Dil / Language: Bu belgenin Türkçe sürümü asıl (otoriter) metindir; aşağıdaki İngilizce metin, kolaylık amacıyla sağlanan bir çeviridir. Yorum farkı hâlinde Türkçe metin esas alınır. Bu hüküm, bulunduğunuz ülkenin veri koruma mevzuatından (ör. AEA/Birleşik Krallık'ta GDPR, Kaliforniya'da CCPA/CPRA) doğan emredici haklarınızı ve bu haklar ile bu belgeye ilişkin kendi dilinizde bilgilendirilme hakkınızı etkilemez.
The Turkish version of this document is the authoritative text; the English text below is a translation provided for convenience. In case of any discrepancy, the Turkish version prevails. This clause does not affect any mandatory rights you have under the data-protection laws of your country of residence (e.g., the GDPR in the EEA/UK, or the CCPA/CPRA in California), nor your right to be informed of those rights and of this document in your own language.
GİZLİLİK POLİTİKASI ve KVKK AYDINLATMA METNİ (Türkçe — asıl/otoriter metin)
Uygulama: Fiery Fixture (Android paket adı: com.crispyears.fieryfixture)
Veri Sorumlusu: Cihan Bozkurt
İletişim / Başvuru: [email protected]
Yürürlük Tarihi: 30 Haziran 2026
Son Güncelleme: 8 Ekim 2026
1. Genel Bilgilendirme
Fiery Fixture ("Uygulama"), futbol verilerine ilişkin istatistiksel analizler ve olasılık tahminleri üreten bir bilgi ve analiz uygulamasıdır. Uygulama yalnızca bilgilendirme, istatistik ve eğlence amaçlıdır; herhangi bir tavsiye (finansal, yatırım vb.) niteliği taşımaz, gerçek para işlemleri yürütmez ve bu tür hizmetlere yönlendirme, bağlantı veya ödeme aracılığı içermez. Uygulamadaki veriler yalnızca bu amaçlarla sunulur; kullanıcılar bu verileri yasadışı bahis dâhil hukuka aykırı hiçbir amaçla kullanamaz ve Uygulamayı bulundukları ülkenin yerel mevzuatına uygun biçimde kullanmakla yükümlüdür.
Bu metin; Cihan Bozkurt ("biz", "Veri Sorumlusu") olarak kişisel verilerinizi hangi amaçla, hangi hukuki sebeplerle işlediğimizi, kimlerle paylaştığımızı ve haklarınızı açıklar. Aşağıdaki düzenlemelere uygun hazırlanmıştır:
- 6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) — Türkiye
- Genel Veri Koruma Tüzüğü (GDPR) — Avrupa Ekonomik Alanı ve Birleşik Krallık
- California Tüketici Gizliliği Yasası (CCPA/CPRA) — Kaliforniya, ABD
- Google Play Geliştirici Politikaları ve Veri Güvenliği (Data Safety) gereklilikleri
2. Yaş Sınırı (18+)
Uygulama yalnızca 18 yaş ve üzeri yetişkinlere yöneliktir. Yaş sınırı iki katmanlı uygulanır:
- İlk kurulumda yaş beyanı: Uygulamayı ilk açtığınızda 18 yaşından büyük olduğunuzu beyan etmeniz istenir.
- Google yaş sinyalleri (uygun bölgelerde): Beyan, desteklenen bölgelerde Google Play'in yaş sinyali/doğrulama mekanizmasıyla ayrıca desteklenir. 18 yaşından küçük olduğu anlaşılan kullanıcılar Uygulamayı açamaz (yaş-bloğu ekranı).
Bu nedenle reşit olmayanlardan veri işlenmesi öngörülmez. Reşit olmayan birine ait verinin entegre bir üçüncü taraf sağlayıcı aracılığıyla işlendiğini öğrenirsek, ilgili sağlayıcıdan silinmesini talep eder ve gerekli adımları atarız. Bir ebeveyn/vasi [email protected] üzerinden bize ulaşabilir.
3. İşlediğimiz Kişisel Veriler ve Uygulamanın Yapısı
Kimlik doğrulama. Uygulama bir kayıt/parola sistemi içermez. İlk açılışta anonim kimlik doğrulama (Firebase Anonymous Authentication) ile sizi doğrudan tanımlamayan, rastgele üretilmiş bir anonim/takma-adlı kullanıcı kimliği (Firebase UID) oluşturulur. Salt-okur içerik (fikstür listesi, canlı skorlar, sonuç panosu, maç bilgisi/ayrıntı ekranları, lig tablosu) bu anonim kimlikle görüntülenebilir; bu kimlikle ayrıca, daha dar bir günlük üst sınır içinde ve her biri ödüllü reklamla kazanılmış bir kredi karşılığında analiz yapılabilir. Favoriler kataloğunu (takım/lig sayfaları, geçmiş maç içeriği ve oyuncu sayfası) ve Oyunlar bölümünü kullanmak, abonelik satın almak, ücretsiz ilk analiz hakkından yararlanmak, kazanılan kredileri bağlı hesaba taşımak ve girişsiz günlük üst sınırın ötesinde analiz yapmak için Google ile giriş yapmanız gerekir; bu durumda anonim kimliğiniz Google hesabınıza bağlanır ve Google hesabınıza ait e-posta adresiniz Firebase Authentication (Google) üzerinde işlenir. Google ile giriş yapmazsanız e-posta veya ad-soyad bilgisi işlenmez.
Sunucu tarafımız. Abonelik yönetimi, kötüye kullanımın önlenmesi ve hizmetin ölçülüp iyileştirilmesi için kendi sunucu altyapımızda (Cloudflare) takma-adlı Firebase UID'ye bağlı sınırlı kayıtlar tutarız:
- Abonelik/hak (entitlement) durumu: premium/VIP olup olmadığınız, ürün kimliği, abonelik bitiş tarihi, ortam (test/üretim) bilgisi, dönem türü (ör. ücretsiz deneme / olağan), mağaza, varsa otomatik yenilemenin iptal edildiği, ödeme sorununun tespit edildiği ve iadenin yapıldığı zaman damgaları ile ürün geçişlerinin özeti (hangi ürünün hangi tarih aralığında alındığı). Ayrıca RevenueCat'in bize bildirdiği abonelik olayları (ilk satın alma, yenileme, iptal, iptalin geri alınması, ürün değişimi, sona erme, ödeme sorunu, iade) olay türü, ürün, mağaza, ortam ve zaman damgasıyla bir olay geçmişinde tutulur.
- Kullanım kotası: günlük analiz sayacı (katman bazlı günlük analiz/adil-kullanım tavanı için; anonim kimlik için ayrı ve daha dar tavan dâhil), katman bazlı günlük farklı-maç bilgisi sayacı (anonim kimlik için ayrı ve daha dar tavan), Favoriler kataloğunda günlük farklı takım/lig/geçmiş maç/oyuncu sayacı (o gün açılan takım, lig, maç ve oyuncu kimlikleri) ve canlı izleme sınırının uygulanması. Google ile giriş yapılmış hesaplarda farklı-maç bilgisi ve Favoriler sayaçları, (b) bendindeki takma-adlı hesap çıpasıyla da işaretlenir; böylece bu tavanlar Google hesabı başına uygulanır.
- Ödüllü reklam kredileri ve işlem kayıtları: kazanılan/harcanan analiz kredileri (varsa süreli Happy Hour bonus kredileri dâhil), tekrar-kullanımı (replay) önlemek için ödül işlem kimlikleri ve Google ile giriş yaptığınızda anonim kimlikte kalan kredilerin bağlı hesabınıza tek seferlik taşınması. Ayrıca ödüllü reklam diyaloğunda oluşan arıza olayları (kota okunamadı, reklam envanteri yok, ağ hatası, gösterim hatası, ödül alınmadan erken kapatma) yalnızca olay türü olarak sayılır; reklam içeriği veya reklam kimliği bu kayda girmez.
- Güvenlik/hız-sınırlama sayaçları ve her istekte işlenen IP adresi (oturum kurma, hız-sınırlama ve kötüye kullanımın önlenmesi için). Hız-sınırlama sayaçları kısa pencereli ve geçicidir (dakika/saat/gün). Oturum kurulduktan sonra reddedilen isteklerin ve güvenlik olaylarının (ör. hız sınırı aşımı, giriş gerekli, kota dolu, doğrulama reddi) gün × olay türü × takma-adlı UID bazında günlük sayacı tutulur; bu sayaç IP içermez ve 90 günden eski satırlar silinir. Sunucumuz ayrıca ret noktalarında Cloudflare'in kısa ömürlü işlem günlüklerine (Workers Logs) yol, ülke, kenar konumu ve kısaltılmış (ilk 8 karakter) UID içeren yapısal bir satır yazar; bu günlüklere IP veya tam UID yazılmaz.
- Hizmet kullanım kaydı: Tamamlanan analizlerde, açılan maç bilgisi / Yorum / bağlam / maç ayrıntısı görüntülemelerinde ve VIP ekranı kullanımında (VIP ekranının açılması, Seçki/Radar sekmesine geçiş, filtre koşusu, filtre karnesinin açılması, Sinerji panelinin görüntülenmesi); takma-adlı UID, zaman damgası, IP'den türetilen ülke bilgisi, ilgili maç kimliği, analize giren oran/lig/tolerans değerleri, seçilen analiz motoru, işlemin hangi hak kapsamında yapıldığı (ödüllü reklam kredisi, ücretsiz ilk analiz hakkı, Happy Hour bonusu veya abonelik) ve analizde size sunulan sonucun kısa bir özeti (öne çıkan market etiketleri ve yüzdeleri, eşleşen maç sayısı, veri sürümü) kaydedilir. Bu kayda IP adresinin kendisi yazılmaz. Kayıt; analiz motorlarının isabetinin ölçülmesi, takma-adlı kayıtlardan toplu kullanım istatistikleri üretilmesi (ör. günlük aktif kullanıcı sayısı, ülke dağılımı), kapasite planlaması ve kötüye kullanımın tespiti için tutulur; 90 günden eski kayıtlar silinir. Kayıt, adınıza/telefonunuza değil yalnızca takma-adlı UID'ye bağlıdır ve reklam amaçlı kullanılmaz.
- Bütünlük doğrulama kaydı: Play Integrity doğrulamasının sonucu — cihaz bütünlüğü sınıfları, uygulama tanınırlığı, uygulama lisans kararı (Google Play'den edinilmiş mi), Play Protect durumu, yakın dönem cihaz etkinlik düzeyi, uygulama erişim-riski kararı (ekranı kaplayan/kaydeden/kontrol eden tanınmayan uygulama var mı) ve Integrity SDK sürümü — ile Uygulamanın derleme numarası, takma-adlı UID ve zaman damgası kaydedilir; IP veya cihaz kimliği içermez. 90 günden eski kayıtlar silinir.
- Ücretsiz ilk analiz hakkı kaydı: hakkın hesap başına yalnız bir kez tanınması için bağlı hesabın takma-adlı çıpası tutulur (bkz. 12. madde).
- Erişim engeli (ban) kaydı: Kullanım Koşulları'nı ihlal ettiği tespit edilen kimlikler için takma-adlı UID, idari not ve engelin konulduğu zaman damgası tutulur; bu kimlikten gelen istekler tüm uçlarda reddedilir. Kayıt IP adresi veya cihaz kimliği içermez ve kendiliğinden sona ermez (bkz. 12. madde). Ayrıca ağ düzeyinde (IP) engellemeler, sunucumuzda değil Cloudflare kenarında tutulur.
- Oyun kayıtları (yalnız Oyunlar bölümünü kullanırsanız): oyuncu profili ve takma ad, tahminler, kadrolar, sonuçlar ve sıralamalar, ödül kayıtları, takma ad moderasyonu kayıtları ve yönetim (denetim) kaydı; ayrıntıları bu maddenin sonundaki "Oyunlar" paragrafındadır.
Bu tanımlayıcılar sizi ad/telefonla doğrudan tanımlamaz; ancak GDPR/KVKK uyarınca takma-adlı çevrimiçi tanımlayıcılar kişisel veri sayılabilir. Ödeme kartı bilgileriniz hiçbir aşamada tarafımıza ulaşmaz/saklanmaz (ödemeleri Google Play yürütür). Analiz girdileriniz (oranlar, lig adı) performans için anonim ve kullanıcılar arası paylaşımlı bir önbellekte tutulur; önbellekteki bu kopya kimliğinize bağlanmaz. Aynı girdi değerleri ayrıca, yukarıda açıklanan hizmet kullanım kaydının bir parçası olarak takma-adlı UID'nize bağlı biçimde en çok 90 gün saklanır. Kaydettiğiniz analizler yalnızca cihazınızda (yerel depolama) saklanır, sunucuya gönderilmez. Yalnızca, takım kimliği eksik olan eski kayıtlarınızın arma renklerini tamamlamak için bu kayıtların maç (fikstür) kimlikleri sunucumuza gönderilir; kimlik tamamlanınca o kayıt için bir daha gönderilmez ve sunucumuz bu kimlikleri sizinle ilişkilendirerek saklamaz.
Takma-adlı Firebase UID'nin ve her istekte işlenen IP adresinin sağlanması Uygulamayı kullanmak için zorunludur; bunlar olmadan oturum kuramaz, hak (entitlement) doğrulaması yapamaz veya hizmeti kötüye kullanıma karşı koruyamayız ve Uygulama sunulamaz. Uygulama ayrıca her istekte kendi derleme (build) numarasını bir başlıkta iletir; bu numara yalnızca bütünlük doğrulama kaydına yazılır ve sürüm bazlı arıza teşhisi için kullanılır.
Girişsiz (anonim) erişimin kapsamı — 1 ve 8 Eylül 2026'dan itibaren. 11 Ağustos 2026'da getirilen ve tüm içerik uçlarını Google girişine bağlayan şart, 1 Eylül 2026'dan itibaren daraltılmıştır: Google hesabına bağlanmamış (anonim) kimlik, salt-okur içerik uçlarını (fikstür ve lig listesi, canlı skorlar, sonuç panosu, maç ayrıntısı, maç bilgisi / Yorum / bağlam ekranları ve lig tablosu) görüntüleyebilir. 8 Eylül 2026'dan itibaren anonim kimlik ayrıca sınırlı sayıda analiz yapabilir: bu analizler daha dar bir günlük üst sınıra tabidir ve her biri ödüllü reklamla kazanılmış bir kredi gerektirir; üst sınır dolduğunda analize devam etmek için Google ile giriş gerekir. Girişsiz analizler de bu maddede açıklanan kota sayaçlarına ve hizmet kullanım kaydına takma-adlı UID ile işlenir; aynı gün Google ile giriş yapılırsa günlük analiz sayacı kaldığı yerden devam eder. Bu erişimde de bütünlük doğrulaması ve kotalar aynen uygulanır; bilgi ekranlarında anonim kimliğe daha dar bir günlük farklı-maç tavanı ve ek bir saatlik istek freni uygulanır. Ücretsiz ilk analiz hakkı, girişsiz günlük üst sınırın ötesindeki analizler, Favoriler kataloğu (oyuncu sayfası dâhil), Oyunlar, abonelik satın alma ve kredi taşıma ise yalnızca Google hesabına bağlanmış kimliklere açıktır; satın alma akışı girişi şart koştuğu için Premium/VIP aboneler her durumda bağlı kimlikle çalışır. Bu şartlar, kullanım kotalarının Uygulama silinip yeniden kurularak sıfırlanmasını ve anonim hesap çoğaltma yoluyla kötüye kullanımı önlemek için uygulanır. Bu nedenle Google hesabınızın e-posta adresinin Firebase Authentication üzerinde işlenmesi, bu özellikler bakımından zorunludur; salt-okur görüntüleme ve girişsiz üst sınır içindeki analiz için zorunlu değildir. Telemetri onayı ve kişiselleştirilmiş reklam onayı ise her durumda isteğe bağlıdır.
Aşağıdaki kişisel veri işleme faaliyetleri, 9. maddedeki üçüncü taraf sağlayıcıların sistemlerinde gerçekleşir:
a) Cihaz ve teknik veriler: Cihaz modeli, işletim sistemi sürümü, dil/bölge, uygulama sürümü ve derleme numarası, ağ bilgisi, IP adresi.
b) Tanımlayıcılar: Reklam Kimliği (AAID), Firebase örnek kimlikleri, RevenueCat anonim kullanıcı kimliği, Firebase (anonim veya Google bağlı) auth kimliği, bağlı Google hesabından türetilen takma-adlı çıpa (geri döndürülemez HMAC özeti; ham Google kimliği sunucumuzda saklanmaz — ücretsiz ilk analiz hakkının hesap başına bir kez tanınması, günlük farklı-maç bilgisi ve Favoriler tavanlarının Google hesabı başına uygulanması ve Google hesabı başına yalnızca bir oyuncu profili açılabilmesi için kullanılır) ve Oyunlar bölümünde diğer kullanıcılara iletilen, rastgele üretilmiş oyuncu kimliği (Firebase UID'den türetilmez).
c) Hesap verisi (yalnız Google ile giriş yaparsanız): Google hesabınızın e-posta adresi.
d) Kullanım ve etkileşim verileri (yalnız onayınızla): Görüntülenen ekranlar, kullanılan özellikler, oturum süreleri, uygulama içi olaylar.
e) Çökme ve performans verileri (yalnız onayınızla): Hata günlükleri, yığın izleri, cihaz durumu, performans/ağ ölçümleri.
f) Abonelik verileri: Abonelik durumu, satın alma jetonu, ürün kimliği.
g) Yaklaşık konum: IP'den türetilen ülke/bölge düzeyinde konum (kesin/GPS konum toplanmaz).
h) Reklam etkileşim verileri: AdMob aracılığıyla görüntülenen banner, geçiş (interstitial), uygulama-açılış ve ödüllü reklamlar ile etkileşimler.
Yukarıdaki (d) kullanım/etkileşim (istatistik) ve (e) çökme/performans verileri (telemetri) yalnızca açık onayınızla toplanır; bu onayı, 6. madde hükümleri uyarınca Ayarlar > Destek > Gizlilik üzerinden dilediğiniz zaman açıp kapatabilirsiniz.
Bildirimler ve arka plan denetimi: Maç hatırlatmaları cihazınızda yerel olarak zamanlanır; sunucularımıza veya üçüncü taraflara push bildirim jetonu gönderilmez. Uygulama açıkken canlı izlediğiniz bir maçta gol olduğunda gösterilen kutlama (animasyon, titreşim ve cihazın kendi sistem sesi) tamamen cihazda çalışır, sunucuya hiçbir şey göndermez ve Ayarlar'dan kapatılabilir. VIP katmanındaki kriter alarmını açarsanız, Uygulama arka planda yaklaşık 12 saatte bir sunucumuza bir sorgu yaparak kaydettiğiniz filtrelere uyan yaklaşan maç olup olmadığını denetler ve bildirimi cihazda kurar; bu sorgu da diğer istekler gibi takma-adlı UID ve IP ile yapılır, ek bir kişisel veri içermez. Alarmı kapattığınızda arka plan görevi de durur.
Ana ekran widget'ı ve arka plan gol bildirimi (Premium ve VIP): Ana ekrana canlı skor widget'ı eklerseniz, izlediğiniz maçların skorları yalnızca cihazınızda bir önbellekte tutulur; widget'ın kendisi sunucumuza veri göndermez. Widget ekliyken ve izlenen bir maç başlamak üzereyken veya oynanırken Uygulama, skorları güncel tutmak için kısa ömürlü bir ön plan servisi çalıştırır (Android bildirim çekmecesinde sessiz bir bildirimle görünür). Bu servis yaklaşık 60 saniyede bir sunucumuzdan izlenen maçların skorunu ister; istek, diğer istekler gibi takma-adlı UID ve IP ile yapılır ve izlenen maç kimliklerini içerir. İzlenen maçta gol olduğunda, Ayarlar'da açık bırakılmışsa cihazda bir gol bildirimi gösterilir. Servis; maçlar bittiğinde, widget kaldırıldığında veya sunucu widget beslemesini reddettiğinde (abonelik yoksa) kendini durdurur.
Favoriler ve oyuncu sayfası: Favori lig ve takım seçimleriniz yalnızca cihazınızda saklanır ve sunucumuza gönderilmez. Bir favori takımın veya ligin sayfasını (künye, sezon fikstürü, kadro, sakat/cezalı listesi; puan durumu, gol/asist sıralaması, haftalık fikstür), bu sayfalardan bir geçmiş maçın içeriğini ya da bir oyuncu sayfasını açtığınızda Uygulama, sunucumuz üzerinden ilgili takım/lig/maç/oyuncu kimliğiyle katalog verisini ister; sunucumuz, günlük farklı takım/lig/maç/oyuncu tavanlarını uygulamak için takma-adlı UID'nize (Google ile giriş yaptıysanız hesap çıpanıza da) bağlı olarak o gün hangi kimlikleri açtığınızı kısa süreli (yaklaşık 2 gün) bir kayıtta tutar. Takım ve lig sayfalarının verisi cihazınızda geçici bir önbellekte saklanır ve favoriyi kaldırdığınızda silinir; açtığınız geçmiş maç içerikleri cihazınızda en çok 150 maç için saklanır (aşılınca en eski açılan silinir).
Oyunlar (Tahmin Ligi ve Kadro Ligi): Oyunlar bölümü yalnızca Google ile giriş yapılmış hesaplara açıktır; bölümü kullanmazsanız aşağıdaki kayıtlar oluşmaz. Oyunlara katıldığınızda sunucumuzda, oyunlara ayrılmış ayrı veritabanlarında (Cloudflare) takma-adlı UID'nize bağlı şu kayıtlar tutulur:
- Oyuncu profili: seçtiğiniz takma ad; UID'nizden türetilmeyen, rastgele üretilmiş ve diğer kullanıcılara iletilen oyuncu kimliği; profilin oluşturulma ve takma adın son değiştirilme zamanı; durum (aktif/askıda); takma adın yönetici tarafından kaldırıldığını veya kilitlendiğini gösteren işaretler ve kaldırma sayısı; Google hesabı başına tek profil açılabilmesi için (b) bendindeki hesap çıpası.
- Tahmin Ligi: verdiğiniz her tahminin maç kimliği, maç ve lig adı, başlama saati, market ve seçiminiz, olası ve kazanılan puan, sonuç ve durum (bekliyor, tuttu, tutmadı, geçersiz, hak iadesi), oluşturma ve son değiştirme zamanı; aylık puan, tahmin ve isabet toplamlarınız.
- Kadro Ligi: haftalık kadronuz (oyuncu kimlikleri ve mevkileri), dizilişiniz, oyuncuların alış değerleri, kullandığınız değişiklik hakkı, satış kaybı ve kayıt zamanı; haftalık puanınız, oynayan oyuncu sayınız, sıranız ve bütçe bonusunuz.
- Ödül kayıtları (resmî dönemde): ödül kazandığınız oyun, ay, sıra ve ödül; ödül hakkının bitiş tarihi ve ödül bildirimini gördüğünüz zaman. Katılımcıların yönetimi ve ödül planlaması için yönetim ekranında abonelik durumunuz (katman, bitiş tarihi, ürün, iptal ve deneme bilgisi) da görüntülenir; bu bilgi oyunların hiçbir hesabına girmez. Ödül hakkı RevenueCat'te Firebase UID'nize promosyon hakkı olarak tanımlanır (bkz. 8. madde).
- Takma ad moderasyonu: otomatik süzgece takılan takma ad denemeleriniz (son reddedilen ad, süzgeçte eşleşen sözcük, deneme sayısı, ilk ve son deneme zamanı ve hesap çıpanız); bir oyuncunun takma adını bildirdiğinizde ya da adınız bildirildiğinde bildiren ve bildirilen UID'ler, bildirim anındaki ad ve zaman; yöneticinin koyduğu inceleme işareti ve notu; gerekçeli puan düzeltmeleri ve oyunlarda askıya alma bilgisi. Bildiren kişinin kimliği bildirilen kullanıcıya gösterilmez; reddedilen ad ve eşleşen sözcük yalnızca yöneticiye görünür.
- Yönetim (denetim) kaydı: yönetici işlemlerinin (ör. takma ad kaldırma/kilitleme, askıya alma, puan düzeltme, ödül kaydı) ve otomatik işlerin (ör. puanlama, günün maçlarının seçimi) kaydı; yalnızca UID'nin ilk 8 karakterini ve işlemin ayrıntılarını (ör. eski/yeni takma ad, gerekçe veya not, düzeltilen puan, ödül) içerebilir.
Diğer kullanıcılara görünen bilgiler: Sıralamalarda takma adınız, sıranız ve puanınız; Tahmin Ligi'nde tahmin sayınız ve isabet oranınız; Kadro Ligi'nde haftalık oynayan oyuncu sayınız ve bütçe bonusunuz ile aylık toplamınız ve hafta sayınız, Google ile giriş yapmış diğer kullanıcılara gösterilir. Tahmin Ligi'nde diğer kullanıcılar ay geçmişinizi (maçlar, başlamış maçlardaki seçimleriniz, sonuçlar, puanlar ve o ay kazandığınız ödül) görebilir; başlamamış maçlardaki seçimleriniz gizli kalır. Kadro Ligi'nde kadronuzdaki oyuncular diğer kullanıcılara gösterilmez; haftalık ve aylık sonuçlarınız (puan, sıra, bütçe bonusu, ödül) görülebilir. Diğer kullanıcılara UID'niz, e-posta adresiniz veya adınız iletilmez; yalnızca takma adınız ve rastgele oyuncu kimliğiniz iletilir. Askıya alınan katılımcılar sıralamalarda gösterilmez. Sıralamalar sunucuda en çok 60 saniyelik bir önbellekte tutulur.
Oyun kayıtları reklam amacıyla kullanılmaz; barındırma (Cloudflare) ve ödül hakkının tanımlanması (RevenueCat) dışında üçüncü taraflarla paylaşılmaz. Oyun istekleri yukarıdaki hizmet kullanım kaydına yazılmaz; diğer istekler gibi takma-adlı UID ve IP ile yapılır ve güvenlik/hız-sınırlama kurallarına tabidir.
4. Verileri Hangi Amaçlarla İşliyoruz
- Uygulamanın temel analiz işlevlerinin sağlanması ve sürdürülmesi (fikstür/oran verisinin sunulması ve analiz)
- Ücretsiz (reklam destekli), Premium ve VIP katmanlarının yönetimi
- Abonelik durumunun doğrulanması ve hak yönetimi (RevenueCat + Google Play Billing)
- Günlük kullanım kotası, ödüllü-reklam kredileri, maç bilgisi görüntüleme hakkı, Favoriler kataloğu günlük tavanı, ücretsiz ilk analiz hakkı ve Happy Hour bonus kontenjanının yönetimi
- Favoriler kataloğunun (takım/lig sayfaları), canlı skor takibinin ve ana ekran widget beslemesinin sunulması
- Oyunlar bölümünün (Tahmin Ligi ve Kadro Ligi) sunulması: oyuncu profili ve takma ad, tahmin ve kadroların kaydı, puanlama ve sıralamaların diğer kullanıcılara gösterilmesi, ödül şartlarının denetimi ve ödüllerin tanımlanması; takma ad moderasyonu, kullanıcı bildirimlerinin incelenmesi ve adil oyunun korunması (çoklu hesap ve hile tespiti dâhil)
- Analiz motorlarının isabetinin ölçülmesi; takma-adlı kullanım kayıtlarından toplu kullanım istatistikleri üretilmesi (ör. günlük aktif kullanıcı sayısı, ülke dağılımı) ve hizmetin kapasite/kalite planlaması ile geliştirilmesi (meşru menfaat)
- Reklam gösterimi ve (rızanıza bağlı olarak) reklamların kişiselleştirilmesi; ödüllü reklam diyaloğu arızalarının teşhisi (meşru menfaat)
- Uygulamanın güvenliği; dolandırıcılığın, sahte/değiştirilmiş istemcilerin ve hız-sınır kötüye kullanımının önlenmesi (App Check, Play Integrity, IP bazlı hız-sınırlama); Uygulamanın Google Play'den edinildiğinin ve cihazda erişim riski taşıyan bir uygulama bulunmadığının doğrulanması
- Uzaktan yapılandırma ile bakım ekranı, zorunlu/isteğe bağlı güncelleme kapıları, duyuru şeridi ve reklam temposu ayarlarının uygulanması (Firebase Remote Config)
- (Onayınızla) cihaz içi telemetri (Analytics, Crashlytics, Performance) aracılığıyla hataların giderilmesi ile kararlılık ve performansın iyileştirilmesi
- Yasal yükümlülüklerin yerine getirilmesi ve hukuki taleplere yanıt verilmesi
5. Hukuki Sebepler
KVKK kapsamında (m.5):
- Bir sözleşmenin kurulması/ifası için zorunlu olması (abonelik hizmetinin sunulması, hak yönetimi; oyunlara katılım, sıralamaların gösterilmesi ve ödüllerin tanımlanması)
- Veri sorumlusunun meşru menfaati (güvenlik, dolandırıcılık ve kötüye kullanımın önlenmesi, hız-sınırlama, temel hizmetin sunumu, takma-adlı kullanım kayıtlarıyla motor isabetinin ölçülmesi ve toplu kullanım istatistikleri; oyunlarda takma ad moderasyonu, adil oyunun korunması ve yönetim işlemlerinin kaydı)
- Açık rızanız (telemetri/analitik ve kişiselleştirilmiş reklamlar)
- Kanunlarda öngörülmesi ve hukuki yükümlülüğün yerine getirilmesi
GDPR kapsamında (m.6):
- Sözleşmenin ifası (Art. 6/1-b) — abonelik ve hak yönetimi; oyunlara katılım, sıralamalar ve ödüller
- Meşru menfaat (Art. 6/1-f) — güvenlik, dolandırıcılık/kötüye kullanım önleme, hız-sınırlama, takma-adlı kullanım kayıtlarıyla ölçüm ve toplu kullanım istatistikleri; oyunlarda takma ad moderasyonu, adil oyun ve yönetim kaydı
- Açık rıza (Art. 6/1-a) — analitik/çökme/performans telemetrisi ve kişiselleştirilmiş reklam
- Hukuki yükümlülük (Art. 6/1-c)
Toplama yöntemi. Kişisel verileriniz; Uygulama ve entegre üçüncü taraf yazılım geliştirme kitleri (SDK'lar) aracılığıyla, sunucumuza yapılan istekler ve cihazınız üzerinden, otomatik veya kısmen otomatik yollarla elektronik ortamda toplanır.
6. Telemetri ve Rıza (Analytics, Crashlytics, Performance)
Kullanım analitiği (Firebase Analytics), çökme raporlaması (Crashlytics) ve performans ölçümü (Performance), varsayılan olarak KAPALIDIR ve yalnızca açık onay verirseniz etkinleşir. Onay, ilk kurulum ekranında istenir ve Ayarlar > Destek > Gizlilik altından dilediğiniz zaman geri alınabilir. Onay metni veya kapsamı değişirse onayınız yeniden istenir. Bu telemetri tercihi tüm kullanıcılar için (yalnızca EEA/UK ile sınırlı olmaksızın) geçerlidir. Analytics olayları, görüntülenen ekranların adları ve ürün olaylarından (ör. analiz istendi, ödeme ekranı görüntülendi, menü açıldı, gezinme stili değişti, cihaz doğrulama jetonu alınamadı, cihaz doğrulama onarım düğmesi gösterildi/kullanıldı) ibarettir; kişisel tanımlayıcı içermez. Onayınızı geri almanız, geri almadan önce onayınıza dayanılarak gerçekleştirilen işlemenin hukuka uygunluğunu etkilemez; aynı ilke, kişiselleştirilmiş reklamlar için verdiğiniz onay bakımından da geçerlidir.
Bu onaydan bağımsız olarak sunucumuza giden tek teşhis verisi, 3. maddede açıklanan ödüllü reklam diyaloğu arıza olayları ile ret/güvenlik olay sayaçlarıdır; bunlar meşru menfaat kapsamında, reklam içeriği veya kişisel tanımlayıcı olmaksızın, yalnızca olay türü olarak sayılır.
7. Reklamlar ve Rıza Yönetimi
Ücretsiz katmanda reklamlar Google AdMob aracılığıyla gösterilir (banner, geçiş, uygulama-açılış ve ödüllü reklam biçimleri). AdMob; reklam kimliği, IP adresi, cihaz bilgisi, yaklaşık konum ve reklam etkileşim verilerini işleyebilir.
Uyumlaştırma (mediation) KULLANILMAZ — 18 Ağustos 2026'dan itibaren. Tüm reklam biçimleri yalnız AdMob tarafından karşılanır; açık artırmaya başka bir reklam ağı davet edilmez ve Uygulama başka bir reklam ağına veri iletmez. Geçmiş dönem bilgisi: 13–18 Ağustos 2026 arasında banner, geçiş ve ödüllü reklam isteklerinde ironSource (Unity) ağı uyumlaştırma ortağı olarak açık artırmaya davet ediliyordu; bu ortaklık sona erdirilmiş ve ilgili bileşen Uygulamadan kaldırılmıştır.
- EEA, Birleşik Krallık ve İsviçre kullanıcılarına, Google'ın Kullanıcı Mesajlaşma Platformu (UMP) üzerinden bir rıza ekranı (CMP) gösterilir. Kişiselleştirilmiş reklamlar yalnızca açık rızanızla sunulur; rıza vermezseniz yalnızca kişiselleştirilmemiş reklam görürsünüz. Bu tercihiniz, Google'ın reklam iş ortakları için de geçerlidir.
- ABD eyalet gizlilik yasaları: Google'ın UMP'si, bulunduğunuz eyalet için bir gizlilik mesajı sunduğu ölçüde, "kişisel verilerimi satmayın/paylaşmayın" seçeneğini işaretleyebilirsiniz; bu tercih Google Mobile Ads SDK'sı tarafından cihazınızda IAB Küresel Gizlilik Platformu (GPP) biçiminde saklanır ve reklam talebinde dikkate alınır. Uygulama bu tercihi başka bir reklam ağına iletmez.
- Reklam kimlikleri ve bütünlük doğrulaması: Reklam birimlerinin kimlikleri Uygulamaya gömülü değildir; her açılışta Play Integrity doğrulaması sonrasında sunucumuzdan alınır (bkz. 3 ve 13. madde). Doğrulamayı geçemeyen cihazlara reklam kimliği ve içerik verilmez.
- Cihaz ayarlarınızdan Reklam Kimliğinizi sıfırlayabilir veya kişiselleştirilmiş reklamları kapatabilirsiniz.
- Google'ın reklam veri uygulamaları: https://policies.google.com/technologies/ads
8. Abonelikler (Google Play Billing + RevenueCat)
Premium ve VIP abonelikler Google Play Billing üzerinden satın alınır. Ödeme işlemini ve kart verilerinizi tamamen Google yönetir; biz bu bilgilere erişmeyiz.
Abonelik durumunuzun doğrulanması ve hak yönetimi için RevenueCat, Inc. (ABD merkezli) hizmetini kullanırız. RevenueCat; uygulama kullanıcı kimliğiniz (Firebase UID), satın alma jetonu, abonelik/ürün durumu, dönem türü (ör. ücretsiz deneme) ve cihaz bilgisini işler. RevenueCat ayrıca abonelik olaylarını (satın alma, yenileme, iptal, iade, ürün değişimi vb.) sunucumuza bildirir; bu olaylar 3. maddede açıklandığı şekilde takma-adlı UID'nize bağlı olarak kaydedilir. Oyunlarda ödül kazanırsanız ödül hakkı tarafımızca RevenueCat'te Firebase UID'nize süreli bir promosyon hakkı olarak tanımlanır; bu, Google Play ödemelerinizi etkilemez.
- Google ödeme politikaları: https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice
- RevenueCat gizlilik politikası: https://www.revenuecat.com/privacy
9. Kullandığımız Üçüncü Taraf Hizmetleri
Aşağıdaki sağlayıcılar, kendi gizlilik politikaları çerçevesinde veri işleyebilir:
| Hizmet | Sağlayıcı | İşlenen veri / Amaç |
|---|---|---|
| Firebase Authentication | Anonim kimlik; isteğe bağlı Google ile giriş (e-posta) | |
| Firebase App Check / Play Integrity | Uygulama/cihaz bütünlüğü, kötüye kullanım önleme | |
| AdMob (+ UMP) | Reklam gösterimi ve rıza; reklam kimliği, IP, cihaz, etkileşim | |
| Firebase Analytics | (Onayla) kullanım istatistikleri; cihaz, olay, yaklaşık konum | |
| Firebase Crashlytics | (Onayla) çökme günlükleri ve hata teşhisi | |
| Firebase Performance | (Onayla) performans ve ağ ölçümleri | |
| Firebase Remote Config | Uzaktan yapılandırma (bakım ekranı, güncelleme kapıları, duyuru şeridi, reklam temposu); Firebase kurulum kimliği | |
| Google Play hizmetleri (Age Signals, In-App Review, In-App Update) | Yaş sinyali (yalnızca cihazda değerlendirilir, sunucumuza iletilmez); Play'in kendi uygulama-içi değerlendirme ve güncelleme akışları | |
| Google Play Billing | Abonelik/ödeme işlemleri | |
| RevenueCat | RevenueCat, Inc. (ABD) | Abonelik durumu ve hak yönetimi (Firebase UID, satın alma jetonu); abonelik olaylarının sunucumuza bildirilmesi; oyun ödüllerinin promosyon hakkı olarak tanımlanması |
| Cloudflare | Cloudflare, Inc. (ABD/küresel) | Sunucu, CDN, güvenlik ve takma-adlı UID'ye bağlı kayıtların (oyun kayıtları dâhil) barındırılması; IP ve sunucu günlükleri; kısa ömürlü yapısal işlem günlükleri (kısaltılmış UID, ülke, uç) |
| Web ve veri barındırma | GoDaddy Operating Company, LLC (ABD) | Web sitelerimizin, statik sonuç dosyalarının, analiz arşivi veritabanının (benzerlik eşleştirmesi), katalog veritabanının (Favoriler, oyuncu sayfası, Bilgiler ekranının maç paketi ve gol krallığı listeleri) ve veri sağlayıcısına giden sabit-IP aktarma katmanının barındırılması; bu katmana istekler yalnızca sunucumuzdan, kullanıcı kimliği ve kullanıcı IP'si olmaksızın yapılır; standart sunucu erişim günlükleri (kullanıcı kimliği içermez) |
Veri kaynağı (kişisel verinizi işlemez): Fikstür, oran, takım/ülke/lig adları, kadro, puan durumu ve sakatlık verileri API-Football (api-sports.io) sağlayıcısından çekilir; Favoriler kataloğu, oyuncu sayfası ve Bilgiler ekranının bazı bölümleri bu verilerin günlük olarak güncellenen kendi kopyamızdan sunulur, Kadro Ligi'nin oyuncu havuzu ve oyuncu puanları da aynı verilerden tarafımızca hazırlanır. Bu sağlayıcıya hiçbir kullanıcı kişisel verisi gönderilmez; istekler sunucumuzdan (sabit-IP aktarma katmanı üzerinden), kullanıcı kimliği içermeden yapılır. Uygulama gerçek kulüp armalarını/logolarını göstermez; takımları, sunucumuzda türetilen forma renklerinden oluşan jenerik bir kalkan simgesiyle temsil eder.
Üçüncü kişilere ait spor verisi. "Bilgiler" ekranı, Favoriler kataloğu, oyuncu sayfası ve Kadro Ligi; kadro listeleri, oyuncu maç puanları, gol/asist sayıları, kiralık bilgisi, transfer hareketleri, sakat/cezalı bilgileri ile oyuncu sayfasındaki doğum tarihi/yaş, uyruk, mevki ve forma numarası gibi künye bilgileri ve sezon/kariyer istatistikleri gibi sporculara ve teknik ekiplere ilişkin kamuya açık spor verilerini aynı sağlayıcıdan alarak gösterir. Bu veriler Uygulama kullanıcısına ait kişisel veri değildir; kamuya açık spor müsabakalarına ilişkin haber/istatistik niteliğindeki bilgilerin sunulmasındaki meşru menfaat kapsamında, yalnızca bilgilendirme ve oyun amacıyla görüntülenir. Kadro Ligi'nde bu verilerden (maç puanı/rating, oynama sıklığı, lig ve ülke katsayıları) yalnızca oyun içinde kullanılan bir oyuncu değeri ve maç puanı otomatik olarak hesaplanır; bu değerler sporcu hakkında bir değerlendirme veya karar niteliği taşımaz ve oyun dışında kullanılmaz. Bunun dışında bu veriler tarafımızca zenginleştirilmez, profilleme için kullanılmaz ve üçüncü taraflara aktarılmaz. İlgili sporcu/temsilcisi, verisine ilişkin talepleri için [email protected] adresine yazabilir; talebi ayrıca kaynak sağlayıcıya iletiriz.
İlgili politikalar:
- Google / Firebase: https://policies.google.com/privacy ve https://firebase.google.com/support/privacy
- Cloudflare: https://www.cloudflare.com/privacypolicy/
- API-Football (api-sports.io): https://www.api-football.com/
10. Veri Paylaşımı
Kişisel verilerinizi para karşılığı satmayız. Verileriniz, hizmetin sunulması için gerekli olduğu ölçüde 9. maddedeki sağlayıcılarla paylaşılır (ör. abonelik yönetimi için RevenueCat'e Firebase UID ve satın alma jetonu; barındırma/güvenlik için Cloudflare'e istek ve IP verisi; cihaz bütünlüğü kararı için cihazınızın ürettiği Play Integrity jetonunun sunucumuz tarafından çözümlenmek üzere Google'a iletilmesi). Reklam tarafında ise reklam kimliği, IP/yaklaşık konum ve reklam etkileşim verisi, reklamın gösterilebilmesi için AdMob'a aktarılır; bu aktarım, ABD eyalet gizlilik yasaları ile CCPA/CPRA kapsamında "paylaşım" sayılabilir (bkz. 16. madde). Oyunlarda takma adınız ve oyun sonuçlarınız, 3. maddede açıklandığı şekilde Google ile giriş yapmış diğer kullanıcılara gösterilir. Yasal bir zorunluluk veya yetkili kamu kurumu talebi hâlinde, elimizdeki sınırlı bilgiler paylaşılabilir.
11. Yurt Dışına Aktarım
Kullandığımız hizmet sağlayıcılarının (Google, RevenueCat, Cloudflare, GoDaddy, api-sports.io) sunucuları Türkiye dışında, başta ABD olmak üzere diğer ülkelerde bulunabilir; bu nedenle verileriniz yurt dışına aktarılabilir.
- KVKK kapsamında aktarımlar; öncelikle KVKK m.9'da öngörülen uygun güvencelere (Kurulca ilan edilen standart sözleşme veya onaylanan taahhütname; hizmet sağlayıcılarımızın veri işleme sözleşmelerinde sağladığı standart sözleşme hükümleri dâhil) dayanılarak yapılır. Yeterlilik kararı veya uygun güvence bulunmayan hâllerde aktarım, yalnızca m.9/6'da sayılan arızi hâllerde (ör. açık rızanız) gerçekleştirilir.
- GDPR kapsamında aktarımlar; yeterlilik kararları veya Standart Sözleşme Hükümleri (SCC) gibi uygun güvencelerle gerçekleştirilir.
Aktarımların uygun güvencelere (Standart Sözleşme Hükümleri; Birleşik Krallık bakımından UK Uluslararası Veri Aktarım Sözleşmesi veya SSH'ye UK Eki) dayandığı hâllerde, uygulanan güvencelerin bir kopyasını veya nerede erişime sunulduğu bilgisini [email protected] adresine yazarak talep edebilirsiniz. ABD'deki sağlayıcılara (ör. Google, Cloudflare) yapılan aktarımlar, alıcının sertifikalı olduğu hâllerde AB–ABD Veri Gizliliği Çerçevesine de dayanabilir.
12. Saklama Süreleri
- Abonelik/hak kayıtları (sunucumuz): Aboneliğiniz aktif olduğu sürece ve geçerli yasal yükümlülükler gerektirdiği ölçüde tutulur; sona erince güncellenir. Abonelik olay geçmişi (RevenueCat bildirimleri) aboneliğinize ilişkin kayıt olarak tutulur; 15. maddedeki silme talepleri bu kaydı da kapsar.
- Kota, kredi ve ödül işlem kayıtları (sunucumuz): Günlük/dönemsel olarak sıfırlanır veya kötüye kullanımı önlemek için sınırlı süre tutulur. Favoriler kataloğunun günlük takım/lig sayacı yaklaşık 2 gün sonra silinir.
- Güvenlik/hız-sınırlama sayaçları ve IP: Hız-sınırlama sayaçları kısa pencereli ve geçicidir; Cloudflare kenar günlükleri Cloudflare'in kısa varsayılan saklama sürelerine tabidir. Oturum sonrası ret/güvenlik olaylarının kimlik bazlı günlük sayaçları (reklam diyaloğu arıza olayları dâhil) sunucumuzda en çok 90 gün tutulur.
- Analitik, çökme ve performans verileri: Onay verdiyseniz Google/Firebase politikaları uyarınca (genellikle 14 aya kadar / varsayılan süreler).
- Cihazınızdaki kayıtlı analizler: Siz silene veya Uygulamayı kaldırana kadar yalnızca cihazınızda kalır.
- Cihazınızdaki maç bilgisi önbelleği: "Bilgiler" ekranında indirilen maç verileri yalnızca cihazınızda geçici olarak saklanır ve ilgili maç sona erdiğinde (en geç 1 gün içinde) otomatik silinir; sunucuya geri gönderilmez.
- Cihazınızdaki favoriler, katalog önbelleği, izleme listesi ve tercihler: Favori lig/takım seçimleri, katalog sayfalarının önbelleği, açtığınız geçmiş maç içerikleri (en çok 150 maç; aşılınca en eski açılan silinir), canlı izleme listesi, hatırlatma kayıtları ve bildirim/gol kutlaması tercihleri yalnızca cihazınızdadır; favoriyi kaldırdığınızda ilgili katalog önbelleği silinir, kalanlar uygulama verisini temizleyene veya Uygulamayı kaldırana kadar durur.
- Hizmet kullanım kaydı (sunucumuz): En çok 90 gün tutulur, sonrasında silinir.
- Bütünlük doğrulama kaydı (sunucumuz): En çok 90 gün tutulur, sonrasında silinir.
- Ücretsiz ilk analiz hakkı kaydı (sunucumuz): Hakkın hesap başına yalnız bir kez tanınmasını sağlamak için bağlı hesabın takma-adlı çıpası, kötüye kullanımın (mükerrer hak talebinin) önlenmesi amacıyla saklanır; 15. maddedeki hesap/veri silme talepleri bu kaydı da kapsar.
- Erişim engeli (ban) kaydı (sunucumuz): Zaman aşımına uğramaz; engel kaldırılana kadar tutulur, kaldırıldığında kayıt silinir. Engelin kaldırılmasını 19. maddedeki iletişim adresinden talep edebilirsiniz.
- Oyun kayıtları (sunucumuz): Oyuncu profili, tahmin ve kadro kayıtları, sonuçlar ve sıralamalar, ödül kayıtları, takma ad ihlal ve bildirim kayıtları ile inceleme notları otomatik olarak silinmez; sıralama ve ödül geçmişinin gösterilebilmesi ve adil oyunun korunması için oyuncu profiliniz durdukça tutulur ve 15. maddedeki silme talebiyle silinir. Takma ad bildirimleri yönetici incelemesinden sonra da silinebilir. Sıralama önbelleği en çok 60 saniye tutulur.
- Oyun yönetim (denetim) kaydı (sunucumuz): Yönetici işlemlerinin hesap verebilirliği ve olası uyuşmazlıklarda hakların korunması için süre sınırı olmaksızın tutulur; yalnızca UID'nin ilk 8 karakterini ve işlemin ayrıntılarını (ör. eski/yeni takma ad, gerekçe veya not) içerebilir ve silme talebinden sonra da bu kısaltılmış hâliyle saklanır.
Uygulamayı kaldırmanız, cihaz tarafındaki veri toplamayı durdurur. Anonim Firebase UID, uygulama verisini temizlediğinizde veya kaldırıp yeniden kurduğunuzda yenilenir.
13. Veri Güvenliği
İletim güvenliği (TLS/HTTPS), Cloudflare güvenlik katmanı, App Check/Play Integrity ile istemci bütünlüğü doğrulaması ve IP bazlı hız-sınırlama gibi teknik/idari tedbirleri uygularız. Kısa ömürlü oturum jetonları cihazda güvenli depolamada (secure storage) tutulur. İçerik uçları, son 7 gün içinde başarılı bir Play Integrity doğrulaması bulunan kimliklere açılır; Uygulamanın Google Play'den edinilmediği (lisans kararı) veya cihazda ekranı gizlice kaplayan, kaydeden ya da kontrol eden tanınmayan bir uygulama bulunduğu (erişim-riski kararı) anlaşılırsa içerik ve reklam kimliği verilmez, Uygulama Google Play'in ilgili düzeltme ekranını gösterir ve durum düzelince erişim kendiliğinden açılır. Cihazdaki Google Play Hizmetleri ya da Play Store eski veya eksik olduğu için (ya da Google Play'in düzeltilebilir saydığı benzer bir hata nedeniyle) doğrulama yapılamazsa Uygulama, Google Play'in onarım ekranını açan bir düğme gösterebilir. Bununla birlikte, internet üzerinden hiçbir iletim veya saklama yöntemi %100 güvenli değildir.
14. Haklarınız ve Hakların Kullanımı
KVKK (m.11) kapsamında: kişisel verilerinizin işlenip işlenmediğini öğrenme; işlenmişse buna ilişkin bilgi talep etme; işlenme amacını ve bunların amacına uygun kullanılıp kullanılmadığını öğrenme; yurt içinde veya yurt dışında aktarıldığı üçüncü kişileri bilme; eksik veya yanlış işlenmişse düzeltilmesini isteme; KVKK m.7'deki şartlar çerçevesinde silinmesini veya yok edilmesini isteme; düzeltme, silme veya yok etme işlemlerinin kişisel verilerin aktarıldığı üçüncü kişilere bildirilmesini isteme; işlenen verilerin münhasıran otomatik sistemler vasıtasıyla analiz edilmesi suretiyle aleyhinize bir sonuç ortaya çıkmasına itiraz etme; ve kanuna aykırı işleme nedeniyle zarara uğramanız hâlinde zararın giderilmesini talep etme.
GDPR kapsamında: erişim, düzeltme, silme ("unutulma"), işlemenin kısıtlanması, veri taşınabilirliği, itiraz, rızayı geri çekme ve denetim makamına şikâyet hakkı.
CCPA/CPRA kapsamında (Kaliforniya sakinleri): toplanan veri kategorilerini bilme, silme, düzeltme, kişisel verilerin "satışına/paylaşımına" itiraz (opt-out) ve ayrımcılığa uğramama hakkı.
Otomatik karar verme hakkında: Uygulama, kişiler hakkında hukuki sonuç doğuran veya benzer biçimde önemli etki yaratan, münhasıran otomatik bir bireysel karar verme veya profilleme işlemi yürütmez. Üretilen analiz ve olasılıklar yalnızca futbol karşılaşmalarına ilişkindir; sizin hakkınızda verilen bir karar değildir ve size herhangi bir eylemde bulunmanızı önermez. Oyunlarda puanlar ve sıralamalar oyun kurallarına göre otomatik hesaplanır; takma ad önerileri otomatik bir süzgeçle denetlenir ve kurallara aykırı görülen ad reddedilir (bu ret yalnızca o adın kullanılmasını engeller, başka bir ad seçebilirsiniz); olağan dışı sonuçlar yönetim ekranında incelemeye işaretlenebilir. Takma adın kaldırılması veya kilitlenmesi, oyunlarda askıya alma, puan düzeltmesi ve ödül kararları bir yönetici tarafından verilir.
Nasıl kullanılır: Bizim sunucumuzdaki kayıtlar takma-adlı Firebase UID'nize (veya Google ile giriş yaptıysanız hesabınıza) bağlı olduğundan, bu kayıtlara ilişkin taleplerinizi 15. maddedeki silme yöntemiyle veya e-posta ile iletebilirsiniz. Üçüncü taraf sağlayıcılarda bulunan verilere ilişkin haklarınızı doğrudan ilgili sağlayıcıların araçlarından da kullanabilirsiniz:
- Reklam (AdMob): Cihaz ayarlarından Reklam Kimliğini sıfırlayın/kişiselleştirmeyi kapatın; EEA/UK'de UMP rıza ekranını, ABD'de gizlilik ekranındaki "satmayın/paylaşmayın" seçeneğini kullanın (bkz. 16. madde).
- Telemetri (Analytics, Crashlytics, Performance): Ayarlar > Destek > Gizlilik'ten onayı geri alın; Uygulamayı kaldırmanız da toplamayı durdurur.
- Abonelik (Google Play + RevenueCat): Aboneliği Google Play hesabınızdan yönetin; RevenueCat verileri için RevenueCat'in gizlilik kanallarını kullanın.
15. Hesap ve Veri Silme
Sunucumuzda takma-adlı Firebase UID'nize bağlı tutulan kayıtların (abonelik/hak ve abonelik olay geçmişi, kota ve Favoriler kataloğu sayaçları, kredi, hizmet kullanım kaydı, bütünlük doğrulama kaydı, ret/güvenlik ve reklam diyaloğu arıza sayaçları, ücretsiz ilk analiz hakkı kaydı, oyun kayıtları (oyuncu profili, tahmin ve kadro kayıtları, sonuçlar, ödül, takma ad ihlal ve bildirim kayıtları, inceleme notları) ve ilgili işlem kayıtları) silinmesini talep edebilirsiniz:
- [email protected] adresine "Veri Silme Talebi" konulu bir e-posta gönderin. Kimliği doğrulayabilmemiz için, mümkünse Uygulama içinde Google ile giriş yaptığınız hesabı belirtin.
- Talebinizi makul bir süre içinde (KVKK için en geç 30 gün) değerlendirir ve elimizdeki ilgili kayıtları sileriz. Yasal saklama yükümlülüğü bulunan kayıtlar bu sürelerin sonunda silinir.
- Anonim kullanıcılar, uygulama verisini temizleyerek veya Uygulamayı kaldırarak cihazdaki tüm yerel verileri ve aktif anonim kimliği temizleyebilir.
Oyun yönetim (denetim) kaydındaki kısaltılmış kimlik içeren satırlar 12. maddede açıklandığı şekilde saklanır. Aktif bir abonelik silme talebinden etkilenmez; aboneliğinizi ayrıca Google Play üzerinden yönetmeniz/iptal etmeniz gerekir. Uygulamayı kaldırmak veya uygulama verisini temizlemek de aboneliği iptal etmez.
16. CCPA — "Kişisel Verilerimi Satmayın/Paylaşmayın"
Verilerinizi para karşılığı satmıyoruz. Ancak kişiselleştirilmiş reklam amacıyla reklam tanımlayıcılarının reklam ortağıyla (AdMob) paylaşılması, CCPA/CPRA ve diğer ABD eyalet yasaları kapsamında "paylaşım" sayılabilir.
ABD'de bulunuyorsanız ve Google'ın UMP'si bulunduğunuz eyalet için bir gizlilik mesajı sunuyorsa, bu ekranda "kişisel verilerimi satmayın/paylaşmayın" seçeneğini işaretleyebilirsiniz. Tercihiniz Google Mobile Ads SDK'sı tarafından cihazınızda IAB Küresel Gizlilik Platformu (GPP) biçiminde saklanır ve reklam talebinde dikkate alınır. Ayrıca cihaz ayarlarınızdan reklam kişiselleştirmesini kapatabilir veya Reklam Kimliğinizi sıfırlayabilir, web üzerinden Google Reklam Ayarları'ndan (https://adssettings.google.com) yönetebilirsiniz. EEA/UK'de ise Uygulama içindeki UMP gizlilik tercihleri ekranını kullanabilirsiniz.
17. Çerezler ve Benzeri Teknolojiler
Uygulama, geleneksel web çerezleri yerine yukarıda açıklanan SDK ve cihaz tanımlayıcılarını kullanır. Bu politikanın yayımlandığı web sitesi, temel işlevsel ve güvenlik amaçlı çerezler kullanabilir.
18. Politikadaki Değişiklikler
Bu politikayı zaman zaman güncelleyebiliriz. Önemli değişikliklerde Uygulama içinde veya bu sayfada bildirim yaparız. Güncel sürüm her zaman bu sayfada yayımlanır ve "Son Güncelleme" tarihi yenilenir.
19. Başvuru, Şikâyet ve İletişim
Sorularınız için [email protected] adresine yazabilirsiniz. KVKK kapsamındaki başvuruları en geç 30 gün içinde değerlendiririz. Sonuçtan memnun kalmazsanız:
- Türkiye: Kişisel Verileri Koruma Kurulu'na (KVKK) şikâyette bulunabilirsiniz.
- AB/UK: Yerel veri koruma denetim makamına başvurabilirsiniz.
Veri Sorumlusu: Cihan Bozkurt
E-posta: [email protected]
PRIVACY POLICY (English — convenience translation)
Application: Fiery Fixture (Android package: com.crispyears.fieryfixture)
Data Controller: Cihan Bozkurt
Contact / Requests: [email protected]
Effective Date: June 30, 2026
Last Updated: October 8, 2026
1. Overview
Fiery Fixture (the "App") is an information and analytics application that produces statistical analyses and probability estimates from football data. The App is provided for informational, statistical, and entertainment purposes only; it does not constitute advice of any kind (financial, investment, etc.), processes no real-money transactions, and contains no redirection, links, or payment intermediation to any such service. The data in the App is provided solely for these purposes; users may not use it for any unlawful purpose, including illegal betting, and must use the App in accordance with the laws of their country of residence.
This document explains how Cihan Bozkurt ("we", "Data Controller") processes your personal data, for what purposes and legal bases, with whom we share it, and your rights. It is prepared in accordance with:
- Law No. 6698 on the Protection of Personal Data (KVKK) — Türkiye
- General Data Protection Regulation (GDPR) — EEA and the United Kingdom
- California Consumer Privacy Act (CCPA/CPRA) — California, USA
- Google Play Developer Policies and Data Safety requirements
2. Age Restriction (18+)
The App is intended exclusively for adults aged 18 and over. The restriction is enforced in two layers:
- Self-declaration at first install: On first launch, you confirm that you are over 18.
- Google age signals (where available): In supported regions, this declaration is additionally supported by Google Play's age-signals/verification mechanism. Users found to be under 18 cannot open the App (age-block screen).
We therefore do not expect to process minors' data. If we learn that data of a minor has been processed through an integrated third-party provider, we will request that the provider delete it and take the necessary steps. A parent/guardian may contact us at [email protected].
3. Personal Data We Process and How the App Works
Authentication. The App has no username/password registration. On first launch, anonymous authentication (Firebase Anonymous Authentication) creates a randomly generated anonymous/pseudonymous user identifier (Firebase UID) that does not directly identify you. Read-only content (the fixture list, live scores, the results board, match info/detail screens, the league table) can be viewed with this anonymous identity; analyses can also be run with it, within a narrower daily cap and each in exchange for a credit earned through a rewarded ad. To use the Favourites catalogue (team/league pages, past-match content and the player page) and the Games section, to purchase a subscription, to use the free first analysis, to transfer earned credits to a linked account, and to run analyses beyond the daily cap without sign-in, you must sign in with Google; in that case your anonymous identity is linked to your Google account and the email address of your Google account is processed by Firebase Authentication (Google). If you do not sign in with Google, no email or name is processed.
Our backend. For subscription management, abuse prevention, and measuring and improving the service, we keep, on our own backend (hosted on Cloudflare), limited records tied to your pseudonymous Firebase UID:
- Subscription/entitlement status: whether you are premium/VIP, product ID, subscription expiry, environment (test/production), period type (e.g., free trial / regular), store, the timestamps at which auto-renewal was cancelled, a billing issue was detected or a refund was issued (where applicable), and a summary of product changes (which product was held over which date range). In addition, the subscription events reported to us by RevenueCat (initial purchase, renewal, cancellation, un-cancellation, product change, expiration, billing issue, refund) are kept in an event history with event type, product, store, environment and timestamp.
- Usage quota: a daily analysis counter (for the tier-based daily analysis/fair-use cap, including a separate, narrower cap for anonymous identities), a tier-based daily distinct-match info counter (with a separate, narrower cap for anonymous identities), a daily distinct team/league/past-match/player counter for the Favourites catalogue (the team, league, match and player IDs opened that day), and enforcement of the live-watch limit. On accounts signed in with Google, the distinct-match info counter and the Favourites counters are also tagged with the pseudonymous account anchor described in (b), so that these caps apply per Google account.
- Rewarded-ad credits and transaction logs: analysis credits earned/spent (including any time-limited Happy Hour bonus credits), ad reward transaction IDs (to prevent replay), and the one-time transfer of credits left on an anonymous identity to your linked account when you sign in with Google. Failure events occurring in the rewarded-ad dialog (quota could not be read, no ad inventory, network error, display error, closing early before the reward) are counted only as an event type; no ad content or advertising ID enters this record.
- Security/rate-limit counters and the IP address processed on each request (for session establishment, rate-limiting, and abuse prevention). Rate-limit counters are short-windowed and transient (minute/hour/day). For requests rejected after a session is established and for security events (e.g., rate-limit exceeded, sign-in required, quota reached, verification denied), a daily counter is kept per day × event type × pseudonymous UID; this counter contains no IP and rows older than 90 days are deleted. At rejection points our backend also writes a structured line to Cloudflare's short-lived operational logs (Workers Logs) containing the path, country, edge location and a truncated UID (first 8 characters); neither the IP nor the full UID is written to those logs.
- Service usage records: for completed analyses, for match info / Insights / context / match detail views, and for use of the VIP screen (opening the VIP screen, switching to the Selection/Radar tab, running a filter, opening the filter report, viewing the Synergy panel), we store the pseudonymous UID, a timestamp, the country derived from the IP, the related match identifier, the odds/league/tolerance values used in the analysis, the selected analysis engine, which entitlement the action was performed under (rewarded-ad credit, free first-analysis right, Happy Hour bonus, or subscription), and a short summary of the result served to you in an analysis (the leading market labels and percentages, the number of matched games, the data version). The IP address itself is not written to these records. They are kept to measure the accuracy of the analysis engines, to produce aggregate usage statistics from the pseudonymous records (e.g., daily active user counts, country distribution), for capacity planning and to detect abuse; records older than 90 days are deleted. They are linked only to the pseudonymous UID (not to your name or phone number) and are not used for advertising.
- Integrity verification record: the outcome of Play Integrity verification — device integrity classes, app recognition, the app licensing verdict (whether the app was obtained from Google Play), Play Protect status, the recent device activity level, the app access-risk verdict (whether an unknown app is overlaying, capturing or controlling the screen) and the Integrity SDK version — together with the App's build number, the pseudonymous UID and a timestamp; no IP address or device identifier is included. Records older than 90 days are deleted.
- Free first-analysis grant record: the pseudonymous anchor of the linked account, kept so the right is granted only once per account (see Section 12).
- Access ban record: for identities found to be in breach of the Terms of Use, we store the pseudonymous UID, an internal administrative note, and the timestamp the ban was applied; requests from that identity are rejected on all endpoints. The record contains no IP address or device identifier and does not expire automatically (see Section 12). Separately, network-level (IP) blocks are held at the Cloudflare edge, not on our backend.
- Game records (only if you use the Games section): player profile and nickname, picks, squads, results and rankings, prize records, nickname moderation records and the administrative (audit) log; details are in the "Games" paragraph at the end of this Section.
These identifiers do not directly identify you by name/phone, but under GDPR/KVKK pseudonymous online identifiers may qualify as personal data. Your payment card details never reach or are stored by us (Google Play processes payments). Your analysis inputs (odds, league name) are kept in an anonymous, cross-user shared cache for performance; that cached copy is not linked to your identity. The same input values are also retained for up to 90 days as part of the service usage records described above, tied to your pseudonymous UID. Analyses you save are stored only on your device (local storage) and are not sent to our servers. The only exception: to complete the crest colours of older saved records that lack team IDs, the match (fixture) IDs of those records are sent to our backend; once completed, they are not sent again for that record, and our backend does not store these IDs in association with you.
Providing the pseudonymous Firebase UID and the IP address processed on each request is necessary to use the App; without them we cannot establish a session, verify entitlements, or protect the service against abuse, and the App cannot be provided. The App also sends its own build number in a header with every request; this number is written only to the integrity verification record and is used for version-specific fault diagnosis.
Scope of access without sign-in (anonymous) — as of September 1 and 8, 2026. The requirement introduced on August 11, 2026, which tied every content endpoint to Google sign-in, has been narrowed as of September 1, 2026: an identity not linked to a Google account (anonymous) may view the read-only content endpoints (fixture and league lists, live scores, the results board, match detail, the match info / Insights / context screens and the league table). As of September 8, 2026, an anonymous identity may also run a limited number of analyses: these analyses are subject to a narrower daily cap and each requires a credit earned through a rewarded ad; once the cap is reached, signing in with Google is required to continue analysing. Analyses run without sign-in are also recorded, under the pseudonymous UID, in the quota counters and the service usage records described in this Section; if you sign in with Google on the same day, the daily analysis counter continues from where it left off. Integrity verification and all quotas apply to this access unchanged; on the info screens an anonymous identity is subject to a narrower daily distinct-match cap and an additional hourly request throttle. The free first-analysis right, analyses beyond the daily cap without sign-in, the Favourites catalogue (including the player page), the Games, subscription purchases and credit transfer remain available only to identities linked to a Google account; because the purchase flow requires sign-in, Premium/VIP subscribers always operate with a linked identity. These requirements exist to prevent usage quotas from being reset by reinstalling the App and to prevent abuse through anonymous account duplication. Consequently, processing of your Google account email address by Firebase Authentication is mandatory for those features, but not for read-only viewing or for analysis within the cap without sign-in. Telemetry consent and personalized-ads consent remain optional in every case.
The following personal-data processing takes place on the systems of the third-party providers listed in Section 9:
a) Device and technical data: Device model, OS version, language/region, app version and build number, network information, IP address.
b) Identifiers: Advertising ID (AAID), Firebase instance identifiers, RevenueCat anonymous user ID, Firebase auth ID (anonymous or Google-linked), and a pseudonymous anchor derived from the linked Google account (an irreversible HMAC digest; the raw Google identifier is not stored on our backend — used to ensure the free first-analysis right is granted only once per account, to apply the daily distinct-match info and Favourites caps per Google account, and to allow only one player profile per Google account), and the randomly generated player ID shared with other users in the Games section (not derived from the Firebase UID).
c) Account data (only if you sign in with Google): The email address of your Google account.
d) Usage and interaction data (only with your consent): Screens viewed, features used, session duration, in-app events.
e) Crash and performance data (only with your consent): Error logs, stack traces, device state, performance/network metrics.
f) Subscription data: Subscription status, purchase token, product ID.
g) Approximate location: Country/region-level location derived from IP (no precise/GPS location collected).
h) Advertising interaction data: Banner, interstitial, app-open and rewarded ads displayed and interactions, via AdMob.
The (d) usage/interaction (statistics) and (e) crash/performance data (telemetry) above are collected only with your explicit consent; you may turn this consent on or off at any time via Settings > Support > Privacy, in accordance with the provisions of Section 6.
Notifications and background checks: Match reminders are scheduled locally on your device; no push notification token is sent to our servers or to third parties. The celebration shown when a goal is scored in a match you are watching live while the App is open (animation, vibration and the device's own system sound) runs entirely on the device, sends nothing to the server and can be turned off in Settings. If you enable the VIP criteria alarm, the App queries our backend in the background approximately every 12 hours to check whether any upcoming match matches your saved filters, and schedules the notification on the device; like any other request, this query carries only the pseudonymous UID and IP and contains no additional personal data. Turning the alarm off also stops the background task.
Home-screen widget and background goal notifications (Premium and VIP): If you add the live-score widget to your home screen, the scores of the matches you follow are cached on your device only; the widget itself sends no data to our servers. While the widget is present and a followed match is about to start or is in play, the App runs a short-lived foreground service to keep scores current (visible as a silent notification in the Android notification drawer). This service requests the scores of the followed matches from our backend roughly every 60 seconds; like any other request, it carries the pseudonymous UID and IP and includes the identifiers of the followed matches. When a goal is scored in a followed match, a goal notification is shown on the device if left enabled in Settings. The service stops itself when the matches end, when the widget is removed, or when the backend refuses the widget feed (no subscription).
Favourites and player page: Your favourite league and team selections are stored on your device only and are not sent to our servers. When you open the page of a favourite team or league (profile, season fixtures, squad, injured/suspended list; standings, top scorers/assists, weekly fixtures), the content of a past match from these pages or a player page, the App requests the catalogue data through our backend using the team/league/match/player identifier; to enforce the daily distinct team/league/match/player caps, our backend keeps a short-lived record (about 2 days) of which identifiers you opened that day, tied to your pseudonymous UID (and, if you signed in with Google, also to your account anchor). Team and league page data is cached temporarily on your device and deleted when you remove the favourite; the past-match content you open is stored on your device for up to 150 matches (beyond that, the oldest opened is deleted).
Games (Prediction League and Squad League): The Games section is open only to accounts signed in with Google; if you do not use it, the records below are not created. When you take part in the games, our backend keeps the following records tied to your pseudonymous UID, in separate databases dedicated to the games (Cloudflare):
- Player profile: the nickname you choose; a randomly generated player ID that is not derived from your UID and is shared with other users; the time the profile was created and the nickname last changed; status (active/suspended); flags showing that the nickname was removed or locked by an administrator, and the removal count; and the account anchor described in (b), so that only one profile can be opened per Google account.
- Prediction League: for each pick you make, the match identifier, match and league name, kick-off time, market and your selection, the potential and awarded points, the result and status (pending, won, lost, void, allowance refunded), and the creation and last-change times; your monthly totals of points, picks and hits.
- Squad League: your weekly squad (player identifiers and positions), your formation, the players' purchase values, the changes you used, the sale loss and the save time; your weekly points, number of players who played, rank and budget bonus.
- Prize records (in the official period): the game, month, rank and prize you won; the end date of the prize entitlement and the time you saw the prize notification. For managing participants and planning prizes, your subscription status (tier, end date, product, cancellation and trial information) is also displayed on the administration screen; this information does not enter any of the games' calculations. The prize entitlement is granted to your Firebase UID in RevenueCat as a promotional entitlement (see Section 8).
- Nickname moderation: your nickname attempts caught by the automatic filter (the last rejected name, the word matched by the filter, the number of attempts, the first and last attempt times and your account anchor); when you report another player's nickname or your nickname is reported, the reporting and reported UIDs, the name at the time of the report and the time; the review flag and note set by an administrator; point corrections with their reasons and suspension from the games. The reporter's identity is not shown to the reported user; the rejected name and the matched word are visible only to administrators.
- Administrative (audit) log: a record of administrator actions (e.g., removing/locking a nickname, suspension, point correction, prize record) and automatic jobs (e.g., scoring, selection of the matches of the day); it may contain only the first 8 characters of the UID and the details of the action (e.g., old/new nickname, reason or note, corrected points, prize).
Information visible to other users: In the rankings, your nickname, rank and points; in the Prediction League your number of picks and hit rate; and in the Squad League your weekly number of players who played and budget bonus, together with your monthly total and number of weeks, are shown to other users signed in with Google. In the Prediction League, other users can view your monthly history (matches, your picks on matches that have started, results, points and any prize won that month); your picks on matches that have not started remain hidden. In the Squad League, the players in your squad are not shown to other users; your weekly and monthly results (points, rank, budget bonus, prize) can be viewed. Your UID, email address or name are not shared with other users; only your nickname and random player ID are shared. Suspended participants are not shown in the rankings. Rankings are cached on our backend for up to 60 seconds.
Game records are not used for advertising and are not shared with third parties other than for hosting (Cloudflare) and for granting prize entitlements (RevenueCat). Game requests are not written to the service usage records above; like other requests, they are made with the pseudonymous UID and IP and are subject to the security/rate-limiting rules.
4. Purposes of Processing
- Providing and maintaining the App's core analytics functions (delivering fixture/odds data and computing analyses)
- Operating the free (ad-supported), Premium, and VIP tiers
- Verifying subscription status and managing entitlements (RevenueCat + Google Play Billing)
- Managing the daily usage quota, rewarded-ad credits, the match-info viewing allowance, the daily Favourites catalogue cap, the free first-analysis right, and the Happy Hour bonus allowance
- Providing the Favourites catalogue (team/league pages), live score tracking and the home-screen widget feed
- Providing the Games section (Prediction League and Squad League): the player profile and nickname, recording picks and squads, scoring and showing rankings to other users, checking prize requirements and granting prizes; nickname moderation, reviewing user reports and protecting fair play (including detecting multiple accounts and cheating)
- Measuring the accuracy of the analysis engines; producing aggregate usage statistics from pseudonymous usage records (e.g., daily active user counts, country distribution); and planning and improving service capacity/quality (legitimate interest)
- Serving ads and (subject to your consent) personalizing them; diagnosing failures of the rewarded-ad dialog (legitimate interest)
- Securing the App and preventing fraud, tampered/fake clients, and rate-limit abuse (App Check, Play Integrity, IP-based rate-limiting); verifying that the App was obtained from Google Play and that no app posing an access risk is present on the device
- Applying, via remote configuration, the maintenance screen, forced/optional update gates, the announcement strip and ad-pacing settings (Firebase Remote Config)
- (With your consent) fixing errors and improving stability and performance via on-device telemetry (Analytics, Crashlytics, Performance)
- Meeting legal obligations and responding to legal requests
5. Legal Bases
Under KVKK (Art. 5): necessity for the performance of a contract (providing the subscription and entitlement management, as well as participation in the games, showing rankings and granting prizes); our legitimate interests (security, fraud/abuse prevention, rate-limiting, delivering the core service, measuring engine accuracy and producing aggregate usage statistics from pseudonymous usage records, as well as nickname moderation, protecting fair play and recording administrative actions in the games); your explicit consent (telemetry/analytics and personalized ads); and compliance with legal obligations.
Under GDPR (Art. 6): performance of a contract (Art. 6(1)(b)) — subscription and entitlements, as well as participation in the games, rankings and prizes; legitimate interests (Art. 6(1)(f)) — security, fraud/abuse prevention, rate-limiting, measurement and aggregate usage statistics from pseudonymous usage records, as well as nickname moderation, fair play and the administrative log in the games; explicit consent (Art. 6(1)(a)) — analytics/crash/performance telemetry and personalized ads; legal obligation (Art. 6(1)(c)).
Method of collection. Your personal data is collected by automated or partly automated means in electronic form, through the App and integrated third-party software development kits (SDKs), through requests made to our backend, and via your device.
6. Telemetry and Consent (Analytics, Crashlytics, Performance)
Usage analytics (Firebase Analytics), crash reporting (Crashlytics), and performance monitoring (Performance) are OFF by default and are enabled only if you give explicit consent. Consent is requested on the first-run setup screen and can be withdrawn at any time under Settings > Support > Privacy. If the consent text or scope changes, your consent is requested again. This telemetry choice applies to all users (not limited to the EEA/UK). Analytics events consist of the names of screens viewed and product events (e.g., analysis requested, paywall viewed, menu opened, navigation style changed, device verification token unavailable, device verification repair button shown/used); they contain no personal identifiers. Withdrawing your consent does not affect the lawfulness of processing carried out on the basis of your consent before its withdrawal; the same applies to any consent you give for personalized advertising.
Independently of this consent, the only diagnostic data sent to our backend are the rewarded-ad dialog failure events and the rejection/security event counters described in Section 3; these are counted as event types only, on the basis of legitimate interest, without ad content or personal identifiers.
7. Advertising and Consent
In the free tier, ads are served via Google AdMob (banner, interstitial, app-open, and rewarded formats). AdMob may process the advertising ID, IP address, device information, approximate location, and ad interaction data.
Mediation is NOT used — as of August 18, 2026. All ad formats are filled by AdMob only; no other ad network is invited into the auction and the App transmits no data to any other ad network. Historical note: between August 13 and August 18, 2026, the ironSource (Unity) network was invited into the auction as a mediation partner for banner, interstitial and rewarded requests; that partnership has been terminated and the corresponding component removed from the App.
- Users in the EEA, UK, and Switzerland are shown a consent screen (CMP) via Google's User Messaging Platform (UMP). Personalized ads are served only with your explicit consent; without consent you will see only non-personalized ads. Your choice also applies to Google's advertising partners.
- U.S. state privacy laws: to the extent Google's UMP presents a privacy message for your state, you may select "do not sell or share my personal information"; that choice is stored on your device by the Google Mobile Ads SDK in IAB Global Privacy Platform (GPP) form and taken into account for its ad requests. The App does not pass this choice to any other ad network.
- Ad unit IDs and integrity verification: the ad unit identifiers are not embedded in the App; they are obtained from our backend at each launch after Play Integrity verification (see Sections 3 and 13). Devices that fail verification receive neither ad unit IDs nor content.
- You can reset your Advertising ID or turn off ad personalization in your device settings.
- Google's advertising data practices: https://policies.google.com/technologies/ads
8. Subscriptions (Google Play Billing + RevenueCat)
Premium and VIP subscriptions are purchased through Google Play Billing. Google fully manages the payment process and your card data; we have no access to it.
To verify subscription status and manage entitlements, we use RevenueCat, Inc. (USA), which processes your app user ID (Firebase UID), purchase token, subscription/product status, period type (e.g., free trial), and device information. RevenueCat also notifies our backend of subscription events (purchase, renewal, cancellation, refund, product change, etc.); these events are recorded against your pseudonymous UID as described in Section 3. If you win a prize in the games, we grant the prize as a time-limited promotional entitlement to your Firebase UID in RevenueCat; this does not affect your Google Play payments.
- Google payments policy: https://payments.google.com/payments/apis-secure/get_legal_document?ldo=0&ldt=privacynotice
- RevenueCat privacy policy: https://www.revenuecat.com/privacy
9. Third-Party Services We Use
The following providers may process data under their own privacy policies:
| Service | Provider | Data processed / Purpose |
|---|---|---|
| Firebase Authentication | Anonymous identity; optional Google Sign-In (email) | |
| Firebase App Check / Play Integrity | App/device integrity, abuse prevention | |
| AdMob (+ UMP) | Ad serving and consent; advertising ID, IP, device, interactions | |
| Firebase Analytics | (With consent) usage statistics; device, events, approximate location | |
| Firebase Crashlytics | (With consent) crash logs and error diagnostics | |
| Firebase Performance | (With consent) performance and network metrics | |
| Firebase Remote Config | Remote configuration (maintenance screen, update gates, announcement strip, ad pacing); Firebase installation ID | |
| Google Play services (Age Signals, In-App Review, In-App Update) | Age signal (evaluated on the device only, not sent to our backend); Play's own in-app review and in-app update flows | |
| Google Play Billing | Subscription/payment processing | |
| RevenueCat | RevenueCat, Inc. (USA) | Subscription status and entitlement management (Firebase UID, purchase token); notification of subscription events to our backend; granting game prizes as promotional entitlements |
| Cloudflare | Cloudflare, Inc. (USA/global) | Hosting, CDN, security, and storage of records tied to the pseudonymous UID (including game records); IP and server logs; short-lived structured operational logs (truncated UID, country, endpoint) |
| Web and data hosting | GoDaddy Operating Company, LLC (USA) | Hosting of our websites, static results files, the analysis archive database (similarity matching), the catalogue database (Favourites, the player page, the Info screen's match bundle and top-scorer lists) and the fixed-IP relay to the data provider; requests to this layer are made only from our server, without any user identifier or user IP; standard server access logs (contain no user identifier) |
Data source (does not process your personal data): Fixtures, odds, team/country/league names, squads, standings and injury data are retrieved from API-Football (api-sports.io); the Favourites catalogue, the player page and some sections of the Info screen are served from our own daily-updated copy of that data, and the Squad League's player pool and player points are also prepared by us from the same data. No user personal data is sent to this provider; requests are made from our server (through the fixed-IP relay) without any user identifier. The App does not display real club crests/logos; it represents teams with a generic shield icon made of kit colours derived on our server.
Sports data relating to third parties. The "Info" screen, the Favourites catalogue, the player page and the Squad League display publicly available sports data about players and coaching staff — squad lists, player match ratings, goal/assist counts, loan status, transfer moves, injury/suspension information and, on the player page, profile details such as date of birth/age, nationality, position and shirt number together with season/career statistics — obtained from the same provider. This data is not personal data of the App's user; it is displayed solely for informational and game purposes, based on the legitimate interest in providing news/statistical information about public sporting events. In the Squad League, a player value and match points used only within the game are calculated automatically from this data (match rating, frequency of appearances, league and country factors); these values are not an assessment of or decision about the athlete and are not used outside the game. Beyond that, we do not enrich this data, use it for profiling, or transfer it to third parties. A player or their representative may write to [email protected] regarding their data; we will also forward the request to the source provider.
Relevant policies:
- Google / Firebase: https://policies.google.com/privacy and https://firebase.google.com/support/privacy
- Cloudflare: https://www.cloudflare.com/privacypolicy/
- API-Football (api-sports.io): https://www.api-football.com/
10. Data Sharing
We do not sell your personal data for monetary value. Your data is shared with the providers in Section 9 only as necessary to provide the service (e.g., Firebase UID and purchase token to RevenueCat for subscription management; request and IP data to Cloudflare for hosting/security; the Play Integrity token generated by your device is forwarded by our backend to Google for decoding in order to obtain the device integrity verdict). On the advertising side, the advertising ID, IP/approximate location and ad interaction data are transferred to AdMob so that ads can be served; that transfer may constitute "sharing" under CCPA/CPRA and other U.S. state privacy laws (see Section 16). In the games, your nickname and game results are shown to other users signed in with Google as described in Section 3. Where required by law or by a competent authority, limited information available to us may be disclosed.
11. International Transfers
Our providers (Google, RevenueCat, Cloudflare, GoDaddy, api-sports.io) may operate servers outside Türkiye, primarily in the USA and other countries; therefore your data may be transferred abroad.
- Under KVKK, transfers are made primarily on the basis of the appropriate safeguards provided for in Art. 9 of KVKK (such as the standard contract announced by the Board or an approved undertaking, including the standard contractual clauses provided by our service providers in their data processing agreements). Where no adequacy decision or appropriate safeguard is available, a transfer is carried out only in the incidental cases listed in Art. 9(6) (e.g., your explicit consent).
- Under GDPR, transfers are carried out with adequacy decisions or appropriate safeguards such as Standard Contractual Clauses (SCCs).
Where transfers rely on appropriate safeguards (Standard Contractual Clauses; for the United Kingdom, the UK International Data Transfer Agreement or the UK Addendum to the SCCs), you may request a copy of the safeguards applied, or information on where they have been made available, by writing to [email protected]. Transfers to U.S. providers (e.g. Google, Cloudflare) may also rely on the EU–U.S. Data Privacy Framework where the recipient is certified.
12. Retention
- Subscription/entitlement records (our backend): kept while your subscription is active and as required by applicable legal obligations; updated when it ends. The subscription event history (RevenueCat notifications) is kept as a record relating to your subscription; deletion requests under Section 15 also cover it.
- Quota, credit, and reward transaction records (our backend): reset daily/periodically or kept for a limited time to prevent abuse. The daily team/league counter of the Favourites catalogue is deleted after about 2 days.
- Security/rate-limit counters and IP: rate-limit counters are short-windowed and transient; Cloudflare edge logs are subject to Cloudflare's short default retention periods. The per-identity daily counters of post-session rejection/security events (including rewarded-ad dialog failure events) are kept on our backend for a maximum of 90 days.
- Analytics, crash, and performance data: if you consented, per Google/Firebase policies (typically up to 14 months / default periods).
- Analyses saved on your device: remain only on your device until you delete them or uninstall the App.
- Match info cache on your device: match data downloaded in the "Info" screen is stored temporarily on your device only and is deleted automatically once that match has ended (within one day at the latest); it is never sent back to our server.
- Favourites, catalogue cache, watch list and preferences on your device: favourite league/team selections, the cache of catalogue pages, the past-match content you open (up to 150 matches; beyond that, the oldest opened is deleted), the live watch list, reminder records and the notification/goal-celebration preferences exist only on your device; the related catalogue cache is deleted when you remove a favourite, and the rest remain until you clear app data or uninstall the App.
- Service usage records (our backend): retained for a maximum of 90 days, then deleted.
- Integrity verification records (our backend): retained for a maximum of 90 days, then deleted.
- Free first-analysis grant record (our backend): to ensure the right is granted only once per account, the pseudonymous anchor of the linked account is retained to prevent abuse (duplicate claims); account/data deletion requests under Section 15 also cover this record.
- Access ban record (our backend): does not expire; it is retained until the ban is lifted, at which point the record is deleted. You may request that a ban be lifted using the contact address in Section 19.
- Game records (our backend): the player profile, pick and squad records, results and rankings, prize records, nickname violation and report records and review notes are not deleted automatically; they are kept for as long as your player profile exists, so that ranking and prize histories can be shown and fair play protected, and are deleted upon a deletion request under Section 15. Nickname reports may also be deleted after administrator review. The rankings cache is kept for up to 60 seconds.
- Game administrative (audit) log (our backend): kept without a time limit for the accountability of administrator actions and the protection of rights in possible disputes; it may contain only the first 8 characters of the UID and the details of the action (e.g., old/new nickname, reason or note) and is retained in this truncated form even after a deletion request.
Uninstalling the App stops data collection on the device side. The anonymous Firebase UID is regenerated when you clear app data or uninstall and reinstall.
13. Data Security
We apply technical and organizational measures such as encryption in transit (TLS/HTTPS), the Cloudflare security layer, client-integrity verification via App Check/Play Integrity, and IP-based rate-limiting. Short-lived session tokens are kept in secure storage on the device. Content endpoints are opened to identities that have a successful Play Integrity verification within the last 7 days; if it is determined that the App was not obtained from Google Play (licensing verdict) or that an unknown app is covertly overlaying, capturing or controlling the screen (access-risk verdict), neither content nor ad unit IDs are provided, the App shows Google Play's corresponding remediation screen, and access reopens automatically once the condition is resolved. If verification cannot be completed because Google Play services or the Play Store on the device are outdated or missing (or because of a similar error that Google Play treats as fixable), the App may show a button that opens Google Play's repair screen. However, no method of transmission or storage over the internet is 100% secure.
14. Your Rights and How to Exercise Them
Under KVKK (Art. 11): to learn whether your personal data is processed; to request information if it has been; to learn the purpose of processing and whether your data is used in accordance with that purpose; to know the third parties in Türkiye or abroad to whom your data is transferred; to request rectification of incomplete or incorrect data; to request erasure or destruction under the conditions in Art. 7 of KVKK; to request that any rectification, erasure, or destruction be notified to the third parties to whom the data has been transferred; to object to a result arising to your detriment from the exclusively automated analysis of your data; and to seek compensation for damages suffered due to unlawful processing.
Under GDPR: access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection, withdrawal of consent, and the right to lodge a complaint with a supervisory authority.
Under CCPA/CPRA (California residents): to know the categories of data collected, delete, correct, opt out of the "sale/sharing" of personal information, and not be discriminated against.
About automated decision-making: The App does not carry out automated individual decision-making or profiling that produces legal or similarly significant effects concerning you. The analyses and probabilities produced relate solely to football matches; they are not a decision about you and do not recommend that you take any action. In the games, points and rankings are calculated automatically under the game rules; proposed nicknames are checked by an automatic filter and a name found to break the rules is rejected (this only prevents that name from being used; you can choose another); unusual results may be flagged for review on the administration screen. Removing or locking a nickname, suspension from the games, point corrections and prize decisions are made by an administrator.
How to exercise: Because records on our backend are tied to your pseudonymous Firebase UID (or your account if you signed in with Google), you may submit related requests via the deletion method in Section 15 or by email. For data held by third-party providers, you may also use those providers' own tools:
- Advertising (AdMob): Reset your Advertising ID / disable personalization in device settings; in the EEA/UK use the UMP consent screen, and in the U.S. the "do not sell or share" option on the privacy screen (see Section 16).
- Telemetry (Analytics, Crashlytics, Performance): Withdraw consent under Settings > Support > Privacy; uninstalling the App also stops collection.
- Subscriptions (Google Play + RevenueCat): Manage your subscription via Google Play; for RevenueCat-held data use RevenueCat's privacy channels.
15. Account and Data Deletion
You may request deletion of the records tied to your pseudonymous Firebase UID on our backend (subscription/entitlement and subscription event history, quota and Favourites catalogue counters, credits, service usage records, integrity verification records, rejection/security and rewarded-ad dialog failure counters, the free first-analysis grant record, game records (player profile, pick and squad records, results, prizes, nickname violation and report records, review notes), and related transaction records):
- Email [email protected] with the subject "Data Deletion Request." So that we can verify identity, please indicate the Google account you used to sign in within the App, where possible.
- We will assess your request within a reasonable time (no later than 30 days for KVKK) and delete the relevant records we hold. Records subject to a legal retention obligation are deleted at the end of those periods.
- Anonymous users can clear all local data and the active anonymous identity by clearing app data or uninstalling the App.
Rows of the game administrative (audit) log that contain a truncated identifier are retained as described in Section 12. An active subscription is not affected by a deletion request; you must separately manage/cancel it via Google Play. Uninstalling the App or clearing app data does not cancel it either.
16. CCPA — "Do Not Sell or Share My Personal Information"
We do not sell your data for monetary value. However, sharing advertising identifiers with our advertising partner (AdMob) for ad personalization may constitute "sharing" under CCPA/CPRA and other U.S. state laws.
If you are located in the U.S. and Google's UMP presents a privacy message for your state, you can select "do not sell or share my personal information" on that screen. Your choice is stored on your device by the Google Mobile Ads SDK in IAB Global Privacy Platform (GPP) form and taken into account for its ad requests. You can also disable ad personalization or reset your Advertising ID in your device settings, or manage it on the web via Google Ads Settings (https://adssettings.google.com); in the EEA/UK you can use the in-app UMP privacy options screen.
17. Cookies and Similar Technologies
Instead of traditional web cookies, the App uses the SDK and device identifiers described above. The website hosting this policy may use essential functional and security cookies.
18. Changes to This Policy
We may update this policy from time to time. For material changes, we will provide notice within the App or on this page. The current version is always published here and the "Last Updated" date is revised accordingly.
19. Requests, Complaints, and Contact
You may write to us at [email protected]. We evaluate KVKK requests within 30 days. If you are not satisfied with the outcome:
- Türkiye: You may file a complaint with the Personal Data Protection Authority (KVKK).
- EU/UK: You may contact your local data protection supervisory authority.
Data Controller: Cihan Bozkurt
Email: [email protected]