Privacy Policy
Who we are
Udeha ("we", "us") operates the Udeha website, diagnostic funnel, and mobile application (together, the "Service"). For the purposes of Türkiye's Personal Data Protection Law (KVKK, Law No. 6698) and the EU General Data Protection Regulation (GDPR), Udeha Studio is the data controller for the personal data described below. You can reach our data protection contact at privacy@udeha.com.
What we collect
- Contact details — the email address and (optionally) the name you provide at the diagnostic gate or when you create an account, so we can send your results and, if you consent, occasional product emails.
- Diagnostic answers — the responses you give in the diagnostic, used to compute your result and assemble your program.
- Account and progress data — your language and time zone, which lessons you have completed, your streak, and which courses you have unlocked.
- Purchase records — confirmation from Apple or Google that a one-time purchase completed and what it unlocked. We never see your card details.
- Technical data — crash and error reports, which include the device model, operating system version, and the technical context of the failure.
- Analytics data — pseudonymized usage events (for example, pages viewed and funnel steps completed), collected only where you have accepted analytics. See our Cookie & Analytics Notice.
We do not collect special-category data. Your private journal and reflective entries are stored encrypted on your device and are never transmitted to our servers — they are not in our backups and cannot appear in a data export.
Why we use it (lawful basis)
- To deliver your diagnostic result and operate the Service — performance of a contract / provision of a service you requested (KVKK Art. 5(2)(c); GDPR Art. 6(1)(b)).
- To send marketing emails — only with your explicit consent, which you can withdraw at any time (KVKK Art. 5(1); GDPR Art. 6(1)(a)).
- To measure and improve the product and keep it secure — our legitimate interest in a functioning, well-designed service, balanced against your rights (KVKK Art. 5(2)(f); GDPR Art. 6(1)(f)).
- To keep purchase and consent records where the law requires us to (KVKK Art. 5(2)(ç); GDPR Art. 6(1)(c)).
Marketing consent
Marketing emails are sent only if you tick the marketing-consent box on the website. That consent is recorded in our consent ledger with a timestamp, so we can show when and how it was given. Every marketing email includes an unsubscribe link, and withdrawing consent is as easy as giving it.
The analytics choice you make inside the mobile app is a separate thing: it governs analytics only and never turns on marketing email. It takes effect on your device the moment you answer, and — so that we can show we asked — your answer is also written to the consent ledger against your account, with a timestamp. You can change it at any time in Settings, and each change is recorded the same way.
Who else processes it
We do not sell personal data and we do not use it for cross-site advertising. We share it only with service providers who process it on our instructions:
- PostHog — product analytics.
- Google Analytics — website audience measurement.
- Sentry — crash and error reporting.
- RevenueCat, with Apple and Google — validating purchases and unlocking what you bought.
- Our email provider — sending transactional and, with your consent, marketing email.
- Our hosting provider — running the servers and the database.
We may also disclose data where the law requires it.
International transfers
Some of these providers process data outside Türkiye and the EEA. Where they do, the transfer relies on the mechanisms available under KVKK Art. 9 and GDPR Chapter V — an adequacy decision or standard contractual clauses — and is limited to the data that provider needs.
How long we keep it
- Leads — an email and name captured at the gate that never became an account are deleted automatically 180 days after they were collected.
- Account, diagnostic and progress data — kept while your account exists and erased when you delete it.
- Consent records — kept as long as we need them to show that a consent was given or withdrawn.
- Analytics and crash data — kept for the retention window configured at the relevant provider, then discarded.
Your rights
Under KVKK and GDPR you may ask us to access the personal data we hold about you, correct it, delete it, restrict or object to processing, and to give you a portable copy. You also have the right to complain to a supervisory authority (in Türkiye, the Personal Data Protection Authority; in the EU, your local data protection authority).
How to exercise them:
- If you have an app account — open Settings in the app. Export my data gives you a machine-readable copy immediately, and Delete account erases the account and its data.
- Everyone else — including anyone who gave an email address on the website but never created an account — email privacy@udeha.com and we will act on your request within 30 days.
Automated processing
The diagnostic scores your answers to decide which modules make up your program. It shapes the content you are shown and nothing else: no price, eligibility, or legal consequence follows from it.
Keeping it safe
Traffic between the apps and our servers is encrypted in transit (TLS). Passwords are stored only as salted hashes. Data held on your device, including your journal, is kept in encrypted storage. Access to production data is limited to the people who need it to operate the Service.
Children
The Service is intended for adults. You must be 18 or older to use it, and we do not knowingly collect personal data from children.
Changes
We may update this policy; the effective date is shown as "last updated" above. Material changes will be communicated through the app or by email where appropriate.