Uygulama / App: Worvento · Paket kimliği / Package name: com.worvento.app
Sürüm: 1.0 · Yürürlük: 8 Ağustos 2026 · Son güncelleme: 8 Ağustos 2026
Veri sorumlusu: Worvento'nun Türkiye'de yerleşik yayıncısı (gerçek kişi) · worvento.info@gmail.com Uygulama: Worvento (com.worvento.app) · Sunucu: https://api.worvento.com
Detayını aşağıda madde madde yazdık. Acele ediyorsanız bu tablo yeter:
| soru | kısa cevap |
|---|---|
| Çerez kullanıyor musunuz? | Hayır, uygulamada tarayıcı yok. Ama aynı kurala tabi üç şey var: SDK'lar, cihazda depolama, tanımlayıcılar. |
| Kişisel verimi satıyor musunuz? | Hayır. Kişisel verilerinizi satmıyoruz. Hizmeti çalıştırmak için sayılı alıcıyla sayılı veriyi paylaşıyoruz (§3, §11). |
| Beni izleyen analitik var mı? | Hayır. Hiçbir analitik ya da çökme raporlama kütüphanesi yok (§7). |
| Onay gereken tek şey ne? | Reklam ve reklam kimliği (§2-B, §6). Diğer her şey hizmetin çalışması için zorunlu. |
| Onay ekranı şu an var mı? | Kişiselleştirilmiş reklam hiç kullanılmadığı için ayrı bir reklam onay ekranı yok; tüm reklam istekleri kişiselleştirmesiz (npa=1) gidiyor (§3.1, §6). Rıza durumunuzu "Ayarlar > Gizlilik ve İzinler"den yönetirsiniz. |
| En rahatsız edici gerçek ne? | İnternet kontrolü eskiden IP adresinizi bize ait olmayan 4 adrese gönderiyordu; bu düzeltildi — kontrol artık yalnız kendi sunucumuza gidiyor (§3.3). |
| Hesabımı silsem cihazda ne kalır? | Silme akışı cihazdaki verinizi de temizliyor; yalnız kötüye kullanımı sınırlayan iki rastgele numara kalır ve uygulamayı kaldırınca iOS dâhil silinir. Tam liste §4.5'te. |
| Reklam kimliğimi nasıl sıfırlarım? | Cihaz ayarlarından, uygulamadan bağımsız (§9.2). |
Worvento bir mobil uygulama. Uygulamanın içinde tarayıcı yok, bu yüzden klasik anlamda çerez (cookie) kullanmıyoruz. Ama aynı işi gören üç şey var:
(örneğin reklam gösteren Google kütüphanesi).
şifreli kayıtlar.
rastgele üretilmiş cihaz numarası).
Hukuk bu üçünü çerezle aynı kefeye koyuyor. Kişisel Verileri Koruma Kurumu'nun Çerez Uygulamaları Hakkında Rehberi (nihai sürüm 20.06.2022) ve Kurul'un 10.03.2022 tarihli 2022/229 sayılı kararı, teknik biçimden bağımsız olarak reklam ve pazarlama amaçlı takip teknolojilerini açık rızaya tabi tutuyor; yalnızca hizmetin sunulması için kesinlikle zorunlu olanlar rıza gerektirmiyor. Kurumun Mobil Uygulamalarda Mahremiyetin Korunmasına Yönelik Tavsiyeler Rehberi (Aralık 2023) de aynı çerçeveyi mobil uygulamalara uyguluyor.
Kısacası: adı çerez değil, ama kuralı çerezin kuralı. Bu yüzden bu metin size cihazınızda ne tuttuğumuzu, hangi hazır kod parçalarını kullandığımızı, bunların hangi veriye dokunduğunu ve hangisinin onayınıza bağlı olduğunu tek tek gösteriyor.
Kaynaklar: KVKK Kurul kararı 10.03.2022 t. 2022/229 · Çerez Uygulamaları Hakkında Rehber (20.06.2022) · Mobil Uygulamalarda Mahremiyetin Korunmasına Yönelik Tavsiyeler Rehberi (Aralık 2023) — <https://www.kvkk.gov.tr>
Cihazınızda yaptığımız her işlem iki gruptan birine giriyor. Bu ayrım hukuken belirleyici, çünkü onay yalnızca ikinci grup için gerekiyor.
A · ZORUNLU/İŞLEVSEL — onay gerekmiyor Bunlar olmadan uygulama isteğiniz üzerine çalışamaz: oturumunuzu açık tutmak, öğrendiğiniz kelimeleri saklamak, tema ve ses tercihinizi hatırlamak, internetiniz kesildiğinde uyarmak. Çerez Rehberi'nin "hizmetin sunulması için kesinlikle zorunlu" istisnası bunları kapsıyor; hukuki dayanak sözleşmenin ifası (KVKK m.5/2-c) ya da meşru menfaat (m.5/2-f).
B · REKLAM — açık rızaya bağlı Ödüllü reklam gösteren Google kütüphanesi ve reklam kimliği. Reklamların kişiselleştirilmesi için meşru menfaat kullanılamaz: Kurul'un 2022/229 sayılı kararı reklam ve pazarlama amaçlı takip teknolojilerini açık rızaya bağlıyor ve reklam kimliğine erişim hiçbir yorumla "hizmetin sunulması için kesinlikle zorunlu" sayılamaz.
Rıza vermezseniz reklam kapanmaz, yalnız kişiselleştirilmez — ödül hakkınızı kaybetmezsiniz (bkz. §6).
| cihazda saklanan grup | dayanak | gerekçe |
|---|---|---|
Oturum jetonları (auth_jwt_token, auth_refresh_token, auth_email, auth_email_verified) | Kesinlikle gerekli — onay gerekmiyor | Giriş yapmanızı istediniz; jeton olmadan oturum sürdürülemez. KVKK m.5/2-c |
Öğrenme ve ayar verisi (Hive user_stats, words, categories, shared_list_cache) | Kesinlikle gerekli — onay gerekmiyor | Uygulamanın temel işlevi kelime öğretmek; ilerlemeniz saklanmazsa hizmet çalışmaz. KVKK m.5/2-c |
| Oyun rekorları ve tur/kutlama/banner bayrakları | Kesinlikle gerekli — onay gerekmiyor | Yalnız cihazda kalan arayüz durumu; dışarıya çıkmıyor, reklamla ilgisi yok |
Senkronizasyon anlık görüntüsü (sync_meta_user_stats_v1) | Kesinlikle gerekli — onay gerekmiyor | Aynı veriyi tekrar tekrar göndermemek için; veri minimizasyonuna hizmet ediyor |
Cihaz parmak izi (device_fingerprint) ve kurulum kimliği (install_id) | Kesinlikle gerekli iddiası + meşru menfaat (KVKK m.5/2-f) — ⚠️ aşağıdaki nota bakın | Kötüye kullanım, çoklu-hesap ve davet kodu istismarı önleme |
| Ana ekran widget'ı verisi | Kesinlikle gerekli — onay gerekmiyor | Widget'ı siz eklediniz; verisi olmadan widget boş kalır |
| Reklam kimliği ve reklamın kişiselleştirilmesi | AÇIK RIZA (KVKK m.5/1) | Kişiselleştirme hiçbir yorumla hizmetin sunulması için kesinlikle zorunlu sayılamaz |
Aşağıdaki tablo uygulamanın pubspec.yaml dosyasındaki bağımlılıkların tamamını ve reklam kütüphanesinin dolaylı olarak getirdiği bir paketi içeriyor. Sürüm numaraları pubspec.yaml içindeki tanımlardır.
Hukuki dayanak kısaltmaları
| kısaltma | anlamı |
|---|---|
| SÖZ | Sözleşmenin ifası — KVKK m.5/2-c |
| MEŞ | Meşru menfaat — KVKK m.5/2-f |
| RIZA | Açık rıza — KVKK m.5/1 |
| HUK | Hukuki yükümlülük — KVKK m.5/2-ç |
| ZOR | "Hizmetin sunulması için kesinlikle zorunlu" → onay gerekmiyor |
| RIZA | Reklam kişiselleştirmesi → açık rıza gerekiyor |
| SDK / paket | ne yapıyor | hangi veriye dokunuyor | cihazdan çıkıyor mu | hukuki dayanak | link |
|---|---|---|---|---|---|
google_mobile_ads ^5.2.0 (Google Mobile Ads / AdMob) | Ödüllü video reklam gösterir. Reklamı izlerseniz ödülünüzü sunucumuz verir. | Reklam kimliği (Android'de GAID, iOS'ta IDFA), IP adresiniz, cihaz ve işletim sistemi bilgisi, ekran bilgisi, uygulamanın paket adı, reklamla etkileşiminiz. Google ayrıca kendi teşhis bilgisi ve ürün etkileşimi verisi topluyor. | Evet — Google'a. Google bu veride bağımsız veri sorumlusu; bizim veri işleyenimiz değil, veriyi kendi amaçları için de işliyor. | RIZA + RIZA | <https://policies.google.com/technologies/partner-sites> |
| Ödül doğrulama (SSV) — yukarıdaki SDK'nın bir özelliği | Ödülü istemci değil sunucu verir; Google ödül bilgisini doğrudan sunucumuza bildirir. | Sunucudaki hesap kimliğiniz (userId) düz metin olarak ve ödül türü, Google'a gönderilir. | Evet — Google'a. Bu kimlik takma ad değil; hesabınızla doğrudan eşleşir. | MEŞRU MENFAAT | <https://policies.google.com/technologies/partner-sites> — bu kalem reklam kişiselleştirme rızasından bağımsızdır; ödüllü reklam izlediğinizde rıza durumunuzdan bağımsız olarak gerçekleşir |
Şu anki kod durumu — dürüst beyan. Uygulamada reklam tercihi ekranı henüz yok. Bu politikanın kurduğu kural şudur: tercih ekranı devreye alınana kadar ödüllü reklamlar kişiselleştirilmeden gösterilir; yani "kişiselleştirmeye izin vermiyorum" bugünkü varsayılan durumdur. Tercih ekranı devreye girdiğinde bu metin güncellenecek ve yürürlük tarihi değişecektir.
| SDK / paket | ne yapıyor | hangi veriye dokunuyor | cihazdan çıkıyor mu | hukuki dayanak | link |
|---|---|---|---|---|---|
in_app_purchase ^3.2.0 (+ in_app_purchase_android, in_app_purchase_storekit) | Uygulama içi satın alma. Ödemeyi mağaza alır; biz yalnız makbuzu sunucuya iletip hakkı veririz. | Ürün kimliği, mağaza işlem kimliği, makbuz metni. Ödeme kartı bilgisini uygulama hiç görmez. | Evet. Android'de Google Commerce Limited'e, iOS'ta Apple Distribution International Ltd'ye. İkisi de bağımsız veri sorumlusu ve mağaza tarafında satıcı/aracı. Makbuz ayrıca kendi sunucumuza gider. | SÖZ + mali kayıt için HUK | <https://policies.google.com/privacy> · <https://www.apple.com/legal/privacy> |
flutter_secure_storage ^9.2.2 | Oturum jetonlarınızı ve cihaz numaranızı şifreli saklar. Android'de Keystore/EncryptedSharedPreferences, iOS'ta Keychain kullanır. | Oturum jetonu, yenileme jetonu, son giriş e-postanız, doğrulama bayrağı, cihaz parmak izi, senkronizasyon anlık görüntüsü (bkz. §4). | Saklanan jetonlar her istekte sunucumuza gider. Depolamanın kendisi cihazda kalır. | SÖZ + ZOR (oturum sürdürme) | — |
shared_preferences ^2.3.2 | Basit ayar ve bayrak saklama. Android'de XML, iOS'ta NSUserDefaults. | Kurulum kimliği, 12 mini-oyun rekoru, tanıtım turu / kutlama / banner bayrakları (bkz. §4). | Kurulum kimliği kayıt ve girişte sunucuya gider; diğerleri cihazda kalır. | SÖZ · kurulum kimliği için MEŞ + ZOR | — |
hive ^2.2.3 + hive_flutter ^1.1.0 | Cihaz üstü yerel veritabanı. İnternetiniz yokken kendi kelime listenizi çalışabilmenizi sağlar. | Kelime havuzu ve sizin eklediğiniz kelimeler, kategori kilitleri, 60'tan fazla alanlı istatistik nesnesi, ortak liste aynası. Şifresiz tutulur (cihazın kendi uygulama-izolasyonuna güvenilir). | Bir kısmı senkronizasyonla sunucuya gider (XP, seri, rozet, günlük aktivite günlüğü). | SÖZ + ZOR | — |
dio ^5.7.0 | Sunucumuzla HTTPS iletişimi. | Gönderdiğiniz her istek ve gelen her yanıt. | Evet — yalnız api.worvento.com adresine. | SÖZ | — |
dio_cache_interceptor ^4.0.6 | Sunucu izin veren uçların yanıtını kısa süre bellekte tutar (bkz. §8). | Katalog yanıtları (hediye listesi, çark listesi). | Hayır — yalnız RAM. | SÖZ + ZOR | — |
internet_connection_checker_plus ^2.5.2 (çözümlenen sürüm 2.9.1+2) | İnternetinizin gerçekten çalıştığını sınar (kaptif portal, internetsiz hotspot tespiti). ⚠️ Bkz. §3.3. | IP adresiniz, User-Agent bilgisi ve zaman damgası. | Evet — bize ait olmayan 4 adrese. | MEŞ, ancak dayanak sorunlu — bkz. §3.3 | <https://www.cloudflare.com/privacypolicy/> |
signalr_netcore ^1.4.0 | Canlı meydan okuma, düello ve asmaca için gerçek-zaman WebSocket bağlantısı. Sürekli sorgulama (polling) yapmaz. | Maç durumu, davetler, kullanıcı adları. Oturum jetonunuz adres satırında (query string) taşınır — ters vekil erişim kayıtlarında görünebilir. | Evet — yalnız kendi sunucumuza. | SÖZ | — |
image_picker ^1.1.2 | Profil fotoğrafı seçtirir. Android Foto Seçici ya da kamera niyeti kullanır. | Yalnız sizin tek tek seçtiğiniz fotoğraf. Galerinin tamamına erişim izni istenmiyor (READ_MEDIA_IMAGES, CAMERA, READ_EXTERNAL_STORAGE izinlerinin hiçbiri yok). | Seçtiğiniz fotoğrafın ham baytları imzalı adresle doğrudan Cloudflare R2 nesne depolamasına yüklenir. Cloudflare, Inc. (ABD) — küresel altyapı; profil fotoğrafları belirli bir ülkeye sabitlenmemiştir. Aktarımda ve saklamada şifrelenir. | RIZA (fotoğraf isteğe bağlı) | <https://www.cloudflare.com/privacypolicy/> |
crop_your_image ^2.0.0 | Fotoğrafı yüklemeden önce daire maskesiyle kırpar. Saf Dart; ağ erişimi yok. | Kırpılan görselin baytları (geçici dizinde). | Hayır. | RIZA | — |
file_picker ^8.1.7 | CSV içe aktarmada dosya seçtirir. Sistem seçicisini kullanır. | Yalnız sizin seçtiğiniz dosya. Geniş depolama izni yok. | Hayır. | SÖZ | — |
share_plus ^10.1.4 | Sonuç kartlarını, davet kodunuzu ve karneyi paylaşmanızı sağlar. | Paylaşım kartı görüntüsü (skor, XP, seri, kategori adı, davet kodu) ve altyazı metni. Düello kartında rakibinizin kullanıcı adı da görüntüye gömülü olarak çıkar. | Evet — sizin seçtiğiniz uygulamaya (WhatsApp, Instagram, e-posta…). O uygulama bağımsız veri sorumlusudur. | SÖZ (paylaşımı siz başlatırsınız) | — |
flutter_tts ^4.2.0 | Kelimenin telaffuzunu okutur. Cihaza yüklü ses motorunu kullanır; biz hiçbir ses saklamıyoruz. | Okutulan kelimenin metni ve hedef dil kodu. | Duruma göre. Kod cihaz motorunun çevrimdışı çalıştığını varsayıyor ama bunu zorlamıyor: motor seçimi ve ağ kullanımı ayarı yok. Bulut sentezi yapan bir motorda (Android'de varsayılan motor yüksek kaliteli ses için bunu yapabilir) kelime metni motor sağlayıcısına gider. | SÖZ | Motora bağlı — Android'de çoğunlukla <https://policies.google.com/privacy> · iOS'ta <https://www.apple.com/legal/privacy> |
home_widget ^0.7.0 | "Günün Kelimesi" ana ekran widget'ını besler. | Seri gün sayınız, gün sayacı, kelime başlığı, kaynak/hedef kelime, emoji. Android'de SharedPreferences, iOS'ta group.com.worvento.app App Group kabında. Kelime cevaplanana kadar gizli tutulur; seri sayısı her tazelemede yazılır ve kapatma ayarı yok — kilit ekranında görünebilir. | Hayır — cihazda kalır. | SÖZ | — |
audioplayers ^6.1.0 | Doğru/yanlış/tık ses efektlerini çalar. | Yalnız uygulamanın içindeki assets/sounds/*.wav dosyaları. Mikrofon izni yok, ses kaydı yok. | Hayır. | SÖZ | — |
path_provider ^2.1.5 | Geçici dizin ve belgeler dizininin yolunu bulur. | Paylaşım görüntüsü, kırpma geçici dosyası, CSV dışa aktarma dosyası. | Hayır. | SÖZ | — |
url_launcher ^6.3.1 | Yasal sayfaları cihazın kendi tarayıcısında açar (uygulama içi tarayıcı kullanmaz). | Açılan adres. | Adrese giden istek tarayıcınız üzerinden yapılır; bu noktadan sonra tarayıcınızın kendi ayarları geçerlidir. | SÖZ | — |
uuid ^4.5.1 | Rastgele numara üretir (cihaz parmak izi ve kurulum kimliği için). Hiçbir donanım bilgisi okumaz. | Ürettiği rastgele numara. | Üretilen numaralar kayıt ve girişte sunucuya gider. | MEŞ + ZOR | — |
csv ^6.0.0 | Kelime listenizi CSV'ye çevirir ve CSV'den okur. Ağ erişimi yok. | Kelimeleriniz. | Hayır. | SÖZ | — |
webview_flutter (dolaylı — google_mobile_ads bağımlılığı olarak gelir) | Uygulama bu paketi kendisi kullanmıyor. Kodda tek bir WebViewWidget veya WebViewController çağrısı yok; yasal sayfalar dış tarayıcıda açılıyor. Paket, reklam kütüphanesinin reklam içeriğini göstermek için ihtiyaç duyduğu için kuruluma dahil oluyor. | Yalnız reklam kütüphanesi bir reklam gösterdiğinde reklam içeriği. | Reklam gösterildiğinde reklam ağına. | Reklamla aynı: RIZA + RIZA | <https://policies.google.com/technologies/partner-sites> |
Yalnız arayüz için olan, hiçbir kişisel veriye dokunmayan paketler (tamlık için): flutter_riverpod, go_router, easy_localization, flutter_card_swiper, lottie, animate_do, shimmer, fl_chart, flutter_heatmap_calendar, confetti, animations, cupertino_icons. Bunlar ağ erişimi yapmaz ve cihazdan veri çıkarmaz.
Sunucu tarafında. Uygulamanın konuştuğu sunucu Hetzner'da barınıyor: Hetzner Online GmbH (Almanya) — sunucumuz Finlandiya'da bulunuyor. Doğrulama, şifre sıfırlama ve hesap silme kodu e-postaları Google'ın Gmail altyapısı üzerinden gönderiliyor. Sunucu tarafındaki verinin tamamı için Gizlilik Politikası ve Aydınlatma Metni metinlerine bakın.
Bağlantı kontrolü yalnız kendi sunucumuza gidiyor: {apiBaseUrl}/health, yaklaşık 45 saniyede bir. Üçüncü tarafa hiçbir şey gitmiyor.
Bu bölümün eski hâli farklıydı ve düzeltildi. internet_connection_checker_plus paketi, hedef adres belirtilmediği için kendi varsayılan adreslerini kullanıyordu; sonuç olarak uygulama ön plandayken yaklaşık 10 saniyede bir IP adresiniz ve User-Agent bilginiz bize ait olmayan dört adrese gidiyordu (one.one.one.one, icanhazip.com, jsonplaceholder.typicode.com, pokeapi.co). Bu taraflarla veri işleme sözleşmemiz yoktu. Kontrol kendi /health ucumuza çevrilerek bu dört aktarım tümden kaldırıldı.
Bunu düzeltmeyi taahhüt ediyoruz: kontrol kendi sunucumuza (api.worvento.com) yönlendirilecek ve kontrol aralığı uzatılacak. Düzeltme yapıldığında bu bölüm kaldırılacak ve metnin sürümü yükseltilecektir. Düzeltilene kadar bu gerçeği saklamak yerine size söylemeyi seçtik.
Aşağıdaki tablolar cihazınızda tuttuğumuz her kalemi gösteriyor. Her grubun hukuki dayanağı §2.1'de.
"Uygulama silinince gider mi?" sütununda platform farkı önemli: Android'de şifreli depolama uygulamayla birlikte silinir; iOS'ta Keychain kayıtları uygulamayı silseniz bile cihazda kalır. Bu fark aşağıdaki oturum jetonları için geçerlidir. Cihaz numarası (device_fingerprint) bu gruptan çıkarıldı ve artık uygulamayla birlikte siliniyor — gerekçesi tablonun altındaki notta.
flutter_secure_storage)| anahtar | ne tutuyor | nerede | uygulama silinince gider mi | hesap silmede temizlenir mi |
|---|---|---|---|---|
auth_jwt_token | Oturum jetonunuz (7 gün geçerli) | Android Keystore · iOS Keychain | Android: gider · iOS: kalır | Evet |
auth_refresh_token | Oturumu sessizce yenileme jetonu (30 gün) | Android Keystore · iOS Keychain | Android: gider · iOS: kalır | Evet |
auth_email | Son giriş yaptığınız e-posta adresi (doğrulama ekranı için) | Android Keystore · iOS Keychain | Android: gider · iOS: kalır | Evet |
auth_email_verified | E-postanızın doğrulanıp doğrulanmadığı (1/0) | Android Keystore · iOS Keychain | Android: gider · iOS: kalır | Evet |
sync_meta_user_stats_v1 | Son başarılı senkronizasyonun anlık görüntüsü: XP, doğru/yanlış sayısı, seri, rozet listesi, günlük aktivite günlüğü, zaman damgası. Gereksiz gönderim yapmamak için | Android Keystore · iOS Keychain | Android: gider · iOS: kalır | Evet |
Cihaz numarası hakkında düzeltme (2026-08-12):
device_fingerprinteskiden şifreli depoda tutuluyordu ve iOS'ta Keychain kayıtları uygulama silinse bile kaldığı için bu numara cihaz ömürlüydü — uygulamayı silip yeniden kuran kullanıcı yine tanınıyordu. Bu düzeltildi: numara artık normal uygulama verisinde (shared_preferences, §4.2) tutuluyor, yani uygulamayı kaldırınca her iki platformda da silinir ve cihazda kalmış eski Keychain kaydı da temizlenir. Bedelini biliyoruz — uygulamayı silip yeniden kuran biri bizim için yeni bir cihaz gibi görünür, yani kötüye kullanım sinyali zayıfladı — ve bu bedeli sizin lehinize kabul ettik.
shared_preferences)Bu grubun tamamı uygulamayı kaldırınca her iki platformda da silinir ve hiçbiri hesap silmede temizlenmez.
| anahtar | ne tutuyor | nerede | uygulama silinince gider mi | hesap silmede temizlenir mi |
|---|---|---|---|---|
device_fingerprint | Rastgele üretilmiş cihaz numarası (UUID). Kötüye kullanım sinyali: davet kodu cihaz sınırı, çoklu-hesap uyarısı, yasaklama yayılımı. 2026-08-12'de şifreli depodan buraya taşındı (§4.1 notu) | Android XML · iOS NSUserDefaults | Evet | Hayır |
install_id | Rastgele üretilmiş kurulum numarası (UUID). "Aynı cihaz, farklı kurulum" ayrımı için; kayıt ve girişte sunucuya gider | Android XML · iOS NSUserDefaults | Evet | Hayır |
anagram_max_level | Anagram oyunu en yüksek seviyeniz | aynı | Evet | Hayır |
blitz_high_score | Blitz oyunu rekorunuz | aynı | Evet | Hayır |
fake_word_high_score | Sahte Kelime oyunu rekorunuz | aynı | Evet | Hayır |
hangman_best_score | Adam Asmaca en iyi puanınız | aynı | Evet | Hayır |
listen_find_high_score | Dinle-Bul oyunu rekorunuz | aynı | Evet | Hayır |
matching_max_level | Eşleştirme oyunu en yüksek seviyeniz | aynı | Evet | Hayır |
memory_max_level | Hafıza oyunu en yüksek seviyeniz | aynı | Evet | Hayır |
missing_letters_best | Eksik Harfler en iyi sonucunuz | aynı | Evet | Hayır |
odd_one_out_best | Farklı Olan en iyi sonucunuz | aynı | Evet | Hayır |
wordle_best_score | Wordle en iyi puanınız | aynı | Evet | Hayır |
word_rain_high_score | Kelime Yağmuru rekorunuz | aynı | Evet | Hayır |
word_search_best_time | Kelime Avı en iyi süreniz | aynı | Evet | Hayır |
seenTour_<ekranId> | Her ekranın tanıtım turunu bir kez göstermek için "görüldü" bayrağı | aynı | Evet | Hayır — ama Ayarlar > Turları sıfırla ile silebilirsiniz |
goldCatCelebrated_<kategoriId> | Altın kategori kutlamasını tekrar oynatmamak için bayrak | aynı | Evet | Hayır |
albumSealed_<kategoriId> | Mühürlenmiş albüm sayfasını tekrar mühürletmemek için bayrak | aynı | Evet | Hayır |
weeklyReportBannerSeenWeek | Haftalık karne banner'ının gösterildiği haftanın Pazartesi tarihi | aynı | Evet | Hayır |
seasonWrappedSeenSeasonId | Sezon özeti banner'ının gösterildiği sezon numarası | aynı | Evet | Hayır |
petLastStageIndex | Pet'in son kutlanan evrim aşaması (pet'in kendisi sunucuda) | aynı | Evet | Hayır |
ya5BackfillDone | Geçmiş öğrenme verinizin sunucuya bir kez aktarıldığı bayrağı. Cihaz başına, kullanıcı başına değil — hesap değişse de kalır | aynı | Evet | Hayır |
daily_word_streak · daily_word_count · daily_word_title · daily_word_target · daily_word_source · daily_word_emoji | Ana ekran widget'ının gösterdiği veriler. Kelime cevaplanana kadar gizli tutulur, seri sayısı her zaman yazılır. Widget'ı kaldırsanız bile veri kalır | Android SharedPreferences · iOS group.com.worvento.app App Group kabı | Evet | Hayır |
Reklam tercihi ekranı devreye alındığında bu listeye tercihinizin kaydı da eklenecektir (kapsam, zaman damgası, metin sürümü). Bugün bu anahtarlar cihazınızda yok, çünkü onay ekranı henüz yok.
hive)Hive kutuları uygulamanın veri dizininde tutulur ve şifresizdir — cihazın kendi uygulama izolasyonuna güvenilir. Hepsi uygulamayı kaldırınca silinir.
| kutu | ne tutuyor | uygulama silinince gider mi | hesap silmede temizlenir mi |
|---|---|---|---|
user_stats (stats anahtarı) | 60'tan fazla alanlı istatistik nesnesi: XP, seri, rozetler, dil tercihi, tema, günlük XP hedefi, ses ve titreşim ayarı, TTS ayarı, görülen kelime kimlikleri, mükemmel kategoriler, günlük aktivite günlüğü, öğle arası / hafta sonu / sessiz test sayaçları | Evet | Evet |
words | Kelime havuzu ve sizin kendi eklediğiniz kelimeler (MyList) — kaynak kelime, hedef kelime, tür, zorluk, doğru/yanlış sayaçları | Evet | Hayır |
categories | Kategori adı, seviyesi ve kilit eşiği | Evet | Hayır |
shared_list_cache | Başkasının sizinle paylaştığı listenin çevrimdışı aynası: kelimeler ve sayfa imleci. Kodda süre sınırı ya da temizlik işi yok | Evet | Hayır |
| dosya | ne tutuyor | nerede | uygulama silinince gider mi | hesap silmede temizlenir mi |
|---|---|---|---|---|
wordmaster_share.png | En son ürettiğiniz paylaşım kartının görüntüsü (skor, XP, seri, davet kodu; düelloda rakibin kullanıcı adı). Sabit adla yazılır ve paylaşımdan sonra silinmez | Geçici dizin | Evet | Hayır |
| Kırpma geçici dosyası | Profil fotoğrafını yüklemeden önceki kırpılmış hâli | Geçici dizin | Evet | Hayır |
my_words_export.csv | CSV dışa aktarmada üretilen kelime listeniz (kaynak kelime, hedef kelime, tür, kategori). Bu dizin uygulamaya özeldir; dosya yöneticisinden göremezsiniz | Uygulamanın Belgeler dizini | Evet | Hayır |
Hesabınızı sildiğinizde cihazda yalnız şunlar temizleniyor: dört oturum anahtarı (auth_jwt_token, auth_refresh_token, auth_email, auth_email_verified), sync_meta_user_stats_v1 ve user_stats Hive kutusu.
Cihazda kalanlar: device_fingerprint (iOS'ta uygulamayı silseniz bile), install_id, words (kendi eklediğiniz kelimeler), categories, shared_list_cache, 12 mini-oyun rekoru, tüm tur/kutlama/banner bayrakları, ya5BackfillDone, ana ekran widget'ı verisi ve §4.4'teki dosyalar.
Bunu düzeltmek düzeltme kaydımızdaki en yüksek öncelikli kalemlerden biri. Sunucu tarafında hesap silmenin neyi silip neyi silmediğini ayrı bir metinde madde madde yazdık: Veri Silme.
| tanımlayıcı | ne | kim okuyor | sıfırlanabilir mi | ne için kullanılıyor |
|---|---|---|---|---|
| Reklam kimliği (Android'de GAID/AAID, iOS'ta IDFA) | İşletim sisteminin reklamcılık için verdiği, sizin sıfırlayabildiğiniz numara | Uygulama kodu bu numarayı okumuyor. Google'ın reklam kütüphanesi kendisi okuyor. Android'de com.google.android.gms.permission.AD_ID iznini bu kütüphane ekliyor | Evet. Android: Ayarlar > Google > Tüm hizmetler > Reklamlar. iOS: Ayarlar > Gizlilik ve Güvenlik > İzleme (izin vermezseniz IDFA tamamen sıfırlardan oluşur) | Ödüllü reklam gösterimi, reklam ilişkilendirmesi, ölçüm — yalnız onayınızla |
Cihaz parmak izi (device_fingerprint) | Bizim ürettiğimiz rastgele UUID. Donanımdan hiçbir bilgi okunmuyor: IMEI, seri numarası, MAC adresi, Android ID, cihaz modeli — hiçbiri | Yalnız kendi sunucumuz | Evet. Uygulamayı kaldırmak ya da uygulama verisini silmek numarayı sıfırlar — iOS ve Android'de aynı | Davet kodu cihaz sınırı, çoklu-hesap uyarı kaydı, yasaklama yayılımı. Reklamla ilgisi yok, üçüncü tarafa gitmiyor |
Kurulum kimliği (install_id) | Bizim ürettiğimiz rastgele UUID | Yalnız kendi sunucumuz | Evet — uygulamayı kaldırıp yeniden kurmak ya da uygulama verisini silmek yeniler | "Aynı cihaz, farklı kurulum" ayrımı. Reklamla ilgisi yok |
Sunucu hesap kimliğiniz (userId) | Sunucudaki hesap satırınızın numarası | Kendi sunucumuz ve ödüllü reklam doğrulamasında Google | Hayır — hesabınız ömrü boyunca sabit | Hesap işlemleri. ⚠️ Ödüllü reklam doğrulamasında bu numara düz metin olarak Google'a gidiyor (bkz. §3.1) |
Neden donanım kimliği kullanmıyoruz. Cihaz modeli ve işletim sistemi bilgisinden üretilecek bir imza aynı telefonu kullanan binlerce kişide çakışır; IMEI gibi gerçek donanım kimlikleri ise ek izin ister. Rastgele üretilip cihazda saklanan bir numara hem daha isabetli hem gizlilik açısından temiz. device_info_plus benzeri bir paket uygulamada yok; parmak izi çıkarma tekniklerinin (canvas, yazı tipi, WebGL) hiçbiri kullanılmıyor; kurulu uygulama listeniz sorgulanmıyor (QUERY_ALL_PACKAGES izni yok); panonuz okunmuyor (yalnız davet kodunu panoya yazıyoruz).
Reklam kimliğine erişmek ve reklam kütüphanesinin cihazınıza yazmasına izin vermek için açık rızanız gerekiyor. Bunun iki ayrı sebebi var ve ikisi de bağımsız olarak zorunlu:
Dayanak, Kişisel Verileri Koruma Kurumu'nun Çerez Uygulamaları Hakkında Rehberi ve Kurul'un 10.03.2022 tarihli 2022/229 sayılı kararıdır: reklam ve pazarlama amaçlı takip teknolojileri açık rızaya tabidir, burada meşru menfaat kullanılamaz.
Bir not: Google, Avrupa Ekonomik Alanı ve Birleşik Krallık trafiğinde sertifikalı bir onay yönetim platformu (CMP) zorunlu tutuyor. Worvento bu bölgelerde dağıtılmadığı için o zorunluluk bizde devreye girmiyor; buna karşılık kişiselleştirme için rıza almak KVKK bakımından yine gereklidir ve uygulama içi bir tercih anahtarıyla sağlanacaktır.
| kişiselleştirilmiş | kişiselleştirilmemiş | |
|---|---|---|
| Reklam neye göre seçilir | Reklam kimliğinize bağlı ilgi profilinize göre | Yalnız bağlama göre (uygulamanın türü, dil, ülke) |
| Reklam kimliği okunur mu | Evet | Hayır (iOS'ta IDFA istenmez) |
| Apple'ın "izleme" tanımına girer mi | Evet — Google, bu uygulamadan topladığı cihaz verisini başka geliştiricilerin uygulamalarından topladığı veriyle birleştirir | Hayır |
| Onay gerekir mi | Evet — açık rıza | Hayır — hizmetin finansmanı bakımından meşru menfaat (bkz. §3.1 uyarısı) |
| Ödülünüzü etkiler mi | — | Hayır. Onay vermezseniz de ödül hakkınız aynı kalır; uygulama tam çalışmaya devam eder |
Bu son satır bir taahhüt: onay vermemeniz ya da onayı geri almanız hiçbir özelliğinizi kapatmaz, ödül hakkınızı kısmaz, uygulamayı kullanmanızı engellemez.
Onay ekranı devreye girdiğinde şu kurallar geçerli olacak:
arkasına gizlemek karanlık desen sayılır ve yapılmayacaktır.
Uygulamanın menüsünde kalıcı bir "Reklam ve gizlilik tercihleri" girişi bulunur.
rızanın alındığının ispatı veri sorumlusuna aittir.
Aynı kapsamdaki rıza kalemlerinin metni ayrı bir belgede: Açık Rıza Metni. Kişisel Verileri Koruma Kurulu'nun 18.02.2026 tarihli 2026/347 sayılı ilke kararı gereği aydınlatma ile açık rıza ayrı belgelerdir ve tek bir onayla sunulamaz.
Apple'ın App Tracking Transparency (ATT) izni, KVKK rızasından ayrı ve ek bir katmandır: Apple'ın kendi platform kuralıdır ve dağıtım bölgesinden bağımsız olarak geçerlidir. Önerilen sıra:
requestTrackingAuthorization). Bu diyalog cihazdayalnız bir kez çıkar.
ATT izni vermezseniz IDFA tamamen sıfırlardan oluşur ve kişiselleştirilmiş reklam gösterilemez. Kaynak: <https://developers.google.com/admob/flutter/privacy/idfa>
iOS için dürüst durum: Worvento App Store'a hiç yüklenmedi. iOS'ta bugün ATT izni istenmiyor: kodda requestTrackingAuthorization çağrısı yok. Info.plist dosyasında izin metni ve 46 SKAdNetwork kimliği tanımlı olsa da izin akışı olmadığı için diyalog hiç çıkmaz. iOS sürümü yayınlandığında bu bölüm ya ATT akışıyla ya da reklamın iOS'ta tamamen kapatılmasıyla güncellenecektir.
Worvento 16 yaş ve üzeri için. Reklam tarafında bunun iki sonucu var:
işareti gönderilir ya reklam tamamen kapatılır.
16+ bir kitleye uygun olmayan reklam gösterilmesi engellenir.
Worvento'da hiçbir analitik ya da çökme raporlama kütüphanesi bulunmuyor. Bu üç yolla doğrulandı: pubspec.yaml satır satır okundu, çözümlenmiş 170 paketin tamamı listelendi ve uygulama kodunun tamamı büyük/küçük harf duyarsız olarak tarandı.
Bulunmayanlar: Firebase (Analytics, Crashlytics, Messaging), Sentry, Amplitude, Mixpanel, AppsFlyer, Adjust, Facebook App Events, PostHog, Datadog, Bugsnag, OneSignal, Segment.
Bunun sizin için anlamı:
bir izleme katmanı yok.
hiçbir yere gönderilmiyor.
şirketine satmıyoruz — çünkü o veriyi hiç toplamıyoruz.
Uygulamanın kullanım verisi beyanı "ürün etkileşimi → uygulama işlevselliği" olarak yapılır.
Bildirimler. Uygulama iki bildirim mekanizması kullanır ve ikisi de Ayarlar → Bildirimler'den ayrı ayrı kapatılabilir:
Cihaza ait bir bildirim jetonu üretilir ve sunucumuzda saklanır (hesap silinince silinir, çıkışta kaldırılır). Jeton bir cihaz kaydıdır, reklam kimliği değildir; izleme veya profil oluşturma amacıyla kullanılmaz ve reklam ağlarıyla paylaşılmaz.
flutter_local_notifications): hatırlatıcılar için. Zamanlama cihazdayapılır, hiçbir veri sunucuya gitmez ve üçüncü taraf devrede değildir.
Android'de POST_NOTIFICATIONS izni istenir (Android 13+); reddedilirse uygulama normal çalışır. Ayrıca canlı maç/düello olayları uygulama açıkken SignalR WebSocket bağlantısıyla geliyor (§3.2), ana ekran widget'ı ise verisini cihazda güncelliyor (§4.2).
Dürüst sınır — bunu da saklamıyoruz. Google'ın reklam kütüphanesi kendi hesabına teşhis bilgisi ve reklam etkileşimi verisi topluyor ve bunu Google'a gönderiyor. Bu bizim analitik katmanımız değil; verisine erişimimiz de yok. Ama teknik olarak cihazınızdan çıkan bir telemetri akışıdır ve reklam onayı verildiğinde devreye girer. Reklam kapalıyken bu akış da olmaz.
Bir gün kendi hata raporlamamızı eklersek bu metni, gizlilik politikasını ve mağaza formlarını aynı anda güncelleyeceğiz.
Uygulama içi önbellek (dio_cache_interceptor). Sunucu yanıtlarını yalnız RAM'de tutuyoruz (MemCacheStore); hiçbir yanıt diske yazılmıyor. Uygulamayı kapattığınızda önbellek kayboluyor.
Politika CachePolicy.request: yalnız sunucunun Cache-Control başlığı gönderdiği uçlar önbelleklenir. Bugün bunlar yalnız katalog uçları (hediye listesi, çark listesi; max-age=300, yani 5 dakika). En uzun bekletme süresi 1 saat.
Önbelleklenmeyenler — kodla doğrulandı: liderlik tablosu, lig, profil ve arkadaş listesi Cache-Control başlığı göndermediği için her seferinde ağdan taze geliyor. Yani başkalarının kullanıcı adı ve istatistikleri cihazınızda önbelleğe düşmüyor.
Profil fotoğrafı dağıtım önbelleği (Cloudflare R2). Profil fotoğrafları Cloudflare R2 nesne depolamasında tutuluyor. Cloudflare, Inc. (ABD) — küresel altyapı; profil fotoğrafları belirli bir ülkeye sabitlenmemiştir. Aktarımda ve saklamada şifrelenir. Fotoğraflar 1 yıl süreyle immutable olarak önbelleklenmesi talimatıyla sunuluyor (public,max-age=31536000,immutable). Bunun dürüst sonucu: fotoğrafınızı sildikten sonra bir kopyası bir süre daha dağıtım ağı önbelleğinde ya da tarayıcı önbelleğinde yaşamaya devam edebilir. Silme talebiniz kaynaktaki nesneyi hedefler; önbellek kopyalarının süresi kendi başına dolar.
| ne yapmak istiyorsunuz | nereden |
|---|---|
| Reklam ve gizlilik tercihlerinizi değiştirmek | Ayarlar > Reklam ve gizlilik tercihleri — ⚠️ Bu giriş bugün uygulamada YOK. Onay ekranıyla birlikte eklenecek. Bugün için reklamlar onay ekranı devreye girene kadar gösterilmiyor |
| Sesi, titreşimi, telaffuzu, temayı kapatmak | Ayarlar |
| Tanıtım turu bayraklarını silmek | Ayarlar > Turları sıfırla |
| Profil fotoğrafınızı kaldırmak | Profil ekranı — fotoğrafı kaldırma işlemi sunucudaki nesneleri de siler |
| Kelime listenizi CSV olarak almak | Ayarlar > CSV Dışa Aktar — ⚠️ dürüst uyarı: üretilen dosya uygulamanın kendi Belgeler dizinine yazılıyor; oradan dosya yöneticisiyle erişemezsiniz. Dosyayı size ulaştırmak düzeltme kaydımızda bir iş kalemi |
| Hesabınızı silmek | Ayarlar > Hesabı sil — iki adımlı: şifre teyidi, sonra e-posta ile gelen kod. Neyin silindiğini ve neyin silinmediğini Veri Silme metninde madde madde yazdık |
| Yasal metinleri okumak | Ayarlar > Yasal — ⚠️ bu bağlantı bugün yayında olmayan bir adrese gidiyor; gerçek yasal sayfalar https://worvento.com/legal/ altındadır. Düzeltme kaydımızda bir iş kalemi |
Reklam kimliği işletim sisteminin verdiği bir numaradır; uygulamadan bağımsız olarak siz yönetirsiniz.
Android
kaldırır; bu andan sonra uygulamalar kimlik yerine sıfır dizisi görür.
Reklam Kimliği politikası, silinen ya da sıfırlanan kimliğin eski kimlikten türeyen veriyle ilişkilendirilmesini yasaklıyor.
iOS
İzin Ver" seçeneğini kapatırsanız hiçbir uygulama izin bile isteyemez ve IDFA sıfırlardan oluşur.
reklamlarını kapatır.
Uygulamayı kaldırmak Hive kutularını, shared_preferences içeriğini ve geçici dosyaları her iki platformda da siler. Ama iOS'ta Keychain kayıtları kalır (§4.1); iOS'ta device_fingerprint gibi anahtarları güvenilir şekilde silmenin tek yolu cihazı sıfırlamaktır. Android'de Ayarlar > Uygulamalar > Worvento > Depolama > Verileri temizle şifreli depoyu da temizler.
Uygulama, izin diyaloğu çıkarmayı gerektiren hiçbir hassas izin istemiyor. Kamera, galeri, mikrofon, konum, rehber, takvim, SMS ve bildirim izinlerinin hiçbiri yayın paketinde yok. Bunun pratik sonucu: uygulama size hiçbir çalışma-anı izin sorusu sormuyor; sormadığı için de izin vermemeniz hâlinde kapanan bir özellik yok.
Yayın paketinde bulunan izinlerin tamamı ve neden bulundukları:
| izin | kim istiyor | ne için |
|---|---|---|
INTERNET | uygulama | Sunucuyla iletişim. Uygulama çevrimiçi çalışır |
ACCESS_NETWORK_STATE | uygulama | Bağlantı durumunu okumak |
com.android.vending.BILLING | in_app_purchase | Uygulama içi satın alma |
com.google.android.gms.permission.AD_ID | reklam kütüphanesi ekliyor | Reklam kimliğine erişim. Yalnız onayınızla kullanılır |
ACCESS_ADSERVICES_AD_ID · ACCESS_ADSERVICES_ATTRIBUTION · ACCESS_ADSERVICES_TOPICS | reklam kütüphanesi ekliyor | Android Privacy Sandbox reklam ölçümü |
WAKE_LOCK · FOREGROUND_SERVICE | reklam kütüphanesi ekliyor | Video reklam oynatımı sırasında ekranın kapanmaması |
DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION | Android kütüphaneleri | Yayın alıcılarının uygulama dışına açılmaması (güvenlik önlemi) |
Profil fotoğrafı seçerken image_picker, Android Foto Seçici ya da kamera niyetini kullanıyor; bu, izin gerektirmeyen yoldur ve galerinin tamamına erişim vermez. CSV içe aktarmada file_picker sistem dosya seçicisini kullanıyor; geniş depolama izni istenmiyor. Yalnız sizin tek tek seçtiğiniz dosyayı görüyoruz.
Toplamadığımız veriler. Şunların hiçbirini toplamıyoruz: GPS ya da ağ tabanlı konum, rehberiniz, telefon numaranız, sağlık ve fitness verisi, mikrofon kaydı, takvim, SMS ve çağrı kaydı, biyometrik veri, kurulu uygulama listeniz, analitik ve çökme raporu, push bildirim jetonu, Google/Apple/Facebook ile giriş. Tek dürüst istisna: günlük limitlerin sizin yerel gece yarınızda sıfırlanması için saat dilimi kaymanızı (dakika olarak) sunucuya gönderiyoruz. Bu GPS konumu değil, ama kaba bir coğrafi çıkarıma imkân verir; bunu "konum toplamıyoruz" derken saklamamayı seçtik.
Yeni bir SDK eklediğimizde, cihazda sakladığımız bir kalem değiştiğinde ya da reklam onayının işleyişi değiştiğinde bu metni güncelleyip yukarıdaki sürüm ve son güncelleme tarihini değiştiriyoruz. Aydınlatma Tebliği'nin 5/1-b maddesi, işleme amacı değiştiğinde işlemeden önce yeniden aydınlatma yapılmasını emrediyor; bu yüzden yeni bir veri akışı devreye girmeden önce metin güncellenir.
Veri sorumlusu: Worvento yayıncısı (Türkiye) · worvento.info@gmail.com Veri koruma başvuruları ve destek: worvento.info@gmail.com Yayındaki adres: https://worvento.com/legal/izleme-teknolojileri
Üçüncü tarafların kendi gizlilik metinleri: Google (reklam ortakları) <https://policies.google.com/technologies/partner-sites> · Google (genel) <https://policies.google.com/privacy> · Cloudflare <https://www.cloudflare.com/privacypolicy/> · Hetzner <https://www.hetzner.com/legal/privacy> · Apple <https://www.apple.com/legal/privacy>
Version: 1.0 · Effective: 8 August 2026 · Last updated: 8 August 2026
This is an information-only English translation. In case of any conflict, the Turkish original prevails. Turkish original: cerez-ve-sdk-politikasi.md
Data controller: the Türkiye-based publisher of Worvento (natural person) · worvento.info@gmail.com App: Worvento (com.worvento.app) · Server: https://api.worvento.com
Full detail follows. If you are in a hurry, this table is enough:
| question | short answer |
|---|---|
| Do you use cookies? | No — there is no browser in the app. But three things fall under the same rule: SDKs, on-device storage, identifiers. |
| Do you sell my personal data? | No. We do not sell your personal data. We share limited data with a limited number of recipients to run the service (§3, §12). |
| Is there analytics tracking me? | No. There is no analytics or crash-reporting library at all (§7). |
| What is the only thing that needs consent? | Advertising and the advertising identifier (§2-B, §6). Everything else is strictly necessary to run the service. |
| Is there a consent screen today? | There is no separate ad-consent screen because personalised advertising is never used; every ad request is non-personalised (npa=1) (§3.1, §6). You manage your consent status under "Settings > Privacy and Permissions". |
| What is the most uncomfortable fact? | The connectivity check used to send your IP address to four hosts we do not own; that has been fixed — the check now goes only to our own server (§3.3). |
| What stays on my device if I delete my account? | Some of it stays, but the device number is no longer among it — it is deleted with the app. Full list in §4.5. |
| How do I reset my advertising ID? | From your device settings, independently of the app (§9.2). |
Worvento is a mobile app. There is no browser inside the app, so we do not use cookies in the classic sense. But three things do the same job:
example the Google library that shows ads).
randomly generated device number).
The law treats all three the same way as cookies. The Turkish Data Protection Authority's Guidelines on Cookie Practices (final version 20 June 2022) and Board decision no. 2022/229 of 10 March 2022 make tracking technologies used for advertising and marketing subject to explicit consent, regardless of technical form; only those strictly necessary to provide the service do not require consent. The Authority's Guidelines on Privacy in Mobile Applications (December 2023) applies the same framework to mobile apps.
In short: it is not called a cookie, but the cookie rules apply. That is why this document shows you, one by one, what we keep on your device, which ready-made code libraries we use, what data each touches, and which of them depend on your consent.
Sources: Turkish DPA Board decision 2022/229 (10.03.2022) · Guidelines on Cookie Practices (20.06.2022) · Guidelines on Privacy in Mobile Applications (December 2023) — <https://www.kvkk.gov.tr>
Everything we do on your device falls into one of two groups. This distinction is legally decisive, because consent is required only for the second group.
A · STRICTLY NECESSARY / FUNCTIONAL — no consent required Without these the app cannot do what you asked it to do: keep your session open, store the words you learn, remember your theme and sound preference, warn you when your internet drops. The Cookie Guidelines' exemption for what is "strictly necessary to provide the service" covers these; the legal ground is performance of a contract (KVKK art.5/2-c) or legitimate interest (KVKK art.5/2-f).
B · ADVERTISING — subject to explicit consent The Google library that shows rewarded ads, and the advertising identifier. Legitimate interest cannot be used for the personalisation of ads: Board decision 2022/229 subjects advertising and marketing tracking technologies to explicit consent, and access to an advertising identifier can never be read as "strictly necessary to provide the service."
If you do not consent, advertising is not switched off — it is only not personalised, and you do not lose your reward entitlement (see §6).
| group stored on device | ground | reasoning |
|---|---|---|
Session tokens (auth_jwt_token, auth_refresh_token, auth_email, auth_email_verified) | Strictly necessary — no consent required | You asked to sign in; a session cannot be maintained without a token. KVKK art.5/2-c |
Learning and settings data (Hive user_stats, words, categories, shared_list_cache) | Strictly necessary — no consent required | The app's core function is teaching words; the service does not work if your progress is not stored. KVKK art.5/2-c |
| Game high scores and tour/celebration/banner flags | Strictly necessary — no consent required | Interface state that stays on the device only; it does not leave and has nothing to do with advertising |
Sync snapshot (sync_meta_user_stats_v1) | Strictly necessary — no consent required | Prevents sending the same data over and over; it serves data minimisation |
Device fingerprint (device_fingerprint) and installation id (install_id) | Strict necessity claim + legitimate interest (KVKK art.5/2-f) — ⚠️ see note below | Preventing abuse, multi-accounting and referral-code exploitation |
| Home screen widget data | Strictly necessary — no consent required | You added the widget yourself; without data it stays empty |
| The advertising identifier and the personalisation of ads | EXPLICIT CONSENT (KVKK art.5/1) | Personalisation can never be read as strictly necessary to provide the service |
The table below contains every dependency in the app's pubspec.yaml plus one package pulled in indirectly by the advertising library. Version numbers are those declared in pubspec.yaml.
Legal ground abbreviations
| abbreviation | meaning |
|---|---|
| CONTRACT | Performance of a contract — KVKK art.5/2-c |
| LEGIT | Legitimate interest — KVKK art.5/2-f |
| CONSENT | Explicit consent — KVKK art.5/1 |
| LEGAL-OBL | Legal obligation — KVKK art.5/2-ç |
| NEC | "Strictly necessary to provide the service" → no consent required |
| CONSENT | Personalisation of advertising → explicit consent required |
| SDK / package | what it does | what data it touches | does it leave the device | legal ground | link |
|---|---|---|---|---|---|
google_mobile_ads ^5.2.0 (Google Mobile Ads / AdMob) | Shows rewarded video ads. If you watch one, our server grants the reward. | Advertising identifier (GAID on Android, IDFA on iOS), your IP address, device and OS information, screen information, the app's package name, your interaction with the ad. Google also collects its own diagnostic and product-interaction data. | Yes — to Google. Google is an independent controller for this data; it is not our processor and also processes the data for its own purposes. | CONSENT + CONSENT | <https://policies.google.com/technologies/partner-sites> |
| Reward verification (SSV) — a feature of the SDK above | The server, not the client, grants the reward; Google reports the reward directly to our server. | Your server account id (userId) in plain text plus the reward type is sent to Google. | Yes — to Google. This id is not a pseudonym; it maps directly to your account. | LEGITIMATE INTEREST | <https://policies.google.com/technologies/partner-sites> — this item is independent of advertising-personalisation consent; it happens regardless of your consent state whenever you watch a rewarded ad |
Current state of the code — an honest statement. The app has no advertising preference screen yet. The rule this policy sets is: until that screen ships, rewarded ads are served without personalisation — that is, "I do not allow personalisation" is today's default state. When the screen ships, this document will be updated and its effective date will change.
| SDK / package | what it does | what data it touches | does it leave the device | legal ground | link |
|---|---|---|---|---|---|
in_app_purchase ^3.2.0 (+ in_app_purchase_android, in_app_purchase_storekit) | In-app purchases. The store takes the payment; we only pass the receipt to our server and grant the entitlement. | Product id, store transaction id, receipt string. The app never sees your payment card details. | Yes. On Android to Google Commerce Limited, on iOS to Apple Distribution International Ltd. Both are independent controllers and act as seller/agent on the store side. The receipt also goes to our own server. | CONTRACT + LEGAL-OBL for financial records | <https://policies.google.com/privacy> · <https://www.apple.com/legal/privacy> |
flutter_secure_storage ^9.2.2 | Stores your session tokens and device number encrypted. Uses Keystore/EncryptedSharedPreferences on Android and the Keychain on iOS. | Session token, refresh token, your last sign-in email, verification flag, device fingerprint, sync snapshot (see §4). | The stored tokens go to our server with every request. The storage itself stays on the device. | CONTRACT + NEC (session continuity) | — |
shared_preferences ^2.3.2 | Simple settings and flag storage. XML on Android, NSUserDefaults on iOS. | Installation id, 12 mini-game high scores, tour / celebration / banner flags (see §4). | The installation id goes to the server on sign-up and sign-in; the rest stays on the device. | CONTRACT · LEGIT + NEC for the installation id | — |
hive ^2.2.3 + hive_flutter ^1.1.0 | On-device local database. Lets you study your own word list when you have no internet. | The word pool and the words you added, category locks, a statistics object with more than 60 fields, the shared-list mirror. Stored unencrypted (relying on the device's own app isolation). | Part of it goes to the server on sync (XP, streak, badges, daily activity log). | CONTRACT + NEC | — |
dio ^5.7.0 | HTTPS communication with our server. | Every request you send and every response received. | Yes — only to api.worvento.com. | CONTRACT | — |
dio_cache_interceptor ^4.0.6 | Keeps responses from endpoints the server allows in memory for a short time (see §8). | Catalogue responses (gift list, spin wheel list). | No — RAM only. | CONTRACT + NEC | — |
internet_connection_checker_plus ^2.5.2 (resolved version 2.9.1+2) | Tests whether your internet actually works (captive portal, hotspot without internet). ⚠️ See §3.3. | Your IP address, User-Agent information and timestamp. | Yes — to 4 hosts we do not own. | LEGIT, but the ground is problematic — see §3.3 | <https://www.cloudflare.com/privacypolicy/> |
signalr_netcore ^1.4.0 | Real-time WebSocket connection for live challenges, duels and hangman. Does not poll. | Match state, invitations, usernames. Your session token is carried in the query string — it may appear in reverse-proxy access logs. | Yes — only to our own server. | CONTRACT | — |
image_picker ^1.1.2 | Lets you pick a profile photo. Uses the Android Photo Picker or a camera intent. | Only the photo you pick individually. No permission for access to your whole gallery is requested (none of READ_MEDIA_IMAGES, CAMERA, READ_EXTERNAL_STORAGE is present). | The raw bytes of the photo you pick are uploaded with a signed URL directly to Cloudflare R2 object storage. Cloudflare, Inc. (USA) — global infrastructure; profile photos are not pinned to a specific country. They are encrypted in transit and at rest. | CONSENT (the photo is optional) | <https://www.cloudflare.com/privacypolicy/> |
crop_your_image ^2.0.0 | Crops the photo with a circular mask before upload. Pure Dart; no network access. | The bytes of the cropped image (in the temporary directory). | No. | CONSENT | — |
file_picker ^8.1.7 | Lets you pick a file for CSV import. Uses the system picker. | Only the file you pick. No broad storage permission. | No. | CONTRACT | — |
share_plus ^10.1.4 | Lets you share result cards, your referral code and your weekly report. | The share card image (score, XP, streak, category name, referral code) and the caption text. On a duel card your opponent's username is also embedded in the image. | Yes — to the app you choose (WhatsApp, Instagram, email…). That app is an independent controller. | CONTRACT (you initiate the share) | — |
flutter_tts ^4.2.0 | Reads out a word's pronunciation. Uses the speech engine installed on your device; we store no audio. | The text of the word being spoken and the target language code. | It depends. The code assumes the device engine works offline but does not enforce it: there is no engine selection or network-use setting. With an engine that performs cloud synthesis (the default engine on Android may do this for higher-quality voices) the word text goes to the engine provider. | CONTRACT | Depends on the engine — mostly <https://policies.google.com/privacy> on Android · <https://www.apple.com/legal/privacy> on iOS |
home_widget ^0.7.0 | Feeds the "Word of the Day" home screen widget. | Your streak day count, day counter, word title, source/target word, emoji. In SharedPreferences on Android, in the group.com.worvento.app App Group container on iOS. The word stays hidden until answered; the streak count is written on every refresh and there is no setting to turn it off — it may be visible on your lock screen. | No — it stays on the device. | CONTRACT | — |
audioplayers ^6.1.0 | Plays correct/wrong/tap sound effects. | Only the assets/sounds/*.wav files inside the app. No microphone permission, no audio recording. | No. | CONTRACT | — |
path_provider ^2.1.5 | Finds the path of the temporary and documents directories. | Share image, crop temporary file, CSV export file. | No. | CONTRACT | — |
url_launcher ^6.3.1 | Opens legal pages in your device's own browser (no in-app browser). | The address opened. | The request to that address is made through your browser; from that point on your browser's own settings apply. | CONTRACT | — |
uuid ^4.5.1 | Generates random numbers (for the device fingerprint and installation id). Reads no hardware information. | The random number it generates. | The generated numbers go to the server on sign-up and sign-in. | LEGIT + NEC | — |
csv ^6.0.0 | Converts your word list to CSV and reads CSV. No network access. | Your words. | No. | CONTRACT | — |
webview_flutter (indirect — pulled in as a google_mobile_ads dependency) | The app does not use this package itself. There is not a single WebViewWidget or WebViewController call in the code; legal pages open in the external browser. The package is installed because the advertising library needs it to render ad content. | Only ad content, when the advertising library shows an ad. | To the ad network, when an ad is shown. | Same as advertising: CONSENT + CONSENT | <https://policies.google.com/technologies/partner-sites> |
Packages that are interface-only and touch no personal data (for completeness): flutter_riverpod, go_router, easy_localization, flutter_card_swiper, lottie, animate_do, shimmer, fl_chart, flutter_heatmap_calendar, confetti, animations, cupertino_icons. These make no network requests and move no data off the device.
On the server side. The server the app talks to is hosted at Hetzner: Hetzner Online GmbH (Germany) — our server is located in Finland. Verification, password reset and account deletion code emails are sent through Google's Gmail infrastructure. For all server-side data see the Privacy Policy and the KVKK Privacy Notice.
The connectivity check goes only to our own server: {apiBaseUrl}/health, roughly every 45 seconds. Nothing goes to any third party.
This section used to read differently, and it has been corrected. Because no target addresses were specified, the internet_connection_checker_plus package used its own defaults; as a result, while the app was in the foreground, roughly every 10 seconds your IP address and User-Agent went to four addresses we do not own (one.one.one.one, icanhazip.com, jsonplaceholder.typicode.com, pokeapi.co). We had no data processing agreement with those parties. Redirecting the check to our own /health endpoint removed all four transfers.
The tables below show every item we keep on your device. The legal ground for each group is in §2.1.
In the "removed when the app is deleted?" column the platform difference matters: on Android encrypted storage is deleted together with the app; on iOS, Keychain records survive even if you delete the app. That difference applies to the session tokens below. The device number (device_fingerprint) was moved out of this group and is now deleted with the app — see the note under the table.
flutter_secure_storage)| key | what it holds | where | removed when the app is deleted | cleared on account deletion |
|---|---|---|---|---|
auth_jwt_token | Your session token (valid 7 days) | Android Keystore · iOS Keychain | Android: yes · iOS: no | Yes |
auth_refresh_token | Token for silently renewing your session (30 days) | Android Keystore · iOS Keychain | Android: yes · iOS: no | Yes |
auth_email | The email address you last signed in with (for the verification screen) | Android Keystore · iOS Keychain | Android: yes · iOS: no | Yes |
auth_email_verified | Whether your email is verified (1/0) | Android Keystore · iOS Keychain | Android: yes · iOS: no | Yes |
sync_meta_user_stats_v1 | Snapshot of the last successful sync: XP, correct/wrong counts, streak, badge list, daily activity log, timestamp. Used to avoid unnecessary uploads | Android Keystore · iOS Keychain | Android: yes · iOS: no | Yes |
Correction about the device number (2026-08-12):
device_fingerprintused to live in encrypted storage, and because iOS Keychain records survive app deletion the number was device-lifetime — a user who deleted and reinstalled the app was still recognised. That has been fixed: the number is now kept in ordinary app data (shared_preferences, §4.2), so it is deleted when you uninstall the app on both platforms, and any leftover Keychain record is purged. We know the cost — someone who reinstalls looks like a new device to us, so the abuse signal is weaker — and we accepted that cost in your favour.
shared_preferences)This entire group is deleted when you uninstall the app on both platforms and none of it is cleared on account deletion.
When the advertising preference screen ships, a record of your choice will be added to this list (scope, timestamp, text version).
hive)Hive boxes are kept in the app's data directory and are unencrypted — we rely on the device's own app isolation. All of them are deleted when you uninstall the app.
| box | what it holds | removed when the app is deleted | cleared on account deletion |
|---|---|---|---|
user_stats (stats key) | A statistics object with more than 60 fields: XP, streak, badges, language preference, theme, daily XP goal, sound and haptic settings, TTS setting, seen word ids, perfect categories, daily activity log, lunch-break / weekend / silent-test counters | Yes | Yes |
words | The word pool and the words you added yourself (MyList) — source word, target word, type, difficulty, correct/wrong counters | Yes | No |
categories | Category name, level and unlock threshold | Yes | No |
shared_list_cache | Offline mirror of a list someone shared with you: words and page cursor. There is no expiry or cleanup job in the code | Yes | No |
| file | what it holds | where | removed when the app is deleted | cleared on account deletion |
|---|---|---|---|---|
wordmaster_share.png | The image of the last share card you produced (score, XP, streak, referral code; in a duel, your opponent's username). Written under a fixed name and not deleted after sharing | Temporary directory | Yes | No |
| Crop temporary file | The cropped version of your profile photo before upload | Temporary directory | Yes | No |
my_words_export.csv | Your word list produced by CSV export (source word, target word, type, category). This directory is app-private; you cannot see the file from a file manager | The app's Documents directory | Yes | No |
When you delete your account, only these are cleared on the device: the four session keys (auth_jwt_token, auth_refresh_token, auth_email, auth_email_verified), sync_meta_user_stats_v1 and the user_stats Hive box.
What remains on the device: device_fingerprint (on iOS even if you delete the app), install_id, words (the words you added), categories, shared_list_cache, 12 mini-game high scores, all tour/celebration/banner flags, ya5BackfillDone, home screen widget data and the files in §4.4.
Fixing this is one of the highest-priority items in our remediation record. What account deletion does and does not delete on the server side is written out item by item in a separate document: Data Deletion.
| identifier | what it is | who reads it | can it be reset | what it is used for |
|---|---|---|---|---|
| Advertising identifier (GAID/AAID on Android, IDFA on iOS) | A number the operating system provides for advertising, which you can reset | The app's code does not read this number. Google's advertising library reads it itself. On Android the com.google.android.gms.permission.AD_ID permission is added by that library | Yes. Android: Settings > Google > All services > Ads. iOS: Settings > Privacy & Security > Tracking (if you refuse permission, the IDFA is all zeros) | Rewarded ad delivery, ad attribution, measurement — only with your consent |
Device fingerprint (device_fingerprint) | A random UUID we generate. No information is read from the hardware: no IMEI, serial number, MAC address, Android ID or device model | Our own server only | Yes. Uninstalling the app or clearing app data resets the number — the same on iOS and Android | Referral-code device limit, multi-account warning record, ban propagation. Nothing to do with advertising; goes to no third party |
Installation id (install_id) | A random UUID we generate | Our own server only | Yes — reinstalling the app or clearing app data regenerates it | Distinguishing "same device, different installation". Nothing to do with advertising |
Your server account id (userId) | The number of your account row on the server | Our own server and Google, during rewarded ad verification | No — it stays fixed for the life of your account | Account operations. ⚠️ During rewarded ad verification this number goes to Google in plain text (see §3.1) |
Why we do not use a hardware identifier. A signature derived from device model and operating system information collides across thousands of people using the same phone; real hardware identifiers such as IMEI require extra permissions. A number generated randomly and stored on the device is both more accurate and cleaner for privacy. No package like device_info_plus is present in the app; none of the fingerprinting techniques (canvas, font, WebGL) is used; your installed app list is not queried (no QUERY_ALL_PACKAGES permission); your clipboard is not read (we only write the referral code to it).
Accessing the advertising identifier and letting the advertising library write to your device requires your explicit consent for the personalisation of ads.
The ground is the Turkish Data Protection Authority's Guidelines on Cookie Practices and Board decision no. 2022/229 of 10 March 2022: tracking technologies used for advertising and marketing are subject to explicit consent, and legitimate interest cannot be used there.
One note: Google requires a certified consent management platform (CMP) for traffic from the European Economic Area and the United Kingdom. Worvento is not distributed in those regions, so that requirement does not apply to us; obtaining consent for personalisation is nevertheless required under the KVKK, and will be provided through an in-app preference switch.
| personalised | non-personalised | |
|---|---|---|
| How the ad is selected | By an interest profile tied to your advertising identifier | By context only (app category, language, country) |
| Is the advertising identifier read | Yes | No (the IDFA is not requested on iOS) |
| Does it fall under Apple's "tracking" definition | Yes — Google combines device data collected from this app with data collected from other developers' apps | No |
| Is consent required | Yes — explicit consent | No — legitimate interest in funding the service (see the note in §3.1) |
| Does it affect your reward | — | No. Your reward entitlement is the same if you refuse consent; the app keeps working fully |
That last row is a commitment: refusing consent or withdrawing it does not disable any of your features, does not reduce your reward entitlement and does not prevent you from using the app.
When the consent screen ships, these rules will apply:
behind a menu counts as a dark pattern and will not be done.
A permanent "Ad and privacy preferences" entry will exist in the app's menu.
burden of proving consent lies with the controller.
The text of the consent items in the same scope lives in a separate document: Explicit Consent Statement. Under principle decision no. 2026/347 of 18 February 2026 of the Turkish Personal Data Protection Board, the privacy notice and the explicit consent statement are separate documents and cannot be presented under a single approval.
Apple's App Tracking Transparency (ATT) permission is a separate and additional layer on top of KVKK consent: it is Apple's own platform rule and applies regardless of distribution territory. The recommended order:
requestTrackingAuthorization). This dialog appearsonly once per device.
If you refuse ATT, the IDFA is all zeros and personalised ads cannot be shown. Source: <https://developers.google.com/admob/flutter/privacy/idfa>
The honest position on iOS: Worvento has never been submitted to the App Store. ATT permission is not requested on iOS today: there is no requestTrackingAuthorization call in the code. Although a permission string and 46 SKAdNetwork identifiers are declared in Info.plist, no dialog ever appears because there is no permission flow. When the iOS version is released, this section will be updated either with the ATT flow or with advertising being disabled entirely on iOS.
Worvento is for ages 16 and over. This has two consequences on the advertising side:
advertising library, or advertising is switched off entirely.
unsuitable for a 16+ audience are not shown.
Worvento contains no analytics or crash reporting library whatsoever. This was verified three ways: pubspec.yaml was read line by line, all 170 resolved packages were listed, and the entire application code was scanned case-insensitively.
Not present: Firebase (Analytics, Crashlytics, Messaging), Sentry, Amplitude, Mixpanel, AppsFlyer, Adjust, Facebook App Events, PostHog, Datadog, Bugsnag, OneSignal, Segment.
What this means for you:
tapped which button, or your session durations.
the crash goes nowhere.
or a measurement company — because we never collect that data.
usage data declaration is made as "product interaction → app functionality."
Notifications. The app uses two notification mechanisms, both of which can be switched off independently under Settings → Notifications:
notifications. A notification token is generated for the device and stored on our server (deleted when the account is deleted, removed on sign-out). The token is a device registration, not an advertising identifier; it is not used for tracking or profiling and is not shared with ad networks.
flutter_local_notifications): used for reminders. Schedulinghappens on the device, no data leaves it, and no third party is involved.
On Android the POST_NOTIFICATIONS permission is requested (Android 13+); if it is denied the app works normally. In addition, live match and duel events arrive while the app is open over the SignalR WebSocket connection (§3.2), and the home screen widget updates its data on the device (§4.2).
An honest limit — we are not hiding this either. Google's advertising library collects diagnostic and ad-interaction data on its own account and sends it to Google. That is not our analytics layer, and we have no access to that data. But technically it is a telemetry stream leaving your device, and it starts when advertising consent is given. While advertising is off, so is that stream.
If we ever add our own error reporting, we will update this document, the privacy policy and the store forms at the same time.
In-app cache (dio_cache_interceptor). We keep server responses in RAM only (MemCacheStore); no response is written to disk. The cache disappears when you close the app.
The policy is CachePolicy.request: only endpoints where the server sends a Cache-Control header are cached. Today these are only catalogue endpoints (gift list, spin wheel list; max-age=300, i.e. 5 minutes). The maximum staleness allowed is 1 hour.
What is not cached — verified in code: the leaderboard, the league, profiles and the friend list send no Cache-Control header, so they always come fresh from the network. That means other people's usernames and statistics are not cached on your device.
Profile photo delivery cache (Cloudflare R2). Profile photos are kept in Cloudflare R2 object storage. Cloudflare, Inc. (USA) — global infrastructure; profile photos are not pinned to a specific country. They are encrypted in transit and at rest. Photos are served with an instruction to cache them for 1 year as immutable (public,max-age=31536000,immutable). The honest consequence: after you delete your photo, a copy may keep living for a while in the delivery network cache or a browser cache. Your deletion request targets the object at the origin; cached copies expire on their own.
| what you want to do | where |
|---|---|
| Change your ad and privacy preferences | Settings > Ad and privacy preferences — ⚠️ This entry does NOT exist in the app today. It will be added together with the consent screen. For now, no ads are shown until the consent screen ships |
| Turn off sound, haptics, pronunciation or theme | Settings |
| Clear the intro tour flags | Settings > Reset tours |
| Remove your profile photo | Profile screen — removing the photo also deletes the objects on the server |
| Get your word list as CSV | Settings > Export CSV — ⚠️ honest warning: the file is written to the app's own Documents directory and you cannot reach it with a file manager. Delivering the file to you is an open item in our remediation record |
| Delete your account | Settings > Delete account — two steps: password confirmation, then a code sent by email. What is and is not deleted is written out item by item in Data Deletion |
| Read the legal documents | Settings > Legal — ⚠️ this link currently points to an address that is not live; the real legal pages are under https://worvento.com/legal/. An open item in our remediation record |
The advertising identifier is a number provided by the operating system; you manage it independently of the app.
Android
entirely; from that moment apps see a string of zeros instead of an identifier.
Advertising ID policy prohibits linking a deleted or reset identifier with data derived from the previous identifier.
iOS
Track", no app can even ask for permission and the IDFA is all zeros.
advertising.
Uninstalling the app deletes the Hive boxes, the shared_preferences contents and the temporary files on both platforms. But Keychain records survive on iOS (§4.1); on iOS the only reliable way to delete keys such as device_fingerprint is to reset the device. On Android, Settings > Apps > Worvento > Storage > Clear data also clears the encrypted store.
The app requests no sensitive permission that would produce a permission dialog. None of the camera, gallery, microphone, location, contacts, calendar, SMS or notification permissions is present in the release package. The practical consequence: the app never asks you a runtime permission question, and because it never asks, no feature breaks if you refuse.
All permissions present in the release package, and why they are there:
| permission | who requests it | what for |
|---|---|---|
INTERNET | the app | Communication with the server. The app works online |
ACCESS_NETWORK_STATE | the app | Reading connectivity state |
com.android.vending.BILLING | in_app_purchase | In-app purchases |
com.google.android.gms.permission.AD_ID | added by the advertising library | Access to the advertising identifier. Used only with your consent |
ACCESS_ADSERVICES_AD_ID · ACCESS_ADSERVICES_ATTRIBUTION · ACCESS_ADSERVICES_TOPICS | added by the advertising library | Android Privacy Sandbox ad measurement |
WAKE_LOCK · FOREGROUND_SERVICE | added by the advertising library | Keeping the screen on during video ad playback |
DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION | Android libraries | Keeping broadcast receivers from being exposed outside the app (a security measure) |
When you pick a profile photo, image_picker uses the Android Photo Picker or a camera intent; this is the permission-free route and does not grant access to your whole gallery. For CSV import, file_picker uses the system file picker; no broad storage permission is requested. We see only the file you pick individually.
Data we do not collect. We collect none of the following: GPS or network-based location, your contacts, your phone number, health and fitness data, microphone recordings, calendar, SMS and call logs, biometric data, your installed app list, analytics and crash reports, push notification tokens, sign-in with Google/Apple/Facebook. The one honest exception: we send your time zone offset (in minutes) to the server so that daily limits reset at your local midnight. That is not GPS location, but it does allow a coarse geographic inference; we chose not to hide it while saying "we do not collect location."
When we add a new SDK, when an item we store on your device changes, or when the way advertising consent works changes, we update this document and change the version and last updated date above. Article 5/1-b of the Communiqué on Privacy Notice requires a fresh privacy notice before processing when the purpose of processing changes; that is why the text is updated before a new data flow goes live.
Data controller: the publisher of Worvento (Türkiye) · worvento.info@gmail.com Data protection requests and support: worvento.info@gmail.com Published address: https://worvento.com/legal/izleme-teknolojileri
Third parties' own privacy documents: Google (advertising partners) <https://policies.google.com/technologies/partner-sites> · Google (general) <https://policies.google.com/privacy> · Cloudflare <https://www.cloudflare.com/privacypolicy/> · Hetzner <https://www.hetzner.com/legal/privacy> · Apple <https://www.apple.com/legal/privacy>