Privacy Policy
On this page
- 1. Data controller
- 2. What we process
- 3. How we collect it
- 4. On what legal basis
- 5. Audio recording — the sensitive part
- 6. Notifications — the first exception
- 7. Subscriptions — the second exception
- 8. Who we share it with
- 9. International transfers
- 10. Files you share — the third exception
- 11. Backups
- 12. Age and children's data
- 13. Retention
- 14. Security
- 15. Your rights (KVKK Art. 11 / GDPR)
- 16. Changes
1. Data controller
Yiğit Samet Ölmez (individual developer) Contact: ygtsmt2999@gmail.com
The address for formal notice is the one registered to the Apple developer account, shown on the App Store developer page.
2. What we process
Agubu keeps the following on your device only:
| Data | Why | Where |
|---|---|---|
| Baby's name (optional), date of birth, sex (optional), gestational weeks | To apply age-appropriate norms | On-device database |
| Sleep, nursing, bottle and diaper entries | Tracking and context estimates | On-device database |
| Cry analysis results and the context at the time | History and learning | On-device database |
| Your feedback ("right"/"wrong") | To tune predictions to your baby | On-device database |
| Language and theme preference | Interface | On-device database (with notifications on, the language is also passed to Google per §6) |
None of this reaches us. We operate no server; we have no technical means of access.
Some of it sits in the law's most protected category. Sleep, feeding and diaper entries, gestational weeks and cry analysis results may count as health data. That is precisely why none of it ever leaves your device. In legal terms: this data is special category personal data under KVKK Art. 6 and GDPR Art. 9; it is processed only with your explicit consent (KVKK Art. 6/2; GDPR Art. 9(2)(a)) and only on your device, and it is transferred to no third party and to no other country.
There is a second place inside your device. The home screen widget and the lock screen timer read from a shared area belonging to the app, so that they can show your sleep state. That area never leaves your phone either — but because your sleep and nursing timers appear on the lock screen, they can be read without unlocking the phone. If you would rather they were not, removing the widget from the home screen is enough.
3. How we collect it
It all comes from one place: the app itself. You enter the baby profile and the records by hand; the audio for cry analysis comes from your device's microphone; the push address is produced by Firebase's software library and the subscription details by the App Store and RevenueCat's software library.
In legal terms: all data is collected electronically, through the app's own interface, by automated and partly automated means. No data is obtained from third-party data brokers, social networks, advertising networks or publicly available sources.
4. On what legal basis
The plain version: you enter the records, you turn on the microphone, you turn on notifications, you buy the subscription. The legal version:
- Baby profile and records: so that the app can do the job it promised you — performance of the contract between us (KVKK Art. 5/2-c; GDPR Art. 6(1)(b)). For the part of it that may count as health data, your explicit consent (KVKK Art. 6/2; GDPR Art. 9(2)(a)).
- Audio recording: only when you press "Listen", on your explicit consent (KVKK Art. 5/1 and Art. 6/2; GDPR Art. 6(1)(a) and Art. 9(2)(a)).
- Push address: only if you allow notifications, on your explicit consent (KVKK Art. 5/1; GDPR Art. 6(1)(a)).
- Subscription verification: performance of your subscription (KVKK Art. 5/2-c; GDPR Art. 6(1)(b)) and financial record-keeping obligations (KVKK Art. 5/2-ç; GDPR Art. 6(1)(c)).
- Language and theme preference: legitimate interest in the app working properly (KVKK Art. 5/2-f; GDPR Art. 6(1)(f)).
Anything that rests on consent you can withdraw at any moment (§15). Withdrawing it does not make the processing that happened before the withdrawal unlawful.
5. Audio recording — the sensitive part
When you press "Listen":
- The microphone runs for 8 seconds.
- Audio is held in volatile memory (RAM) only — no file is created, nothing is written to disk.
- The analysis runs on a machine-learning model inside your device.
- The moment the analysis ends, the audio is discarded from memory.
- What remains is the result (e.g. "Hungry · 62%"), never the sound.
The microphone is never activated at any other time. There is no background listening.
The app can play audio in the background — so a lullaby keeps going with the screen locked. But it cannot record audio in the background. The microphone opens only when you say "Listen", and only for 8 seconds.
The audio is used to estimate what kind of cry this is, not to answer who is making it: no voiceprint is derived, nobody is identified, nothing is compared against any other voice. For that reason the recording is not processed as biometric data within the meaning of KVKK Art. 6 or GDPR Art. 9.
You can revoke microphone permission at any time in your device settings; the rest of the app keeps working.
6. Notifications — the first exception
The app's reminders (sleep window, forgotten entry, feedback prompt) are computed on your device and never leave it; no data is sent for them.
If you enable notifications, Firebase Cloud Messaging (Google) may additionally be used to deliver announcements. In that case the following reaches Google:
- The anonymous push token assigned to your device
- The installation ID generated by Firebase
- The IP address seen when the connection is made
- Technical details such as device model and app version
- Your device language (Turkish/English) — so announcements arrive in the right language. No other preference is sent.
None of this contains anything about your baby and none of it is linked to any database of ours — there is no account, so there is no identity to link it to. It is used solely to deliver announcements; your in-app behaviour is not tracked.
When you turn notifications off, we attempt to delete the push address. We cannot guarantee that the deletion completes on the provider's side in every case; according to Firebase's own documentation, removing the relevant record from live and backup systems at Google can take up to 180 days.
To be straight with you: the app currently ships without a Firebase configuration file, so this section is not actually in operation. Even if you allow notifications, nothing goes to Google. If that changes, we will announce it beforehand under §16. And if you never enable notifications, this section does not apply to you anyway.
7. Subscriptions — the second exception
If you buy a Premium subscription, the payment goes through Apple; your card details never reach us. To verify whether a subscription is active, we use a subscription platform called RevenueCat.
Let us say this plainly: the subscription layer starts up and assigns an anonymous subscriber ID to your device in two cases, even if you buy nothing:
- the first time you open the Premium screen
- at the end of the setup flow, to find out whether a free trial can be offered to you
Why the second one: only the store knows whether a trial exists. Showing an offer without asking would mean promising something that may not be there. What is sent in this step is limited to the list below as well; nothing about your baby is sent.
What RevenueCat receives is limited to:
- An anonymous subscriber ID assigned to your device (there is no account, so it is not tied to your name, email or your baby)
- The purchase event and Apple's receipt details: which product, when, how long the subscription runs, and the transaction ID Apple issued for it
- The IP address seen when the connection is made — the country is derived from it
- Technical details such as device model, OS version and app version
We do not have RevenueCat collect your advertising identifier or your vendor device identifier; we never call the software library's device-identifier collection function.
Nothing about your baby is sent. Your sleep entries, cry analyses and audio recordings are entirely outside this flow.
8. Who we share it with
Nobody, beyond what §6 and §7 describe. Your baby's records never leave your device, so there is nothing to share.
We use no third-party analytics tools that track user behaviour, no advertising networks, no crash reporting and no tracking software. The single exception is §7: RevenueCat shows us how many subscribers we have and how long subscriptions last — that is a purchase statistic, not in-app behaviour tracking. Which screen you opened, how many analyses you ran or which sound you played is sent nowhere.
Our agreements with the two services named in §6 and §7 (Google — Firebase Cloud Messaging, and RevenueCat) contractually require them to provide the same or equal protection of your data as this policy promises. Both may use what they receive only for the job we gave them; they may not use it for their own purposes, sell it, or process it for advertising. We give data to no third party that does not meet that condition.
9. International transfers
The plain version: the two exceptions in §6 and §7 are also transfers abroad. Your push address goes to servers operated by Google LLC (United States), and your subscriber ID and purchase record to servers operated by RevenueCat, Inc. (United States). Nothing else leaves Türkiye — none of your baby's records are part of these flows. Do neither, and no transfer takes place at all.
The transfer is governed by each provider's own data processing terms: the Firebase Data Processing and Security Terms for Google, and RevenueCat's Data Processing Addendum for RevenueCat. Both are published publicly and take effect through use of the service; each may process the data it receives only for the service it provides to us.
Avoiding the transfer entirely is in your hands: if you never enable notifications and never open the Premium screen, no data leaves the country.
10. Files you share — the third exception
If you choose to share the 30-day doctor report PDF or the night summary image, your device opens its own share sheet and the file leaves your device — but you do that, not us. No copy reaches us; where it goes and what happens to it there is decided by the app or the person you shared it with.
Unless you share, no such file is created. The report contains your baby's health information, so be careful who you send it to.
11. Backups
Your device's own backup system (iCloud Backup, Google One) may include Agubu's data. That backup belongs to your account, not ours, and is governed by the relevant platform's privacy policy.
12. Age and children's data
Agubu is made for parents and caregivers; it is not a children's app and it is not in the App Store Kids Category. You must be 18 or older to use it.
The information you enter may relate to an infant. By entering it, you confirm that you are acting as that child's parent or legal guardian. Because this data never leaves your device, it is not processed, seen or stored by us.
13. Retention
- Records on your device: until you delete them. Deleting the app deletes its data.
- Push address (push token): becomes invalid when you turn notifications off or delete the app, and a deletion request is sent. According to Firebase's own documentation, removing the relevant record from live and backup systems at Google can take up to 180 days.
- Subscription record (RevenueCat): kept after your subscription ends for as long as it is needed for accounting and possible refund disputes; if you want it deleted, write to ygtsmt2999@gmail.com and we will pass the request to RevenueCat. Apple's purchase and invoice records are subject to Apple's own retention policy and to statutory financial record-keeping periods, and we cannot delete them.
Deleting the app does not automatically delete these two records from §6 and §7.
14. Security
Your data is protected by iOS's own file protection and device encryption; the key to that protection is your passcode. Because we run no server, there is no central database to leak. The two connections in §6 and §7 are made over encrypted transport (HTTPS/TLS) only.
15. Your rights (KVKK Art. 11 / GDPR)
You can exercise your rights of access, rectification and erasure directly inside the app:
- Access and rectification: Settings → Edit profile; entries are listed in the History tab and can be deleted individually.
- Erasure: Settings → Privacy and data → Delete all data. This is irreversible and removes your baby's records from your device. Because the home screen widget and the lock screen timer read from a separate place, they may briefly still show the old state after deletion; removing the widget from the home screen and dismissing the lock screen timer clears that too.
- Withdrawing notification consent: Settings → Notifications → turn off "Allow notifications" (or, on iPhone, Settings → Notifications → Agubu).
- Deleting the subscription record: write to ygtsmt2999@gmail.com. If your subscription is still active, deleting it may also switch off your Premium access.
Because your baby's records never reach us, there is no access or erasure request you could make to us for that data — you already manage it yourself, on your device. But for the two exceptions in §6 and §7 (your push address and your subscription record) you can exercise your rights against us: erase them, ask for information, find out who they were transferred to.
Your full set of statutory rights: to learn whether your personal data is being processed; if it is, to request information about it; to learn the purpose of the processing and whether the data is used in accordance with that purpose; to know the third parties to whom it is transferred, at home or abroad; to request rectification if it is incomplete or inaccurate; to request erasure or destruction within the framework of KVKK Art. 7; to request that rectification and erasure be notified to the third parties the data was transferred to; to object to an adverse outcome produced by analysis carried out solely by automated systems; and to claim compensation if you suffer damage from unlawful processing (KVKK Art. 11).
If you are in the EU/EEA or the United Kingdom, you also have the right to request restriction of processing (GDPR Art. 18), to receive your data in a structured, machine-readable format and port it to another controller (Art. 20), to object to processing based on legitimate interests (Art. 21), and to withdraw your consent at any time (Art. 7(3)).
On portability: because the records on your device are not held by us, you cannot request them from us — you can export them yourself as the doctor report PDF (§10). For the two records in §6 and §7, write to us and we will send you what we hold.
If something has gone wrong, write to us first — most things are settled with one email. If you find our answer inadequate, or you get no answer within 30 days, you can lodge a complaint with the Turkish Personal Data Protection Board (kvkk.gov.tr): within 30 days of learning our answer and in any case within 60 days of your application (KVKK Art. 14). If you are in the EU/EEA you can complain to the data protection authority of the country where you live, where you work, or where the infringement took place; if you are in the United Kingdom, to the ICO (GDPR Art. 77). Having come to us first does not affect that right.
15.1 How to make a formal request
The short version: write to ygtsmt2999@gmail.com and we will answer free of charge within 30 days at the latest.
The formal route, for completeness: you may submit your request in Turkish and in writing; via a registered electronic mail (KEP) address, a secure electronic signature, a mobile signature, or the email address you previously notified to us and that is registered in our system. Your request should contain: your name and surname; your signature if it is a written request; your Turkish national ID number (if you are a foreign national, your nationality, passport number, or ID number if you have one); your address of residence or workplace for notification purposes; your email address, telephone and fax number for notification, if any; and the subject of your request.
We will conclude your request as quickly as its nature permits and within thirty days at the latest, free of charge. If the action required also involves a cost, the tariff in Article 7 of the Communiqué on the Procedures and Principles of Application to the Data Controller may be applied.
16. Changes
If this policy changes, we will announce it inside the app and update the version number. The version number here is the version of this text; it is independent of the app's version number.
Should the product ever start sending data to a server (for example if cloud backup is added later), it will happen only with your explicit consent and will be disclosed separately beforehand.