Privacy Policy
Your WhatsApp chat file never leaves your phone.
The file is read, masked and summarized entirely on your device; the raw chat text is never stored on our servers.
This Privacy Policy explains what data we process when you use the Chat Moments mobile app (the “app”, published in Turkish as “Sohbet Doktoru”), where that data goes, and how long it is kept. The data controller is Nursel Bayrak (Türkiye). Questions: support@sohbetdoktoru.com.
1. Data we collect
The app works without an account. The only identifier you share with us is an anonymous user ID created automatically on Supabase the first time the app opens (anonymous auth UUID). It is not linked to your name, email or phone number, and it is regenerated when you delete and reinstall the app.
1.1. Data processed only on your device
- Your WhatsApp chat file — the
.txt/.zipexport you choose is processed entirely on your device and is never uploaded as a whole. The chat text is masked on your device (phone numbers, email addresses, IBANs and other bank details, national ID / Social Security / National Insurance numbers, postal codes and street addresses, social-media handles, one-time codes) and summarized. The app never asks for or collects your date of birth, contacts, or location.
1.2. Data sent to our servers
- The masked, summarized chat sample (participant names replaced with pseudonyms such as “Member 1”, “Member 2”).
- Your anonymous user ID (Supabase anonymous auth).
- Usage events (e.g. screen opened, analysis started, report viewed) and technical metadata about AI calls (provider, duration, success, token counts, chat language). These records are tied to your anonymous user ID and contain no chat content, names or messages — counts and status only.
- Ad-measurement events (app install and steps such as viewing a report or completing a purchase), a device identifier and general device information — solely to measure the performance of our own ads. The identifier depends on the operating system: on iOS only the app-scoped IDFV; on Android Google’s resettable advertising ID (AAID) and the Google Play install referrer. See Section 2, AppsFlyer.
Your real name is never sent to the AI model in any analysis (it is replaced with an anonymous code on your device). Phone numbers, email addresses, bank details and similar personal data inside the chat text are masked on your device on a best-effort basis.
2. Where your data goes
- Chat Moments AI proxy (runs on Vercel) — forwards the masked analysis request to the selected large language model (Google Gemini or OpenAI). The proxy does not store the chat text; it only relays the request. Call metadata kept for debugging and service quality (provider name, duration, success, token counts — not chat content) is stored in Supabase (Frankfurt, EU), linkable to your anonymous ID, and deleted automatically after 12 months.
- Google Gemini API — may be used to generate the report. Request content is processed by Google under the retention policy of the tier in use, subject to Google’s Gemini API Terms of Service.
- OpenAI API — may be used to generate the report. In production, requests are not stored by OpenAI (
store: false); OpenAI may still retain requests for abuse monitoring for up to 30 days under its data usage policy. - Sentry (sentry.io, EU) — crash and error reporting. Your anonymous device ID is attached to error events; no chat content, names or messages are sent, and events are scrubbed of personal data before leaving the device.
- Supabase (eu-central-1, Frankfurt) — holds only your anonymous user ID and the usage/call telemetry above. Your reports are never stored on Supabase or any other server of ours; they live only on your device. Access is restricted to your own anonymous ID by row-level security (RLS).
- Apple App Store / Google Play — in-app purchases (unlocking a full report) are handled entirely by the store; no payment or card details ever reach our servers.
- AppsFlyer — the ad-measurement service we use to measure our own advertising. It processes events such as app install and in-app steps (viewing a report, making a purchase) together with a device identifier and general device information. Your chat content, the names in it and your reports are never sent to this service. On iOS, measurement runs through Apple’s privacy-preserving SKAdNetwork and uses only the app-scoped IDFV; the cross-app advertising identifier (IDFA) is not read and no tracking permission is requested. On Android, measurement uses Google’s advertising ID (AAID) and the Google Play install referrer. The advertising ID is a shared, resettable identifier; although we use it only to answer “which ad did this install come from”, it is by nature an advertising identifier. You can reset or delete it at any time under Settings → Google → Ads; the app keeps working normally, only our ad measurement on that device becomes anonymous. The measurement outcome (e.g. “this install came from campaign X”) is reported back to the advertising platform — currently TikTok — and carries no chat content, names or report data. AppsFlyer processes this data on our behalf under its own privacy policy and protection obligations equivalent to this one.
Usage events are kept only on our own infrastructure (Supabase). The only third-party tools are the crash reporter Sentry and the ad-measurement service AppsFlyer (both described above); neither receives chat content or names. No Facebook, Google Analytics, Mixpanel or similar analytics/advertising SDK is integrated; the only thing that reaches an ad platform is the AppsFlyer measurement feedback described above. We never sell your data, and we do not “share” it for cross-context behavioral advertising in the sense of US state privacy laws (including the California CCPA/CPRA).
3. Retention
- AI call metadata (tied to the anonymous ID, no chat content; Supabase, EU): 12 months, deleted automatically.
- Usage/flow events (product telemetry tied to the anonymous ID; Supabase, EU): 12 months, deleted automatically.
- OpenAI abuse-monitoring logs: up to 30 days per OpenAI policy (only when OpenAI is the provider; request content is not stored in production).
- Sentry crash/error records: per Sentry’s retention policy; no chat content or names.
- AppsFlyer ad-measurement records: per AppsFlyer’s retention policy; no chat content, names or report data.
- Your reports: stored only on your device, never on our servers. If you delete the app or change phones, access to them ends; save a report as PDF for a permanent copy.
- Local data on your device: deleted the moment you uninstall the app, or earlier via Privacy → Delete all my data inside the app.
4. Children’s privacy
The app is for users aged 13 and over. We do not knowingly collect data from anyone under 13. If we learn that data belongs to a child under 13, we delete it promptly.
5. Your rights (GDPR / UK GDPR / US state laws / KVKK)
Depending on where you live, you have the right to:
- request a copy of the personal data we process about you (access / portability);
- request deletion;
- object to, or ask us to restrict, processing;
- request correction;
- not be discriminated against for exercising these rights (US state laws);
- lodge a complaint with your data protection authority (EU/UK residents).
Email your request to support@sohbetdoktoru.com together with your anonymous user ID, which you can find under Privacy inside the app. Because we hold no name, email or account for you, the anonymous ID is the only way we can locate your records. You can also delete everything yourself at any time from the same screen — that wipes local data and regenerates your anonymous ID, so remaining server-side telemetry can no longer be associated with you.
Legal bases (GDPR Art. 6): performance of the contract with you (generating the report you requested — Art. 6(1)(b)); your explicit consent, given in the app before any analysis, for sending the masked chat sample to a third-party AI provider (Art. 6(1)(a), withdrawable at any time by not running further analyses or by deleting your data); and our legitimate interests in keeping the service stable and measuring our own advertising (Art. 6(1)(f)).
6. Security
- All traffic is carried over HTTPS (TLS 1.2+).
- Requests to the AI proxy are authenticated with a shared secret app token (
x-app-token). - A 200 KB payload limit and a 60 requests/minute rate limit apply to every request.
- Row-level security on Supabase rejects any read/write whose anonymous user ID does not match.
7. International transfers
Our servers are in the European Union (Frankfurt, Germany). The data controller is established in Türkiye. Google Gemini, OpenAI, the ad-measurement service AppsFlyer and the advertising platform receiving measurement feedback (TikTok) may process data on servers in the United States or elsewhere outside the EU/UK; these transfers rely on the providers’ commitments under the European Commission’s Standard Contractual Clauses (SCC) and, where applicable, the UK International Data Transfer Addendum.
8. Changes to this policy
When we make a material change we update the date at the top of this page and, if needed, show a notice inside the app.