Before publishing
Fill in every bracketed field ([company name], [full address], [Supabase region]). Have the text reviewed by a lawyer, and make sure it matches your Google Play Console Data Safety declaration exactly — a mismatch will get the app rejected.
1. Who we are
IO Planner and ioplanner.com.tr are operated by [company name] ("we", "us"), the data controller.
2. Summary
- Using the app requires an account; we collect your email address and name.
- Your tasks, projects and goals stay on your device only — they are never sent to our servers.
- We show no ads, collect no advertising identifiers, and never sell your data.
- Your data is hosted on Supabase.
- You can request deletion of your account and all data at any time.
3. Account data (Supabase Auth)
We use Supabase Auth for authentication. When you create an account or sign in, we process:
- Email address — to identify your account, let you sign in, reset your password and send essential service notices. Required.
- Name / display name — to address you in the app and, where team features are used, to identify you to your colleagues. Required.
- Password — never stored in plain text. Supabase stores a one-way hash (bcrypt); we cannot see your password.
- Session and authentication records — session tokens, last sign-in time, account creation date and the IP address used at sign-in, for security and abuse prevention.
If you choose to sign in with a social account (Google, Apple), that provider shares only your email address and name with us. We do not access your contacts, posts or any other data held by the provider.
4. Task and content data
The task titles, descriptions, notes, goals, dates, project and label names you enter belong to you.
- This content is stored only in a local database on your device. It is never sent to our servers and we hold no copy of it.
- We cannot see your content, so reading, analysing or profiling it is not even technically possible for us.
- Uninstalling the app deletes this data too. To keep it, export it as
.json first via Settings → Data → Export.
- Content does not move automatically when you change devices; you import the export file on the new device.
5. Technical and usage data
- Device and app information — operating system version, app version, device model, to diagnose compatibility problems.
- Crash reports — technical diagnostics sent only when you approve. They never contain your task content.
- Server access logs — IP address, request time and requested resource, kept for security and troubleshooting.
What we never collect: advertising identifiers (GAID/IDFA), location data, contacts, photo library, microphone, search history, installed app lists or biometric data. The app contains no third-party ad network and no behavioural analytics SDK (no Google Analytics, no Facebook SDK).
6. Website and contact form
ioplanner.com.tr runs no analytics tool, advertising pixel or social media tracker. See our cookie policy for details.
When you use the contact or business enquiry form we process your name, email address, optional phone number and company, chosen subject, message content, submission time and IP address. This is used solely to reply to you; it is never added to a mailing list or used for marketing.
7. Purposes and legal bases
- Providing the service (account creation, sign-in, syncing your data) — performance of a contract.
- Security and abuse prevention (session records, IP, rate limiting) — legitimate interests.
- Handling support requests — at your request, performance of a contract.
- Essential service notices (security alerts, changes to terms) — legal obligation and legitimate interests.
- Legal compliance (financial records, lawful authority requests) — legal obligation.
- Optional notifications (new release announcements) — your consent, withdrawable at any time.
8. Who we share data with
We do not sell, rent or share your data for marketing. Data is shared only with the providers needed to run the service, and only as far as necessary:
- Supabase Inc. — authentication and account database. Data processed: name, email address, password hash, session records and subscription status. Your task and content data is never sent to Supabase. Supabase privacy policy
- [your hosting provider] — website and email infrastructure. Data processed: form messages, server access logs.
- Google Play / App Store — app distribution and payments, subject to their own privacy policies. Your payment card details never reach us.
We may also disclose data where legally required, on a valid request from a competent authority. In the event of a merger or acquisition, data may transfer to the acquiring entity; you would be informed beforehand.
9. International transfers
Our Supabase infrastructure runs in the [Supabase region — e.g. Frankfurt / EU] region. If you are located outside that region, your personal data is processed abroad.
Transfers are made under appropriate safeguards (standard contractual clauses) or your explicit consent, as required by applicable law including the Turkish Personal Data Protection Law (KVKK) and the GDPR.
10. Retention periods
- Account data: while your account is open; permanently deleted within 30 days of a deletion request.
- Task and content data: until you delete it or close your account.
- Session and sign-in records: 90 days.
- Server access logs: maximum 30 days.
- Contact form messages: 2 years after the conversation closes.
- Financial records: 10 years, as required by tax law.
Dormant accounts: if there is no sign-in for 24 months we email you a warning, and delete the account and its data if you do not sign in within 30 days.
11. Account and data deletion
You can request deletion of your account and its associated data at any time. Email info@ioplanner.com.tr from the address registered to your account with the subject “Account Deletion Request”. Full instructions: account deletion page.
Deleted from our servers: your account, name, email address, subscription / Pro plan records and session records.
Data on your device: your tasks, projects and goals are held only on your device, so they are unaffected by the request; uninstalling the app removes them.
Retained: financial records we are legally required to keep (10 years) and anonymised aggregate statistics that cannot be linked back to you.
Deletion completes within 30 days and is confirmed by email. It cannot be undone.
12. Security
- All connections use HTTPS/TLS; data is encrypted at rest on the server.
- Passwords are stored as one-way hashes and never in plain text.
- Row Level Security is enforced in the database: each user can reach only their own data.
- Administrative access requires two-factor authentication and is limited to staff who need it.
No system can be perfectly secure. If a breach affects your personal data we will notify you and the competent supervisory authority within the period required by law. If you find a vulnerability, please report it to info@ioplanner.com.tr and allow us reasonable time before public disclosure.
13. Your rights
You have the right to:
- Know whether we process your data and obtain information about it
- Receive a copy (data portability) — available instantly through in-app export
- Have inaccurate or incomplete data corrected
- Have your data erased
- Object to processing and withdraw consent
- Lodge a complaint with your supervisory authority (in Türkiye, the Personal Data Protection Board)
Send requests to info@ioplanner.com.tr; we respond within 30 days at the latest.
14. Children's privacy
IO Planner is not directed at children under 13 and we do not knowingly collect their data. If we learn that a child under 13 has sent us data, we delete the account and data without delay. Please contact us if you believe your child has provided us with data.
15. Changes
We may update this policy from time to time. For material changes we update the effective date, show an in-app notice and email your registered address. Continued use after a change means you accept the current version.
Effective date: 16 August 2026 · Version 2.0 · Türkçe sürüm