Privacy Policy

Last updated:

This policy explains what information the Sinyal mobile app for iOS and Android (“Sinyal”, “we”, “us”) processes, why we process it, who we share it with, how long we keep it and what choices you have. It applies to the app and to these web pages.

The short version
  • We do not store your photos or videos. They are sent to our server and passed to Google’s Gemini API only to produce your analysis.
  • Reports are text. They stay on your phone unless you turn on “Back up reports to my account”, which is off by default.
  • No advertising, no selling of personal data and no third-party analytics SDK in the app.
  • If you play the Signal Hunt game, your hunter name, avatar and season XP are visible to other players in the ranking; your email never is.
  • You can delete your account and all synced data from the app at any time.

1. Who is responsible for your data

Sinyal is published by Ferhat Gör, trading as Fernis Labs (sole proprietorship; Avcılar Tax Office, tax no. 4090798320), Tahtakale Mah. Gülfidan Sk. No: 3 İç Kapı No: 1, Avcılar / İstanbul, Türkiye. This person is the data controller for the personal data described in this policy under the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and, where it applies, the EU/UK General Data Protection Regulation (“GDPR”).

Contact for all privacy matters: destek@fernislabs.com.

The data controller is exempt from registering with the Data Controllers’ Registry (VERBİS) under the exemption criteria set by the Personal Data Protection Board (data controllers with fewer than 50 employees per year whose main activity is not processing special categories of personal data), so no contact person has been appointed. Sinyal is not currently offered in the European Union or the United Kingdom; if it becomes available there, a representative under GDPR Art. 27 will be appointed and this policy updated.

2. Your account

You need an account to use Sinyal. You can sign in with Google, with Apple (on iPhone and iPad) or with an email address and password. Sign-in is provided by Firebase Authentication, a service of Google LLC.

Firebase stores:

  • your account ID (a random identifier called a UID),
  • your email address,
  • your display name, if one is available,
  • which sign-in method you use (Google, Apple or email).

If you use email and password, your password is handled by Firebase Authentication and is not stored in our own database. Email accounts must verify their address before they can use the AI features; Firebase sends the verification and password reset emails.

Why: to create and protect your account, to link your preferences, progress and subscription to you, and to apply the usage limits of your plan.

3. Photos, videos and the AI analysis

What happens when you start an analysis

  1. You choose one photo (body-language analysis), or two photos or a video of up to 10 seconds (compatibility analysis).
  2. The app uploads the media over an encrypted HTTPS connection to our backend, which runs on Supabase (Supabase Inc.) in the Seoul, South Korea region (ap-northeast-2).
  3. Our backend forwards the media to Google’s Gemini API (Google LLC), which returns a structured text analysis.
  4. You receive a text report: observations, possible interpretations and alternatives. The report does not contain the photo or video.

Your consent

Before any media is sent, the app explains that it will be processed by Google Gemini and asks for your explicit consent for that analysis. If you do not give consent, no media is sent and the analysis cannot start. When you start using Sinyal you also agree to use only media you have permission to share and never media of children; we cannot check this, and it is your responsibility. Consent is asked for each analysis separately; the wording in the app is, for example: “I agree to send this image to our AI service provider for analysis.” As there is no ongoing consent, you can stop at any time by not giving it for the next analysis. Because Sinyal does not store media it has sent, there is no stored copy to withdraw.

Videos

Videos may be compressed on your device before upload. When a video is re-encoded this way, its audio track is removed. Small videos may be uploaded as you picked them, which means the original file, including any sound, is sent.

We do not store your media

Sinyal does not store raw photos or videos: they are not kept in your history, in your account or in our database. They are used only to produce the analysis you requested.

Google’s role

Google processes the media and the request as a service provider under its Gemini API terms. How Google handles API data is governed by Google’s own terms, not by us: https://ai.google.dev/gemini-api/terms.

Before forwarding a photo or video to Google, our server removes metadata embedded in the file, such as location (EXIF/GPS), camera and device details and comments. This applies to JPEG, PNG and WebP photos, HEIC photos from iPhones, and MP4 and MOV videos. A rare file whose structure cannot be read may be forwarded without this cleaning. Videos may include their sound.

AI coach (Pro)

When you ask the AI Coach a question, your question, up to the last 12 messages of that conversation and the text of the related report are sent through our server to the Google Gemini API to produce a reply. No photo or video is sent. Coach conversations are not stored on our server or on your device; they are cleared when you close the report.

4. What we store on our servers

Our database is a Supabase Postgres database. The tables listed below are in a private schema that only our server code can access; the app cannot read them directly.

  • Usage and rate-limit counters, linked to your account ID. They enforce the daily limits of your plan (analyses, how many of them were videos and, for Pro, AI coach messages) and protect the service from abuse. Daily usage rows are deleted within 3 days at most.
  • Request records for retries. For each analysis request we keep, for up to 24 hours, a request identifier, a fingerprint of the request (a one-way hash of the uploaded content, used to recognise a retry of the same request; the photo or video cannot be recovered from it), the number of attempts and the structured analysis result. If your connection drops, the app can collect the result without running (and counting) the analysis again, and if you subscribe to Pro within that time, the full version of a report made on the free plan can be opened. These records contain no photos or videos and are deleted immediately when you delete your account.
  • Free full report record. Every account gets one free full report; we record which analysis used it.
  • Profile. Created when you open the app while signed in, it keeps your Profile screen the same on another phone: the avatar you chose, the times of your avatar changes (to apply the change limit; only the last 7 days count), your daily visit streak, your best streak and the last day you opened the app (a calendar date in your own time zone), the number of analyses you have completed (just a number, not the reports) and, if you play Signal Hunt, your hunter name.
  • Account sync profile. So you can continue on another phone: your dictionary learning progress (IDs of learned cues, completed collections, visit streak) and the preferences you have changed (app language, “Save reports on this device” and “Back up reports to my account”).
  • Report backup — only if you turn it on. “Back up reports to my account” is off by default. When it is on, your structured text reports are stored with your account. Photos and videos are never backed up. If you turn backup off, the copies on our servers are deleted. When you delete a single report, we keep a marker without any report content so that your other devices do not upload that report again.
  • Signal Hunt records — only if you play. Your hunter name, game state, question history and season scores. See section 5 for details.

Like most online services, our hosting provider also records short-lived technical logs of requests (which can include, for example, IP address, time and error details) for operation and security. These logs are kept in our hosting provider’s system for at most 7 days and are then deleted automatically.

5. Signal Hunt and the ranking

Signal Hunt (Sinyal Avı) is an optional game in which you try to find body-language cues in ready-made question photos. It has a seasonal ranking (“Night Flight”). You need to be signed in to play, and email accounts must have verified their address. We prepare the question photos ourselves: the game never uses your own photos or videos, and game data is not sent to Google Gemini or any other AI service.

What we keep on our server

  • Hunter name: the name you choose before your first question, shown in the ranking (2 to 16 characters). We recommend not using your real name or anything that could identify you.
  • Avatar: the owl you chose in your profile (kept in the profile record described in section 4); it is shown next to your name in the ranking.
  • Game state: your lives (owls) and when they wake, your streaks, whether you are resting after a practice run, your progress in the current set, your total XP, the number of questions you have solved, the IDs of the last 12 or fewer questions you were given, the question waiting for your answer and when it was given to you, the next question, and the last check of your Pro status (used for up to 10 minutes, then checked again).
  • Question history: the ID of each question you were given, whether you solved it and when it was last shown. It is used to put questions you have not seen first.
  • Season scores: each calendar month (in UTC) is a season. For each season we keep your XP, the number of right answers that scored, your best streak and when your score last grew. Your place and your end-of-season summary are calculated from these.

We do not store your answers (the point you tapped or the option you chose): our server checks the answer and records only the outcome (XP, streak, lives). Answer speed is measured by our server’s clock, not your phone’s, and answers that arrive faster than a person could give them are not accepted.

What other players see

When you earn XP in a season, you appear in that season’s ranking. Other signed-in players see only this about you there: your place, your hunter name, your avatar and your XP for that season. The ranking shows each player the season’s top 90 and a few players close to their own place, so some players can see you whatever your place. For the first 7 days of a new season, the top three of the previous season are also shown with the same details. Your email address, the display name from your sign-in provider and your account ID (UID) are never shown. A player without a hunter name appears as “Mystery hunter”.

How hunter names are checked

Before a hunter name is saved, our server checks it against an automatic list of insults and swear words. Names containing “@” are refused, so an email address cannot appear as a name. This check does not catch every unsuitable name; if you see one, please email us.

Your choices

  • You can change your hunter name at any time on the app’s Profile screen. You can also change your avatar there, within the change limit shown in the app.
  • There is currently no separate setting to stay out of the ranking. If you do not want to appear in it, do not earn XP in Signal Hunt.
  • When you delete your account, your hunter name, avatar, game state, question history and all your season scores, including past seasons, are deleted immediately, and you leave every ranking. If you want your game data deleted without deleting your account, email us.

Why and for how long

We process this data to provide the game and the ranking you asked for (performance of a contract) and to protect the game against cheating and abuse (legitimate interests). Game data, including past seasons’ scores, is kept until you delete your account. When you change your hunter name, the new one replaces the old one.

6. What stays on your device

  • Report history: if “Save reports on this device” is on (it is on by default), your structured reports are stored on your phone. You can delete a single report or all reports at any time.
  • Dictionary progress and preferences, including your reminder settings.
  • Daily reminder: the optional learning reminder is a local notification scheduled on your phone. We do not use a push notification server.
  • Signal Hunt season summary: so the last season’s summary is shown only once, your phone records which season’s summary you have seen.

The app asks for device permissions (for example photo library or notifications) only when a feature needs them. You can change them in your phone’s settings. The permissions the app may ask for are: the camera, to take a photo or record a short video; the photo library, to choose the photo or video to analyse; and notifications, for dictionary reminders. On iOS, recording a video with the camera also asks for microphone access; sound is not analysed. On Android the app does not ask for the microphone.

7. Subscriptions and payments

Payments are handled by the Apple App Store or Google Play. We never receive your card or bank details. RevenueCat (RevenueCat Inc.) manages subscription status for us: it processes purchase and entitlement data (such as which plan you bought, purchase, renewal and expiry dates and store transaction identifiers), linked to your Firebase account ID, so that Pro works on the devices where you sign in.

8. Service providers

We only share data with the providers we need to run Sinyal. They act on our behalf or, for the app stores, under their own terms with you.

ProviderWhat forData involved
Google LLC — Firebase AuthenticationSign-in and account managementUID, email, display name, sign-in provider
Google LLC — Gemini APIProducing the AI analysisPhotos/videos you submit and the analysis request (API terms)
Supabase Inc.Backend and database (region ap-northeast-2, Seoul)Media in transit; the server-side data listed in sections 4 and 5; technical logs
RevenueCat Inc.Subscription managementPurchase and entitlement data linked to your UID
Apple Inc. / Google LLC — App Store and Google PlayApp distribution and paymentsPurchase and payment data under their own privacy policies
Expo (650 Industries, Inc.)Delivering app updates (EAS Update)Device and app metadata sent when the app downloads an update

We may also disclose data where the law requires it, for example to a court or public authority with a valid legal request.

9. International transfers

Our providers store or process data outside Türkiye and possibly outside your country: our backend is in South Korea, and Google, RevenueCat, Apple and Expo operate from the United States and other countries. As no country has yet been recognised as adequate for Türkiye, these transfers rely on the standard contracts published by the Personal Data Protection Board under KVKK Art. 9; each standard contract is notified to the Authority within five business days of signature. Where the GDPR applies, we rely on the Standard Contractual Clauses in the providers’ data processing terms.

10. How long we keep data

DataHow long
Photos and videosNot stored by Sinyal; used only while your request is processed. Google’s handling is governed by its API terms.
Request records (incl. the structured result)Up to 24 hours; deleted immediately when you delete your account
Daily usage countersUp to 3 days
Rate-limit countersAbout 20 minutes
Free full report recordUntil you delete your account; deleted immediately when you do
Profile (avatar, avatar change times, visit streak, last visit day, completed analyses count)Until you delete your account; deleted immediately when you do. Avatar change times older than 7 days are dropped at your next avatar change.
Account sync profileUntil you delete your account
Report backupUntil you delete the report, turn backup off or delete your account (content-free deletion markers are removed with the account)
Signal Hunt hunter nameUntil you change it or delete your account; deleted immediately when you do
Signal Hunt game state, question history and season scores (incl. past seasons)Until you delete your account; deleted immediately when you do
Account data in FirebaseUntil you delete your account
Technical server logsUp to 7 days
Subscription recordsKept by RevenueCat, Apple and Google as required for billing, tax and legal purposes
Data on your deviceUntil you delete it, delete your account or uninstall the app
Emails you send us1 year
  • To provide the service you asked for (KVKK Art. 5(2)(c); GDPR Art. 6(1)(b)): your account, the analyses you request, syncing, report backup, Signal Hunt and its ranking, and subscriptions.
  • Your explicit consent (KVKK Art. 5(1); GDPR Art. 6(1)(a)): sending your photos and videos to Google Gemini for analysis.
  • Our legitimate interests (KVKK Art. 5(2)(f); GDPR Art. 6(1)(f)): usage limits, preventing abuse (including cheating in Signal Hunt and checking hunter names), keeping the service secure and running.
  • Legal obligations (KVKK Art. 5(2)(ç); GDPR Art. 6(1)(c)): where the law requires us to keep or disclose data.

Special categories of personal data. Photos and videos are not processed to recognise, identify or verify anyone; the analysis only interprets visible posture and gestures. An image counts as biometric data only when it goes through specific technical processing that allows a person to be uniquely identified, and Sinyal does no such processing. The AI is also explicitly told not to draw conclusions about health, religion, ethnic origin, sexual orientation or other sensitive traits. Sinyal therefore does not knowingly process special categories of personal data under KVKK Art. 6 or GDPR Art. 9. Upload photos or videos showing other people only with their permission.

The analyses are generated automatically by AI, but we do not use them to make decisions about you.

12. Security

Data travels between the app and our backend over HTTPS. Server-side data is kept in a private database schema that only our server code can access, and sign-in is handled by Firebase Authentication. No system is perfectly secure, but we limit what we keep: we do not store your photos or videos at all.

13. Your rights (KVKK and GDPR)

Under KVKK Article 11 you can ask us whether we process your personal data and request information about it, learn the purpose of processing and whether data is used for that purpose, know the third parties in Türkiye or abroad to whom data is transferred, ask for incomplete or incorrect data to be corrected, ask for data to be deleted or destroyed and for those third parties to be told, object to a result that is against you and arises only from automated analysis of your data, and claim compensation if you suffer damage from unlawful processing.

If the GDPR applies to you, you have the rights of access, rectification, erasure, restriction, data portability and objection, and you can withdraw consent at any time (this does not affect processing before the withdrawal).

How to use your rights. Many things you can do yourself in the app: delete reports, turn backup off, change preferences and your hunter name, or delete your account (see how). For anything else, email destek@fernislabs.com, preferably from your account’s email address. We may ask you to confirm your identity. We will answer within 30 days at the latest.

Complaints. You can complain to the Personal Data Protection Board in Türkiye (kvkk.gov.tr) or, if the GDPR applies, to the data protection authority where you live or work. We would appreciate the chance to fix the problem first.

How to apply under KVKK. Under the Communiqué on the Procedures and Principles of Application to the Data Controller, you can send your application in Turkish by a signed letter to our postal address below, signed with a secure electronic or mobile signature, or from the email address registered in your Sinyal account to destek@fernislabs.com. Include your name, (for letters) your signature, your Turkish ID number (or nationality and passport number), an address for notifications and your request. We will resolve it free of charge as soon as possible and within 30 days at the latest.

14. Other people in your photos and videos

Only upload media that you have the right to use and that the other people shown have agreed to share. You agree to this, and to never analysing anyone under 18, when you start using Sinyal; the rules are also explained in the app’s Settings. We cannot verify that they are followed. Because we do not store photos or videos, we cannot find or delete a specific image later. Reports are kept on the uploader’s device and, if they enabled backup, in their account. If you believe someone analysed you without permission, contact us and we will help where we can.

15. What an analysis can and cannot tell you

An analysis interprets visible signals only. It cannot determine anyone’s intent, emotions, honesty, personality, health or the outcome of a relationship with certainty, and it is not professional, medical, psychological, legal or HR advice. Do not use Sinyal for surveillance, harassment or discrimination, or to make decisions about someone’s employment, credit or housing. Full rules are in the Terms of Use.

16. Age limit

Sinyal is intended only for people aged 18 and over; the terms of the AI service that produces the analyses also require this. We do not knowingly allow accounts for children. If you believe a child has created an account, contact us and we will delete it.

Photos and videos of children must not be analysed. You agree to this when you start using Sinyal; we cannot verify it. As an additional safeguard, the same AI request that produces an analysis first checks whether the media clearly shows a child (such as a baby or young child). If it does, no report is produced or kept; the request is recorded only as refused, without any content, for up to 24 hours. This check does not determine anyone’s age, can miss teenagers or unclear images, and can occasionally stop an image of an adult. Because it runs on the AI service, the media has already been sent to Google by the time it applies.

17. Things we do not do

  • We do not show advertising.
  • We do not sell personal data.
  • We do not include a third-party analytics SDK in the app.
  • We do not store your photos or videos.

18. Changes to this policy

If we change how we handle data, we will update this page and the date at the top. For significant changes we will also let you know in the app before they take effect.

19. Contact

Fernis Labs · Ferhat Gör
Tahtakale Mah. Gülfidan Sk. No: 3 İç Kapı No: 1, Avcılar / İstanbul, Türkiye
Email: destek@fernislabs.com