NOYGG
DilLanguage

Gizlilik Politikası ve Aydınlatma Metni

Sürüm: 3.1 — Yürürlük: 10 Eylül 2026

Bu metin, NOYGG hizmetinde hangi kişisel verilerin neden işlendiğini anlatan KVKK md. 10 ve GDPR md. 13 kapsamındaki aydınlatma metnidir. E-posta, görünen ad, parola ve kayıt modu gerektiriyorsa davet kodu sunucuya gönderilmeden önce gösterilir.

“Okudum ve bilgi edindim” beyanı yalnızca aydınlatmanın yapıldığını gösterir; açık rıza veya Kullanım Şartları kabulü değildir. Kullanım Şartları kabulü ve 16 yaşını doldurduğuna ilişkin beyan ayrı ayrı alınır.

Veri sorumlusu, NOYGG hizmetini işleten gerçek kişidir. Başvuru ve iletişim kanalı: support@noygg.com

1. Ses nasıl işlenir

Odalardaki konuşmalar kaydedilmiyor. Odadaki ses, Almanya'daki kendi LiveKit sunucumuz üzerinden diğer katılımcılara gerçek zamanlı iletilir. Bu geçici iletim sırasında ses işlenir; ancak kaydedilmez, dosyaya yazılmaz ve sonradan dinlenemez. Uygulamada kayıt, transkript veya tekrar oynatma özelliği yoktur. Ses Google Firebase'e gönderilmez.

Android uygulamasında oda ekranı açıkken ekran görüntüsü ve ekran kaydı engellenir, oda sesi aynı telefondaki başka uygulamaların yakalamasına kapalı işaretlenir. Bu önlemler kaydı zorlaştırır ama ikinci bir cihazla kayıt alınmasını imkânsız kılamaz; işletim sisteminin böyle bir koruma sunmadığı ortamlarda uygulanamaz. İzinsiz kayıt ve paylaşım Kullanım Şartları'nda yasaktır ve şikâyet edilebilir.

2. İşlenen veri kategorileri

Hesap ve kayıt

Oda ve güvenlik

Yetkili oda erişimi

Yetki ve talepler

Hesap güvenlik olayları

Teknik kayıtlar ve istatistik

Sorun bildirimi (yalnız sen gönderirsen)

Uygulamada bir bağlantı veya ses sorunu yaşarsan Sorun bildir ile teknik bir anlık görüntü gönderebilirsin. Bu veri pasif olarak toplanmaz: yalnız sen düğmeye bastığında ve gönderilecek her satırı ekranda gördükten sonra iletilir.

Bu liste cihazında geçici olarak tutulur, uygulamayı kapattığında silinir ve bildirimi gönderdikten sonra temizlenir. Ses kaydı, konuşulanlar, IP adresin, konumun ve kişi listen gönderilmez. Bildirim bir destek talebi olarak açılır; yalnız yöneticiler teknik anlık görüntüyü görebilir — moderatörler göremez.

İsteğe bağlı bildirim verisi

Şehir, kesin konum, rehber, reklam kimliği, kişi bazlı analiz olayı veya izleme çerezi toplanmaz. Yukarıda açıklanan ülke kodu yalnız toplu katılım sayacı içindir ve kullanıcı profiline bağlanmaz. Firebase Analytics kapalıdır. Cihazındaki fotoğraf galerisi taranmaz veya okunmaz: yalnızca senin seçtiğin tek dosya işlenir ve o dosya da konum bilgisi silinerek gönderilir.

İsteğe bağlı kategoriler ve topluluklar

3. Amaçlar ve hukuki sebepler

E-posta, görünen ad, parola, e-posta doğrulaması, ayrı Kullanım Şartları kabulü ve 16+ beyanı hesap açmak için zorunludur. Davet kodu yalnız davetli kayıt modunda zorunludur; açık kayıt modunda istenmez. Tanıtım metni, konuşmacı olmak ve FCM bildirimi isteğe bağlıdır. Zorunlu veriler verilmezse hesap veya ilgili özellik sunulamaz.

Topluluk işlemleri için ayrı açık rıza. Kategori takiplerini, topluluk üyeliklerini ve sahipliğini hesabınla ilişkilendirerek keşif, Topluluklarım ve topluluk yönetimini sunmak, ortaya çıkabilecek hassas ilgi bilgileri dahil, isteğe bağlı ve ayrı açıklanmış işleme amacıdır. Bunun için açık rızan istenir; genel Kullanım Şartları kabulü veya bu metni okuman rıza yerine geçmez (GDPR md. 6/1-a ve özel nitelikli veri için md. 9; KVKK md. 5 ve 6 kapsamındaki açık rıza şartları).

Rıza vermemek veya geri çekmek normal hesabını ve bağımsız oda kullanımını engellemez; yalnız bu isteğe bağlı ilişkileri kurma/sürdürme işlevleri kullanılamaz. Görünürlük ve bildirim tercihleri rızadan ayrıdır. Mevcut bir hesabın olması da topluluk rızası sayılmaz.

Rıza kararının kanıtı, mevcut bir yaptırımın uygulanması ve itirazın incelenmesi ayrı amaçlardır; bunlara ait sınırlı kayıtlar aşağıdaki saklama kurallarına tabidir. Bu kayıtlar geri çekilen rızaya dayanarak keşif veya ilgi ilişkilerini sürdürmek için kullanılamaz. Hakların tesisi, kullanılması ve korunması için zorunlu kayıtlar bakımından KVKK md. 5/2-e ve GDPR md. 6/1-f; özel nitelikli veri söz konusuysa ayrıca md. 6 ve GDPR md. 9'daki uygulanabilir şartlar değerlendirilir. Rızanın geri çekilmesi, önceki rızaya dayalı işlemenin geçmişteki hukuka uygunluğunu etkilemez.

Seçtiğin ilgi ilişkileri yukarıdaki amaçla işlenir; bunlardan reklam profili veya otomatik hassas görüş çıkarımı yapılmaz. Hukuki ya da benzer önemli sonuç doğuran yalnızca otomatik karar verme yapılmaz; moderasyon kararlarını bir insan verir.

4. Kimler görür ve veri nerede işlenir

Ana PocketBase veritabanı ve canlı ses sunucusu Almanya'dadır. Giriş yapmış üyeler, hizmetin yapısı gereği görünen adını, tanıtımını, seçtiğin avatarı, varsa yüklediğin profil fotoğrafını, erişebildikleri oda bilgilerini ve o odadaki rolünü görebilir. E-posta ve parola diğer üyelere gösterilmez. Takip ilişkisini yalnız ilişkinin iki tarafı kendi takipçi veya takip edilen listesinde görür; bildirim tercihlerini ve geçici bildirim kuyruğunu diğer üyeler göremez. Hesap güvenlik olaylarını (giriş, başarısız giriş, parola işlemleri) yalnızca hesabın sahibi görür; bunlar diğer üyelere de, moderatörlere de gösterilmez. İtiraz ve destek yazışmalarını yalnızca sen ve talebi inceleme yetkisi olan yetkililer görür; kararı veren kişi kendi kararına yapılan itirazı inceleyemez — bunun mümkün olmadığı durumda incelemenin aynı kişi tarafından yapıldığı sana açıkça bildirilir. Yetkili yönetici; üyelik, güvenlik ve moderasyon için gerekli kayıtlara erişebilir. Kanunen zorunluysa yetkili makamlara gerekli veri verilebilir.

Topluluk görünürlüğü. Kişisel Topluluklarım listesi herkese açık değildir. Kategori/topluluk kişi dizinindeki görünürlüğün, sahip olsan bile, her ilişki için başlangıçta kapalıdır. Ayrı olarak açarsan, aynı kategori veya topluluğa katılan ve erişim şartlarını sağlayan kişiler profil özetini görebilir; iki yönlü engeller uygulanır. Kişi dizini e-posta veya platform kademesi göstermez. Keşfe açık topluluğun adı, açıklaması ve sahip bilgisi ise topluluk tanıtımının parçasıdır; üye dizinini gizlemek, oluşturduğun topluluğu veya sahipliğini gizli yapmaz.

Topluluk sahipliği, platform moderatörlüğü veya gizli üyelerin listesini görme yetkisi vermez. Yetkililer yalnız kendilerine tanımlanan topluluk işlemlerini yapabilir; teknik NOYGG Yönetimi daha geniş ve ayrı bir yönetim yüzeyidir. İtirazın ve karar ayrıntıların ilgili kişiye ve bunları incelemeye yetkili görevlilere açıktır; sahiplik tek başına başkasının itirazını okuma hakkı vermez. Yetkili veri dökümüne topluluk ilişkileri ve rıza kararı da girer; gerekçe ve işlem kaydı şartları sürer.

E-posta doğrulama, parola sıfırlama ve yeni konumdan giriş güvenlik bildirimleri yapılandırılmış posta hizmeti üzerinden gönderilir. E-posta adresini değiştirme işlemini başlatırsan değişiklik onayı; tek kullanımlık parola ile giriş özelliği etkinleştirilirse istediğin giriş kodu da aynı hizmetle gönderilir. Alıcı e-posta adresi, standart SMTP teslim bilgileri, ileti türü ve giriş bildiriminde yer alan güvenlik ayrıntıları yalnız bu iletileri ulaştırmak için posta hizmeti sağlayıcısı tarafından işlenebilir. Otomatik iletilerin gönderen adresi noreply@noygg.com, yardım kanalı support@noygg.com adresidir.

Verinin kopyasını isteme ve yetkili makam talebi. Bir kişinin verisi birden çok yerde tutulduğu için, talep hâlinde tamamı tek bir dökümde toplanır. Bu döküm yalnız yönetici tarafından alınabilir, yazılı gerekçe ister ve dökümün kendisi moderasyon işlem kaydına yazılır — yani kimin dökümünün ne zaman ve hangi gerekçeyle alındığı sonradan denetlenebilir. Döküm parola ya da oturum anahtarı içermez; bunlar hesabın kilididir, verin değildir.

Google Firebase Cloud Messaging. FCM otomatik başlatma ilk kurulumda kapalıdır. Yalnız güncel aydınlatma gösterildikten ve cihaz bildirim izni verildikten sonra jeton ile FID oluşturulur. İzin vermezsen uygulamanın temel işlevleri çalışır; arka plan sesi ve kapalıyken oda daveti bildirimi kısıtlanabilir.

FCM küresel Google altyapısıdır; veriler Google veya alt işleyenlerinin tesis bulundurduğu ülkelerde işlenebilir. Almanya'daki ana sunucu, FCM verisini Almanya ile sınırlamaz. Google, müşteri verisi için genel olarak veri işleyen olduğunu; kısıtlı Avrupa aktarımlarında geçerli aktarım çözümü ve gerektiğinde standart sözleşme maddeleri kullandığını belirtir. Google ayrıca hizmetin işletilmesi sırasında oluşan hizmet verisini kendi şartları kapsamında işler. Aktarım güvenceleri hakkında bilgi support@noygg.com adresinden istenebilir.

5. Saklama ve hesap silme

Hesabı silme. Ayarlar → Hesabımı sil onaylandığında oturum erişimi hemen kesilir. Ana veritabanı temizliği normalde aynı işlemde tamamlanır; geçici bir veritabanı hatasında hesap kilitli kalır ve dakikalık görev temizliği yeniden dener. Sahibi olduğun bütün odalar kapanır, rastgele bir kişiye devredilmez. Canlı ses sunucusundaki oda ve yetki temizliği ana silme kararından sonra arka planda tamamlanabilir.

Depoda doğrulanmış sabit bir yedek silme süresi bulunmadığı için “7 günde tüm yedeklerden silinir” sözü verilmez. Güncel yedek yaşam döngüsü bilgisi support@noygg.com adresinden istenebilir.

5.1. Topluluklar: geri çekme ve ayrı saklama süreleri

Ayarlar → Topluluk gizlilik tercihleri → Rızamı geri çek yolunu kullanabilirsin. Başarılı geri çekmede kategori takiplerin, topluluk üyeliklerin, tarafı olduğun devirler, hesabına bağlı topluluk bildirim kuyruğu/tekrar önleme kayıtları ve topluluk bildirim tercihlerin silinir. Sahiplik bağın kaldırılır; topluluk hemen sahipsiz ve keşfe kapalı olur. Hesabın, oturumun, mevcut odaların ve ses bağlantın kapanmaz. Yeniden rıza vermek eski üyelikleri veya sahipliği geri getirmez.

6. Hakların

KVKK md. 11 ve uygulanabildiği ölçüde GDPR md. 15-21 kapsamında verine erişme, kopya alma, düzeltme, silme, işlemeyi kısıtlama, taşınabilirlik ve itiraz haklarına sahipsin. Bir işlem rızaya dayanıyorsa rızanı ileriye etkili olarak geri çekebilirsin. Ayrıca yetkili veri koruma makamına şikâyette bulunabilirsin.

Talebini support@noygg.com adresine gönder. Kimliğini ve başkasının verisini korumak için makul doğrulama istenebilir. Hesabın için en doğrudan silme yolu: Ayarlar → Hesabımı sil.

7. Çocuklar

Hizmet 16 yaşından küçükler için değildir. Kayıtta doğum tarihi değil, 16 yaşını doldurduğuna ilişkin ayrı bir beyan alınır. 16 yaşından küçük birine ait olduğunu öğrendiğimiz hesap silinir.

8. Değişiklikler

Önemli bir değişiklikte yeni metin kullanım öncesi gösterilir ve yalnızca okuyup bilgi edindiğin beyanı alınır. Gizlilik metnini “kabul etmen” istenmez; gerekli ayrı bir rıza varsa kendi amacıyla ayrı sunulur.

9. İletişim

Veri koruma talepleri ve sorular için: support@noygg.com

Privacy Policy and Notice

Version: 3.1 — Effective: 10 September 2026

This is the privacy notice required by KVKK art. 10 and GDPR art. 13. It explains what personal data NOYGG processes and why. It is shown before your email, display name, password and, where the registration mode requires one, invite code are sent to the server.

“I have read and understood” only records that the notice was provided; it is not consent and not acceptance of the Terms of Use. Acceptance of the Terms and the declaration that you are 16 or older are collected separately.

The data controller is the individual who operates the NOYGG service. Requests and contact: support@noygg.com

1. How audio is processed

Room audio is relayed in real time to the other participants through our own LiveKit server in Germany. Audio is processed transiently for that delivery, but it is not recorded, written to a file or available for replay. The app has no recording, transcript or replay feature. Audio is not sent to Google Firebase.

In the Android app, while the room screen is open, screenshots and screen recording are blocked and room audio is marked as not capturable by other apps on the same phone. These measures make recording harder but cannot prevent a second device from recording, and they cannot be applied where the operating system offers no such protection. Recording or sharing without permission is prohibited by the Terms and can be reported.

2. Categories of data processed

Account and registration

Rooms and safety

Staff access to rooms

Authorisation and requests

Account security events

Technical records and statistics

Problem reports (only when you send one)

If you run into a connection or audio problem, you can send a technical snapshot using Report a problem. This is not collected passively: it is sent only when you press the button, and only after you have seen every line that will be sent on screen.

The list is kept temporarily on your device, is erased when you close the app, and is cleared after you send a report. Audio recordings, what was said, your IP address, your location and your contacts are not sent. The report opens as a support request; only administrators can see the technical snapshot — moderators cannot.

Optional notification data

We do not collect city or precise location, contacts, an advertising identifier, person-level analytics events or tracking cookies. The country code described above is used only for an aggregate join counter and is not linked to a user profile. Firebase Analytics is disabled. Your photo gallery is never scanned or read: only the single file you pick is processed, and it is sent with its location data stripped.

Optional categories and communities

3. Purposes and legal bases

An email, display name, password, email verification, separate acceptance of the Terms and the 16+ declaration are required to create an account. An invite code is required only in invited-registration mode and is not requested in open-registration mode. A bio, speaking in a room and FCM notifications are optional. If required data is not provided, the account or relevant feature cannot be provided.

Separate explicit consent for community processing. Linking your category follows, community memberships and ownership to your account to provide discovery, My communities and community management, including sensitive interests those choices may reveal, is an optional, separately explained purpose. We ask for explicit consent; accepting the general Terms or reading this notice is not consent (GDPR art. 6(1)(a), and art. 9 for special-category data; the explicit-consent conditions in KVKK arts. 5 and 6).

Declining or withdrawing consent does not prevent normal account use or independent room use; only the optional functions that create or maintain these relationships become unavailable. Visibility and notification choices are separate from consent. Having an existing account is not community consent.

Evidence of the consent decision, enforcing an existing measure and reviewing an appeal serve separate purposes, with limited records subject to the retention rules below. Those records cannot be used to continue discovery or interest relationships based on withdrawn consent. Where records are necessary to establish, exercise or defend rights, KVKK art. 5(2)(e) and GDPR art. 6(1)(f) are considered; special-category data additionally requires an applicable condition under KVKK art. 6 and GDPR art. 9. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.

Your chosen interest relationships are processed for the purpose above, not to create advertising profiles or automatically infer sensitive views. There is no solely automated decision-making with legal or similarly significant effects; a human makes moderation decisions.

4. Who sees data and where it is processed

The primary PocketBase database and live-audio server are in Germany. Authenticated members can see your display name, bio, the avatar you chose, your profile picture if you uploaded one, rooms they are allowed to access and your role in those rooms as needed for the service. Your email and password are not shown to other members. A follow relationship is visible only to its two parties in their own follower or following list; other members cannot see your notification preferences or the temporary delivery queue. Account security events (sign-ins, failed sign-ins, password activity) are visible to the account holder only — not to other members and not to moderators. Appeal and support conversations are visible to you and to staff authorised to review them; whoever made a decision cannot review the appeal against it — where that is not possible, you are told plainly that the review was carried out by the same person. An authorised administrator can access records needed for membership, security and moderation. Data may be provided to competent authorities where legally required.

Community visibility. Your personal My communities list is not public. Visibility in each category/community people directory starts off, including for owners. If you enable it separately, people who have joined the same category or community and meet the access conditions can see your profile summary; blocks in both directions apply. The directory does not show email addresses or platform tiers. A discoverable community's name, description and owner information are part of its presentation; hiding your directory membership does not make a community you create or its ownership private.

Community ownership does not grant platform moderation powers or access to hidden membership lists. Staff may perform only the community actions assigned to them; technical NOYGG Management is a separate, broader administration surface. Appeal and decision details are available to the affected person and authorised reviewers; ownership alone does not allow reading somebody else's appeal. Authorised data exports include community relationships and the consent decision, with the existing reason and audit requirements.

Email-verification, password-reset and new-location sign-in security notices are sent through the configured mail service. If you start an email-address change, its confirmation message is sent through the same service; if one-time-password sign-in is enabled, so is the sign-in code you request. The recipient address, standard SMTP delivery information, message type and the security details included in a sign-in notice may be processed by the mail-service provider solely to deliver those messages. The sender for automated messages is noreply@noygg.com and the support channel is support@noygg.com.

Requesting a copy of your data, and lawful requests. Because a person's data is held in more than one place, on request all of it is gathered into a single export. Only an administrator can produce that export, it requires a written reason, and the export itself is written to the moderation audit log — so whose data was exported, when, and on what grounds can be audited afterwards. The export never contains passwords or session keys; those are the lock on your account, not your data.

Google Firebase Cloud Messaging. FCM automatic initialisation is off on a fresh install. A token and FID are created only after the current notice has been shown and the device notification permission is granted. If you decline, the app's core functions still work; background audio and room invite notifications while the app is closed may be limited.

FCM uses Google's global infrastructure, and data may be processed in any country where Google or its subprocessors maintain facilities. Hosting the primary server in Germany does not confine FCM data to Germany. Google states that it generally acts as processor for customer data and uses a valid data transfer solution and, where needed, Standard Contractual Clauses for restricted European transfers. Google separately processes service data under its own terms. Information about transfer safeguards can be requested at support@noygg.com.

5. Retention and account deletion

Deleting the account. Once you confirm Settings → Delete my account, access to the account ends immediately. Primary database cleanup normally finishes in the same operation; if a temporary database error occurs, the account remains locked and a scheduled task retries the cleanup every minute. Every room you own closes and is not transferred to a random participant. Room and permission cleanup on the live-audio server may finish in the background after the primary deletion decision.

The repository does not evidence a fixed backup-erasure period, so no promise that every backup is cleared “within 7 days” is made. You may request the current backup lifecycle at support@noygg.com.

5.1. Communities: withdrawal and separate retention periods

Use Settings → Community privacy preferences → Withdraw my consent. A successful withdrawal deletes your category follows, community memberships, transfers involving you, account-linked community delivery/cooldown records and community notification preferences. Your ownership link is removed; the community immediately becomes ownerless and undiscoverable. Your account, session, existing rooms and audio connection stay open. Consenting again does not restore old memberships or ownership.

6. Your rights

Under KVKK art. 11 and, where applicable, GDPR arts. 15-21, you may request access, a copy, correction, erasure, restriction, portability, or object to processing. Where processing relies on consent, you may withdraw it for the future. You may also complain to the competent data protection authority.

Send a request to support@noygg.com. Reasonable verification may be required to protect your data and other people's data. The direct account deletion path is Settings → Delete my account.

7. Children

The service is not for anyone under 16. Registration asks for a separate declaration that you are at least 16, not a date of birth. If we learn that an account belongs to someone under 16, it is deleted.

8. Changes

If this notice changes materially, the new version is shown before further use and you are asked only to confirm that you have read and understood it. You are not asked to “accept” a privacy notice; any consent that is actually required is presented separately for its specific purpose.

9. Contact

Privacy requests and questions: support@noygg.com