Privacy Policy Turkey Privacy Notice Terms of Use Cookie Policy

Turkey Privacy Notice

Last updated: July 24, 2026

This notice is prepared under Turkish Personal Data Protection Law No. 6698 (KVKK), Article 10, to inform users about data processing activities carried out by VelNotes.

1. Data Controller

Data Controller: VelNotes
Contact: support@velnotes.com
Website: https://velnotes.com/

2. Collection Methods

Personal data may be collected electronically through app usage, the website, direct email communication, subscription verification, and user-initiated backup/export workflows.

3. Personal Data Categories

The current mobile app does not require a VelNotes account and does not create an email profile or sign-in-provider record. The app and website do not offer a support form that asks for a name, email address, or phone number. If the user chooses to write from their own email app, the sender address, subject, and message content are processed as part of ordinary email delivery. A random Support ID is kept in the device Keychain, contains no name or email, and is not sent automatically; it may be associated with the correspondence if the user sends the prepared email. Legacy Firebase Authentication records created by earlier versions may temporarily contain an email, display name, provider identifier, and account status during migration; the accountless release does not use those records for notebook access or Pro entitlement. Usage/transaction data may include notebook operations and backup activity. Device/security data may include request timestamps, IP address, user-agent, and security logs for the website. For website analytics, country/region distribution may be measured using country code inferred from request headers (with Accept-Language fallback when needed). To preserve the selected website language (Turkish or English), the page may read a language value from the URL and, where preference cookies are allowed, a local on-device preference record; no separate server-side language profile is created. Where voice and Video to Text features are used, user-approved transcription output may be processed as notebook content. During local video import, the audio track of the supported media file the user chose may be extracted on device; VelNotes does not download videos from YouTube or third-party links. When iCloud Backup is enabled, a backup archive may be refreshed automatically after local changes or manually by the user in that user's iCloud Drive area. It is not sent to a VelNotes server; Apple protects it under the Apple Account and iCloud settings, and end-to-end encryption depends on Advanced Data Protection. Backup and data export payloads may include limited technical metadata for restore-safety checks. Pages captured through camera/document-scanner flows, images imported from the photo library, and image/video exports saved to the photo library at the user's request may also be processed as related content data. Device-local biometric lock checks using Face ID / Touch ID or device passcode fallback are handled on the device; VelNotes does not access, store, or transmit biometric template data to its servers. Website admin access may use Google/Firebase authentication only for authorized administrators; that administrator session is not a mobile-app account.

4. Local-first Backup Notice

Notebook data you own is processed local-first. When iCloud Backup is enabled, a safety copy may be refreshed automatically after local changes or manually by the user; a restore check starts enabled by default when no active local notebook exists and can be turned off. Data export is user-initiated and governed by the destination the user selects.

5. Processing Purposes

Data is processed for service delivery, subscription management, notebook editing, subscription validation, security and anti-abuse controls, device-permission-based local notifications, user support, and legal compliance.

6. Legal Bases

Processing may rely on legal bases including contractual necessity, legal obligations, protection/exercise of rights, legitimate interests, and explicit consent when required.

7. Data Transfers and Sub-processors

Data may be transferred to infrastructure/service providers such as Apple, iCloud Drive and website/admin infrastructure depending on user action and technical workflow. Firebase/Google infrastructure may be used for authorized administrator Google sign-in, the web admin panel, site configuration, admin media management, temporary migration storage for legacy app-account records, and consented web analytics; support messages are not sent to Firebase and reach us only if the user sends an email. This does not mean the iOS app has a notebook account or automatic notebook-content transfer. In the current production version, content processing and audio/video transcription are not sent to an external AI/LLM provider. International transfer may occur.

Sub-processors: Apple Inc. (StoreKit 2, Speech.framework, and when enabled iCloud Drive — USA, under Apple Developer Program License Agreement). Google/Firebase for authorized administrator sign-in, web admin panel, site configuration, admin media management, temporary legacy-account migration, and consented web analytics.

International transfer safeguards: Transfers are safeguarded under KVKK Article 9 through explicit consent or adequate protection conditions, and under GDPR Article 46 through EU Standard Contractual Clauses (SCCs).

8. Voice Recording Storage Notice

When voice recording starts, an app-local temporary audio file may be created (velnotes_recording_*.m4a). The file is used for recording/transcription workflow continuity and may be removed by cleanup flows or when a new recording replaces it. If the user exports the file, retention is governed by the selected destination. Audio/video transcription uses on-device speech recognition provided by the operating system when supported; on unsupported devices this feature cannot be used. Video to Text works only with supported local media files and within the in-app duration limit. Transcription output is generated automatically and may contain mistakes. In the default flow, raw audio/video files are not uploaded to VelNotes servers as notebook content.

9. Retention

Data is retained for the period necessary for processing purposes and legal requirements. Data deletion requests trigger cleanup flows for relevant support/operational records. Each move to Trash writes a new deletion timestamp. Restore clears it, and deleting the item again restarts the 30-day period from the latest deletion. Unless permanently deleted earlier, an item may remain locally and, when enabled, in the iCloud backup until the 30-day boundary. On the first eligible app maintenance run at or after expiry, it is removed locally and excluded from new backups; it is removed from the iCloud archive when that archive is read or refreshed. If the device, app, or iCloud is unavailable, this completes on the next eligible run. Security and anti-abuse logs (including IP address and user-agent) may be retained for limited periods under legitimate-interest and legal-obligation grounds. Sent support emails may remain in the mailbox and the email providers' ordinary retention or backup systems for the time needed to answer and meet legal obligations; they enter deletion flows when no longer needed. Legacy account records are deleted or anonymized after migration and applicable legal or operational needs end. Free-tier local notebook data may be lost on uninstall/device-loss unless a backup exists. iCloud backups remain under the user's Apple account control, and the restore check reads from that same user-controlled iCloud area. Exported archives remain under the user's selected destination.

10. Rights Under KVKK Article 11

You may request access, correction, deletion, objection, and other rights recognized under KVKK. You can also manage notification permissions through operating system settings. Requests may be submitted to support@velnotes.com with sufficient identity verification details.

11. Data Breach Notification Procedure

In the event of a personal data breach, notification will be made to the relevant Data Protection Authority within 72 hours in accordance with KVKK Article 12/5 and GDPR Article 33. If the breach poses a high risk to users' rights, affected people with known contact details will be notified directly; otherwise notice will be provided through an appropriate method such as the website or an in-app notice as soon as reasonably possible. Contact: support@velnotes.com

12. Cookie Note

velnotes.com uses strictly necessary storage and consent-based optional categories. Website analytics may include visited-page and country/region distribution measurements via country code inferred from request headers, without requesting browser geolocation access. See Cookie Policy for details.