← Back to home

Privacy Policy

Last updated:

This policy explains which personal data is processed, for what purposes and on which legal basis when you use the Ravu mobile app and the ravuapp.com website. It was written with both Türkiye's Personal Data Protection Law No. 6698 (KVKK) and the EU General Data Protection Regulation (GDPR) in mind. By using Ravu you acknowledge that you have read this policy.

1. Data controller and contact

The controller of your personal data is Adem Özmermer, an individual developer based in Türkiye. Ravu is published directly by its developer, not by a company.

For any privacy question, request or complaint: destek@ravuapp.com. Requests are answered within 30 days at the latest.

2. Scope

This policy covers the Ravu app for iOS and Android (package name com.ravu.ravu), the backend service at api.ravuapp.com and the ravuapp.com website. Services run by third parties such as Apple and Google (sign-in, store, payments) are governed by their own privacy policies.

3. Data we process

Ravu collects only what the app needs in order to work. The categories are:

  • Account identity: when you sign in with Apple or Google, the user identifier and e-mail address the provider gives us (a relay address if you use Apple's "Hide My Email"). The username, display name, avatar and bio you set in Ravu.
  • Birth details: your date, time and place of birth, used to compute your natal chart. The chart is computed on your device; the birth details you enter are synced to your account so the chart survives a change of phone.
  • Content you share: posts, replies, likes, zodiac-group and direct chat messages, and the images you upload.
  • Device data: push notification token, platform (iOS/Android), app version and time zone. These are used to deliver notifications to the right device at the right hour.
  • Diagnostics: crash reports sent to Sentry when the app crashes. Reports contain a pseudonymous user id, device model and OS version; they do not contain your e-mail address.
  • Subscription status: the product id, start/expiry dates and trial information reported by the App Store or Google Play. Your payment card details never reach Ravu; payment is handled entirely by the store.

Ravu does not track your location, read your contacts, collect an advertising identifier or embed any third-party analytics or advertising SDK.

4. Purposes and legal bases

We process your data for the following purposes, relying on the bases in Article 5 KVKK and Article 6 GDPR:

  • Providing the service (creating your account, syncing your chart, feed and chat, notifications): performance of a contract.
  • Managing Premium subscriptions (verifying purchases, unlocking features): performance of a contract and legal obligation.
  • Security and abuse prevention (detecting spam, harassment and fake accounts, moderation): legitimate interest.
  • Debugging and stability (crash reports): legitimate interest.
  • Legal obligations (requests from competent authorities, accounting records): legal obligation.
  • Promotional notifications (announcing new features): consent; you can withdraw it at any time through notification permissions.

Birth details are not a special category of data under KVKK, but we treat them as sensitive: they are used solely for computing and syncing your chart and are never processed for profiling or advertising.

5. Where data is processed and international transfers

Ravu's servers run in DigitalOcean's Frankfurt (Germany) data centre. Images you upload are stored on Cloudflare R2 in the European Union region and served through cdn.ravuapp.com. Crash reports are kept in Sentry's EU region.

For a controller based in Türkiye this counts as an international transfer under Article 9 KVKK. Transfers are safeguarded by their necessity for providing the service, data processing agreements with each provider and the EU Standard Contractual Clauses. Data shared with Apple and Google (sign-in identity, subscription status, notification delivery) is processed on their global infrastructure under their own privacy policies.

We do not transfer personal data outside Türkiye and the EU for any other purpose.

6. Retention

  • Account data (identity, profile, birth details, subscription status): for as long as your account exists.
  • Account deletion: when you choose Settings → Delete account, your account is frozen for 30 days; during that period you can cancel the deletion by signing in again. At the end of day 30 the account, birth details, device tokens and uploaded images are permanently erased.
  • Posts and chat messages: content you own is deleted with your account. So that other people's conversations still make sense, your messages in group chats and your replies to other users' posts may be kept in anonymised form ("Deleted user") where necessary; that content can no longer be linked to you.
  • Crash reports: 90 days in Sentry.
  • Server access logs (IP address, request time): at most 30 days, for security purposes.
  • Backups: encrypted database backups are kept for at most 30 days; deleted data leaves the backups at the end of that period.

7. Sharing

We do not sell or rent your personal data and never share it for advertising. Data is shared only with the processors below, which we need in order to run the service, and only to the extent each task requires:

  • DigitalOcean (Frankfurt, Germany): application server and database hosting.
  • Cloudflare (EU region): image storage (R2) and content delivery.
  • Sentry (EU region): crash and error reporting.
  • Apple: Sign in with Apple, App Store subscriptions, notification delivery through the Apple Push Notification service.
  • Google: Sign in with Google, Google Play subscriptions, Android notification delivery through Firebase Cloud Messaging.

Beyond these, your data is disclosed only where the law requires it (a court order or a request from a competent authority) and only to the extent of that request. Other users can see your public profile and the content you share inside the app.

8. Your rights

Under Article 11 KVKK and Articles 15–22 GDPR you have the following rights:

  • Access: learn which of your data is processed and request a copy. In the app, Settings → Export my data lets you download your data yourself.
  • Rectification: you can change your profile and birth details in the app at any time.
  • Erasure: Settings → Delete account removes your account and data (the 30-day grace period is described in section 6). You can also freeze your account temporarily without deleting it.
  • Objection and restriction: you may object to processing based on legitimate interest and, in certain cases, ask for processing to be restricted.
  • Portability: exported data is provided in a machine-readable (JSON) format.
  • Withdrawing consent: notification permissions can be switched off in your device settings at any time.

Send your requests to destek@ravuapp.com; to verify your identity we may ask you to write from the e-mail address linked to your account. If you are not satisfied with the outcome, you have the right to lodge a complaint with the Turkish Personal Data Protection Board (KVKK Kurulu) or, if you live in the European Union, with your local supervisory authority.

9. Security

All data in transit is encrypted with TLS. Session tokens are stored encrypted on the server and rotated on a schedule; there is no Ravu password, authentication is delegated to Apple and Google. Server access is limited to key-based SSH behind a firewall, and only the application server can reach the database. Uploaded images are accepted only after their type and size are validated.

No system is completely secure. If we detect a security breach affecting your data, we will inform you and the relevant authorities within the legally required time frames.

10. Children

Ravu is not directed at children under 13 and we do not knowingly collect data from them. Because the app includes social features (feed, chat, messaging) we recommend it for users aged 16 and over. If we learn that a child under 13 has created an account we delete the account and its data; if you are aware of such a case, please write to us.

11. Website cookies

ravuapp.com uses a single cookie: the lang cookie that stores your language preference (tr or en, for 1 year). It does not track you, contains no identifier and is not shared with third parties. The site has no analytics, advertising or social-media trackers; everything, fonts included, is served from our own server.

12. Changes

We may update this policy as the app changes. For significant changes we will notify you inside the app and, where required, ask for your consent again. The current version is always published on this page; the date at the top shows the last update.

13. Contact

Data controller: Adem Özmermer, Türkiye. E-mail: destek@ravuapp.com.

← Back to home