Muhabbet

Gizlilik Politikası

Yürürlük tarihi: 17 Ağustos 2026 · Sürüm 2.0

Önce en önemli şey. Muhabbet şu anda uçtan uca şifreli değildir. Mesajlarınız cihazınız ile sunucumuz arasında TLS ile şifrelenir, ancak sunucuda şifresiz olarak saklanır. Bu, sunucuyu işleten kişinin teknik olarak mesajlarınızı okuyabileceği anlamına gelir.

Bunu ilk paragrafta yazıyoruz çünkü aksini ima eden bir uygulama, hiç şifreleme olmamasından daha kötüdür. Uygulamanın içindeki sohbet ekranı da aynı şeyi söyler: "Aktarım sırasında şifreli (TLS) — uçtan uca şifreleme yakında." Uçtan uca şifreleme devreye girdiğinde bu politika güncellenecek ve uygulamada açıkça belirtilecektir. O gün gelene kadar, okunmasını istemediğiniz bir şeyi buradan göndermeyin.

1. Veri sorumlusu

6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) uyarınca veri sorumlusu:

Rollingcat Software
Muhabbet uygulamasının geliştiricisi ve işletmecisi
E-posta: rollingcat.help@gmail.com

Ticari unvan, açık adres ve varsa MERSİS/VKN bilgileri, tüzel kişilik kuruluşu tamamlandığında bu bölüme eklenecektir. Şu anda uygulama, tek bir geliştirici tarafından yürütülen bir test aşaması ürünüdür.

2. İşlenen kişisel veriler

Aşağıdaki tablo, sunucuda fiilen tutulan verileri gösterir. Uygulamanın kaynak koduna ve çalışan veritabanına karşı doğrulanmıştır.

VeriNasıl saklanırNeden
Telefon numarasıAçık metin (şifrelenmemiş, hash'lenmemiş)Hesabınızın kimliği ve giriş yönteminiz budur
Telefon numarası özeti (SHA-256)Ayrı bir tabloda, hash olarakRehberinizdeki kişilerin Muhabbet'te olup olmadığını, numaraları sunucuya göndermeden bulmak için
Görünen ad, profil fotoğrafı, hakkımda metniAçık metin / dosyaSizi tanıyanların sizi tanıması için. Üçü de isteğe bağlıdır
Mesajlar (metin)Açık metinMesajı iletmek ve siz silene kadar geçmişinizde tutmak için
Medya (fotoğraf, ses, video, belge)Nesne depolamada, dosya olarakAynı
Cihaz kaydı: cihaz kimliği, platform, push jetonu, dilAçık metinBildirim gönderebilmek ve bildirimi okuduğunuz dilde yazabilmek için
Çevrimiçi durumu ve son görülme zamanıÖnbellekte (geçici) ve veritabanındaGörünürlüğünü Gizlilik ayarlarından siz belirlersiniz
Teslim ve okundu bilgisiMesaj başına satırTik göstergeleri. Okundu bilgisini kapatabilirsiniz
Doğrulama kaydıKod saklanmaz; harici doğrulayıcı kullanıldığı için yalnızca doğrulandığı işaretlenirHesabın numaraya ait olduğunu doğrulamak için
Sunucu günlükleriKullanıcı kimliği, cihaz kimliği, IP, zaman damgasıHata ayıklama ve kötüye kullanımı tespit etmek için

Rehberiniz sunucuya yüklenmez

Rehber eşleştirmesi yalnızca açık rızanızla ve yalnızca numaraların SHA-256 özetleri gönderilerek yapılır. İsimler, e-posta adresleri veya diğer rehber alanları hiçbir zaman gönderilmez. Sunucu, gönderdiğiniz özetlerden yalnızca Muhabbet'te karşılığı olanları döndürür; eşleşmeyen özetler saklanmaz.

Toplamadığımız veriler

3. İşleme amaçları ve hukuki sebepler

AmaçHukuki sebep (KVKK m.5)
Hesap oluşturma, telefon doğrulama, oturum yönetimiSözleşmenin kurulması ve ifası (m.5/2-c)
Mesaj ve medyanın iletilmesi, saklanmasıSözleşmenin ifası (m.5/2-c)
Rehber eşleştirmesiAçık rıza (m.5/1) — uygulama içinde ayrıca sorulur, reddedebilirsiniz
Push bildirimi göndermeSözleşmenin ifası (m.5/2-c)
Kötüye kullanım, spam ve yasa dışı içerikle mücadele; şikayet ve engellemeMeşru menfaat (m.5/2-f) ve hukuki yükümlülük (m.5/2-ç), 5651 sayılı Kanun kapsamında
Hata ayıklama, çökme raporu, hizmet sürekliliğiMeşru menfaat (m.5/2-f)

4. Kimlerle paylaşıyoruz

Verilerinizi satmıyoruz ve reklam amacıyla kimseyle paylaşmıyoruz. Hizmetin çalışması için zorunlu olan aşağıdaki sağlayıcılar kullanılmaktadır:

SağlayıcıNe görüyorNerede
Twilio (doğrulama SMS'i) Telefon numaranız ve doğrulama kodu ABD — yurt dışına aktarım
Google Firebase Cloud Messaging (bildirimler) Cihaz push jetonu, gönderenin adı ve metin mesajlarının ilk 100 karakteri ABD/AB — yurt dışına aktarım
Sentry (hata izleme) Çökme ve hata kayıtları; teknik bağlam ve kullanıcı kimliği içerebilir ABD/AB — yurt dışına aktarım
Hetzner Online GmbH (sunucu barındırma) Tüm veriler bu sağlayıcının makinesinde durur Nürnberg, Almanya

Bildirimler hakkında dürüst olmak gerekirse: bir metin mesajı size ulaştığında, bildirim satırında görünmesi için mesajın ilk 100 karakteri Google'ın bildirim altyapısından geçer. Bu, bildirimlerin çalıştığı her uygulamada böyledir; Muhabbet'i farklı kılmaz. Bunu ortadan kaldırmak için bildirimlerin sunucudan boş gönderilip içeriğin cihazda doldurulması gerekir — bu, üzerinde çalıştığımız bir değişikliktir ve tamamlandığında burada belirtilecektir.

5. Saklama süreleri

6. Hesabınızı sildiğinizde ne oluyor

Uygulama içinden hesabınızı sildiğinizde şunlar gerçekten silinir: telefon numaranız (yerine geri döndürülemez bir yer tutucu yazılır), görünen adınız, profil fotoğrafınız, hakkımda metniniz, son görülme bilginiz, iki adımlı doğrulama bilgileriniz, cihazlarınız, push jetonlarınız, şifreleme anahtarlarınız, rehber eşleştirme özetiniz ve tüm oturumlarınız. Tüm sohbetlerden çıkarılırsınız.

Gönderdiğiniz mesajlar silinmez. Bir mesaj, gönderildiği anda karşı tarafın da sohbetinin parçası olur; onu tek taraflı silmek, başka birinin yazışma geçmişinden bir parçayı çıkarmak anlamına gelir. Bu mesajlar kimliksizleştirilmiş bir gönderene bağlı kalır. Bu, KVKK m.7 kapsamında sizin verinizin silinmesi yükümlülüğünü karşılar; başkasının verisi olan yazışmayı yok etmeyi gerektirmez. Belirli mesajları kaldırmak isterseniz, hesabınızı silmeden önce sohbet ekranından tek tek silebilirsiniz.

7. Güvenlik

Sunucuda saklanan mesaj içeriği şifrelenmemiştir — bkz. sayfanın başındaki uyarı. Uçtan uca şifreleme tamamlandığında bu bölüm değişecektir.

8. Haklarınız

KVKK m.11 ve GDPR uyarınca şu haklara sahipsiniz:

Bu hakların ikisi uygulamanın içinden anında kullanılabilir: Ayarlar → Gizlilik ekranından verilerinizin tamamını dışa aktarabilir veya hesabınızı silebilirsiniz.

Diğer talepleriniz için rollingcat.help@gmail.com adresine yazabilirsiniz. Başvurunuz en geç 30 gün içinde sonuçlandırılır. Yanıttan memnun kalmazsanız Kişisel Verileri Koruma Kurumu'na şikâyette bulunma hakkınız saklıdır.

9. Çocuklar

Muhabbet 13 yaşın altındaki çocuklara yönelik değildir ve bilerek bu yaş grubundan veri toplamaz. 18 yaşından küçük kullanıcıların hizmeti veli veya vasi gözetiminde kullanması beklenir. Bu yaş grubuna ait bir hesabı fark ettiğimizde kapatırız.

10. Bu politikadaki değişiklikler

Politika değiştiğinde bu sayfadaki yürürlük tarihi ve sürüm numarası güncellenir. Sizi doğrudan etkileyen bir değişiklik olursa — özellikle uçtan uca şifrelemenin devreye girmesi — uygulama içinde ayrıca bildirilir.

Bu politika, uygulamanın kaynak koduna ve çalışan sistemine karşı doğrulanarak yazılmıştır. Bir maddesinin gerçeği yansıtmadığını düşünüyorsanız lütfen yazın; düzeltiriz.


Privacy Policy

Effective: 17 August 2026 · Version 2.0

The most important thing first. Muhabbet is not end-to-end encrypted today. Your messages are encrypted in transit with TLS between your device and our server, but they are stored unencrypted on that server. That means whoever operates the server can technically read them.

This is the first paragraph because an app that implies otherwise is worse than one with no encryption at all. The app itself says the same thing on its chat screen: "Encrypted in transit (TLS) — end-to-end encryption coming soon." When end-to-end encryption is switched on, this policy will be updated and the app will say so plainly. Until then, do not send anything here you would mind being read.

1. Data controller

Rollingcat Software
Developer and operator of the Muhabbet application
Email: rollingcat.help@gmail.com

Registered trade name, address and company registration details will be added here once the legal entity is formed. Muhabbet is currently a test-phase product run by a single developer.

2. What we process

The table below reflects what is actually stored, verified against the source code and the running database.

DataHow it is storedWhy
Phone numberPlaintext (not encrypted, not hashed)It is your account identity and how you sign in
Phone number digest (SHA-256)Separate table, as a hashTo find which of your contacts are on Muhabbet without sending their numbers
Display name, profile photo, about textPlaintext / fileSo people recognise you. All three are optional
Messages (text)PlaintextTo deliver them and keep your history until you delete it
Media (photo, audio, video, document)Object storage, as filesSame
Device record: device id, platform, push token, languagePlaintextTo send notifications, in the language you read the app in
Online status and last seenCache (transient) and databaseYou control who sees it in Privacy settings
Delivery and read statusOne row per messageThe tick indicators. Read receipts can be turned off
Verification recordThe code is not stored; with an external verifier only the fact of verification isTo confirm the account belongs to the number
Server logsUser id, device id, IP, timestampDebugging and abuse detection

Your address book is never uploaded

Contact matching happens only with your explicit consent, and only SHA-256 digests of numbers are sent. Names, email addresses and other address-book fields are never transmitted. The server returns only the digests that correspond to Muhabbet users; digests with no match are not retained.

What we do not collect

3. Purposes and legal bases

PurposeLegal basis
Account creation, phone verification, session managementPerformance of a contract (KVKK 5/2-c; GDPR Art. 6(1)(b))
Delivering and storing messages and mediaPerformance of a contract
Contact matchingExplicit consent (KVKK 5/1; GDPR Art. 6(1)(a)) — asked separately in the app and refusable
Push notificationsPerformance of a contract
Abuse, spam and unlawful content; reports and blockingLegitimate interest and legal obligation (Turkish Law No. 5651)
Debugging, crash reporting, service continuityLegitimate interest

4. Who we share with

We do not sell your data and share none of it for advertising. These providers are required for the service to function:

ProviderWhat it seesWhere
Twilio (verification SMS)Your phone number and the verification codeUSA — international transfer
Google Firebase Cloud Messaging (notifications)Device push token, sender name, and the first 100 characters of text messagesUSA/EU — international transfer
Sentry (error monitoring)Crash and error reports; may include technical context and a user idUSA/EU — international transfer
Hetzner Online GmbH (hosting)All data resides on this provider's machineNuremberg, Germany

Being honest about notifications: when a text message arrives, its first 100 characters pass through Google's notification infrastructure so they can appear in your notification tray. This is true of every app with working notifications and does not make Muhabbet unusual. Removing it requires the server to send an empty notification and the device to fill in the content locally — a change we are working on, and one this page will record when it lands.

5. Retention

6. What happens when you delete your account

Deleting your account from within the app genuinely erases: your phone number (replaced with an irreversible placeholder), display name, profile photo, about text, last seen, two-step verification details, devices, push tokens, encryption keys, contact-matching digest, and all sessions. You are removed from every conversation.

Messages you sent are not deleted. A message becomes part of the other person's conversation the moment it is sent; deleting it unilaterally would remove a piece of somebody else's correspondence. Those messages remain attached to an anonymised sender. This satisfies erasure of your personal data under KVKK Art. 7 and GDPR Art. 17; it does not extend to destroying correspondence that is also someone else's data. If you want specific messages gone, delete them from the chat before closing your account.

7. Security

Message content stored on the server is not encrypted — see the notice at the top of this page. This section will change when end-to-end encryption ships.

8. Your rights

Under KVKK Art. 11 and the GDPR you may request access, rectification, erasure, information about recipients including international transfers, object to automated decisions, and seek compensation for unlawful processing.

Two of these work instantly inside the app: Settings → Privacy lets you export all of your data or delete your account.

For anything else, write to rollingcat.help@gmail.com. Requests are answered within 30 days. If you are not satisfied you may complain to the Turkish Personal Data Protection Authority (KVKK) or your local supervisory authority.

9. Children

Muhabbet is not directed at children under 13 and does not knowingly collect their data. Users under 18 are expected to use the service with a parent or guardian's supervision. Accounts we identify as belonging to this age group are closed.

10. Changes

When this policy changes, the effective date and version at the top are updated. Changes that affect you directly — above all, end-to-end encryption being switched on — are also announced inside the app.

This policy was written by checking each claim against the application's source code and running system. If you believe a statement here is not true, please write to us and we will correct it.