Gizlilik Politikası
Son güncelleme: 2026-07-31
Bu politika; GriFlo mobil uygulamasının ve grifloapp.com adresinin kişisel verileri hangi amaçlarla işlediğini, kimlerle paylaştığını, ne kadar süreyle sakladığını ve kullanıcının haklarını açıklar.
1. Veri sorumlusu
Veri sorumlusu GriFlo'dur. Bu politikaya ilişkin talep ve sorular support@grifloapp.com adresine iletilir.
2. İşlenen kişisel veriler
- Kimlik ve iletişim: ad, e-posta adresi, profil görseli ve hesap kimliği.
- Sağlık verileri: boy, kilo, vücut ölçüleri, hedefler, öğün ve aktivite kayıtları ile kullanıcının kendi isteğiyle yüklediği vücut fotoğrafları.
- Kullanım verileri: uygulama içi ilerleme, bildirim kaydı ve özellik kullanım sayaçları.
- Tercihler: ülke, para birimi, dil ve bildirim ayarları.
- Destek yazışmaları: uygulama içinden iletilen mesajlar ve bunlara ilişkin hesap bilgileri.
- Teknik kayıtlar: hata ve çökme kayıtları.
Uygulama konum, rehber ve takvim verisi işlemez. Kamera ve galeri erişimi yalnızca kullanıcının kendi başlattığı fotoğraf işlemleri için kullanılır.
3. İşleme amaçları ve hukuki dayanak
- Hizmetin sunulması: hesap oluşturma, kayıtların saklanması, cihazlar arası eşitleme ve hesaplama. Dayanak: sözleşmenin ifası.
- Sağlık verilerinin işlenmesi: takip ve analiz özelliklerinin çalışması. Dayanak: açık rıza.
- Bildirim gönderimi: hatırlatma ve bilgilendirme. Dayanak: açık rıza.
- Destek: talebin yanıtlanması. Dayanak: sözleşmenin ifası.
- Güvenlik ve kötüye kullanımın önlenmesi: kullanım sınırlarının uygulanması ve hata kayıtları. Dayanak: meşru menfaat.
Açık rızaya dayanan işlemelerde rıza her zaman geri alınabilir. Geri alma, o tarihe kadar gerçekleştirilen işlemenin hukuka uygunluğunu etkilemez.
4. Paylaşım ve yurt dışına aktarım
Sağlık verileri varsayılan olarak gizlidir ve diğer kullanıcılara gösterilmez. Sosyal özelliklerde yalnızca kullanıcının paylaşmayı seçtiği sınırlı bilgiler görünür.
Kişisel veriler pazarlama amacıyla üçüncü taraflara satılmaz veya devredilmez. Veriler; barındırma, kimlik doğrulama, bildirim ve hata takibi amacıyla Google Firebase altyapısında işlenir. Hesaba giriş için Google ve Facebook kimlik doğrulama hizmetleri kullanılır; bu hizmetlere yalnızca girişin gerçekleşmesi için gerekli bilgiler iletilir. Ada göre besin araması yapıldığında, girdiğiniz besin terimi ABD Tarım Bakanlığı'nın (USDA) besin veritabanına iletilir. Bu hizmetler yurt dışındaki sunucularda çalıştığından işleme yurt dışına aktarım içerir.
5. Yapay zekâ ile işleme
Bazı özellikler, kullanıcının gönderdiği içeriği çözümlemek üzere Google'ın yapay zekâ hizmetine (Gemini) iletir. İletilen içerik yalnızca ilgili isteğin yanıtlanması amacıyla kullanılır ve ad, e-posta gibi kimlik bilgileriyle birlikte gönderilmez. Üretilen sonuçlar tahmini niteliktedir.
6. Saklama süreleri
Kişisel veriler hesap var olduğu sürece saklanır. Hesap silindiğinde veriler aktif sistemlerden kaldırılır; yedeklerde kalan kopyalar en geç otuz gün içinde silinir. Mevzuat uyarınca saklanması zorunlu kayıtlar bu sürelerden bağımsızdır.
7. Kullanıcının hakları
Kullanıcı; kişisel verilerinin işlenip işlenmediğini öğrenme, bunlara erişme, düzeltilmesini, silinmesini veya işlenmesinin kısıtlanmasını isteme, işlemeye itiraz etme ve verilerinin aktarılmasını talep etme haklarına sahiptir.
Hesap ve verilerin silinmesi uygulama içinden doğrudan yapılabilir; adımlar Veri Silme sayfasında açıklanmıştır. Diğer talepler yukarıdaki adrese iletilir ve en geç otuz gün içinde yanıtlanır. Kullanıcı, yetkili veri koruma makamına şikâyette bulunma hakkına da sahiptir.
8. Güvenlik
Veriler iletim sırasında ve saklandıkları yerde şifrelenir. Hesap verilerine erişim, sunucu tarafında tanımlı yetkilendirme kurallarıyla hesap sahibiyle sınırlandırılmıştır. Parolalar tarafımızca görülmez ve saklanmaz.
9. Çerezler (web sitesi)
grifloapp.com, sitenin çalışması için gerekli tercih kayıtlarını (çerez tercihi ve görünüm seçimi) yalnızca tarayıcıda saklar. Kullanıcı izin verdiğinde, IP adresi anonimleştirilerek anonim kullanım ölçümü yapılır. Pazarlama çerezi kullanılmaz. Tercih, sitedeki "Çerez Tercihleri" bağlantısından her zaman değiştirilebilir.
10. Çocukların gizliliği
Uygulama 13 yaşın altındaki kişilere yönelik değildir ve bu yaş grubundan bilerek veri toplanmaz. Böyle bir kaydın bulunduğu tespit edilirse hesap ve ilgili veriler silinir.
11. Değişiklikler
Bu politika güncellenebilir. Güncel sürüm bu sayfada yayımlanır ve yukarıdaki tarih buna göre değiştirilir.
12. İletişim
Talep ve sorular için support@grifloapp.com.
This policy explains the purposes for which the GriFlo mobile application and grifloapp.com process personal data, with whom such data is shared, how long it is retained, and the rights of the user.
1. Data controller
The data controller is GriFlo. Requests and questions regarding this policy are to be sent to support@grifloapp.com.
2. Personal data processed
- Identity and contact: name, email address, profile image and account identifier.
- Health data: height, weight, body measurements, goals, meal and activity records, and body photographs uploaded at the user's own initiative.
- Usage data: in-app progress, notification registration and feature usage counters.
- Preferences: country, currency, language and notification settings.
- Support correspondence: messages submitted from within the application and the related account information.
- Technical records: error and crash logs.
The application does not process location, contacts or calendar data. Camera and gallery access is used solely for photo operations initiated by the user.
3. Purposes and legal bases
- Provision of the service: account creation, storage of records, synchronisation across devices and calculation. Basis: performance of a contract.
- Processing of health data: operation of tracking and analysis features. Basis: explicit consent.
- Notifications: reminders and information. Basis: explicit consent.
- Support: responding to requests. Basis: performance of a contract.
- Security and prevention of misuse: enforcement of usage limits and error logging. Basis: legitimate interest.
Where processing is based on explicit consent, that consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
4. Sharing and international transfer
Health data is private by default and is not displayed to other users. In social features, only the limited information the user chooses to share is visible.
Personal data is not sold or transferred to third parties for marketing purposes. Data is processed on Google Firebase infrastructure for hosting, authentication, notification and error monitoring. Google and Facebook authentication services are used for account sign-in; only the information required to complete sign-in is shared with them. When a food is searched by name, the food term you enter is sent to the food database of the United States Department of Agriculture (USDA). As these services operate on servers located abroad, the processing involves an international transfer.
5. Processing by artificial intelligence
Certain features transmit content submitted by the user to Google's artificial intelligence service (Gemini) for analysis. Transmitted content is used solely to respond to the relevant request and is not sent together with identity information such as name or email. Results produced are estimates.
6. Retention periods
Personal data is retained for as long as the account exists. Upon deletion of the account, data is removed from active systems; copies remaining in backups are deleted within thirty days at the latest. Records whose retention is mandatory under applicable law are not subject to these periods.
7. Rights of the user
The user has the right to learn whether personal data is processed, to access such data, to request its rectification, erasure or restriction of processing, to object to processing, and to request the portability of the data.
Deletion of the account and data can be carried out directly from within the application; the steps are set out on the Data Deletion page. Other requests are to be sent to the address above and are answered within thirty days at the latest. The user also has the right to lodge a complaint with the competent data protection authority.
8. Security
Data is encrypted in transit and at rest. Access to account data is restricted to the account holder by authorisation rules defined on the server. Passwords are not visible to us and are not stored by us.
9. Cookies (website)
grifloapp.com stores only the preference records necessary for the operation of the site (cookie preference and appearance selection) in the browser. Where the user consents, anonymous usage measurement is carried out with the IP address anonymised. Marketing cookies are not used. The preference can be changed at any time via the "Çerez Tercihleri" (Cookie Preferences) link on the site.
10. Children's privacy
The application is not directed at persons under the age of 13, and data is not knowingly collected from that age group. If such a record is identified, the account and the related data are deleted.
11. Changes
This policy may be updated. The current version is published on this page and the date above is amended accordingly.
12. Contact
For requests and questions: support@grifloapp.com.