Last Updated: 24 August 2026
Thank you for using Tudory. This Privacy Policy explains what personal data the Tudory mobile application ("the app", "Tudory") collects, how it is used, who it is shared with, and the rights you have. It applies to your use of the app on both Apple iOS and Google Android. It does not apply to information you choose to send us directly by email or social media, which is handled outside the app.
Tudory is developed and operated by Akıncan Alan, an independent (sole) developer based in Türkiye ("we", "our", "us"). For the purposes of the EU/UK General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law No. 6698 (KVKK), the data controller is Akıncan Alan.
We apply the principle of data minimisation across all jurisdictions: we collect only what the app genuinely needs to function, and we do not request access to your camera, microphone, contacts, precise location, biometric data, or full photo library.
Contact: tudoryapp@gmail.com
Depending on how you sign up, we collect:
Email & password sign-up: your name, email address, a securely stored password, and the user type/category you choose during onboarding (e.g. student, professional).
Sign in with Apple / Sign in with Google: the unique user identifier provided by Apple or Google, your name, and your email address. Your user type/category is also requested during onboarding. Google sign-in is performed through a standard OAuth web flow; Apple sign-in uses Apple's native token exchange.
Separately from sign-up, we also collect:
Profile photo (optional): a profile photo that you can add, change or remove at any time from your profile — this is not part of registration.
Country/region: a country/region code that the app derives automatically from your device's regional (locale) settings — you are not asked to enter it. It is used, for example, to suggest relevant study rooms.
To provide its core functions (focus timing, planning, statistics and collaborative study rooms), the app collects and synchronises the content you create:
Study & focus: study sessions (date, start/end time, total duration), labels/tags assigned to sessions, session notes, and free-form daily notes.
Planning & tasks: task titles, descriptions, colour and icon preferences, recurrence rules (daily, weekly, monthly and intervals), reminder schedules, subtasks, and the completion, postponement or cancellation state of each task and occurrence.
Goals & statistics: daily target study minutes, goal achievement status, tag-based study distribution, and study streaks (current streak, longest streak, last study date).
Workspaces & collaboration: the names and hierarchy of the personal, organisation or group workspaces you belong to, your role in each (e.g. owner, admin, member, observer), your invitation/delegation privileges, invitations you send (recipient email address, assigned role, invitation status and quota), and workspace seat capacity.
Study rooms: rooms you create or join, including room name, description, cover image, join settings and questions, your answers to join questions, membership and "currently studying" status, and the chat messages you post in a room.
System data: your device's local time zone (so times display correctly for you) and record timestamps for creation, update and deletion.
Crash and performance data (Firebase Crashlytics): crash reports and error logs, which include technical details such as device model and operating system version. These are not intended to contain personal data.
Usage analytics (Firebase Analytics): anonymised, aggregated interaction data about which features are used and how often, to help us improve the app. We have disabled advertising-identifier collection on both platforms: the app does not collect the Android Advertising ID or the iOS advertising identifier (IDFA), does not use App Tracking Transparency, and does not track you across other apps or websites.
Remote configuration (Firebase Remote Config): non-personal configuration values used to adjust features remotely; this does not collect personal data.
Our minimum-data principle: we do not access, or request permission to access, your camera, microphone, contacts, precise location, biometric data, or your full photo library. When you set a profile photo or a room cover image, you pick a single image using your device's built-in system photo picker; the app receives only the image you select, not your library.
We process your personal data on the following legal bases (as applicable under GDPR, KVKK and comparable laws):
To provide the service (performance of a contract): managing your account, syncing your data across your devices, enabling workspace and study-room features, and showing you your statistics and tasks. These are necessary to perform our Terms of Use with you.
Subscription and payment management: Tudory Pro purchases and cancellations are handled entirely by your app store — the Apple App Store on iOS and Google Play on Android. We use RevenueCat to verify purchases and grant your subscription entitlement. We do not collect or store your card or financial data; all payments occur through your app store's secure infrastructure.
Communication and security (legitimate interests / performance of a contract): we use Resend as our email delivery provider to send required messages such as account verification, password resets, workspace invitations, important service or maintenance notices, and security notifications.
Improving the app (legitimate interests / consent where required): diagnostic and analytics data as described in Section 2.3. Where local law requires consent for analytics, we rely on that consent.
We do not sell or rent your personal data, and we do not share it with third parties for their own targeted advertising.
Cloud infrastructure: your account and app data are hosted by Supabase on servers located in the European Union (Frankfurt, Germany).
On-device secure storage: your session/authentication tokens and identity details are kept in your device's hardware-backed secure store — the iOS Keychain on Apple devices and the Android Keystore-backed secure store on Android.
On-device app database: your sessions, tasks, notes and statistics are stored in a local database within the app's private storage on your device so the app works offline. This data is protected by your operating system's built-in storage encryption; the app does not add its own separate encryption layer.
Security measures: all data transmitted between your device and our servers is encrypted in transit. Passwords are stored only as modern cryptographic hashes, never in plain text. Access is isolated per account and per workspace through server-side access rules reinforced on the client.
While we take these measures, we cannot guarantee absolute security.
We rely only on the following providers, each for a specific, necessary purpose:
Supabase — database hosting and authentication; servers in the EU (Germany).
RevenueCat — verifying App Store / Google Play purchases and granting your Pro entitlement; no card data.
Resend — delivering transactional emails (verification, password reset, invitations).
Firebase / Google — crash reporting (Crashlytics), aggregate usage analytics (Analytics, without advertising identifiers), and remote configuration (Remote Config).
Apple — Sign in with Apple and App Store purchases on iOS; Apple is the seller of record for App Store purchases.
Google — Sign in with Google and Google Play purchases on Android; Google is the seller of record for Google Play purchases.
Each provider processes data under its own terms and privacy policy.
Your personal workspace is private to you and cannot be seen by other users.
If you join a group or organisation workspace via an invitation link, the content you create in that workspace — including, without limitation, tasks, notes and study durations — can be viewed by the administrators and other authorised members of that workspace.
In a study room, other members can see your profile name and photo, the study statistics shown on the room's leaderboard (such as your daily and weekly study time), whether you have a Pro subscription, and your live "currently studying" status. Public study rooms can be discovered and joined by other users, so this information should be treated as visible to other users. Chat messages you post in a room are visible to that room's members.
Leaving a workspace or room does not automatically delete content you previously shared there.
We keep your data for as long as your account is active.
When you use Delete Account in the app, your account enters a 30-day waiting period during which you can recover it by signing back in. After 30 days the deletion becomes permanent and irreversible. At that point, the data tied to your personal workspace and your personal study records are permanently deleted, and your profile photo and any room cover images you uploaded are removed from storage.
Content you created in a group or organisation workspace, and messages you posted in study rooms, are anonymised rather than deleted, because this content forms part of that shared workspace's records and of the room's conversation; it is no longer linked to your identity.
Data we are required to keep for legal reasons (for example, records related to billing or tax, which are held by the app stores) may be retained for the periods required by applicable law.
For full details of what is deleted, kept and anonymised, see our separate Account Deletion page.
You have control over your account:
Access and correction: view and edit your profile and data directly in the app.
Deletion: delete your account at any time via Settings → Profile → Delete Account. If you can no longer access the app, email us from your registered address to request deletion.
Notification control: the app uses only local device notifications; you can disable them in your device settings at any time.
Data export: contact us at tudoryapp@gmail.com to request a copy of your data.
If you are in the European Economic Area or the United Kingdom, you have the rights to access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and to object to processing, subject to the conditions provided under applicable law. Where we rely on consent, you may withdraw it at any time. You also have the right to lodge a complaint with your local data protection supervisory authority. To exercise these rights, contact tudoryapp@gmail.com.
International transfers are described in Section 11.
If you reside in Türkiye, under Law No. 6698 (KVKK) you have the right to learn whether your personal data is processed, to request information about the processing, to learn its purpose and whether it is used accordingly, and to request correction, deletion or destruction of your data, among other rights set out in Article 11, subject to the conditions provided under applicable law. You may submit your requests to tudoryapp@gmail.com, and they will be concluded within 30 days at the latest as required by law.
To provide the service globally, your data is stored on servers in the EU (Supabase, Germany) and may be processed by our sub-processors (Section 5) in other countries. Where data is transferred outside your country or the EEA/UK, we rely on appropriate safeguards recognised under applicable data protection law, such as the European Commission's Standard Contractual Clauses.
Because creating an account and using cloud synchronisation requires processing personal data, Tudory is intended for users aged 13 and over. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it.
Timer alerts and reminders are generated locally on your device and do not require an internet connection. We do not send push notifications or advertisements from our servers to your device.
We use aggregate analytics (Firebase Analytics) only to understand which features are used and how often. We do not use advertising identifiers, we do not track you across other apps or websites, and we do not show advertising in the app. Because we do not track you across other companies' apps or websites, the app does not present an App Tracking Transparency prompt.
We may update this Privacy Policy as the app evolves. The "Last Updated" date at the top reflects the current version, and we encourage you to review this policy periodically.
Data Controller / Developer: Akıncan Alan
Email Support: tudoryapp@gmail.com
© 2026 Akıncan Alan. All rights reserved.