Kuran EzberleTecvid Öğren

GizlilikPrivacy

Gizlilik PolitikasıPrivacy Policy

Son güncelleme: 9 Ekim 2026 · Veri sorumlusu: Abdullah Darçın Last updated: October 9, 2026 · Data controller: Abdullah Darçın

Bu politika, “Kuran Ezberle: Tecvid Öğren” mobil uygulamasının (“Uygulama”) hangi verileri işlediğini, neden işlediğini ve haklarınızı açıklar. Uygulamayı kullanarak bu politikayı kabul etmiş olursunuz.

1.Kim olduğumuz

Uygulama, bireysel geliştirici Abdullah Darçın tarafından geliştirilip yayımlanmaktadır. Gizlilikle ilgili her konuda bize abdullahdarcin01@gmail.com adresinden ulaşabilirsiniz.

2.Topladığımız veriler

a) Hesap ve profil bilgileri

Apple, Google veya e‑posta/şifre ile giriş yaptığınızda, kimlik doğrulama sağlayıcısından (Firebase Authentication) bize aktarılan ve users/{uid} kaydında saklanan bilgiler:

  • Benzersiz kullanıcı kimliği (UID)
  • E‑posta adresi ve e‑posta doğrulama durumu
  • Görünen ad ve (varsa) profil fotoğrafı bağlantısı
  • Kullanılan giriş yöntemi (apple.com / google.com / şifre)
  • Cihaz platformu (iOS/Android), dil/yerel ayar, ilk kayıt ve son giriş zamanı

b) Ses kayıtları (tilavet)

Bir ayeti sesli okuduğunuzda, ses kaydınız analiz için sunucumuza gönderilir. Sunucumuz kaydı metne çevirmek için Groq, Inc.’e (ABD — konuşmayı metne çevirme, Whisper), okumanızdaki hataların listesini geri bildirim metnine dönüştürmek için Microsoft Azure OpenAI Service’e (GPT‑4o‑mini) iletir. Ses kaydı yalnızca Groq’a gider; Azure’a ses ve hesap kimliğiniz gönderilmez, yalnızca okunan kelimelerin metni ve hata listesi gönderilir. Ses kaydı sunucularımızda saklanmaz; anlık olarak işlenip sonuç döndürülür. Okuma geçmişiniz (yalnızca Pro) yalnızca kendi cihazınızda yerel olarak tutulur, sunucuya yüklenmez.

Bağlantı koptuğunda aynı kaydın ikinci kez ücretlendirilmemesi için analiz sonucu (sesten çevrilen metin dahil, ses hariç) hesabınıza bağlı olarak en fazla 2 gün saklanır ve sonra otomatik silinir. Ayrıca hizmeti iyileştirmek için hesabınıza bağlanmayan anonim sayaçlar tutarız: hangi ayette hangi kelimenin ne sıklıkla yanlış/eksik okunduğu ve aynı hata kümesi için üretilen geri bildirim metni (en fazla 30 gün). Bunlar ses, metin dökümü veya kullanıcı kimliği içermez. “Bu analiz yanlış” bildirimi gönderirseniz, bildiriminiz (sebep, işaretlediğiniz kelimeler ve isteğe bağlı notunuz) hesabınıza bağlı olarak en fazla 180 gün saklanır.

c) Kullanım ve abonelik verileri

  • Günlük analiz sayacı (kota): usage/{uid}_{tarih} → kullanıcı kimliği, tarih ve adet.
  • Abonelik durumu: subscriptions/{uid} → Pro olup olmadığınız ve geçerlilik tarihi. Bu bilgi ödeme altyapısı RevenueCat üzerinden güncellenir.

d) Tanılama ve bildirim

  • Çökme/hata raporları (Firebase Crashlytics) — uygulamanın kararlılığı için.
  • Bildirim izni verdiyseniz, cihazınızın push bildirim jetonu (FCM token) users/{uid} altında saklanır; çıkış yaptığınızda kaldırılır.

e) Reklam verileri

Ücretsiz sürümde, Google AdMob aracılığıyla reklam gösterilir. AdMob, reklamların sunulması ve ölçümlenmesi için cihazınızın reklam tanımlayıcısı (iOS IDFA / Android Reklam Kimliği) ve genel cihaz/etkileşim bilgilerini işleyebilir. İzleme şeffaflığı (iOS App Tracking Transparency) izni vermezseniz, kişiselleştirilmemiş reklam gösterilir.

3.Mikrofon izni

Mikrofon erişimi yalnızca siz kayıt düğmesine bastığınızda, tilavetinizi kaydetmek için kullanılır. Arka planda dinleme yapılmaz. İzni dilediğiniz an cihaz ayarlarından geri alabilirsiniz.

4.Verileri hangi amaçla kullanırız

  • Tilavet analizini üretmek ve sonucu size göstermek
  • Hesabınızı oluşturmak, oturumunuzu yönetmek ve güvenliği sağlamak
  • Günlük kullanım kotasını ve Pro aboneliğini uygulamak
  • Uygulamayı kararlı tutmak (çökme analizi) ve geliştirmek
  • İzin verdiyseniz bildirim göndermek ve reklam sunmak

Verilerinizi reklam dışı amaçlarla satmıyoruz ve pazarlama için üçüncü taraflara kiralamıyoruz.

5.Verileri paylaştığımız hizmet sağlayıcılar

Uygulamayı çalıştırmak için aşağıdaki alt işleyicileri kullanırız. Her biri kendi gizlilik politikasına tabidir:

SağlayıcıAmaçİşlenen veri
Google Firebase (Authentication, Firestore, Cloud Functions, Cloud Messaging, Crashlytics, Analytics)Kimlik doğrulama, veri saklama, sunucu işlevleri, bildirim, çökme ve kullanım analiziHesap bilgileri, kota/abonelik, FCM jetonu, tanılama, ekran/olay istatistikleri
Firebase App Check (Apple App Attest / Google Play Integrity)Sunucu isteklerinin gerçek uygulamadan geldiğini doğrulama (kötüye kullanım önleme)Cihaz/uygulama bütünlük doğrulaması — kişisel içerik gönderilmez
Groq, Inc. (ABD)Sesi metne çevirme (Whisper)Ses kaydı — anlık işlenir, tarafımızca saklanmaz
Microsoft Azure OpenAI Service (Microsoft Corporation)Geri bildirim metni üretme (GPT‑4o‑mini)Okunan kelimelerin metni ve hata listesi — ses ve hesap kimliği gönderilmez
RevenueCatAbonelik/satın alma yönetimiSatın alma ve abonelik durumu
Apple / GoogleGiriş ve uygulama içi satın almaGiriş kimliği, satın alma makbuzu
Google AdMobÜcretsiz sürümde reklam gösterimiReklam kimliği, cihaz/etkileşim bilgisi

6.Yurt dışına aktarım

Yukarıdaki sağlayıcıların sunucuları Türkiye dışında (örneğin ABD veya Avrupa Birliği) bulunabilir. Özellikle: tilavet ses kaydınız, metne çevrilmek üzere ABD’deki Groq, Inc. sunucularına aktarılır; orada yalnızca o analiz için anlık olarak işlenir ve tarafımızca saklanmaz. Geri bildirim metni, ses içermeyen hata listesinden Microsoft Azure OpenAI Service üzerinde (Microsoft’un ABD veya AB’deki veri merkezlerinde) üretilir. Uygulamayı kullanarak verilerinizin bu hizmetler tarafından yurt dışında işlenebileceğini kabul etmiş olursunuz. Sunucu işlevlerimiz ve veritabanımız europe-west1 (AB) bölgesinde çalışır.

7.Saklama süresi

  • Ses kayıtları: sunucuda saklanmaz; işlem sonrası tutulmaz.
  • Analiz sonucu (ses hariç): tekrar gönderimde çift ücreti önlemek için en fazla 2 gün; sonra otomatik silinir.
  • “Analiz yanlış” bildirimleri: en fazla 180 gün; hesabınızı silerseniz hemen silinir.
  • Anonim sayaçlar ve geri bildirim metni önbelleği: hesabınıza bağlı değildir (önbellek en fazla 30 gün).
  • Hesap/profil, kota ve abonelik: hesabınız aktif olduğu sürece saklanır.
  • Cihazdaki geçmiş: siz silene veya uygulamayı kaldırana kadar yalnızca cihazınızda kalır.

8.Haklarınız ve hesap silme

6698 sayılı KVKK ve geçerli veri koruma mevzuatı uyarınca; verilerinize erişme, düzeltme, silme ve işlemeye itiraz etme haklarına sahipsiniz. Hesabınızı uygulama içinden Ayarlar → Hesabı ve verileri sil ile hemen silebilirsiniz: sunucudaki verileriniz (profil, kota, abonelik kayıtları), ödeme altyapısındaki (RevenueCat) abone kaydınız ve cihazdaki okuma geçmişiniz ile ezber kartlarınız silinir. Uygulamaya erişemiyorsanız abdullahdarcin01@gmail.com adresine yazarak da silme talep edebilirsiniz; talebinizi makul süre içinde yerine getiririz. Ayrıntılar: Hesap ve Veri Silme.

9.Çocukların gizliliği

Uygulama 13 yaşından küçük çocuklara yönelik değildir ve onlardan bilerek veri toplamayız. Çocuğunuzun bize veri sağladığını düşünüyorsanız lütfen bizimle iletişime geçin; ilgili veriyi sileriz.

10.Güvenlik

Veriler şifreli bağlantılar (HTTPS) üzerinden iletilir. Firestore güvenlik kuralları, her kullanıcının yalnızca kendi kayıtlarına erişmesine izin verir; kota ve abonelik kayıtlarına yalnızca sunucu yazabilir. API anahtarları istemciye gömülmez; gizli anahtarlar sunucu tarafında saklanır.

11.Bu politikadaki değişiklikler

Bu politikayı zaman zaman güncelleyebiliriz. Önemli değişikliklerde bu sayfadaki “Son güncelleme” tarihini değiştirir, gerektiğinde uygulama içinde bilgilendiririz.

12.İletişim

Sorularınız için: abdullahdarcin01@gmail.com

This policy explains what data the “Kuran Ezberle: Tecvid Öğren” mobile app (“the App”) processes, why, and your rights. By using the App you agree to this policy.

1.Who we are

The App is developed and published by independent developer Abdullah Darçın. For any privacy matter, contact us at abdullahdarcin01@gmail.com.

2.Data we collect

a) Account & profile

When you sign in with Apple, Google, or email/password, the following data — provided by the authentication provider (Firebase Authentication) and stored in your users/{uid} record — is processed:

  • Unique user ID (UID)
  • Email address and email‑verification status
  • Display name and (if available) profile photo URL
  • Sign‑in method used (apple.com / google.com / password)
  • Device platform (iOS/Android), locale, first sign‑up and last login time

b) Voice recordings (recitation)

When you recite a verse, your audio is sent to our server. Our server forwards it to Groq, Inc. (USA — speech‑to‑text, Whisper) for transcription, and sends the list of mistakes in your recitation to Microsoft Azure OpenAI Service (GPT‑4o‑mini) to turn it into feedback text. The audio goes to Groq only; neither the audio nor your account ID is sent to Azure — only the text of the recited words and the list of mistakes. Audio is not stored on our servers; it is processed transiently and only the result is returned. Your recitation history (Pro only) is kept locally on your device only and is never uploaded.

So that the same recording is not charged twice when your connection drops, the analysis result (including the text transcribed from your audio, but never the audio) is kept linked to your account for at most 2 days and then deleted automatically. To improve the service we also keep anonymous counters that are not linked to your account: how often each word of a verse is misread or skipped, and the feedback text generated for the same set of mistakes (kept up to 30 days). These contain no audio, no transcript and no user ID. If you send a “this analysis is wrong” report, your report (reason, the words you marked and your optional note) is kept linked to your account for up to 180 days.

c) Usage & subscription

  • Daily analysis counter (quota): usage/{uid}_{date} → user ID, date, and count.
  • Subscription status: subscriptions/{uid} → whether you are Pro and its expiry, updated via the payments provider RevenueCat.

d) Diagnostics & notifications

  • Crash/error reports (Firebase Crashlytics) for app stability.
  • If you grant notification permission, your device push token (FCM token) is stored under users/{uid} and removed when you sign out.

e) Advertising

In the free tier, ads are shown via Google AdMob. AdMob may process your device’s advertising identifier (iOS IDFA / Android Advertising ID) and general device/interaction data to serve and measure ads. If you do not grant App Tracking Transparency (iOS) permission, non‑personalized ads are shown.

3.Microphone permission

Microphone access is used only while you press record, to capture your recitation. There is no background listening. You can revoke the permission anytime in your device settings.

4.How we use data

  • To produce your recitation analysis and show you the result
  • To create your account, manage your session, and ensure security
  • To enforce the daily quota and Pro subscription
  • To keep the App stable (crash analytics) and improve it
  • To send notifications and serve ads where you have consented

We do not sell your data for non‑advertising purposes, nor rent it to third parties for marketing.

5.Service providers we share data with

We use the sub‑processors below to operate the App. Each is governed by its own privacy policy:

ProviderPurposeData processed
Google Firebase (Authentication, Firestore, Cloud Functions, Cloud Messaging, Crashlytics, Analytics)Auth, data storage, server functions, notifications, crash and usage analyticsAccount info, quota/subscription, FCM token, diagnostics, screen/event statistics
Firebase App Check (Apple App Attest / Google Play Integrity)Verifying that server requests come from the genuine app (abuse prevention)Device/app integrity attestation — no personal content is sent
Groq, Inc. (USA)Speech‑to‑text (Whisper)Audio recording — processed transiently, not stored by us
Microsoft Azure OpenAI Service (Microsoft Corporation)Generating feedback text (GPT‑4o‑mini)Text of the recited words and list of mistakes — no audio, no account ID
RevenueCatSubscription/purchase managementPurchase and subscription status
Apple / GoogleSign‑in and in‑app purchasesSign‑in identity, purchase receipt
Google AdMobAds in the free tierAdvertising ID, device/interaction data

6.International transfers

The providers above may operate servers outside Türkiye (e.g., the United States or the European Union). In particular: your recitation audio is transferred to Groq, Inc. servers in the United States for speech‑to‑text; it is processed there transiently, only for that analysis, and is not stored by us. The feedback text is generated from the audio‑free list of mistakes on Microsoft Azure OpenAI Service (in Microsoft data centers in the US or the EU). By using the App you acknowledge that your data may be processed abroad by these services. Our server functions and database run in the europe-west1 (EU) region.

7.Retention

  • Voice recordings: not stored on the server; not retained after processing.
  • Analysis result (no audio): at most 2 days, to avoid double charging on a retry; then deleted automatically.
  • “Analysis is wrong” reports: up to 180 days; deleted immediately if you delete your account.
  • Anonymous counters and feedback‑text cache: not linked to your account (cache kept up to 30 days).
  • Account/profile, quota and subscription: kept while your account is active.
  • On‑device history: stays on your device only until you delete it or uninstall the App.

8.Your rights & account deletion

Under Türkiye’s KVKK (Law No. 6698) and applicable data‑protection law, you have the right to access, rectify, erase, and object to the processing of your data. You can delete your account immediately in the app via Settings → Delete account and data: your server‑side data (profile, quota, subscription records), your subscriber record at our payments provider (RevenueCat), and the recitation history and memorization cards on your device are deleted. If you cannot access the app, you can also request deletion by emailing abdullahdarcin01@gmail.com; we will fulfill your request within a reasonable period. Details: Account & Data Deletion.

9.Children’s privacy

The App is not directed to children under 13, and we do not knowingly collect their data. If you believe your child has provided us data, please contact us and we will delete it.

10.Security

Data is transmitted over encrypted connections (HTTPS). Firestore security rules let each user access only their own records; quota and subscription records are written by the server only. API keys are never embedded in the client; secret keys are stored server‑side.

11.Changes to this policy

We may update this policy from time to time. For material changes we will update the “Last updated” date on this page and, where appropriate, notify you in‑app.

12.Contact

Questions: abdullahdarcin01@gmail.com