Gizlilik Politikası ve Aydınlatma Metni
Sürüm: 3.1 — Yürürlük: 10 Eylül 2026
Bu metin, NOYGG hizmetinde hangi kişisel verilerin neden işlendiğini anlatan KVKK md. 10 ve GDPR md. 13 kapsamındaki aydınlatma metnidir. E-posta, görünen ad, parola ve kayıt modu gerektiriyorsa davet kodu sunucuya gönderilmeden önce gösterilir.
“Okudum ve bilgi edindim” beyanı yalnızca aydınlatmanın yapıldığını gösterir; açık rıza veya Kullanım Şartları kabulü değildir. Kullanım Şartları kabulü ve 16 yaşını doldurduğuna ilişkin beyan ayrı ayrı alınır.
Veri sorumlusu, NOYGG hizmetini işleten gerçek kişidir. Başvuru ve iletişim kanalı: support@noygg.com
1. Ses nasıl işlenir
Odalardaki konuşmalar kaydedilmiyor. Odadaki ses, Almanya'daki kendi LiveKit sunucumuz üzerinden diğer katılımcılara gerçek zamanlı iletilir. Bu geçici iletim sırasında ses işlenir; ancak kaydedilmez, dosyaya yazılmaz ve sonradan dinlenemez. Uygulamada kayıt, transkript veya tekrar oynatma özelliği yoktur. Ses Google Firebase'e gönderilmez.
Android uygulamasında oda ekranı açıkken ekran görüntüsü ve ekran kaydı engellenir, oda sesi aynı telefondaki başka uygulamaların yakalamasına kapalı işaretlenir. Bu önlemler kaydı zorlaştırır ama ikinci bir cihazla kayıt alınmasını imkânsız kılamaz; işletim sisteminin böyle bir koruma sunmadığı ortamlarda uygulanamaz. İzinsiz kayıt ve paylaşım Kullanım Şartları'nda yasaktır ve şikâyet edilebilir.
2. İşlenen veri kategorileri
Hesap ve kayıt
- E-posta adresi, adresin doğrulanıp doğrulanmadığı, okunabilir düz parola yerine parola doğrulama verisi, görünen ad ve isteğe bağlı tanıtım metni
- İsteğe bağlı avatar seçimi: uygulamanın sunduğu hazır görsellerden hangisini seçtiğin. Seçim bir numaradır, görsel değildir; görseller uygulamayla birlikte gelir. Seçmezsen adının baş harfleri gösterilir
- İsteğe bağlı profil fotoğrafı: yüklemeyi seçersen tek bir kare görsel dosyası. Fotoğraf senin cihazında kırpılır, 512×512 piksele küçültülür ve yeniden kodlanır; konum dahil bütün EXIF bilgileri silinir ve orijinal dosya sunucuya hiç gönderilmez. Sunucu da aynı kuralları denetler; ölçüyü aşan ya da gizli bilgi taşıyan dosyayı kabul etmez. Fotoğraf yüklemek zorunlu değildir ve dilediğin zaman kaldırabilirsin
- Davetli kayıt modu açıksa üyelik davet kodu ve seni davet eden hesap; davet oluşturma özelliği açıksa oluşturduğun davetlerin durumu
- Yeni hesap için e-posta adresine gönderilen kısa ömürlü ve tek kullanımlık doğrulama bağlantısı. Bağlantı kullanılana kadar hesap etkin değildir
- Kabul edilen Kullanım Şartları sürümü ve sunucu zamanı
- Okunup bilgi edinilen gizlilik sürümü, dil ve sunucu zamanı
- 16+ beyanı ve sunucu zamanı; doğum tarihi istenmez
Oda ve güvenlik
- Oda başlığı, açık/özel durumu, sahibi ile açılış ve kapanış zamanları
- Aktif odadaki katılımcı, rol, el kaldırma ve sahne daveti durumu
- Özel oda davetleri, engeller, odadan çıkarma ve oda yasağı kayıtları
- Takip ilişkileri: takip ettiğin hesaplar ve seni takip eden hesaplar. Bu listeler herkese açık bir keşif dizini değildir; yalnız ilişkinin tarafları kendi “Takipçiler” ve “Takip Edilenler” ekranlarında görür
- Özel odanın paylaşım bağlantısı anahtarı (sahibi iptal edince ya da yenileyince silinir; oda kapanınca geçersizleşir ve oda kaydıyla birlikte silinir; bağlantıyla giriş davet kaydı olarak tutulur)
- Şikâyetin tarafları, oda, sebep, isteğe bağlı not, inceleme durumu ve işlem
- Yaptırım türü (askı ya da kısmi kısıt), süresi, kategorisi ve yönetici gerekçesi
- Moderasyon işlem kaydı: yetkililerin yaptığı işlemler kaydedilir — yaptırım uygulanması ve kaldırılması, yetki değişikliği, kademe tanımı değişikliği, platform ayarı değişikliği, davet hakkı değişikliği, yetkilinin bir odayı kapatması, gerekçeli oda sorgusu ve kişi dökümü alınması. Her kayıtta işlemi yapan yetkilinin kimliği ve rolü, işlemin hedefi, türü, kategorisi, süresi ve zamanı bulunur. Bu kayıt yöneticiler dahil herkesi kapsar ve sonradan değiştirilemez; bir düzeltme gerekirse eski kayıt silinmez, yanına yeni bir kayıt yazılır. Amacı kararların denetlenebilir olması ve yetkinin kötüye kullanılmasını tespit edebilmektir.
Yetkili oda erişimi
- Kapalı bir odaya yetkili erişimi olduğunda şunlar kaydedilir: erişen görevlinin kimliği ve kademesi, oda, gerekçe kategorisi ve yazılı gerekçe, iznin ve gerçek girişin başladığı an, süreli gizliliğin bittiği ve görevlinin görünür olduğu an, odadaki uyarının belirmesi için hesaplanan ve gerçekten belirdiği an, oda sahibine bildirim gidip gitmediği
- Bu kayıt yöneticiler dahil herkesi kapsar ve sonradan değiştirilemez
- Görevli, yalnız kapalı odaya gerçekten girdikten sonra başlayan ve yönetim ayarına göre en çok 15 dakika süren ilk bölümde diğer katılımcılardan gizlenebilir. Süre dolunca görevli odadaysa görünür olur. Uyarı gecikmesi bu görünürlük anından sonra başlar
- Görevli uyarı belirmeden ayrılırsa sonradan “yetkili bu odada” uyarısı gösterilmez. Gerçek giriş olmuşsa oda sahibine bir kez, görevlinin odada bulunduğunu geçmiş zamanlı anlatan bildirim gider; hiç girilmeyen bir izin bildirim üretmez. Bildirimde oda başlığı yer almaz
- Odada konuşulanlar kaydedilmez. Erişim, sesin kaydedilmesi ya da saklanması anlamına gelmez; yetkili odaya diğer katılımcılar gibi girer ve ses yalnız o an iletilir
Yetki ve talepler
- Hesabına bir yetkili kademesi verilmişse bu bilgi hesap kaydında tutulur (örneğin moderatör). Kademen yalnız sana ve yetki dağıtan yöneticiye görünür; diğer üyelere gösterilmez
- Yetki verildiğinde ya da alındığında bu işlem, kimin yaptığıyla birlikte moderasyon işlem kaydına yazılır
- İtiraz ve destek talepleri: açtığın talebin türü (itiraz/destek), konusu, yazdığın mesajlar ve yetkilinin yanıtları; itirazsa hangi yaptırıma karşı açıldığı ve sonucu (karar korundu / geri alındı)
- İtirazı inceleyen yetkilinin kimliği sana gösterilmez; yalnız "yetkili" olduğu görünür
- İtirazın sonucu, yazışmadan ayrı olarak moderasyon işlem kaydına da yazılır
Hesap güvenlik olayları
- Kendi hesabında şu olaylar kaydedilir: giriş, başarısız giriş denemesi, parola değişikliği, parola sıfırlama ve tüm cihazlardan çıkış
- Her olayla birlikte olayın zamanı ve isteğin geldiği IP adresi tutulur
- Bu kayıtları uygulamada yalnızca sen görürsün (Ayarlar → Hesap güvenliği) ve sana maskelenmiş olarak gösterilir: adresin son bölümü kaldırılır, tam adres uygulamaya hiç gönderilmez. Moderatörlere kapalıdır. Aşağıdaki iki durum istisnadır ve ikisi de kayda geçer: kendi verinin kopyasını istemen, ve kanunen zorunlu bir talep
- Var olmayan bir e-posta adresiyle yapılan giriş denemesi kaydedilmez; böylece bu kayıtlar bir adresin kayıtlı olup olmadığını sorgulamaya yaramaz
- Amacı hesabına yetkisiz erişim olup olmadığını görebilmen ve kaba kuvvet denemelerini tespit edebilmemizdir
Teknik kayıtlar ve istatistik
- Bağlantı IP adresi, istek zamanı, yol ve durum kodu ile hata/güvenlik günlüklerinde gerekli olduğunda hesap veya oda kimliği
- Günlük toplamlar: açılan oda, odaya katılım, gönderilen oda daveti, yeni üye, üretilen üyelik davet kodu, odalarda geçen toplam süre ve açılan şikâyet sayısı. Bu sayılar kimlik taşımaz
- Günlük tekil kullanıcı sayısı için kimlik yalnız o gün tutulur, gece silinir; sonra yalnız toplu sayı kalır
- Odaya yeni bir katılım olduğunda bağlantı IP adresi, sunucumuzdaki yerel ülke veritabanıyla yalnız iki harfli ülke koduna çevrilir. İstatistik tablosuna sadece gün + ülke kodu + katılım sayısı yazılır; IP adresi, hesap/oda kimliği, şehir, koordinat veya kesin konum bu tabloya yazılmaz. 5'ten küçük ülke grupları istatistik ekranında tek tek gösterilmez, “Diğer” altında birleştirilir. VPN veya mobil ağ geçidi nedeniyle ülke tahmini hatalı olabilir. Ülke veritabanı yerel çalışır; IP bu amaçla başka bir hizmete gönderilmez
Sorun bildirimi (yalnız sen gönderirsen)
Uygulamada bir bağlantı veya ses sorunu yaşarsan Sorun bildir ile teknik bir anlık görüntü gönderebilirsin. Bu veri pasif olarak toplanmaz: yalnız sen düğmeye bastığında ve gönderilecek her satırı ekranda gördükten sonra iletilir.
- Cihazın üreticisi, modeli ve Android sürümü
- Son teknik olayların listesi: yalnız olay kodları ve zamanları (örneğin "yeniden bağlanılıyor", "mikrofon izni reddedildi"), bulunduğun odanın kimliği
- Yazdığın açıklama metni
Bu liste cihazında geçici olarak tutulur, uygulamayı kapattığında silinir ve bildirimi gönderdikten sonra temizlenir. Ses kaydı, konuşulanlar, IP adresin, konumun ve kişi listen gönderilmez. Bildirim bir destek talebi olarak açılır; yalnız yöneticiler teknik anlık görüntüyü görebilir — moderatörler göremez.
İsteğe bağlı bildirim verisi
- Kendi sunucumuzda FCM bildirim jetonu, cihaz platformu ve uygulama dili
- Google tarafında Firebase Installation ID (FID)
- Hesabına bağlı dört bildirim tercihi: doğrudan oda daveti, takip ettiğin kişinin herkese açık oda açması, konuşmacı daveti ve takip ettiğin kişinin herkese açık bir odaya katılması. Yalnız doğrudan oda daveti başlangıçta açıktır; diğer üçü kapalıdır ve her birini sonradan değiştirebilirsin. Yeni takipçi bildirimi yoktur
- Takip edilen kişinin herkese açık oda etkinliği için kendi sunucumuzdaki kısa ömürlü dağıtım kuyruğunda kişinin hesap kimliği, oda kimliği, aktif katılım kaydı ve teknik teslim durumu tutulur. Özel odalar bu kuyruğa hiç alınmaz
- Google'a genel bildirim metni ve yalnız opak yönlendirme alanları (teknik adları type, roomId ve tag) gönderilir. Takip edilen kişinin hesap kimliği veya adı, oda başlığı, e-posta ve ses gönderilmez
- Doğrudan oda daveti en fazla bir saat, konuşmacı daveti 60 saniye, takip edilen kişinin herkese açık oda etkinliği en fazla 15 dakika geçerlidir
Şehir, kesin konum, rehber, reklam kimliği, kişi bazlı analiz olayı veya izleme çerezi toplanmaz. Yukarıda açıklanan ülke kodu yalnız toplu katılım sayacı içindir ve kullanıcı profiline bağlanmaz. Firebase Analytics kapalıdır. Cihazındaki fotoğraf galerisi taranmaz veya okunmaz: yalnızca senin seçtiğin tek dosya işlenir ve o dosya da konum bilgisi silinerek gönderilir.
İsteğe bağlı kategoriler ve topluluklar
- Takip ettiğin kategori, katıldığın topluluk, sahiplik, ilişki zamanları, her ilişki için görünürlük ve topluluğa özel susturma tercihi hesabınla ilişkilendirilir. Kategori takibi, topluluk üyeliği ve kişi takibi ayrı işlemlerdir; biri diğerini otomatik oluşturmaz.
- Oluşturduğun topluluğun adı, açıklaması, kategorisi ve sahiplik bilgisi; sahiplik teklifinin tarafları, süresi ve sonucu işlenir.
- Bu seçimler, özellikle serbest topluluk adı/açıklamasıyla birlikte, siyasi görüş veya inanç gibi özel nitelikli bilgileri ortaya çıkarabilir. Üyelik tek başına belirli bir görüşe sahip olduğunun kanıtı sayılmaz.
- Ayrı rıza kaydında hesap, amaç sürümü, son kabul ve varsa geri çekme sunucu zamanı ile kayıt revizyonu tutulur. Bu kayıtta IP veya konum yoktur; bütün geçmiş kararların ayrı ayrı saklandığı bir günlük değildir.
- Topluluk kısıtları, üyelik engelleri ve itirazlarda kararın gerekçesi, zamanı, tarafları, başvuru/yanıt ve sonuç tutulur. Karar kanıtı, işlem anındaki topluluk adını ve bazı işlemlerde üyenin görünen adını içerebilir. Olağan kategori takipleri ve katılmalar moderasyon günlüğüne kopyalanmaz.
- Topluluk oda duyuruları ve topluluk güncellemeleri için mevcut dört bildirim tercihine iki ayrı tercih eklenir; ikisi de başlangıçta kapalıdır. Topluluğu susturma ve cihaz bildirim izni ayrıca uygulanır. Kendi sunucumuzdaki geçici kuyruk; topluluk, oda/olay, ilgili hesap ve teknik teslim bilgilerini tutar. Google FCM'ye genel bildirim metni ile teknik yönlendirme alanları gider; kategori/topluluk adı, üye listesi, e-posta, karar/itiraz gerekçesi veya ses gönderilmez.
3. Amaçlar ve hukuki sebepler
- Hesap, e-posta doğrulaması, varsa davet, kişiden kişiye takip ilişkileri, temel bildirim tercihleri, oda ve geçici ses iletimi; istediğin hizmeti kurmak ve sunmak için işlenir (KVKK md. 5/2-c; GDPR md. 6/1-b).
- Engelleme, şikâyet, yasak, askı ve güvenlik günlükleri; topluluğu korumak, kötüye kullanımı önlemek ve hukuki yükümlülükleri yerine getirmek için işlenir (KVKK md. 5/2-ç ve 5/2-f; GDPR md. 6/1-c ve 6/1-f). Meşru menfaat, kullanıcıların güvenli hizmet beklentisiyle sınırlı ve ölçülü uygulanır.
- Hukuki metin sürümü ve yaş beyanı; kabulü ve kayıt uygunluğunu kanıtlamak için tutulur (sözleşmenin kurulması ve hukuki yükümlülük).
- Kimlik taşımayan kullanım ve ülke toplamları; hizmetin hangi dönemlerde ve hangi ülkelerde kullanıldığını anlayıp kapasiteyi planlamak için meşru menfaat kapsamında işlenir (KVKK md. 5/2-f; GDPR md. 6/1-f). Şehir veya kişi profili çıkarılmaz ve küçük ülke grupları yönetim ekranında birleştirilir.
- FCM yalnız cihazın bildirim iznini verdiğinde etkinleşir. Bu veri, isteğe bağlı bildirimi sunmak için işlenir. İzni işletim sistemi ayarından geri almak bildirimin teslimini engeller; uygulama bunu bir sonraki denetimde görüp FCM'yi kapatır ve teknik tanımlayıcıların temizlenmesini ister. Geçici ağ veya platform hatası bu temizliği geciktirebilir.
- Hesap içindeki dört bildirim tercihi cihaz izninden ayrıdır. Bir kategoriyi kapatmak o türün gönderimini durdurur; diğer açık kategoriler çalışabilsin diye FCM jetonu sunucuda kayıtlı kalabilir.
E-posta, görünen ad, parola, e-posta doğrulaması, ayrı Kullanım Şartları kabulü ve 16+ beyanı hesap açmak için zorunludur. Davet kodu yalnız davetli kayıt modunda zorunludur; açık kayıt modunda istenmez. Tanıtım metni, konuşmacı olmak ve FCM bildirimi isteğe bağlıdır. Zorunlu veriler verilmezse hesap veya ilgili özellik sunulamaz.
Topluluk işlemleri için ayrı açık rıza. Kategori takiplerini, topluluk üyeliklerini ve sahipliğini hesabınla ilişkilendirerek keşif, Topluluklarım ve topluluk yönetimini sunmak, ortaya çıkabilecek hassas ilgi bilgileri dahil, isteğe bağlı ve ayrı açıklanmış işleme amacıdır. Bunun için açık rızan istenir; genel Kullanım Şartları kabulü veya bu metni okuman rıza yerine geçmez (GDPR md. 6/1-a ve özel nitelikli veri için md. 9; KVKK md. 5 ve 6 kapsamındaki açık rıza şartları).
Rıza vermemek veya geri çekmek normal hesabını ve bağımsız oda kullanımını engellemez; yalnız bu isteğe bağlı ilişkileri kurma/sürdürme işlevleri kullanılamaz. Görünürlük ve bildirim tercihleri rızadan ayrıdır. Mevcut bir hesabın olması da topluluk rızası sayılmaz.
Rıza kararının kanıtı, mevcut bir yaptırımın uygulanması ve itirazın incelenmesi ayrı amaçlardır; bunlara ait sınırlı kayıtlar aşağıdaki saklama kurallarına tabidir. Bu kayıtlar geri çekilen rızaya dayanarak keşif veya ilgi ilişkilerini sürdürmek için kullanılamaz. Hakların tesisi, kullanılması ve korunması için zorunlu kayıtlar bakımından KVKK md. 5/2-e ve GDPR md. 6/1-f; özel nitelikli veri söz konusuysa ayrıca md. 6 ve GDPR md. 9'daki uygulanabilir şartlar değerlendirilir. Rızanın geri çekilmesi, önceki rızaya dayalı işlemenin geçmişteki hukuka uygunluğunu etkilemez.
Seçtiğin ilgi ilişkileri yukarıdaki amaçla işlenir; bunlardan reklam profili veya otomatik hassas görüş çıkarımı yapılmaz. Hukuki ya da benzer önemli sonuç doğuran yalnızca otomatik karar verme yapılmaz; moderasyon kararlarını bir insan verir.
4. Kimler görür ve veri nerede işlenir
Ana PocketBase veritabanı ve canlı ses sunucusu Almanya'dadır. Giriş yapmış üyeler, hizmetin yapısı gereği görünen adını, tanıtımını, seçtiğin avatarı, varsa yüklediğin profil fotoğrafını, erişebildikleri oda bilgilerini ve o odadaki rolünü görebilir. E-posta ve parola diğer üyelere gösterilmez. Takip ilişkisini yalnız ilişkinin iki tarafı kendi takipçi veya takip edilen listesinde görür; bildirim tercihlerini ve geçici bildirim kuyruğunu diğer üyeler göremez. Hesap güvenlik olaylarını (giriş, başarısız giriş, parola işlemleri) yalnızca hesabın sahibi görür; bunlar diğer üyelere de, moderatörlere de gösterilmez. İtiraz ve destek yazışmalarını yalnızca sen ve talebi inceleme yetkisi olan yetkililer görür; kararı veren kişi kendi kararına yapılan itirazı inceleyemez — bunun mümkün olmadığı durumda incelemenin aynı kişi tarafından yapıldığı sana açıkça bildirilir. Yetkili yönetici; üyelik, güvenlik ve moderasyon için gerekli kayıtlara erişebilir. Kanunen zorunluysa yetkili makamlara gerekli veri verilebilir.
Topluluk görünürlüğü. Kişisel Topluluklarım listesi herkese açık değildir. Kategori/topluluk kişi dizinindeki görünürlüğün, sahip olsan bile, her ilişki için başlangıçta kapalıdır. Ayrı olarak açarsan, aynı kategori veya topluluğa katılan ve erişim şartlarını sağlayan kişiler profil özetini görebilir; iki yönlü engeller uygulanır. Kişi dizini e-posta veya platform kademesi göstermez. Keşfe açık topluluğun adı, açıklaması ve sahip bilgisi ise topluluk tanıtımının parçasıdır; üye dizinini gizlemek, oluşturduğun topluluğu veya sahipliğini gizli yapmaz.
Topluluk sahipliği, platform moderatörlüğü veya gizli üyelerin listesini görme yetkisi vermez. Yetkililer yalnız kendilerine tanımlanan topluluk işlemlerini yapabilir; teknik NOYGG Yönetimi daha geniş ve ayrı bir yönetim yüzeyidir. İtirazın ve karar ayrıntıların ilgili kişiye ve bunları incelemeye yetkili görevlilere açıktır; sahiplik tek başına başkasının itirazını okuma hakkı vermez. Yetkili veri dökümüne topluluk ilişkileri ve rıza kararı da girer; gerekçe ve işlem kaydı şartları sürer.
E-posta doğrulama, parola sıfırlama ve yeni konumdan giriş güvenlik bildirimleri yapılandırılmış posta hizmeti üzerinden gönderilir. E-posta adresini değiştirme işlemini başlatırsan değişiklik onayı; tek kullanımlık parola ile giriş özelliği etkinleştirilirse istediğin giriş kodu da aynı hizmetle gönderilir. Alıcı e-posta adresi, standart SMTP teslim bilgileri, ileti türü ve giriş bildiriminde yer alan güvenlik ayrıntıları yalnız bu iletileri ulaştırmak için posta hizmeti sağlayıcısı tarafından işlenebilir. Otomatik iletilerin gönderen adresi noreply@noygg.com, yardım kanalı support@noygg.com adresidir.
Verinin kopyasını isteme ve yetkili makam talebi. Bir kişinin verisi birden çok yerde tutulduğu için, talep hâlinde tamamı tek bir dökümde toplanır. Bu döküm yalnız yönetici tarafından alınabilir, yazılı gerekçe ister ve dökümün kendisi moderasyon işlem kaydına yazılır — yani kimin dökümünün ne zaman ve hangi gerekçeyle alındığı sonradan denetlenebilir. Döküm parola ya da oturum anahtarı içermez; bunlar hesabın kilididir, verin değildir.
Google Firebase Cloud Messaging. FCM otomatik başlatma ilk kurulumda kapalıdır. Yalnız güncel aydınlatma gösterildikten ve cihaz bildirim izni verildikten sonra jeton ile FID oluşturulur. İzin vermezsen uygulamanın temel işlevleri çalışır; arka plan sesi ve kapalıyken oda daveti bildirimi kısıtlanabilir.
FCM küresel Google altyapısıdır; veriler Google veya alt işleyenlerinin tesis bulundurduğu ülkelerde işlenebilir. Almanya'daki ana sunucu, FCM verisini Almanya ile sınırlamaz. Google, müşteri verisi için genel olarak veri işleyen olduğunu; kısıtlı Avrupa aktarımlarında geçerli aktarım çözümü ve gerektiğinde standart sözleşme maddeleri kullandığını belirtir. Google ayrıca hizmetin işletilmesi sırasında oluşan hizmet verisini kendi şartları kapsamında işler. Aktarım güvenceleri hakkında bilgi support@noygg.com adresinden istenebilir.
5. Saklama ve hesap silme
- E-posta adresini doğrulamayan yeni hesap ve onunla ilişkilendirilmiş kayıt kanıtları en geç 7 gün sonra otomatik silinir. Davetli modda kullanılmış bir kod yeniden kullanıma açılmaz; ancak hesap gerçek üyeye dönüşmediği için davet sahibinin harcanan hakkı geri verilir.
- Aktif oda katılım kaydı ayrılınca, oda kapanınca veya sunucu uzlaştırmasıyla silinir. Ses içeriği baştan kaydedilmez.
- Günlük tekil istatistik kimliği ertesi günlük temizlikte silinir; kişi içermeyen günlük ve ülke bazlı toplu sayaçlar kalabilir.
- Kapanmış oda üst verisi ve davet kayıtları için sabit otomatik silme süresi yoktur; hesap açıkken hizmet, güvenlik ve inceleme amacı sürdüğü ölçüde tutulur. Aşağıda belirtilen özel saklama süreleri ve silme kuralları önceliklidir.
- Teknik günlükler otomatik silinir. Sunucu isteklerinin günlüğü (bağlantı IP adresi ve hesap kimliğini içerir) en çok 5 gün, web sunucusu erişim günlüğü (IP ve istenen adres) en çok 14 gün, işletim sistemi günlüğü (başarısız giriş denemelerinin kaynak adresi dahil) en çok 30 gün tutulur. Canlı ses sunucusunun günlüğü süreyle değil boyutla sınırlıdır ve yalnızca yerel ağ adreslerini içerir. Bu süreler hizmetin işletilmesi ve kötüye kullanımın tespiti için gereken en az ölçüdür.
- Hesap güvenlik olaylarında ayrıca cihaz sınıfı tutulur: girişin uygulamadan mı tarayıcıdan mı geldiği ve tarayıcı ailesi (örneğin “NOYGG uygulaması (Android)” ya da “Chrome”). Bu kaba bir etikettir; tarayıcının gönderdiği ayrıntılı tanıtım dizesi (sürüm, cihaz modeli) saklanmaz. Amacı tek: “Hesap güvenliği” ekranında bir girişi tanıyıp tanımadığını anlayabilmen. Konum bilgisi çıkarılmaz ve tutulmaz.
- Hesap güvenlik olaylarında iki ayrı süre işler: olayın IP adresi 30 gün sonra silinir, olayın kendisi (türü ve zamanı) 365 gün tutulur. Kısa süre kaba kuvvet incelemesi için, uzun süre "hesabıma ne oldu" sorusunu cevaplayabilmen içindir. Hesabını sildiğinde bu kayıtların tamamı seninle birlikte silinir — bunlar senin verin ve tek okuyucusu sensin.
- Hesap yaptırımı itirazları ve destek yazışmaları (topluluk itirazları için bkz. 5.1) hesabın açık olduğu sürece tutulur ve hesabını sildiğinde tamamen silinir — bunlar senin yazışmandır. Yalnızca itirazın SONUCU (hangi karara itiraz edildi, korundu mu geri mi alındı) moderasyon işlem kaydında aşağıdaki süre boyunca kalır; o kayıt yetkililerin denetlenmesi içindir.
- Yetkili kademesi hesap kaydının bir parçasıdır; hesap silinince o da silinir. Yetki verme/alma işleminin kaydı moderasyon işlem kaydında kalır.
- Moderasyon işlem kaydı 365 gün tutulur ve süresi dolan kayıtlar otomatik silinir. Bu süre, bir karara itiraz edilebilmesi ve yetki kullanımının denetlenebilmesi için gereken en az ölçüdür.
- Hesabını silsen de moderasyon işlem kaydı kalır (yukarıdaki 365 gün boyunca): hakkında uygulanan yaptırımın türü, kategorisi, zamanı ve işlemi yapan yetkilinin kimliği. Sebebi şudur — bu kayıt yetkililerin denetlenmesi içindir ve hesap silinerek yok edilebilseydi bir yetkili kendi işlem geçmişini silebilirdi. Kimlik bağı teknik kimlik içerir; ancak özellikle topluluk işlemlerinde karar anındaki ad veya gerekçe de tutulabilir. Dolayısıyla kalan kaydın tamamen anonim olduğu söylenemez (bkz. 5.1).
- Şikâyetler için sabit otomatik son kullanma süresi yoktur. Şikâyetin iki tarafından biri hesabını sildiğinde ilgili şikâyet satırı, notu ve bağlamı tamamen silinir; takma adlı arşiv, vaka özeti veya sayaç tutulmaz.
- Takip ilişkisi, takipten çıkıldığında silinir. Taraflardan biri diğerini engellediğinde iki yöndeki takip de aynı işlemde kaldırılır. Hesap silinince o hesabın bütün takip ilişkileri ve bildirim tercihleri silinir.
- Takip edilen kişinin herkese açık oda etkinliği için açılan geçici dağıtım kaydı; işlendiğinde, geçersiz hâle geldiğinde veya en geç 15 dakikalık penceresi dolduğunda silinir. Özel oda etkinliği için böyle bir kayıt baştan oluşturulmaz.
- Çıkışta, işletim sistemi bildirim izni geri alındığında, hesap silindiğinde veya Google jetonu geçersiz bildirdiğinde istemci FCM'yi kapatır; kendi sunucumuzdaki bildirim jetonunun ve FID'nin silinmesini ister. Tek tek hesap bildirim tercihlerini kapatmak bu teknik tanımlayıcıları silmez. Her temizleme adımı ayrı yürütülür; geçici ağ veya platform hatası işlemi sonraki uygun denemeye kadar geciktirebilir. Google, FID silme isteğinden sonra FID'nin canlı ve yedek sistemlerden kaldırılmasının 180 güne kadar sürebileceğini belirtir.
Hesabı silme. Ayarlar → Hesabımı sil onaylandığında oturum erişimi hemen kesilir. Ana veritabanı temizliği normalde aynı işlemde tamamlanır; geçici bir veritabanı hatasında hesap kilitli kalır ve dakikalık görev temizliği yeniden dener. Sahibi olduğun bütün odalar kapanır, rastgele bir kişiye devredilmez. Canlı ses sunucusundaki oda ve yetki temizliği ana silme kararından sonra arka planda tamamlanabilir.
Depoda doğrulanmış sabit bir yedek silme süresi bulunmadığı için “7 günde tüm yedeklerden silinir” sözü verilmez. Güncel yedek yaşam döngüsü bilgisi support@noygg.com adresinden istenebilir.
5.1. Topluluklar: geri çekme ve ayrı saklama süreleri
Ayarlar → Topluluk gizlilik tercihleri → Rızamı geri çek yolunu kullanabilirsin. Başarılı geri çekmede kategori takiplerin, topluluk üyeliklerin, tarafı olduğun devirler, hesabına bağlı topluluk bildirim kuyruğu/tekrar önleme kayıtları ve topluluk bildirim tercihlerin silinir. Sahiplik bağın kaldırılır; topluluk hemen sahipsiz ve keşfe kapalı olur. Hesabın, oturumun, mevcut odaların ve ses bağlantın kapanmaz. Yeniden rıza vermek eski üyelikleri veya sahipliği geri getirmez.
- Takibi bırakmak/ayrılmak yalnız ilgili ilişkiyi kaldırır. Görünürlüğü kapatmak yalnız kişi dizininde gösterimi durdurur; üyeliği silmez.
- Son rıza kararının sürümü/zamanı ve revizyonu hesap silinene kadar tutulur; geri çekmek bu son karar kanıtını silmez.
- 30 gün sahipsiz kalan topluluğun ad/açıklaması, bağlı üyelikleri, devirleri ve geçici bildirim kayıtları temizlik kapsamına girer. Ad, kişisel olmayan sabit bir kaldırılma etiketiyle değiştirilir. Mevcut odaların değişmez bağlantısını koruyan erişime kapalı teknik kayıt kalır; odalar sırf bu nedenle silinmez veya kapatılmaz. Bu sürede yetkili kurtarma teklifi ve yeni sahibin açık kabulüyle sahiplenilirse sahipsiz içerik temizliği uygulanmaz. Eski sahibin rızası veya üyeliği geri kurulmaz.
- Bu 30 günlük kural hesap silinmesiyle sahipsiz kalan topluluğa da uygulanır. Hesap silme, geri çekmeden farklı olarak hesabı ve kişinin hâlen sahibi olduğu odaları kapatır. Sahipsizliğin başladığı an bilinmeyen eski kayıtlarda süre teknik geçişten başlar; geçmiş bir tarih varsayılmaz.
- Sahiplik teklifi 24 saat sonra kabul edilemez; bakımda temizlenir. Topluluk oda duyurusu 15 dakika, diğer topluluk güncellemesi 24 saat sonra gönderilemez. Tekrar önleme kaydı 10 dakika sürer; işlenen/geçersiz kuyruk kayıtları temizlenir.
- Topluluk üyelik engeli kaldırılınca veya hedef hesap/topluluk silinince aktif engel kaydı silinir. Aktör hesabı silinirse aktör bağı boşaltılır. Aktif engelin yaşa bağlı otomatik silme süresi yoktur.
- Topluluk itirazları başvuran hesap/topluluk silinince silinir. Sonuçlanan başvurular sonuçtan 365 gün sonra temizlenir; açık başvurular bu süre nedeniyle silinmez. Karar veren/inceleyen hesabın silinmesi ilgili kimlik bağını kaldırır.
- Moderasyon işlem kayıtları 365 gün kuralını izler. Rızayı geri çekmek veya sahipsiz topluluğun adını temizlemek, önceki kararın kanıtını, aktif engeli veya itirazı kendiliğinden silmez. Bu kayıtlar eski topluluk/üye adını ya da yazılmış gerekçeyi içerebilir; tamamı anonim değildir. Ayrı saklama, ilgi takibine devam etmek için kullanılamaz.
- Sürenin dolmasıyla fiziksel silme aynı an olmak zorunda değildir. Dakikalık bakım sahipsiz içerikte en fazla 100, sonuçlanan itirazlarda 200 kayıt işler; yoğunluk veya arıza silmeyi geciktirebilir. Süresi dolmuş teklif kabul edilmez ve bildirim gönderilmez. Erişilemez teknik kayıt, topluluğun tamamen silinmesi değildir. Yedekler için yukarıdaki ayrı açıklama geçerlidir.
6. Hakların
KVKK md. 11 ve uygulanabildiği ölçüde GDPR md. 15-21 kapsamında verine erişme, kopya alma, düzeltme, silme, işlemeyi kısıtlama, taşınabilirlik ve itiraz haklarına sahipsin. Bir işlem rızaya dayanıyorsa rızanı ileriye etkili olarak geri çekebilirsin. Ayrıca yetkili veri koruma makamına şikâyette bulunabilirsin.
Talebini support@noygg.com adresine gönder. Kimliğini ve başkasının verisini korumak için makul doğrulama istenebilir. Hesabın için en doğrudan silme yolu: Ayarlar → Hesabımı sil.
7. Çocuklar
Hizmet 16 yaşından küçükler için değildir. Kayıtta doğum tarihi değil, 16 yaşını doldurduğuna ilişkin ayrı bir beyan alınır. 16 yaşından küçük birine ait olduğunu öğrendiğimiz hesap silinir.
8. Değişiklikler
Önemli bir değişiklikte yeni metin kullanım öncesi gösterilir ve yalnızca okuyup bilgi edindiğin beyanı alınır. Gizlilik metnini “kabul etmen” istenmez; gerekli ayrı bir rıza varsa kendi amacıyla ayrı sunulur.
9. İletişim
Veri koruma talepleri ve sorular için: support@noygg.com
Privacy Policy and Notice
Version: 3.1 — Effective: 10 September 2026
This is the privacy notice required by KVKK art. 10 and GDPR art. 13. It explains what personal data NOYGG processes and why. It is shown before your email, display name, password and, where the registration mode requires one, invite code are sent to the server.
“I have read and understood” only records that the notice was provided; it is not consent and not acceptance of the Terms of Use. Acceptance of the Terms and the declaration that you are 16 or older are collected separately.
The data controller is the individual who operates the NOYGG service. Requests and contact: support@noygg.com
1. How audio is processed
Room audio is relayed in real time to the other participants through our own LiveKit server in Germany. Audio is processed transiently for that delivery, but it is not recorded, written to a file or available for replay. The app has no recording, transcript or replay feature. Audio is not sent to Google Firebase.
In the Android app, while the room screen is open, screenshots and screen recording are blocked and room audio is marked as not capturable by other apps on the same phone. These measures make recording harder but cannot prevent a second device from recording, and they cannot be applied where the operating system offers no such protection. Recording or sharing without permission is prohibited by the Terms and can be reported.
2. Categories of data processed
Account and registration
- Email address, whether that address has been verified, password verification data rather than a readable plain-text password, display name, and optional bio
- Optional avatar choice: which of the built-in illustrations you picked. The choice is a number, not an image; the illustrations ship with the app. If you pick none, your initials are shown
- Optional profile picture: a single square image file, if you choose to upload one. The photo is cropped, scaled to 512×512 pixels and re-encoded on your own device; all EXIF data, including location, is removed and the original file is never sent to the server. The server enforces the same rules and refuses a file that is too large or still carries hidden data. Uploading a picture is never required and you can remove it at any time
- When invited registration is enabled, the membership invite code and the account that invited you; when invite creation is enabled, the status of invites you create
- The short-lived, single-use verification link sent to the email address for a new account. The account remains inactive until the link is used
- Accepted Terms version and server timestamp
- Privacy notice version, language and server timestamp recording that it was read and understood
- 16+ declaration and server timestamp; no date of birth is requested
Rooms and safety
- Room title, public/private status, owner, and opening and closing times
- Participant, role, raised-hand and stage-invite state in an active room
- Private-room invites, blocks, removals and room bans
- Follow relationships: the accounts you follow and the accounts that follow you. These lists are not a public discovery directory; only the parties to the relationship see them in their own Followers and Following screens
- The private room's share-link key (deleted when the owner cancels or renews it; it stops working when the room closes and is deleted together with the room record; joining through the link is stored as an invite record)
- Parties to a report, room, reason, optional note, review status and action
- Measure type (suspension or partial restriction), its duration, category and administrator reason
- Moderation action log: actions taken by staff are recorded — applying and lifting a measure, changing someone's role, changing a tier definition, changing a platform setting, changing an invite quota, a staff member closing a room, a justified room lookup, and taking a person export. Each entry holds the identity and role of the staff member who acted, the target, the type, category, duration and time of the action. This log covers everyone, administrators included, and cannot be altered afterwards; where a correction is needed the original entry is not deleted, a new entry is written beside it. Its purpose is to make decisions auditable and to detect misuse of authority.
Staff access to rooms
- When staff access a private room, we record: the staff member's identity and level, the room, the reason category and the written reason, when the grant and actual entry started, when the limited hidden period ended and the staff member became visible, the moment calculated for the in-room notice to appear and the moment it actually appeared, and whether the room owner was notified
- This record covers everyone including administrators and cannot be altered afterwards
- Only after actually joining a private room, the staff member may be hidden from other participants for an initial period set by administrators and limited to 15 minutes. If still in the room when it ends, the staff member becomes visible. The notice delay starts from that visibility time
- If the staff member leaves before the notice appears, a “staff is in this room” notice is not shown afterwards. After a real entry, the room owner receives one past-tense notification that staff were present; a grant that was never used sends no notification. The notification contains no room title
- What is said in the room is not recorded. Access does not mean audio is captured or stored; the staff member joins like any other participant and audio is only relayed live
Authorisation and requests
- If your account has been given a staff level (for example moderator), that is stored on the account record. Your level is visible only to you and to the administrator who grants roles; it is not shown to other members
- Granting or removing a role is written to the moderation action log together with who did it
- Appeals and support requests: the type (appeal/support), subject, the messages you write and the staff replies; for an appeal, which measure it concerns and its outcome (upheld / reversed)
- The identity of the staff member reviewing your appeal is not shown to you; you only see that it was staff
- The outcome of an appeal is also written to the moderation action log, separately from the conversation
Account security events
- The following events on your own account are recorded: sign-in, failed sign-in attempt, password change, password reset and sign-out of all devices
- Each event stores its time and the IP address the request came from
- In the app only you can see these records (Settings → Account security) and they are shown masked: the last part of the address is removed and the full address is never sent to the app. Moderators cannot see them. Two situations are exceptions and both are recorded: you asking for a copy of your own data, and a legally binding request
- A sign-in attempt using an email address that does not exist is not recorded, so these records cannot be used to test whether an address is registered
- Their purpose is to let you see whether anyone else has accessed your account, and to let us detect brute-force attempts
Technical records and statistics
- Connection IP address, request time, path and status, and where needed account or room identifiers in error and security logs
- Daily totals: rooms opened, room joins, room invites sent, new members, membership invite codes issued, total time spent in rooms and reports opened. These numbers carry no identity
- To count daily unique users an identifier is kept for that day only and deleted overnight; after that only the aggregate remains
- When a new room join occurs, the connection IP address is resolved only to a two-letter country code using a country database on our own server. The statistics table receives only day + country code + join count; it does not receive the IP address, account or room id, city, coordinates or precise location. Country groups below 5 are not shown separately in the statistics view and are merged into “Other”. VPNs and mobile gateways can make the country estimate inaccurate. Resolution is local and the IP is not sent to another service for this purpose
Problem reports (only when you send one)
If you run into a connection or audio problem, you can send a technical snapshot using Report a problem. This is not collected passively: it is sent only when you press the button, and only after you have seen every line that will be sent on screen.
- Your device's manufacturer, model and Android version
- A list of recent technical events: event codes and their times only (for example "reconnecting", "microphone permission denied"), and the id of the room you were in
- The description you write
The list is kept temporarily on your device, is erased when you close the app, and is cleared after you send a report. Audio recordings, what was said, your IP address, your location and your contacts are not sent. The report opens as a support request; only administrators can see the technical snapshot — moderators cannot.
Optional notification data
- On our server, the FCM registration token, device platform and app language
- At Google, a Firebase Installation ID (FID)
- Four account-bound notification preferences: a direct room invitation, a person you follow starting a public room, a speaker invitation, and a person you follow joining a public room. Only direct room invitations are enabled initially; the other three are off, and you can change each one later. There is no new-follower notification
- For public-room activity by a person you follow, our server's short-lived delivery queue holds that person's account id, the room id, the active participant record and technical delivery state. Private rooms never enter this queue
- Google receives generic notification text and only opaque routing fields (technical names type, roomId and tag). The followed person's account id or name, room title, email and audio are not sent
- A direct room invitation is valid for at most one hour, a speaker invitation for 60 seconds, and followed public-room activity for at most 15 minutes
We do not collect city or precise location, contacts, an advertising identifier, person-level analytics events or tracking cookies. The country code described above is used only for an aggregate join counter and is not linked to a user profile. Firebase Analytics is disabled. Your photo gallery is never scanned or read: only the single file you pick is processed, and it is sent with its location data stripped.
Optional categories and communities
- Categories you follow, community memberships, ownership, relationship timestamps, visibility for each relationship and per-community muting are linked to your account. Following a category, joining a community and following a person are separate actions; none automatically creates another.
- A community you create has a name, description, category and ownership information. Ownership offers include their parties, expiry and outcome.
- These choices, especially alongside free-text community names and descriptions, may reveal sensitive information such as political opinions or beliefs. Membership alone is not proof of a particular view.
- The separate consent record contains the account, purpose version, last acceptance and any withdrawal server timestamps, and record revision. It contains no IP address or location and is not a complete history of every previous consent decision.
- Community restrictions, membership bans and appeals hold grounds, times, parties, submissions/responses and outcomes. Decision evidence may include the community name and, for some actions, the member's display name at the time. Ordinary category follows and joins are not copied into the audit log.
- Community room announcements and community updates add two separate notification preferences to the existing four; both start off. Per-community muting and device permission apply separately. Our temporary delivery queue holds community, room/event, related account and technical delivery details. Google FCM receives generic text and technical routing fields, not category/community names, member lists, email, decision/appeal reasons or audio.
3. Purposes and legal bases
- Account, email verification, any applicable invite, person-to-person follow relationships, basic notification preferences, room and transient audio processing is necessary to set up and provide the service you request (KVKK art. 5(2)(c); GDPR art. 6(1)(b)).
- Blocks, reports, bans, suspensions and security logs protect the community, prevent abuse and meet legal duties (KVKK art. 5(2)(ç) and 5(2)(f); GDPR art. 6(1)(c) and 6(1)(f)). Legitimate interests are applied proportionately and balanced against users' rights and safety expectations.
- Legal-document versions and the age declaration are kept to prove account eligibility and the contractual record (contract performance and legal obligations).
- Non-identifying usage and country totals are processed under legitimate interests to understand when and from which countries the service is used and to plan capacity (KVKK art. 5(2)(f); GDPR art. 6(1)(f)). No city or person profile is created, and small country groups are merged in the management view.
- FCM is enabled only after you grant the device notification permission. The data is processed to provide that optional feature. Revoking permission in the operating-system settings blocks delivery; when the app next checks the permission, it disables FCM and requests cleanup of the technical identifiers. A temporary network or platform error may delay that cleanup.
- The four in-account notification preferences are separate from the device permission. Turning off one category stops that type of message; the FCM token may remain registered so that other enabled categories can work.
An email, display name, password, email verification, separate acceptance of the Terms and the 16+ declaration are required to create an account. An invite code is required only in invited-registration mode and is not requested in open-registration mode. A bio, speaking in a room and FCM notifications are optional. If required data is not provided, the account or relevant feature cannot be provided.
Separate explicit consent for community processing. Linking your category follows, community memberships and ownership to your account to provide discovery, My communities and community management, including sensitive interests those choices may reveal, is an optional, separately explained purpose. We ask for explicit consent; accepting the general Terms or reading this notice is not consent (GDPR art. 6(1)(a), and art. 9 for special-category data; the explicit-consent conditions in KVKK arts. 5 and 6).
Declining or withdrawing consent does not prevent normal account use or independent room use; only the optional functions that create or maintain these relationships become unavailable. Visibility and notification choices are separate from consent. Having an existing account is not community consent.
Evidence of the consent decision, enforcing an existing measure and reviewing an appeal serve separate purposes, with limited records subject to the retention rules below. Those records cannot be used to continue discovery or interest relationships based on withdrawn consent. Where records are necessary to establish, exercise or defend rights, KVKK art. 5(2)(e) and GDPR art. 6(1)(f) are considered; special-category data additionally requires an applicable condition under KVKK art. 6 and GDPR art. 9. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
Your chosen interest relationships are processed for the purpose above, not to create advertising profiles or automatically infer sensitive views. There is no solely automated decision-making with legal or similarly significant effects; a human makes moderation decisions.
4. Who sees data and where it is processed
The primary PocketBase database and live-audio server are in Germany. Authenticated members can see your display name, bio, the avatar you chose, your profile picture if you uploaded one, rooms they are allowed to access and your role in those rooms as needed for the service. Your email and password are not shown to other members. A follow relationship is visible only to its two parties in their own follower or following list; other members cannot see your notification preferences or the temporary delivery queue. Account security events (sign-ins, failed sign-ins, password activity) are visible to the account holder only — not to other members and not to moderators. Appeal and support conversations are visible to you and to staff authorised to review them; whoever made a decision cannot review the appeal against it — where that is not possible, you are told plainly that the review was carried out by the same person. An authorised administrator can access records needed for membership, security and moderation. Data may be provided to competent authorities where legally required.
Community visibility. Your personal My communities list is not public. Visibility in each category/community people directory starts off, including for owners. If you enable it separately, people who have joined the same category or community and meet the access conditions can see your profile summary; blocks in both directions apply. The directory does not show email addresses or platform tiers. A discoverable community's name, description and owner information are part of its presentation; hiding your directory membership does not make a community you create or its ownership private.
Community ownership does not grant platform moderation powers or access to hidden membership lists. Staff may perform only the community actions assigned to them; technical NOYGG Management is a separate, broader administration surface. Appeal and decision details are available to the affected person and authorised reviewers; ownership alone does not allow reading somebody else's appeal. Authorised data exports include community relationships and the consent decision, with the existing reason and audit requirements.
Email-verification, password-reset and new-location sign-in security notices are sent through the configured mail service. If you start an email-address change, its confirmation message is sent through the same service; if one-time-password sign-in is enabled, so is the sign-in code you request. The recipient address, standard SMTP delivery information, message type and the security details included in a sign-in notice may be processed by the mail-service provider solely to deliver those messages. The sender for automated messages is noreply@noygg.com and the support channel is support@noygg.com.
Requesting a copy of your data, and lawful requests. Because a person's data is held in more than one place, on request all of it is gathered into a single export. Only an administrator can produce that export, it requires a written reason, and the export itself is written to the moderation audit log — so whose data was exported, when, and on what grounds can be audited afterwards. The export never contains passwords or session keys; those are the lock on your account, not your data.
Google Firebase Cloud Messaging. FCM automatic initialisation is off on a fresh install. A token and FID are created only after the current notice has been shown and the device notification permission is granted. If you decline, the app's core functions still work; background audio and room invite notifications while the app is closed may be limited.
FCM uses Google's global infrastructure, and data may be processed in any country where Google or its subprocessors maintain facilities. Hosting the primary server in Germany does not confine FCM data to Germany. Google states that it generally acts as processor for customer data and uses a valid data transfer solution and, where needed, Standard Contractual Clauses for restricted European transfers. Google separately processes service data under its own terms. Information about transfer safeguards can be requested at support@noygg.com.
5. Retention and account deletion
- A new account that does not verify its email address, together with its associated registration evidence, is deleted automatically after no more than 7 days. In invited-registration mode, a consumed code is not made reusable; because the account never became a member, the inviter's spent allowance is returned.
- An active room-participation record is removed when you leave, the room closes or server reconciliation completes. Audio content is never recorded.
- The identifier used for the daily unique-user count is cleared by the next daily purge; non-personal daily and country aggregate counts may remain.
- There is no fixed automated expiry for closed-room metadata and invitations; while an account is active, they are kept only for as long as the service, security and review purpose continues. Specific retention periods and deletion rules below take precedence.
- Technical logs are deleted automatically. The server request log (which contains the connection IP address and the account identifier) is kept for at most 5 days, the web server access log (IP and requested path) for at most 14 days, and the operating system log (including source addresses of failed sign-in attempts) for at most 30 days. The live-audio server's log is capped by size rather than time and contains only local network addresses. These periods are the minimum needed to operate the service and detect abuse.
- Account security events also record a device class: whether the sign-in came from the app or a browser, and the browser family (for example "NOYGG app (Android)" or "Chrome"). This is a coarse label; the detailed identification string the browser sends (version, device model) is not stored. Its only purpose is to let you recognise a sign-in on the "Account security" screen. No location is inferred or kept.
- Account security events run on two clocks: the IP address of an event is deleted after 30 days, while the event itself (its type and time) is kept for 365 days. The short period serves brute-force investigation, the long one lets you answer "what happened to my account". Deleting your account deletes all of these records with it — they are your data and you are their only reader.
- Account-sanction appeals and support conversations (see 5.1 for community appeals) are kept while your account exists and are deleted completely when you delete your account — they are your correspondence. Only the OUTCOME of an appeal (which decision it concerned, upheld or reversed) remains in the moderation action log for the period below; that log exists to hold staff accountable.
- Your staff level is part of the account record and is deleted with the account. The record of granting or removing a role remains in the moderation action log.
- The moderation action log is kept for 365 days and expired entries are deleted automatically. This period is the minimum needed for a decision to be appealed and for the use of authority to be audited.
- The moderation action log survives account deletion (for the 365 days above): the type, category and time of the measure applied to you and the identity of the staff member who acted. The reason is that this log exists to hold staff accountable, and if deleting an account erased it a staff member could erase their own history. The identity link includes a technical identifier, but particularly for community actions the name or reason at the time may also be retained. The remaining record therefore cannot be described as entirely anonymous (see 5.1).
- Reports have no fixed automatic expiry. If either person involved deletes their account, the report row, note and context are erased completely; no pseudonymous archive, case summary or counter is retained.
- A follow relationship is deleted when either person unfollows. If either person blocks the other, follows in both directions are removed in the same operation. Deleting an account deletes all its follow relationships and notification preferences.
- A temporary delivery record for followed public-room activity is deleted when processed, when it becomes ineligible, or no later than the end of its 15-minute window. No such record is created for private-room activity.
- When you sign out, revoke the operating-system notification permission, delete the account, or Google marks the token invalid, the client disables FCM and requests deletion of both the registration token on our server and the FID. Turning individual account notification preferences off does not delete those technical identifiers. Each cleanup step runs independently; a temporary network or platform error may delay it until the next suitable attempt. Google states that after an FID deletion request, removal from its live and backup systems may take up to 180 days.
Deleting the account. Once you confirm Settings → Delete my account, access to the account ends immediately. Primary database cleanup normally finishes in the same operation; if a temporary database error occurs, the account remains locked and a scheduled task retries the cleanup every minute. Every room you own closes and is not transferred to a random participant. Room and permission cleanup on the live-audio server may finish in the background after the primary deletion decision.
The repository does not evidence a fixed backup-erasure period, so no promise that every backup is cleared “within 7 days” is made. You may request the current backup lifecycle at support@noygg.com.
5.1. Communities: withdrawal and separate retention periods
Use Settings → Community privacy preferences → Withdraw my consent. A successful withdrawal deletes your category follows, community memberships, transfers involving you, account-linked community delivery/cooldown records and community notification preferences. Your ownership link is removed; the community immediately becomes ownerless and undiscoverable. Your account, session, existing rooms and audio connection stay open. Consenting again does not restore old memberships or ownership.
- Unfollowing/leaving removes only that relationship. Hiding your membership only stops its directory display and does not delete the membership.
- The last consent decision's version/timestamps and revision remain until account deletion; withdrawal does not erase that last decision evidence.
- Once a community has been ownerless for 30 days, its name/description, memberships, transfers and temporary notification records become eligible for cleanup. Its name is replaced with a fixed, non-personal removal label. An inaccessible technical record remains to preserve existing rooms' immutable links; those rooms are not deleted or closed solely by this cleanup. If an authorised recovery offer and the new owner's explicit acceptance restore ownership during that period, ownerless-content cleanup does not apply. The previous owner's consent or membership is not restored.
- The same 30-day rule applies to communities left ownerless by account deletion. Unlike withdrawal, account deletion closes the account and rooms the person still owns. Older records without a known ownership loss date receive the period from the technical transition; no earlier date is assumed.
- An ownership offer cannot be accepted after 24 hours and is cleaned by maintenance. Community room announcements cannot be sent after 15 minutes, other community updates after 24 hours. Cooldowns last 10 minutes; processed/ineligible queue records are cleaned up.
- An active community membership ban is deleted when lifted or when the target account/community is deleted. Deleting the actor's account clears the actor link. Active bans have no automatic age-based expiry.
- Community appeals are deleted when the applicant account/community is deleted. Resolved submissions are cleaned 365 days after resolution; open submissions are not deleted just because that period passes. Deleting an issuer/reviewer account clears the corresponding identity link.
- Moderation audit records follow the 365-day rule. Withdrawal or cleanup of an ownerless community's name does not itself erase previous decision evidence, an active ban or an appeal. Records may contain a former community/member name or a written reason; they are not all anonymous. Separate retention must not be used to continue tracking interests.
- Expiry and physical deletion need not happen at the same instant. Minute-based maintenance processes at most 100 ownerless communities or 200 resolved appeals per run; backlog or failures can delay deletion. Expired offers cannot be accepted and expired messages cannot be sent. An inaccessible technical record is not complete community deletion. The separate backup explanation above still applies.
6. Your rights
Under KVKK art. 11 and, where applicable, GDPR arts. 15-21, you may request access, a copy, correction, erasure, restriction, portability, or object to processing. Where processing relies on consent, you may withdraw it for the future. You may also complain to the competent data protection authority.
Send a request to support@noygg.com. Reasonable verification may be required to protect your data and other people's data. The direct account deletion path is Settings → Delete my account.
7. Children
The service is not for anyone under 16. Registration asks for a separate declaration that you are at least 16, not a date of birth. If we learn that an account belongs to someone under 16, it is deleted.
8. Changes
If this notice changes materially, the new version is shown before further use and you are asked only to confirm that you have read and understood it. You are not asked to “accept” a privacy notice; any consent that is actually required is presented separately for its specific purpose.
9. Contact
Privacy requests and questions: support@noygg.com