Gizlilik Politikası ve Aydınlatma Metni

Yürürlük tarihi: 3 Ağustos 2026

Son güncelleme: 3 Ağustos 2026

Bu metin, Takıl mobil uygulamasının kişisel verilerinizi nasıl işlediğini açıklar. 6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) kapsamında aydınlatma yükümlülüğümüzü ve Avrupa Birliği Genel Veri Koruma Tüzüğü (GDPR) kapsamındaki bilgilendirmeyi birlikte karşılar.


1. Veri Sorumlusu

Veri sorumlusu Barbaros Köklü (gerçek kişi)
İletişim kaptan3k@gmail.com
Uygulama Takıl
Web takil.app

Takıl bir tüzel kişilik bünyesinde değil, şahsım adına yürütülmektedir. Bu durum değiştiğinde bu metin güncellenecektir.


2. Hangi Verileri İşliyoruz

2.1 Hesap ve kimlik doğrulama

2.2 Profil

Ad, profil fotoğrafı, kısa durum metni ("şu an" metni), biyografi, şehir, ilgi alanı etiketleri, bağlantı/sosyal medya adresleri, katılım amacı ("neden buradayım") ve bildirim tercihleri.

Bu alanların tamamı isteğe bağlıdır; doldurmadığın alanlar işlenmez.

2.3 Konum — nasıl işlediğini bilmen önemli

Takıl kesin konum koordinatlarını saklamaz.

Cihazının konumu, uygulama açıkken yaklaşık 150 metrelik bir ızgara hücresine yuvarlanır ve yalnızca bu hücre numarası (grid_x, grid_y) ile son güncelleme zamanı hesabında tutulur. Yani sunucuda "şu sokakta, şu binada" bilgisi bulunmaz; "şu 150 metrelik karede" bilgisi bulunur.

2.4 Etkinlik ve sosyal etkileşim

Katıldığın etkinlikler ve katılım durumun, etkinliğe giriş (check-in) zamanı, etkinlik sohbetlerindeki mesajların, yorumların, anket oyların, emoji tepkilerin, yüklediğin etkinlik fotoğrafları, beğenilerin, kaydettiğin kişiler ve kayıt notların, karşılıklı eşleşmeler, teşekkür notları ve topladığın puanlar.

2.5 Sinyaller

Bıraktığın sinyalin metni, varsa fotoğrafı, ızgara hücresi, şehir bilgisi, görüntülenme sayısı ve son kullanma zamanı. Sinyaller süreli bir içeriktir ve süresi dolduğunda geçerliliğini yitirir.

2.6 Mesajlaşma

Kişiler arası mesajlarının içeriği, gönderen/alıcı bilgisi ve okunma zamanı.

Açıkça belirtmemiz gereken bir nokta: Mesajlar uçtan uca şifreli değildir. Aktarım sırasında TLS ile şifrelenir ve veritabanında erişim kuralları (RLS) ile korunur; ancak teknik olarak veri tabanı yöneticisi tarafından okunabilir durumdadır. Hassas bilgilerinizi mesajlaşma yoluyla paylaşmamanızı öneririz.

2.7 Rehber eşleştirme (isteğe bağlı)

Ayrıntısı için bölüm 4'e bakınız.

2.8 Bildirimler

Cihazına ait push bildirim jetonu (token), platform bilgisi (iOS/Android) ve bildirim gönderim durumu. Kayıt sırasında hata oluşursa bu hata kaydı da tutulur.

2.9 Güvenlik ve moderasyon

Gönderdiğin şikâyetler, engellediğin kullanıcılar, otomatik içerik filtresinin ürettiği işaretler ve bunların çözüm durumu.

2.10 Teknik teşhis verisi

Uygulama çökerse; çökme yığın izi, cihaz modeli, işletim sistemi sürümü, uygulama sürümü ve çökmeden önceki eylem izleri toplanır. Ayrıca oturumların küçük bir bölümünde (%20) performans ölçümü yapılır. Bu veriler kimliğinle ilişkilendirilmez — kullanıcı kimliğini teşhis sağlayıcımıza göndermiyoruz.

2.11 Bağlantı tıklama istatistiği

Uygulama tanıtım bağlantılarına yapılan tıklamalarda; işletim sistemi, dil, kampanya etiketi ve IP adresinden türetilmiş kaba konum (ülke/bölge/şehir/ilçe) kaydedilir. Bu kayıt kullanıcı hesabıyla ilişkilendirilmez.

2.12 İşlemediğimiz veriler


3. İşleme Amaçları ve Hukuki Sebepler

Amaç İşlenen veri KVKK m.5 dayanağı GDPR m.6 dayanağı
Hesap oluşturma ve oturum yönetimi Kimlik doğrulama verileri Sözleşmenin kurulması/ifası m.6/1-b Sözleşme
Profilin gösterilmesi Profil verileri Sözleşmenin ifası m.6/1-b Sözleşme
Etkinlik keşfi, katılım, sohbet Etkinlik ve etkileşim verileri Sözleşmenin ifası m.6/1-b Sözleşme
Yakındakiler / Sinyal Izgara konumu Açık rıza m.6/1-a Rıza
Rehber eşleştirme Telefon/e-posta özetleri Açık rıza m.6/1-a Rıza
Bildirim gönderimi Push jetonu Açık rıza m.6/1-a Rıza
18 yaş sınırının denetimi Doğum yılı Hukuki yükümlülük · Meşru menfaat m.6/1-c · m.6/1-f
Güvenlik, kötüye kullanım önleme Şikâyet, engelleme, moderasyon Meşru menfaat m.6/1-f Meşru menfaat
Hata giderme ve kararlılık Teşhis verisi Meşru menfaat m.6/1-f Meşru menfaat

Açık rızaya dayanan işlemeleri dilediğin an durdurabilirsin; ilgili özelliği Ayarlar'dan kapatman yeterlidir. Rızanın geri alınması, geri alınmadan önceki işlemenin hukuka uygunluğunu etkilemez.


4. Rehber Eşleştirme — Tam ve Açık Anlatım

Bu özellik yalnızca sen başlattığında çalışır ve istediğin an kapatabilirsin. Nasıl işlediğini eksiksiz anlatıyoruz:

1. Rehberindeki telefon numaraları ve e-posta adresleri cihazının içinde, SHA-256 algoritmasıyla özetlenir (hash'lenir).

2. Numaraların ve e-posta adreslerinin kendisi hiçbir zaman sunucularımıza gönderilmez.

3. Ancak eşleştirmenin yapılabilmesi için bu özetler sunucuya gönderilir. Sunucu, gelen özetleri yalnızca kayıtlı kullanıcıların kendi kayıtlı özetleriyle karşılaştırır ve eşleşenleri sana döndürür.

4. Gönderdiğin özetler sunucuda saklanmaz. Karşılaştırma bittiğinde sorguyla birlikte ortadan kalkar; kalıcı bir kayıt oluşturulmaz.

5. Kendi telefon numaranın ve e-posta adresinin özeti, başkalarının seni bulabilmesi için hesabında saklanır.

6. Profilinde "rehberde bulunabilirlik" ayarını kapatırsan, senin özetlerin eşleştirmeye hiç dahil edilmez.

Dürüst olmamız gereken teknik bir nokta: SHA-256 özeti geri döndürülemez bir işlem olsa da, telefon numarası gibi kısa ve tahmin edilebilir bir veri için özet anonim sayılmaz. Bu nedenle bu özetleri anonim veri gibi değil, kişisel veri olarak sınıflandırıyor ve KVKK/GDPR koruması altında işliyoruz.

Rehberinizdeki kişiler Takıl kullanıcısı olmayabilir ve bu işlemeye rıza göstermemiş olabilir. Bu nedenle: eşleşmeyen özetler hiçbir şekilde kaydedilmez, kullanılmaz veya profil oluşturmak için işlenmez.


5. Üçüncü Taraf Hizmet Sağlayıcılar

Sağlayıcı Ne için Ne aktarılıyor Veri konumu
Supabase Veritabanı, dosya depolama, kimlik doğrulama Uygulama verilerinin tamamı Frankfurt, Almanya
Apple (Apple ile Giriş, APNs) Kimlik doğrulama, iOS bildirimleri E-posta, UID, bildirim jetonu ABD / küresel
Google (Google ile Giriş) Kimlik doğrulama E-posta, UID ABD / küresel
Google Maps Harita gösterimi Harita görüntüleme istekleri ABD / küresel
Google Places Etkinlik oluştururken mekân arama Yazdığın mekân arama metni ABD / küresel
Expo / EAS Uygulama dağıtımı ve bildirim iletimi Push jetonu, bildirim içeriği ABD
Sentry Çökme ve hata teşhisi Çökme izi, cihaz/OS/sürüm bilgisi — kimliğinle ilişkilendirilmeden Almanya (alım sunucusu)
Meta / Instagram Uygulama içinde gösterilen Takıl Instagram akışı Akışın çekilmesi için yapılan istekler ABD / küresel
Vercel Bu hukuki sayfaların yayını Sayfa görüntüleme istekleri Küresel

Bu sağlayıcılar veri işleyen sıfatıyla, yalnızca burada belirtilen amaçlarla ve talimatlarımız doğrultusunda hareket eder. Hiçbiri verilerinizi kendi amaçları için kullanma yetkisine sahip değildir.


6. Yurt Dışına Aktarım

Kullanıcı verileriniz Almanya'daki (Frankfurt) sunucularda barındırılmaktadır. Bölüm 5'te belirtilen bazı hizmet sağlayıcılar ise Türkiye dışında yerleşiktir.


7. Saklama Süreleri

Veri Süre
Hesap ve profil verileri Hesap açık kaldığı sürece
Etkinlik katılımı ve sohbetler Hesap açık kaldığı sürece
Mesajlar Hesap açık kaldığı sürece
Sinyaller Sinyalin süresi dolana kadar
Izgara konumu Yalnızca en son hücre tutulur; geçmiş konum kaydı oluşturulmaz
Rehberden gönderilen özetler Saklanmaz — sorgu bitince silinir
Kendi telefon/e-posta özetin Hesap açık kaldığı sürece
Push jetonu Bildirimleri kapatana veya hesabı silene kadar
Teşhis (çökme) verisi Sentry'nin saklama süresi boyunca (90 güne kadar)
Şikâyet ve moderasyon kayıtları Hesap silinse dahi, hukuki yükümlülük ve kötüye kullanımın önlenmesi amacıyla makul bir süre

Hesabını sildiğinde, Ayarlar > Hesabı Sil adımıyla verilerin ilişkili tüm kayıtlarla birlikte kalıcı olarak silinir. Bu işlem geri alınamaz.


8. Haklarınız

KVKK m.11 kapsamındaki haklarınız

Veri sorumlusuna başvurarak aşağıdaki taleplerde bulunabilirsiniz:

1. Kişisel verinizin işlenip işlenmediğini öğrenme

2. İşlenmişse buna ilişkin bilgi talep etme

3. İşlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme

4. Yurt içinde veya yurt dışında verilerin aktarıldığı üçüncü kişileri bilme

5. Eksik veya yanlış işlenmiş verilerin düzeltilmesini isteme

6. Kanun'un 7. maddesindeki şartlar çerçevesinde silinmesini veya yok edilmesini isteme

7. Düzeltme, silme ve yok etme işlemlerinin, verilerin aktarıldığı üçüncü kişilere bildirilmesini isteme

8. Verilerin münhasıran otomatik sistemlerle analiz edilmesi suretiyle aleyhinize bir sonuç ortaya çıkmasına itiraz etme

9. Kanuna aykırı işleme sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme

GDPR kapsamındaki haklarınız

Erişim (m.15), düzeltme (m.16), silinme (m.17), işlemenin kısıtlanması (m.18), veri taşınabilirliği (m.20), itiraz (m.21) ve otomatik karar almaya tabi olmama (m.22) haklarına sahipsiniz. Ayrıca yetkili denetim makamına şikâyette bulunma hakkınız saklıdır.


9. Başvuru Usulü

Haklarınıza ilişkin taleplerinizi kaptan3k@gmail.com adresine iletebilirsiniz.

Veri Sorumlusuna Başvuru Usul ve Esasları Hakkında Tebliğ uyarınca başvurunuzu ayrıca şu yollarla da yapabilirsiniz:

Başvurunuzda ad-soyad, imza (yazılı başvuruda), T.C. kimlik numarası (yabancılar için uyruk ve pasaport numarası), tebligata esas adres, varsa telefon ve e-posta ile talep konusu yer almalıdır.

Başvurularınız, talebin niteliğine göre en kısa sürede ve her hâlükârda en geç OTUZ (30) GÜN içinde sonuçlandırılır. İşlemin ayrıca bir maliyet gerektirmesi hâlinde Kurul tarafından belirlenen tarifedeki ücret alınabilir.

Talebinizin reddedilmesi veya yanıtın yetersiz bulunması hâlinde, yanıtı öğrendiğiniz tarihten itibaren 30 gün ve her hâlde başvuru tarihinden itibaren 60 gün içinde Kişisel Verileri Koruma Kurulu'na şikâyette bulunabilirsiniz.


10. 18 Yaş Sınırı

Takıl 18 yaş ve üzeri kullanıcılar içindir. Kayıt sırasında yaş beyanı alınır ve doğum yılı kaydedilir. 18 yaşından küçük olduğu tespit edilen hesaplar kapatılır ve verileri silinir.

18 yaşından küçük bir kişiye ait veri işlediğimizi düşünüyorsanız lütfen kaptan3k@gmail.com adresinden bize bildirin.


11. Veri Güvenliği

Hiçbir sistem mutlak güvenlik vaat edemez. Bir güvenlik açığı fark ederseniz lütfen kaptan3k@gmail.com adresinden bildirin.


12. Değişiklikler

Bu metinde değişiklik yapılması hâlinde güncel sürüm bu sayfada yayımlanır ve "son güncelleme" tarihi değiştirilir. Esaslı değişikliklerde uygulama içi bildirim yapılır.


13. İletişim

Barbaros Köklü

kaptan3k@gmail.com

Şikâyet ve acil bildirimlere 48 saat içinde dönüş yapılır. Veri sahibi başvuruları için yasal süre bölüm 9'da belirtilen 30 gündür.

Privacy Policy

Effective date: 3 August 2026

Last updated: 3 August 2026

This document explains how the Takıl mobile application processes your personal data. It serves as our disclosure notice under Turkish Personal Data Protection Law No. 6698 (KVKK) and as our information notice under the EU General Data Protection Regulation (GDPR).


1. Data Controller

Controller Barbaros Köklü (natural person)
Contact kaptan3k@gmail.com
Application Takıl
Web takil.app

Takıl is operated by an individual, not a legal entity. This notice will be updated if that changes.


2. What Data We Process

2.1 Account and authentication

2.2 Profile

Name, profile photo, short status text ("now" text), bio, city, interest tags, links/social handles, your stated intent ("why I'm here") and notification preferences.

All of these fields are optional; fields you leave empty are not processed.

2.3 Location — how this actually works matters

Takıl does not store precise coordinates.

While the app is open, your device location is rounded to an approximately 150-metre grid cell, and only that cell identifier (grid_x, grid_y) plus a last-updated timestamp is kept on your account. In other words, the server does not hold "this street, this building" — it holds "somewhere in this 150-metre square".

2.4 Events and social interaction

Events you attend and your attendance status, check-in time, your messages in event chats, comments, poll votes, emoji reactions, event photos you upload, likes, people you save and your notes on them, mutual matches, thank-you notes, and points you earn.

2.5 Signals

The text of a signal you post, its photo if any, its grid cell, city, view count and expiry time. Signals are time-limited content and lapse when they expire.

2.6 Messaging

The content of your direct messages, sender/recipient information and read timestamps.

A point we need to state plainly: messages are not end-to-end encrypted. They are encrypted in transit with TLS and protected in the database by row-level access rules; however, they are technically readable by the database administrator. We recommend you do not share sensitive information through messaging.

2.7 Contacts matching (optional)

See section 4 for the full explanation.

2.8 Notifications

Your device's push notification token, platform (iOS/Android) and delivery status. If registration fails, that error record is also kept.

2.9 Safety and moderation

Reports you submit, users you block, flags produced by the automated content filter, and their resolution status.

2.10 Technical diagnostic data

If the app crashes, we collect the crash stack trace, device model, operating system version, app version and the trail of actions preceding the crash. We also measure performance on a small share of sessions (20%). This data is not linked to your identity — we do not send your user identifier to our diagnostics provider.

2.11 Link click statistics

When someone clicks a promotional link for the app, we record the operating system, language, campaign tag and a coarse location derived from the IP address (country/region/city/district). This record is not linked to any user account.

2.12 What we do NOT process


3. Purposes and Legal Bases

Purpose Data KVKK Art. 5 basis GDPR Art. 6 basis
Account creation and session management Authentication data Performance of contract Art. 6(1)(b) Contract
Displaying your profile Profile data Performance of contract Art. 6(1)(b) Contract
Event discovery, attendance, chat Event and interaction data Performance of contract Art. 6(1)(b) Contract
Nearby / Signal Grid location Explicit consent Art. 6(1)(a) Consent
Contacts matching Phone/email hashes Explicit consent Art. 6(1)(a) Consent
Sending notifications Push token Explicit consent Art. 6(1)(a) Consent
Enforcing the 18+ limit Year of birth Legal obligation · Legitimate interest Art. 6(1)(c) · 6(1)(f)
Safety and abuse prevention Reports, blocks, moderation Legitimate interest Art. 6(1)(f) Legitimate interest
Debugging and stability Diagnostic data Legitimate interest Art. 6(1)(f) Legitimate interest

You may withdraw consent at any time for consent-based processing by turning the relevant feature off in Settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.


4. Contacts Matching — The Full, Honest Explanation

This feature runs only when you start it and can be turned off at any time. Here is exactly what happens:

1. Phone numbers and email addresses in your address book are hashed on your device using SHA-256.

2. The numbers and email addresses themselves are never sent to our servers.

3. However, in order for matching to work, those hashes are sent to the server. The server compares the incoming hashes only against registered users' own stored hashes and returns the matches to you.

4. The hashes you send are not stored on the server. They disappear with the query once the comparison completes; no persistent record is created.

5. A hash of your own phone number and email address is stored on your account so that others can find you.

6. If you turn off "discoverable via contacts" in your profile, your hashes are excluded from matching entirely.

A technical point we owe you honestly: although SHA-256 is a one-way function, a hash of short and predictable data such as a phone number is not anonymous. We therefore classify these hashes not as anonymous data but as personal data, and process them under KVKK/GDPR protection.

People in your address book may not be Takıl users and may not have consented to this processing. For that reason: hashes that do not match are never recorded, used, or processed to build any profile.


5. Third-Party Service Providers

Provider Purpose What is transferred Data location
Supabase Database, file storage, authentication All application data Frankfurt, Germany
Apple (Sign in with Apple, APNs) Authentication, iOS notifications Email, UID, push token USA / global
Google (Sign in with Google) Authentication Email, UID USA / global
Google Maps Map rendering Map view requests USA / global
Google Places Venue search when creating an event The venue search text you type USA / global
Expo / EAS App distribution and notification delivery Push token, notification content USA
Sentry Crash and error diagnostics Crash trace, device/OS/version info — without linking to your identity Germany (ingest endpoint)
Meta / Instagram The Takıl Instagram feed shown in-app Requests made to fetch the feed USA / global
Vercel Hosting of these legal pages Page view requests Global

These providers act as data processors, solely for the purposes stated here and on our instructions. None of them is authorised to use your data for their own purposes.


6. International Transfers

Your user data is hosted on servers in Frankfurt, Germany. Some of the providers listed in section 5 are established outside Türkiye.


7. Retention Periods

Data Period
Account and profile data For as long as the account exists
Event attendance and chats For as long as the account exists
Messages For as long as the account exists
Signals Until the signal expires
Grid location Only the most recent cell is kept; no location history is created
Hashes sent from your contacts Not stored — discarded when the query ends
Your own phone/email hash For as long as the account exists
Push token Until you disable notifications or delete your account
Diagnostic (crash) data For Sentry's retention period (up to 90 days)
Reports and moderation records Retained for a reasonable period even after account deletion, for legal compliance and abuse prevention

When you delete your account via Settings > Delete Account, your data is permanently erased together with all associated records. This action cannot be undone.


8. Your Rights

Your rights under KVKK Article 11

By applying to the data controller you may:

1. Learn whether your personal data is being processed

2. Request information if it has been processed

3. Learn the purpose of processing and whether the data is used in accordance with that purpose

4. Know the third parties to whom your data is transferred, domestically or abroad

5. Request rectification of incomplete or inaccurate data

6. Request erasure or destruction within the conditions of Article 7

7. Request that rectification, erasure and destruction be notified to the third parties to whom the data was transferred

8. Object to an adverse outcome arising from analysis carried out exclusively by automated systems

9. Claim compensation for damages suffered as a result of unlawful processing

Your rights under GDPR

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21) and not to be subject to automated decision-making (Art. 22). You also retain the right to lodge a complaint with the competent supervisory authority.


9. How to Submit a Request

You may send requests concerning your rights to kaptan3k@gmail.com.

Under the Turkish Communiqué on the Procedures and Principles of Application to the Data Controller, you may also submit your request:

Your application should state your name and surname, signature (for written applications), Turkish ID number (for foreign nationals, nationality and passport number), an address for notification, your telephone and email if any, and the subject of your request.

Requests are concluded as soon as possible and in any event within THIRTY (30) DAYS. Where the process incurs a cost, a fee under the tariff set by the Turkish Data Protection Board may be charged.

If your request is refused or you find the response inadequate, you may lodge a complaint with the Turkish Personal Data Protection Board within 30 days of learning the response and in any event within 60 days of the application date.


10. Age Limit: 18+

Takıl is intended for users aged 18 and over. Age is declared at sign-up and the year of birth is recorded. Accounts found to belong to users under 18 are closed and their data deleted.

If you believe we are processing data belonging to a person under 18, please notify us at kaptan3k@gmail.com.


11. Data Security

No system can promise absolute security. If you discover a vulnerability, please report it to kaptan3k@gmail.com.


12. Changes

If this notice changes, the current version will be published on this page and the "last updated" date will be revised. Material changes will be announced in-app.


13. Contact

Barbaros Köklü

kaptan3k@gmail.com

Reports and urgent notifications receive a response within 48 hours. The statutory period for data subject requests is the 30 days stated in section 9.