Privacy Policy

Privacy Policy

POVL · How We Protect Your Data
Last Updated: February 18, 2026

⚠️ Important Legal Disclaimer

POVL is not a medical device.

The personality analyses, archetypes, social comparisons, and results provided through this application are intended solely for entertainment, social interaction, and personal awareness purposes. The application's content does not substitute for professional psychological counseling, clinical diagnosis, treatment, or medical advice and should not be used for such purposes.

POVL is a platform where users share their subjective opinions about people in their social circles and engage in "social discovery" through algorithmic patterns.


1. Introduction

POVL ("Application", "we", "us", "our") is a social discovery and interaction platform developed by Barış Altın, designed to help people discover the characteristics they are curious about regarding people in their social circles, share their impressions of each other, and transform relationship dynamics into an entertaining, viral experience. This Privacy Policy explains how your personal data is collected, processed, stored, shared, and protected when you use the Application.

This Privacy Policy has been prepared in compliance with the Turkish Personal Data Protection Law No. 6698 (KVKK), the principles of the European Union General Data Protection Regulation (GDPR), Apple App Store Review Guidelines (Section 5.1), and Google Play Developer Policy (User Data policy) requirements.

By using the Application, you represent that you have read, understood, and accepted this Privacy Policy.


2. Data Controller

Data Controller: Barış Altın
📧 Email: hello@povl.app
📍 Country: Turkey

You may contact us using the information above for any questions, requests, or complaints regarding the processing of your personal data.


3. Data Collected

3.1 Data Collected Directly from You

Data CategoryData CollectedPurpose
Account InformationName/surname, email address, profile photo (via Google or Apple Sign-In)Account creation and authentication
Profile InformationDisplay name, profile photo (optional change), friend codeIn-app profile and social features
Personality Analysis DataAnalysis Subject Label: A symbolic nickname or label assigned by the User in their own mind to identify the analysis account (This data is not based on a real person's identity verification).
Trait Ratings: Subjective evaluation scores ranging from 1-20.
Creating personality analysis reports and profile differentiation
Circle DataCircle connections, friend code sharing, mutual/transparent analysis preferencesSocial connection and circle features
Partner Matching DataInvitation codes, invitation statuses, matching informationPartner matching feature
Discovery DataAnswers to daily discovery questions, streak trackingEnriching analysis profiles
Notification PreferencesPush notification permission, notification tokenNotification services
Reporting DataReported content, report reason, descriptionContent moderation and user safety
Purchase DataCredit purchase history, transaction recordsCredit system management

3.2 Automatically Collected Data

Data CategoryData CollectedPurpose
Device IdentifiersIDFV (iOS) or Android ID, platform information (iOS/Android)Preventing welcome bonus abuse
Application Usage DataSession duration, feature usage frequency, error logsImproving service quality
IP AddressConnection IP address (in server logs)Security and abuse prevention

3.3 Data We Do Not Collect

For the sake of transparency, we do not collect the following data:


4. Purposes and Legal Bases for Data Processing

4.1 Processing Purposes

We process your personal data for the following purposes:

PurposeDescriptionLegal Basis
Service ProvisionCreating personality analysis reports, circle features, partner matchingPerformance of contract
Account ManagementAccount creation, authentication, profile managementPerformance of contract
SecurityDetecting fake accounts, preventing welcome bonus abuse, blocking systemLegitimate interest
Content ModerationReviewing reported content, ensuring compliance with community rulesLegitimate interest / Legal obligation
NotificationsMutual analysis results, circle requests, achievement notificationsExplicit consent
ImprovementImproving service quality and user experience (analysis with anonymized data)Legitimate interest
Legal ObligationsLegal regulations and requests from authorized bodiesLegal obligation

4.2 Algorithmic Data Processing

POVL processes the rating data entered by Users to create personality analysis reports. In this process:

Important: Analysis results generated by algorithmic systems are for entertainment purposes and do not constitute a scientific assessment.


5. Data Sharing

5.1 When Data Is Shared

We do not share your personal data with third parties except in the following circumstances:

Sharing ScenarioDescription
In-App SharingMutual or transparent analysis results are shared only with the relevant Circle members. This sharing depends on your preferences (transparent/mutual mode selection).
Infrastructure and Server ServicesSupabase (Database) and Expo (Notification Service). To ensure uninterrupted service delivery on a global scale, your data may be stored in encrypted form on secure cloud servers located abroad (EU or US) that maintain high security standards. By using the Application, you are deemed to have consented to this technical transfer.
Authentication ProvidersGoogle Sign-In and Apple Sign-In are used for authentication purposes. Only the minimum necessary information (authentication token) is shared with these providers.
Legal RequirementWe may be required to share your data pursuant to applicable laws, court orders, or requests from authorized bodies.
Transfer of RightsIn the event of a company merger, acquisition, or asset sale, your personal data may be transferred to the acquiring party. Prior notice will be provided in such cases.

5.2 What We Never Share


6. Data Retention

6.1 Retention Periods

Data TypeRetention Period
Account DataFor as long as the account exists. (Data is retained for service continuity unless the User requests account deletion).
Analysis DataFor as long as the account exists. (Immediately destroyed when the User deletes the report or account).
Circle DataFor as long as the connection is active (deleted when the connection or account is deleted)
Device FingerprintsFor as long as the account exists and, in cases of suspected fraud, for the duration of the legal statute of limitations (10 years).
Reporting DataFor as long as the account is active and for the duration of the legal dispute statute of limitations (10 years)
Transaction Records10 years pursuant to legal requirements and tax regulations
Server Logs90 days

6.2 Post-Retention

Data that has exceeded its retention period is permanently deleted automatically or within 30 days at the latest, or anonymized in an irreversible manner.


7. Data Security

We implement the following technical and administrative measures to ensure the security of your personal data:

7.1 Technical Measures

7.2 Administrative Measures

7.3 Data Breach Notification

In the event that a security breach affecting your personal data is detected:


8. User Rights

8.1 Your Rights Under KVKK

You have the following rights pursuant to Article 11 of the Turkish Personal Data Protection Law No. 6698 (KVKK):

  1. Right to Information: To learn whether your personal data is being processed.
  2. Right of Access: To request information regarding the processing of your personal data.
  3. Right to Rectification: To request the correction of personal data if it has been processed incompletely or inaccurately.
  4. Right to Erasure/Destruction: To request the deletion or destruction of your personal data when the purpose for processing no longer exists.
  5. Right to Object: To object to results that arise against you through the exclusive analysis of processed data via automated systems.
  6. Right to Compensation: To seek compensation for damages arising from the unlawful processing of personal data.
  7. Right to Data Portability: To receive your personal data in a structured, commonly used, and machine-readable format.

8.2 Additional Rights Under GDPR (EU/EEA Users)

Additional rights for users residing in the European Union or European Economic Area:

8.3 How to Exercise Your Rights

To exercise the rights listed above:

We may request additional information for identity verification purposes.


9. Account Deletion and Data Removal

9.1 Account Deletion

You can delete your account at any time from within the Application:

Settings > Account > Delete My Account

9.2 Scope of Deletion

When you delete your account, the following data is permanently deleted:

9.3 Data Retained After Deletion

The following data may be retained for a limited period for legitimate purposes:

9.4 Deletion Timeline

Your data will be permanently deleted within 30 days after receiving your account deletion request. If you wish to recover your account within this period, you can contact us via email.


10. Children's Privacy

10.1 Age Restriction

POVL is designed for users over the age of 13. We do not knowingly collect personal data from children under the age of 13.

10.2 Detection of Child Data

If we discover that we have collected personal data from a user under the age of 13:

10.3 Parent/Guardian Notification

If you believe your child is under the age of 13 and is using the Application, please immediately contact us at hello@povl.app.


11. International Data Transfers

11.1 Data Processing Location

Your data is processed through the Supabase infrastructure. Supabase servers may be located in different regions. When your data is processed outside of Turkey, we ensure that appropriate security measures are in place.

11.2 Security Measures

For international data transfers:


12. Cookies and Tracking Technologies

12.1 Mobile Application

POVL is a mobile application and does not use traditional web cookies. However, we may use the following similar technologies:

12.2 Third-Party Tracking

POVL does not use third-party ad tracking SDKs (Facebook SDK, Google Ads SDK, etc.). We do not track your user behavior for advertising purposes and do not collect your advertising identifier (IDFA/GAID).


13. Push Notifications

13.1 Notification Types

POVL may send push notifications in the following situations:

13.2 Notification Control

You can manage push notification permissions at any time from your device settings:

Disabling notifications does not affect the core functionality of the Application.


14. Apple and Google Specific Privacy Requirements

14.1 Apple App Tracking Transparency (ATT)

POVL does not engage in tracking under Apple's ATT framework. We do not access your device's advertising identifier (IDFA) and do not perform cross-app/website tracking.

14.2 Apple Privacy Nutrition Label

Our privacy label on the App Store reflects the following data collection categories:

14.3 Google Play Data Safety

Our data safety section on the Google Play Store includes the following information:


15. Third-Party Service Providers

We work with the following third-party service providers, and these providers may interact with your data:

ProviderPurposeData ProcessedPrivacy Policy
SupabaseDatabase, authentication, server functionsAccount information, analysis data, application datasupabase.com/privacy
Google Sign-InAuthenticationGoogle account token, name, emailpolicies.google.com/privacy
Apple Sign-InAuthenticationApple ID token, name, email (hiding option available)apple.com/legal/privacy
ExpoPush notifications, application distributionPush token, device informationexpo.dev/privacy

These providers process your data solely for the stated purposes and are subject to their own privacy policies.

Note: The service providers listed above act as Data Processors and process your data solely in accordance with our instructions, under contractual data protection safeguards (DPA).

16. Data Protection Impact Assessment

When adding new features or data processing activities, we conduct a Data Protection Impact Assessment (DPIA) to evaluate potential privacy risks. This assessment covers:


17. Request Response Time

Response times for personal data requests:

Request TypeResponse Time
Information / AccessWithin 30 days at the latest
RectificationWithin 30 days at the latest
Deletion (in-app)Immediate (permanent deletion within 30 days)
Deletion (email request)Within 30 days at the latest
ObjectionWithin 30 days at the latest
Data portabilityWithin 30 days at the latest

In the case of complex or numerous requests, we may extend this period up to 60 days, provided we inform you.


18. Policy Changes

We may update this Privacy Policy from time to time. In the event of significant changes:

Your continued use of the Application after the changes constitutes acceptance of the updated Privacy Policy.


19. Complaints and Applications

19.1 Contact Us

For all complaints and applications regarding the processing of your personal data:

📧 Email: hello@povl.app

All applications will be responded to within 30 days at the latest.

19.2 Supervisory Authority

If the outcome of your application is not satisfactory, you may apply to the following authorities:


20. Contact

If you have any questions, concerns, or requests regarding this Privacy Policy:

Barış Altın
📧 Email: hello@povl.app
📍 Country: Turkey