oynd.
Terms of ServiceSubscription TermsCommunity GuidelinesSupport
Back home

Privacy and data protection

Privacy Policy and Data Protection Notice

Last updated: July 30, 2026

1. Data controller

Bilgizci Yazılım Tasarım Yayıncılık ve Ticaret Limited Şirketi, a limited liability company established in the Republic of Türkiye, is the data controller for the personal data described in this notice. Privacy and support requests: info@bilgizci.com. Formal applications and legal notices: bilgizciyazilim@hs01.kep.tr.

This Privacy Policy and Data Protection Notice (“Notice”) explains how we collect, use, disclose, transfer, retain, and protect personal data when you use oynd. It is intended to provide the information required under Article 10 of Türkiye’s Personal Data Protection Law No. 6698 (“KVKK”) and other applicable privacy laws.

2. Scope and collection methods

We collect personal data electronically: directly from you when you register, confirm adult eligibility, edit a profile, configure settings, submit a report, request support, or delete an account; automatically from your device and use of the Service; from other users when they send friend requests, oynds, blocks, or reports involving your account; from Apple concerning an age range and subscription entitlement; and from service providers that operate authentication, hosting, messaging, security, and diagnostics.

Providing data marked optional is voluntary. If required account, authentication, safety, or subscription data is not provided, the relevant feature or the Service may not be available.

3. Account and profile data

We process your name, username, email address, optional phone number, Firebase authentication identifier, email-verification state, optional profile image, account status, creation and update timestamps, and legal-document acknowledgment and acceptance records.

To enforce the adults-only eligibility rule, supported Apple devices may provide an age range rather than an exact age. We may record that the range meets the minimum age, its lower or upper bound where provided, whether a regulatory check was required, the declaration category, the check method, and a server timestamp. We do not receive or store your exact birth date through Apple’s Declared Age Range API. Where that API is unavailable or sharing is not legally required, we may record your 18-or-older self-attestation instead.

Firebase Authentication processes credentials for email authentication. Bilgizci does not receive or store your password in readable form. Password reset and verification messages are delivered through authentication services.

4. Social, activity, and safety data

We process username searches, friend requests and responses, accepted friendships, removals, blocks, oynd and oynd-back events, turn and cooldown state, activity and notification history, timestamps, rate-limit records, report reasons and details, reported and reporting account identifiers, moderation status, and account-enforcement actions.

Report and support text may contain information you choose to provide. Do not submit unnecessary sensitive or special-category personal data. We may process information concerning alleged misconduct where necessary to protect rights, investigate safety concerns, establish or defend legal claims, or comply with law.

5. Device, notification, security, and diagnostic data

We process push-notification tokens and device-registration identifiers, device platform, notification preferences, quiet-hour settings, time-zone offset, app version, authentication state, request metadata, IP address and service logs, security and abuse signals, and crash or diagnostic information.

Firebase Cloud Messaging and Apple Push Notification service deliver notifications. Firebase Crashlytics processes crash traces, installation identifiers, and technical device or app information used to diagnose reliability problems. Notification content may be visible on a device lock screen according to the user’s iOS settings.

We do not use personal data for third-party advertising, cross-context behavioral advertising, or tracking across apps and websites owned by other companies.

6. Subscription data

When subscriptions are enabled, Apple processes payment credentials and purchase confirmation. We may receive and store transaction or original-transaction identifiers, product identifier, purchase, renewal, expiration, revocation, refund or billing state, storefront country, offer eligibility, and entitlement status. We do not receive or store your full payment-card number.

Apple’s independent processing is governed by Apple’s privacy terms. Account deletion does not delete records Apple must or chooses to retain independently and does not automatically cancel a subscription.

7. Purposes and legal bases

We process account, profile, social, activity, device, and subscription-entitlement data to enter into and perform our agreement with you, provide requested features, authenticate users, maintain friendships and history, deliver notifications, verify paid access, restore purchases, and provide support. Under KVKK, this processing principally relies on necessity for the establishment or performance of a contract and, where applicable, establishment, exercise, or protection of a right.

We process email verification, adult-eligibility and age-range confirmation, logs, rate limits, blocks, reports, diagnostics, and enforcement data to enforce eligibility, meet applicable age-assurance obligations, secure the Service, prevent spam, fraud, abuse, and unauthorized access, investigate incidents, protect users and infrastructure, and improve reliability. This processing relies on legal obligations where applicable, our legitimate interests where those interests do not override fundamental rights, performance of the service agreement, and establishment, exercise, or protection of rights.

We process consent and transaction evidence, respond to authorities and data-subject requests, and retain records where necessary to comply with legal obligations. We rely on explicit consent only where applicable law requires it for a specific optional activity; the Privacy Policy acknowledgment itself is not treated as blanket consent.

We do not make decisions producing legal or similarly significant effects based solely on automated processing. Automated security and rate-limit controls may temporarily accept, delay, or reject technical actions; users may contact us if they believe a control operated incorrectly.

8. Public visibility and other users

Your display name, username, optional profile image, and active profile state may be visible to verified, signed-in users so they can search for and identify accounts. Accepted friends may see friendship, oynd, turn, and related activity information involving them. Private email, optional phone number, legal consent records, device tokens, and report details are not intended to be displayed to other users.

A blocked person may retain information they saw before blocking, and users may capture information outside our control. Do not place private contact details in public profile fields.

9. Service providers, recipients, and disclosure purposes

We disclose data as necessary to processors and recipients that help operate the Service: Google Firebase and Google Cloud services for authentication, database and storage hosting, cloud functions, messaging, application attestation where enabled, logs, and crash reporting; and Apple for App Store distribution, APNs delivery, StoreKit subscriptions, purchase restoration, and platform security.

We may disclose limited information to professional advisers, auditors, insurers, hosting or security vendors, and competent courts, regulators, law-enforcement bodies, or public authorities where necessary for services, legal obligations, valid requests, safety, fraud prevention, rights protection, or dispute resolution.

We may transfer data in a merger, financing, restructuring, acquisition, insolvency, or sale of all or part of the business, subject to confidentiality, lawful processing, and notice requirements. We do not sell personal data and do not share it for cross-context behavioral advertising.

10. International transfers

Because Bilgizci is established in Türkiye and providers operate internationally, personal data may be processed in Türkiye, the United States, and other countries where Apple, Google, Firebase, or their subprocessors maintain facilities. Firebase Authentication is operated from U.S. data centers, while other Firebase services may use global or selected cloud locations.

Where personal data is transferred abroad, we rely on a transfer mechanism permitted by applicable law, including an adequacy decision, an agreement that provides appropriate safeguards such as the standard contracts recognized under Article 9 of the KVKK, binding corporate rules, or a legally available derogation for an occasional transfer. We complete required filings or notifications where applicable.

Different countries may provide different legal protections. We apply contractual, organizational, and technical safeguards appropriate to the transfer and service. Contact info@bilgizci.com for information about the applicable safeguard, subject to confidentiality and security limitations.

11. Retention

We retain profile, private-account, friendship, oynd, notification, preference, and device-registration data while the account is active and until it is deleted, becomes stale, or is no longer needed for the feature. Active-service data targeted by the account-deletion flow is removed from active systems when the deletion completes.

Push tokens are retained until removed, invalidated, replaced, or the account is deleted. Rate-limit and operational-security records are retained for the period reasonably necessary to enforce limits, investigate abuse, and protect the Service. Safety reports and related enforcement evidence may be retained while a report or dispute is active and afterward for the applicable limitation period or as necessary to prevent repeated abuse and establish, exercise, or defend legal claims.

Consent, adult-eligibility, and acceptance evidence, transaction and entitlement records, legal correspondence, and records subject to accounting, tax, consumer, corporate, or regulatory duties are retained for the period required by law and applicable limitation periods. Firebase Crashlytics generally retains crash stack traces and associated identifiers for 90 days before beginning deletion, according to Firebase’s published service information.

Residual copies may remain in provider backups until overwritten or deleted under provider backup cycles. We delete or de-identify data when the applicable purpose and legal retention period end. We periodically review retention criteria and may maintain a more detailed internal retention schedule.

12. Security

We use measures designed to protect personal data, including authenticated access, email verification for social features, role and document access rules, encrypted network connections, server-managed sensitive actions, rate limits, secret and credential controls, logging, dependency updates, and application-attestation controls where enabled.

No method of transmission, storage, or authentication is completely secure. You are responsible for protecting your credentials and device. Notify info@bilgizci.com promptly if you suspect unauthorized access.

13. Your controls

You can update account details, control push and in-app notification preferences, remove friends, block or unblock users, submit safety reports, reset your password, and permanently delete your account through available app controls. You can also control lock-screen notification visibility and permissions in iOS Settings.

Withdrawing optional consent does not affect processing already performed lawfully and does not prevent processing based on another lawful ground. Some information is required to provide or secure the account; deleting that information may require account deletion.

14. Privacy rights and applications

Subject to Article 11 of the KVKK, you may ask whether we process your personal data; request information about processing; learn its purposes and whether it is used accordingly; learn recipients in Türkiye or abroad; request correction; request deletion or destruction where legal conditions are met; request notification of correction or deletion to recipients; object to a result produced exclusively by automated analysis that is against you; and request compensation where unlawful processing causes damage.

Where other applicable privacy laws apply, you may also have rights to access, confirm, correct, delete, obtain a portable copy, restrict or object to processing, appeal a denied request, or opt out of sale, targeted advertising, or qualifying profiling. We do not sell personal data or use it for targeted advertising. We will not unlawfully discriminate against you for exercising a privacy right.

Send requests to info@bilgizci.com or formal KVKK applications to bilgizciyazilim@hs01.kep.tr and include enough information to identify your account and request. Do not send a password or verification code. We may verify identity, authority, and account ownership and may request legally required information. We respond within the period required by applicable law; KVKK applications are answered as soon as possible and no later than 30 days. Requests may be refused or limited where an exemption applies, identity cannot be verified, another person’s rights would be affected, or retention is legally required.

15. Account deletion

Delete your account from Profile > Permanently delete account. The process is designed to delete your Firebase Authentication account, active profile, private account record, friendships, pending requests, oynd threads and events involving you, notifications, preferences, device registrations, username reservation, subscription entitlement copy, blocks you created, and reports you submitted, subject to successful completion and lawful retention exceptions.

Limited transaction, consent, security, abuse, report, legal, and backup records may remain as described above. Reports submitted by other users may be retained in restricted form where necessary for safety, enforcement, rights, or legal obligations. Account deletion does not cancel an App Store subscription; manage it separately through Apple Account subscription settings. See Support and Account Deletion page if you cannot access the app.

16. Adults only

oynd is intended only for adults aged 18 or older and is not directed to children or minors. We do not knowingly offer the Service to or collect personal data through the Service from anyone under 18. Permission from a parent or legal guardian does not authorize a minor to use the Service.

If you believe a person under 18 has created an account, contact info@bilgizci.com. We may investigate, restrict access, request an age-range check or other lawful confirmation, and delete the account and associated data subject to safety and legal retention requirements. We do not sell personal data, use it for targeted advertising, or track users across apps and websites owned by other companies.

17. Changes to this Notice

We may update this Notice when our Service, providers, practices, or legal obligations change. We will update the version and date and provide additional notice before a material change where required. If a new purpose is incompatible with the original notice or requires consent, we will provide the required notice or obtain consent before that processing begins.

18. Contact

Privacy and support: info@bilgizci.com. Formal legal and KVKK notices: bilgizciyazilim@hs01.kep.tr. Data controller: Bilgizci Yazılım Tasarım Yayıncılık ve Ticaret Limited Şirketi.

oynd.

A gentle signal for people who matter.

LegalPrivacyTermsSubscriptionCommunity
Contactinfo@bilgizci.comSupport
© 2026 Bilgizci Yazılım Tasarım Yayıncılık ve Ticaret Limited ŞirketiDocument version 2026-07-30.7