Whiscret Privacy Policy
Last updated: 10 September 2026
This policy explains what personal data Whiscret collects, why, on what legal basis, how long we keep it, who we share it with, and what rights you have. It applies to everyone who uses https://whiscret-production.up.railway.app (or any domain we later move to), whether or not you have an account.
We wrote it to meet the EU General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law No. 6698 (KVKK). Turkish-speaking users can also read our KVKK disclosure notice (Aydınlatma Metni), which presents the same information in the format Turkish law requires.
1. Who is responsible for your data
The data controller is Talha Orak, an individual developer based in Türkiye.
- Email: talhaorak@gmail.com
- Address: Türkiye
We have not appointed a data protection officer; write to the email above for anything privacy-related.
2. In short
- We collect only what Whiscret needs to work: your account, your profile, the questions and answers you exchange, and a small amount of safety data on each question.
- We do not sell your data, show ads, or use third-party analytics or tracking cookies. If we add analytics later, we will ask for your consent first.
- Anonymous means anonymous: the recipient of an anonymous question never sees who asked it. We disclose an asker's identity only when the law or a competent authority requires it.
- Your data is stored on servers in the European Union (Supabase in Frankfurt, Germany; Railway in Amsterdam, Netherlands).
- You can delete your account yourself in Settings at any time.
3. What we collect, why, on what basis, and for how long
"Contract" below means GDPR Art. 6(1)(b) and KVKK Art. 5(2)(c): the processing is needed to provide the service you asked for. "Legitimate interest" means GDPR Art. 6(1)(f) and KVKK Art. 5(2)(f). "Legal obligation" means GDPR Art. 6(1)(c) and KVKK Art. 5(2)(ç). "Consent" means GDPR Art. 6(1)(a) and KVKK Art. 5(1).
| What we collect | Why | Legal basis | How long |
|---|---|---|---|
| Account data: email address, password (stored only as a hash by Supabase Auth), username, sign-up date, and the record that you accepted the Terms and confirmed your age | To create and secure your account, sign you in, send account emails (confirmation, password reset, security notices) | Contract; legal obligation (keeping proof of consent and age confirmation) | Until you delete your account |
| Profile data (public): avatar image, bio, links to Instagram, TikTok, YouTube or a website | To show your public profile | Contract | Until you remove it or delete your account |
| Questions you send: text, time sent, whether you chose anonymity, and, if you were signed in, your account ID | To deliver the question to the profile owner; to let them answer; to handle abuse | Contract (signed-in users); legitimate interest in delivering a question you asked us to deliver (guests) | Until the recipient deletes the question or their account. The link to your account ID is removed when you delete your account |
| Answers and published Q&A: the answer text and time, shown with the question on your profile and in the public feed | To publish what you choose to publish | Contract | Until you delete the answer or your account |
| Abuse-prevention data on each question: a keyed hash (HMAC) of the sender's IP address, which cannot be turned back into the address; the sender's country code; a shortened browser identifier (user agent) | To detect and limit spam, harassment and repeat abusers; to meet traffic-record obligations under Turkish Law No. 5651 | Legitimate interest (keeping the service safe, GDPR Recital 49); legal obligation | Up to 24 months. [LEGAL REVIEW: confirm the period required by Law No. 5651 and its regulation for a service like Whiscret] |
| Moods: the mood you post and its time | To show it on your profile for 24 hours | Contract | Shown for 24 hours; removed with your account at the latest |
| Spotify link (optional): OAuth access and refresh tokens and your Spotify account identifier. Now-playing, recently-played and public-playlist information is fetched from Spotify to display on your profile | To show what you are listening to | Consent (you connect the account; you withdraw by unlinking) | Tokens until you unlink or delete your account |
| X (Twitter) link (optional): OAuth tokens and your X account identifier; the answers you choose to cross-post are sent to X | To post answers to X on your behalf | Consent (you connect the account; you withdraw by unlinking) | Tokens until you unlink or delete your account |
| Notifications: in-app notification records (what happened, when, whether you read it); your email-notification setting | To notify you of new questions and answers in the app and, if you keep it on, by email | Contract | Until you delete your account; you can turn email notifications off at any time |
| Cookie choice: whether you chose "only necessary" or "allow analytics" | To remember your choice and not ask again | Legal obligation (recording consent decisions) | 12 months |
| Server logs: IP address, requested page, time, browser identifier, response status and error details | To keep the service running securely, investigate incidents and fix bugs | Legitimate interest (security and reliability) | 30 days |
| Correspondence: emails you send us, including reports, rights requests and any information we need to verify your identity | To answer you, handle reports and rights requests, and show that we did so | Legal obligation (rights requests); legitimate interest (support, defending claims) | As long as needed to handle the matter and to demonstrate compliance, then deleted |
We do not knowingly collect special categories of data (health, religion, sexual orientation, and so on). Please do not put such information in your bio, questions or answers; if you do, you are choosing to make it public.
4. Where the data comes from
- From you, when you sign up, fill in your profile, post answers and moods, or contact us.
- From other people, when they send you questions.
- From Spotify or X, only if you link those accounts and only the data described above.
- Automatically, when you use the service (abuse-prevention data on questions, server logs, cookies described in the Cookie Policy).
5. What is public
Your username, avatar, bio, links, moods, answered questions with their answers, and (if linked) your Spotify listening information are visible to anyone on the internet, including people without an account and search engines. Unanswered questions are visible only to you. Your email address, your settings, unanswered questions, abuse-prevention data and OAuth tokens are never public.
6. How anonymity works
- When a question is sent anonymously, the recipient sees only the question. They never see the asker's username, email, IP address or any other identifier.
- We keep the asker's account ID (if signed in) and the hashed IP, country code and browser identifier with the question so that we can act against spam and abuse. Nobody outside Whiscret's operator sees this data.
- We disclose an anonymous asker's identity only when the law requires it or a competent authority (such as a court or prosecutor acting under Turkish or EU law) orders us to. We check every such request before responding and disclose only what is required.
7. Who we share data with
We use the following service providers (processors) that process data on our instructions:
| Provider | What they do | Where |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage (avatars), account emails | Project hosted in the eu-central-1 region (Frankfurt, Germany); data processing agreement with EU standard contractual clauses in place |
| Railway Corp. | Runs the Whiscret application | Amsterdam, Netherlands (Railway region europe-west4). [LEGAL REVIEW: confirm the data processing agreement] |
| Spotify AB | Provides your listening data when you link Spotify | Sweden (EU). Only if you link your account |
| X Corp. | Receives the answers you cross-post when you link X | United States. Only if you link your account |
We also disclose data:
- to courts, prosecutors, data protection authorities or other public bodies when a valid legal request under Turkish or EU law requires it;
- to a successor if Whiscret is transferred to another operator, after telling you.
We do not sell personal data. We do not share it with advertisers or data brokers. We do not use third-party analytics today; if we add analytics in future, it will run only with your consent and this policy will be updated first.
8. International transfers
- Your data is stored in the European Union (Germany and the Netherlands).
- We, the controller, are based in Türkiye and access the data from there to operate the service. Türkiye is not covered by an EU adequacy decision. [LEGAL REVIEW: confirm the transfer mechanism for the controller's own access from Türkiye, e.g. GDPR Art. 49(1)(b) necessity for the contract with the user, or standard contractual clauses with the processors]
- If you link X, the answers you cross-post and your X tokens are sent to X Corp. in the United States under X's own transfer safeguards.
- For users in Türkiye: storing data with Supabase (Germany), Railway (EU), Spotify (Sweden) and X (USA) is a transfer abroad under KVKK Art. 9. We rely on appropriate safeguards (standard contracts published by the Personal Data Protection Board, notified to the Board) and, for Spotify and X, on the fact that you initiate the link yourself. [LEGAL REVIEW: confirm the KVKK Art. 9 mechanism and complete the Board notification]
9. How long we keep data and what happens when you delete your account
The table in Section 3 gives the period for each type of data. When you delete your account (Settings, or by emailing talhaorak@gmail.com):
- your profile, account data, moods, answered and unanswered questions on your profile, notifications and any Spotify/X tokens are deleted;
- questions you sent to other users stay on their profiles (they are the recipient's content) but are no longer linked to your account;
- abuse-prevention data on questions is kept for the period in Section 3 without any link to your account;
- copies may remain in encrypted backups for a limited time before being overwritten;
- server logs expire after 30 days.
10. Security
Passwords are stored only as salted hashes. Connections use TLS. Database access is restricted with row-level security so that users can only read what they are allowed to see. OAuth tokens are stored server-side and never sent to browsers. IP addresses on questions are stored only as keyed hashes. If a security breach affects your data, we will notify the competent authority and, where the law requires, you.
11. Your rights
Under the GDPR and KVKK you have the right to:
- access the personal data we hold about you and get a copy;
- rectification of inaccurate or incomplete data (most profile data you can edit yourself in Settings);
- erasure (delete your account in Settings, or ask us by email);
- restriction of processing in certain cases;
- portability: receive the data you gave us in a structured, machine-readable format;
- object to processing based on legitimate interest, on grounds relating to your situation;
- withdraw consent at any time where processing is based on consent (for example by unlinking Spotify or X), without affecting processing before withdrawal;
- learn whether your data has been transferred abroad and to whom, and ask us to inform recipients of corrections or deletions (KVKK Art. 11);
- complain to a supervisory authority.
To exercise a right, use Settings where possible or email talhaorak@gmail.com from the address on your account. We may ask you to confirm your identity. We respond within one month (GDPR), which may be extended by two more months for complex requests, and in any case within 30 days for KVKK applications. Exercising your rights is free.
Complaints: in Türkiye, to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu, https://www.kvkk.gov.tr). Under KVKK Art. 14 you must apply to us first; you may complain to the Board within 30 days of our reply, or within 60 days of your application if we do not reply. In the EU or EEA, to the data protection authority of the country where you live or work (list at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en).
12. Children
Whiscret is not for children under 15, in line with Turkish Law No. 7578. In the EU/EEA, users under 16 may use Whiscret only with the agreement of a parent or guardian. We record your age confirmation at sign-up and may ask for age verification where the law requires it. If we learn that an account belongs to a child under 15, or to an EU/EEA user under 16 without parental agreement, we delete it. Parents and guardians can contact us at talhaorak@gmail.com.
13. Cookies and local storage
We use only strictly necessary cookies (your sign-in session, short-lived cookies during Spotify/X linking, and the cookie that records your cookie choice) and two browser-storage entries for your theme and panel layout. No tracking or advertising cookies. Details are in the Cookie Policy.
14. Automated decisions
We do not make decisions about you by automated means that have legal or similarly significant effects, and we do not profile you. Automated rate limits based on the hashed IP address may temporarily block sending questions to prevent spam; you can contact us if you think this happened by mistake.
15. Changes to this policy
We will update this policy when the service or the law changes. For material changes we will tell you in the app and/or by email before they take effect. The date at the top shows when the policy was last changed.
16. Contact
Talha Orak · talhaorak@gmail.com · Türkiye