⚠️ Draft — pending legal review. This is a draft and not legal advice. KVKK/GDPR obligations vary by market; have it reviewed by a lawyer before publishing. Highlighted fields must be filled in before going live.

Privacy Policy

Last updated: [EFFECTIVE_DATE]

Flanio ([COMPANY_NAME], "we") is a travel/discovery app. This policy explains what data we process, why, who we share it with, and your rights.

1. Data we collect

Account and identity. For guest use we create an anonymous user ID (UID). If you create a permanent account, your email and password (your password is held by our authentication provider; we do not separately store it), and a display name if provided. For session security, our authentication provider keeps audit logs that include your IP address and browser/device information.

Travel data. Trips you create; information such as destination, date preference, traveller/interest/pace notes, route, transport type and approximate budget preference.

Content. AI Travel Cards you generate; messages you write to the travel assistant; memory photos you add.

Usage/analytics (product_events). We measure in-app events (e.g. the card-generation flow). These records are not fully anonymous — they can be technically linked to your account (pseudonymous). You can turn analytics off in settings.

Location. With your permission we use your location to show nearby places; this is not stored in our app database and is used momentarily for the request.

Device/technical. For service operation, security and diagnostics we process IP address, request/session metadata and server logs.

Permissions. Camera and photo access (photos/translation), location, notifications, storage (saving to gallery).

2. Data that stays on your device

Some features run entirely on your device and are not sent to our servers: your Travel DNA answers and preference profile; your memory timeline; the memory photos you add (not uploaded to the cloud); and photo translation — text recognition (OCR) and translation happen on your device; your image/text is not sent anywhere (only a translation language pack is downloaded on first use; no user data is sent).

Important: Trips you create without signing in (as a guest) are saved to the cloud (under your anonymous ID) — they do not stay only on your device.

3. How we use data

To provide and personalize the service; to generate AI Travel Cards and voice/text content; to run the travel assistant; to operate the Flân Puan economy; for security, fraud prevention and diagnostics; and for product measurement (analytics).

4. Third parties

We do not sell your data. To provide the service we use:

5. AI features

For AI Travel Cards, limited route/season information is sent to OpenAI (without identity). For the travel assistant, your messages and trip context are sent to Anthropic. These providers have their own retention periods (typically time-limited). If you do not use AI features, these transfers do not occur.

6. Retention

7. Your rights and controls

8. Security

Your session keys are held in your device's secure store (iOS Keychain / Android Keystore). Data is encrypted in transit (HTTPS). Database access is restricted with row-level security (RLS). No method is 100% secure.

9. Children

Flanio is not designed for people under [MINIMUM_AGE]; we do not knowingly collect data from anyone under this age.

10. International transfers

Some of our providers (OpenAI, Anthropic, Mapbox, Supabase) may process your data outside your country (e.g. the US). [If GDPR applies: appropriate transfer mechanism — clarify.]

11. Changes

We may update this policy; we will notify you of material changes appropriately.

12. Contact

Questions: info@flanio.com.tr.

13. Language

This policy is prepared in Turkish and may also be provided in other languages. Non-Turkish versions are for information only; in case of any conflict or difference in interpretation, the Turkish version prevails.