GetDone Türkçe

GetDone Privacy Policy

Effective date: 28 September 2026 · Version: 1.6

This is the privacy policy for the GetDone mobile app (Android) and its web version. It also serves as the information notice required by Article 10 of Turkey's Personal Data Protection Law No. 6698 (KVKK). The Turkish text at veyronistudios.com/getdone/gizlilik is authoritative; this English text is a translation.

1. Data controller

The controller of your personal data is Berkay Atalay, trading as "Veyroni Studios". No company has been formed yet; the app is published on Google Play under a personal developer account.

2. What data we process

Most data is entered by you while using the app; some is generated automatically or results from actions of people in your connection or group (approvals, points, votes). Collection is fully automated, through the app and our servers. When you write to us by e-mail, your data is processed partly by automated means, in our mailbox.

Account. Your e-mail address and password. The password is stored only as a hash; we cannot see it. To confirm your address when you create an account, and to reset your password, we e-mail you a one-time 6-digit code. Sign-in with Apple or Google does not exist yet.

Acceptance of the Terms of Use. Which version of the Terms of Use you accepted and when (date and time).

Profile. Username, display name, the app language you chose and your device's time zone.

Connections and groups. Which connection or group you belong to, in which role (task giver / task doer) and for which period; invitation codes you create (stored only as a hash) and acceptance records.

Messages. Messages you write in connection and group chats, plus system lines such as task starts and departures. The departure line contains your display name at the moment you left.

Tasks and reports. Task title, description, schedule and targets; your progress reports and notes; approval or rejection decisions and their notes; outcome texts for missed work; your requests to leave a task and their reasons.

Points and rewards. Point movements and balances; reward definitions and their change history; reward claims, votes on them and notes.

Notifications. Event records in the in-app inbox (type, related connection or group, related task, the person whose action triggered it, limited status values, creation, read and closing times). No names, titles or text are stored. For notifications sent to your phone, see "Phone notifications" below.

Phone notifications (push). If you turn notifications on in the Android app, the record of your phone: the address the notification service gives your phone (push token), a random identifier the app creates for this installation, the platform (Android), the number of the session that registered it, when the record was created, last refreshed and closed, and why it was closed (sign-out, permission turned off, phone registered by another account, token no longer valid). The notification types you turned off on the notification settings screen. For each notification, whether it was sent to your phone, why it was skipped if it was, and the number of attempts. A notification sent to your phone carries only the name of the person who acted (or the nickname you gave them), a general sentence in your app language, the number of unread notifications, and the notification, chat or group and task numbers needed to open the right screen; it carries no task, note or reward text. The web version has no phone notifications.

Nicknames. A private nickname you give to a contact; only you see it.

Blocks and user reports. When you block someone, we record who you blocked, when, and the display name they had at that moment, so your list of blocked people can show it. When you report someone, we record who reported whom, in which connection or group, the reason you chose, your optional note (up to 500 characters) and the time; if you report a specific message, we also record which message it was and keep a copy of its text as it was when you reported it. While a report is reviewed we record the admin who took it on and when it was taken on and handed up to a senior admin; when it is closed we record the decision (no action, content removed from view, a warning, a temporary suspension, a permanent closure, or an account restriction), the reason for it, when it was made and by whom. If content is removed from view because of a report, we keep its original text and the text of the copies the app shows with the report.

Warnings, suspensions and permanent closures. If your account is given a warning, we record its category (for example harassment or spam), the related report if there is one, the admin who gave it, the date, and when you acknowledged it in the app. If your account is suspended or closed permanently, we record the category, when the suspension ends, the related report if there is one, the admin who did it, and the date. The reason the admin wrote is not shown to you; it stays in the admin action log. Every view and action an admin makes about your account in the admin panel is written to that log with your account number (section 4).

Permanently closed accounts. If we close an account permanently for breaking the Terms of Use, we keep, to stop a new account being opened with the same e-mail address, not the address itself but only a hash of it computed with a secret key (HMAC-SHA256), together with the account number and the date. The address cannot be read from the hash; the hash is compared only when someone tries to sign up again with the same address or to change an account's address to it, and when an authorised member of our team checks an address someone gives us, for example in an appeal, to find the closed account it belonged to. Upper and lower case and spaces before or after the address are ignored in the comparison. No such record is kept for a temporary suspension.

Photo and video evidence. This feature is currently switched off. Once enabled, the photo or video you attach to a progress report (including the sound track of a video) is processed together with its size, type, resolution, duration, a fingerprint (SHA-256) of the original file and any processing error code. Source metadata such as location is stripped on the server; the original file is deleted from the server once processing ends.

Technical records. The authentication component (Supabase Auth) writes, for session security, your IP address and device/browser information to the session record each time you sign in, and writes your sign-up, e-mail confirmation, sign-in, sign-out and password events together with your e-mail address and IP address to an authentication event log. These records live in the database of our Supabase project; they are not shown in the app and only the database operator can access them. The session record is deleted when you sign out or the session expires; the authentication event log is kept until your account is deleted (see section 7). Supabase's server access logs also keep your IP address for the provider's log retention period; we read them only for troubleshooting and security review. The same rule applies to the access logs of the media processing server and the web version once they are live. The app contains no advertising, analytics, crash reporting, location or contacts access.

Please do not write special categories of personal data (health, religion, political opinion and the like) into chats, notes or evidence; the app is not designed for them.

3. Purposes and legal bases

PurposeLegal basis (KVKK Art. 5/2)
Creating an account, signing in, resetting the password, keeping the session(c) processing necessary for the parties to a contract, directly related to its formation or performance
Recording your acceptance of the Terms of Use(c) same basis; (e) necessary to establish, exercise or protect a right
Chat, tasks, progress reports, approvals, points, rewards, notifications, language and time zone(c) same basis
Preventing abuse, restricting accounts, technical maintenance and security review, admin panel security and audit trail(f) processing necessary for our legitimate interests, provided it does not harm your fundamental rights and freedoms
Blocking and reporting; reviewing reports by authorised staff in the admin panel or by the database operator, opening reported content only through the report and acting on it (removing content from view and putting it back, warnings, temporary suspensions, permanent closures, and lifting them); writing these actions to the admin action log(f) our legitimate interest in keeping users safe, enforcing the Terms of Use and preventing abuse, provided it does not harm your fundamental rights and freedoms
Preventing a new account with the e-mail address of a permanently closed account, and finding that account when someone writes to us about the closure(f) our legitimate interest in keeping users safe and preventing abuse, provided it does not harm your fundamental rights and freedoms
Answering lawful requests (including opening reported content in the admin panel on the ground of a request from an authority) and meeting legal obligations(ç) necessary to meet a legal obligation; (e) necessary to establish, exercise or protect a right
Sending notifications to your phone and applying your notification settings(c) processing necessary for the parties to a contract, directly related to its formation or performance

No processing relies on your explicit consent. Your data is used only for these purposes, never for marketing, profiling or advertising.

4. Who sees what inside the app

5. Processors and transfers abroad

We do not sell your data or share it for marketing. These service providers process your data on our behalf and under our instructions:

ProviderWhat it doesWhere
Supabase Inc.Database, authentication, realtime delivery, file storage (sub-processor: Amazon Web Services)AWS eu-west-1, Ireland
Resend Inc.Sign-up confirmation and password reset e-mailsIreland (eu-west-1)
650 Industries, Inc. (Expo)Passes phone notifications (push) to Google's notification service: the push token, the notification's title and general sentence, the unread count, and the notification, chat or group and task numbersUSA
Google (Firebase Cloud Messaging)Delivers the notification to your phone on AndroidGoogle's global infrastructure
Railway CorporationThe admin panel's server: serves the panel pages to authorised staff and passes staff sign-ins to Supabase. Staff sign-in details, IP address and browser information, and the account and report numbers in the panel's page addresses pass through this server; the IP address, browser information and page addresses stay in the provider's access logs for its retention period. Report details and content do not pass through this server; they go from the staff member's browser straight to Supabase. Once photo and video evidence is enabled, the media processing server will run here tooServers in the Netherlands (Amsterdam, EU West region); company in the USA

The contracted developer who builds and technically operates the app may access the database as a processor, only on our instructions and for maintenance and troubleshooting; the "database operator" in sections 2 and 4 is whoever holds that role. A written confidentiality and data-processing agreement covers this access.

Google Play only distributes the app; the app sends no user data to Google Play (how phone notifications pass through Google's notification service is in the next paragraph). When you install or update the app from Google Play, the data Google itself collects (your Google account, device information) is processed by Google as an independent controller under its own privacy policy; it is not passed to us.

Phone notifications. When you turn notifications on, your phone's push token is obtained from Google's notification service (Firebase Cloud Messaging) and registered with our server. When a notification is due for your phone, our server sends the token and the short content described in section 2 to Expo's notification service; Expo passes it to Google, and Google delivers it to your phone. Expo and Google process this data to deliver it and keep it for their own retention periods.

Once photo and video evidence is enabled, files pass through a processing server we will operate on Railway (in the Netherlands) into Supabase's private storage; a file stays on that server only while it is processed.

Because Supabase's and Resend's servers are in Ireland, Railway's servers are in the Netherlands and Railway Corporation is based in the USA, this is a transfer abroad under KVKK Article 9. The safeguard relied on under Article 9/4 for transfers to these providers is the standard contract published by the Turkish Personal Data Protection Board. Phone notifications sent through Expo (USA) and Google (global infrastructure) are a transfer abroad too. Where the law requires it, your data may also be disclosed to competent public authorities.

6. Data on your device and permissions

7. Retention and deletion

8. Security

Data travels between device and server encrypted with TLS. Row-level security rules in the database show each record only to the members entitled to it. Evidence files are kept in a private bucket and opened only through signed links valid for 60 seconds. Passwords and invitation codes are stored only as hashes. A permanent ban keeps only a hash of the e-mail address, not the address itself; the key for that hash sits in the database's encrypted secret store (Vault) and is used only by the server's matching and lookup functions. Push tokens are kept in tables the app cannot read and only the server can reach. The admin panel requires two-step verification (TOTP), and every admin action is written to a chained, tamper-evident audit log that is never deleted. In the panel the permission for every action is checked in the database against the admin's role; reported content opens only through the report record, with an access reason and a justification. The panel's server holds no secret key with full access to the database. If we learn of a data breach, we inform you and the Personal Data Protection Board as soon as possible, as KVKK Article 12 requires.

9. Your rights (KVKK Art. 11)

By applying to us you may:

How to apply. Write to veyronistudios@gmail.com from the e-mail address registered in your account; send an application signed with a secure electronic signature or mobile signature to the same e-mail address; or deliver a hand-signed written application to the address in section 1, in person or through a notary. Include your name and surname (and your signature if the application is in writing), your Turkish ID number (for foreigners: nationality, passport number or ID number if any), your residence or business address for notifications, an e-mail address and telephone number for notifications if you have them, and the subject of your request. Applications are concluded free of charge within 30 days at the latest; where the operation involves a separate cost, the fee in the Board's tariff may be charged. Formal applications are made in Turkish; we also answer questions in other languages. If your application is rejected, the answer is insufficient or no answer is given within 30 days, you may complain to the Personal Data Protection Board within 30 days of learning the answer and in any case within 60 days of applying. You must apply to us first before complaining to the Board.

10. Children

GetDone may be used by people aged 16 or older; it is not directed to anyone under 16. If you are under 18, use GetDone with the knowledge of a parent or guardian (Terms of Use section 3). If we learn that a person under 16 has created an account, we close it, delete it as described in section 7 and remove the messages it sent from the other members' view. You can report such a case to veyronistudios@gmail.com.

11. Changes

When we change this policy, we publish the new Turkish version at veyronistudios.com/getdone/gizlilik and this translation at veyronistudios.com/getdone/privacy, and update the version number and effective date on both. Every version is also published at its own address, which carries the version number (for example veyronistudios.com/getdone/privacy/1.6). We announce significant changes inside the app. Before processing your data for a new purpose, we inform you separately.

12. About this document