Gezi Rehberim – Privacy Policy
Last Updated: May 15, 2026
This Privacy Policy explains how personal data is collected, used, stored, and protected for users of the Gezi Rehberim application (“App”). By downloading, registering for, or using the App, you represent that you have read, understood, and agreed to all provisions of this policy. If you do not agree, you must not use the App.
2. Data We Collect
The following information is collected during registration:
- Email address – for authentication and sending verification emails
- Username – for creating an in-app profile
- Password – hashed by Firebase Authentication; never stored as plain text
- Profile photo – optionally uploaded by the user; stored in Firebase Storage
- Biography (bio) – optionally added by the user
2.3 Travel Data
- Visited countries and cities – for displaying on a map and generating statistics
- Travel memories and photos – user-generated content; stored in Firebase Storage and Firestore
- AI-assisted travel plans – plans created and approved by the user; stored in Firestore
2.4 Location Data
- Current location – used only for the “show my location on map” feature, after explicit user consent
- Location data is not sent to our servers; it is processed on-device and may be attached to a travel record at the user’s own request
2.5 Social Features
- Friend requests – sender and recipient user IDs (UIDs); stored in Firestore
- Direct messages (DMs) – messages and shared media between users; stored in Firestore and accessible only to the relevant participants
⚠️ Important: In-app messages and shared media are not end-to-end (E2E) encrypted. Messages are stored in Google Cloud Firestore and images in Firebase Storage, protected under Google’s own security standards. By using the App, the user acknowledges and accepts this technical limitation.
2.6 Notification Data
- FCM Token (Firebase Cloud Messaging) – used to send friend request notifications; stored in Firestore
- Notification permission is always explicitly requested from the user
- Premium subscription status – managed via RevenueCat; monthly and yearly subscription options
- Credit card or payment information is not processed by the App; it is handled by the App Store and RevenueCat
2.8 Device & Technical Data
- Device identifiers – used solely within the RevenueCat integration
- App preferences and settings – language, theme, offline map mode; stored encrypted on-device (Hive + flutter_secure_storage)
- AI question usage quota – stored on-device to track the daily AI question limit
3. How We Use Your Data
| Data |
Purpose |
| Email & Password |
Authentication |
| Username |
Profile identification and friend search |
| Profile photo |
In-app profile display |
| Location |
Real-time location display on map |
| Travel data |
Personal map and statistics |
| Travel memories & photos |
User’s personal archive |
| DM messages |
Communication with friends |
| FCM Token |
Push notification delivery |
| RevenueCat data |
Premium subscription management |
4. Third-Party Services
The App uses the following third-party services, each governed by their own privacy policies:
5. Photo Safety Filter
Uploaded profile photos and travel memory images are analyzed by an on-device content safety filter (NSFW detector) to detect inappropriate content. This analysis is performed entirely on-device; images are never sent to any server for this purpose.
6. Local Storage & Security
The App stores some data encrypted on your device:
- Hive for local database
- flutter_secure_storage for encryption keys
This data is used solely for app functionality and is not shared with third parties.
⚠️ Security Limitation: No method of data transmission over the internet or electronic storage is 100% secure. While the developer applies industry-standard technical safeguards, absolute security is not guaranteed. By using the App, the user acknowledges and accepts this technical reality.
7. Data Retention & Deletion
- When you delete your account, your personal data (profile information, travel data, photos, messages) is deleted from Firestore and Firebase Storage.
- To request account deletion: send an email to egeseymen@icloud.com.
- Purchase history in RevenueCat may be separately retained by the App Store in accordance with App Store policies.
8. App Permissions
The App uses the following permissions. All permissions are explicitly requested before use:
| Permission |
Purpose |
| Location (While Using) |
Real-time location display on map |
| Camera |
Taking profile photos and travel memory shots |
| Photo Library |
Selecting profile and travel images, sharing photos in chat |
| Notifications |
Friend request and acceptance notifications |
9. Children’s Privacy
The App is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13. If you become aware of such a case, please contact us.
10. Data Transfers
Collected data is processed through Google (Firebase) and RevenueCat infrastructure and may be stored on servers in locations including the United States. These transfers are carried out under the relevant service providers’ data processing agreements and GDPR-compliant standard contractual clauses.
11. Your Rights
You have the following rights regarding your personal data:
- Right to access your data
- Right to rectification of inaccurate data
- Right to erasure of your data
- Right to object to data processing
To exercise these rights: egeseymen@icloud.com
12. Policy Changes
This Privacy Policy may be updated from time to time. You will be notified of significant changes via an in-app notification or email. The current policy is always available on this page.
For questions about our privacy policy:
Email: egeseymen@icloud.com
14. Prohibited Use
The App may only be used for lawful and ethical purposes. The following activities are strictly prohibited:
A. Violence, Threats & Harassment
- Threatening, blackmailing, or coercing any person through the App
- Sending messages or media containing harassment, abuse, hate speech, or discrimination
- Stalking or covertly monitoring other users
- Cyberbullying or subjecting any person to an overwhelming barrage of unwanted messages
- Sharing content that promotes, glorifies, instructs, or facilitates self-harm, suicide, or acts of violence
B. Sexual Abuse & Obscene Content
- Creating, sharing, or transmitting child sexual abuse material (CSAM)
- Sharing private images or photos of others without their consent (including revenge pornography and AI-generated deepfakes)
- Creating or distributing obscene or pornographic content
- Sexual extortion (sextortion) or any form of sexual coercion
C. Organized Crime & Illegal Organizations
- Forming, managing, or joining a criminal organization, or using the App to recruit members, coordinate activities, or operate on its behalf
- Forming, managing, or joining an armed terrorist organization, or creating propaganda on its behalf
- Facilitating, supporting, or producing content on behalf of any illegal armed or unarmed organization (including but not limited to FETO, PKK, and similar groups)
- Organizing, advertising, or facilitating illegal organization meetings, membership drives, or fundraising activities
- Supporting organized activities aimed at undermining state authority or the constitutional order
D. Drug, Weapons & Human Trafficking
- Drug trafficking — buying, selling, supplying, or facilitating trade in controlled or illegal substances
- Weapons, explosives, or ammunition trafficking or unlawful procurement
- Human trafficking or migrant smuggling — including facilitation or coordination
- Organ or tissue trafficking
E. Fraud & Financial Crimes
- Using the App for fraud, money laundering, payment fraud, or financial deception
- Operating or promoting Ponzi schemes, pyramid schemes, or unlawful investment plans
- Conducting illegal financial transactions via cryptocurrency or digital assets
- Facilitating tax evasion
- Producing, sharing, or using forged documents, invoices, or official instruments
- Organizing, operating, or soliciting participants for illegal gambling or betting
- Organizing the sale of counterfeit goods or trademark-infringing products
F. Privacy & Identity Violations
- Impersonating another individual or creating fake profiles
- Collecting, processing, or sharing personal data without the subject’s consent
- Publishing others’ private communications, photos, or personal information without authorization
- Identity document or official record forgery
G. Cybercrime & Technical Violations
- Attempting to gain unauthorized access to the App, servers, or network infrastructure
- Sending malware, viruses, ransomware, or phishing content
- Conducting DDoS attacks or any technical attempt to disrupt the App’s functionality
- Operating coordinated inauthentic accounts via bots, scrapers, or automated tools
- Sending unsolicited commercial messages (spam)
- Sharing content that incites hatred or discrimination based on race, religion, language, gender, disability, or political opinion
- Sharing content that insults or demeans religious values or incites societal hostility
- Spreading disinformation or deliberately false information that threatens public order
- Sharing copyrighted content without authorization
- Transmitting content depicting animal abuse or cruelty
Accounts found in violation of these rules may be suspended or permanently terminated immediately and without prior notice. Competent legal authorities may be notified where required, and such notification may occur without prior notice to the user.
15. User-Generated Content
- Sole responsibility for all content shared through the App (messages, photos, comments, travel memories) rests with the user who created it.
- The developer has no obligation to pre-moderate user content but reserves the right to remove content and initiate appropriate action upon receiving a violation report.
- Intellectual property rights over content remain with the user; however, by sharing content through the App, the user grants the developer a limited, non-exclusive license necessary for operating the App.
- The user represents and warrants that content they share does not infringe the rights of third parties (copyright, personality rights, privacy rights, etc.).
16. Law Enforcement Cooperation
The developer may be required to share user data with competent authorities in the following circumstances:
- Receipt of a lawful order, summons, or official request from courts, public prosecutors, or law enforcement agencies
- A notification obligation arising under applicable data protection law
- Detection of a serious and imminent threat to a user’s life or physical safety
- Mandatory reporting of content suspected or confirmed to contain CSAM
- Compliance with authority requests in connection with cybercrime, fraud, or counter-terrorism investigations
In such cases, prior notice to the user may not be possible. The developer assumes no liability for complying with a valid legal request.
17. Account Suspension and Termination
The developer may suspend or permanently terminate a user account without prior notice in the following circumstances:
- Violation of the prohibited use rules set out in Section 14
- Verified complaints filed by other users or third parties
- Attempts to compromise the App’s technical infrastructure
- Any other conduct deemed inappropriate by the developer
Subscription fees paid are non-refundable upon account termination due to a policy violation. The developer reserves the right to retain relevant data independently of an account deletion request if required by an active legal proceeding or authority request.
18. Limitation of Liability
To the maximum extent permitted by applicable law, the developer shall not be liable for:
- Physical, emotional, or financial harm arising from interactions, disputes, or communications between users
- Outages, security incidents, or data loss caused by third-party service providers (Google Firebase, RevenueCat, OpenStreetMap, etc.)
- Damages resulting from force majeure events (natural disasters, cyberattacks, infrastructure failures, government actions, etc.)
- Any harm arising from decisions made in reliance on AI-generated content
- No warranty, express or implied, is made that the App will meet any particular purpose or operate uninterrupted and error-free
- Any unauthorized access, message leak, or image exposure resulting from the user’s failure to safeguard their account credentials (password, email, device)
- Data exposure caused by the theft, loss, malware infection, or unauthorized sharing of the user’s device
- Disclosure of messages or images sent through the App despite the user having been clearly informed that end-to-end encryption is not provided
- Any security breach, vulnerability, or data leak within Google LLC’s (Firebase/Firestore/Storage) or RevenueCat Inc.’s own systems; such events are outside the developer’s control and are the responsibility of the respective company
- Harm arising from content being copied, screenshotted, or redistributed outside the App by another user
- Account takeover resulting from social engineering, phishing, or unauthorized access by a third party
The developer’s maximum aggregate liability for any claim shall not exceed the total subscription fees paid by the user in the preceding 12 months. For free-tier users, the developer’s maximum liability is zero (USD $0).
19. Indemnification
The user agrees to indemnify, defend, and hold harmless the developer and its affiliates from and against any claims, damages, penalties, administrative actions, or legal costs (including reasonable attorney’s fees) arising from the user’s violation of this policy, applicable law, or the rights of any third party. This obligation covers both intentional conduct and negligence.
20. AI Content Disclaimer
AI-assisted travel plans and suggestions provided within the App are for general informational purposes only and do not constitute professional travel advice, medical guidance, or safety consulting.
- The developer makes no guarantee as to the accuracy, completeness, or currency of AI-generated content.
- The developer accepts no liability for any harm resulting from decisions made based on AI suggestions.
- Users are always advised to consult authoritative and up-to-date official sources regarding travel safety and health matters.
21. Data Breach Notification
In the event of a security breach resulting in unauthorized access to personal data:
- Affected users will be notified within 72 hours via email or in-app notification.
- Required notifications will be submitted to the relevant supervisory authority in accordance with applicable data protection law.
- Users will be informed of the scope of the breach, categories of data affected, and remediation measures taken.
22. Abuse Reporting Mechanism
To report illegal content, threats, blackmail, harassment, or any policy violation occurring through the App:
Email: egeseymen@icloud.com
Subject line: [REPORT] – User Complaint
Please include: the username/UID of the reported user, date and time of the incident, and any available screenshots. All reports are reviewed within 5 business days. Reports involving imminent threats to life or safety are treated as urgent and, where necessary, escalated to law enforcement.
23. Data Protection Rights (GDPR / KVKK)
For users in the European Economic Area or other jurisdictions with applicable data protection laws, you have the following rights regarding your personal data:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure (“right to be forgotten”)
- Right to restriction of processing
- Right to data portability
- Right to object to processing
- Right not to be subject to solely automated decision-making
To exercise any of these rights: egeseymen@icloud.com
You also have the right to lodge a complaint with your local data protection supervisory authority.
24. Governing Law and Jurisdiction
This Privacy Policy and any disputes arising from or in connection with the App shall be governed by and construed in accordance with the laws of the Republic of Turkey. The courts and enforcement offices of Istanbul shall have exclusive jurisdiction to resolve any such disputes.
25. User Account Security Obligations
The user agrees to the following obligations in order to maintain account security:
- Keep their password strong, unpredictable, and unique; update it regularly
- Never share their password with anyone and store it securely on their device
- Immediately notify egeseymen@icloud.com upon detecting any unauthorized access or suspicious activity on their account
- Sign out of the App in shared or unsecured environments after use
- Keep their device protected with up-to-date operating system and security patches
The developer shall not be liable for account takeover, message leaks, or image exposure resulting from the user’s failure to fulfil these obligations. Any additional harm caused by delayed notification shall also be borne solely by the user.
26. Third-Party Infrastructure Breach Disclaimer
The App relies on independent third-party service providers including Google LLC (Firebase), RevenueCat Inc., and the OpenStreetMap Foundation. In the event of a data breach, leak, cyberattack, service outage, or unauthorized access within those providers’ infrastructure:
- The developer cannot anticipate or prevent such incidents and therefore bears no liability for any resulting harm.
- Full responsibility lies with the affected service provider.
- Users should direct any claims arising from such incidents to the relevant provider directly:
- The developer will make reasonable efforts to notify users of any such incidents it becomes aware of, but notification obligations are limited strictly to systems under the developer’s own control.
27. Message and Media Content Disclaimer
Direct messages (DMs) and shared media files (photos, images) within the App are stored under the following conditions:
- Messages and images are not end-to-end (E2E) encrypted. Data is protected under Google Cloud Firestore and Firebase Storage using Google’s own security standards.
- The developer reserves the right to access messages and media for technical support, legal compliance, or security review purposes.
- The user acknowledges that the messaging channel is not a secure communication medium and agrees not to transmit sensitive personal, financial, or legal information through it.
- The developer shall not be liable for the exposure of messages or images resulting from a third party gaining access to an account or copying content outside the App.
- Any legal disputes, defamation, threats, or copyright claims arising from messages exchanged between users are the sole responsibility of the users involved.
28. Force Majeure
The developer shall not be held liable for partial or complete service interruption, data loss, temporary inaccessibility of data, or any direct or indirect damages resulting from events beyond the developer’s reasonable control, including but not limited to: earthquake, flood, fire, pandemic, war, act of terrorism, government intervention, regulatory change, power outage, internet infrastructure failure, large-scale cyberattack (DDoS, ransomware, etc.), or any other comparable force majeure event.
In the event of a force majeure, the developer will make reasonable efforts to restore service but will make no commitment regarding a specific timeline or full data recovery.
29. Disclaimer of Warranties
The App is provided “as is” and “as available” without any representations or warranties of any kind, express or implied. The developer specifically disclaims all warranties regarding:
- The App operating uninterrupted, error-free, or securely
- Stored data being free from loss or corruption
- Messages and images being absolutely protected from unauthorized access
- The App being fit for any particular purpose of the user
- Any security vulnerability being detected or remediated within a specific timeframe
By using the App, the user expressly acknowledges and accepts these conditions.
30. Limitation on Consequential Damages
To the maximum extent permitted by applicable law, the developer shall not be liable for any indirect, incidental, special, consequential, or punitive damages — including but not limited to loss of use, loss of data, loss of profits, reputational harm, or emotional distress — even if the developer has been advised of the possibility of such damages. This exclusion covers:
- Message and image leaks resulting from third-party infrastructure breaches
- Personal data exposure resulting from account security compromise
- Damages arising from App unavailability or data loss
- Harm suffered as a result of another user’s content
Where mandatory consumer protection law applicable in the user’s jurisdiction provides broader protection, such statutory rights are preserved and not limited by this clause.