ThinkOnce

Gizlilik

Gizlilik Politikası

Yürürlük tarihi: 1 Ağustos 2026 · Sürüm 2.0 · ThinkOnce, bir Elbruz Logic ürünüdür

Notların ve bilgilerin senindir. Uygulamayı çalıştırmak dışında onlara karışmayız. Notların önce cihazında yaşar; giriş yaparsan yalnızca senin açabildiğin özel bir alana yedeklenir ve Avrupa Birliği'nde saklanır. Aşağıdaki bölümlerde ne topladığımızı, nerede tuttuğumuzu ve kiminle paylaştığımızı ayrıntısıyla bulabilirsin.

İçindekiler: 1. Veri sorumlusu ve kapsam · 2. İşlenen kişisel veriler · 3. İşleme amaçları ve hukuki sebepler · 4. Not içerikleri ve yapay zekâ · 5. Verinin saklandığı yer ve yurt dışına aktarım · 6. Alt işleyenler ve üçüncü taraflar · 7. Saklama süreleri · 8. İlgili kişinin hakları ve başvuru · 9. Veri güvenliği · 10. Çocukların verisi · 11. Değişiklikler ve iletişim

1. Veri sorumlusu ve kapsam

İşbu Gizlilik Politikası ("Politika"), Bandırma / Balıkesir, Türkiye adresinde mukim Elbruz Logic (vergi kimlik numarası 1990661347) tarafından geliştirilen ve işletilen ThinkOnce mobil uygulaması (com.elbruzlogic.thinkonce) ile thinkonce.app alan adı altında yayımlanan internet sitesi bakımından, 6698 sayılı Kişisel Verilerin Korunması Kanunu ("KVKK") uyarınca veri sorumlusu sıfatıyla ve Avrupa Birliği Genel Veri Koruma Tüzüğü ("GDPR") m.4/7 anlamında "controller" sıfatıyla gerçekleştirilen kişisel veri işleme faaliyetlerine ilişkin usul ve esasları düzenlemek üzere hazırlanmıştır. Uygulamayı indirmen, hesap oluşturman veya hizmetlerden herhangi birini kullanman hâlinde bu Politikanın kapsamına girersin. Politika, uygulama içinden ve internet sitesinden sürekli olarak erişilebilir durumda tutulur. Gizliliğe ilişkin her türlü soru, talep ve başvuru support@thinkonce.app adresine yöneltilebilir.

2. İşlenen kişisel veriler

Hizmetin sunulabilmesi amacıyla işlediğimiz kişisel veriler şunlardır. Kimlik ve iletişim verileri kapsamında, hesap oluşturman hâlinde ad ve e-posta adresin; Google veya Apple ile giriş yapmayı tercih etmen hâlinde ilgili sağlayıcının bize ilettiği ad, e-posta ve kullanıcı kimliği bilgisi işlenir. Uygulamayı hesap açmadan, misafir olarak kullanman mümkündür; bu durumda herhangi bir kimlik verisi işlenmez. Kullanıcı içeriği kapsamında, uygulamaya yazarak veya sesle eklediğin not metinleri, bu notlara atadığın etiketler, öncelik değerleri, hatırlatma tarih ve saatleri ile kaydettiğin konum adları işlenir; bu veriler öncelikli olarak cihazının yerel depolamasında tutulur ve yalnızca giriş yapmış olman hâlinde hesabına özel bir alana yedeklenir. Konum verisi, yalnızca senin kaydettiğin yerlere yaklaştığında hatırlatma alabilmen amacıyla ve yalnızca ilgili izni vermen hâlinde işlenir; yakınlık eşleştirmesi cihazın üzerinde gerçekleştirilir, sürekli konum geçmişin tarafımıza aktarılmaz ve sunucularımızda bir konum izi oluşturulmaz. Ses verisi, sesle not alma özelliğini kullandığında yalnızca konuşmanın metne dönüştürülmesi amacıyla işlenir; dönüştürme işlemi tamamlandığı anda ses kaydı silinir ve hiçbir şekilde saklanmaz. İşlem güvenliği verileri kapsamında, ücretsiz deneme ve referans haklarının kötüye kullanılmasını önlemek amacıyla cihazına ait geri döndürülemez nitelikte bir özet (hash) değeri tutulur; ham cihaz tanımlayıcısı saklanmaz. Kullanım sinyalleri kapsamında, bildirimleri hangi saatlerde açtığın gibi temel etkileşim verileri, hatırlatma zamanlamasının sana göre iyileştirilmesi amacıyla işlenir. Toplu kullanım istatistikleri kapsamında ise hangi ekranların görüntülendiği, uygulama sürümü ve üyelik seviyesi gibi ölçümler toplanır. Reklam kimliği (IDFA / Android Reklam Kimliği) kullanılmamakta, kullanıcılar uygulamalar veya internet siteleri arasında izlenmemekte ve bu istatistikler kimlik verileriyle eşleştirilmemektedir.

3. İşleme amaçları ve hukuki sebepler

Kişisel verilerin, aşağıda belirtilen amaçlarla ve karşılarında gösterilen hukuki sebeplere dayanılarak işlenmektedir. Notlarının saklanması ve cihazların arasında eşitlenmesi, hatırlatmaların zamanlanması ve iletilmesi, hesabının oluşturulması ve yönetilmesi ile satın aldığın üyelik haklarının tanımlanması amaçlarıyla yürütülen işleme faaliyetleri, sözleşmenin kurulması veya ifası için gerekli olması hukuki sebebine dayanır (KVKK m.5/2-c; GDPR m.6/1-b). Mikrofon erişimi, konum erişimi ve yapay zekâ destekli çözümleme özellikleri bakımından işleme, açık rızana dayanır (KVKK m.5/1; GDPR m.6/1-a); bu özelliklerin tamamı varsayılan olarak kapalıdır, ilgili izni vermediğin sürece çalışmaz ve verdiğin izni dilediğin an cihazının işletim sistemi ayarlarından geri alabilirsin; iznin geri alınması, geri alma anına kadar gerçekleştirilmiş işlemelerin hukuka uygunluğunu etkilemez. Hizmetin güvenliğinin sağlanması, hataların tespiti ve giderilmesi ile ücretsiz deneme ve referans haklarının kötüye kullanımının önlenmesi amaçlarıyla yürütülen işleme, veri sorumlusunun meşru menfaatleri hukuki sebebine dayanır (KVKK m.5/2-f; GDPR m.6/1-f); bu kapsamda menfaat dengesi gözetilmekte ve temel hak ve özgürlüklerine zarar vermeyecek şekilde hareket edilmektedir. Satın alma ve fatura kayıtlarının mevzuatın öngördüğü süre boyunca muhafaza edilmesi ise hukuki yükümlülüğün yerine getirilmesi hukuki sebebine dayanır (KVKK m.5/2-ç; GDPR m.6/1-c). Kişisel veriler, bu bölümde sayılan amaçlar dışında herhangi bir amaçla işlenmez; kullanıcılar hakkında profilleme yapılmaz, tamamen otomatik sistemler aracılığıyla analiz edilerek kullanıcı aleyhine hukuki sonuç doğuran bir karar üretilmez ve hiçbir kişisel veri üçüncü kişilere satılmaz.

4. Not içerikleri ve yapay zekâ

Yapay zekâ destekli özellikler bakımından uyguladığımız esaslar aşağıdaki gibidir. Not içeriklerine rutin insan erişimi bulunmamaktadır; personelimiz notlarını okumaz. Sunucu tarafındaki hiçbir işlev not içeriğini okumaz, listelemez veya görüntülemez; not içeriğine dokunan tek sunucu işlevi, hesap silme talebin üzerine verileri kaldıran işlevdir. Toplanan kullanım istatistikleri yalnızca sayısal ölçümlerden ibarettir ve not metni içermez. Erişim yalnızca, bir destek talebi kapsamında ilgili notu bize açıkça iletmen hâlinde veya yürürlükteki mevzuat ya da yetkili makam kararı uyarınca hukuken zorunlu kalınması hâlinde ve yalnızca gerekli olan ölçüde söz konusu olur. Not içerikleri ve ses kayıtları, yapay zekâ modellerinin eğitilmesi amacıyla kullanılmaz; bu husus hem tarafımız hem de hizmet sağlayıcımız bakımından geçerlidir. Yapay zekâ işlevleri, Google tarafından sunulan Gemini uygulama programlama arayüzü üzerinden ve ücretli hizmet katmanında yürütülmektedir; Google'ın ücretli hizmet şartları uyarınca, bu katmanda gönderilen istem ve yanıtlar Google tarafından kendi modellerinin eğitilmesi amacıyla kullanılmaz. Bir not içeriği yapay zekâya, yalnızca ilgili özelliği bizzat çalıştırman hâlinde ve yalnızca o işlemin gerektirdiği süre boyunca iletilir; notların arka planda taranmaz, toplu olarak işlenmez veya başka bir amaçla analiz edilmez. Sesle not alma özelliğinde ses kaydı, metne dönüştürme işleminin tamamlanmasının ardından derhâl silinir. Uygulamada reklam gösterilmemekte, reklam kimliği kullanılmamakta ve kullanıcılar uygulamalar veya internet siteleri arasında izlenmemektedir.

5. Verinin saklandığı yer ve yurt dışına aktarım

Notlarına, etiketlerine, kaydettiğin yerlere ve hesap bilgilerine ilişkin veriler, Google Cloud altyapısı üzerinde çalışan Firestore veri tabanında ve Avrupa Birliği çoklu bölgesinde (Belçika ve Hollanda'da konumlu veri merkezleri) saklanmaktadır. Yapay zekâ ile çözümleme ve sesi metne dönüştürme işlemleri, Avrupa Birliği sınırları içinde (Belçika) konumlu sunucular üzerinde yürütülmektedir. Buna karşılık, satın alma doğrulaması, bildirim gönderimi ve hesap e-postalarının iletilmesi gibi bazı destekleyici sunucu işlevleri Amerika Birleşik Devletleri'nde konumlu sunucular üzerinde çalışmakta olup, bu işlevlerin gerektirdiği ölçüde ve kapsamda kişisel verilerin yurt dışına aktarımı söz konusu olmaktadır. Söz konusu aktarımlar, hizmet sağlayıcılarımızla akdedilen veri işleme sözleşmeleri ve Avrupa Komisyonu tarafından kabul edilen Standart Sözleşme Maddeleri kapsamında, KVKK m.9 ve GDPR Bölüm V hükümlerine uygun şekilde gerçekleştirilmektedir. Bu belgelerin bir örneğini talep etmen hâlinde, ticari sır niteliği taşıyan kısımları kapatılmak suretiyle tarafına iletilir.

6. Alt işleyenler ve üçüncü taraflar

Hizmetin sunulabilmesi için aşağıdaki hizmet sağlayıcılarından yararlanılmaktadır. Google Firebase; kimlik doğrulama, bulut veri tabanı, sunucu işlevleri, anlık bildirim, uygulama içi mesaj, uzaktan yapılandırma, kötüye kullanım koruması (App Check) ve toplu kullanım istatistikleri hizmetleri bakımından. Google Gemini uygulama programlama arayüzü (ücretli katman); sesin metne dönüştürülmesi ve ifadenin görevlere ayrıştırılması bakımından. Google Haritalar; konum hatırlatması oluştururken harita görüntülenmesi ve yer seçimi bakımından. Apple ve Google işletim sistemi ses tanıma hizmetleri; cihazının yerleşik dikte özelliğini kullanman hâlinde, ses verisinin ilgili işletim sistemi sağlayıcısı tarafından işlenmesi bakımından. Apple App Store ve Google Play; satın alma ve abonelik doğrulaması bakımından — ödeme kartı bilgilerin tarafımızca hiçbir aşamada görülmez veya saklanmaz. Amazon Simple Email Service ve Resend; hesap doğrulama, parola sıfırlama ve bilgilendirme e-postalarının iletilmesi bakımından. Shorebird; uygulama güncellemelerinin mağaza sürecinden bağımsız olarak iletilmesi bakımından. Google Play Install Referrer (yalnızca Android); uygulamanın hangi kampanya üzerinden yüklendiğinin tespiti bakımından. Bu sağlayıcılar, kişisel verileri yalnızca bize hizmet sunulması amacıyla ve talimatlarımız doğrultusunda işlemekte olup, kendi amaçları için kullanmaları sözleşme ile yasaklanmıştır. Kişisel veriler hiçbir üçüncü kişiye satılmamakta ve reklam amacıyla paylaşılmamaktadır. Kurumsal kullanım hâlinde veri işleme sözleşmesi ve güncel alt işleyen listesi talep edilebilir.

7. Saklama süreleri

Kişisel veriler, işlendikleri amacın gerektirdiği süre boyunca ve mevzuatta öngörülen azami süreler gözetilerek saklanır. Notların, etiketlerin ve kaydettiğin yerler, bunları silmen veya hesabını kapatman anına kadar muhafaza edilir; hesabın silinmesi hâlinde kalıcı olarak ortadan kaldırılır. Ses kayıtları, metne dönüştürme işleminin tamamlanmasının ardından derhâl silinir ve hiçbir şekilde saklanmaz. Hesap bilgileri, hesabın açık olduğu süre boyunca saklanır; silme talebinin tarafımıza ulaşmasından itibaren en geç otuz gün içinde aktif sistemlerden kaldırılır, yedek ortamlardan tamamen temizlenmesi ise teknik nedenlerle doksan günü bulabilir. Satın alma ve fatura kayıtları, vergi mevzuatı uyarınca daha uzun süre (Türkiye bakımından on yıl) muhafaza edilir; bu kayıtlar herhangi bir not içeriği barındırmaz. Kötüye kullanımın önlenmesi amacıyla tutulan geri döndürülemez cihaz özeti, ücretsiz deneme suistimalinin tekrarının engellenmesi amacıyla saklanmaya devam eder ve kimlik verilerinle eşleştirilmez. Saklama sürelerinin sona ermesi hâlinde kişisel veriler silinir, yok edilir veya anonim hâle getirilir.

8. İlgili kişinin hakları ve başvuru

Bulunduğun ülkenin mevzuatına göre; kişisel verilerinin işlenip işlenmediğini öğrenme, işlenmişse buna ilişkin bilgi talep etme, işlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme, yurt içinde veya yurt dışında verilerin aktarıldığı üçüncü kişileri bilme, eksik veya yanlış işlenmiş olması hâlinde bunların düzeltilmesini isteme, silinmesini veya yok edilmesini isteme, işlenmesinin kısıtlanmasını talep etme, işlenmesine itiraz etme, verilerini yapılandırılmış ve yaygın kullanılan bir biçimde alma ve verdiğin açık rızayı geri çekme haklarına sahipsin (KVKK m.11; GDPR m.15-22). Hesabını ve tüm verini silmenin en hızlı yolu, uygulama içindeki Ayarlar → Hesabımı sil adımıdır; bu işlem tarafımıza başvurmana gerek kalmaksızın, doğrudan senin tarafından ve derhâl gerçekleştirilir. Diğer tüm talepler support@thinkonce.app adresine iletilebilir; başvurular en geç otuz gün içinde ve kural olarak ücretsiz şekilde sonuçlandırılır. Başvurunun yanıtını yeterli bulmaman hâlinde, Türkiye'de Kişisel Verileri Koruma Kurumu'na, Avrupa Birliği'nde ise mutat meskeninin bulunduğu üye devletin veri koruma otoritesine şikâyette bulunma hakkın saklıdır. Kaliforniya eyaleti mevzuatı (CCPA/CPRA) bakımından: kişisel verilerini satmamakta ve paylaşmamaktayız; bu haklarını kullanman hâlinde sana farklı muamele edilmez.

9. Veri güvenliği

Kişisel verilerin hukuka aykırı şekilde işlenmesini ve verilere hukuka aykırı erişilmesini önlemek ile verilerin muhafazasını sağlamak amacıyla, teknolojik imkânlar ve uygulama maliyeti gözetilerek gerekli teknik ve idari tedbirler alınmaktadır. Veriler aktarım sırasında endüstri standardı şifreleme protokolleri (HTTPS/TLS) ile, saklama sırasında ise hizmet sağlayıcı altyapısında şifreli olarak korunur. Veri tabanı erişim kuralları, bir hesabın yalnızca kendisine ait verilere erişebilmesine izin verecek biçimde yapılandırılmıştır; başka bir kullanıcının notlarına erişim teknik olarak engellenmiştir. Sunucularımıza ulaşan istekler Firebase App Check ile doğrulanmakta, böylece yetkisiz istemcilerden gelen erişim girişimleri reddedilmektedir. Alınan tüm tedbirlere rağmen, internet üzerinden yapılan hiçbir aktarımın veya elektronik saklamanın mutlak güvenliğinin taahhüt edilemeyeceğini belirtmek isteriz. Kişisel verilerin hukuka aykırı olarak başkaları tarafından elde edilmesi hâlinde, mevzuatın öngördüğü süreler içinde ilgili kişilere ve yetkili makamlara bildirimde bulunulur.

10. Çocukların verisi

ThinkOnce, on üç yaşın altındaki kullanıcılara yönelik bir hizmet değildir ve bu yaş grubundan bilerek kişisel veri toplanmaz. Uygulama, çocuklara yönelik içerik barındırmamakta ve çocuklara yönelik pazarlama faaliyeti yürütülmemektedir. Bu yaşın altındaki bir kullanıcıya ait kişisel verinin rızası olmaksızın tarafımıza iletildiğinin tespit edilmesi hâlinde, söz konusu veri gecikme olmaksızın silinir. Velisi olduğun bir çocuğun kişisel verisinin tarafımızca işlendiğini düşünüyorsan support@thinkonce.app adresi üzerinden bize ulaşabilirsin.

11. Değişiklikler ve iletişim

Bu Politika, mevzuattaki değişiklikler, hizmetin kapsamında meydana gelen güncellemeler veya kullanılan hizmet sağlayıcılarındaki değişiklikler nedeniyle güncellenebilir. Güncel metin her zaman bu sayfada yayımlanır ve sayfanın başında yer alan yürürlük tarihi ile sürüm numarası buna göre değiştirilir. Haklarını esaslı biçimde etkileyen bir değişiklik yapılması hâlinde, değişikliğin yürürlüğe girmesinden makul bir süre önce uygulama içi bildirim veya e-posta yoluyla ayrıca bilgilendirilirsin. Değişikliğin yürürlüğe girmesinden sonra hizmeti kullanmaya devam etmen, güncellenmiş Politikayı kabul ettiğin anlamına gelir. Bu Politikaya, uygulamanın kullanım koşullarına veya kişisel verilerine ilişkin her türlü soru, talep ve bildirim için support@thinkonce.app adresine yazabilirsin.

Privacy

Privacy Policy

Effective date: 1 August 2026 · Version 2.0 · ThinkOnce is an Elbruz Logic product

Your notes and your information are yours. Beyond running the app, we leave them alone. They live on your device first; if you sign in, they're backed up to a private space only you can open, stored in the European Union. The sections below set out in detail what we collect, where we keep it and who we share it with.

Contents: 1. Controller and scope · 2. Personal data we process · 3. Purposes and legal bases · 4. Note content and artificial intelligence · 5. Where data is stored and international transfers · 6. Sub-processors and third parties · 7. Retention periods · 8. Your rights and how to exercise them · 9. Data security · 10. Children's data · 11. Changes and contact

1. Controller and scope

This Privacy Policy (the "Policy") sets out the principles and procedures governing the processing of personal data carried out by Elbruz Logic, established in Bandırma / Balıkesir, Türkiye (tax identification number 1990661347), acting as data controller within the meaning of Article 4(7) of the EU General Data Protection Regulation ("GDPR") and as veri sorumlusu under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"), in connection with the ThinkOnce mobile application (com.elbruzlogic.thinkonce) and the website published under the thinkonce.app domain. You fall within the scope of this Policy if you download the application, create an account, or otherwise use any of the services. The Policy is made permanently accessible from within the application and from the website. Any question, request or application concerning privacy may be addressed to support@thinkonce.app.

2. Personal data we process

The categories of personal data processed in order to provide the service are as follows. As regards identity and contact data, where you create an account we process your name and email address; where you elect to sign in with Google or Apple, we process the name, email address and user identifier transmitted to us by the relevant provider. You may use the application as a guest without creating an account, in which case no identity data is processed. As regards user content, we process the note texts you enter by typing or dictation, the labels you assign to those notes, priority values, reminder dates and times, and the names of places you save; such data is held primarily in the local storage of your device and is backed up to a space private to your account only where you have signed in. Location data is processed solely so that you may receive reminders when you approach places you have saved, and only where you have granted the relevant permission; proximity matching is performed on your device, no continuous location history is transmitted to us, and no location trail is created on our servers. Voice data is processed, where you use the dictation feature, solely for the purpose of converting speech into text; the recording is deleted the moment conversion is complete and is not retained in any form. As regards transaction security data, an irreversible hash value derived from your device is retained in order to prevent abuse of free trials and referral entitlements; the raw device identifier is not stored. As regards engagement signals, basic interaction data such as the times at which you open notifications is processed in order to improve the timing of reminders for you. As regards aggregate usage statistics, measurements such as which screens are displayed, application version and membership tier are collected. No advertising identifier (IDFA / Android Advertising ID) is used, users are not tracked across applications or websites, and these statistics are not matched with identity data.

3. Purposes and legal bases

Personal data is processed for the purposes set out below and on the legal bases indicated against each of them. Processing carried out for the purposes of storing your notes and synchronising them across your devices, scheduling and delivering reminders, creating and administering your account, and conferring the membership entitlements you have purchased is based on the necessity of processing for the conclusion or performance of a contract (Article 6(1)(b) GDPR; Article 5/2-c KVKK). In respect of microphone access, location access and artificial-intelligence-assisted analysis features, processing is based on your explicit consent (Article 6(1)(a) GDPR; Article 5/1 KVKK); all such features are disabled by default, do not operate unless you grant the relevant permission, and any permission granted may be withdrawn at any time through your device's operating system settings, without affecting the lawfulness of processing carried out prior to withdrawal. Processing carried out for the purposes of securing the service, detecting and remedying faults, and preventing abuse of free trials and referral entitlements is based on the legitimate interests pursued by the controller (Article 6(1)(f) GDPR; Article 5/2-f KVKK); a balancing exercise has been undertaken in this respect and processing is conducted in a manner that does not prejudice your fundamental rights and freedoms. Retention of purchase and invoice records for the period prescribed by law is based on compliance with a legal obligation (Article 6(1)(c) GDPR; Article 5/2-ç KVKK). Personal data is not processed for any purpose other than those enumerated in this section; users are not profiled, no decision producing legal effects concerning them is taken solely on the basis of automated processing, and no personal data is sold to third parties.

4. Note content and artificial intelligence

The principles we apply in respect of artificial-intelligence-assisted features are as follows. There is no routine human access to note content; our personnel do not read your notes. No server-side function reads, lists or displays note content; the only server function that touches note content is the one that removes your data upon your account deletion request. The usage statistics we collect consist solely of numerical measurements and contain no note text. Access occurs only where you expressly transmit a note to us in the context of a support request, or where we are legally compelled to do so under applicable law or by a decision of a competent authority, and then only to the extent strictly necessary. Note content and voice recordings are not used for the purpose of training artificial intelligence models; this applies both to us and to our service provider. Artificial intelligence functions are performed through the Gemini application programming interface made available by Google, on its paid service tier; under Google's paid service terms, prompts and responses submitted on that tier are not used by Google to train its models. Note content is transmitted to the artificial intelligence service only where you personally invoke the relevant feature, and only for such time as that operation requires; your notes are not scanned in the background, processed in bulk, or analysed for any other purpose. In the dictation feature, the voice recording is deleted immediately upon completion of the conversion to text. No advertising is displayed within the application, no advertising identifier is used, and users are not tracked across applications or websites.

5. Where data is stored and international transfers

Data relating to your notes, labels, saved places and account information is stored in the Firestore database operating on Google Cloud infrastructure, in the European Union multi-region (data centres located in Belgium and the Netherlands). Artificial intelligence analysis and speech-to-text conversion are performed on servers located within the borders of the European Union (Belgium). By contrast, certain supporting server functions — such as purchase validation, delivery of notifications and transmission of account emails — operate on servers located in the United States of America, and to the extent and within the scope required by those functions a transfer of personal data abroad takes place. Such transfers are effected in accordance with Chapter V of the GDPR and Article 9 of the KVKK, under data processing agreements concluded with our service providers and the Standard Contractual Clauses adopted by the European Commission. Upon request, a copy of these instruments will be provided to you, with any parts constituting trade secrets redacted.

6. Sub-processors and third parties

The following service providers are engaged in order to deliver the service. Google Firebase, in respect of authentication, cloud database, server functions, push notifications, in-application messaging, remote configuration, abuse protection (App Check) and aggregate usage statistics. The Google Gemini application programming interface (paid tier), in respect of converting speech into text and separating an utterance into tasks. Google Maps, in respect of displaying the map and selecting a place when a location reminder is created. Apple and Google operating-system speech recognition services, in respect of the processing of voice data by the relevant operating system provider where you use your device's built-in dictation feature. The Apple App Store and Google Play, in respect of purchase and subscription validation — your payment card details are at no stage seen or stored by us. Amazon Simple Email Service and Resend, in respect of transmitting account verification, password reset and notice emails. Shorebird, in respect of delivering application updates independently of the store process. Google Play Install Referrer (Android only), in respect of determining the campaign through which the application was installed. These providers process personal data solely for the purpose of providing services to us and in accordance with our instructions, and are contractually prohibited from using it for their own purposes. No personal data is sold to any third party or shared for advertising purposes. A data processing agreement and an up-to-date list of sub-processors may be requested for business use.

7. Retention periods

Personal data is retained for such period as the purpose of processing requires, having regard to the maximum periods prescribed by law. Your notes, labels and saved places are retained until you delete them or close your account; upon deletion of the account they are permanently erased. Voice recordings are deleted immediately upon completion of the conversion to text and are not retained in any form. Account information is retained for as long as your account remains open; it is removed from active systems within thirty days of a deletion request reaching us, while complete clearance from backup media may, for technical reasons, take up to ninety days. Purchase and invoice records are retained for a longer period pursuant to tax legislation (ten years in Türkiye); such records contain no note content. The irreversible device hash retained for the prevention of abuse continues to be held in order to prevent repeated abuse of free trials and is not matched with your identity data. Upon expiry of the applicable retention periods, personal data is deleted, destroyed or anonymised.

8. Your rights and how to exercise them

Depending on the law of the country in which you are located, you have the right to learn whether your personal data is being processed, to request information in that regard, to learn the purpose of processing and whether the data is used in accordance with that purpose, to know the third parties to whom the data is transferred domestically or abroad, to request rectification where the data has been processed incompletely or inaccurately, to request erasure or destruction, to request restriction of processing, to object to processing, to receive your data in a structured and commonly used format, and to withdraw any explicit consent you have given (Articles 15-22 GDPR; Article 11 KVKK). The fastest route to erasing your account and all of your data is the Settings → Delete my account step within the application; this operation is carried out directly by you and takes effect immediately, without any need to apply to us. All other requests may be addressed to support@thinkonce.app; applications are concluded within thirty days and, as a rule, free of charge. Should you consider our response inadequate, you retain the right to lodge a complaint with the Turkish Data Protection Authority in Türkiye, or with the supervisory authority of the Member State of your habitual residence within the European Union. For the purposes of California legislation (CCPA/CPRA): we do not sell or share your personal information, and you will not be treated differently for exercising these rights.

9. Data security

Appropriate technical and organisational measures are implemented, having regard to the state of the art and the cost of implementation, in order to prevent the unlawful processing of and unlawful access to personal data and to ensure its preservation. Data is protected in transit by industry-standard encryption protocols (HTTPS/TLS) and at rest in encrypted form within the service provider's infrastructure. Database access rules are configured such that an account may access only data belonging to that account; access to the notes of any other user is technically prevented. Requests reaching our servers are verified by means of Firebase App Check, such that access attempts originating from unauthorised clients are rejected. Notwithstanding all measures taken, we note that the absolute security of any transmission over the internet or of any electronic storage cannot be guaranteed. In the event that personal data is unlawfully obtained by others, notification will be made to the data subjects concerned and to the competent authorities within the periods prescribed by law.

10. Children's data

ThinkOnce is not a service directed to users under the age of thirteen, and personal data is not knowingly collected from that age group. The application contains no content directed to children and no marketing activity is directed to children. Where it is established that personal data belonging to a user under that age has been transmitted to us without the requisite consent, such data is deleted without undue delay. If you believe that we are processing the personal data of a child of whom you are the guardian, you may contact us at support@thinkonce.app.

11. Changes and contact

This Policy may be updated by reason of changes in legislation, updates occurring in the scope of the service, or changes among the service providers engaged. The current text is at all times published on this page, and the effective date and version number appearing at the head of the page are amended accordingly. Where a change materially affects your rights, you will additionally be informed by means of an in-application notice or by email a reasonable period before the change takes effect. Your continued use of the service following the entry into force of a change constitutes acceptance of the updated Policy. For any question, request or notification concerning this Policy, the terms of use of the application, or your personal data, you may write to support@thinkonce.app.