Gizlilik Politikası
Yürürlük tarihi: 17 Ağustos 2026 · Sürüm 2.0
Önce en önemli şey. Muhabbet şu anda uçtan uca şifreli değildir. Mesajlarınız cihazınız ile sunucumuz arasında TLS ile şifrelenir, ancak sunucuda şifresiz olarak saklanır. Bu, sunucuyu işleten kişinin teknik olarak mesajlarınızı okuyabileceği anlamına gelir.
Bunu ilk paragrafta yazıyoruz çünkü aksini ima eden bir uygulama, hiç şifreleme olmamasından daha kötüdür. Uygulamanın içindeki sohbet ekranı da aynı şeyi söyler: "Aktarım sırasında şifreli (TLS) — uçtan uca şifreleme yakında." Uçtan uca şifreleme devreye girdiğinde bu politika güncellenecek ve uygulamada açıkça belirtilecektir. O gün gelene kadar, okunmasını istemediğiniz bir şeyi buradan göndermeyin.
1. Veri sorumlusu
6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) uyarınca veri sorumlusu:
Rollingcat Software
Muhabbet uygulamasının geliştiricisi ve işletmecisi
E-posta: rollingcat.help@gmail.com
Ticari unvan, açık adres ve varsa MERSİS/VKN bilgileri, tüzel kişilik kuruluşu tamamlandığında bu bölüme eklenecektir. Şu anda uygulama, tek bir geliştirici tarafından yürütülen bir test aşaması ürünüdür.
2. İşlenen kişisel veriler
Aşağıdaki tablo, sunucuda fiilen tutulan verileri gösterir. Uygulamanın kaynak koduna ve çalışan veritabanına karşı doğrulanmıştır.
| Veri | Nasıl saklanır | Neden |
|---|---|---|
| Telefon numarası | Açık metin (şifrelenmemiş, hash'lenmemiş) | Hesabınızın kimliği ve giriş yönteminiz budur |
| Telefon numarası özeti (SHA-256) | Ayrı bir tabloda, hash olarak | Rehberinizdeki kişilerin Muhabbet'te olup olmadığını, numaraları sunucuya göndermeden bulmak için |
| Görünen ad, profil fotoğrafı, hakkımda metni | Açık metin / dosya | Sizi tanıyanların sizi tanıması için. Üçü de isteğe bağlıdır |
| Mesajlar (metin) | Açık metin | Mesajı iletmek ve siz silene kadar geçmişinizde tutmak için |
| Medya (fotoğraf, ses, video, belge) | Nesne depolamada, dosya olarak | Aynı |
| Cihaz kaydı: cihaz kimliği, platform, push jetonu, dil | Açık metin | Bildirim gönderebilmek ve bildirimi okuduğunuz dilde yazabilmek için |
| Çevrimiçi durumu ve son görülme zamanı | Önbellekte (geçici) ve veritabanında | Görünürlüğünü Gizlilik ayarlarından siz belirlersiniz |
| Teslim ve okundu bilgisi | Mesaj başına satır | Tik göstergeleri. Okundu bilgisini kapatabilirsiniz |
| Doğrulama kaydı | Kod saklanmaz; harici doğrulayıcı kullanıldığı için yalnızca doğrulandığı işaretlenir | Hesabın numaraya ait olduğunu doğrulamak için |
| Sunucu günlükleri | Kullanıcı kimliği, cihaz kimliği, IP, zaman damgası | Hata ayıklama ve kötüye kullanımı tespit etmek için |
Rehberiniz sunucuya yüklenmez
Rehber eşleştirmesi yalnızca açık rızanızla ve yalnızca numaraların SHA-256 özetleri gönderilerek yapılır. İsimler, e-posta adresleri veya diğer rehber alanları hiçbir zaman gönderilmez. Sunucu, gönderdiğiniz özetlerden yalnızca Muhabbet'te karşılığı olanları döndürür; eşleşmeyen özetler saklanmaz.
Toplamadığımız veriler
- Konum — yalnızca siz bir konum mesajı gönderirseniz, o mesajın içeriği olarak iletilir. Arka planda konum takibi yoktur.
- Reklam kimliği, izleyici, analitik SDK'sı — hiçbiri yoktur. Uygulama sizi reklam için profillemez.
- Rehberinizin kendisi — yukarıda açıklandığı gibi yalnızca özetler gönderilir.
3. İşleme amaçları ve hukuki sebepler
| Amaç | Hukuki sebep (KVKK m.5) |
|---|---|
| Hesap oluşturma, telefon doğrulama, oturum yönetimi | Sözleşmenin kurulması ve ifası (m.5/2-c) |
| Mesaj ve medyanın iletilmesi, saklanması | Sözleşmenin ifası (m.5/2-c) |
| Rehber eşleştirmesi | Açık rıza (m.5/1) — uygulama içinde ayrıca sorulur, reddedebilirsiniz |
| Push bildirimi gönderme | Sözleşmenin ifası (m.5/2-c) |
| Kötüye kullanım, spam ve yasa dışı içerikle mücadele; şikayet ve engelleme | Meşru menfaat (m.5/2-f) ve hukuki yükümlülük (m.5/2-ç), 5651 sayılı Kanun kapsamında |
| Hata ayıklama, çökme raporu, hizmet sürekliliği | Meşru menfaat (m.5/2-f) |
4. Kimlerle paylaşıyoruz
Verilerinizi satmıyoruz ve reklam amacıyla kimseyle paylaşmıyoruz. Hizmetin çalışması için zorunlu olan aşağıdaki sağlayıcılar kullanılmaktadır:
| Sağlayıcı | Ne görüyor | Nerede |
|---|---|---|
| Twilio (doğrulama SMS'i) | Telefon numaranız ve doğrulama kodu | ABD — yurt dışına aktarım |
| Google Firebase Cloud Messaging (bildirimler) | Cihaz push jetonu, gönderenin adı ve metin mesajlarının ilk 100 karakteri | ABD/AB — yurt dışına aktarım |
| Sentry (hata izleme) | Çökme ve hata kayıtları; teknik bağlam ve kullanıcı kimliği içerebilir | ABD/AB — yurt dışına aktarım |
| Hetzner Online GmbH (sunucu barındırma) | Tüm veriler bu sağlayıcının makinesinde durur | Nürnberg, Almanya |
Bildirimler hakkında dürüst olmak gerekirse: bir metin mesajı size ulaştığında, bildirim satırında görünmesi için mesajın ilk 100 karakteri Google'ın bildirim altyapısından geçer. Bu, bildirimlerin çalıştığı her uygulamada böyledir; Muhabbet'i farklı kılmaz. Bunu ortadan kaldırmak için bildirimlerin sunucudan boş gönderilip içeriğin cihazda doldurulması gerekir — bu, üzerinde çalıştığımız bir değişikliktir ve tamamlandığında burada belirtilecektir.
5. Saklama süreleri
- Mesajlar ve medya: Siz silene veya hesabınızı kapatana kadar. Kaybolan mesaj süresi ayarladıysanız, süre dolduğunda otomatik olarak silinir.
- Durum paylaşımları: 24 saat sonra otomatik silinir.
- Doğrulama kayıtları: Kod saklanmaz; doğrulama kaydı kısa süre sonra geçersizleşir.
- Sunucu günlükleri: Konteyner günlük döngüsü boyunca, tipik olarak günler mertebesinde.
- Şikayet ve engelleme kayıtları: 5651 sayılı Kanun kapsamındaki yükümlülükler süresince.
6. Hesabınızı sildiğinizde ne oluyor
Uygulama içinden hesabınızı sildiğinizde şunlar gerçekten silinir: telefon numaranız (yerine geri döndürülemez bir yer tutucu yazılır), görünen adınız, profil fotoğrafınız, hakkımda metniniz, son görülme bilginiz, iki adımlı doğrulama bilgileriniz, cihazlarınız, push jetonlarınız, şifreleme anahtarlarınız, rehber eşleştirme özetiniz ve tüm oturumlarınız. Tüm sohbetlerden çıkarılırsınız.
Gönderdiğiniz mesajlar silinmez. Bir mesaj, gönderildiği anda karşı tarafın da sohbetinin parçası olur; onu tek taraflı silmek, başka birinin yazışma geçmişinden bir parçayı çıkarmak anlamına gelir. Bu mesajlar kimliksizleştirilmiş bir gönderene bağlı kalır. Bu, KVKK m.7 kapsamında sizin verinizin silinmesi yükümlülüğünü karşılar; başkasının verisi olan yazışmayı yok etmeyi gerektirmez. Belirli mesajları kaldırmak isterseniz, hesabınızı silmeden önce sohbet ekranından tek tek silebilirsiniz.
7. Güvenlik
- Cihaz ile sunucu arasındaki tüm trafik TLS ile şifrelenir. Uygulama, şifresiz bağlantıyı reddeder.
- Oturum jetonları HMAC-SHA256 ile imzalanır ve sınırlı ömürlüdür.
- Uygulama içinde saklanan hassas veriler cihazda şifrelenir (Android'de EncryptedSharedPreferences, iOS'te Keychain).
- Medya bağlantıları süreli ve imzalıdır; bağlantıyı bilen herkes değil, yalnızca yetkili kullanıcı erişebilir.
- Sunucu tarafında yetkilendirme her istekte kontrol edilir: bir sohbetin üyesi olmayan kişi o sohbetin mesajlarına, tepkilerine veya anketlerine erişemez.
Sunucuda saklanan mesaj içeriği şifrelenmemiştir — bkz. sayfanın başındaki uyarı. Uçtan uca şifreleme tamamlandığında bu bölüm değişecektir.
8. Haklarınız
KVKK m.11 ve GDPR uyarınca şu haklara sahipsiniz:
- Kişisel verilerinizin işlenip işlenmediğini öğrenme ve işlenmişse bilgi talep etme
- İşlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme
- Yurt içinde veya yurt dışında verilerin aktarıldığı üçüncü kişileri bilme
- Eksik veya yanlış işlenmiş verilerin düzeltilmesini isteme
- Silinmesini veya yok edilmesini isteme
- İşlemenin yalnızca otomatik sistemlerle analizi sonucu aleyhinize bir sonuç doğmasına itiraz etme
- Hukuka aykırı işleme sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme
Bu hakların ikisi uygulamanın içinden anında kullanılabilir: Ayarlar → Gizlilik ekranından verilerinizin tamamını dışa aktarabilir veya hesabınızı silebilirsiniz.
Diğer talepleriniz için rollingcat.help@gmail.com adresine yazabilirsiniz. Başvurunuz en geç 30 gün içinde sonuçlandırılır. Yanıttan memnun kalmazsanız Kişisel Verileri Koruma Kurumu'na şikâyette bulunma hakkınız saklıdır.
9. Çocuklar
Muhabbet 13 yaşın altındaki çocuklara yönelik değildir ve bilerek bu yaş grubundan veri toplamaz. 18 yaşından küçük kullanıcıların hizmeti veli veya vasi gözetiminde kullanması beklenir. Bu yaş grubuna ait bir hesabı fark ettiğimizde kapatırız.
10. Bu politikadaki değişiklikler
Politika değiştiğinde bu sayfadaki yürürlük tarihi ve sürüm numarası güncellenir. Sizi doğrudan etkileyen bir değişiklik olursa — özellikle uçtan uca şifrelemenin devreye girmesi — uygulama içinde ayrıca bildirilir.
Bu politika, uygulamanın kaynak koduna ve çalışan sistemine karşı doğrulanarak yazılmıştır. Bir maddesinin gerçeği yansıtmadığını düşünüyorsanız lütfen yazın; düzeltiriz.
Privacy Policy
Effective: 17 August 2026 · Version 2.0
The most important thing first. Muhabbet is not end-to-end encrypted today. Your messages are encrypted in transit with TLS between your device and our server, but they are stored unencrypted on that server. That means whoever operates the server can technically read them.
This is the first paragraph because an app that implies otherwise is worse than one with no encryption at all. The app itself says the same thing on its chat screen: "Encrypted in transit (TLS) — end-to-end encryption coming soon." When end-to-end encryption is switched on, this policy will be updated and the app will say so plainly. Until then, do not send anything here you would mind being read.
1. Data controller
Rollingcat Software
Developer and operator of the Muhabbet application
Email: rollingcat.help@gmail.com
Registered trade name, address and company registration details will be added here once the legal entity is formed. Muhabbet is currently a test-phase product run by a single developer.
2. What we process
The table below reflects what is actually stored, verified against the source code and the running database.
| Data | How it is stored | Why |
|---|---|---|
| Phone number | Plaintext (not encrypted, not hashed) | It is your account identity and how you sign in |
| Phone number digest (SHA-256) | Separate table, as a hash | To find which of your contacts are on Muhabbet without sending their numbers |
| Display name, profile photo, about text | Plaintext / file | So people recognise you. All three are optional |
| Messages (text) | Plaintext | To deliver them and keep your history until you delete it |
| Media (photo, audio, video, document) | Object storage, as files | Same |
| Device record: device id, platform, push token, language | Plaintext | To send notifications, in the language you read the app in |
| Online status and last seen | Cache (transient) and database | You control who sees it in Privacy settings |
| Delivery and read status | One row per message | The tick indicators. Read receipts can be turned off |
| Verification record | The code is not stored; with an external verifier only the fact of verification is | To confirm the account belongs to the number |
| Server logs | User id, device id, IP, timestamp | Debugging and abuse detection |
Your address book is never uploaded
Contact matching happens only with your explicit consent, and only SHA-256 digests of numbers are sent. Names, email addresses and other address-book fields are never transmitted. The server returns only the digests that correspond to Muhabbet users; digests with no match are not retained.
What we do not collect
- Location — only if you choose to send a location message, as that message's content. There is no background tracking.
- Advertising identifiers, trackers, analytics SDKs — none. The app does not profile you for advertising.
- Your address book itself — only digests, as above.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Account creation, phone verification, session management | Performance of a contract (KVKK 5/2-c; GDPR Art. 6(1)(b)) |
| Delivering and storing messages and media | Performance of a contract |
| Contact matching | Explicit consent (KVKK 5/1; GDPR Art. 6(1)(a)) — asked separately in the app and refusable |
| Push notifications | Performance of a contract |
| Abuse, spam and unlawful content; reports and blocking | Legitimate interest and legal obligation (Turkish Law No. 5651) |
| Debugging, crash reporting, service continuity | Legitimate interest |
4. Who we share with
We do not sell your data and share none of it for advertising. These providers are required for the service to function:
| Provider | What it sees | Where |
|---|---|---|
| Twilio (verification SMS) | Your phone number and the verification code | USA — international transfer |
| Google Firebase Cloud Messaging (notifications) | Device push token, sender name, and the first 100 characters of text messages | USA/EU — international transfer |
| Sentry (error monitoring) | Crash and error reports; may include technical context and a user id | USA/EU — international transfer |
| Hetzner Online GmbH (hosting) | All data resides on this provider's machine | Nuremberg, Germany |
Being honest about notifications: when a text message arrives, its first 100 characters pass through Google's notification infrastructure so they can appear in your notification tray. This is true of every app with working notifications and does not make Muhabbet unusual. Removing it requires the server to send an empty notification and the device to fill in the content locally — a change we are working on, and one this page will record when it lands.
5. Retention
- Messages and media: until you delete them or close your account. If you set a disappearing-message timer, they are deleted automatically when it expires.
- Status updates: deleted automatically after 24 hours.
- Verification records: the code is not stored; the record expires shortly after use.
- Server logs: for the container's log rotation window, typically days.
- Reports and blocks: for as long as obligations under Law No. 5651 require.
6. What happens when you delete your account
Deleting your account from within the app genuinely erases: your phone number (replaced with an irreversible placeholder), display name, profile photo, about text, last seen, two-step verification details, devices, push tokens, encryption keys, contact-matching digest, and all sessions. You are removed from every conversation.
Messages you sent are not deleted. A message becomes part of the other person's conversation the moment it is sent; deleting it unilaterally would remove a piece of somebody else's correspondence. Those messages remain attached to an anonymised sender. This satisfies erasure of your personal data under KVKK Art. 7 and GDPR Art. 17; it does not extend to destroying correspondence that is also someone else's data. If you want specific messages gone, delete them from the chat before closing your account.
7. Security
- All traffic between device and server is encrypted with TLS. The app refuses cleartext connections.
- Session tokens are signed with HMAC-SHA256 and are short-lived.
- Sensitive values held by the app are encrypted on the device (EncryptedSharedPreferences on Android, Keychain on iOS).
- Media links are signed and time-limited, so possession of a URL is not access.
- Authorisation is checked server-side on every request: someone who is not a member of a conversation cannot reach its messages, reactions or polls.
Message content stored on the server is not encrypted — see the notice at the top of this page. This section will change when end-to-end encryption ships.
8. Your rights
Under KVKK Art. 11 and the GDPR you may request access, rectification, erasure, information about recipients including international transfers, object to automated decisions, and seek compensation for unlawful processing.
Two of these work instantly inside the app: Settings → Privacy lets you export all of your data or delete your account.
For anything else, write to rollingcat.help@gmail.com. Requests are answered within 30 days. If you are not satisfied you may complain to the Turkish Personal Data Protection Authority (KVKK) or your local supervisory authority.
9. Children
Muhabbet is not directed at children under 13 and does not knowingly collect their data. Users under 18 are expected to use the service with a parent or guardian's supervision. Accounts we identify as belonging to this age group are closed.
10. Changes
When this policy changes, the effective date and version at the top are updated. Changes that affect you directly — above all, end-to-end encryption being switched on — are also announced inside the app.
This policy was written by checking each claim against the application's source code and running system. If you believe a statement here is not true, please write to us and we will correct it.