Privacy Policy
Last updated:
This policy explains which personal data is processed when the DuyApp mobile application and the duyapp.com website are used, the purposes for which this data is used, with whom it is shared and how long it is kept. The data controller is DUYAPP YAZILIM LİMİTED ŞİRKETİ.
The legal grounds for processing personal data under Law No. 6698 on the Protection of Personal Data (KVKK) and information on how to exercise your rights are available on the KVKK Disclosure Notice page.
Key points
- Personal data is not sold.
- The DuyApp application does not currently use advertising, advertising-related tracking or third-party analytics tools.
- Email addresses are not shown to other users.
- The author of an anonymous post is not shown to other users. However, anonymous posts are kept in our systems in association with the account and may be shared with competent authorities in line with legal obligations.
- With every post and comment, the name of the neighbourhood, district, city, university or campus where it was shared is shown to other users. This also applies to anonymous posts.
- The content of private messages is end-to-end encrypted and cannot be read by DuyApp.
Account creation
You can register for DuyApp only with a university email address ending in .edu.tr. During registration, a 6-digit verification code is sent to the email address. The code is valid for 10 minutes and only its hashed form is kept in our systems.
Once the email address is verified, a passkey is created for signing in to the account. DuyApp does not use passwords. The passkey is protected by the device's own security system (Face ID, fingerprint or device lock). Biometric data stays on the device and is not transmitted to DuyApp. The email address appears as the name of the passkey in the device's password manager and, if the passkey is synced, it is also stored in iCloud Keychain or Google Password Manager.
No first name, last name, phone number, date of birth or gender is requested during registration.
Data processed
Account information
- University email address.
- Username, and the optional nickname, biography and profile photo.
- The date the account was created and the date the community guidelines were accepted.
- Account settings and notification preferences.
- The preferred campus saved when a campus is selected on the map. This information is used to show campus-specific content and notifications.
Session and security information
- The IP address recorded when a session is opened.
- Device and browser information (user agent) and the device name.
- The start, last use and end times of sessions.
- Technical information such as the public key of the passkey, the device type and the time of last use.
- Records of account recovery operations and the device information used in those operations.
Shared content
- Posts, comments and polls.
- Photos and GIFs added to posts and comments.
- Votes cast, poll answers and saved posts.
- The area where the content was shared (neighbourhood, district, city, university or campus).
Uploaded photos are reprocessed on our servers, and during this process additional data such as the location and device information within the photo (EXIF) is removed. The original of the photo is deleted after it has been processed.
Notification information
To send push notifications, the device's notification token (push token), device platform, language, time zone, application version and a random installation ID that the application generates for each installation are processed.
Duy Points and invitations
- Duy Points are calculated from votes given to content and are kept both overall and by area (neighbourhood, university or campus). The vote records that make up the points are stored in association with the accounts that cast and received the votes. Votes given to anonymous content are also included in the points. Duy Points can be seen only by the account holder.
- Every account has an invitation code. When an invitation code is used, the link between the inviting account and the invited account is recorded. The inviting user sees only the number of people they have invited, not their identities.
Report and block records
When content is reported, the reporting account, the reported content and account, the reason for the report and any explanation attached to the report are recorded. When anonymous content is reported, the account that the content belongs to is also added to the report record. Records relating to blocked accounts are also kept.
Device permissions
- Location: Used only while the application is in use and if permission has been granted. Location is not collected in the background.
- Camera: Used only when taking a photo for a post.
- Photos: Only photos selected to be added to a post, comment or profile are used.
- Notifications: Used to send push notifications.
Contacts, the microphone and the device's motion sensors are not used. Permissions can be withdrawn at any time in the device settings.
Data not processed
The DuyApp application does not collect first name, last name, phone number, date of birth, gender, contacts or biometric data. The application does not currently use an advertising ID and does not perform cross-app tracking.
Location
DuyApp is a hyperlocal application. Content is shown according to the area in which it was shared. Location information is therefore necessary for the core operation of the application.
How location is collected
- Location is collected only while the application is open: when a post or comment is shared, when the current area is shown and when the map is used. Continuous or background location tracking is not performed.
- The collected location is converted into an area (neighbourhood, district, city, university or campus) using map data held on our servers. The location is not sent to a third-party service for this process.
- To show the name of the current place on the post creation screen, the location service of the device's operating system, provided by Apple or Google, is also used.
How location is stored
- Exact coordinates are not stored in posts and comments. Only the area in which the content was shared is recorded.
- For posts shared with the "Show on map" option turned on, the exact location is held in temporary memory for no more than 15 minutes. A rounded map point, described below, is created from this location and the exact location is deleted.
- The most recently used area information is stored on the device for no more than 7 days so that the application can open quickly.
What other users see
- With every post and comment, the name of the neighbourhood, district, city, university or campus where it was shared is shown. This information is also shown for anonymous posts.
- Posts made under a nickname are listed on the profile page.
- If the "Show on map" option is turned on, the post is shown on the map at a rounded point. The point is rounded to an area of approximately 100 metres for posts made under a nickname and approximately 400 metres for anonymous posts. The map point is kept until the post is deleted. This option is turned off by default.
- The exact location is never shown to other users.
Location access can be turned off in the application settings or the device settings. When location access is turned off, the area-based features of the application do not work.
Anonymity
On DuyApp, content can be shared under a nickname or anonymously.
- For content shared under a nickname, the username, nickname and profile photo are visible to other users.
- For content shared anonymously, the author's account is not shown to other users. Anonymous posts are shown with a random number, and anonymous comments are shown with a label specific to that post only. Anonymous identities in different posts are not matched with each other.
- Anonymous content is kept in our systems in association with the account. This link is necessary to prevent abuse, to review reports and to fulfil legal obligations.
Information contained in the content itself (such as a name, place, event or photo), together with the area name and the time of sharing shown with the content, may lead others to guess the identity of the author, particularly in small areas.
Private messages
Encryption
- The content of private messages is end-to-end encrypted. Messages can be read only on the sending and receiving devices. DuyApp servers cannot open message content.
- So that a message can be delivered, our servers process which accounts a conversation is between, the times messages were sent, their read status and which post the conversation was started from.
- Message history and encryption keys are stored on the device in an encrypted database and are not included in device backups.
Identity
A user who starts a message from a post appears to the other party only under an anonymous label specific to that conversation. The owner of the post appears in the way the post was shared: under an anonymous label if the post is anonymous, or under their nickname if it was shared under a nickname.
Retention
- Encrypted messages are kept on our servers for no more than 30 days and are then deleted.
- Message requests that are not answered expire after 14 days.
- Conversation records are kept for as long as at least one of the participants' accounts exists. The link between a participant who deletes their account and that account is removed during the deletion process. Remaining conversation records are deleted within 30 days at the latest after both accounts have been deleted. The retention conditions for evidence set aside for a specific report or legal proceeding apply separately.
- A copy of a sent message exists on the recipient's device. The recipient may keep this message or share it with others. These copies cannot be recalled by DuyApp.
- Receiving messages can be turned off in the application settings.
Reporting messages
When a conversation is reported, with the consent of the reporting user, up to 10 of the most recent messages on their device are sent to the moderation team. After reaching the server, these messages are separately encrypted and stored, and can be opened only by authorised moderators. The account of the reported person is also added to the report record. Evidence copies of the reported messages are kept for 90 days from the creation of the evidence record, and the report record is kept for 365 days from its creation. The reported person is not notified of the report.
Artificial intelligence (Duyu)
The artificial intelligence features in DuyApp are offered under the name Duyu and operate through an artificial intelligence service provider located abroad. Details on the recipient and the use of data are explained in the Duyu data transfer section.
Duyu chat
- In chats with Duyu, the messages written and the chat history are sent to the artificial intelligence service provider so that a reply can be generated and the chat can be given a title. Messages written by the user are sent without modification.
- When the web search feature is used, the search is carried out through the artificial intelligence service provider's web search tool. Location information is not sent in searches. Source links in the reply open in the in-app browser.
- When Duyu answers based on nearby posts, it also sends the name of the area where the question was asked, the time zone and the times at which the relevant posts were shared to the artificial intelligence service provider.
- Duyu chats and the area where each message was asked are kept on our servers until the account is deleted, so that the chat history can be displayed.
Use of posts in Duyu
- So that Duyu can search nearby posts, the text of public posts shared under a nickname is sent to the artificial intelligence service provider and added to the search index. This is done regardless of whether the owner of the post uses Duyu.
- Anonymous posts are not included in Duyu's post search or area summaries; they are not sent to the artificial intelligence service provider for these purposes.
- Comments and poll answers are not used in Duyu.
- Before the text of posts shared under a nickname and used in Duyu is sent to the artificial intelligence service provider, information such as email addresses, mobile phone numbers, Turkish national ID numbers, IBANs and card numbers is automatically masked.
Duyu Fun
- Duyu Fun is a feature consisting of fictional posts, comments and images generated by artificial intelligence.
- In this feature, the scenario text entered and the comments written are sent to the artificial intelligence service provider so that content can be generated. Comments written in Duyu Fun are stored together with information on the area in which the comment was made.
- Content generated by artificial intelligence is marked in the application as artificial intelligence content and passes through an automatic safety check before it is published.
- Duyu Fun content can be deleted from within the application.
Duyu chats are different from end-to-end encrypted private messages between people; they are sent to the service provider in order to generate replies. Automatic masking cannot detect all personal information and does not necessarily make the text anonymous. Do not write unnecessary identity, contact or sensitive information to Duyu, and do not unlawfully share private information belonging to others.
The publication of a post or acceptance of the Terms of Service does not mean that the personal data in that post may be used in artificial intelligence for every purpose. The scope of use of posts in Duyu and the explanations on special categories of personal data are addressed separately in the KVKK Disclosure Notice.
Duyu data transfer
The data described above in connection with Duyu chat, Duyu Fun and the use of posts in Duyu is sent to the OpenAI service, based in the United States. The service provider processes this data on behalf of DuyApp. This transfer does not cover end-to-end encrypted messaging between people.
In Duyu requests, the email address, username, nickname or raw account ID is not sent as a separate account field. However, the text you write or the content of a post may contain this information. In some requests, a pseudonymised security code derived from the account ID of the requesting user is sent to the artificial intelligence service provider for the detection of abuse. This code does not reveal the raw account ID; it is not regarded as anonymous data.
In this provider's API service, customer data is not used for model training by default. Abuse monitoring logs may be kept for up to 30 days under normal conditions; longer retention may apply because of legal obligations or security exceptions. The retention periods of application logs may also vary depending on the API feature used. For this reason, no definitive commitment of 30-day deletion or zero retention is given for all data. Details are set out in the provider's API data explanation. Transfer abroad is also explained below.
Purposes of processing
- To create accounts, authenticate users and secure the account.
- To show area-based content and to associate content with the correct area.
- To provide features such as posts, comments, messaging, Duyu, Duy Points and invitations.
- To send push notifications.
- To enforce the community guidelines, review reports and prevent spam and abuse.
- To use as evidence in legal disputes and to fulfil legal obligations.
The legal grounds on which data is processed are explained in the KVKK Disclosure Notice.
Sharing of data
Other users
- Shared posts, comments and polls can be seen, together with the area name, by all users of DuyApp.
- For posts made under a nickname, the username, nickname and profile photo are visible. The profile page additionally shows the biography and the join date.
- Notifications may include the nickname or anonymous label of the user who triggered the notification and may be visible on the device's lock screen. Notifications do not include the content of other users' posts or messages.
Service providers
DuyApp's main application server and database are kept on the infrastructure of the hosting service provider. So that the service can be provided, only the data necessary for the relevant service is shared with the following service providers:
- Server and database hosting service providers: Hosting of the main application server and database; storage of account, content and application records so that the service can be provided. The countries where hosting actually takes place and the transfer conditions are explained separately in the KVKK Disclosure Notice.
- Artificial intelligence and content safety service providers: The Duyu and Duyu Fun features. The chat messages described above, the text of posts shared under a nickname and suitable for use in Duyu, area names, scenario texts and comments.
- Media storage, content delivery and website service providers: Storage and delivery of photos, hosting of the duyapp.com website.
- Email delivery service providers: Sending verification and account recovery codes by email. The email address and the code.
- Push notification service providers: Delivery of push notifications. The notification token and the notification text.
- GIF and visual content service providers: GIFs. GIF searches are made through our servers and only the search text is sent. GIF images are loaded from the servers of the relevant content provider. In this process, the IP address of the device displaying the GIF is sent to the content provider.
- Map service providers: Map images in the application. When map images are loaded, the IP address of the device and the map area being viewed are sent to this service.
Transfer abroad
Transferring personal data abroad requires the conditions set out in Article 9 of Law No. 6698 to be met. For regular service provider transfers, an adequacy decision or appropriate safeguards are assessed; the exceptions for occasional transfers do not give a general permission for continuous API use. Service providers may process data abroad. For the relevant services, the countries where processing actually takes place and the transfer mechanism used are stated in the KVKK Disclosure Notice.
Competent authorities
Personal data may be shared with competent authorities in line with legal obligations and upon requests made in due form.
Corporate transactions
In the event of a merger, demerger, acquisition or sale of assets of the company that operates DuyApp, personal data may be transferred to the relevant parties, limited to the safeguards in this policy.
Retention periods
- Account information and shared content: For as long as the account is open.
- Deleted posts and comments: Deleting a post or comment in the app hides it from other users. This does not remove its text and photo copies from active systems at the same time; copies may remain until account deletion or completion of a separate personal-data deletion request. You can submit a separate deletion request using the contact address below. Evidence copies necessary for a specific report, legal dispute or binding preservation obligation may be kept separately. A separate retention period applies to backups.
- Email verification code: 10 minutes.
- Exact location collected for the map: No more than 15 minutes.
- IP address and session records: Ordinary session records kept for security purposes and the IP and device information associated with them may be retained while the account exists and are removed during account deletion. Expiry or revocation of a session does not mean that its records are deleted at the same time. Separate retention conditions apply to legally required traffic records. The purposes and legal grounds for processing these records are explained in the Session security and traffic logs section of the KVKK Disclosure Notice.
- Encrypted private messages: No more than 30 days on our servers.
- Report records: Evidence copies of private messages sent with a report are kept for 90 days from the creation of the evidence record; private message report records are kept for 365 days from the creation of the report record. Other content report records are kept for 365 days from the date on which the file was closed, whether by action taken or by rejection. If a file is reopened, this period is calculated from the date it is closed again.
- Duyu chats: Until the account is deleted.
- Technical tracking record of the deletion process: 30 days after the completion of the account deletion.
- Destruction operation records: The minimum records documenting deletion, destruction and anonymisation operations are kept for at least 3 years from the date of the operation. These records do not contain copies of the content of deleted posts, comments or messages.
- Ordinary support correspondence: 6 months from the closing of the request, then deletion.
- KVKK application records: The minimum records documenting the application, the reply, the relevant dates and the delivery are kept for 3 years from the final reply; unnecessary attachments are deleted earlier.
- Website security records: Access and error logs under DuyApp's control, for no more than 30 days from their creation.
- Backups: Deletion in active systems may not remove previously created backup copies at the same time. Backup copies are subject to separate retention and destruction processes.
Data whose retention period has ended is deleted, destroyed or anonymised. Records kept separately for a specific report, security incident, legal dispute or binding preservation obligation are limited to the relevant purpose and the necessary period; not all records are kept indefinitely on this ground.
Account deletion
The account can be deleted from within the application with passkey confirmation. If the application cannot be accessed, a deletion request can be sent to the support team from the registered university email address.
When deletion is confirmed, the account is closed, the email address is removed from the account, and the content and data belonging to the account enter the deletion process. Certain security, report and message records and backups may be kept for a further period in accordance with the relevant retention conditions. Copies and screenshots on other users' devices cannot be recalled by DuyApp.
Application steps, processing times, deleted data, retention exceptions and temporary security restrictions are explained together on the Delete Account page.
Data security
Technical and administrative measures are taken for the security of personal data. Communication between the application and the servers is encrypted. Passwords are not used. Sign-ins are made with a passkey. Verification codes and session keys are stored only in hashed form. The content of private messages is end-to-end encrypted.
Website
The duyapp.com website does not use cookies for advertising or analytics purposes. The site is served on the infrastructure of the hosting and security service provider; the site's access logs are processed by the same provider for security purposes.
Age limit
DuyApp is intended only for users aged 18 and over. Verification of a university email address does not constitute age verification. The accounts of users found to be under 18 are closed and their data enters the deletion process; records that must be kept by law are retained, limited to the relevant purpose and period.
Rights
Under Article 11 of Law No. 6698, rights such as learning whether personal data is being processed, requesting information, requesting correction or deletion, and the other rights can be exercised. Applications can be made to destek@duyapp.com and are concluded free of charge within 30 days at the latest. The application methods and the full list of rights are set out in the KVKK Disclosure Notice.
Changes
This policy may be updated as the features of the application or the relevant legislation change. If advertising or a new data processing activity is added to the application, this policy is updated before the feature in question is made available, and explicit consent is obtained where necessary. The publication date of the current version appears at the top of the page. Significant changes are also announced within the application.
Contact
For questions about this policy, you can write to destek@duyapp.com, and for requests relating to personal data, to destek@duyapp.com.
The company and postal address details are included in the Terms of Service.