YADA Logo YADA

Privacy Policy

Legal privacy framework and data protection terms for YADA Mobile Application.

1. Introduction and Identity of the Data Controller

This Privacy Policy determines the procedures and principles regarding personal data processed during the execution of the YADA mobile application ("Application") and its associated services. YADA, in its capacity as data controller, accepts ensuring the security of its users' personal data and protecting their privacy rights as its highest mission.

2. Legal Legislation and International Compliance

All data processing activities carried out within YADA are performed in full compliance with the Republic of Turkey Law No. 6698 on the Protection of Personal Data ("KVKK"), the European Union General Data Protection Regulation ("GDPR"), and Apple App Store Review Guidelines (specifically Article 5.1.1 - Privacy and Data Collection) legislation.

3. Explicit Consent and Acceptance of Service

Your registration on the application, creation of a user profile, or initiation of the use of map-based interaction services implies that you freely accept and approve all technical and administrative data processing methods, storage conditions, and legal transfer mechanisms regulated under this Privacy Policy and the linked User Agreement.

4. Processing of Identity and Account Data

Data collected directly via user declaration for the purpose of registering on the platform and ensuring account security—such as username, email address, password hashes (salted hashes), date of birth, and user profile description (biography)—is processed based on the legal ground of establishing and executing the membership agreement.

5. Third-Party Login Integrations (OAuth)

In case you register to the platform through 'Sign in with Apple' or other external authentication services, unique user identification tokens, profile verification status, and system-provided email addresses transferred to YADA by the respective external platform are processed for account matching purposes.

6. Processing of Sensitive and Approximate Location Data

YADA is a platform whose core architecture is built upon map-based social discovery. Your geographical coordinate data obtained through your device's GPS, base station signals, and Wi-Fi network location is processed for the purposes of letting you discover nearby users on the map, matching with people within a specified radius, and viewing posts in the immediate vicinity.

7. Foreground and Background Distinction in Location Data

As a rule, your location data is processed only when the application is in the foreground (open and active) on your device. When the application is completely closed or sent to the background, your instant location tracking is strictly not performed in the background unless you explicitly activate the 'Always Allow' option through your device operating system's permission mechanisms.

8. Coordinate Masking and Security on the Map

To protect the physical safety of users, your precise GPS coordinates are never reflected to other users as raw data. Your location on the map is displayed to other users with a random margin of error (using an approximate area logic) through special geographic masking and approximate positioning algorithms.

9. User-Generated Content (UGC)

Instant stories, posts, uploaded profile pictures, left emojis, and all other media content shared by users on the map are processed, indexed on servers, and made available to other users within the designated interaction area to fulfill the social interaction function of the platform.

10. Real-Time Messaging and Chat Security

Chat content, text messages, and instantly sent photos carried out between users are directly transferred to the recipient using a real-time transmission infrastructure. Your messaging content is strictly not scanned, analyzed, or shared with third parties for ad targeting, user profiling, or commercial data mining purposes.

11. Complaint and Moderation Data Processing Workflows

When the integrated 'Report' mechanism—designed to prevent platform abuse, harassment, copyright infringements, and illegal activities—is triggered; the messaging history, story, or profile content subject to the complaint can only be reviewed by authorized moderators to determine whether community guidelines have been violated.

12. Device, Hardware, and Technical Log Data

To maintain the technical stability of the application; IP address, device brand, model, operating system version, unique device identifiers (IDFV/IDFA), language preferences, network provider information, and in-app navigation (clickstream) logs are collected automatically and processed for system optimization.

13. Third-Party SDK, API, and Infrastructure Providers

YADA uses SDK and API components of global infrastructure providers (e.g., Firebase, Google Cloud Platform) during database management, server hosting, and crash reporting processes. These providers possess the status of 'Data Processor' and cannot use the data for their own independent commercial or advertising activities.

14. Cookies and Local Storage Technologies

In-device local storage (Local Storage, Keychain) and mobile token technologies are utilized to maintain the security of user sessions, remember in-app preferences, and verify API requests. This data is strictly not used to track you across third-party websites or to display advertisements.

15. Uninterrupted Account Deletion Right (Apple Guideline 5.1.1(v) Compliance)

In accordance with Apple App Store rules and legal regulations, your right to delete your account and all associated digital footprints at any time is secured. Users can instantly delete their accounts without facing any artificial obstacles or approvals by following the steps: In-App Settings > Account Management > Permanently Delete Account.

16. Synchronized Data Destruction and Purging Process

The moment the account deletion process is confirmed; your profile information, profile pictures, all active and past stories on the map, and created chat rooms are completely and irreversibly deleted from active databases. For accounts using Sign in with Apple, a revocation call is automatically sent to Apple servers for access tokens.

17. Legal Retention Periods and Exceptions

To prevent cybercrimes, handle legal requests from official judicial authorities, and comply with obligations under Law No. 5651, technical traffic logs demonstrating your access to the system (IP address, login-logout timestamps) are kept in an encrypted archive isolated from the main systems for the legally mandatory period (maximum 1-2 years). At the end of this period, this data is completely destroyed or anonymized.

18. Data Subject Rights and Communication Channels

Pursuant to KVKK Article 11 and GDPR Chapter 3, you have the right to learn whether your personal data is being processed, and to request correction or deletion of your data. For any legal applications regarding the privacy policy, data processing workflows, or account destruction requests, you can contact us directly 24/7 via the 'Support' center inside the application or through our official email address.