hedian

Gizlilik Politikası

Son güncelleme: 14 Eylül 2026 · Yürürlük: 12 Ağustos 2026

1. Kim, neyi, neden

Hedian, sosyal medyada karşılaştığınız bir gönderinin bağlantısını yapıştırdığınızda o içeriği sizin adınıza açıklayan bir uygulamadır. Bu politika, uygulamayı kullandığınızda hangi verilerin işlendiğini, neden işlendiğini ve haklarınızı anlatır.

Veri sorumlusu: Kerem Kaya (gerçek kişi)
Nisantepe Mh Kavaklı Sk No 61A, İstanbul 34794, Türkiye
info@hedian.app

6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) kapsamındaki aydınlatma yükümlülüğümüz bu metinle yerine getirilir. Avrupa Ekonomik Alanı'ndaysanız aynı metin Genel Veri Koruma Tüzüğü (GDPR) kapsamındaki bilgilendirme yükümlülüğümüzü de karşılar.

2. Hangi verileri işliyoruz

Aşağıdaki tablo işlediğimiz her alanı kapsar: veritabanımızda tuttuklarımızı ve sunucumuzun tuttuğu erişim kaydını.

VeriİçeriğiNedenHukuki sebep
Hesap Kullanıcı kimliği (rastgele UUID), varsa e-posta adresi, giriş sağlayıcısı (Apple / Google / e-posta). E-posta ile giriyorsanız hesabınızın bir parolası olur. Parolanız kimlik doğrulama sağlayıcımız Supabase tarafında yalnızca geri çevrilemez bir özet (hash) olarak saklanır; parolanın kendisini ne biz görürüz ne de herhangi bir yerde tutarız. Apple ya da Google ile giriyorsanız hiç parola oluşmaz. Ayrıca hesabın anonim olup olmadığını söyleyen bir işaret bulunur; bugün açılan her hesapta bu işaret “hayır”dır ve alan yalnızca eski uygulama sürümleriyle uyum için duruyor Kayıtlarınızı size bağlamak, cihaz değiştirdiğinizde erişiminizi sürdürmek Sözleşmenin ifası (KVKK m.5/2-c)
Apple oturum jetonu Yalnızca Apple ile giriş yaptıysanız: Apple'ın bize verdiği bir yenileme jetonu. Adınızı, e-postanızı ya da Apple hesabınıza dair başka hiçbir şeyi içermez Hesabınızı sildiğinizde Apple'a da haber verip bağlantıyı onun tarafında da iptal etmek. Bu jeton olmadan Apple sizi hâlâ bu uygulamanın kullanıcısı olarak hatırlar Hukuki yükümlülük (KVKK m.5/2-ç). Apple'ın uygulama kuralı
Profil Açıklamaların yazılacağı dil; konu alanı bazında seviye tercihiniz; dilerseniz görünen adınız; başlangıç adımında belirttiyseniz ne iş yaptığınız (hazır listeden bir seçim, ya da “başka bir şey” derseniz kendi yazdığınız en fazla 34 karakterlik kısa metin) Açıklamayı sizin seviyenizde ve dilinizde yazmak. Ne iş yaptığınız, seviye tercihlerinizi sizin yerinize önden doldurmak ve açıklamaları zaten kullandığınız terimlere göre uyarlamak için kullanılır. Bu adım isteğe bağlıdır, atlanabilir ve boş bırakıldığında ürün aynı şekilde çalışır Sözleşmenin ifası
Kayıtlar Yapıştırdığınız bağlantı; sizin için üretilen açıklama ve onunla birlikte gelenler (başlık, tek cümlelik özet, madde başlığı ve maddeler, terim sözlüğü, önerilen sorular, kontrol etmeye değer iddialar); varsa notunuz ve etiketleriniz, klasörü, soru sayısı, tarih. Bir kaydın işlenmesi başarısız olursa sebebini anlatan teknik bir hata notu da tutulur; bu not size gösterilmez, arızayı bulmak için vardır Ürünün kendisi. Kaydedilen şey budur Sözleşmenin ifası
Sorularınız ve cevapları Bir kayda sorduğunuz sorular ve üretilen cevaplar Soru-cevap zincirini saklamak Sözleşmenin ifası
Klasörler Oluşturduğunuz klasörlerin adı ve iç içe yapısı Kendi düzeninizi kurmanız Sözleşmenin ifası
Haftalık özet O haftanın kayıtlarından ve sorularınızdan üretilen metin: haftanın özeti, öne çıkan kayıtlar ve devamı için yazılan kısa not; ayrıca özetin hangi dilde yazıldığı ve üretiminin kaça mal olduğu. Hesabınıza bağlıdır Aynı hafta için modeli ikinci kez çalıştırmamak. Bu bir önbellektir: silinse içeriği kayıtlarınızdan yeniden üretilebilir Sözleşmenin ifası
İçerik bildirimi Bir analizi “bildir” dediğinizde: seçtiğiniz sebep (rahatsız edici / yanlış / başka), bildirilen kaydın ve içeriğin kimliği, tarih. Serbest metin toplanmaz Rahatsız edici ya da yanlış yapay zekâ çıktısını görebilmek ve filtrelemeyi buna göre düzeltmek. Google Play'in yapay zekâ içeriği kuralı bu yolu zorunlu tutuyor Meşru menfaat (KVKK m.5/2-f). Hukuki yükümlülük (mağaza kuralı)
Kullanım ve bütçe Aylık dönem, o dönemde oluşan işlem maliyeti, kayıt sayısı Kötüye kullanımı önlemek, maliyet sınırını uygulamak Meşru menfaat (KVKK m.5/2-f)
Abonelik Plan kademeniz, abonelik durumu ve bitiş tarihi; mağaza olay kaydı (ürün kimliği, olay türü, zamanı). Ödeme bilgileriniz bize hiç gelmez. Tahsilatı uygulamayı indirdiğiniz mağaza yapar (App Store ya da Google Play), kart bilgisi orada kalır Satın aldığınız planı uygulamak, aboneliğe dair destek taleplerini çözebilmek Sözleşmenin ifası
Model çağrı günlüğü Kullanılan model adı, token sayıları, hesaplanan maliyet. Metin içeriği tutulmaz Maliyet muhasebesi ve hata ayıklama Meşru menfaat
Paylaşılan çıkarım önbelleği Kamuya açık gönderiden türetilen analiz: başlık, süre, yazar kullanıcı adı, konuşma metni, ekrandaki yazılar. Sizin hesabınıza bağlı değildir; buna karşılık gönderiyi paylaşan kişiye veya içeriğinde adı geçen kişilere ait kişisel veri içerebilir Aynı gönderi ikinci kez yapıştırıldığında yeniden işlememek Meşru menfaat
Sunucu erişim kaydı (IP adresi) Sunucumuza gelen her isteğin IP adresi, zamanı, istenen adres ve sonucu. Bu kayıt veritabanında değil, sunucunun sistem günlüğündedir ve hesabınızla eşleştirilmez Sunucuyu ayakta tutmak, bir arıza olduğunda sebebini bulmak, kötüye kullanımı ve uygulamamızda var olmayan adresleri tarayan otomatik istekleri görebilmek Meşru menfaat (KVKK m.5/2-f)

Bir uyarı: sorularınız kişisel bilgi içerebilir

Bir kayda sorduğunuz soru serbest metindir. Örneğin “bunu üç yaşındaki oğluma uyarlayabilir miyim?” yazarsanız bu bilgi saklanır. Sorularınız hiçbir koşulda paylaşılan önbelleğe karışmaz; yalnızca sizin hesabınıza bağlıdır ve yalnızca siz erişebilirsiniz. Bunu uygulama katmanına bırakmadık, veritabanı seviyesinde zorluyoruz.

3. Toplamadıklarımız

Bu bölüm bir taahhüttür; değişirse bu metin de değişir.

4. Medya nasıl ele alınır

Bir gönderiyi analiz ederken videosu ya da sesi geçici olarak indirilir.

5. Kimlerle paylaşılıyor

Hizmeti çalıştırmak için kullandığımız sağlayıcılar (veri işleyenler):

SağlayıcıNe içinNereye giderNerede işlenir
SupabaseKimlik doğrulama ve veritabanı Yukarıdaki tüm hesap ve kayıt verileri. Giriş istekleri cihazınızdan doğrudan Supabase'e gittiği için bağlantı IP'nizi de görür AB, Frankfurt
Google (Gemini API)Açıklama, sözlük ve cevapların üretilmesi; konuşmanın metne çevrilmesi; görsel analiz; haftalık özet Gönderinin metni, sesi ve seçilmiş kareleri; sorduğunuz sorular. Haftalık özet için ayrıca o haftaki kayıtlarınızın başlıkları, tek cümlelik özetleri, madde başlıkları ve o hafta sorduğunuz sorular ABD
Apify Bir gönderi doğrudan alınamadığında devreye giren yedek çekim yolu (Instagram ve TikTok bağlantıları) Yapıştırdığınız gönderinin bağlantısı. Kimliğiniz gönderilmez Sağlayıcının kendi altyapısı
DataImpulse YouTube bağlantılarının alınmasında kullanılan vekil sunucu ağı YouTube'a giden istek bu ağın üzerinden geçer, yani gönderinin bağlantısını görür. Kimliğiniz gönderilmez Küresel
ResendHesap doğrulama ve parola sıfırlama e-postalarıE-posta adresinizABD / AB
RevenueCatAbonelik satın alma ve yenilemelerin takibi; planlar ekranının görüntülenme sayısı Rastgele kullanıcı kimliğiniz, satın alınan ürün ve abonelik durumu, planlar ekranını açtığınız an ve ekrana hangi düğmeden geldiğiniz; adınız, e-postanız ve kart bilgileriniz gönderilmezABD
Apple, Google“Apple ile giriş”, “Google ile giriş” Yalnızca kimlik doğrulama bilgisiSağlayıcının kendi altyapısı
CloudflareAlan adı ve DNSKişisel veri aktarılmazKüresel

Ayrıca, bir bağlantı yapıştırdığınızda içeriği almak için ilgili platforma (Instagram, TikTok, YouTube) bir istek gönderilir. Bu isteği biz yaparız; kimliğiniz o platforma bildirilmez. İstek kimi zaman yukarıdaki iki sağlayıcının üzerinden geçer: YouTube için DataImpulse'un vekil sunucu ağı, Instagram ve TikTok'ta doğrudan alma başarısız olduğunda Apify.

Bunların dışında verileriniz yalnızca hukuken zorunlu olduğunda (mahkeme kararı, yetkili kamu kurumu talebi) paylaşılır.

Yurt dışına aktarım

Google, Apify, DataImpulse, Resend ve RevenueCat hizmetleri Türkiye dışında sunulmaktadır. KVKK m.9 kapsamında bu aktarım, hizmetin sunulabilmesi için zorunludur ve uygulamayı kullanarak bu aktarıma açık rıza vermiş olursunuz. AEA'daysanız aktarım GDPR md.46 uyarınca Standart Sözleşme Maddeleri'ne dayanır.

6. Yapay zeka kullanımı

7. Ne kadar süre saklanır

8. Haklarınız

KVKK m.11 ve GDPR md.15–22 uyarınca:

Silme uygulama içinden yapılır: Ayarlar → Hesap → Hesabımı sil. İki aşamalı onay istenir ve işlem geri alınamaz. Apple ile giriş yaptıysanız, silme sırasında Apple'a da haber verilir ve uygulamanın Apple hesabınızla bağlantısı orada da iptal edilir; böylece uygulama, Apple Kimliğinizi kullanan uygulamalar listesinden çıkar.

Verilerinizin bir kopyasını istemek için info@hedian.app adresine yazın; en geç 30 gün içinde yanıtlanır. (Ücretli kademelerde tek bir kaydı uygulama içinden PDF veya Markdown olarak dışa aktarabilirsiniz; hesabınızın tamamının kopyası kademenizden bağımsız olarak bu adresten verilir.)

9. Güvenlik

10. Çocuklar

Hedian 13 yaşından küçükler için tasarlanmamıştır; Avrupa Ekonomik Alanı'nda yaş sınırı 16'dır (ilgili ülke daha düşük bir yaş belirlemişse o yaş). Bu yaşın altındaki bir kullanıcıya ait veri işlediğimizi öğrenirsek hesabı sileriz.

11. Değişiklikler

Bu politika değişirse yukarıdaki “son güncelleme” tarihi değişir. Esaslı bir değişiklikte uygulama içinden bilgilendirilirsiniz.

12. İletişim

info@hedian.app

Privacy Policy

Last updated: 14 September 2026 · Effective: 12 August 2026

1. Who we are and what this covers

Hedian is an app that explains a social media post for you when you paste its link. This policy tells you what data we process, why, and what rights you have.

Data controller: Kerem Kaya (individual)
Nisantepe Mh Kavaklı Sk No 61A, Istanbul 34794, Türkiye
info@hedian.app

We process personal data under Turkey's Personal Data Protection Law (KVKK No. 6698) and, if you are in the European Economic Area, the GDPR.

2. What we process

The table below covers every field we process: what we keep in our database, and the access log our server keeps.

DataWhat it isWhyLegal basis
Account A random user ID, your email address if we have one, your sign-in provider (Apple / Google / email). If you sign in with email, your account has a password. It is stored by our authentication provider, Supabase, only as an irreversible hash; we never see the password itself and never keep it anywhere. If you sign in with Apple or Google, no password is created at all. There is also a flag saying whether the account is anonymous; for every account created today that flag is “no”, and the field is kept only for compatibility with older versions of the app To tie your threads to you and keep them across devices Performance of a contract
Apple sign-in token Only if you signed in with Apple: a refresh token Apple issued to us. It carries no name, no email and nothing else about your Apple account So that deleting your account also tells Apple to revoke the link on its side. Without this token Apple keeps remembering you as a user of this app Legal obligation. Apple's App Store requirement
Profile The language explanations are written in; your level per subject area; your display name if you set one; what you do for a living if you told us during setup (a choice from a fixed list, or if you pick “something else”, up to 34 characters you type yourself) To write at your level, in your language. What you do is used to pre-fill your level preferences for you and to pitch explanations at the terms you already work with. That step is optional, can be skipped, and the product works the same if you leave it empty Performance of a contract
Threads The link you pasted; the explanation generated for you and everything that comes with it (title, one-line summary, the heading and the list of key points, the glossary, suggested questions, claims worth checking); your note and tags if any, the folder, question count, timestamps. If processing a thread fails, we also keep a technical note about why; it is not shown to you and exists so the failure can be diagnosed This is the product. It is what gets saved Performance of a contract
Your questions and answers Questions you ask about a thread and the answers generated To keep the question-and-answer chain Performance of a contract
Folders Names and nesting of folders you createYour own organisation Performance of a contract
Weekly digest Text generated from that week's threads and questions: the week's summary, its highlighted threads and a short note on where to go next; plus the language it was written in and what producing it cost. Tied to your account So the model is not run a second time for the same week. This is a cache: if deleted, its content can be regenerated from your threads Performance of a contract
Content report When you tap “report” on an analysis: the reason you picked (offensive / wrong / something else), the id of the reported thread and of the content, and the date. No free text is collected So that offensive or wrong AI output can be seen and filtering corrected. Google Play's AI content policy requires this route Legitimate interests; legal obligation (store rule)
Usage and budget Monthly period, processing cost incurred, number of threads Abuse prevention and cost limitsLegitimate interests
Subscription Your plan tier, subscription status and expiry; a store event record (product ID, event type, timestamp). Your payment details never reach us. The store you downloaded the app from handles the charge (App Store or Google Play) and your card stays there To apply the plan you bought and resolve subscription support requests Performance of a contract
Model call log Model name, token counts, computed cost. No text content Cost accounting and debuggingLegitimate interests
Shared extraction cache Analysis derived from the public post: title, duration, author handle, speech transcript, on-screen text. Not linked to your account; it may, however, contain personal data belonging to the person who posted it or to people named in it So the same post is not reprocessed when pasted again Legitimate interests
Server access log (IP address) The IP address, time, requested path and result of every request that reaches our server. This lives in the server's system log, not in the database, and is not matched to your account Keeping the server running, diagnosing failures, and spotting abuse and the automated scans that probe for paths we do not have Legitimate interests

One caution: your questions may contain personal information

Questions are free text. If you write “can I adapt this for my three-year-old?”, that is stored. Your questions never enter the shared cache; they are tied to your account only, and only you can read them. This is enforced at the database level, not left to application code.

3. What we do not collect

4. How media is handled

5. Who we share with

ProviderPurposeWhat is sentWhere processed
SupabaseAuthentication and database All account and thread data above. Sign-in requests go from your device straight to Supabase, so it also sees your connecting IP address EU, Frankfurt
Google (Gemini API) Generating explanations, glossaries and answers; speech-to-text; visual analysis; the weekly digest The post's text, audio and selected frames; the questions you ask. For the weekly digest, also the titles, one-line summaries and point headings of that week's threads, plus the questions you asked that week United States
Apify The backup fetching route used when a post cannot be retrieved directly (Instagram and TikTok links) The link to the post you pasted. Your identity is not sent Provider's own infrastructure
DataImpulse The proxy network used to fetch YouTube links Requests to YouTube pass through this network, so it sees the link to the post. Your identity is not sent Global
ResendAccount confirmation and password reset emailsYour email addressUS / EU
RevenueCatTracking subscription purchases and renewals; how often the plans screen is viewed Your random user ID, the product purchased and subscription status, the moment you open the plans screen and which button brought you there; no name, email or card detailsUnited States
Apple, GoogleSign in with Apple / Google Authentication data onlyProvider's own infrastructure
CloudflareDomain and DNSNo personal dataGlobal

When you paste a link we also request the content from the source platform (Instagram, TikTok, YouTube). We make that request; your identity is not disclosed to that platform. That request sometimes goes through two of the providers above: DataImpulse's proxy network for YouTube, and Apify for Instagram and TikTok when fetching directly fails.

Otherwise we disclose data only where legally required (court order or lawful authority request).

International transfers

Google, Apify, DataImpulse, Resend and RevenueCat operate outside Turkey. Under KVKK Art. 9 this transfer is necessary to provide the service and you consent to it by using the app. If you are in the EEA, transfers rely on Standard Contractual Clauses under GDPR Art. 46.

6. Use of AI

7. Retention

8. Your rights

Under KVKK Art. 11 and GDPR Arts. 15–22 you may:

Deletion is available in the app: Settings → Account → Delete my account. It asks twice and cannot be undone. If you signed in with Apple, deleting also tells Apple to revoke the link, so the app disappears from the list of apps using your Apple ID.

For a copy of your data, email info@hedian.app; we respond within 30 days. (On paid tiers you can export a single thread as PDF or Markdown from the app; a copy of your whole account is provided through this address whatever your tier.)

9. Security

10. Children

Hedian is not intended for anyone under 13, or under 16 in the European Economic Area (or the lower age set by your country). If we learn we hold data from someone below that age, we delete the account.

11. Changes

If this policy changes, the “last updated” date above changes. You will be told in the app about material changes.

12. Contact

info@hedian.app