Veri sorumlusu: Firenite
İletişim: info@firenitetr.com
Sandık bir banka, ödeme kuruluşu, aracı kurum veya kripto varlık hizmet sağlayıcısı değildir. Para gönderme, hesap açma, yatırım emri verme veya kripto transferi yapmaz. Kullanıcılar varlık, borç, gelir ve gider kayıtlarını kendileri ekler.
Aşağıdakiler yalnızca kullanıcının cihazında saklanır ve sunucularımıza gönderilmez:
Sandık bu kayıtları banka hesabına bağlanmak, ödeme başlatmak veya yatırım işlemi yapmak için kullanmaz; reklam isteklerine de eklemez.
Sandık'ı kullanmak için hesap açmak zorunlu değildir. "Cihazda devam et" seçeneğiyle hiçbir sunucu kaydı oluşturmadan tüm özellikler kullanılabilir.
Kullanıcı Apple veya Google ile giriş yapmayı seçerse kimlik doğrulaması Google Firebase Authentication üzerinden yapılır ve aşağıdaki veriler işlenir:
| Veri | Amaç | Hukuki dayanak |
|---|---|---|
| Ad | Profilde gösterim | Sözleşme ifası |
| E-posta adresi | Hesabın tekilliği, destek | Sözleşme ifası |
| Kullanıcı kimliği (UID) | Hesabın tanınması | Sözleşme ifası |
Giriş doğrulandıktan sonra Firebase oturumu kapatılır; cihazda yalnızca yerel profil saklanır.
Giriş yapan kullanıcılar için hesap başına tek bir kayıtta aşağıdaki teknik meta veriler tutulur. Bu kayıt hiçbir finansal bilgi içermez:
| Ne tutulur | Amaç | Hukuki dayanak |
|---|---|---|
| Hesabın oluşturulma ve son giriş zamanı | Hesap yönetimi, güvenlik, atıl hesap tespiti | Meşru menfaat |
| Giriş yöntemi (Apple / Google), platform, uygulama sürümü ve seçili arayüz dili | Hizmetin sunulması, hesap silmede doğru doğrulama, destek ve hata çözümü | Sözleşme ifası, meşru menfaat |
| Reklam onayı ve izleme izni kararınız + zaman damgası | Rızanın ispatı | Hukuki yükümlülük |
| Kabul ettiğiniz politika sürümü + zaman damgası | Kabulün ispatı | Hukuki yükümlülük |
| Son girişteki abonelik durumu | Abonelik hakkının doğrulanması, destek | Sözleşme ifası |
Ad ve e-posta bu kayda bilerek kopyalanmaz; kimlik doğrulama servisinde zaten mevcuttur.
Premium aboneliklerin satın alınması ve geri yüklenmesi Apple App Store veya Google Play tarafından işlenir. Sandık ödeme kartı bilgilerini görmez ve saklamaz. Aboneliğin aktif olup olmadığı bilgisi, §3.1'de anlatılan hesap kaydında son giriş anına ait olacak şekilde tutulur.
Google AdMob aracılığıyla banner, uygulama açılışı, geçiş ve yerel reklamlar gösterilir. Reklamlar Premium abonelik durumundan bağımsız olarak gösterilir; Premium'un sunduğu ayrıcalıklar arasında reklamsız kullanım yer almaz.
AdMob; reklam sunumu, sıklık kontrolü, sahtekârlığın önlenmesi ve performans ölçümü için aşağıdaki verileri işleyebilir:
| Veri türü | Amaç | Kimliğe bağlı | İzleme amaçlı |
|---|---|---|---|
| Cihaz tanımlayıcı (reklam kimliği / IDFA) | Üçüncü taraf reklamcılığı, analiz | Hayır | Evet |
| Reklam verisi (görülen reklamlar) | Üçüncü taraf reklamcılığı | Hayır | Evet |
| Ürün etkileşimi (açılış, dokunma, görüntüleme) | Üçüncü taraf reklamcılığı, analiz | Hayır | Evet |
| Diğer tanı verileri | Analiz | Hayır | Hayır |
Ayrıca hesap kaydındaki son giriş zamanı bir uygulama açılışı kaydı olduğu için "ürün etkileşimi" kapsamındadır ve kimliğe bağlıdır; ancak reklam amacıyla üçüncü taraf verisiyle birleştirilmez.
İzleme (tracking) ne demek: yukarıda "Evet" işaretli veriler, reklamcılık ve reklam ölçümü amacıyla üçüncü tarafların verileriyle ilişkilendirilebilir.
Onay ve kontrol:
Bu işlemler Google'ın gizlilik politikası kapsamındadır. Sandık; manuel finans kayıtlarını, IBAN bilgilerini veya bakiyeleri reklam isteğine eklemez.
api.frankfurter.dev, api.gold-api.com). Bu istekler yalnızca güncel fiyatı almak içindir; varlık, IBAN ve hareket kayıtları gönderilmez. Her ağ isteğinde olduğu gibi cihazın IP adresi ilgili servis tarafından görülebilir.Bu sürümde kamera veya fotoğraf kitaplığı erişimi istenmez; fiş/dekont tarama özelliği kullanıma kapalıdır.
| Veri | Süre |
|---|---|
| Cihazdaki finansal kayıtlar | Kullanıcı silene veya uygulamayı kaldırana kadar |
| Hesap meta verisi ve kimlik kaydı | Hesap silinene kadar; en fazla 24 ay giriş yapılmayan hesaplarda silinir |
| Reklam tarafındaki veriler | Google'ın saklama politikalarına tabidir |
Profil → "Hesabımı ve tüm verilerimi sil" işlemi tek akışta:
Kullanıcının daha önce Dosyalar/iCloud Drive gibi başka bir konuma aktardığı yedekler, saklandıkları yerden ayrıca silinmelidir.
Kişisel verilerinize ilişkin olarak; işlenip işlenmediğini öğrenme, erişme, düzeltilmesini, silinmesini veya kısıtlanmasını isteme, işlemeye itiraz etme ve verilerinizin taşınmasını talep etme haklarına sahipsiniz. Meşru menfaate dayanan işlemelere her zaman itiraz edebilirsiniz.
Silme talebinin en hızlı yolu uygulama içindeki §9'daki akıştır. Diğer talepler için info@firenitetr.com adresine yazabilirsiniz. Talepler en geç 30 gün içinde sonuçlandırılır. Sonuçtan memnun kalmazsanız Kişisel Verileri Koruma Kurumu'na (KVKK) şikâyette bulunma hakkınız saklıdır.
Kimlik doğrulama ve hesap meta verisi Google (Firebase), reklam verileri ise Google (AdMob) altyapısında işlenir. Bu hizmetler verileri Türkiye dışındaki sunucularda işleyebilir.
Sandık çocuklara yönelik tasarlanmamıştır ve bilerek çocuklardan kişisel veri toplamaz.
Bu politika, uygulama özellikleri veya veri uygulamaları değiştiğinde güncellenir. Önemli değişikliklerde politika sürümü artırılır ve kullanıcının bir sonraki girişinde yeni sürüm kaydedilir.
← Destek sayfasına dönData controller: Firenite
Contact: info@firenitetr.com
Sandık is not a bank, payment institution, brokerage or crypto-asset service provider. It does not send money, open accounts, place investment orders or transfer crypto. Users add their own asset, debt, income and expense records manually.
The following is stored only on the user's device and is never sent to our servers:
Sandık does not use these records to connect to a bank account, initiate a payment or execute an investment transaction, and never attaches them to ad requests.
Creating an account is not required to use Sandık. With "Continue on this device" every feature can be used without creating any server-side record.
If the user chooses to sign in with Apple or Google, authentication is handled by Google Firebase Authentication and the following data is processed:
| Data | Purpose | Legal basis |
|---|---|---|
| Name | Display on the profile | Performance of a contract |
| Email address | Account uniqueness, support | Performance of a contract |
| User ID (UID) | Identifying the account | Performance of a contract |
Once the credential is verified the Firebase session is closed; only a local profile is kept on the device.
For signed-in users, the following technical metadata is kept in a single record per account. This record contains no financial information:
| What is kept | Purpose | Legal basis |
|---|---|---|
| When the account was created and last signed in | Account management, security, detecting dormant accounts | Legitimate interest |
| Sign-in method (Apple / Google), platform, app version and selected interface language | Providing the service, correct verification on account deletion, support and troubleshooting | Performance of a contract, legitimate interest |
| Your ad consent and tracking permission decision + timestamp | Proof of consent | Legal obligation |
| The policy version you accepted + timestamp | Proof of acceptance | Legal obligation |
| Subscription status at last sign-in | Verifying subscription entitlement, support | Performance of a contract |
Name and email are deliberately not copied into this record; they already exist in the authentication service.
Purchasing and restoring Premium subscriptions is handled by the Apple App Store or Google Play. Sandık never sees or stores payment card details. Whether the subscription is active is kept in the account record described in §3.1, as of the last sign-in.
Banner, app-open, interstitial and native ads are shown through Google AdMob. Ads are shown regardless of Premium subscription status; an ad-free experience is not among the benefits Premium offers.
AdMob may process the following data for ad serving, frequency capping, fraud prevention and performance measurement:
| Data type | Purpose | Linked to identity | Used for tracking |
|---|---|---|---|
| Device identifier (advertising ID / IDFA) | Third-party advertising, analytics | No | Yes |
| Advertising data (ads seen) | Third-party advertising | No | Yes |
| Product interaction (launches, taps, views) | Third-party advertising, analytics | No | Yes |
| Other diagnostic data | Analytics | No | No |
In addition, the last sign-in time in the account record is a record of an app launch and therefore falls under "product interaction" and is linked to identity; it is not, however, combined with third-party data for advertising purposes.
What tracking means: the data marked "Yes" above may be linked with third parties' data for advertising and advertising measurement.
Consent and control:
These operations are covered by Google's privacy policy. Sandık never attaches manual financial records, IBAN details or balances to an ad request.
api.frankfurter.dev, api.gold-api.com). These requests are only to obtain the current price; asset, IBAN and transaction records are not sent. As with any network request, the device's IP address can be seen by the relevant service.This version requests no camera or photo library access; receipt scanning is disabled.
| Data | Period |
|---|---|
| Financial records on the device | Until the user deletes them or removes the app |
| Account metadata and identity record | Until the account is deleted; deleted after at most 24 months without a sign-in |
| Data on the advertising side | Subject to Google's retention policies |
Profile → "Delete my account and all my data" does the following in a single flow:
Backups the user previously exported to another location such as Files or iCloud Drive must be deleted separately from where they are stored.
In relation to your personal data you have the right to learn whether it is processed, to access it, to request its rectification, erasure or restriction, to object to processing and to request data portability. You may object at any time to processing based on legitimate interest.
The fastest route for an erasure request is the in-app flow in §9. For other requests you can write to info@firenitetr.com. Requests are resolved within 30 days at the latest. If you are not satisfied with the outcome, you retain the right to lodge a complaint with the Turkish Personal Data Protection Authority (KVKK).
Authentication and account metadata are processed on Google (Firebase) infrastructure, and advertising data on Google (AdMob) infrastructure. These services may process data on servers outside Türkiye.
Sandık is not designed for children and does not knowingly collect personal data from children.
This policy is updated when app features or data practices change. For significant changes the policy version is incremented and the new version is recorded at the user's next sign-in.
← Back to support