Privacy Policy
App: Family Diaries · Last updated: August 25, 2026
1. Data Controller and Scope
This Privacy Policy explains how we collect, use, share, and protect your personal data when you use the Family Diaries mobile app (the "App").
The data controller within the meaning of Türkiye's Personal Data Protection Law No. 6698 ("KVKK") and the EU General Data Protection Regulation ("GDPR") is:
Email: harun.aybi99@gmail.com
By using the App, you are informed of the data processing activities described in this policy.
2. Personal Data We Process
2.1. Account and identity data
When you sign in with your Google or Apple account, we process:
- Your email address and full name (provided by your sign-in provider)
- A profile photo, if you choose to upload one
- A unique user ID generated by your sign-in provider
- A device notification token (FCM token) so we can send you notifications
- The date your account was created
- The identifier of the family group you belong to and your role in it (admin, member, or pending approval)
We never hold your password; authentication is handled entirely by your sign-in provider and Firebase Authentication.
2.2. Content you share in the App
The following content you share with your family group is stored, tied to your account:
- Notes you leave on the fridge board
- Calendar events
- Shared shopping list items
- Meal plans and your poll votes
- Status updates you share
- The family group's name and its 6-digit invite code (created by the member who sets the group up)
This content is visible only to members of your own family group; access is restricted server-side by security rules based on your group membership.
2.3. Technical data processed automatically
The infrastructure providers we rely on to run and secure the App (see Section 5) may automatically process:
- IP address and the approximate country/region derived from it
- Device model, operating system and version, app version
- Sign-in timestamps and authentication logs
This data arises on the provider's side while the infrastructure is operated; it is not collected or stored by the App itself. The App contains no analytics or crash-reporting software: your usage behaviour is not measured, and crash logs are not collected by us.
2.4. Device permissions
The App requests only the following permissions, and only at the moment you use the related feature:
- Camera access: only at the moment you choose to take your profile photo directly
- Photo library access: to upload a profile photo
- Notification permission: to deliver reminders and updates for your family group
2.5. Important note on location
The App does not track your location in the background and does not request access to your device's location services. The status shown on the "Where Are You?" tab is only a preset or note you choose to enter by hand; it is never collected automatically or continuously.
3. Purposes of Processing
Your personal data is processed for the following purposes:
- To create your account and verify your identity
- To run your family group's shared board (notes, calendar, shopping list, meals, status)
- To send you the notifications and reminders you have requested
- To secure the App and detect and fix errors
- To check whether the app version you are running is still supported and, if not, show you an update notice
- To comply with our legal obligations
Your data is not used for profiling, ad targeting, or automated decision-making.
4. Legal Basis
| Processing activity | KVKK legal basis | GDPR legal basis |
|---|---|---|
| Account creation, authentication, core app functionality | Art. 5/2(c) – Necessary for performance of a contract | Art. 6(1)(b) – Performance of a contract |
| Sending notifications | Art. 5/1 – Explicit consent | Art. 6(1)(a) – Consent |
| Security, error logs | Art. 5/2(f) – Legitimate interest | Art. 6(1)(f) – Legitimate interest |
| Cross-border transfer | Art. 9 – Standard contract / explicit consent | Chapter V – Standard Contractual Clauses |
Where processing is based on consent, you may withdraw it at any time; turning off notifications from your device settings or in the App deletes your notification token.
5. Data Sharing and Service Providers
Your data is processed through the following service providers, only to the extent necessary to run the App:
| Provider | Data processed | Purpose |
|---|---|---|
| Google Firebase (Authentication, Cloud Firestore, Storage, Cloud Messaging) | Account, content, technical data | Authentication, data storage, file storage, notifications |
| Google Firebase (Remote Config) | App version, platform, and app instance identifier | Checking the minimum supported version and showing the forced-update notice |
| Cloudflare Workers | Notification token and the data of the event triggering the notification | Delivering notifications. This service only relays; it does not store your data on its own side. |
| Google Sign-In / Sign in with Apple | Email, full name, user ID | Sign-in provider only |
We do not share or sell your data to advertisers, data brokers, or analytics/tracking companies, under any circumstances. The App contains no ad network or user-tracking software.
If a lawful request is received from a competent public authority, data may be shared, but only to the extent required by that request.
6. Cross-Border Data Transfer
Because the service providers listed above operate global cloud infrastructure, your data may be processed on servers outside Türkiye and the European Economic Area, primarily in the United States.
These transfers rely on standard contractual clauses and your explicit consent under KVKK Art. 9, and on the Standard Contractual Clauses (SCCs) adopted by the European Commission under GDPR. The relevant providers commit to these safeguards in their own data processing terms.
7. Retention Period
- Your data is retained for as long as your account is active.
- Your data is retained until you delete your account. We do not currently operate any automatic inactivity-based account deletion; if such a period is introduced in the future, you will be notified by email a reasonable time before deletion.
- Authentication and security logs are retained according to the retention periods of the infrastructure providers listed in Section 5; we do not keep separate copies of these logs.
- Data subject to a statutory retention obligation is kept for the period required by the applicable law.
8. Account Deletion and Leaving a Family
When you use "Delete My Account" in the profile screen:
- Your account record, profile photo, the fridge notes you wrote, and status updates are permanently deleted, and your poll votes are withdrawn from the vote lists.
- Shared family content, such as shopping list items, calendar events, and fridge notes written by someone else that you later edited, remains for other family members, but your identity is unlinked from it — your name is replaced with "Departed Member".
- If you are the family group's admin and other members remain, admin rights are transferred to one of them.
- When the last member of a family leaves, all of that family's content is permanently deleted.
- The link to your sign-in provider is also removed: if you signed in with Apple, your access token is revoked; if you signed in with Google, the access granted to the App is disconnected.
- Your identity record in Firebase Authentication is deleted; the process requires you to re-authenticate with your sign-in provider so we can confirm the account is yours.
- Records in backups, if any exist, are purged within the backup cycle, no later than 30 days.
If you cannot delete your account through the App, you may send a request to the email address in Section 1. See also the Account Deletion page for step-by-step instructions and how to submit a request.
Leaving a family. You may leave your current family without deleting your account, and then create a new family or join another one with a join code using the same account. In that case:
- Your account record, profile photo, and sign-in provider connection are kept; only your family link is removed.
- Content you leave behind in that family is handled by exactly the same rule as account deletion: the fridge notes you wrote and your status updates are deleted; shopping list items, calendar events, and notes written by someone else that you edited remain with the family, with your name replaced by "Departed Member".
- If you are the family admin and other members remain, admin rights are transferred to one of them.
- If you are the last member of the family, the family and all content in it are permanently deleted. You are warned about this before leaving.
- You stop receiving notifications for that family.
9. Data Security
Under KVKK Art. 12 and GDPR Art. 32, we apply the following technical and organizational measures to prevent unlawful processing of and access to your personal data:
- All communication between your device and our servers is encrypted with TLS; data is stored encrypted on the server side.
- Database access is restricted by security rules that let users access only content belonging to their own family.
- Administrative access is limited to authorized personnel and protected by multi-factor authentication.
- The components we use are regularly reviewed for security updates.
In the event of a data breach, we notify the Turkish Personal Data Protection Board and affected users within the timeframes required by law (as soon as possible, and within 72 hours, under KVKK).
10. Your Rights
Under KVKK Art. 11, by applying to the data controller you have the right to:
- Learn whether your personal data is being processed,
- Request information about it if it has been processed,
- Learn the purpose of processing and whether it is used consistently with that purpose,
- Know the third parties to whom your data is transferred, domestically or abroad,
- Request correction of incomplete or inaccurate data,
- Request its deletion or destruction,
- Request that correction, deletion, or destruction be notified to third parties to whom the data was transferred,
- Object to a result that is to your detriment arising solely from analysis by automated systems,
- Request compensation for damage arising from unlawful processing.
Under GDPR you also have the rights to data portability, restriction of processing, and objection to processing.
You may send your requests to harun.aybi99@gmail.com. We respond within 30 days at the latest.
You also retain the right to lodge a complaint with the Turkish Personal Data Protection Authority, or, in the European Economic Area, with your country's data protection supervisory authority.
11. Children's Privacy
The App is designed for parents and adult family members to create and manage accounts. It is not intended for children under 13 (or under 16 in the European Economic Area) to create their own account independently.
If we discover that we have processed a child's personal data below this age without parental consent, we will delete the relevant account and data without delay. Parents or guardians who become aware of such a case may contact us at the email address in Section 1.
12. Changes to This Policy
This Privacy Policy may be updated from time to time. Material changes will be announced in the App or on this page a reasonable time before they take effect. The "Last updated" date at the top of this page indicates the version currently in force.
13. Contact
For any questions or requests regarding this policy:
Email: harun.aybi99@gmail.com