In short: The core calculators work without an account. If you create an account we process your email address; if you use the profile, social feed, notification and Premium features we process the data those services need. Calculation summaries are sent to our server on a pseudonymous basis — not tied to your identity or account — to improve the product. We never sell your data.
1. Data controller and scope
Under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"), the data controller is Burak Altıntaş (Antalya, Türkiye), reachable at burak.altintas@yahoo.com.tr and info@bankaci.app.
This policy covers:
- the Bankacı mobile application (iOS and Android), and
- bankaci.app and other Bankacı web properties serving the same content.
Bankacı is an independent professional helper tool; it is not a bank or a financial institution, it does not extend loans and it does not guarantee financial advice.
Request link: a Premium banker may collect membership-free loan requests from their customers through a link they share. For the personal data of the customer who fills in that form, the banker who establishes and uses the customer relationship is the independent data controller; Bankacı acts as a service provider/intermediary only for technically serving the form and delivering the request to the correct banker. The request form links to this Privacy Policy, so the customer who submits it is deemed informed by this text. Any further features such as future campaigns will be reflected in this policy and in in-app notices in advance.
2. Data we process, purposes and legal bases
| Data | Purpose | Legal basis |
|---|---|---|
| Membership and security: email address, one-time-code records, IP address of a code request, a one-way digest of the session, device name, session and last-seen times | Account creation, email-code authentication, session security, prevention of abuse and fraud | Establishment/performance of a contract and legitimate interests (KVKK Art. 5/2-c, 5/2-f) |
| Profile and social feed: display name; optional bio, bank/job title and profile photo; post, photo, like, comment, report and block records | Providing the profile and the social feed among bankers, moderation, security and handling complaints | Performance of a contract, your own sharing and legitimate interests (KVKK Art. 5/2-c, 5/2-d, 5/2-f) |
| Premium: RevenueCat pseudonymous user id, verified account email, entitlement, product, purchase/renewal/cancellation events, platform and app version | Verifying the Premium entitlement, carrying it across devices, restoring purchases, disabling ads and locating the account during support | Establishment/performance of a contract and legal obligation (KVKK Art. 5/2-c, 5/2-ç) |
| Premium advantage redemptions: the code record of the advantage you used (which advantage, your account id and when the code was revealed) | Offering premium-only partner perks, disclosing a discount code solely to a signed-in Premium member, and reporting how many and which members used each perk | Performance of a contract and legitimate interests (KVKK Art. 5/2-c, 5/2-f) |
| Notifications: Expo push token, platform, device name, notification ticket/receipt and delivery status | Sending the notifications you allow and troubleshooting delivery | Performance of a contract and legitimate interests (KVKK Art. 5/2-c, 5/2-f); the operating-system permission is obtained separately |
| Calculation usage data: HMAC digest of a random install id, event id, calculation type, loan/plan type, amount, term, rate, tax rates, result summary, platform and app version | Improving the calculators, measuring usage trends in a pseudonymous and aggregate way, detecting errors and abuse | Legitimate interests, provided fundamental rights are not harmed (KVKK Art. 5/2-f) |
| Loan requests (request link): the full name, phone, optional email, request/loan details, customer note and any documents submitted by the customer who fills the form at a link shared by a banker; the recipient banker, creation time and status records | Delivering the request to the banker who shared the link and letting it be tracked in the app; preventing abuse and fraud. The banker uses this data as an independent controller for their own customer relationship | Performance of the request (the customer's own application) and legitimate interests (KVKK Art. 5/2-c, 5/2-f) |
| Advertising: advertising id/IDFA (where permitted), IP, approximate location, device/app info and ad interactions | Serving ads only in non-Premium use, measurement and fraud prevention | Explicit consent for personalisation/cross-app tracking; other applicable legal bases for processing outside non-essential tracking |
| Communication: the email, request content and reply records you send us | Support, KVKK applications and managing disputes | Performance of the request, legal obligation and establishment/exercise/defence of a right (KVKK Art. 5/2-c, 5/2-ç, 5/2-e) |
The OTP code itself is not stored in plaintext; a salt and an HMAC digest are kept. Only a one-way digest of the session token is stored. Calculation events carry no name, email, phone, profile or RevenueCat id and are not linked to your membership account. Still, because pseudonymous data could in theory be matched with additional information, it is not treated as fully anonymous data.
3. Data that stays on your device
A local copy of your calculation inputs and history inside the app, your preferences and the PDFs generated on the device are kept on your device. You decide with whom to share the customer details you add to a PDF; Bankacı does not upload them to a server for PDF generation. Deleting the app removes the local data on the device; on its own it does not delete your membership account or the data on the server.
The home-screen widget is fed by a summary kept on your device alone; it sends nothing to a server. A home screen is a surface other people can see, so what crosses into it is the names of the shortcuts you chose and your last calculation's amount, term and kind of loan. The monthly instalment, a customer's name, a phone number and the rate never cross, and you can hide the amount too.
We do not ask for bank/card details, national ID number, precise location, contacts, microphone or message content. Photo access is used only to upload the profile/feed image you choose.
4. How we collect data
Data is obtained electronically through the mobile app and web forms, your own upload/share actions, device and operating-system APIs, Apple/Google store records, RevenueCat webhooks, the Expo notification infrastructure and automatic technical logs kept for service security. This notice is separate from the processes that require explicit consent; reading the policy does not mean you have given explicit consent for every processing activity.
5. Service providers and recipient groups
The following service providers process data solely for the purposes above:
- Google LLC and group companies — Google Cloud Run, PostgreSQL/GCS infrastructure, Google Play, Firebase/FCM and Google AdMob for distribution, hosting, media, notifications, payment and advertising. How Google uses data · Privacy policy
- OpenAI, L.L.C. (USA) — only when the AI Assistant is used, to turn the financing scenario entered into a recommendation. What is sent is limited to the product's own scenario schema; a name, national ID number, phone, account or card details are neither asked for nor sent, and the note field on screen says not to type them. Conversation history, payment schedule rows and customer records are not sent. Privacy policy
- RevenueCat, Inc. (USA) — verifying and managing subscription status; matching the verified account email with the subscription record during support. Privacy policy
- Apple Inc. and group companies — App Store distribution, payment, subscription and APNs notification infrastructure. Privacy policy
- Expo / 650 Industries, Inc. — push token, notification delivery and delivery result.
- Email service provider — delivery of OTP and new-account welcome emails.
- Competent public authorities and legal advisers — only in case of a legal obligation, establishment of a right or a lawful request.
We do not sell or rent your data. Only the data categories required for the relevant service are transferred to service providers.
6. Payments, Premium and ads
Subscription payments are handled entirely through the Apple App Store or Google Play. We do not see, process or store your card details. RevenueCat processes the store receipt, entitlement status, pseudonymous user id and the verified account email so the account can be found during support. The email is not used as the primary entitlement id in RevenueCat or for ad tracking. Cancellation and refunds are subject to the rules of the relevant store. Deleting your account does not automatically cancel the store subscription; you must also cancel it from your App Store or Google Play subscription settings.
No ads are shown to Premium users and no ad-removal control is offered to them. In non-Premium use AdMob may process data. iOS cross-app tracking and legally required ad-personalisation choices are managed through separate permission mechanisms.
7. International transfers
The infrastructure of Google, Apple, RevenueCat, Expo, OpenAI and the email provider may operate outside Türkiye or globally. The relevant data categories may therefore be transferred abroad.
Transfers rely on whichever of the mechanisms in KVKK Art. 9 is applicable — an adequacy decision, an appropriate safeguard (such as a standard contract announced by the Board) or one of the incidental situations in the law. Where a transfer requires explicit consent, that consent is requested separately from this notice. For users in the European Economic Area, Chapter V mechanisms of the GDPR are used to the extent applicable.
8. Retention periods
- OTP: the code is valid for 10 minutes and single-use; security/rate-limit records are kept until the appropriate technical clean-up.
- Session: expires after 90 days or is revoked on logout; security records may be kept with limited access until periodic clean-up.
- Account/profile/feed: until the account or the relevant content is deleted; report/moderation and legal-dispute records may be kept with limited access for the required period.
- AI Assistant: the scenario and the recommendation it produced are kept against your account so you can reopen them from the history, and are deleted after 180 days at the latest; deleting your account deletes them at the same time. The daily usage counter belongs to that day only.
- Loan requests: the name, phone, optional email, customer note and documents submitted in the form are tracked by the banker who owns the request link; not kept longer than needed for the service, security and legal obligations. Communication data is not included in anonymous product analytics.
- Premium advantage redemptions: kept while the advantage is live and your account remains open; after the advantage is removed or your account is deleted, only aggregated/limited records needed for reporting may be retained.
- Calculation analytics: raw pseudonymous events for at most 180 days; external reports are produced only from aggregated groups meeting a threshold of at least 20 distinct installs.
- Push token: until logout, disabling the device registration, the provider reporting it invalid, or account deletion.
- Purchase and ad records: for the retention periods of Apple, Google, RevenueCat and the ad provider and for the duration of legal obligations.
- Support/KVKK applications: for the period needed to resolve the request and for any dispute limitation period.
- Backups: daily backups of the database are kept encrypted with restricted access and deleted after 30 days at the latest; when you delete your account or any data, it leaves the backups within that period too.
9. Data security
HTTPS/TLS, one-way token digests, OTP HMAC, access controls, Google Cloud IAM, file type/size validation, rate limiting and structured security logs are used. No system can guarantee absolute security.
10. Social feed, notifications and visibility
Reading the feed may be public. The display name, photo, bio, profession/bank information and content you share on your profile and in the feed may be seen by other users. Do not upload special categories of personal data, customer secrets, banking secrets, third-party financial/contact information or content you are not authorised to share.
Notification permission is requested by the operating system and can be turned off in device settings. Comment text, email or the name of the commenter is not placed in the notification payload.
11. Cookies on the website
Alongside its promotional and legal-information pages, bankaci.app may offer a membership-free loan-request form via a link shared by a banker. The form links to this Privacy Policy, form data is sent to the relevant banker with explicit approval, and no payment is taken through the web. If advertising/analytics cookies beyond mandatory technical logs start being used, this section and, where needed, a cookie-preference mechanism will be updated in advance.
12. Children's privacy
Bankacı is aimed at professionals and is not directed at persons under 18. If we notice that a child's data has been processed without authorisation, we apply deletion and the necessary protective steps after verification.
13. Account deletion and KVKK rights
Under KVKK Art. 11 you have the right to learn whether your data is processed, to request information, to learn whether it is used for its purpose, to know the third parties to whom it is transferred, to request correction of incomplete/incorrect data, to request erasure/destruction where the conditions are met and notification of these to recipients, to object where an automated analysis produces a result against you, and to claim compensation for damage arising from unlawful processing.
You can delete your account directly from the "Delete account" option at the bottom of the Profile page in the mobile app, after a two-step confirmation. You can send other requests to the email address below with the subject "Bankacı KVKK Application". For security we may need to verify that the account belongs to you. Requests are concluded as soon as possible and within 30 days at the latest; where a cost arises, the conditions in the Board's tariff are reserved.
Account deletion starts the process of deleting active sessions, the profile and related data or anonymising/restricting records that must be kept by law. Public feed content is also deleted unless it must be kept by law. Deleting the app does not delete the account; deleting the account does not cancel your Apple or Google subscription. Applications: info@bankaci.app.
If your application is refused, the reply is inadequate or no reply is given in time, you may complain to the Personal Data Protection Board within 30 days of learning of the reply and in any case within 60 days of the application. Applicable GDPR rights of EEA users and the right to apply to the local supervisory authority are separately reserved.
14. Changes to this policy
This policy may be updated from time to time. Every update changes the effective date and version number on this page. Where a change materially affects your rights, we notify you inside the app before it takes effect and, where required, ask for your consent again.
15. Contact
Data controller: Burak Altıntaş — Antalya, Türkiye
Email:
burak.altintas@yahoo.com.tr
·
info@bankaci.app
Web:
burak-altintas.com