# MeraRadar Gizlilik Politikası ve KVKK Aydınlatma Metni / Privacy Policy
**Son güncelleme / Last updated:** 18 Eylül 2026 / September 18, 2026
*English version below.*
**Uygulama:** MeraRadar (`com.meraradar.app`)
**Veri Sorumlusu:** UTKU AKÇA
**Adres:** Ahmet Efendi Mh. 1102 Sokak No:1 E Blok Kat:5 Daire No:39 Çiğli/İzmir
**İletişim / Başvuru:** akcautku@gmail.com
---
## 1. Giriş
MeraRadar, kıyıdan amatör balıkçılık için tasarlanmış bir mobil uygulamadır. Bu metin, uygulamayı
kullandığınızda hangi verilerin işlendiğini, neden işlendiğini ve haklarınızı açıklar.
**MeraRadar yerel-öncelikli bir uygulamadır:** av günlüğünüz, kaydettiğiniz balık noktaları ("mera"),
fotoğraflar, sefer planları ve istatistikleriniz **yalnızca cihazınızda, şifreli (SQLCipher) olarak**
saklanır; sunucularımıza gönderilmez. Uygulamada hesap açma veya giriş yapma yoktur.
## 2. İşlenen Veriler ve Amaçları
### a) Konum bilgisi (yaklaşık ve kesin)
- **Neden:** Bulunduğunuz yere ve kayıtlı meralarınıza göre hava/deniz koşulları, av puanı,
dip/derinlik analizi, su verimliliği ve yakın meralar gibi özellikleri sunmak.
- **Nasıl:** Koordinatlar (enlem/boylam), ilgili veriyi getirmek için aşağıdaki hizmetlere **anlık
olarak** iletilir ve bu hizmetlerde sizinle ilişkilendirilmez:
- **Open-Meteo:** hava durumu ve deniz koşulları
- **OpenTopoData:** yükseklik
- **EMODnet:** deniz dibi derinliği
- **MeraRadar sunucu fonksiyonu** (Google Cloud üzerinde): su verimliliği (klorofil) verisi,
kaynağı Copernicus Marine Service. Aynı bölgedeki kullanıcılara hızlı yanıt vermek için sonuç,
yaklaşık **5 km'lik bölgeye yuvarlanmış** konumla ve **hiçbir kullanıcı kimliği olmadan**
önbellekte tutulur.
- **Android'in yerleşik adres çözümleme hizmeti** (Google): ekranda yer adını göstermek için.
- **Harita döşemeleri** (OpenStreetMap / OpenFreeMap, OpenSeaMap, Esri uydu görüntüsü, EMODnet
derinlik haritası): görüntülediğiniz harita bölgesi iletilir.
- Kaydettiğiniz meraların koordinatları **yalnızca cihazınızda** (şifreli) tutulur.
- **İzin:** Konum izni isteğe bağlıdır; vermezseniz konum-temelli özellikler çalışmaz, uygulamanın
geri kalanı çalışır.
### b) İletişim / Hata Bildir mesajları (yalnızca siz gönderdiğinizde)
"Hata Bildir / Bize Yaz" ekranından mesaj gönderdiğinizde şunlar **Google Firebase (Firestore)**
hizmetine kaydedilir: mesaj metni, konu (hata/genel), uygulama sürümü, cihaz modeli, Android sürümü,
uygulamanın ürettiği **anonim kimlik** ve gönderim zamanı. Cevap almak isterseniz **isteğe bağlı
olarak e-posta adresinizi** de yazabilirsiniz; yazmazsanız e-posta gönderilmez.
- **Neden:** Hataları gidermek, sorunlarınızı çözmek ve (e-posta verdiyseniz) size cevap vermek.
- **E-posta adresi:** Yalnızca size cevap vermek için kullanılır; pazarlama amacıyla kullanılmaz,
kimseyle paylaşılmaz.
- Konum/koordinat bilgisi mesaja **eklenmez**. Ad istenmez.
### c) Öneri Panosu (yalnızca siz yazdığınızda veya oy verdiğinizde)
Öneri Panosu'na yazdığınız **başlık ve açıklama herkese açıktır**; uygulamayı kullanan herkes görebilir.
Bu yüzden önerilere kişisel bilgi yazmayın. Oy verdiğinizde, aynı öneriye iki kez oy verilmesini
önlemek için **anonim kimliğiniz** o önerinin oy listesine eklenir; bu kimlik diğer kullanıcılara
gösterilmez. Geliştiricinin önerilere yazdığı durum ve cevaplar da herkese açıktır.
### d) Anonim kimlik (Firebase Anonymous Authentication)
Mesaj gönderme, öneri yazma ve oy vermeyi güvenli kılmak için uygulama, cihaz başına **anonim bir
kimlik** oluşturur. Bu kimlik adınızı, e-postanızı veya telefon numaranızı içermez; reklam kimliği
değildir.
### e) Kullanım istatistikleri ve çökme raporları
Uygulamayı iyileştirmek ve hataları bulmak için **Google Firebase Analytics** ve **Firebase
Crashlytics** kullanılır.
- **Analytics:** Hangi ekranların açıldığı ve bazı işlemlerin sonucu (ör. ödeme ekranının
açılması, satın alma sonucu, bir veri servisinin hata vermesi), cihaz modeli, Android sürümü,
uygulama sürümü, dil ve IP adresinden türetilen **ülke/bölge** bilgisi. Uygulamaya özel rastgele bir
kurulum kimliği kullanılır. **Koordinat gönderilmez.**
- **Crashlytics:** Uygulama çöktüğünde veya beklenmeyen bir hata olduğunda teknik hata kaydı, cihaz
modeli, Android ve uygulama sürümü.
- **Reklam kimliği (Advertising ID) kullanılmaz;** uygulamadan bilinçli olarak çıkarılmıştır. Bu veriler
reklam veya profil çıkarma amacıyla kullanılmaz.
### f) Cihazda kalan veriler (sunucuya gönderilmez)
Av günlüğü kayıtları, av fotoğrafları, kaydettiğiniz meralar, sefer planları, takım dolabı ve
istatistikler cihazınızdaki **şifreli yerel veritabanında** tutulur. Fotoğraflar cihazın
foto-seçicisi/kamera uygulaması aracılığıyla eklenir ve cihazda kalır. Deneysel "tür öner" özelliği
fotoğrafı **cihaz üzerinde** (Google ML Kit) işler; fotoğraf sunucuya gönderilmez.
### g) Bildirimler
Av zamanı, yasak ve koşul hatırlatmaları **cihaz üzerinde yerel olarak** üretilir; sunucudan anlık
bildirim (push) gönderilmez.
### h) Abonelik / satın alma verisi (yalnızca Pro satın alırsanız)
MeraRadar Pro aboneliği **Google Play Billing** üzerinden satın alınır; abonelik durumu **RevenueCat**
hizmetiyle yönetilir. Bu kapsamda işlenen veriler: **satın alma geçmişi** (hangi abonelik,
satın alma/yenileme zamanı, abonelik durumu), uygulamanın ürettiği **kullanıcı kimliği** ve **IP adresi**.
- **Neden:** Aboneliğinizi tanımak, Pro özellikleri açmak ve "satın almaları geri yükle" işlevini sağlamak.
- Kart bilgileriniz **yalnızca Google** tarafından işlenir; biz görmeyiz, saklamayız.
## 3. Üçüncü Taraf Hizmetler
Uygulama, işlevsellik için aşağıdaki hizmetleri kullanır; bu hizmetlerin kendi gizlilik politikaları geçerlidir:
- **Open-Meteo** (hava/deniz verisi): konum koordinatı iletilir.
- **OpenTopoData** (yükseklik), **EMODnet** (derinlik): konum koordinatı iletilir.
- **Copernicus Marine Service** (su verimliliği): MeraRadar sunucu fonksiyonu üzerinden, bölgeye yuvarlanmış konumla.
- **OpenStreetMap / OpenFreeMap, OpenSeaMap, Esri, EMODnet** (harita döşemeleri): görüntülenen harita bölgesi iletilir.
- **Wikimedia Commons** (tür görselleri): görsel indirilir.
- **Google Firebase** (Firestore, Anonymous Authentication, Analytics, Crashlytics, App Check, Cloud Functions), **Google Play Billing**, **Google Play uygulama içi değerlendirme**, **Google ML Kit** (cihaz üzerinde): [Google Gizlilik Politikası](https://policies.google.com/privacy).
- **RevenueCat** (abonelik durumu yönetimi): satın alma geçmişi, kullanıcı kimliği ve IP iletilir; [RevenueCat Gizlilik Politikası](https://www.revenuecat.com/privacy/).
## 4. Veri Paylaşımı ve Satışı
Verilerinizi **satmıyoruz** ve **reklam amacıyla paylaşmıyoruz**. Uygulamada reklam ve reklam ağı
bulunmaz. Veriler yalnızca yukarıdaki hizmet sağlayıcılara, uygulamanın çalışması için gereken ölçüde
iletilir. Öneri Panosu'na yazdıklarınız ise (bkz. 2c) tasarımı gereği herkese açıktır.
## 5. Güvenlik
Cihazdaki veriler **SQLCipher** ile şifrelenir. Ağ üzerindeki tüm veri aktarımı **HTTPS/TLS** ile
şifrelidir. Hiçbir yöntem %100 güvenli olmasa da verilerinizi korumak için makul önlemler alınır.
## 6. Saklama Süresi
- **Cihaz verileri:** Siz silene veya uygulamayı kaldırana kadar cihazınızda kalır.
- **Mesajlar ve e-posta adresi:** Destek amacıyla saklanır; talebiniz üzerine silinir.
- **Öneri ve oylar:** Pano yayında olduğu sürece saklanır; talebiniz üzerine silinir.
- **Analytics:** Google Analytics'te ayarlı saklama süresi boyunca (en fazla 14 ay).
- **Crashlytics:** Çökme kayıtları 90 gün.
## 7. Haklarınız (KVKK m. 11 / Aydınlatma)
6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) kapsamında; kişisel verilerinizin işlenip
işlenmediğini öğrenme, bilgi talep etme, düzeltilmesini/silinmesini isteme ve işlemeye itiraz etme
haklarına sahipsiniz.
- **Hukuki sebep:** Konum işleme, mesajlar, öneriler ve abonelik; talep ettiğiniz işlevlerin yerine
getirilmesi (sözleşmenin ifası / açık rıza) temelindedir. Kullanım istatistikleri ve çökme raporları;
uygulamanın güvenli ve hatasız çalışmasını sağlama **meşru menfaatine** dayanır.
- **Silme talebi:** Mesajlarınızın, e-posta adresinizin veya önerilerinizin silinmesini
**akcautku@gmail.com** adresine yazarak isteyebilirsiniz. Cihazınızdaki verileri uygulama
ayarlarından temizleyerek veya uygulamayı kaldırarak silebilirsiniz.
## 8. Çocukların Gizliliği
Uygulama çocuklara yönelik değildir ve bilerek 13 yaşından küçük kullanıcılardan veri toplamaz.
## 9. Değişiklikler
Bu politika güncellenebilir; önemli değişikliklerde "Son güncelleme" tarihi yenilenir.
## 10. İletişim
Sorularınız için: **akcautku@gmail.com**
---
---
# English version
**App:** MeraRadar (`com.meraradar.app`)
**Data controller:** UTKU AKÇA
**Address:** Ahmet Efendi Mh. 1102 Sokak No:1 E Blok Kat:5 Daire No:39 Çiğli/İzmir, Türkiye
**Contact:** akcautku@gmail.com
## 1. Introduction
MeraRadar is a mobile app for recreational shore fishing. This policy explains what data is processed
when you use the app, why, and what your rights are.
**MeraRadar is local-first:** your catch log, saved fishing spots ("mera"), photos, trip plans and
statistics are stored **only on your device, encrypted (SQLCipher)**, and are not sent to our servers.
The app has no accounts or sign-in.
## 2. Data We Process and Why
### a) Location (approximate and precise)
- **Why:** To provide weather and sea conditions, the bite score, seabed/depth analysis, water
productivity and nearby spots for where you are and for your saved spots.
- **How:** Coordinates (latitude/longitude) are sent **in real time** to the services below to fetch
that data, and are not linked to you there:
- **Open-Meteo:** weather and sea conditions
- **OpenTopoData:** elevation
- **EMODnet:** seabed depth
- **MeraRadar server function** (on Google Cloud): water productivity (chlorophyll) data, sourced
from the Copernicus Marine Service. To answer users in the same area quickly, the result is cached
with the location **rounded to an area of about 5 km** and **without any user identifier**.
- **Android's built-in address lookup** (Google): to show the place name on screen.
- **Map tiles** (OpenStreetMap / OpenFreeMap, OpenSeaMap, Esri satellite imagery, EMODnet depth
map): the map area you are viewing is requested.
- Coordinates of your saved spots are kept **only on your device** (encrypted).
- **Permission:** Location permission is optional; without it, location-based features don't work but
the rest of the app does.
### b) Contact / bug report messages (only when you send one)
When you send a message from the "Report a Bug / Write to Us" screen, the following is stored in
**Google Firebase (Firestore)**: the message text, topic (bug/general), app version, device model,
Android version, the app-generated **anonymous ID** and the time sent. If you'd like a reply, you may
**optionally enter your email address**; if you leave it empty, no email is sent.
- **Why:** To fix bugs, solve your issue and (if you gave an email) reply to you.
- **Email address:** Used only to reply to you; never used for marketing and never shared.
- Your location/coordinates are **not** added to the message. Your name is not requested.
### c) Idea Board (only when you post or vote)
The **title and description you post on the Idea Board are public**; anyone using the app can see
them, so please don't include personal information. When you vote, your **anonymous ID** is added to
that idea's vote list so the same idea can't be voted twice; this ID is not shown to other users. The
status and replies the developer adds to ideas are also public.
### d) Anonymous ID (Firebase Anonymous Authentication)
To secure sending messages, posting ideas and voting, the app creates an **anonymous ID** per device.
It does not contain your name, email or phone number, and it is not an advertising ID.
### e) Usage statistics and crash reports
**Google Firebase Analytics** and **Firebase Crashlytics** are used to improve the app and find bugs.
- **Analytics:** which screens are opened and the outcome of some actions (e.g. the paywall being
shown, a purchase result, a data service returning an error), device model, Android version, app
version, language, and **country/region** derived from the IP address. A random app-specific
installation ID is used. **Coordinates are not sent.**
- **Crashlytics:** when the app crashes or hits an unexpected error, a technical error log, device
model, Android and app version.
- **The Advertising ID is not used;** it has been deliberately removed from the app. This data is not
used for advertising or profiling.
### f) Data that stays on your device (not sent to any server)
Catch log entries, catch photos, saved spots, trip plans, tackle box and statistics are kept in an
**encrypted local database** on your device. Photos are added through the system photo picker/camera
app and stay on the device. The experimental "suggest species" feature processes the photo **on the
device** (Google ML Kit); the photo is not uploaded.
### g) Notifications
Bite-time, closed-season and condition reminders are generated **locally on the device**; no push
notifications are sent from a server.
### h) Subscription / purchase data (only if you buy Pro)
MeraRadar Pro is purchased through **Google Play Billing**, and the subscription status is managed with
**RevenueCat**. Data processed: **purchase history** (which subscription, purchase/renewal time,
subscription status), an app-generated **user ID** and **IP address**.
- **Why:** To recognise your subscription, unlock Pro features and support "restore purchases".
- Your card details are processed **only by Google**; we never see or store them.
## 3. Third-Party Services
The app uses the following services; their own privacy policies apply:
- **Open-Meteo** (weather/sea data): coordinates are sent.
- **OpenTopoData** (elevation), **EMODnet** (depth): coordinates are sent.
- **Copernicus Marine Service** (water productivity): via the MeraRadar server function, with the location rounded to an area.
- **OpenStreetMap / OpenFreeMap, OpenSeaMap, Esri, EMODnet** (map tiles): the viewed map area is requested.
- **Wikimedia Commons** (species images): images are downloaded.
- **Google Firebase** (Firestore, Anonymous Authentication, Analytics, Crashlytics, App Check, Cloud Functions), **Google Play Billing**, **Google Play In-App Review**, **Google ML Kit** (on-device): [Google Privacy Policy](https://policies.google.com/privacy).
- **RevenueCat** (subscription status): purchase history, user ID and IP are sent; [RevenueCat Privacy Policy](https://www.revenuecat.com/privacy/).
## 4. Sharing and Sale of Data
We **do not sell** your data and **do not share it for advertising**. The app contains no ads or ad
networks. Data is sent only to the service providers above, as far as needed for the app to work.
What you post on the Idea Board (see 2c) is public by design.
## 5. Security
On-device data is encrypted with **SQLCipher**. All network traffic is encrypted with **HTTPS/TLS**. No
method is 100% secure, but reasonable measures are taken to protect your data.
## 6. Retention
- **Device data:** stays on your device until you delete it or uninstall the app.
- **Messages and email address:** kept for support; deleted on request.
- **Ideas and votes:** kept while the board is live; deleted on request.
- **Analytics:** for the retention period set in Google Analytics (at most 14 months).
- **Crashlytics:** crash logs for 90 days.
## 7. Your Rights
Depending on where you live (for example under Türkiye's KVKK or the EU/UK GDPR), you may have the
right to access, correct or delete your personal data and to object to its processing.
- **Legal basis:** Location processing, messages, ideas and subscriptions are based on providing the
features you request (performance of a contract / consent). Usage statistics and crash reports are
based on our **legitimate interest** in keeping the app secure and working.
- **Deletion requests:** Email **akcautku@gmail.com** to have your messages, email address or ideas
deleted. You can delete on-device data by clearing the app's data or uninstalling it.
## 8. Children's Privacy
The app is not directed at children and does not knowingly collect data from children under 13.
## 9. Changes
This policy may be updated; for significant changes the "Last updated" date is changed.
## 10. Contact
Questions: **akcautku@gmail.com**