Privacy policy
We explain app and website data separately
HatırdaKi V1 keeps app records on the device. Information you send through website contact and survey forms is processed separately from app data.
Data controller and contact
- Data controller
- Barbaros Kırılmaz · BKDev
- Contact
- info@hatirdaki.app
- Location
- Kocaeli / Türkiye
Send privacy, access and deletion questions to info@hatirdaki.app. Using the same email address that you previously provided may help us locate a record. For a survey record, you may share the one-time submission reference; only proportionate verification is requested.
1. Data kept on the device by the app
Medication, schedule, dose-decision, physical-stock, calendar, notification-centre and app-preference data is stored in the local database on your device. BKDev does not operate a user-account or central health-data server for these records.
The V1 Android app does not request INTERNET permission or initiate in-app network requests. If you choose to open the website, an email app or an Android share target, the action continues outside HatırdaKi; the browser, mail app, file location or recipient you select may process data under its own rules.
2. Local backups, PDF and protection
You initiate local backup and PDF creation. New backups are created in the shared Downloads/Tabletki folder; you use Android’s document picker to import another backup file and choose the save or share target for a PDF. HatırdaKi does not automatically send these files to a developer server or cloud account. An app, service or recipient you share them with may access them under its own rules; you manage exported copies.
Backup encryption with a recovery passphrase is optional. A backup without a passphrase is not cryptographically encrypted. BKDev does not receive or recover your passphrase. The local on-device database is not separately encrypted; app lock is not database encryption.
3. Website technical data and preferences
For security, error investigation and service operation, the web server may temporarily process standard technical records such as IP address, request time, requested path, limited browser information and response code.
Theme and reduced-motion preferences are stored in your browser. Language is determined by the language path you visit. The required hatirdaki_form cookie is used for the form session, security and result notice. No advertising, visitor analytics, profiling or third-party CAPTCHA is used; essential site content continues to work if preference storage is unavailable.
4. Contact form
When you send a message, the required topic category and message, any name or email you provide, and necessary language, time, delivery-status and security records are processed to review and answer your request and prevent misuse. Name and email are optional; email is needed if you want a direct reply.
The form does not request medicine lists, diagnoses, health reports, backups, recovery passphrases or other health data and does not support attachments. Do not enter that information in free text.
5. Voluntary survey
Usage state, platform need, setup, navigation, alarm and stock experience, useful functions, friction, priorities, optional suggestion, survey version, language and submission time are recorded to evaluate product priorities. Email is collected only if you request a reply; no name is requested.
The survey is not designed to collect health data. A one-time submission reference appears only on the success screen and helps locate the record for deletion; it is not added to the URL or sent by automatic email.
6. Purposes and legal conditions
Contact data is processed under the applicable KVKK condition for steps requested by you or directly connected with a contract, establishing/exercising/protecting rights, or the legitimate interest in operating a secure service without harming your fundamental rights. Site-security records are kept proportionately for that security interest. Voluntary survey responses are assessed under the legitimate interest in product improvement, with data minimisation and the option not to participate.
Special-category health data is not requested in the forms. Health information entered accidentally is not an intended data category and is not used for product profiling; you may request deletion if you notice it. If explicit consent is legally required for an activity, a separate, specific and optional choice will be provided; this notice is not itself consent.
7. Service categories and possible international processing
Website-hosting and email-delivery providers may process the website, communication and technical records necessary to operate the site and carry messages. Their standard server/mail logs and backups may follow their own retention arrangements. Personal data is not sold or shared for advertising.
When the APK is published, the site's download link will lead to a verified GitHub release. When you open it, GitHub may process connection data under its own notice. Depending on hosting, mail or GitHub infrastructure, some data may be processed outside Türkiye; applicable international-transfer rules separately apply to those operations.
8. Retention periods
The periods below apply to purpose-limited internal records. A record may be separated for only the necessary additional period where required by a limited legal obligation, establishment/exercise/protection of rights in a concrete dispute, or investigation of a security event.
Provider-managed standard logs and backups may follow their own periods outside BKDev’s direct control. You manage on-device app records and exported files.
| Record | Period or deletion condition |
|---|---|
| Contact correspondence | No more than 12 months in the active support mailbox; review and deletion of expired messages on the first Türkiye business day of each month. |
| Survey responses | Marked for deletion 365 days after submission and removed by the following hourly cleanup. |
| Optional reply email | Marked for deletion 90 days after submission and removed by the following hourly cleanup. |
| Rate-limit and duplicate-submission records | 24-hour operating window, then the following hourly cleanup. |
| Numeric security question | Valid for 10 minutes or no more than five wrong attempts; kept in the form session. |
| Site-specific technical error records | No more than 30 days from creation, then the following hourly cleanup. |
| Form cookie | For the browser session. |
| Theme and motion preferences | Until the user clears browser site data. |
9. Security and misuse prevention
Forms use server-side validation, CSRF/origin checks, a honeypot, size and selection limits, duplicate-submission protection, rate limiting and a first-party numeric security question. No third-party CAPTCHA script is loaded.
A keyed HMAC digest is used instead of a raw IP in form rate-limit and duplicate-submission records. A separate purpose-specific keyed HMAC fingerprint is derived from the normalized content of a valid submission; raw form content is not copied into that security fingerprint. These identifiers are used during a 24-hour operating window and deleted by the following hourly cleanup, so physical deletion may occur slightly after 24 hours. They may still be personal data and are used only for security. Separate web-server access logs may contain a raw IP. No internet transmission offers absolute security.
10. Your rights and requests
KVKK rights include asking whether your data is processed, requesting information or correction, requesting deletion/destruction where conditions are met, and the other rights in Article 11. KVKK applications that meet the procedural requirements are answered as soon as possible and no later than 30 days.
Send ordinary privacy and deletion questions to info@hatirdaki.app. Applying from the same email previously recorded in our systems may help matching; use the one-time reference for a survey. This ordinary contact address is not presented, by itself, as a universal and complete channel for every formal request under KVKK Article 11. If a formal request needs an additional procedure or identity check, we ask only for necessary information. Do not send health data or a recovery passphrase. HatırdaKi does not automatically send records on your device or exported files to BKDev. If you share a file, the app, service or recipient you select may access and retain it under its own rules. You manage on-device and exported copies that remain under your control.
11. Türkiye V1 pilot and languages
The V1 pilot is directed to users in Türkiye and is offered only as an Android APK through hatirdaki.app and a GitHub release verified from this site. Google Play and other app-store distribution are outside V1 scope.
Seven language options improve accessibility; a language choice does not establish the user’s country and does not by itself mean that a market outside Türkiye is targeted. Any mandatory rights that do apply are not limited by language choice.
12. Changes
If app permissions, site forms, service categories or data flows change, this policy will be updated to match actual operation and show a new date.
If a new purpose, data type or required permission arises, information and any required separate choice will be presented before processing starts. A policy update does not replace consent that was never given.