Privacy Policy
1. What Does This Policy Cover?
The Tatonia platform explains on this page which data it collects and for what purpose, how it protects that data, and which third-party services it uses. This policy applies to all processing activities under the KVKK and should be read together with the KVKK Disclosure Notice.
2. Use of Cookies
The platform uses functional cookies only; no advertising or third-party tracking cookies are run. For more detail, please see the Cookie Policy page.
- Session cookies: to remember that you are signed in. Deleted when the session ends.
- Preference cookies: to remember your theme (light/dark mode) and language choice
- Form security cookies: prevent abuse of form actions such as commenting and registration
You can reject cookies from your browser settings; however, in that case functions such as signing in and saving preferences may not be available.
3. Data Security
For detailed technical measures, you can refer to the Security page.
- All traffic is transmitted over HTTPS (TLS 1.3).
- Passwords are hashed with the bcrypt algorithm and are never stored or logged as plain text.
- In OAuth integrations (Google), your password is not sent to us; only an account-linking identifier is kept.
- Database access is made only from the platform servers and to the extent necessary; manual access is logged.
- For security incidents, 24/7 error/anomaly monitoring is active on Sentry.
4. Third-Party Processors
The following infrastructure providers are used to deliver the platform services. Each is subject to its own data processing policy.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Hosting, CDN | USA/EU |
| Neon | PostgreSQL data storage | EU (London) |
| Cloudflare | DNS, DDoS protection | Global |
| Google OAuth | Optional authentication | Global |
| Resend | Email delivery (verification, reset) | EU |
| Sentry | Error monitoring (PII filtered) | EU |
| Upstash Redis | Rate limiting | Global |
| Apple APNs | iOS push notification delivery (mobile app) | USA/EU |
| Google FCM | Android push notification delivery (mobile app) | Global |
| Expo Push Service | APNs/FCM bridge, push token management (mobile app) | USA |
The Apple, Google, and Expo rows apply only to users who use the mobile app and consent to push notifications; the push notification infrastructure does not run in the web version.
5. User-Generated Content (UGC)
The adaptations, comments, and collections you share may be visible to other users. Our content moderation is two-layered: automated (slang/spam/repeated-character filter) and manual (admin queue). Public content that passes admin approval may be used in statistics in anonymized form.
6. Mobile App Data
The Tatonia mobile app (iOS + Android) may process data in the following categories in addition to the web version. These operations apply only to users who install and use the mobile app; all push, biometric, and device identifier operations depend on user consent and can be disabled on request.
- Push notification token: When the user approves the push permission, the anonymous device token generated by Apple APNs or Google FCM is stored in the database, linked to the account. The token is used only to send app notifications; it is not sold to third parties or shared for marketing purposes. When notification consent is removed from within the app or from device settings, the token is deleted immediately. Legal basis: KVKK 5/2-f (legitimate interest) and explicit consent.
- Biometric authentication: If you prefer Touch ID, Face ID, or Android biometric, authentication happens on your device; biometric data (fingerprint, face map) never leaves your device and is not transmitted to our servers. Only the authentication result (success/failure) is processed locally.
- Device identifier: The app may use an anonymous identifier per device (Expo application ID or Android ID) for session security and push notification matching. This identifier is not used for advertising tracking and is not transferred to third parties.
- Crash and performance data: To fix app errors, anonymized crash reports and performance metrics are collected with Sentry React Native (App Store nutrition label classification: “Crashes, Linked to You: No” + “Diagnostics, Linked to You: No”). Personal content, screenshots, or location data are not included in the reports.
- App Tracking Transparency (iOS): The Tatoniamobile app does not perform cross-app tracking of users, does not use the IDFA, and does not send data to ad networks. For this reason the iOS ATT prompt (the “App would like to track you” modal) is not shown.
- Location data: The app does not request location permission and does not collect GPS data.
- Photo upload (Phase 2): When recipe photo sharing is added in the future, only the image selected by the user is uploaded; the camera/gallery permission can be revoked, and past uploads can be deleted via Settings.
You can withdraw mobile push notification consent at any time from device settings or the in-app profile page. When you delete your account, all device data including the mobile push token record is permanently deleted according to the rules in section 8.
7. Children’s Privacy
The platform is not designed for users under the age of 13. Alcoholic recipes are additionally protected with age verification. If you believe the personal data of a child under 13 has been collected without permission, please contact us.
8. Data Deletion
You can delete your account from the Settings page. The deletion is completed instantly and irreversibly: your account information, session/log records, and your adaptations and comments are permanently deleted from the DB. Your published public recipe contributions (a rare case; community adaptations are separate) may remain with identity information anonymized. Anonymous statistical data may be retained under Article 28 of the KVKK. If a copy exists in backup systems, it is also cleared from backups within the rotation period (at most 90 days).
9. Updates
This policy may be updated over time. For material changes, a notification is sent to your registered email address. The current version is always published on this page.
For questions about privacy, you can reach us through our Contact page or write to [email protected].