Legal Notice

Privacy Policy

Privacy policy for the Tercih Robotu web and mobile application

Last Updated: Reading Time: 10 Minutes

Data Controller

Tercih Robotu ("we", "our", "the Platform") operates the tercih-robotu.com website and the Tercih Robotu mobile application.

This Privacy Policy explains how we collect, use, and protect your personal data in accordance with KVKK (Turkish Data Protection Law No. 6698) and the European General Data Protection Regulation (GDPR).

For more comprehensive disclosure under KVKK, see our KVKK Information Notice page.

Data We Collect

The following data categories are collected and processed depending on the nature of the service:

  • Account Data

    When you create an account, we collect your email address and encrypted password. Authentication is handled securely via Supabase Auth.

  • Usage Data

    We store your preference list containing university and department selections. This data is linked to your account for syncing across devices.

  • AI Chat Data

    When you use the AI Advisor, your messages are sent to Google Gemini AI to generate responses. Chat history is stored linked to your account for continuity. Your name and email are not shared with the AI service.

  • Contact Form Data

    If you submit a contact form, we collect your name, email address, and message content.

  • Device Data

    Our mobile app may process limited device data (device type, OS version, app version) for crash reports and compatibility checks. This data is not linked to your account.

How We Use Data

We use the data we collect for the following purposes:

  • Providing personalized university and department recommendations

  • Powering the AI Advisor with contextual responses

  • Syncing your preference list across devices

  • Responding to your contact form inquiries

  • Improving our services and user experience

Advertising

This website displays ads served by <strong>Google AdSense</strong>; our mobile application uses the <strong>Google AdMob</strong> SDK. Both services may collect browser/device identifiers, approximate location, and usage signals to deliver personalized or contextual ads. On the web, advertising cookies are blocked until you grant consent thanks to the Google Consent Mode v2 integration.

Your control:

  • iOS: On first launch (iOS 14+), the system App Tracking Transparency prompt lets you allow or deny tracking across apps. You can change this choice any time under Settings → Privacy & Security → Tracking.

  • Android: Settings → Google → Ads lets you opt out of personalized ads.

  • In-app: The Privacy Settings screen includes a "Personalized Ads" toggle. When it is off, only non-personalized (contextual) ads are served.

If you deny consent, contextual ads may still be shown, but they are not based on a personal advertising identifier.

Third-Party Services

The following services process data on our behalf:

  • Supabase (Supabase, Inc., US)

    Database and authentication. Stores your profile, preference list, and AI chat history.

  • Google Gemini AI (Google LLC, US)

    Generates AI Advisor responses. Only your chat messages are transmitted; your name, email, and profile data are never sent.

  • Vercel (Vercel Inc., US)

    Web hosting, API backend, and edge CDN. Processes HTTP request metadata (IP, user-agent) for operational purposes.

  • Expo Application Services (Expo, Inc., US)

    Mobile OTA updates. On each app launch, the device sends its runtime version, app ID, and an anonymous install ID to u.expo.dev to check for updates. No personal data is transmitted.

  • Google AdMob / AdSense (Google LLC, US)

    Advertising SDKs. AdSense runs only on the tercih-robotu.com website; AdMob runs only in the mobile application. Device identifiers and usage signals are collected only after consent is granted (Consent Mode v2 / ATT).

  • Google Fonts (Google LLC, US)

    Web font delivery. Processes IP address and user-agent for font requests.

We do not sell your personal data to third parties. We do not share your profile, preference list, or chat history with advertisers.

International data transfer: Supabase, Vercel, Google, and Expo are US-based. KVKK Article 9 normally requires explicit consent for transfers to countries without an adequacy decision. You are informed of and consent to these transfers when you create an account.

Data Retention

Your data is retained as long as your account is active. Upon account deletion request, all your data (preferences, chat history, notifications, profile) is permanently deleted within 30 days.

See our Account Deletion page for detailed instructions.

Offline data (mobile app): As of v1.4, public university and department information (YÖK Atlas dataset) is shipped inside the mobile app binary rather than fetched from our servers. This dataset contains no personal data — only public university statistics. It is refreshed annually via Expo OTA updates.

Your Rights

Under KVKK Article 11 and GDPR, you have the following rights:

  1. Access your personal data
  2. Request correction of inaccurate data
  3. Request deletion of your data
  4. Object to data processing
  5. Data portability

To exercise these rights, contact us at destek@tercih-robotu.com or via our contact form.

Children's Privacy

Our services are not intended for children under 13, and we do not knowingly collect personal data from children under 13. If you learn that your child has provided us with information, please contact us; we will take steps to delete such information from our records.

For candidates in their preference period, this service is used by youth aged 17-25. This category is considered a competent data subject under KVKK and GDPR.

Data Security

We apply the following technical and administrative measures to protect your data:

  • SSL/TLS EncryptionAll data transmission is protected with 256-bit encryption
  • Row Level SecurityDatabase-level access control
  • Regular BackupThe database is automatically backed up
  • Access LogsAll access events are recorded

Policy Changes

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-service notification. The "Last Updated" date at the top of the page reflects the most recent change to the policy.

Contact

If you have questions about this Privacy Policy, please contact us:

You Are in Control of Your Data

Your privacy matters to us. We are always reachable for your questions and requests.