Privacy Policy
This Privacy Policy explains how FormAI ("we", "us", "our") collects, uses, shares, and safeguards information when you use the FormAI mobile application (the "App"). We designed FormAI to minimize the personal data we collect. Your workout camera feed stays entirely on your device. Food photographs you choose to scan for calories do leave your device — Section 1.3.1 explains exactly what happens to them.
Data Controller (Veri Sorumlusu)
FormAI is operated by Emre Doğan, an individual developer (the "data controller" / veri sorumlusu under KVKK Art. 3). For any privacy question or data-subject request — including access, deletion, or objection — contact support@formai.app. A postal correspondence address is available on request via the same email.
Food photos are the exception, and they are opt-in. If you use the calorie scanner, that one photograph is sent through our server to Anthropic to be analysed. FormAI does not store the image. Section 1.3.1 sets out the detail.
1. Data We Collect
1.1 Account information
- Identifier: Email address, sign-in provider (Google, Apple, or email), and a randomly generated user ID.
- Profile: Display name (if provided), avatar URL (if provided through your sign-in provider).
1.2 Fitness & health data (you provide)
- Body metrics: Height, weight, sex, age range, fitness goal (e.g., lose weight, build muscle), activity level, and any body measurements you log (waist, chest, arm, thigh, hip). These are written to your device first and synced to your account on our servers (Supabase, EU) so your measurement history and progress charts survive a reinstall or a second device. They are used to personalize workout and nutrition plans and to draw your own trends. They are deleted when you delete your account, and removed from the device when you sign out or uninstall the App.
- Workout history: Which plan days you completed and when is synced to your account so your progress survives reinstalls. Detailed session logs (sets, reps, durations) stay on your device.
- Meal log: Foods you log — by photo scan, barcode, or by hand — with their portions, calories, macronutrients and the date and meal they belong to. Stored in your account so your history and daily totals survive a reinstall. Deleted with your account.
1.2.1 AI coach conversations
When you chat with the in-app AI coach, your message and a short profile context block — your first name (as you typed it), age, height, weight, activity level, stated goal, current streak and recent plan progress, and any 30-day weight or waist change — are sent to Anthropic (US) through our server, which generates the coach's reply. A rolling summary of the conversation is sent with later turns so the coach remembers earlier context. We do not send your email address, your account identifier, or any camera data. Anthropic processes this data to return the reply and does not use it to train its models. If you would rather not send this data, do not use the AI coach — every other part of the App works without it.
1.2.2 Reports you file about AI replies
Press and hold any coach reply to report it. Doing so sends us that reply's text, the reason you picked, which screen it came from, and the language it was written in — nothing else, and nothing at all unless you report something. The reply is carried with the report because there is no server-side transcript to look it up in later (see §1.2.1), so a report without it would be a complaint about a sentence that no longer exists anywhere. Reports are readable only by you and by us; they are deleted with your account.
1.3 Camera feed (on-device only)
During pose-detection workouts, the App accesses your device camera to count repetitions and check form. The video stream is processed by Google ML Kit Pose Detection running entirely on your device's CPU/GPU. No frame, image, video, or pose-landmark coordinate is uploaded to our servers, sent to Google, or shared with any third party. Only the resulting numerical results (e.g., rep count, exercise duration) are saved to your workout history.
1.3.1 Food photographs (calorie scanner) — leaves your device
The calorie scanner is optional. Nothing here happens unless you open it and choose a photo.
- Prepared on your device first. Before anything is sent, the App resizes the picture so its longest edge is at most 1024 pixels, re-encodes it as JPEG, and removes the file's metadata — including any EXIF GPS coordinates your camera recorded. The full-resolution original never leaves your handset.
- Where it goes. The prepared image is sent to our server (Supabase, EU) and forwarded to Anthropic (US), which identifies the foods and returns an estimate of portions, calories and macronutrients. Nothing else about you travels with it — no name, no email, no body metrics, no location.
- We do not keep the photo. FormAI does not write the image to a database, an object store, or a log. It exists only for the duration of the request. Anthropic processes it to produce the reply and applies its own limited abuse-monitoring window; it is not used to train its models.
- What we do store is the result you confirm: the food names, portion descriptions, calories, macronutrients, a per-item confidence level, and which meal and date you filed them under. This is your meal log, and it lives in your account until you delete it.
- We also store a scan counter. To enforce the daily limit on AI scans, we record one row per scan containing your user ID, the date, and whether the scan succeeded. It contains no image and no food data.
- The estimates are estimates. AI calorie estimation carries meaningful error, particularly for mixed dishes. The App shows a confidence level per item and lets you correct every number before and after saving. Do not rely on it for medical or clinical purposes.
1.3.2 Barcode scanning
When you scan a product barcode, the barcode is decoded on your device and only the resulting number is sent to Open Food Facts, a public open food database, to look up the product. No image is uploaded and no AI processing takes place. Your identity is not sent with the lookup.
1.4 Device & technical data
- Device model, operating system version, app version, locale, and time zone — used for compatibility and analytics.
- Crash and error reports — stack traces and minimal device context, sent to Sentry for diagnostic purposes (see Section 4).
- Anonymous product analytics events — feature usage, screen views, funnel completion (see Section 4).
1.5 Subscription & billing
When you subscribe to FormAI Pro, your purchase is processed by Apple App Store or Google Play. We do not see your full payment information (card number, billing address). RevenueCat, our subscription infrastructure provider, receives a transaction identifier and entitlement state so the App knows whether your Pro subscription is active.
2. How We Use Data
- Provide the Service: Generate personalized workout and nutrition plans, track your progress, and sync your data across devices.
- Improve the Service: Analyze anonymous usage patterns to understand which features are valuable, and to debug issues.
- Communicate with you: Send essential service messages (e.g., subscription receipts, security alerts). We do not send marketing email without your opt-in.
- Comply with law: Respond to lawful requests from authorities and enforce our Terms.
3. Legal Bases (GDPR / KVKK)
If you are in the European Economic Area, the United Kingdom, or Türkiye, our legal bases for processing are:
- Contract (GDPR Art. 6(1)(b) / KVKK Art. 5(2)(c)): To provide the Service you have signed up for.
- Consent (GDPR Art. 6(1)(a) / KVKK Art. 5(1)): Crash reporting and anonymous product analytics. Both are off by default and only activate if you opt in on the in-app consent screen; you can withdraw consent at any time in Settings.
- Legitimate interest (GDPR Art. 6(1)(f) / KVKK Art. 5(2)(f)): Service security, fraud and abuse prevention, balanced against your privacy interests.
- Legal obligation (GDPR Art. 6(1)(c) / KVKK Art. 5(2)(a)): Tax records relating to your subscription.
4. Third-Party Processors
We rely on a small set of carefully selected processors to operate the Service. We have data-processing agreements in place with each of them, and they may only process your data on our instructions.
| Processor | Purpose | Data shared | Region |
|---|---|---|---|
| Supabase | Cloud database, authentication, storage | Account profile (email, user ID), workout completion history, in-app feedback messages, referral code | EU (Frankfurt) |
| PostHog | Anonymous product analytics | Pseudonymous user ID, screen views, feature events. No persistent advertising identifier. | US or EU (per region selected at project creation) |
| Sentry | Crash and error reporting | Stack traces, app version, device model, locale. Personally identifying fields scrubbed. | EU (Frankfurt) |
| RevenueCat | Subscription state management | Pseudonymous user ID, app-store transaction identifier, entitlement status | US |
| Anthropic | AI coach replies, and food recognition for the calorie scanner (large language model) | Coach: your chat messages and a profile context block — first name, age, height, weight, activity level, goal, streak, plan progress, and 30-day weight/waist change. Calorie scanner: the single food photograph you chose, resized and stripped of metadata (see §1.3.1). No email address, no account identifier, no location, no workout camera data. |
US |
| Open Food Facts | Product lookup for barcode scanning | The scanned barcode number only. No account identifier, no image, no personal data. | EU (France) |
| Google ML Kit | On-device pose detection and on-device barcode decoding | None. Runs entirely on your device. No data leaves the device. | On-device |
| Apple App Store / Google Play | App distribution and billing | Payment information per platform terms | Per platform |
4.1 No advertising; no data sale
We do not sell, rent, or share your personal data with advertisers, data brokers, or marketing networks. The App does not include third-party advertising SDKs or cross-app tracking. The iOS Privacy Manifest declares NSPrivacyTracking = false, which is why no App Tracking Transparency prompt is shown.
5. Data Retention
- Account data: Retained while your account is active. Deleted within 30 days after you delete your account, with limited exceptions for legal recordkeeping (e.g., tax invoices retained per applicable law).
- Workout completion history: Retained while your account is active; deleted alongside your account.
- Body metrics: Retained on our servers while your account is active and deleted alongside your account; the device copy is removed when you sign out or uninstall the App.
- AI coach conversations: Message history and its rolling summary are held on your device. Anthropic retains the request only as long as needed to return the reply and for its own limited abuse-monitoring window; we do not keep a server-side transcript.
- Food photographs: Not retained by FormAI. The image is held in memory only for the length of the analysis request and is never written to our database or file storage. Anthropic retains the request only as long as needed to return the result and for its own limited abuse-monitoring window.
- Meal log and scan counters: Retained while your account is active and deleted alongside your account. You can delete an individual food, meal or day at any time from inside the App.
- Crash reports: Retained for up to 90 days, then automatically purged.
- Anonymous analytics: Aggregated event data has no fixed expiry and may persist after account deletion in non-identifying form.
6. Your Rights
Subject to applicable law (including GDPR, the UK GDPR, and KVKK), you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Delete your data. You can delete your account directly within the App (Profile → Account Settings → Delete account). If you have uninstalled the App or cannot sign in, request deletion at formai.app/delete-account or by emailing support@formai.app. That page lists exactly what is deleted and what is retained;
- Export your data in a machine-readable format;
- Restrict or object to certain processing;
- Withdraw consent at any time, where processing is based on consent;
- Lodge a complaint with your local data-protection authority (in Türkiye: Kişisel Verileri Koruma Kurumu, KVKK).
To exercise any of these rights, email support@formai.app from the address associated with your account. We will respond within 30 days.
7. Security
We use technical and organizational measures to protect your data, including:
- Encryption in transit: All network requests between the App and our backend use HTTPS/TLS 1.2+.
- Encryption at rest: Database and storage encryption provided by Supabase.
- Row-Level Security (RLS): Supabase RLS policies ensure each user can read and write only their own rows.
- Principle of least privilege: Internal access to production data is restricted to the minimum personnel required.
No system is perfectly secure. If we become aware of a security incident affecting your data, we will notify you and the relevant authorities as required by law.
8. Children's Privacy
FormAI is intended for adults and is not directed to anyone under 18; the App enforces an 18+ age gate during onboarding. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us at support@formai.app and we will delete it.
9. International Data Transfers
Some of our processors are located outside Türkiye and the EEA (e.g., RevenueCat in the United States). Where data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) and equivalent KVKK-approved mechanisms, to ensure your data continues to receive an adequate level of protection.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the App and, where appropriate, by email or in-app notification at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
11. Contact
For privacy questions, data-subject requests, or to report a concern, email us at support@formai.app.
Gizlilik Politikası
Bu Gizlilik Politikası, FormAI mobil uygulamasını ("Uygulama") kullandığında FormAI'nin ("biz") hangi bilgileri topladığını, nasıl kullandığını, kiminle paylaştığını ve nasıl koruduğunu açıklar. FormAI'yi mümkün olan en az kişisel veriyi toplayacak şekilde tasarladık. Antrenman sırasındaki kamera görüntün tamamen cihazında kalır. Kalori taraması için seçtiğin yemek fotoğrafları ise cihazından çıkar — bölüm 1.3.1 bunun tam olarak nasıl işlediğini anlatır.
Veri Sorumlusu
FormAI, bireysel geliştirici Emre Doğan tarafından işletilmektedir (KVKK m.3 anlamında "veri sorumlusu"). Erişim, silme veya itiraz dahil her türlü gizlilik sorusu ve ilgili kişi başvurusu için support@formai.app adresine yazabilirsin. Posta adresi aynı e-posta üzerinden talep edilebilir.
Yemek fotoğrafları bunun istisnasıdır ve tamamen senin tercihindir. Kalori tarayıcısını kullanırsan o tek fotoğraf, sunucumuz üzerinden analiz edilmek üzere Anthropic'e gönderilir. FormAI bu görseli saklamaz. Ayrıntılar bölüm 1.3.1'de.
1. Topladığımız Veriler
1.1 Hesap bilgileri
- Kimlik: E-posta adresi, giriş sağlayıcısı (Google, Apple veya e-posta) ve rastgele üretilmiş bir kullanıcı kimliği.
- Profil: Görünen ad (verdiysen) ve giriş sağlayıcın üzerinden gelen avatar bağlantısı (varsa).
1.2 Fitness ve sağlık verileri (senin girdiğin)
- Vücut ölçüleri: Boy, kilo, cinsiyet, yaş aralığı, hedef (ör. kilo vermek, kas yapmak), aktivite düzeyi ve kaydettiğin ölçüler (bel, göğüs, kol, bacak, kalça). Önce cihazına yazılır, ardından hesabına senkronlanır (Supabase, AB) — böylece ölçüm geçmişin ve grafiklerin yeniden kurulumdan veya ikinci bir cihazdan sonra da durur. Antrenman ve beslenme planını kişiselleştirmek ve kendi trendlerini çizmek için kullanılır. Hesabını sildiğinde silinir; çıkış yaptığında veya uygulamayı kaldırdığında cihazdan kaldırılır.
- Antrenman geçmişi: Hangi plan günlerini ne zaman tamamladığın hesabına senkronlanır. Ayrıntılı seans kayıtları (set, tekrar, süre) cihazında kalır.
- Öğün kaydı: Fotoğrafla, barkodla veya elle kaydettiğin yiyecekler; porsiyonları, kalorileri, makro değerleri ve hangi öğüne ve tarihe ait oldukları. Günlük toplamların ve geçmişin yeniden kurulumdan sonra da dursun diye hesabında saklanır. Hesabınla birlikte silinir.
1.2.1 Yapay zekâ koçu konuşmaları
Uygulama içindeki yapay zekâ koçuyla yazıştığında mesajın ve kısa bir profil bağlamı — yazdığın şekliyle adın, yaşın, boyun, kilon, aktivite düzeyin, hedefin, güncel serin, son plan ilerlemen ve varsa 30 günlük kilo veya bel değişimin — sunucumuz aracılığıyla Anthropic'e (ABD) gönderilir ve koçun yanıtı üretilir. Koçun önceki konuşmayı hatırlaması için sonraki mesajlarda dönen bir özet de iletilir. E-posta adresini, hesap kimliğini veya herhangi bir kamera verisini göndermiyoruz. Anthropic bu veriyi yalnızca yanıtı döndürmek için işler ve modellerini eğitmek için kullanmaz. Bu veriyi göndermek istemiyorsan yapay zekâ koçunu kullanma — uygulamanın geri kalanı onsuz da çalışır.
1.2.2 Yapay zekâ yanıtlarıyla ilgili bildirimlerin
Herhangi bir koç yanıtını basılı tutarak bildirebilirsin. Bunu yaptığında bize o yanıtın metni, seçtiğin gerekçe, hangi ekrandan geldiği ve hangi dilde yazıldığı iletilir — başka hiçbir şey ve sen bildirmediğin sürece hiçbir şey. Yanıtın metni bildirimle birlikte taşınır; çünkü sunucu tarafında bir konuşma kaydı yok (bkz. 1.2.1) ve metni olmayan bir bildirim, artık hiçbir yerde bulunmayan bir cümle hakkında şikâyet olurdu. Bildirimler yalnızca sana ve bize açıktır; hesabınla birlikte silinir.
1.3 Kamera görüntüsü (yalnızca cihazda)
Poz algılamalı antrenmanlarda Uygulama, tekrarları saymak ve formu kontrol etmek için cihazının kamerasına erişir. Video akışı tamamen cihazının işlemcisinde Google ML Kit Pose Detection ile işlenir. Hiçbir kare, görüntü, video veya poz koordinatı sunucularımıza yüklenmez, Google'a gönderilmez veya üçüncü taraflarla paylaşılmaz. Yalnızca sayısal sonuçlar (ör. tekrar sayısı, süre) antrenman geçmişine kaydedilir.
1.3.1 Yemek fotoğrafları (kalori tarayıcısı) — cihazından çıkar
Kalori tarayıcısı isteğe bağlıdır. Sen açıp bir fotoğraf seçmedikçe burada anlatılanların hiçbiri gerçekleşmez.
- Önce cihazında hazırlanır. Hiçbir şey gönderilmeden önce Uygulama görseli, uzun kenarı en fazla 1024 piksel olacak şekilde küçültür, JPEG olarak yeniden kodlar ve dosyanın üst verilerini siler — kameranın kaydettiği EXIF GPS konumu dahil. Tam çözünürlüklü orijinal telefonundan hiç çıkmaz.
- Nereye gider. Hazırlanan görsel sunucumuza (Supabase, AB) ve oradan Anthropic'e (ABD) iletilir; yiyecekleri tanıyıp porsiyon, kalori ve makro tahmini döndürür. Yanında senin hakkında başka hiçbir şey gitmez — ad yok, e-posta yok, vücut ölçüsü yok, konum yok.
- Fotoğrafı saklamıyoruz. FormAI görseli bir veritabanına, dosya deposuna veya kayda yazmaz; yalnızca isteğin sürdüğü süre boyunca bellekte bulunur. Anthropic görseli yanıtı üretmek için işler ve kendi sınırlı kötüye kullanım denetimi süresini uygular; modellerini eğitmek için kullanmaz.
- Sakladığımız şey, senin onayladığın sonuçtur: yiyecek adları, porsiyon açıklamaları, kalori, makro değerler, kalem başına güven düzeyi ve hangi öğün ve tarihe kaydettiğin. Bu senin öğün kaydındır ve sen silene kadar hesabında durur.
- Bir de tarama sayacı tutuyoruz. Günlük yapay zekâ tarama sınırını uygulayabilmek için her tarama başına kullanıcı kimliğini, tarihi ve taramanın başarılı olup olmadığını içeren bir kayıt tutarız. İçinde görsel de yiyecek verisi de yoktur.
- Tahminler tahmindir. Yapay zekâ ile kalori tahmininin, özellikle karışık yemeklerde, kayda değer bir hata payı vardır. Uygulama her kalem için bir güven düzeyi gösterir ve kaydetmeden önce de sonra da her sayıyı düzeltmene izin verir. Tıbbi veya klinik amaçlarla bu tahminlere güvenme.
1.3.2 Barkod tarama
Bir ürün barkodunu taradığında barkod cihazında çözülür ve yalnızca çıkan numara, ürünü bulmak için açık bir gıda veritabanı olan Open Food Facts'e gönderilir. Hiçbir görsel yüklenmez ve yapay zekâ işlemesi yapılmaz. Sorguyla birlikte kimliğin gönderilmez.
1.4 Cihaz ve teknik veriler
- Cihaz modeli, işletim sistemi sürümü, uygulama sürümü, dil ve saat dilimi — uyumluluk ve analiz için.
- Çökme ve hata raporları — yığın izleri ve asgari cihaz bilgisi; teşhis amacıyla Sentry'ye gönderilir (bkz. Bölüm 4).
- Anonim ürün analitiği — özellik kullanımı, ekran görüntülenmeleri, huni tamamlanması (bkz. Bölüm 4).
1.5 Abonelik ve ödeme
FormAI Pro'ya abone olduğunda satın alman Apple App Store veya Google Play tarafından işlenir. Tam ödeme bilgilerini (kart numarası, fatura adresi) görmüyoruz. Abonelik altyapı sağlayıcımız RevenueCat, Uygulamanın Pro aboneliğinin etkin olup olmadığını bilmesi için bir işlem kimliği ve yetki durumu alır.
2. Verileri Nasıl Kullanıyoruz
- Hizmeti sunmak: Kişiselleştirilmiş antrenman ve beslenme planları üretmek, ilerlemeni takip etmek ve verilerini cihazlar arasında senkronlamak.
- Hizmeti geliştirmek: Hangi özelliklerin değerli olduğunu anlamak ve sorunları gidermek için anonim kullanım desenlerini incelemek.
- Seninle iletişim kurmak: Zorunlu hizmet mesajları göndermek (ör. abonelik makbuzları, güvenlik uyarıları). Onayın olmadan pazarlama e-postası göndermiyoruz.
- Hukuka uymak: Yetkili makamların hukuka uygun taleplerini karşılamak ve Kullanım Şartlarımızı uygulamak.
3. Hukuki Sebepler (KVKK / GDPR)
Türkiye'de, Avrupa Ekonomik Alanı'nda veya Birleşik Krallık'ta isen işleme faaliyetimizin hukuki sebepleri şunlardır:
- Sözleşme (KVKK m.5/2-c · GDPR m.6(1)(b)): Kaydolduğun hizmeti sunmak.
- Açık rıza (KVKK m.5/1 · GDPR m.6(1)(a)): Çökme raporlama ve anonim ürün analitiği. Her ikisi de varsayılan olarak kapalıdır ve yalnızca uygulama içi onay ekranında kabul edersen çalışır; rızanı istediğin zaman Ayarlar'dan geri çekebilirsin.
- Meşru menfaat (KVKK m.5/2-f · GDPR m.6(1)(f)): Hizmet güvenliği, dolandırıcılık ve kötüye kullanımın önlenmesi — gizlilik menfaatinle dengelenerek.
- Hukuki yükümlülük (KVKK m.5/2-a · GDPR m.6(1)(c)): Aboneliğine ilişkin vergi kayıtları.
4. Üçüncü Taraf Veri İşleyenler
Hizmeti işletmek için özenle seçilmiş az sayıda veri işleyenle çalışıyoruz. Her biriyle veri işleme sözleşmemiz var ve verilerini yalnızca bizim talimatlarımızla işleyebilirler.
| Veri işleyen | Amaç | Paylaşılan veri | Bölge |
|---|---|---|---|
| Supabase | Bulut veritabanı, kimlik doğrulama, depolama | Hesap profili (e-posta, kullanıcı kimliği), antrenman tamamlama geçmişi, öğün kaydı, uygulama içi geri bildirim mesajları, davet kodu | AB (Frankfurt) |
| PostHog | Anonim ürün analitiği | Takma adlı kullanıcı kimliği, ekran görüntülenmeleri, özellik olayları. Kalıcı reklam tanımlayıcısı yok. | ABD veya AB (proje oluşturulurken seçilen bölgeye göre) |
| Sentry | Çökme ve hata raporlama | Yığın izleri, uygulama sürümü, cihaz modeli, dil. Kimlik belirtici alanlar temizlenir. | AB (Frankfurt) |
| RevenueCat | Abonelik durumu yönetimi | Takma adlı kullanıcı kimliği, uygulama mağazası işlem kimliği, yetki durumu | ABD |
| Anthropic | Yapay zekâ koçu yanıtları ve kalori tarayıcısı için yemek tanıma (büyük dil modeli) | Koç: mesajların ve bir profil bağlamı — adın, yaşın, boyun, kilon, aktivite düzeyin, hedefin, serin, plan ilerlemen ve 30 günlük kilo/bel değişimin. Kalori tarayıcısı: seçtiğin tek yemek fotoğrafı; küçültülmüş ve üst verisi silinmiş halde (bkz. 1.3.1). E-posta adresi yok, hesap kimliği yok, konum yok, antrenman kamerası verisi yok. |
ABD |
| Open Food Facts | Barkod taramasında ürün sorgulama | Yalnızca taranan barkod numarası. Hesap kimliği yok, görsel yok, kişisel veri yok. | AB (Fransa) |
| Google ML Kit | Cihaz üzerinde poz algılama ve barkod çözme | Yok. Tamamen cihazında çalışır. Hiçbir veri cihazdan çıkmaz. | Cihaz üzerinde |
| Apple App Store / Google Play | Uygulama dağıtımı ve ödeme | Platform şartlarına göre ödeme bilgileri | Platforma göre |
4.1 Reklam yok; veri satışı yok
Kişisel verilerini reklamverenlere, veri simsarlarına veya pazarlama ağlarına satmıyor, kiralamıyor veya paylaşmıyoruz. Uygulamada üçüncü taraf reklam SDK'sı veya uygulamalar arası izleme yoktur. iOS Gizlilik Manifestosu NSPrivacyTracking = false beyan eder; App Tracking Transparency izni bu yüzden gösterilmez.
5. Verilerin Saklanması
- Hesap verileri: Hesabın etkin olduğu sürece saklanır. Hesabını sildikten sonra 30 gün içinde silinir; yasal kayıt yükümlülükleri (ör. ilgili mevzuat gereği tutulan vergi belgeleri) saklıdır.
- Antrenman tamamlama geçmişi: Hesabın etkin olduğu sürece saklanır; hesabınla birlikte silinir.
- Vücut ölçüleri: Hesabın etkin olduğu sürece sunucularımızda saklanır ve hesabınla birlikte silinir; cihazdaki kopya çıkış yaptığında veya uygulamayı kaldırdığında kaldırılır.
- Yapay zekâ koçu konuşmaları: Mesaj geçmişi ve dönen özeti cihazında tutulur. Anthropic isteği yalnızca yanıtı döndürmek için gereken süre ve kendi sınırlı kötüye kullanım denetimi süresi boyunca saklar; bizde sunucu tarafında konuşma kaydı yoktur.
- Yemek fotoğrafları: FormAI tarafından saklanmaz. Görsel yalnızca analiz isteği sürdüğü sürece bellekte tutulur; veritabanımıza veya dosya depomuza hiç yazılmaz. Anthropic isteği yalnızca sonucu döndürmek için gereken süre ve kendi sınırlı kötüye kullanım denetimi süresi boyunca saklar.
- Öğün kaydı ve tarama sayaçları: Hesabın etkin olduğu sürece saklanır ve hesabınla birlikte silinir. Tek bir yiyeceği, öğünü veya günü istediğin zaman Uygulama içinden silebilirsin.
- Çökme raporları: En fazla 90 gün saklanır, sonra otomatik olarak temizlenir.
- Anonim analitik: Toplulaştırılmış olay verisinin sabit bir son kullanma tarihi yoktur ve hesap silindikten sonra kimlik belirtmeyen biçimde kalabilir.
6. Haklarınız
KVKK m.11 ve GDPR uyarınca; verilerine erişme, düzeltilmesini isteme, silinmesini isteme, işlemenin kısıtlanmasını isteme, verilerini taşınabilir biçimde alma ve işlemeye itiraz etme haklarına sahipsin. Bu hakları kullanmak için support@formai.app adresine yaz; en geç 30 gün içinde yanıt veriyoruz. Hesabını ve verilerini Uygulama içindeki hesap ayarlarından da doğrudan silebilirsin. Sonuçtan memnun kalmazsan Kişisel Verileri Koruma Kurumu'na (KVKK) veya bulunduğun ülkedeki veri koruma otoritesine şikâyette bulunabilirsin.
7. Güvenlik
Verileri aktarım sırasında TLS ile, sunucu tarafında ise erişim denetimli şifreli depolama ile koruyoruz. Hesap verilerine erişim, veritabanı düzeyinde satır bazlı güvenlik kurallarıyla kendi kullanıcı kimliğinle sınırlandırılmıştır. Hiçbir sistem tamamen güvenli değildir; bir güvenlik açığı fark edersen lütfen bize bildir.
8. Çocukların Gizliliği
FormAI 18 yaşından küçükler için tasarlanmamıştır ve bilerek onlardan veri toplamayız. Bir çocuğun bize veri gönderdiğini fark edersen bizimle iletişime geç; sileriz.
9. Uluslararası Veri Aktarımı
Veri işleyenlerimizin bir kısmı Türkiye ve AEA dışında bulunmaktadır (ör. Anthropic ve RevenueCat, ABD). Verilerin yurt dışına aktarıldığı hallerde, korumanın yeterli düzeyde sürmesi için Standart Sözleşme Hükümleri (SCC) ve KVKK'nın kabul ettiği eşdeğer mekanizmalar gibi uygun güvenceler uygulanır.
10. Bu Politikadaki Değişiklikler
Bu Gizlilik Politikasını zaman zaman güncelleyebiliriz. Esaslı değişiklikler yürürlüğe girmeden en az 14 gün önce Uygulama üzerinden ve uygun olduğunda e-posta veya uygulama içi bildirimle duyurulur. Sayfanın başındaki "Son güncelleme" tarihi en son revizyonu gösterir.
11. İletişim
Gizlilikle ilgili sorular, ilgili kişi başvuruları veya bildirimlerin için support@formai.app adresine yazabilirsin.