Türkçe
Zoday, gerçek gökyüzü verisinden kişisel bir gökyüzü takvimi oluşturan, özel bir düşünme günlüğü ve isteğe bağlı eğlence amaçlı astrolojik yorumlar sunan bir mobil uygulamadır. Bu politika, uygulamayı kullandığında hangi verilerin toplandığını, neden toplandığını, kimlerle paylaşıldığını ve bunlar üzerinde hangi haklara sahip olduğunu anlatır.
Veri sorumlusu: DuniaOps Solution and Consulting LTD
İletişim: info@duniaops.com
1. Topladığımız veriler
1.1 Senin girdiğin bilgiler
| Veri | Zorunlu mu | Ne için |
|---|---|---|
| Doğum tarihi | Evet | Kişisel Ay dönüşünü, gökyüzü takvimini ve Güneş burcunu hesaplamak |
| Doğum saati | Hayır | Ay dönüşünün kesin anı, yükselen burç ve natal harita |
| Doğum yeri | Hayır | Natal haritanın doğru hesaplanması |
| Adın | Hayır | İsteğe bağlı geleneksel yorumlarda sana hitap etmek |
| Bulunduğun şehir | Hayır | İsteğe bağlı geleneksel bir yoruma şehir, yerel saat ve mevsim katmak |
| Yorum soruların | Hayır | Sorduğun soruya eğlence amaçlı bir cevap üretmek |
| Günlük kaydın: ruh hâli, enerji, odak ve not | Hayır | Yalnızca sana ait özel bir günlük tutmak |
| Bildirim tercihleri | Hayır | Ay dönüşü, check-in ve isteğe bağlı ikincil bildirimleri göndermek |
1.2 Sevdiklerin — başkalarına ait bilgiler
Uygulamaya sevdiğin kişileri ekleyebilir, onlar için günlük yorum ve fal alabilirsin. Bunun için o kişinin adını, yakınlık derecesini ve doğum tarihini giriyorsun. Bu bilgiler yalnızca senin hesabına bağlı kalır; o kişiye hiçbir bildirim gitmez ve kimseyle paylaşılmaz.
Ancak bu, başka bir insanın kişisel verisi. Uygulama bunu eklerken sana hatırlatıyor: yalnızca o kişinin rahatsız olmayacağından emin olduğun bilgileri gir. Bu veriyi girmenin hukuki sorumluluğu sana aittir. İstediğin an kişiyi silebilirsin; silindiğinde ona ait tüm yorumlar da silinir.
1.3 Otomatik oluşan veriler
- Uygulama hesabı kimliği — anonim başlayan rastgele bir tanımlayıcı; Apple veya Google ile giriş yaparsan cihazlar arasında aynı kalır.
- Kişisel gökyüzü takvimi — natal Ay konumu, Ay dönüşleri ve bunlara bağlı hesaplanmış olaylar.
- Hesaplanan astrolojik veriler — güneş burcu, yükselen burç, natal harita.
- Üretilen fallar — metnin kendisi ve üretilirken kullanılan bağlam (sorduğun soru, adın, burcun, doğum tarihin ve şehrin dahil).
- Betimleyici günlük örüntüleri — yalnızca kendi kayıtlarındaki sayılar, ortalamalar ve birlikte görülmeler; nedensellik veya sağlık çıkarımı değil.
- Cihaz dili ve saat dilimi — içeriğin doğru dil ve saatte gelmesi için.
- Bildirim jetonu — bildirim açıksa, telefonuna bildirim gönderebilmek için.
- Abonelik durumu — Plus üyeliğinin aktif olup olmadığı, ürün ve bitiş tarihi.
- Davet verileri — sana ait davet kodu, kodunu kimin kullandığı ve kazandığın hediye günlerin kaydı.
1.4 Konum
Konum tamamen isteğe bağlıdır ve Profil'den istediğin an kapatabilirsin.
- Cihaz konumuna izin verirsen: koordinatların yaklaşık 1 kilometre hassasiyetine yuvarlanır, yalnızca isteğe bağlı geleneksel bir yorumu doğru yarıküreye ve mevsime oturtmak için bir kez kullanılır ve hiçbir yerde saklanmaz. Şehir adı cihazında çözülür.
- Konum yerine şehir seçersen: seçtiğin şehrin adı ve şehir merkezinin koordinatları profilinde saklanır. Bu senin bulunduğun nokta değil, şehrin merkezidir.
1.5 Ödeme bilgileri
Zoday hiçbir zaman kart numaranı, banka bilgini veya fatura adresini görmez. Abonelik ödemeleri tamamen Apple App Store veya Google Play üzerinden yürür. Bize yalnızca aboneliğin aktif olup olmadığı bilgisi ulaşır.
1.6 Apple veya Google ile hesap koruma
Verilerini yeni bir cihaza taşımak istersen uygulama hesabı kimliğini iPhone'da bir Apple hesabına veya Android'de bir Google hesabına bağlayabilirsin. Bu tamamen isteğe bağlıdır ve uygulamanın hiçbir özelliği bunu gerektirmez. Bu akışlar Supabase Auth üzerinden hesabını tanımak ve geri yüklemek içindir; parolan Zoday ile paylaşılmaz.
- Apple: Apple bize bir e-posta adresi ve Apple'a özgü
sağlayıcı kimliğini Supabase Auth aracılığıyla verir. Apple'ın
E-postamı Gizle seçeneğini kullanırsan bize ulaşan adres
@privaterelay.appleid.comuzantılı bir yönlendirme adresidir; gerçek adresini görmeyiz. - Google: Google, Supabase Auth'a e-posta adresini ve Google'a özgü sağlayıcı kimliğini verir. Zoday bu alanları yalnızca aynı hesabı tekrar tanımak için kullanır; uygulama Google parolanı istemez veya saklamaz.
- Bu kimlik alanlarını sana pazarlama e-postası göndermek için kullanmayız.
- Bağlantıyı kaldırmak istersen hesabını silmen yeterlidir (Ayarlar → "Hesabımı sil"). Apple bağlantılı hesaplarda silme sırasında Apple'ın sistem onayı bir kez daha açılır; Zoday bu tek kullanımlık kodla Apple yetkisini iptal eder ve kodu saklamaz.
- Google bağlantılı hesaplarda silme, Supabase'deki Zoday kimliğini ve bağlı Zoday verilerini siler. Google hesabını silmez; Google OAuth yetkisini ayrıca kaldırdığını veya Google tarafında bir token iptali yaptığını iddia etmeyiz.
1.7 Özel günlük ve cihazdaki taslak
Her yerel takvim günü için bir günlük kaydı oluşturabilirsin. Kaydedilen ruh hâli, enerji, isteğe bağlı odak ve not; kaydın yerel tarihi ve o tarihi belirlemek için kullanılan saat dilimiyle birlikte Supabase'de uygulama hesabı kimliğine bağlı olarak saklanır.
Kaydetmeden önce yazdıkların, kayıt başarılı olana veya sen taslağı silene kadar yalnızca cihazındaki uygulama depolamasında tutulur. Böylece bağlantı hatası yazdıklarını silmez. Günlük alanlarının gerçek değerleri yapay zekâya, analitik araçlarına, bildirimlere veya paylaşım metinlerine gönderilmez.
Örüntü ekranı, sunucuda kendi kayıtlarının sayısal özetlerini deterministik olarak hesaplar. Günlük notunu yapay zekâya göndermez, tıbbi bir çıkarım üretmez ve Ay'ın bir duyguya neden olduğunu iddia etmez.
2. Verileri neden işliyoruz
| Amaç | Hukuki dayanak |
|---|---|
| Kişisel takvimi hesaplamak ve uygulamayı çalıştırmak | Sözleşmenin ifası |
| İsteğe bağlı geleneksel yorumları üretmek | Sözleşmenin ifası |
| Özel günlük kayıtlarını saklamak, düzenlemek, dışa aktarmak ve silmek | Sözleşmenin ifası |
| Konum, bildirim, sevdiklerin | Açık rızan (istediğin an geri alabilirsin) |
| Apple veya Google ile giriş (cihaz değiştirme) | Açık rızan |
| Aboneliği ve davet kredisini yönetmek | Sözleşmenin ifası |
| Kötüye kullanımı ve sahte davetleri engellemek | Meşru menfaat |
| Yasal yükümlülükler (ör. muhasebe) | Hukuki yükümlülük |
3. Yapay zekâ ile üretilen içerik
Fallar OpenAI'ın dil modelleri kullanılarak üretilir. Bir fal istediğinde OpenAI'a şunlar gönderilir: adın (girdiysen), burcun, doğum tarihin, seçtiğin konu, yazdıysan sorunun metni ve şehrinin adı ile o gün Dünya'nın yakınından geçen gök cisimlerinin NASA verisi. Ham koordinatların asla gönderilmez.
Serbest metin soruları, gönderilmeden önce OpenAI'ın içerik denetim servisinden geçirilir. Bu denetim kendine zarar verme sinyali yakalarsa Zoday fal üretmez; bunun yerine destek almanı öneren bir mesaj gösterir ve o soru hiçbir yere kaydedilmez.
Günlükteki ruh hâli, enerji, odak ve not alanları OpenAI'a veya başka bir yapay zekâ modeline gönderilmez. Kişisel örüntüler kural tabanlı sayısal özetlerdir; yapay zekâ tarafından üretilmez ve tavsiye vermez.
4. Verileri kimlerle paylaşıyoruz
Verilerini satmıyoruz, reklam amacıyla kimseye vermiyoruz. Uygulamanın çalışması için şu hizmet sağlayıcılarını kullanıyoruz:
| Sağlayıcı | Ne alıyor | Ne için |
|---|---|---|
| Supabase | Yukarıda sayılan tüm veriler | Veritabanı ve sunucu altyapısı |
| OpenAI | Bölüm 3'te sayılanlar | Fal metnini üretmek ve içerik denetimi |
| Open-Meteo | Yalnızca aradığın şehrin adı | Şehir arama (coğrafi kodlama) |
| NASA (NeoWs) | Hiçbir kişisel veri | Günlük gök cismi verisi |
| RevenueCat | Uygulama hesabı kimliği ve abonelik durumu | Abonelik yönetimi |
| Expo | Bildirim jetonu ve bildirim metni | Bildirim teslimi |
| Apple / Google | Ödeme bilgileri (bize ulaşmadan) | Satın alma işlemleri |
| Apple | Apple ile giriş yaparsan e-posta adresin ve sağlayıcı kimliğin | iPhone'da kimlik doğrulama |
| Google ile giriş yaparsan e-posta adresin ve sağlayıcı kimliğin | Android'de kimlik doğrulama | |
| PostHog | Uygulama hesabı kimliği ve sınırlı ekran/işlem olayları | Ürün analitiği |
| Sentry | Hesap kimliği içermeyen çökme, performans, uygulama/cihaz/işletim sistemi teknik verileri | Hata bulma ve performans |
PostHog'a uygulama hesabı kimliği ile hangi ekranın açıldığı veya bir işlemin tamamlandığı gibi sınırlı olaylar gönderilir. Sentry'ye hesap kimliği gönderilmez; çökme kaydı, uygulama sürümü, cihaz/işletim sistemi bağlamı ve örneklenmiş performans verileri gönderilebilir. Fal metinleri, soruların, adın, doğum bilgilerin ve günlükteki ruh hâli, enerji, odak veya not değerleri bu araçlara gönderilmez. Günlük olayları yalnızca "not var mı" gibi içerik olmayan boolean değerler veya kayıt-sayısı aralıkları içerebilir. Profil'deki "Kullanım verisini paylaş" anahtarı kapalıyken iki araç da uygulamadan veri göndermez.
PostHog ve Sentry, Zoday'in verilerini Avrupa Birliği'ndeki sunucularda işler. Diğer sağlayıcıların bir kısmı Türkiye dışında, Avrupa Birliği ve Amerika Birleşik Devletleri'nde bulunan sunucularda veri işler. Verilerin yurt dışına aktarımı, uygulamayı kullanmayı seçerek verdiğin açık rızaya ve ilgili sözleşmesel güvencelere dayanır.
5. Ne kadar süre saklıyoruz
Verilerin, sen silene kadar saklanır. Tek bir günlük kaydını istediğin an silebilirsin. Hesabını sildiğinde profilin, günlük kayıtların ve cihazdaki kaydedilmemiş günlük taslakların, falların, sevdiklerin, bildirim jetonun ve davet kayıtların kalıcı olarak silinir; RevenueCat müşteri kaydı ile PostHog kişi/olay silme işlemi de başlatılır. Apple ile giriş bağlantın varsa Apple yetkisi de iptal edilir. Google ile giriş bağlantın varsa Supabase'deki Zoday kimliği silinir; Google hesabın veya Google OAuth yetkin Zoday tarafından silinmez. Bu işlem geri alınamaz. Yasal saklama yükümlülüğü bulunan muhasebe kayıtları (satın alma kayıtları) ilgili mevzuatın öngördüğü süre boyunca Apple ve Google tarafında kalır. Hesabı silmek App Store veya Google Play aboneliğini otomatik olarak iptal etmez.
6. Haklarını nasıl kullanırsın
Çoğunu uygulamanın içinden, kimseye başvurmadan kullanabilirsin:
- Verilerini indir — Ayarlar → "Verilerimi indir (JSON)". Profilin, günlük kayıtların, falların, sevdiklerin ve abonelik durumun tek dosyada.
- Hesabını sil — Ayarlar → "Hesabımı sil". Anında ve kalıcı.
- Konumu kapat — Profil → "İsteğe bağlı yorumlarda konumumu kullan".
- Analitik ve hata paylaşımını kapat — Profil → "Kullanım verisini paylaş".
- Bağlam verilerini temizle — Ayarlar → "Bağlam verilerimi temizle".
- Bildirimleri kapat — Ayarlar veya telefonunun bildirim ayarları.
KVKK 11. madde ve GDPR kapsamında ayrıca bilgi talep etme, düzeltme, işlemeye itiraz etme ve şikâyette bulunma haklarına sahipsin. Bunlar için info@duniaops.com adresine yazabilirsin; başvurulara en geç 30 gün içinde dönüş yapılır. Türkiye'de Kişisel Verileri Koruma Kurumu'na, Avrupa Birliği'nde ise bulunduğun ülkenin veri koruma otoritesine şikâyette bulunma hakkın saklıdır.
7. Çocuklar
Zoday 13 yaşın altındaki çocuklara yönelik değildir ve bilerek onlardan veri toplamayız. 13 yaşın altında bir çocuğa ait veri topladığımızı fark edersek siliriz. 18 yaşın altındaysan uygulamayı ebeveyninin bilgisi dâhilinde kullanmalısın.
8. Güvenlik
Veriler şifreli bağlantı üzerinden taşınır ve veritabanında satır düzeyinde erişim kuralları ile korunur: her kayıt yalnızca onu oluşturan uygulama hesabı kimliği tarafından okunabilir. Hiçbir sistem yüzde yüz güvenli değildir; bu nedenle paylaşmak istemediğin bilgileri fal sorularına veya günlüğe yazmamanı öneririz.
9. Eğlence amaçlıdır
Zoday'in ürettiği yorum ve fallar eğlence amaçlıdır. Tıbbi, psikolojik, hukuki veya finansal tavsiye niteliği taşımaz ve bu alanlarda uzman görüşünün yerine geçmez.
10. Bu politikadaki değişiklikler
Politikayı güncellersek bu sayfadaki yürürlük tarihini değiştiririz. Veri işleme biçimimizde esaslı bir değişiklik olursa uygulama içinden bilgilendiririz.
English
Zoday is a mobile app that builds a personal celestial calendar from real sky data, offers a private reflection journal, and keeps optional astrological readings as entertainment. This policy explains what we collect when you use it, why, who else sees it, and what you can do about it.
Data controller: DuniaOps Solution and Consulting LTD
Contact: info@duniaops.com
1. What we collect
1.1 What you enter
| Data | Required | Why |
|---|---|---|
| Birth date | Yes | Personal lunar returns, celestial calendar and sun sign |
| Birth time | No | Exact lunar-return timing, rising sign and natal chart |
| Birth place | No | Accurate natal chart |
| Your name | No | So optional traditional readings can address you |
| Your current city | No | To add city, local time and season to an optional traditional reading |
| Your reading questions | No | To generate an entertainment response to what you asked |
| Journal mood, energy, focus and note | No | To keep a private journal that belongs to you |
| Notification preferences | No | Lunar-return, check-in and optional secondary reminders |
1.2 Loved ones — other people's data
You can add people you care about and get daily readings for them. To do that you enter their name, relationship to you, and birth date. This stays private to your account, is never shared, and that person is never contacted.
But it is another person's personal data. The app reminds you of this when you add someone: only enter details they would be comfortable with. You are responsible for having a lawful basis to enter it. You can delete a person at any time, which also deletes every reading made for them.
1.3 What is generated automatically
- An app account ID — a random identifier that starts anonymously and stays stable across devices if you link Apple or Google sign-in.
- Your personal celestial calendar — natal Moon position, lunar returns and related calculated events.
- Computed astrology — sun sign, rising sign, natal chart.
- Your readings — the text, plus the context used to produce it (your question, name, sign, birth date and city).
- Descriptive journal patterns — counts, averages and co-occurrences in your own entries, never a causal or health inference.
- Device language and time zone — so content arrives in the right language at the right hour.
- A push token — only if notifications are on.
- Subscription state — whether Plus is active, the product, expiry.
- Referral data — your invite code, who used it, and the gift days you have earned.
1.4 Location
Location is entirely optional and can be switched off in Profile at any time.
- If you allow device location: your coordinates are rounded to roughly one kilometre, used once to place an optional traditional reading in the right hemisphere and season, and never stored. The city name is resolved on your device.
- If you pick a city instead: the city name and the coordinates of the city centre are saved to your profile. That is the centre of a city, not where you are.
1.5 Payment data
Zoday never sees your card number, bank details or billing address. Subscription payments are handled entirely by the Apple App Store or Google Play. All we receive is whether your subscription is active.
1.6 Protecting an account with Apple or Google
If you want to move your data to a new device, you can link your app account identity to an Apple account on iPhone or a Google account on Android. This is entirely optional and no feature of the app requires it. These flows use Supabase Auth to recognise and restore your account; your password is never shared with Zoday.
- Apple: Apple gives Supabase Auth an email address and
an Apple-specific provider identifier. If you use Apple's
Hide My Email, the address we receive is
a
@privaterelay.appleid.comrelay — we never see your real one. - Google: Google gives Supabase Auth your email address and a Google-specific provider identifier. Zoday uses those fields only to recognise the same account again; the app does not ask for or store your Google password.
- We do not use these identity fields to send marketing email.
- To undo the link, delete your account (Settings → "Delete my account"). For an Apple-linked account, Apple's system confirmation appears once more during deletion; Zoday uses that one-time code to revoke the Apple authorization and does not store it.
- For a Google-linked account, deletion removes the Zoday identity held by Supabase and the connected Zoday data. It does not delete the Google account, and Zoday does not claim to revoke Google authorization or a Google token.
1.7 Private journal and on-device drafts
You can create one journal entry per local calendar day. Saved mood, energy, optional focus and note are stored in Supabase under your app account identity, together with the local date and the time zone used to choose that date.
Before a save succeeds, what you type is kept only in the app's storage on your device until you save it or discard the draft. This prevents a network failure from erasing your words. Actual journal field values are not sent to AI, analytics, notifications or sharing text.
The patterns screen deterministically calculates numerical summaries from your own entries on the server. It does not send journal notes to AI, infer medical information, or claim that the Moon caused a feeling.
2. Why we process it
| Purpose | Legal basis |
|---|---|
| Calculating the personal calendar and running the app | Performance of a contract |
| Producing optional traditional readings | Performance of a contract |
| Saving, editing, exporting and deleting private journal entries | Performance of a contract |
| Location, notifications, loved ones | Your consent (withdrawable anytime) |
| Apple or Google sign-in (moving devices) | Your consent |
| Managing subscriptions and referral credit | Performance of a contract |
| Preventing abuse and fraudulent referrals | Legitimate interest |
| Legal obligations such as accounting | Legal obligation |
3. AI-generated content
Readings are produced using OpenAI's language models. When you request one, we send OpenAI: your name (if given), sun sign, birth date, chosen topic, your question if you wrote one, and your city name, along with NASA data about objects passing near Earth. Your raw coordinates are never sent.
Free-text questions pass through OpenAI's content moderation service first. If that check detects a self-harm signal, Zoday does not produce a reading — it shows a message encouraging you to reach out for support, and that question is not stored anywhere.
Your journal mood, energy, focus and note are not sent to OpenAI or any other AI model. Personal patterns are rule-based numerical summaries, not AI-generated analysis or advice.
4. Who else sees your data
We do not sell your data and we do not share it for advertising. We use these providers to run the app:
| Provider | What they receive | Why |
|---|---|---|
| Supabase | Everything listed above | Database and server infrastructure |
| OpenAI | The items in section 3 | Generating readings, content moderation |
| Open-Meteo | Only the city name you type | City search (geocoding) |
| NASA (NeoWs) | No personal data | Daily near-Earth object data |
| RevenueCat | App account ID and subscription state | Subscription management |
| Expo | Push token and notification text | Notification delivery |
| Apple / Google | Payment data (never reaching us) | Purchases |
| Apple | Your email address and provider identifier, if you sign in with Apple | Authentication on iPhone |
| Your email address and provider identifier, if you sign in with Google | Authentication on Android | |
| PostHog | App account ID and limited screen/action events | Product analytics |
| Sentry | Crash, performance, app/device/OS technical data without the app account ID | Debugging and performance |
PostHog receives the app account ID and limited events such as which screen opened or that an action completed. Sentry does not receive the app account ID; it may receive a crash record, app version, device/OS context and sampled performance data. Reading text, your questions, your name, birth details, and journal mood, energy, focus or note values are not sent to either service. Journal events may contain only non-content booleans such as whether a note exists, or an entry-count range. While "Share usage data" is off in Profile, the app sends no data to either service.
PostHog and Sentry process Zoday's data on servers in the European Union. Some of the other providers process data on servers in the European Union and the United States. Any transfer outside your country relies on your consent in choosing to use the app, together with the contractual safeguards we have in place with each provider.
5. How long we keep it
We keep your data until you delete it. You can delete an individual journal entry at any time. Deleting your account permanently removes your profile, journal entries and unsaved journal drafts on that device, readings, loved ones, push token and referral records, and initiates deletion of the RevenueCat customer and PostHog person/events. If you linked Sign in with Apple, its authorization is revoked too. If you linked Google, the Zoday identity held by Supabase is removed; Zoday does not delete your Google account or claim to revoke Google authorization or a Google token. This cannot be undone. Purchase records that Apple and Google are legally required to retain remain with them for the period the law requires. Deleting the account does not automatically cancel an App Store or Google Play subscription.
6. Your rights
Most of them you can exercise inside the app, without asking anyone:
- Export your data — Settings → "Download my data (JSON)". The export includes every journal field in chronological order.
- Delete your account — Settings → "Delete my account". Immediate and permanent.
- Turn off location — Profile → "Use my location for optional readings".
- Turn off analytics and crash sharing — Profile → "Share usage data".
- Clear your context data — Settings → "Clear my context data".
- Turn off notifications — Settings, or your phone's settings.
Under the GDPR and Turkey's KVKK you also have rights of access, rectification, objection to processing, and complaint. Write to info@duniaops.com; we respond within 30 days at the latest. You may also complain to your national data protection authority, or in Turkey to the Personal Data Protection Authority (KVKK).
7. Children
Zoday is not directed at children under 13 and we do not knowingly collect their data. If we learn that we have, we delete it. If you are under 18, use the app with your parent's knowledge.
8. Security
Data travels over encrypted connections and is protected in the database by row-level access rules: each record can only be read by the app account identity that created it. No system is perfectly secure, which is why we suggest not writing anything into a question or journal entry that you would not want stored.
9. For entertainment
Zoday's horoscopes and readings are for entertainment. They are not medical, psychological, legal or financial advice and are not a substitute for a professional.
10. Changes to this policy
If we update this policy we will change the effective date on this page. If we change something material about how we handle data, we will tell you inside the app.