik doğrulama verileri Sözleşmenin kurulması/ifası m.6/1-b Sözleşme
Profilin gösterilmesi Profil verileri Sözleşmenin ifası m.6/1-b Sözleşme
Etkinlik keşfi, katılım, sohbet Etkinlik ve etkileşim verileri Sözleşmenin ifası m.6/1-b Sözleşme
Yakındaki etkinlikler ve harita Izgara konumu Açık rıza m.6/1-a Rıza
Rehber eşleştirme Telefon/e-posta özetleri Açık rıza m.6/1-a Rıza
Bildirim gönderimi Push jetonu Açık rıza m.6/1-a Rıza
18 yaş sınırının denetimi Yaş onayı zamanı Hukuki yükümlülük · Meşru menfaat m.6/1-c · m.6/1-f
Güvenlik, kötüye kullanım önleme Şikâyet, engelleme, moderasyon Meşru menfaat m.6/1-f Meşru menfaat
Hata giderme ve kararlılık Teşhis verisi Meşru menfaat m.6/1-f Meşru menfaat

Açık rızaya dayanan işlemeleri dilediğin an durdurabilirsin; ilgili özelliği Ayarlar'dan kapatman yeterlidir. Rızanın geri alınması, geri alınmadan önceki işlemenin hukuka uygunluğunu etkilemez.


4. Rehber Eşleştirme — Tam ve Açık Anlatım

Bu özellik yalnızca sen başlattığında çalışır ve istediğin an kapatabilirsin. Nasıl işlediğini eksiksiz anlatıyoruz:

1. Rehberindeki telefon numaraları ve e-posta adresleri cihazının içinde, SHA-256 algoritmasıyla özetlenir (hash'lenir).

2. Numaraların ve e-posta adreslerinin kendisi hiçbir zaman sunucularımıza gönderilmez.

3. Ancak eşleştirmenin yapılabilmesi için bu özetler sunucuya gönderilir. Sunucu, gelen özetleri yalnızca kayıtlı kullanıcıların kendi kayıtlı özetleriyle karşılaştırır ve eşleşenleri sana döndürür.

4. Gönderdiğin özetler sunucuda saklanmaz. Karşılaştırma bittiğinde sorguyla birlikte ortadan kalkar; kalıcı bir kayıt oluşturulmaz.

5. Kendi telefon numaranın ve e-posta adresinin özeti, başkalarının seni bulabilmesi için hesabında saklanır.

6. Profilinde "rehberde bulunabilirlik" ayarını kapatırsan, senin özetlerin eşleştirmeye hiç dahil edilmez.

Dürüst olmamız gereken teknik bir nokta: SHA-256 özeti geri döndürülemez bir işlem olsa da, telefon numarası gibi kısa ve tahmin edilebilir bir veri için özet anonim sayılmaz. Bu nedenle bu özetleri anonim veri gibi değil, kişisel veri olarak sınıflandırıyor ve KVKK/GDPR koruması altında işliyoruz.

Rehberinizdeki kişiler Takıl kullanıcısı olmayabilir ve bu işlemeye rıza göstermemiş olabilir. Bu nedenle: eşleşmeyen özetler hiçbir şekilde kaydedilmez, kullanılmaz veya profil oluşturmak için işlenmez.

Rehberinizdeki kişilere ayrıca bilgilendirme yapılamamaktadır; elimizde yalnızca geri döndürülemez özetler bulunduğu ve bu kişilere ulaşacak hiçbir iletişim bilgisi tutulmadığı için bu, GDPR m.14/5-b anlamında orantısız çaba gerektirmektedir. Bu nedenle eşleşmeyen özetler kaydedilmez, kullanılmaz ve hiçbir profil oluşturmak için işlenmez.


5. Üçüncü Taraf Hizmet Sağlayıcılar

Sağlayıcı Ne için Ne aktarılıyor Veri konumu
Supabase (DPA & Güvenlik) Veritabanı, dosya depolama, kimlik doğrulama Uygulama verilerinin tamamı Almanya (Avrupa Birliği)
Apple (Apple ile Giriş, APNs) Kimlik doğrulama, iOS bildirimleri E-posta, UID, bildirim jetonu ABD / küresel
Google (Google ile Giriş) Kimlik doğrulama E-posta, UID ABD / küresel
Google Maps Harita gösterimi Harita görüntüleme istekleri ABD / küresel
Google Places Etkinlik oluştururken mekân arama Yazdığın mekân arama metni ABD / küresel
Expo / EAS Uygulama dağıtımı ve bildirim iletimi Push jetonu, bildirim içeriği ABD
Sentry Çökme ve hata teşhisi Çökme izi, cihaz/OS/sürüm bilgisi — kimliğinle ilişkilendirilmeden Almanya (alım sunucusu)
Meta / Instagram Uygulama içinde gösterilen Takıl Instagram akışı Akışın çekilmesi için yapılan istekler ABD / küresel
Vercel Bu hukuki sayfaların yayını Sayfa görüntüleme istekleri Küresel
Anthropic (Claude) Geliştirme ve bakım Teknik sorgu sonuçları ABD
Google (Gemini) Geliştirme ve bakım Teknik sorgu sonuçları ABD

Bu sağlayıcılar veri işleyen sıfatıyla, yalnızca burada belirtilen amaçlarla ve talimatlarımız doğrultusunda hareket eder. Hiçbiri verilerinizi kendi amaçları için kullanma yetkisine sahip değildir.

Geliştirme ve bakım erişimi

Uygulamanın teknik bakımı, şema değişiklikleri ve hata ayıklaması sırasında yapay zekâ destekli geliştirme araçları kullanılır. Bu araçlarla veritabanına yapılan sorguların sonuçları, aracı sağlayan şirketin yurt dışındaki sunucularında işlenir.

Bu sorgular; ad, e-posta, telefon, biyografi ve mesaj içeriği gibi alanları dışarıda bırakan teknik görünümler üzerinden yapılır. Erişim yalnızca veri sorumlusunun talimatıyla gerçekleşir ve kullanıcı profilleme, pazarlama veya reklam amacıyla kullanılmaz. Sağlayıcıların ticari kullanım şartları uyarınca bu veriler yapay zekâ modellerinin eğitiminde kullanılmaz.


6. Yurt Dışına Aktarım

Kullanıcı verileriniz Almanya'daki (Avrupa Birliği) güvenli sunucularda barındırılmaktadır. Bölüm 5'te belirtilen bazı hizmet sağlayıcılar Türkiye ve Avrupa Ekonomik Alanı dışında yerleşiktir.

KVKK açısından: Verilerin Türkiye dışındaki sunuculara yazılması, Kanun'un 9. maddesi anlamında yurt dışına aktarımdır. 2/3/2024 tarihli 7499 sayılı Kanun'la değişen 9. madde bu aktarımı sırasıyla üç yola bağlar: yeterlilik kararı (m.9/1), uygun güvenceler (m.9/4) ve yalnızca arızi hâllerde geçerli istisnalar (m.9/6).

Verileriniz, uluslararası bilgi güvenliği standardına (ISO 27001) sahip bulut altyapı sağlayıcımıza, gerekli veri güvenliği tedbirleri (TLS, satır düzeyi güvenlik) alınarak aktarılmakta ve barındırılmaktadır. Aktarım, 6698 sayılı Kanun'un 9. maddesi kapsamındadır.

Aktarımın muhtemel riskleri: verinin bulunduğu ülkenin hukuku Türkiye'den farklıdır, o ülkenin yetkili makamları kendi mevzuatı uyarınca veriye erişim talep edebilir ve haklarınızı kullanırken yabancı bir hukuk düzenine başvurmanız gerekebilir.

GDPR açısından: Ana barındırma konumumuz Almanya (Avrupa Birliği), Avrupa Ekonomik Alanı içindedir; bu nedenle temel veri barındırma bakımından üçüncü ülkeye aktarım söz konusu değildir. AEA dışına yapılan aktarımlarda: Amerika Birleşik Devletleri için Avrupa Komisyonu'nun 10 Temmuz 2023 tarihli EU-US Data Privacy Framework yeterlilik kararı bulunmaktadır ve sağlayıcı bu çerçeveye kayıtlıysa aktarım bu karara dayanır. Kayıtlı olmayan sağlayıcılarda aktarım, Komisyon'un standart sözleşme hükümlerine (SCC / DPA) dayanır. Bu belgelerin bir kopyasını destek@takil.app adresinden talep edebilirsiniz.


7. Saklama Süreleri

Veri Süre
Hesap ve profil verileri Hesap açık kaldığı sürece
Etkinlik katılımı ve sohbetler Hesap açık kaldığı sürece
Mesajlar Hesap açık kaldığı sürece
Izgara konumu Yalnızca en son hücre tutulur; geçmiş konum kaydı oluşturulmaz
Rehberden gönderilen özetler Saklanmaz — sorgu bitince silinir
Kendi telefon/e-posta özetin Hesap açık kaldığı sürece
Push jetonu Bildirimleri kapatana veya hesabı silene kadar
Teşhis (çökme) verisi Sentry'nin saklama süresi boyunca (90 güne kadar)
Şikâyet ve moderasyon kayıtları Hesap silinse dahi, hukuki yükümlülük (KVKK m.5/2-e, 5651) ve kötüye kullanımın önlenmesi amacıyla makul bir süre
Erişim ve Trafik Logları 5651 sayılı Kanun m.5/3 uyarınca 1 yıl

Hesabını sildiğinde, Ayarlar > Hesabı Sil adımıyla profil ve içerik verilerin ilişkili tüm kayıtlarla birlikte kalıcı olarak derhal silinir. Bu işlem geri alınamaz.

Bahsi geçen saklama ve imha hususları Veri Saklama ve İmha Politikamız metninde ayrıca ve detaylıca düzenlenmiştir.


8. Haklarınız

KVKK m.11 kapsamındaki haklarınız

Veri sorumlusuna başvurarak aşağıdaki taleplerde bulunabilirsiniz:

1. Kişisel verinizin işlenip işlenmediğini öğrenme

2. İşlenmişse buna ilişkin bilgi talep etme

3. İşlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme

4. Yurt içinde veya yurt dışında verilerin aktarıldığı üçüncü kişileri bilme

5. Eksik veya yanlış işlenmiş verilerin düzeltilmesini isteme

6. Kanun'un 7. maddesindeki şartlar çerçevesinde silinmesini veya yok edilmesini isteme

7. Düzeltme, silme ve yok etme işlemlerinin, verilerin aktarıldığı üçüncü kişilere bildirilmesini isteme

8. Verilerin münhasıran otomatik sistemlerle analiz edilmesi suretiyle aleyhinize bir sonuç ortaya çıkmasına itiraz etme

9. Kanuna aykırı işleme sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme

GDPR kapsamındaki haklarınız

Erişim (m.15), düzeltme (m.16), silinme (m.17), işlemenin kısıtlanması (m.18), veri taşınabilirliği (m.20), itiraz (m.21) ve otomatik karar almaya tabi olmama (m.22) haklarına sahipsiniz. Ayrıca yetkili denetim makamına şikâyette bulunma hakkınız saklıdır.


9. Başvuru Usulü

Haklarınıza ilişkin taleplerinizi destek@takil.app adresine iletebilirsiniz.

Veri Sorumlusuna Başvuru Usul ve Esasları Hakkında Tebliğ uyarınca başvurunuzu ayrıca şu yollarla da yapabilirsiniz:

Başvurunuzda ad-soyad, imza (yazılı başvuruda), T.C. kimlik numarası (yabancılar için uyruk ve pasaport numarası), tebligata esas adres, varsa telefon ve e-posta ile talep konusu yer almalıdır.

Başvurularınız, talebin niteliğine göre en kısa sürede ve her hâlükârda en geç OTUZ (30) GÜN içinde ücretsiz olarak sonuçlandırılır. Yalnızca işlemin ayrıca bir maliyet gerektirmesi hâlinde, Kurul tarafından belirlenen tarifedeki ücret alınabilir. Başvurunun bizim hatamızdan kaynaklanması hâlinde alınan ücret iade edilir. Cevabımız size yazılı olarak veya elektronik ortamda bildirilir.

Başvurunuzun reddedilmesi, verdiğimiz cevabı yetersiz bulmanız veya süresinde cevap verilmemesi hâllerinde; cevabı öğrendiğiniz tarihten itibaren 30 gün ve her hâlde başvuru tarihinden itibaren 60 gün içinde Kişisel Verileri Koruma Kurulu'na şikâyette bulunabilirsiniz. Kanun'un 14. maddesi uyarınca, önce bize başvurmadan doğrudan Kurul'a şikâyet yoluna gidilemez.


10. 18 Yaş Sınırı

Takıl 18 yaş ve üzeri kullanıcılar içindir. Kayıt sırasında 18 yaş beyanı alınır ve beyanın zamanı kaydedilir. 18 yaşından küçük olduğu tespit edilen hesaplar kapatılır ve verileri silinir.

18 yaşından küçük bir kişiye ait veri işlediğimizi düşünüyorsanız lütfen destek@takil.app adresinden bize bildirin.


11. Veri Güvenliği

Hiçbir sistem mutlak güvenlik vaat edemez. Bir güvenlik açığı fark ederseniz lütfen destek@takil.app adresinden bildirin.


12. Veri Sorumluları Sicili (VERBİS)

Kanun'un 16. maddesi kişisel veri işleyen gerçek ve tüzel kişilere Veri Sorumluları Siciline kayıt yükümlülüğü getirmekte, Kurul'a bu yükümlülüğe objektif kriterlerle istisna tanıma yetkisi vermektedir. Takıl, gerçek kişi tarafından işletilmekte olup ana faaliyeti özel nitelikli kişisel veri işlemek değildir; bu nedenle Kurul'un belirlediği istisna kapsamında değerlendirilmektedir. Durumun değişmesi hâlinde kayıt yaptırılacak ve bu metin güncellenecektir.


13. Politika Değişiklikleri

Bu Aydınlatma Metni ve Gizlilik Politikası, mevzuat değişiklikleri veya teknik gereksinimler doğrultusunda güncellenebilir. Güncel metin takil.app/privacy adresinde yayımlandığı tarihte yürürlüğe girer ve sayfa başındaki "Son Güncelleme" tarihi revize edilir.

Kişisel veri işleme amacının değişmesi hâlinde, Aydınlatma Yükümlülüğünün Yerine Getirilmesinde Uyulacak Usul ve Esaslar Hakkında Tebliğ'in 5. maddesi uyarınca veri işleme faaliyetine başlamadan önce ayrıca aydınlatma yapılır; açık rıza gerektiren yeni bir işleme söz konusuysa rıza ayrıca alınır.


14. İletişim

Barbaros Köklü

destek@takil.app

Şikâyet ve acil bildirimlere 48 saat içinde dönüş yapılır. Veri sahibi başvuruları için yasal süre bölüm 9'da belirtilen 30 gündür.

Privacy Policy

Effective date: 3 August 2026

Last updated: September 02, 2026

This document explains how the Takıl mobile application processes your personal data. It serves as our disclosure notice under Turkish Personal Data Protection Law No. 6698 (KVKK) and as our information notice under the EU General Data Protection Regulation (GDPR).


1. Data Controller

Controller Barbaros Köklü (natural person)
Contact destek@takil.app
Application Takıl
Web takil.app

No separate data protection officer (DPO) has been appointed; all data protection enquiries go to the address above.

Takıl is operated by an individual, not a legal entity. This notice will be updated if that changes.


2. What Data We Process

2.1 Account and authentication

2.2 Profile

Name, profile photo, short status text ("now" text), bio, city, interest tags, links/social handles, your stated intent ("why I'm here") and notification preferences.

All of these fields are optional; fields you leave empty are not processed.

2.3 Location — how this actually works matters

Takıl does not store precise coordinates.

While the app is open, your device location is rounded to an approximately 150-metre grid cell, and only that cell identifier (grid_x, grid_y) plus a last-updated timestamp is kept on your account. In other words, the server does not hold "this street, this building" — it holds "somewhere in this 150-metre square".

2.4 Events and social interaction

Events you attend and your attendance status, check-in time, your messages in event chats, comments, poll votes, emoji reactions, event photos you upload, likes, people you save and your notes on them, mutual matches, thank-you notes, and points you earn.

2.5 Messaging

The content of your direct messages, sender/recipient information and read timestamps.

2.6.1 Direct Messages and Limits on Access

Private messages between users, along with club and event chats, are stored on our servers in Germany (European Union) for the purposes of organising events, enabling communication between participants, and performing the service (KVKK Art. 5/2-c). These messages are not end-to-end encrypted; they are protected with TLS in transit and restricted by row-level security (RLS) rules in the database.

The data controller does not review message content arbitrarily. Message contents may only be accessed under the following legitimate and strictly defined circumstances:

Automated content filter: Messages pass through an automated server-side content filter on submission. The filter may detect prohibited expressions and block the message from being sent. It operates automatically and does not mean the message is read by a person.

Message data and the related processing records are retained for the periods set out in our Data Retention and Destruction Policy. Upon expiry of statutory retention periods, closure of the account, or a valid erasure request, your data is securely deleted, destroyed or anonymised within the six-month periodic disposal cycle, or within thirty days at the latest where a request has been made.

2.7 Contacts matching (optional)

See section 4 for the full explanation.

2.8 Notifications

Your device's push notification token, platform (iOS/Android) and delivery status. If registration fails, that error record is also kept.

When a notification is sent, the title and body shown in it — for message notifications, the sender's name and the message itself — are transmitted to the service that delivers the notification to your device. That service and its location are listed in Section 5. You can hide notification previews from your device's system settings; this does not change how the notification is transmitted.

2.9 Safety and moderation

Reports you submit, users you block, flags produced by the automated content filter, and their resolution status.

2.10 Technical diagnostic data

If the app crashes, we collect the crash stack trace, device model, operating system version, app version and the trail of actions preceding the crash. We also measure performance on a small share of sessions (20%). This data is not linked to your identity — we do not send your user identifier to our diagnostics provider.

2.11 Link click statistics

When someone clicks a promotional link for the app, we record the operating system, language, campaign tag and a coarse location derived from the IP address (country/region/city/district). This record is not linked to any user account.

2.12 Access and traffic logs (Law No. 5651)

Pursuant to Article 5 of Law No. 5651 as hosting provider; connection IP address, timestamp, user ID, and action type during login, logout, and account deletion actions are recorded. These records are isolated from the public database, restricted from user access, used strictly upon lawful requests by competent judicial authorities, and retained for the statutory period of 1 year.

2.13 What we do NOT process


3. Purposes and Legal Bases

Purpose Data KVKK Art. 5 basis GDPR Art. 6 basis
Account creation and session management Authentication data Performance of contract Art. 6(1)(b) Contract
Displaying your profile Profile data Performance of contract Art. 6(1)(b) Contract
Event discovery, attendance, chat Event and interaction data Performance of contract Art. 6(1)(b) Contract
Nearby events and map Grid location Explicit consent Art. 6(1)(a) Consent
Contacts matching Phone/email hashes Explicit consent Art. 6(1)(a) Consent
Sending notifications Push token Explicit consent Art. 6(1)(a) Consent
Enforcing the 18+ limit Age confirmation timestamp Legal obligation · Legitimate interest Art. 6(1)(c) · 6(1)(f)
Safety and abuse prevention Reports, blocks, moderation Legitimate interest Art. 6(1)(f) Legitimate interest
Access and traffic logging Login IP address, timestamp, action type Compliance with legal obligation (KVKK Art. 5/2-ç) Art. 6(1)(c) Legal obligation
Debugging and stability Diagnostic data Legitimate interest Art. 6(1)(f) Legitimate interest

You may withdraw consent at any time for consent-based processing by turning the relevant feature off in Settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.


4. Contacts Matching — The Full, Honest Explanation

This feature runs only when you start it and can be turned off at any time. Here is exactly what happens:

1. Phone numbers and email addresses in your address book are hashed on your device using SHA-256.

2. The numbers and email addresses themselves are never sent to our servers.

3. However, in order for matching to work, those hashes are sent to the server. The server compares the incoming hashes only against registered users' own stored hashes and returns the matches to you.

4. The hashes you send are not stored on the server. They disappear with the query once the comparison completes; no persistent record is created.

5. A hash of your own phone number and email address is stored on your account so that others can find you.

6. If you turn off "discoverable via contacts" in your profile, your hashes are excluded from matching entirely.

A technical point we owe you honestly: although SHA-256 is a one-way function, a hash of short and predictable data such as a phone number is not anonymous. We therefore classify these hashes not as anonymous data but as personal data, and process them under KVKK/GDPR protection.

People in your address book may not be Takıl users and may not have consented to this processing. For that reason: hashes that do not match are never recorded, used, or processed to build any profile.


5. Third-Party Service Providers

Provider Purpose What is transferred Data location
Supabase (DPA & Security) Database, file storage, authentication All application data Germany (European Union)
Apple (Sign in with Apple, APNs) Authentication, iOS notifications Email, UID, push token USA / global
Google (Sign in with Google) Authentication Email, UID USA / global
Google Maps Map rendering Map view requests USA / global
Google Places Venue search when creating an event The venue search text you type USA / global
Expo / EAS App distribution and notification delivery Push token, notification content USA
Sentry Crash and error diagnostics Crash trace, device/OS/version info — without linking to your identity Germany (ingest endpoint)
Meta / Instagram The Takıl Instagram feed shown in-app Requests made to fetch the feed USA / global
Vercel Hosting of these legal pages Page view requests Global
Anthropic (Claude) Development and maintenance Technical query results USA
Google (Gemini) Development and maintenance Technical query results USA

These providers act as data processors, solely for the purposes stated here and on our instructions. None of them is authorised to use your data for their own purposes.

Development and maintenance access

AI-assisted development tools are used for technical maintenance, schema changes and debugging. Results of queries run against the database through these tools are processed on the provider's servers outside Türkiye.

Such queries are made through technical views that exclude fields including name, email address, phone number, biography and message content. Access occurs only on the data controller's instruction and is not used for user profiling, marketing or advertising. Under the providers' commercial terms, this data is not used to train AI models.


6. International Transfers

Your user data is hosted on servers in Germany (European Union). Some of the providers listed in section 5 are established outside Türkiye and outside the European Economic Area.

Under KVKK: Writing data to servers outside Türkiye is a transfer abroad within the meaning of Article 9. As amended by Law No. 7499 of 2 March 2024, Article 9 provides three routes in order: an adequacy decision (Art. 9/1), appropriate safeguards (Art. 9/4), and derogations that apply only on an incidental basis (Art. 9/6).

Because our transfer is continuous rather than incidental, the Article 9/6 derogation does not apply to it. We rely on the standard contract published by the Turkish Data Protection Board under Article 9/4(c); the process of signing that contract with our service providers and notifying the Authority within five business days of signature, as required by Article 9/5, is underway. This section will be updated with a date once that is complete.

Risks inherent in the transfer: the law of the country where the data is held differs from Turkish law, its competent authorities may request access to data under their own legislation, and you may need to invoke a foreign legal system to exercise your rights.

Under GDPR: Our primary hosting location in Germany (European Union), is within the European Economic Area, so no third-country transfer arises for core data hosting. For transfers outside the EEA: an adequacy decision exists for the United States — the European Commission's EU-US Data Privacy Framework decision of 10 July 2023 — and where a provider is certified under that framework, the transfer relies on it. For providers that are not certified, transfers rely on the Commission's Standard Contractual Clauses (SCCs / DPA). You may request a copy of these documents at destek@takil.app.


7. Retention Periods

Data Period
Account and profile data For as long as the account exists
Event attendance and chats For as long as the account exists
Messages For as long as the account exists
Grid location Only the most recent cell is kept; no location history is created
Hashes sent from your contacts Not stored — discarded when the query ends
Your own phone/email hash For as long as the account exists
Push token Until you disable notifications or delete your account
Diagnostic (crash) data For Sentry's retention period (up to 90 days)
Reports and moderation records Retained for a reasonable period even after account deletion, for statutory legal compliance (KVKK Art. 5/2-e, Law 5651) and abuse prevention
Access & Traffic Logs 1 year pursuant to Law No. 5651 Article 5/3

When you delete your account via Settings > Delete Account, your profile and content data are permanently erased immediately together with all associated records. This action cannot be undone.

The retention and destruction schedules are further detailed in our Data Retention and Destruction Policy.


8. Your Rights

Your rights under KVKK Article 11

By applying to the data controller you may:

1. Learn whether your personal data is being processed

2. Request information if it has been processed

3. Learn the purpose of processing and whether the data is used in accordance with that purpose

4. Know the third parties to whom your data is transferred, domestically or abroad

5. Request rectification of incomplete or inaccurate data

6. Request erasure or destruction within the conditions of Article 7

7. Request that rectification, erasure and destruction be notified to the third parties to whom the data was transferred

8. Object to an adverse outcome arising from analysis carried out exclusively by automated systems

9. Claim compensation for damages suffered as a result of unlawful processing

Your rights under GDPR

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and not to be subject to automated decision-making (Art. 22). You also retain the right to lodge a complaint with the competent supervisory authority.


9. How to Submit a Request

You may send requests concerning your rights to destek@takil.app.

Under the Turkish Communiqué on the Procedures and Principles of Application to the Data Controller, you may also submit your request:

Your application should state your name and surname, signature (for written applications), Turkish ID number (for foreign nationals, nationality and passport number), an address for notification, your telephone and email if any, and the subject of your request.

Requests are concluded free of charge, as soon as possible and in any event within THIRTY (30) DAYS. A fee under the tariff set by the Turkish Data Protection Board may be charged only where the process incurs an additional cost. If the request arose from an error on our side, any fee charged is refunded. Our response is delivered to you in writing or by electronic means.

If your request is refused or you find the response inadequate, you may lodge a complaint with the Turkish Personal Data Protection Board within 30 days of learning the response and in any event within 60 days of the application date. Under Article 14 of the Law, you may not complain to the Board without first applying to us.

10. Age Limit: 18+

Takıl is intended for users aged 18 and over. During registration, an 18+ age declaration is collected and the timestamp is recorded. Accounts found to belong to users under 18 are closed and their data deleted.

If you believe we are processing data belonging to a person under 18, please notify us at destek@takil.app.


11. Data Security

No system can promise absolute security. If you discover a vulnerability, please report it to destek@takil.app.


12. Data Controllers' Registry (VERBİS)

Article 16 of the Law requires natural and legal persons who process personal data to register with the Data Controllers' Registry, and empowers the Board to grant exemptions on the basis of objective criteria. Takıl is operated by a natural person and its main activity is not the processing of special categories of personal data; it is therefore treated as falling within the exemption set by the Board. Should this change, registration will be completed and this notice updated.


13. Policy Changes

This Privacy Policy and Disclosure Notice may be updated to reflect legislative changes or technical requirements. The current version becomes effective upon publication at takil.app/privacy, and the "Last updated" date at the top of the page will be revised.

If the purpose of data processing changes, additional notice will be provided prior to processing in accordance with Article 5 of the Turkish Communiqué on the Procedures and Principles of Application of the Disclosure Obligation, and explicit consent will be obtained where required by law.


14. Contact

Barbaros Köklü

destek@takil.app

Reports and urgent notifications receive a response within 48 hours. The statutory period for data subject requests is the 30 days stated in section 9.