Privacy Policy

Last updated:

This policy explains which personal data is processed when the DuyApp mobile application and the duyapp.com website are used, the purposes for which this data is used, with whom it is shared and how long it is kept. The data controller is DUYAPP YAZILIM LİMİTED ŞİRKETİ.

The legal grounds for processing personal data under Law No. 6698 on the Protection of Personal Data (KVKK) and information on how to exercise your rights are available on the KVKK Disclosure Notice page.

Key points

Account creation

You can register for DuyApp only with a university email address ending in .edu.tr. During registration, a 6-digit verification code is sent to the email address. The code is valid for 10 minutes and only its hashed form is kept in our systems.

Once the email address is verified, a passkey is created for signing in to the account. DuyApp does not use passwords. The passkey is protected by the device's own security system (Face ID, fingerprint or device lock). Biometric data stays on the device and is not transmitted to DuyApp. The email address appears as the name of the passkey in the device's password manager and, if the passkey is synced, it is also stored in iCloud Keychain or Google Password Manager.

No first name, last name, phone number, date of birth or gender is requested during registration.

Data processed

Account information

Session and security information

Shared content

Uploaded photos are reprocessed on our servers, and during this process additional data such as the location and device information within the photo (EXIF) is removed. The original of the photo is deleted after it has been processed.

Notification information

To send push notifications, the device's notification token (push token), device platform, language, time zone, application version and a random installation ID that the application generates for each installation are processed.

Duy Points and invitations

Report and block records

When content is reported, the reporting account, the reported content and account, the reason for the report and any explanation attached to the report are recorded. When anonymous content is reported, the account that the content belongs to is also added to the report record. Records relating to blocked accounts are also kept.

Device permissions

Contacts, the microphone and the device's motion sensors are not used. Permissions can be withdrawn at any time in the device settings.

Data not processed

The DuyApp application does not collect first name, last name, phone number, date of birth, gender, contacts or biometric data. The application does not currently use an advertising ID and does not perform cross-app tracking.

Location

DuyApp is a hyperlocal application. Content is shown according to the area in which it was shared. Location information is therefore necessary for the core operation of the application.

How location is collected

How location is stored

What other users see

Location access can be turned off in the application settings or the device settings. When location access is turned off, the area-based features of the application do not work.

Anonymity

On DuyApp, content can be shared under a nickname or anonymously.

Information contained in the content itself (such as a name, place, event or photo), together with the area name and the time of sharing shown with the content, may lead others to guess the identity of the author, particularly in small areas.

Private messages

Encryption

Identity

A user who starts a message from a post appears to the other party only under an anonymous label specific to that conversation. The owner of the post appears in the way the post was shared: under an anonymous label if the post is anonymous, or under their nickname if it was shared under a nickname.

Retention

Reporting messages

When a conversation is reported, with the consent of the reporting user, up to 10 of the most recent messages on their device are sent to the moderation team. After reaching the server, these messages are separately encrypted and stored, and can be opened only by authorised moderators. The account of the reported person is also added to the report record. Evidence copies of the reported messages are kept for 90 days from the creation of the evidence record, and the report record is kept for 365 days from its creation. The reported person is not notified of the report.

Artificial intelligence (Duyu)

The artificial intelligence features in DuyApp are offered under the name Duyu and operate through an artificial intelligence service provider located abroad. Details on the recipient and the use of data are explained in the Duyu data transfer section.

Duyu chat

Use of posts in Duyu

Duyu Fun

Duyu chats are different from end-to-end encrypted private messages between people; they are sent to the service provider in order to generate replies. Automatic masking cannot detect all personal information and does not necessarily make the text anonymous. Do not write unnecessary identity, contact or sensitive information to Duyu, and do not unlawfully share private information belonging to others.

The publication of a post or acceptance of the Terms of Service does not mean that the personal data in that post may be used in artificial intelligence for every purpose. The scope of use of posts in Duyu and the explanations on special categories of personal data are addressed separately in the KVKK Disclosure Notice.

Duyu data transfer

The data described above in connection with Duyu chat, Duyu Fun and the use of posts in Duyu is sent to the OpenAI service, based in the United States. The service provider processes this data on behalf of DuyApp. This transfer does not cover end-to-end encrypted messaging between people.

In Duyu requests, the email address, username, nickname or raw account ID is not sent as a separate account field. However, the text you write or the content of a post may contain this information. In some requests, a pseudonymised security code derived from the account ID of the requesting user is sent to the artificial intelligence service provider for the detection of abuse. This code does not reveal the raw account ID; it is not regarded as anonymous data.

In this provider's API service, customer data is not used for model training by default. Abuse monitoring logs may be kept for up to 30 days under normal conditions; longer retention may apply because of legal obligations or security exceptions. The retention periods of application logs may also vary depending on the API feature used. For this reason, no definitive commitment of 30-day deletion or zero retention is given for all data. Details are set out in the provider's API data explanation. Transfer abroad is also explained below.

Purposes of processing

The legal grounds on which data is processed are explained in the KVKK Disclosure Notice.

Sharing of data

Other users

Service providers

DuyApp's main application server and database are kept on the infrastructure of the hosting service provider. So that the service can be provided, only the data necessary for the relevant service is shared with the following service providers:

Transfer abroad

Transferring personal data abroad requires the conditions set out in Article 9 of Law No. 6698 to be met. For regular service provider transfers, an adequacy decision or appropriate safeguards are assessed; the exceptions for occasional transfers do not give a general permission for continuous API use. Service providers may process data abroad. For the relevant services, the countries where processing actually takes place and the transfer mechanism used are stated in the KVKK Disclosure Notice.

Competent authorities

Personal data may be shared with competent authorities in line with legal obligations and upon requests made in due form.

Corporate transactions

In the event of a merger, demerger, acquisition or sale of assets of the company that operates DuyApp, personal data may be transferred to the relevant parties, limited to the safeguards in this policy.

Retention periods

Data whose retention period has ended is deleted, destroyed or anonymised. Records kept separately for a specific report, security incident, legal dispute or binding preservation obligation are limited to the relevant purpose and the necessary period; not all records are kept indefinitely on this ground.

Account deletion

The account can be deleted from within the application with passkey confirmation. If the application cannot be accessed, a deletion request can be sent to the support team from the registered university email address.

When deletion is confirmed, the account is closed, the email address is removed from the account, and the content and data belonging to the account enter the deletion process. Certain security, report and message records and backups may be kept for a further period in accordance with the relevant retention conditions. Copies and screenshots on other users' devices cannot be recalled by DuyApp.

Application steps, processing times, deleted data, retention exceptions and temporary security restrictions are explained together on the Delete Account page.

Data security

Technical and administrative measures are taken for the security of personal data. Communication between the application and the servers is encrypted. Passwords are not used. Sign-ins are made with a passkey. Verification codes and session keys are stored only in hashed form. The content of private messages is end-to-end encrypted.

Website

The duyapp.com website does not use cookies for advertising or analytics purposes. The site is served on the infrastructure of the hosting and security service provider; the site's access logs are processed by the same provider for security purposes.

Age limit

DuyApp is intended only for users aged 18 and over. Verification of a university email address does not constitute age verification. The accounts of users found to be under 18 are closed and their data enters the deletion process; records that must be kept by law are retained, limited to the relevant purpose and period.

Rights

Under Article 11 of Law No. 6698, rights such as learning whether personal data is being processed, requesting information, requesting correction or deletion, and the other rights can be exercised. Applications can be made to destek@duyapp.com and are concluded free of charge within 30 days at the latest. The application methods and the full list of rights are set out in the KVKK Disclosure Notice.

Changes

This policy may be updated as the features of the application or the relevant legislation change. If advertising or a new data processing activity is added to the application, this policy is updated before the feature in question is made available, and explicit consent is obtained where necessary. The publication date of the current version appears at the top of the page. Significant changes are also announced within the application.

Contact

For questions about this policy, you can write to destek@duyapp.com, and for requests relating to personal data, to destek@duyapp.com.

The company and postal address details are included in the Terms of Service.