GogoDex — Privacy Policy
Last updated: 8 September 2026 Data controller: Kirakeep Bilgisayar Yazılım A.Ş. Bebek Mahallesi, Vezirköşkü Sokak, Martı Apartmanı No: 8 D:1, Beşiktaş/İstanbul, Türkiye Tax office: Beşiktaş — Tax ID 563 138 9046 Contact: support@gogodex.app
This document explains how GogoDex handles your data. The short version: Your records live on your phone. If you create an account, a copy is kept on our server as a backup, and only you can read it.
What we do NOT do
These are founding decisions of this app, not settings that may quietly change:
We do not sell, rent or share your data with third parties.
No advertising. We collect no advertising identifier and send nothing to ad networks.
No trackers, no analytics. We do not measure what you do in the app.
We do not read the content of your records. Row Level Security is enabled on the server; every record is tied to your account and cannot be read from another.
No location history. Location is used in the moment for travel time only.
We do not store the content of your emails.
We never write notes or meeting records back to your contacts.
1. What data we process
1.1 Records you create
This is what the whole app is built around:
People (name, title, company, phone, email, address, social links, photo)
Notes and meeting records (pre/post notes, decisions, follow-up items)
Places (address, parking/floor/entry notes)
Tags, files, scanned business cards, voice notes
1.2 Account information
If you create an account: your email address and a hashed form of your password. The password itself is never stored and cannot be read by us.
Signing in with an Apple ID is not offered. An account is created with an email address and a password only.
1.3 What device permissions give us access to
Permission
What for
Where it goes
Contacts
Importing people you choose into your Dex; if you enable it, saving a scanned business card to your Contacts
Only the people you select enter the app. Writing to your Contacts is off by default; if you turn it on, only name, phone, email, company and job title are written. Your notes, meeting records and anything you create inside the app are never written to your Contacts.
Calendar
Showing upcoming meetings, matching attendees to your people
Meeting details are brought into the app. It can create a follow-up event if you ask.
Location
Estimated travel time to a meeting
Not stored. Used in the moment, never sent to the server.
Camera
Scanning business cards and documents
Images are stored on your device; if you have an account they are also uploaded to a private storage area as a backup (see section 2).
Microphone
Voice notes after meetings
Recordings are stored on your device; if you have an account they are also uploaded to a private storage area as a backup (see section 2).
Each permission is requested the first time you use that feature — never all at once. The app works without them; only that feature stays off.
1.4 What we do not process
No advertising identifiers, no trackers.
No analytics or usage telemetry.
No location history.
If you connect email, only the subject and a short preview are stored; the content of your emails is never stored.
2. Where your data is stored
Your phone comes first. The app works fully offline.
When you create an account, a copy of your records is uploaded to the server as a backup. The infrastructure is Supabase (PostgreSQL). Data is encrypted in transit with TLS and encrypted at rest on disk.
Only you can read it. Row Level Security is enabled in the database: every record is tied to your account and cannot be read from another user's account. A request that is not signed in sees nothing at all.
Your files are backed up too. Contact photos, scanned business cards and voice notes are uploaded to a private storage area tied to your account. That area is protected by row level security as well; no other user can reach your files. Deleting your account deletes these files too.
Restoring from the backup works: if you delete and reinstall the app, your records and files come back with your account.
Not yet available: Real-time sync across devices and two-way conflict resolution do not exist yet. Syncing runs when the app comes to the foreground and when you trigger it manually.
3. Other people's data (important)
Most of the people you save in GogoDex are third parties. You are the one entering their data.
That data is tied to your account only; no other user can see it.
We do not market to these people, do not contact them, and do not share their data with anyone.
When you delete a person, their notes, interactions and files are deleted too.
Your responsibility: processing the data of the people you save, on a lawful basis under GDPR/KVKK and applicable law, is your obligation. If you use the app for business purposes, your own transparency obligations continue to apply.
If someone you saved asks for their data to be erased, deleting that person in the app is sufficient.
4. Legal basis (GDPR Art. 6 / KVKK Art. 5)
Processing
Legal basis
Account creation and session management
Performance of a contract
Storing and backing up your records
Performance of a contract
Contacts / calendar / location access
Your explicit consent (granted via the device permission, withdrawable at any time)
Security and abuse prevention
Legitimate interest
You can withdraw device permissions at any time in iOS Settings > GogoDex.
5. How long we keep it
Your records are kept until you delete them or close your account.
When you delete your account (in the app: Settings > Delete Account), your account and all of your records on the server are permanently deleted. This cannot be undone and cannot be recovered from backups. The records on your phone are deleted in the same operation.
6. Your rights
Under GDPR and KVKK Art. 11 you may:
Ask whether your data is being processed and request information about it
Ask for it to be corrected
Ask for it to be deleted — you can do this yourself, instantly, in the app
Portability — Settings > Export gives you all of your data as a JSON and file archive. You do not need to go through us.
Object to processing
Withdraw consent (by turning off device permissions)
For requests: support@gogodex.app. Requests are answered within 30 days at the latest.
7. Third-party service providers
Provider
What for
Data transferred
Supabase (database and authentication)
Account and backup
Account information and your records
Apple (Sign in with Apple, App Store)
Sign-in and distribution
Apple's own policy applies
Resend (email delivery)
Password reset codes
Your email address and the message sent
RevenueCat (subscription management)
Verifying and restoring your subscription
Your account identifier (a random ID, not your email), purchase history and country
We do not share or sell your data to ad networks, data brokers or any other third party.
International transfers: Supabase servers may be located outside your country. By creating an account you consent to this transfer. If you would like to request a specific region, contact us at the support address.
8. Children
GogoDex is not directed at children under 13 and we do not knowingly collect data from that age group.
9. Data breaches
In the event of a security breach affecting your data, affected individuals and the competent supervisory authority will be notified within the time limits required by law.
10. Changes to this policy
If this policy changes, the "Last updated" date on this page is revised. If the change is material, you will be informed inside the app.