Uygulama / App: Worvento  ·  Paket kimliği / Package name: com.worvento.app

Çerez ve SDK Politikası
Cookie and SDK Policy

Bu sayfanın adresi / Address of this page: https://worvento.com/legal/izleme-teknolojileri
Bu sayfaya erişmek için giriş yapmanız gerekmez. You do not need to sign in to read this page.

Türkçe

Çerez ve SDK Politikası

Sürüm: 1.0 · Yürürlük: 8 Ağustos 2026 · Son güncelleme: 8 Ağustos 2026

Veri sorumlusu: Worvento'nun Türkiye'de yerleşik yayıncısı (gerçek kişi) · worvento.info@gmail.com Uygulama: Worvento (com.worvento.app) · Sunucu: https://api.worvento.com


Kısa özet — bir bakışta

Detayını aşağıda madde madde yazdık. Acele ediyorsanız bu tablo yeter:

sorukısa cevap
Çerez kullanıyor musunuz?Hayır, uygulamada tarayıcı yok. Ama aynı kurala tabi üç şey var: SDK'lar, cihazda depolama, tanımlayıcılar.
Kişisel verimi satıyor musunuz?Hayır. Kişisel verilerinizi satmıyoruz. Hizmeti çalıştırmak için sayılı alıcıyla sayılı veriyi paylaşıyoruz (§3, §11).
Beni izleyen analitik var mı?Hayır. Hiçbir analitik ya da çökme raporlama kütüphanesi yok (§7).
Onay gereken tek şey ne?Reklam ve reklam kimliği (§2-B, §6). Diğer her şey hizmetin çalışması için zorunlu.
Onay ekranı şu an var mı?Kişiselleştirilmiş reklam hiç kullanılmadığı için ayrı bir reklam onay ekranı yok; tüm reklam istekleri kişiselleştirmesiz (npa=1) gidiyor (§3.1, §6). Rıza durumunuzu "Ayarlar > Gizlilik ve İzinler"den yönetirsiniz.
En rahatsız edici gerçek ne?İnternet kontrolü eskiden IP adresinizi bize ait olmayan 4 adrese gönderiyordu; bu düzeltildi — kontrol artık yalnız kendi sunucumuza gidiyor (§3.3).
Hesabımı silsem cihazda ne kalır?Silme akışı cihazdaki verinizi de temizliyor; yalnız kötüye kullanımı sınırlayan iki rastgele numara kalır ve uygulamayı kaldırınca iOS dâhil silinir. Tam liste §4.5'te.
Reklam kimliğimi nasıl sıfırlarım?Cihaz ayarlarından, uygulamadan bağımsız (§9.2).

1. Bu metin neyi anlatıyor — ve neden adı "çerez" değil

Worvento bir mobil uygulama. Uygulamanın içinde tarayıcı yok, bu yüzden klasik anlamda çerez (cookie) kullanmıyoruz. Ama aynı işi gören üç şey var:

  1. SDK'lar — başkalarının yazdığı, uygulamanın içine gömülü hazır kod parçaları

(örneğin reklam gösteren Google kütüphanesi).

  1. Cihaz üzerinde depolama — telefonunuzun içinde tuttuğumuz dosyalar, anahtarlar,

şifreli kayıtlar.

  1. Tanımlayıcılar — sizi ya da cihazınızı ayırt eden numaralar (reklam kimliği,

rastgele üretilmiş cihaz numarası).

Hukuk bu üçünü çerezle aynı kefeye koyuyor. Kişisel Verileri Koruma Kurumu'nun Çerez Uygulamaları Hakkında Rehberi (nihai sürüm 20.06.2022) ve Kurul'un 10.03.2022 tarihli 2022/229 sayılı kararı, teknik biçimden bağımsız olarak reklam ve pazarlama amaçlı takip teknolojilerini açık rızaya tabi tutuyor; yalnızca hizmetin sunulması için kesinlikle zorunlu olanlar rıza gerektirmiyor. Kurumun Mobil Uygulamalarda Mahremiyetin Korunmasına Yönelik Tavsiyeler Rehberi (Aralık 2023) de aynı çerçeveyi mobil uygulamalara uyguluyor.

Kısacası: adı çerez değil, ama kuralı çerezin kuralı. Bu yüzden bu metin size cihazınızda ne tuttuğumuzu, hangi hazır kod parçalarını kullandığımızı, bunların hangi veriye dokunduğunu ve hangisinin onayınıza bağlı olduğunu tek tek gösteriyor.

Kaynaklar: KVKK Kurul kararı 10.03.2022 t. 2022/229 · Çerez Uygulamaları Hakkında Rehber (20.06.2022) · Mobil Uygulamalarda Mahremiyetin Korunmasına Yönelik Tavsiyeler Rehberi (Aralık 2023) — <https://www.kvkk.gov.tr>


2. İki kategori: zorunlu olanlar ve reklam için olanlar

Cihazınızda yaptığımız her işlem iki gruptan birine giriyor. Bu ayrım hukuken belirleyici, çünkü onay yalnızca ikinci grup için gerekiyor.

A · ZORUNLU/İŞLEVSEL — onay gerekmiyor Bunlar olmadan uygulama isteğiniz üzerine çalışamaz: oturumunuzu açık tutmak, öğrendiğiniz kelimeleri saklamak, tema ve ses tercihinizi hatırlamak, internetiniz kesildiğinde uyarmak. Çerez Rehberi'nin "hizmetin sunulması için kesinlikle zorunlu" istisnası bunları kapsıyor; hukuki dayanak sözleşmenin ifası (KVKK m.5/2-c) ya da meşru menfaat (m.5/2-f).

B · REKLAM — açık rızaya bağlı Ödüllü reklam gösteren Google kütüphanesi ve reklam kimliği. Reklamların kişiselleştirilmesi için meşru menfaat kullanılamaz: Kurul'un 2022/229 sayılı kararı reklam ve pazarlama amaçlı takip teknolojilerini açık rızaya bağlıyor ve reklam kimliğine erişim hiçbir yorumla "hizmetin sunulması için kesinlikle zorunlu" sayılamaz.

Rıza vermezseniz reklam kapanmaz, yalnız kişiselleştirilmez — ödül hakkınızı kaybetmezsiniz (bkz. §6).

2.1 Cihazda sakladığımız her grubun dayanağı

cihazda saklanan grupdayanakgerekçe
Oturum jetonları (auth_jwt_token, auth_refresh_token, auth_email, auth_email_verified)Kesinlikle gerekli — onay gerekmiyorGiriş yapmanızı istediniz; jeton olmadan oturum sürdürülemez. KVKK m.5/2-c
Öğrenme ve ayar verisi (Hive user_stats, words, categories, shared_list_cache)Kesinlikle gerekli — onay gerekmiyorUygulamanın temel işlevi kelime öğretmek; ilerlemeniz saklanmazsa hizmet çalışmaz. KVKK m.5/2-c
Oyun rekorları ve tur/kutlama/banner bayraklarıKesinlikle gerekli — onay gerekmiyorYalnız cihazda kalan arayüz durumu; dışarıya çıkmıyor, reklamla ilgisi yok
Senkronizasyon anlık görüntüsü (sync_meta_user_stats_v1)Kesinlikle gerekli — onay gerekmiyorAynı veriyi tekrar tekrar göndermemek için; veri minimizasyonuna hizmet ediyor
Cihaz parmak izi (device_fingerprint) ve kurulum kimliği (install_id)Kesinlikle gerekli iddiası + meşru menfaat (KVKK m.5/2-f) — ⚠️ aşağıdaki nota bakınKötüye kullanım, çoklu-hesap ve davet kodu istismarı önleme
Ana ekran widget'ı verisiKesinlikle gerekli — onay gerekmiyorWidget'ı siz eklediniz; verisi olmadan widget boş kalır
Reklam kimliği ve reklamın kişiselleştirilmesiAÇIK RIZA (KVKK m.5/1)Kişiselleştirme hiçbir yorumla hizmetin sunulması için kesinlikle zorunlu sayılamaz

3. Kullandığımız SDK'lar ve paketler — tam liste

Aşağıdaki tablo uygulamanın pubspec.yaml dosyasındaki bağımlılıkların tamamını ve reklam kütüphanesinin dolaylı olarak getirdiği bir paketi içeriyor. Sürüm numaraları pubspec.yaml içindeki tanımlardır.

Hukuki dayanak kısaltmaları

kısaltmaanlamı
SÖZSözleşmenin ifası — KVKK m.5/2-c
MEŞMeşru menfaat — KVKK m.5/2-f
RIZAAçık rıza — KVKK m.5/1
HUKHukuki yükümlülük — KVKK m.5/2-ç
ZOR"Hizmetin sunulması için kesinlikle zorunlu" → onay gerekmiyor
RIZAReklam kişiselleştirmesi → açık rıza gerekiyor

3.1 B kategorisi — reklam (onaya bağlı)

SDK / paketne yapıyorhangi veriye dokunuyorcihazdan çıkıyor muhukuki dayanaklink
google_mobile_ads ^5.2.0 (Google Mobile Ads / AdMob)Ödüllü video reklam gösterir. Reklamı izlerseniz ödülünüzü sunucumuz verir.Reklam kimliği (Android'de GAID, iOS'ta IDFA), IP adresiniz, cihaz ve işletim sistemi bilgisi, ekran bilgisi, uygulamanın paket adı, reklamla etkileşiminiz. Google ayrıca kendi teşhis bilgisi ve ürün etkileşimi verisi topluyor.Evet — Google'a. Google bu veride bağımsız veri sorumlusu; bizim veri işleyenimiz değil, veriyi kendi amaçları için de işliyor.RIZA + RIZA<https://policies.google.com/technologies/partner-sites>
Ödül doğrulama (SSV) — yukarıdaki SDK'nın bir özelliğiÖdülü istemci değil sunucu verir; Google ödül bilgisini doğrudan sunucumuza bildirir.Sunucudaki hesap kimliğiniz (userId) düz metin olarak ve ödül türü, Google'a gönderilir.Evet — Google'a. Bu kimlik takma ad değil; hesabınızla doğrudan eşleşir.MEŞRU MENFAAT<https://policies.google.com/technologies/partner-sites> — bu kalem reklam kişiselleştirme rızasından bağımsızdır; ödüllü reklam izlediğinizde rıza durumunuzdan bağımsız olarak gerçekleşir

Şu anki kod durumu — dürüst beyan. Uygulamada reklam tercihi ekranı henüz yok. Bu politikanın kurduğu kural şudur: tercih ekranı devreye alınana kadar ödüllü reklamlar kişiselleştirilmeden gösterilir; yani "kişiselleştirmeye izin vermiyorum" bugünkü varsayılan durumdur. Tercih ekranı devreye girdiğinde bu metin güncellenecek ve yürürlük tarihi değişecektir.

3.2 A kategorisi — zorunlu/işlevsel (onay gerekmiyor)

SDK / paketne yapıyorhangi veriye dokunuyorcihazdan çıkıyor muhukuki dayanaklink
in_app_purchase ^3.2.0 (+ in_app_purchase_android, in_app_purchase_storekit)Uygulama içi satın alma. Ödemeyi mağaza alır; biz yalnız makbuzu sunucuya iletip hakkı veririz.Ürün kimliği, mağaza işlem kimliği, makbuz metni. Ödeme kartı bilgisini uygulama hiç görmez.Evet. Android'de Google Commerce Limited'e, iOS'ta Apple Distribution International Ltd'ye. İkisi de bağımsız veri sorumlusu ve mağaza tarafında satıcı/aracı. Makbuz ayrıca kendi sunucumuza gider.SÖZ + mali kayıt için HUK<https://policies.google.com/privacy> · <https://www.apple.com/legal/privacy>
flutter_secure_storage ^9.2.2Oturum jetonlarınızı ve cihaz numaranızı şifreli saklar. Android'de Keystore/EncryptedSharedPreferences, iOS'ta Keychain kullanır.Oturum jetonu, yenileme jetonu, son giriş e-postanız, doğrulama bayrağı, cihaz parmak izi, senkronizasyon anlık görüntüsü (bkz. §4).Saklanan jetonlar her istekte sunucumuza gider. Depolamanın kendisi cihazda kalır.SÖZ + ZOR (oturum sürdürme)—
shared_preferences ^2.3.2Basit ayar ve bayrak saklama. Android'de XML, iOS'ta NSUserDefaults.Kurulum kimliği, 12 mini-oyun rekoru, tanıtım turu / kutlama / banner bayrakları (bkz. §4).Kurulum kimliği kayıt ve girişte sunucuya gider; diğerleri cihazda kalır.SÖZ · kurulum kimliği için MEŞ + ZOR—
hive ^2.2.3 + hive_flutter ^1.1.0Cihaz üstü yerel veritabanı. İnternetiniz yokken kendi kelime listenizi çalışabilmenizi sağlar.Kelime havuzu ve sizin eklediğiniz kelimeler, kategori kilitleri, 60'tan fazla alanlı istatistik nesnesi, ortak liste aynası. Şifresiz tutulur (cihazın kendi uygulama-izolasyonuna güvenilir).Bir kısmı senkronizasyonla sunucuya gider (XP, seri, rozet, günlük aktivite günlüğü).SÖZ + ZOR—
dio ^5.7.0Sunucumuzla HTTPS iletişimi.Gönderdiğiniz her istek ve gelen her yanıt.Evet — yalnız api.worvento.com adresine.SÖZ—
dio_cache_interceptor ^4.0.6Sunucu izin veren uçların yanıtını kısa süre bellekte tutar (bkz. §8).Katalog yanıtları (hediye listesi, çark listesi).Hayır — yalnız RAM.SÖZ + ZOR—
internet_connection_checker_plus ^2.5.2 (çözümlenen sürüm 2.9.1+2)İnternetinizin gerçekten çalıştığını sınar (kaptif portal, internetsiz hotspot tespiti). ⚠️ Bkz. §3.3.IP adresiniz, User-Agent bilgisi ve zaman damgası.Evet — bize ait olmayan 4 adrese.MEŞ, ancak dayanak sorunlu — bkz. §3.3<https://www.cloudflare.com/privacypolicy/>
signalr_netcore ^1.4.0Canlı meydan okuma, düello ve asmaca için gerçek-zaman WebSocket bağlantısı. Sürekli sorgulama (polling) yapmaz.Maç durumu, davetler, kullanıcı adları. Oturum jetonunuz adres satırında (query string) taşınır — ters vekil erişim kayıtlarında görünebilir.Evet — yalnız kendi sunucumuza.SÖZ—
image_picker ^1.1.2Profil fotoğrafı seçtirir. Android Foto Seçici ya da kamera niyeti kullanır.Yalnız sizin tek tek seçtiğiniz fotoğraf. Galerinin tamamına erişim izni istenmiyor (READ_MEDIA_IMAGES, CAMERA, READ_EXTERNAL_STORAGE izinlerinin hiçbiri yok).Seçtiğiniz fotoğrafın ham baytları imzalı adresle doğrudan Cloudflare R2 nesne depolamasına yüklenir. Cloudflare, Inc. (ABD) — küresel altyapı; profil fotoğrafları belirli bir ülkeye sabitlenmemiştir. Aktarımda ve saklamada şifrelenir.RIZA (fotoğraf isteğe bağlı)<https://www.cloudflare.com/privacypolicy/>
crop_your_image ^2.0.0Fotoğrafı yüklemeden önce daire maskesiyle kırpar. Saf Dart; ağ erişimi yok.Kırpılan görselin baytları (geçici dizinde).Hayır.RIZA—
file_picker ^8.1.7CSV içe aktarmada dosya seçtirir. Sistem seçicisini kullanır.Yalnız sizin seçtiğiniz dosya. Geniş depolama izni yok.Hayır.SÖZ—
share_plus ^10.1.4Sonuç kartlarını, davet kodunuzu ve karneyi paylaşmanızı sağlar.Paylaşım kartı görüntüsü (skor, XP, seri, kategori adı, davet kodu) ve altyazı metni. Düello kartında rakibinizin kullanıcı adı da görüntüye gömülü olarak çıkar.Evet — sizin seçtiğiniz uygulamaya (WhatsApp, Instagram, e-posta…). O uygulama bağımsız veri sorumlusudur.SÖZ (paylaşımı siz başlatırsınız)—
flutter_tts ^4.2.0Kelimenin telaffuzunu okutur. Cihaza yüklü ses motorunu kullanır; biz hiçbir ses saklamıyoruz.Okutulan kelimenin metni ve hedef dil kodu.Duruma göre. Kod cihaz motorunun çevrimdışı çalıştığını varsayıyor ama bunu zorlamıyor: motor seçimi ve ağ kullanımı ayarı yok. Bulut sentezi yapan bir motorda (Android'de varsayılan motor yüksek kaliteli ses için bunu yapabilir) kelime metni motor sağlayıcısına gider.SÖZMotora bağlı — Android'de çoğunlukla <https://policies.google.com/privacy> · iOS'ta <https://www.apple.com/legal/privacy>
home_widget ^0.7.0"Günün Kelimesi" ana ekran widget'ını besler.Seri gün sayınız, gün sayacı, kelime başlığı, kaynak/hedef kelime, emoji. Android'de SharedPreferences, iOS'ta group.com.worvento.app App Group kabında. Kelime cevaplanana kadar gizli tutulur; seri sayısı her tazelemede yazılır ve kapatma ayarı yok — kilit ekranında görünebilir.Hayır — cihazda kalır.SÖZ—
audioplayers ^6.1.0Doğru/yanlış/tık ses efektlerini çalar.Yalnız uygulamanın içindeki assets/sounds/*.wav dosyaları. Mikrofon izni yok, ses kaydı yok.Hayır.SÖZ—
path_provider ^2.1.5Geçici dizin ve belgeler dizininin yolunu bulur.Paylaşım görüntüsü, kırpma geçici dosyası, CSV dışa aktarma dosyası.Hayır.SÖZ—
url_launcher ^6.3.1Yasal sayfaları cihazın kendi tarayıcısında açar (uygulama içi tarayıcı kullanmaz).Açılan adres.Adrese giden istek tarayıcınız üzerinden yapılır; bu noktadan sonra tarayıcınızın kendi ayarları geçerlidir.SÖZ—
uuid ^4.5.1Rastgele numara üretir (cihaz parmak izi ve kurulum kimliği için). Hiçbir donanım bilgisi okumaz.Ürettiği rastgele numara.Üretilen numaralar kayıt ve girişte sunucuya gider.MEŞ + ZOR—
csv ^6.0.0Kelime listenizi CSV'ye çevirir ve CSV'den okur. Ağ erişimi yok.Kelimeleriniz.Hayır.SÖZ—
webview_flutter (dolaylı — google_mobile_ads bağımlılığı olarak gelir)Uygulama bu paketi kendisi kullanmıyor. Kodda tek bir WebViewWidget veya WebViewController çağrısı yok; yasal sayfalar dış tarayıcıda açılıyor. Paket, reklam kütüphanesinin reklam içeriğini göstermek için ihtiyaç duyduğu için kuruluma dahil oluyor.Yalnız reklam kütüphanesi bir reklam gösterdiğinde reklam içeriği.Reklam gösterildiğinde reklam ağına.Reklamla aynı: RIZA + RIZA<https://policies.google.com/technologies/partner-sites>

Yalnız arayüz için olan, hiçbir kişisel veriye dokunmayan paketler (tamlık için): flutter_riverpod, go_router, easy_localization, flutter_card_swiper, lottie, animate_do, shimmer, fl_chart, flutter_heatmap_calendar, confetti, animations, cupertino_icons. Bunlar ağ erişimi yapmaz ve cihazdan veri çıkarmaz.

Sunucu tarafında. Uygulamanın konuştuğu sunucu Hetzner'da barınıyor: Hetzner Online GmbH (Almanya) — sunucumuz Finlandiya'da bulunuyor. Doğrulama, şifre sıfırlama ve hesap silme kodu e-postaları Google'ın Gmail altyapısı üzerinden gönderiliyor. Sunucu tarafındaki verinin tamamı için Gizlilik Politikası ve Aydınlatma Metni metinlerine bakın.

3.3 ⚠️ Bağlantı kontrolü — açıkça beyan ettiğimiz rahatsız edici bir gerçek

Bağlantı kontrolü yalnız kendi sunucumuza gidiyor: {apiBaseUrl}/health, yaklaşık 45 saniyede bir. Üçüncü tarafa hiçbir şey gitmiyor.

Bu bölümün eski hâli farklıydı ve düzeltildi. internet_connection_checker_plus paketi, hedef adres belirtilmediği için kendi varsayılan adreslerini kullanıyordu; sonuç olarak uygulama ön plandayken yaklaşık 10 saniyede bir IP adresiniz ve User-Agent bilginiz bize ait olmayan dört adrese gidiyordu (one.one.one.one, icanhazip.com, jsonplaceholder.typicode.com, pokeapi.co). Bu taraflarla veri işleme sözleşmemiz yoktu. Kontrol kendi /health ucumuza çevrilerek bu dört aktarım tümden kaldırıldı.

Bunu düzeltmeyi taahhüt ediyoruz: kontrol kendi sunucumuza (api.worvento.com) yönlendirilecek ve kontrol aralığı uzatılacak. Düzeltme yapıldığında bu bölüm kaldırılacak ve metnin sürümü yükseltilecektir. Düzeltilene kadar bu gerçeği saklamak yerine size söylemeyi seçtik.


4. Cihazınızda ne saklıyoruz — tam anahtar listesi

Aşağıdaki tablolar cihazınızda tuttuğumuz her kalemi gösteriyor. Her grubun hukuki dayanağı §2.1'de.

"Uygulama silinince gider mi?" sütununda platform farkı önemli: Android'de şifreli depolama uygulamayla birlikte silinir; iOS'ta Keychain kayıtları uygulamayı silseniz bile cihazda kalır. Bu fark aşağıdaki oturum jetonları için geçerlidir. Cihaz numarası (device_fingerprint) bu gruptan çıkarıldı ve artık uygulamayla birlikte siliniyor — gerekçesi tablonun altındaki notta.

4.1 Şifreli depolama (flutter_secure_storage)

anahtarne tutuyorneredeuygulama silinince gider mihesap silmede temizlenir mi
auth_jwt_tokenOturum jetonunuz (7 gün geçerli)Android Keystore · iOS KeychainAndroid: gider · iOS: kalırEvet
auth_refresh_tokenOturumu sessizce yenileme jetonu (30 gün)Android Keystore · iOS KeychainAndroid: gider · iOS: kalırEvet
auth_emailSon giriş yaptığınız e-posta adresi (doğrulama ekranı için)Android Keystore · iOS KeychainAndroid: gider · iOS: kalırEvet
auth_email_verifiedE-postanızın doğrulanıp doğrulanmadığı (1/0)Android Keystore · iOS KeychainAndroid: gider · iOS: kalırEvet
sync_meta_user_stats_v1Son başarılı senkronizasyonun anlık görüntüsü: XP, doğru/yanlış sayısı, seri, rozet listesi, günlük aktivite günlüğü, zaman damgası. Gereksiz gönderim yapmamak içinAndroid Keystore · iOS KeychainAndroid: gider · iOS: kalırEvet

Cihaz numarası hakkında düzeltme (2026-08-12): device_fingerprint eskiden şifreli depoda tutuluyordu ve iOS'ta Keychain kayıtları uygulama silinse bile kaldığı için bu numara cihaz ömürlüydü — uygulamayı silip yeniden kuran kullanıcı yine tanınıyordu. Bu düzeltildi: numara artık normal uygulama verisinde (shared_preferences, §4.2) tutuluyor, yani uygulamayı kaldırınca her iki platformda da silinir ve cihazda kalmış eski Keychain kaydı da temizlenir. Bedelini biliyoruz — uygulamayı silip yeniden kuran biri bizim için yeni bir cihaz gibi görünür, yani kötüye kullanım sinyali zayıfladı — ve bu bedeli sizin lehinize kabul ettik.

4.2 Ayar ve bayrak depolaması (shared_preferences)

Bu grubun tamamı uygulamayı kaldırınca her iki platformda da silinir ve hiçbiri hesap silmede temizlenmez.

anahtarne tutuyorneredeuygulama silinince gider mihesap silmede temizlenir mi
device_fingerprintRastgele üretilmiş cihaz numarası (UUID). Kötüye kullanım sinyali: davet kodu cihaz sınırı, çoklu-hesap uyarısı, yasaklama yayılımı. 2026-08-12'de şifreli depodan buraya taşındı (§4.1 notu)Android XML · iOS NSUserDefaultsEvetHayır
install_idRastgele üretilmiş kurulum numarası (UUID). "Aynı cihaz, farklı kurulum" ayrımı için; kayıt ve girişte sunucuya giderAndroid XML · iOS NSUserDefaultsEvetHayır
anagram_max_levelAnagram oyunu en yüksek seviyenizaynıEvetHayır
blitz_high_scoreBlitz oyunu rekorunuzaynıEvetHayır
fake_word_high_scoreSahte Kelime oyunu rekorunuzaynıEvetHayır
hangman_best_scoreAdam Asmaca en iyi puanınızaynıEvetHayır
listen_find_high_scoreDinle-Bul oyunu rekorunuzaynıEvetHayır
matching_max_levelEşleştirme oyunu en yüksek seviyenizaynıEvetHayır
memory_max_levelHafıza oyunu en yüksek seviyenizaynıEvetHayır
missing_letters_bestEksik Harfler en iyi sonucunuzaynıEvetHayır
odd_one_out_bestFarklı Olan en iyi sonucunuzaynıEvetHayır
wordle_best_scoreWordle en iyi puanınızaynıEvetHayır
word_rain_high_scoreKelime Yağmuru rekorunuzaynıEvetHayır
word_search_best_timeKelime Avı en iyi sürenizaynıEvetHayır
seenTour_<ekranId>Her ekranın tanıtım turunu bir kez göstermek için "görüldü" bayrağıaynıEvetHayır — ama Ayarlar > Turları sıfırla ile silebilirsiniz
goldCatCelebrated_<kategoriId>Altın kategori kutlamasını tekrar oynatmamak için bayrakaynıEvetHayır
albumSealed_<kategoriId>Mühürlenmiş albüm sayfasını tekrar mühürletmemek için bayrakaynıEvetHayır
weeklyReportBannerSeenWeekHaftalık karne banner'ının gösterildiği haftanın Pazartesi tarihiaynıEvetHayır
seasonWrappedSeenSeasonIdSezon özeti banner'ının gösterildiği sezon numarasıaynıEvetHayır
petLastStageIndexPet'in son kutlanan evrim aşaması (pet'in kendisi sunucuda)aynıEvetHayır
ya5BackfillDoneGeçmiş öğrenme verinizin sunucuya bir kez aktarıldığı bayrağı. Cihaz başına, kullanıcı başına değil — hesap değişse de kalıraynıEvetHayır
daily_word_streak · daily_word_count · daily_word_title · daily_word_target · daily_word_source · daily_word_emojiAna ekran widget'ının gösterdiği veriler. Kelime cevaplanana kadar gizli tutulur, seri sayısı her zaman yazılır. Widget'ı kaldırsanız bile veri kalırAndroid SharedPreferences · iOS group.com.worvento.app App Group kabıEvetHayır

Reklam tercihi ekranı devreye alındığında bu listeye tercihinizin kaydı da eklenecektir (kapsam, zaman damgası, metin sürümü). Bugün bu anahtarlar cihazınızda yok, çünkü onay ekranı henüz yok.

4.3 Yerel veritabanı (hive)

Hive kutuları uygulamanın veri dizininde tutulur ve şifresizdir — cihazın kendi uygulama izolasyonuna güvenilir. Hepsi uygulamayı kaldırınca silinir.

kutune tutuyoruygulama silinince gider mihesap silmede temizlenir mi
user_stats (stats anahtarı)60'tan fazla alanlı istatistik nesnesi: XP, seri, rozetler, dil tercihi, tema, günlük XP hedefi, ses ve titreşim ayarı, TTS ayarı, görülen kelime kimlikleri, mükemmel kategoriler, günlük aktivite günlüğü, öğle arası / hafta sonu / sessiz test sayaçlarıEvetEvet
wordsKelime havuzu ve sizin kendi eklediğiniz kelimeler (MyList) — kaynak kelime, hedef kelime, tür, zorluk, doğru/yanlış sayaçlarıEvetHayır
categoriesKategori adı, seviyesi ve kilit eşiğiEvetHayır
shared_list_cacheBaşkasının sizinle paylaştığı listenin çevrimdışı aynası: kelimeler ve sayfa imleci. Kodda süre sınırı ya da temizlik işi yokEvetHayır

4.4 Dosyalar

dosyane tutuyorneredeuygulama silinince gider mihesap silmede temizlenir mi
wordmaster_share.pngEn son ürettiğiniz paylaşım kartının görüntüsü (skor, XP, seri, davet kodu; düelloda rakibin kullanıcı adı). Sabit adla yazılır ve paylaşımdan sonra silinmezGeçici dizinEvetHayır
Kırpma geçici dosyasıProfil fotoğrafını yüklemeden önceki kırpılmış hâliGeçici dizinEvetHayır
my_words_export.csvCSV dışa aktarmada üretilen kelime listeniz (kaynak kelime, hedef kelime, tür, kategori). Bu dizin uygulamaya özeldir; dosya yöneticisinden göremezsinizUygulamanın Belgeler diziniEvetHayır

4.5 Hesap silmenin cihaz üzerindeki gerçeği

Hesabınızı sildiğinizde cihazda yalnız şunlar temizleniyor: dört oturum anahtarı (auth_jwt_token, auth_refresh_token, auth_email, auth_email_verified), sync_meta_user_stats_v1 ve user_stats Hive kutusu.

Cihazda kalanlar: device_fingerprint (iOS'ta uygulamayı silseniz bile), install_id, words (kendi eklediğiniz kelimeler), categories, shared_list_cache, 12 mini-oyun rekoru, tüm tur/kutlama/banner bayrakları, ya5BackfillDone, ana ekran widget'ı verisi ve §4.4'teki dosyalar.

Bunu düzeltmek düzeltme kaydımızdaki en yüksek öncelikli kalemlerden biri. Sunucu tarafında hesap silmenin neyi silip neyi silmediğini ayrı bir metinde madde madde yazdık: Veri Silme.


5. Tanımlayıcılar

tanımlayıcınekim okuyorsıfırlanabilir mine için kullanılıyor
Reklam kimliği (Android'de GAID/AAID, iOS'ta IDFA)İşletim sisteminin reklamcılık için verdiği, sizin sıfırlayabildiğiniz numaraUygulama kodu bu numarayı okumuyor. Google'ın reklam kütüphanesi kendisi okuyor. Android'de com.google.android.gms.permission.AD_ID iznini bu kütüphane ekliyorEvet. Android: Ayarlar > Google > Tüm hizmetler > Reklamlar. iOS: Ayarlar > Gizlilik ve Güvenlik > İzleme (izin vermezseniz IDFA tamamen sıfırlardan oluşur)Ödüllü reklam gösterimi, reklam ilişkilendirmesi, ölçüm — yalnız onayınızla
Cihaz parmak izi (device_fingerprint)Bizim ürettiğimiz rastgele UUID. Donanımdan hiçbir bilgi okunmuyor: IMEI, seri numarası, MAC adresi, Android ID, cihaz modeli — hiçbiriYalnız kendi sunucumuzEvet. Uygulamayı kaldırmak ya da uygulama verisini silmek numarayı sıfırlar — iOS ve Android'de aynıDavet kodu cihaz sınırı, çoklu-hesap uyarı kaydı, yasaklama yayılımı. Reklamla ilgisi yok, üçüncü tarafa gitmiyor
Kurulum kimliği (install_id)Bizim ürettiğimiz rastgele UUIDYalnız kendi sunucumuzEvet — uygulamayı kaldırıp yeniden kurmak ya da uygulama verisini silmek yeniler"Aynı cihaz, farklı kurulum" ayrımı. Reklamla ilgisi yok
Sunucu hesap kimliğiniz (userId)Sunucudaki hesap satırınızın numarasıKendi sunucumuz ve ödüllü reklam doğrulamasında GoogleHayır — hesabınız ömrü boyunca sabitHesap işlemleri. ⚠️ Ödüllü reklam doğrulamasında bu numara düz metin olarak Google'a gidiyor (bkz. §3.1)

Neden donanım kimliği kullanmıyoruz. Cihaz modeli ve işletim sistemi bilgisinden üretilecek bir imza aynı telefonu kullanan binlerce kişide çakışır; IMEI gibi gerçek donanım kimlikleri ise ek izin ister. Rastgele üretilip cihazda saklanan bir numara hem daha isabetli hem gizlilik açısından temiz. device_info_plus benzeri bir paket uygulamada yok; parmak izi çıkarma tekniklerinin (canvas, yazı tipi, WebGL) hiçbiri kullanılmıyor; kurulu uygulama listeniz sorgulanmıyor (QUERY_ALL_PACKAGES izni yok); panonuz okunmuyor (yalnız davet kodunu panoya yazıyoruz).


6. Reklam ve onay

6.1 Neden onay şart

Reklam kimliğine erişmek ve reklam kütüphanesinin cihazınıza yazmasına izin vermek için açık rızanız gerekiyor. Bunun iki ayrı sebebi var ve ikisi de bağımsız olarak zorunlu:

Dayanak, Kişisel Verileri Koruma Kurumu'nun Çerez Uygulamaları Hakkında Rehberi ve Kurul'un 10.03.2022 tarihli 2022/229 sayılı kararıdır: reklam ve pazarlama amaçlı takip teknolojileri açık rızaya tabidir, burada meşru menfaat kullanılamaz.

Bir not: Google, Avrupa Ekonomik Alanı ve Birleşik Krallık trafiğinde sertifikalı bir onay yönetim platformu (CMP) zorunlu tutuyor. Worvento bu bölgelerde dağıtılmadığı için o zorunluluk bizde devreye girmiyor; buna karşılık kişiselleştirme için rıza almak KVKK bakımından yine gereklidir ve uygulama içi bir tercih anahtarıyla sağlanacaktır.

6.2 Kişiselleştirilmiş ve kişiselleştirilmemiş reklam farkı

kişiselleştirilmişkişiselleştirilmemiş
Reklam neye göre seçilirReklam kimliğinize bağlı ilgi profilinize göreYalnız bağlama göre (uygulamanın türü, dil, ülke)
Reklam kimliği okunur muEvetHayır (iOS'ta IDFA istenmez)
Apple'ın "izleme" tanımına girer miEvet — Google, bu uygulamadan topladığı cihaz verisini başka geliştiricilerin uygulamalarından topladığı veriyle birleştirirHayır
Onay gerekir miEvet — açık rızaHayır — hizmetin finansmanı bakımından meşru menfaat (bkz. §3.1 uyarısı)
Ödülünüzü etkiler mi—Hayır. Onay vermezseniz de ödül hakkınız aynı kalır; uygulama tam çalışmaya devam eder

Bu son satır bir taahhüt: onay vermemeniz ya da onayı geri almanız hiçbir özelliğinizi kapatmaz, ödül hakkınızı kısmaz, uygulamayı kullanmanızı engellemez.

6.3 Onay nasıl alınacak, nasıl geri alınacak

Onay ekranı devreye girdiğinde şu kurallar geçerli olacak:

arkasına gizlemek karanlık desen sayılır ve yapılmayacaktır.

Uygulamanın menüsünde kalıcı bir "Reklam ve gizlilik tercihleri" girişi bulunur.

rızanın alındığının ispatı veri sorumlusuna aittir.

Aynı kapsamdaki rıza kalemlerinin metni ayrı bir belgede: Açık Rıza Metni. Kişisel Verileri Koruma Kurulu'nun 18.02.2026 tarihli 2026/347 sayılı ilke kararı gereği aydınlatma ile açık rıza ayrı belgelerdir ve tek bir onayla sunulamaz.

6.4 iOS'ta ATT'nin rolü ve sırası

Apple'ın App Tracking Transparency (ATT) izni, KVKK rızasından ayrı ve ek bir katmandır: Apple'ın kendi platform kuralıdır ve dağıtım bölgesinden bağımsız olarak geçerlidir. Önerilen sıra:

  1. Uygulama içi reklam tercihi durumunu oku.
  2. Google'ın IDFA açıklama mesajını göster (ATT'nin neden istendiğini anlatır).
  3. ATT izin diyaloğunu göster (requestTrackingAuthorization). Bu diyalog cihazda

yalnız bir kez çıkar.

  1. Reklam kütüphanesini başlat ve ilk reklamı yükle.

ATT izni vermezseniz IDFA tamamen sıfırlardan oluşur ve kişiselleştirilmiş reklam gösterilemez. Kaynak: <https://developers.google.com/admob/flutter/privacy/idfa>

iOS için dürüst durum: Worvento App Store'a hiç yüklenmedi. iOS'ta bugün ATT izni istenmiyor: kodda requestTrackingAuthorization çağrısı yok. Info.plist dosyasında izin metni ve 46 SKAdNetwork kimliği tanımlı olsa da izin akışı olmadığı için diyalog hiç çıkmaz. iOS sürümü yayınlandığında bu bölüm ya ATT akışıyla ya da reklamın iOS'ta tamamen kapatılmasıyla güncellenecektir.

6.5 Yaş ve reklam

Worvento 16 yaş ve üzeri için. Reklam tarafında bunun iki sonucu var:

işareti gönderilir ya reklam tamamen kapatılır.

16+ bir kitleye uygun olmayan reklam gösterilmesi engellenir.


7. Analitik ve çökme raporu: bizde yok

Worvento'da hiçbir analitik ya da çökme raporlama kütüphanesi bulunmuyor. Bu üç yolla doğrulandı: pubspec.yaml satır satır okundu, çözümlenmiş 170 paketin tamamı listelendi ve uygulama kodunun tamamı büyük/küçük harf duyarsız olarak tarandı.

Bulunmayanlar: Firebase (Analytics, Crashlytics, Messaging), Sentry, Amplitude, Mixpanel, AppsFlyer, Adjust, Facebook App Events, PostHog, Datadog, Bugsnag, OneSignal, Segment.

Bunun sizin için anlamı:

bir izleme katmanı yok.

hiçbir yere gönderilmiyor.

şirketine satmıyoruz — çünkü o veriyi hiç toplamıyoruz.

Uygulamanın kullanım verisi beyanı "ürün etkileşimi → uygulama işlevselliği" olarak yapılır.

Bildirimler. Uygulama iki bildirim mekanizması kullanır ve ikisi de Ayarlar → Bildirimler'den ayrı ayrı kapatılabilir:

Cihaza ait bir bildirim jetonu üretilir ve sunucumuzda saklanır (hesap silinince silinir, çıkışta kaldırılır). Jeton bir cihaz kaydıdır, reklam kimliği değildir; izleme veya profil oluşturma amacıyla kullanılmaz ve reklam ağlarıyla paylaşılmaz.

yapılır, hiçbir veri sunucuya gitmez ve üçüncü taraf devrede değildir.

Android'de POST_NOTIFICATIONS izni istenir (Android 13+); reddedilirse uygulama normal çalışır. Ayrıca canlı maç/düello olayları uygulama açıkken SignalR WebSocket bağlantısıyla geliyor (§3.2), ana ekran widget'ı ise verisini cihazda güncelliyor (§4.2).

Dürüst sınır — bunu da saklamıyoruz. Google'ın reklam kütüphanesi kendi hesabına teşhis bilgisi ve reklam etkileşimi verisi topluyor ve bunu Google'a gönderiyor. Bu bizim analitik katmanımız değil; verisine erişimimiz de yok. Ama teknik olarak cihazınızdan çıkan bir telemetri akışıdır ve reklam onayı verildiğinde devreye girer. Reklam kapalıyken bu akış da olmaz.

Bir gün kendi hata raporlamamızı eklersek bu metni, gizlilik politikasını ve mağaza formlarını aynı anda güncelleyeceğiz.


8. Önbellek

Uygulama içi önbellek (dio_cache_interceptor). Sunucu yanıtlarını yalnız RAM'de tutuyoruz (MemCacheStore); hiçbir yanıt diske yazılmıyor. Uygulamayı kapattığınızda önbellek kayboluyor.

Politika CachePolicy.request: yalnız sunucunun Cache-Control başlığı gönderdiği uçlar önbelleklenir. Bugün bunlar yalnız katalog uçları (hediye listesi, çark listesi; max-age=300, yani 5 dakika). En uzun bekletme süresi 1 saat.

Önbelleklenmeyenler — kodla doğrulandı: liderlik tablosu, lig, profil ve arkadaş listesi Cache-Control başlığı göndermediği için her seferinde ağdan taze geliyor. Yani başkalarının kullanıcı adı ve istatistikleri cihazınızda önbelleğe düşmüyor.

Profil fotoğrafı dağıtım önbelleği (Cloudflare R2). Profil fotoğrafları Cloudflare R2 nesne depolamasında tutuluyor. Cloudflare, Inc. (ABD) — küresel altyapı; profil fotoğrafları belirli bir ülkeye sabitlenmemiştir. Aktarımda ve saklamada şifrelenir. Fotoğraflar 1 yıl süreyle immutable olarak önbelleklenmesi talimatıyla sunuluyor (public,max-age=31536000,immutable). Bunun dürüst sonucu: fotoğrafınızı sildikten sonra bir kopyası bir süre daha dağıtım ağı önbelleğinde ya da tarayıcı önbelleğinde yaşamaya devam edebilir. Silme talebiniz kaynaktaki nesneyi hedefler; önbellek kopyalarının süresi kendi başına dolar.


9. Tercihlerinizi nasıl yönetirsiniz

9.1 Uygulama içinden

ne yapmak istiyorsunuznereden
Reklam ve gizlilik tercihlerinizi değiştirmekAyarlar > Reklam ve gizlilik tercihleri — ⚠️ Bu giriş bugün uygulamada YOK. Onay ekranıyla birlikte eklenecek. Bugün için reklamlar onay ekranı devreye girene kadar gösterilmiyor
Sesi, titreşimi, telaffuzu, temayı kapatmakAyarlar
Tanıtım turu bayraklarını silmekAyarlar > Turları sıfırla
Profil fotoğrafınızı kaldırmakProfil ekranı — fotoğrafı kaldırma işlemi sunucudaki nesneleri de siler
Kelime listenizi CSV olarak almakAyarlar > CSV Dışa Aktar — ⚠️ dürüst uyarı: üretilen dosya uygulamanın kendi Belgeler dizinine yazılıyor; oradan dosya yöneticisiyle erişemezsiniz. Dosyayı size ulaştırmak düzeltme kaydımızda bir iş kalemi
Hesabınızı silmekAyarlar > Hesabı sil — iki adımlı: şifre teyidi, sonra e-posta ile gelen kod. Neyin silindiğini ve neyin silinmediğini Veri Silme metninde madde madde yazdık
Yasal metinleri okumakAyarlar > Yasal — ⚠️ bu bağlantı bugün yayında olmayan bir adrese gidiyor; gerçek yasal sayfalar https://worvento.com/legal/ altındadır. Düzeltme kaydımızda bir iş kalemi

9.2 Cihaz ayarlarından reklam kimliğinizi sıfırlamak

Reklam kimliği işletim sisteminin verdiği bir numaradır; uygulamadan bağımsız olarak siz yönetirsiniz.

Android

kaldırır; bu andan sonra uygulamalar kimlik yerine sıfır dizisi görür.

Reklam Kimliği politikası, silinen ya da sıfırlanan kimliğin eski kimlikten türeyen veriyle ilişkilendirilmesini yasaklıyor.

iOS

İzin Ver" seçeneğini kapatırsanız hiçbir uygulama izin bile isteyemez ve IDFA sıfırlardan oluşur.

reklamlarını kapatır.

9.3 Cihazda kalan verileri silmek

Uygulamayı kaldırmak Hive kutularını, shared_preferences içeriğini ve geçici dosyaları her iki platformda da siler. Ama iOS'ta Keychain kayıtları kalır (§4.1); iOS'ta device_fingerprint gibi anahtarları güvenilir şekilde silmenin tek yolu cihazı sıfırlamaktır. Android'de Ayarlar > Uygulamalar > Worvento > Depolama > Verileri temizle şifreli depoyu da temizler.


10. İşletim sistemi izinleri

Uygulama, izin diyaloğu çıkarmayı gerektiren hiçbir hassas izin istemiyor. Kamera, galeri, mikrofon, konum, rehber, takvim, SMS ve bildirim izinlerinin hiçbiri yayın paketinde yok. Bunun pratik sonucu: uygulama size hiçbir çalışma-anı izin sorusu sormuyor; sormadığı için de izin vermemeniz hâlinde kapanan bir özellik yok.

Yayın paketinde bulunan izinlerin tamamı ve neden bulundukları:

izinkim istiyorne için
INTERNETuygulamaSunucuyla iletişim. Uygulama çevrimiçi çalışır
ACCESS_NETWORK_STATEuygulamaBağlantı durumunu okumak
com.android.vending.BILLINGin_app_purchaseUygulama içi satın alma
com.google.android.gms.permission.AD_IDreklam kütüphanesi ekliyorReklam kimliğine erişim. Yalnız onayınızla kullanılır
ACCESS_ADSERVICES_AD_ID · ACCESS_ADSERVICES_ATTRIBUTION · ACCESS_ADSERVICES_TOPICSreklam kütüphanesi ekliyorAndroid Privacy Sandbox reklam ölçümü
WAKE_LOCK · FOREGROUND_SERVICEreklam kütüphanesi ekliyorVideo reklam oynatımı sırasında ekranın kapanmaması
DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSIONAndroid kütüphaneleriYayın alıcılarının uygulama dışına açılmaması (güvenlik önlemi)

Profil fotoğrafı seçerken image_picker, Android Foto Seçici ya da kamera niyetini kullanıyor; bu, izin gerektirmeyen yoldur ve galerinin tamamına erişim vermez. CSV içe aktarmada file_picker sistem dosya seçicisini kullanıyor; geniş depolama izni istenmiyor. Yalnız sizin tek tek seçtiğiniz dosyayı görüyoruz.

Toplamadığımız veriler. Şunların hiçbirini toplamıyoruz: GPS ya da ağ tabanlı konum, rehberiniz, telefon numaranız, sağlık ve fitness verisi, mikrofon kaydı, takvim, SMS ve çağrı kaydı, biyometrik veri, kurulu uygulama listeniz, analitik ve çökme raporu, push bildirim jetonu, Google/Apple/Facebook ile giriş. Tek dürüst istisna: günlük limitlerin sizin yerel gece yarınızda sıfırlanması için saat dilimi kaymanızı (dakika olarak) sunucuya gönderiyoruz. Bu GPS konumu değil, ama kaba bir coğrafi çıkarıma imkân verir; bunu "konum toplamıyoruz" derken saklamamayı seçtik.


11. Bu metin değiştiğinde

Yeni bir SDK eklediğimizde, cihazda sakladığımız bir kalem değiştiğinde ya da reklam onayının işleyişi değiştiğinde bu metni güncelleyip yukarıdaki sürüm ve son güncelleme tarihini değiştiriyoruz. Aydınlatma Tebliği'nin 5/1-b maddesi, işleme amacı değiştiğinde işlemeden önce yeniden aydınlatma yapılmasını emrediyor; bu yüzden yeni bir veri akışı devreye girmeden önce metin güncellenir.


12. İlgili metinler ve iletişim

Veri sorumlusu: Worvento yayıncısı (Türkiye) · worvento.info@gmail.com Veri koruma başvuruları ve destek: worvento.info@gmail.com Yayındaki adres: https://worvento.com/legal/izleme-teknolojileri

Üçüncü tarafların kendi gizlilik metinleri: Google (reklam ortakları) <https://policies.google.com/technologies/partner-sites> · Google (genel) <https://policies.google.com/privacy> · Cloudflare <https://www.cloudflare.com/privacypolicy/> · Hetzner <https://www.hetzner.com/legal/privacy> · Apple <https://www.apple.com/legal/privacy>

English

Version: 1.0 · Effective: 8 August 2026 · Last updated: 8 August 2026

This is an information-only English translation. In case of any conflict, the Turkish original prevails. Turkish original: cerez-ve-sdk-politikasi.md

Data controller: the Türkiye-based publisher of Worvento (natural person) · worvento.info@gmail.com App: Worvento (com.worvento.app) · Server: https://api.worvento.com


Short summary — at a glance

Full detail follows. If you are in a hurry, this table is enough:

questionshort answer
Do you use cookies?No — there is no browser in the app. But three things fall under the same rule: SDKs, on-device storage, identifiers.
Do you sell my personal data?No. We do not sell your personal data. We share limited data with a limited number of recipients to run the service (§3, §12).
Is there analytics tracking me?No. There is no analytics or crash-reporting library at all (§7).
What is the only thing that needs consent?Advertising and the advertising identifier (§2-B, §6). Everything else is strictly necessary to run the service.
Is there a consent screen today?There is no separate ad-consent screen because personalised advertising is never used; every ad request is non-personalised (npa=1) (§3.1, §6). You manage your consent status under "Settings > Privacy and Permissions".
What is the most uncomfortable fact?The connectivity check used to send your IP address to four hosts we do not own; that has been fixed — the check now goes only to our own server (§3.3).
What stays on my device if I delete my account?Some of it stays, but the device number is no longer among it — it is deleted with the app. Full list in §4.5.
How do I reset my advertising ID?From your device settings, independently of the app (§9.2).

1. What this document covers — and why it is not called "cookies"

Worvento is a mobile app. There is no browser inside the app, so we do not use cookies in the classic sense. But three things do the same job:

  1. SDKs — ready-made pieces of code written by others and embedded in the app (for

example the Google library that shows ads).

  1. On-device storage — files, keys and encrypted records we keep inside your phone.
  2. Identifiers — numbers that distinguish you or your device (advertising identifier,

randomly generated device number).

The law treats all three the same way as cookies. The Turkish Data Protection Authority's Guidelines on Cookie Practices (final version 20 June 2022) and Board decision no. 2022/229 of 10 March 2022 make tracking technologies used for advertising and marketing subject to explicit consent, regardless of technical form; only those strictly necessary to provide the service do not require consent. The Authority's Guidelines on Privacy in Mobile Applications (December 2023) applies the same framework to mobile apps.

In short: it is not called a cookie, but the cookie rules apply. That is why this document shows you, one by one, what we keep on your device, which ready-made code libraries we use, what data each touches, and which of them depend on your consent.

Sources: Turkish DPA Board decision 2022/229 (10.03.2022) · Guidelines on Cookie Practices (20.06.2022) · Guidelines on Privacy in Mobile Applications (December 2023) — <https://www.kvkk.gov.tr>


2. Two categories: strictly necessary, and advertising

Everything we do on your device falls into one of two groups. This distinction is legally decisive, because consent is required only for the second group.

A · STRICTLY NECESSARY / FUNCTIONAL — no consent required Without these the app cannot do what you asked it to do: keep your session open, store the words you learn, remember your theme and sound preference, warn you when your internet drops. The Cookie Guidelines' exemption for what is "strictly necessary to provide the service" covers these; the legal ground is performance of a contract (KVKK art.5/2-c) or legitimate interest (KVKK art.5/2-f).

B · ADVERTISING — subject to explicit consent The Google library that shows rewarded ads, and the advertising identifier. Legitimate interest cannot be used for the personalisation of ads: Board decision 2022/229 subjects advertising and marketing tracking technologies to explicit consent, and access to an advertising identifier can never be read as "strictly necessary to provide the service."

If you do not consent, advertising is not switched off — it is only not personalised, and you do not lose your reward entitlement (see §6).

group stored on devicegroundreasoning
Session tokens (auth_jwt_token, auth_refresh_token, auth_email, auth_email_verified)Strictly necessary — no consent requiredYou asked to sign in; a session cannot be maintained without a token. KVKK art.5/2-c
Learning and settings data (Hive user_stats, words, categories, shared_list_cache)Strictly necessary — no consent requiredThe app's core function is teaching words; the service does not work if your progress is not stored. KVKK art.5/2-c
Game high scores and tour/celebration/banner flagsStrictly necessary — no consent requiredInterface state that stays on the device only; it does not leave and has nothing to do with advertising
Sync snapshot (sync_meta_user_stats_v1)Strictly necessary — no consent requiredPrevents sending the same data over and over; it serves data minimisation
Device fingerprint (device_fingerprint) and installation id (install_id)Strict necessity claim + legitimate interest (KVKK art.5/2-f) — ⚠️ see note belowPreventing abuse, multi-accounting and referral-code exploitation
Home screen widget dataStrictly necessary — no consent requiredYou added the widget yourself; without data it stays empty
The advertising identifier and the personalisation of adsEXPLICIT CONSENT (KVKK art.5/1)Personalisation can never be read as strictly necessary to provide the service

3. The SDKs and packages we use — full list

The table below contains every dependency in the app's pubspec.yaml plus one package pulled in indirectly by the advertising library. Version numbers are those declared in pubspec.yaml.

Legal ground abbreviations

abbreviationmeaning
CONTRACTPerformance of a contract — KVKK art.5/2-c
LEGITLegitimate interest — KVKK art.5/2-f
CONSENTExplicit consent — KVKK art.5/1
LEGAL-OBLLegal obligation — KVKK art.5/2-ç
NEC"Strictly necessary to provide the service" → no consent required
CONSENTPersonalisation of advertising → explicit consent required
SDK / packagewhat it doeswhat data it touchesdoes it leave the devicelegal groundlink
google_mobile_ads ^5.2.0 (Google Mobile Ads / AdMob)Shows rewarded video ads. If you watch one, our server grants the reward.Advertising identifier (GAID on Android, IDFA on iOS), your IP address, device and OS information, screen information, the app's package name, your interaction with the ad. Google also collects its own diagnostic and product-interaction data.Yes — to Google. Google is an independent controller for this data; it is not our processor and also processes the data for its own purposes.CONSENT + CONSENT<https://policies.google.com/technologies/partner-sites>
Reward verification (SSV) — a feature of the SDK aboveThe server, not the client, grants the reward; Google reports the reward directly to our server.Your server account id (userId) in plain text plus the reward type is sent to Google.Yes — to Google. This id is not a pseudonym; it maps directly to your account.LEGITIMATE INTEREST<https://policies.google.com/technologies/partner-sites> — this item is independent of advertising-personalisation consent; it happens regardless of your consent state whenever you watch a rewarded ad

Current state of the code — an honest statement. The app has no advertising preference screen yet. The rule this policy sets is: until that screen ships, rewarded ads are served without personalisation — that is, "I do not allow personalisation" is today's default state. When the screen ships, this document will be updated and its effective date will change.

SDK / packagewhat it doeswhat data it touchesdoes it leave the devicelegal groundlink
in_app_purchase ^3.2.0 (+ in_app_purchase_android, in_app_purchase_storekit)In-app purchases. The store takes the payment; we only pass the receipt to our server and grant the entitlement.Product id, store transaction id, receipt string. The app never sees your payment card details.Yes. On Android to Google Commerce Limited, on iOS to Apple Distribution International Ltd. Both are independent controllers and act as seller/agent on the store side. The receipt also goes to our own server.CONTRACT + LEGAL-OBL for financial records<https://policies.google.com/privacy> · <https://www.apple.com/legal/privacy>
flutter_secure_storage ^9.2.2Stores your session tokens and device number encrypted. Uses Keystore/EncryptedSharedPreferences on Android and the Keychain on iOS.Session token, refresh token, your last sign-in email, verification flag, device fingerprint, sync snapshot (see §4).The stored tokens go to our server with every request. The storage itself stays on the device.CONTRACT + NEC (session continuity)—
shared_preferences ^2.3.2Simple settings and flag storage. XML on Android, NSUserDefaults on iOS.Installation id, 12 mini-game high scores, tour / celebration / banner flags (see §4).The installation id goes to the server on sign-up and sign-in; the rest stays on the device.CONTRACT · LEGIT + NEC for the installation id—
hive ^2.2.3 + hive_flutter ^1.1.0On-device local database. Lets you study your own word list when you have no internet.The word pool and the words you added, category locks, a statistics object with more than 60 fields, the shared-list mirror. Stored unencrypted (relying on the device's own app isolation).Part of it goes to the server on sync (XP, streak, badges, daily activity log).CONTRACT + NEC—
dio ^5.7.0HTTPS communication with our server.Every request you send and every response received.Yes — only to api.worvento.com.CONTRACT—
dio_cache_interceptor ^4.0.6Keeps responses from endpoints the server allows in memory for a short time (see §8).Catalogue responses (gift list, spin wheel list).No — RAM only.CONTRACT + NEC—
internet_connection_checker_plus ^2.5.2 (resolved version 2.9.1+2)Tests whether your internet actually works (captive portal, hotspot without internet). ⚠️ See §3.3.Your IP address, User-Agent information and timestamp.Yes — to 4 hosts we do not own.LEGIT, but the ground is problematic — see §3.3<https://www.cloudflare.com/privacypolicy/>
signalr_netcore ^1.4.0Real-time WebSocket connection for live challenges, duels and hangman. Does not poll.Match state, invitations, usernames. Your session token is carried in the query string — it may appear in reverse-proxy access logs.Yes — only to our own server.CONTRACT—
image_picker ^1.1.2Lets you pick a profile photo. Uses the Android Photo Picker or a camera intent.Only the photo you pick individually. No permission for access to your whole gallery is requested (none of READ_MEDIA_IMAGES, CAMERA, READ_EXTERNAL_STORAGE is present).The raw bytes of the photo you pick are uploaded with a signed URL directly to Cloudflare R2 object storage. Cloudflare, Inc. (USA) — global infrastructure; profile photos are not pinned to a specific country. They are encrypted in transit and at rest.CONSENT (the photo is optional)<https://www.cloudflare.com/privacypolicy/>
crop_your_image ^2.0.0Crops the photo with a circular mask before upload. Pure Dart; no network access.The bytes of the cropped image (in the temporary directory).No.CONSENT—
file_picker ^8.1.7Lets you pick a file for CSV import. Uses the system picker.Only the file you pick. No broad storage permission.No.CONTRACT—
share_plus ^10.1.4Lets you share result cards, your referral code and your weekly report.The share card image (score, XP, streak, category name, referral code) and the caption text. On a duel card your opponent's username is also embedded in the image.Yes — to the app you choose (WhatsApp, Instagram, email…). That app is an independent controller.CONTRACT (you initiate the share)—
flutter_tts ^4.2.0Reads out a word's pronunciation. Uses the speech engine installed on your device; we store no audio.The text of the word being spoken and the target language code.It depends. The code assumes the device engine works offline but does not enforce it: there is no engine selection or network-use setting. With an engine that performs cloud synthesis (the default engine on Android may do this for higher-quality voices) the word text goes to the engine provider.CONTRACTDepends on the engine — mostly <https://policies.google.com/privacy> on Android · <https://www.apple.com/legal/privacy> on iOS
home_widget ^0.7.0Feeds the "Word of the Day" home screen widget.Your streak day count, day counter, word title, source/target word, emoji. In SharedPreferences on Android, in the group.com.worvento.app App Group container on iOS. The word stays hidden until answered; the streak count is written on every refresh and there is no setting to turn it off — it may be visible on your lock screen.No — it stays on the device.CONTRACT—
audioplayers ^6.1.0Plays correct/wrong/tap sound effects.Only the assets/sounds/*.wav files inside the app. No microphone permission, no audio recording.No.CONTRACT—
path_provider ^2.1.5Finds the path of the temporary and documents directories.Share image, crop temporary file, CSV export file.No.CONTRACT—
url_launcher ^6.3.1Opens legal pages in your device's own browser (no in-app browser).The address opened.The request to that address is made through your browser; from that point on your browser's own settings apply.CONTRACT—
uuid ^4.5.1Generates random numbers (for the device fingerprint and installation id). Reads no hardware information.The random number it generates.The generated numbers go to the server on sign-up and sign-in.LEGIT + NEC—
csv ^6.0.0Converts your word list to CSV and reads CSV. No network access.Your words.No.CONTRACT—
webview_flutter (indirect — pulled in as a google_mobile_ads dependency)The app does not use this package itself. There is not a single WebViewWidget or WebViewController call in the code; legal pages open in the external browser. The package is installed because the advertising library needs it to render ad content.Only ad content, when the advertising library shows an ad.To the ad network, when an ad is shown.Same as advertising: CONSENT + CONSENT<https://policies.google.com/technologies/partner-sites>

Packages that are interface-only and touch no personal data (for completeness): flutter_riverpod, go_router, easy_localization, flutter_card_swiper, lottie, animate_do, shimmer, fl_chart, flutter_heatmap_calendar, confetti, animations, cupertino_icons. These make no network requests and move no data off the device.

On the server side. The server the app talks to is hosted at Hetzner: Hetzner Online GmbH (Germany) — our server is located in Finland. Verification, password reset and account deletion code emails are sent through Google's Gmail infrastructure. For all server-side data see the Privacy Policy and the KVKK Privacy Notice.

3.3 Connectivity check

The connectivity check goes only to our own server: {apiBaseUrl}/health, roughly every 45 seconds. Nothing goes to any third party.

This section used to read differently, and it has been corrected. Because no target addresses were specified, the internet_connection_checker_plus package used its own defaults; as a result, while the app was in the foreground, roughly every 10 seconds your IP address and User-Agent went to four addresses we do not own (one.one.one.one, icanhazip.com, jsonplaceholder.typicode.com, pokeapi.co). We had no data processing agreement with those parties. Redirecting the check to our own /health endpoint removed all four transfers.


4. What we store on your device — full key list

The tables below show every item we keep on your device. The legal ground for each group is in §2.1.

In the "removed when the app is deleted?" column the platform difference matters: on Android encrypted storage is deleted together with the app; on iOS, Keychain records survive even if you delete the app. That difference applies to the session tokens below. The device number (device_fingerprint) was moved out of this group and is now deleted with the app — see the note under the table.

4.1 Encrypted storage (flutter_secure_storage)

keywhat it holdswhereremoved when the app is deletedcleared on account deletion
auth_jwt_tokenYour session token (valid 7 days)Android Keystore · iOS KeychainAndroid: yes · iOS: noYes
auth_refresh_tokenToken for silently renewing your session (30 days)Android Keystore · iOS KeychainAndroid: yes · iOS: noYes
auth_emailThe email address you last signed in with (for the verification screen)Android Keystore · iOS KeychainAndroid: yes · iOS: noYes
auth_email_verifiedWhether your email is verified (1/0)Android Keystore · iOS KeychainAndroid: yes · iOS: noYes
sync_meta_user_stats_v1Snapshot of the last successful sync: XP, correct/wrong counts, streak, badge list, daily activity log, timestamp. Used to avoid unnecessary uploadsAndroid Keystore · iOS KeychainAndroid: yes · iOS: noYes

Correction about the device number (2026-08-12): device_fingerprint used to live in encrypted storage, and because iOS Keychain records survive app deletion the number was device-lifetime — a user who deleted and reinstalled the app was still recognised. That has been fixed: the number is now kept in ordinary app data (shared_preferences, §4.2), so it is deleted when you uninstall the app on both platforms, and any leftover Keychain record is purged. We know the cost — someone who reinstalls looks like a new device to us, so the abuse signal is weaker — and we accepted that cost in your favour.

4.2 Settings and flag storage (shared_preferences)

This entire group is deleted when you uninstall the app on both platforms and none of it is cleared on account deletion.

When the advertising preference screen ships, a record of your choice will be added to this list (scope, timestamp, text version).

4.3 Local database (hive)

Hive boxes are kept in the app's data directory and are unencrypted — we rely on the device's own app isolation. All of them are deleted when you uninstall the app.

boxwhat it holdsremoved when the app is deletedcleared on account deletion
user_stats (stats key)A statistics object with more than 60 fields: XP, streak, badges, language preference, theme, daily XP goal, sound and haptic settings, TTS setting, seen word ids, perfect categories, daily activity log, lunch-break / weekend / silent-test countersYesYes
wordsThe word pool and the words you added yourself (MyList) — source word, target word, type, difficulty, correct/wrong countersYesNo
categoriesCategory name, level and unlock thresholdYesNo
shared_list_cacheOffline mirror of a list someone shared with you: words and page cursor. There is no expiry or cleanup job in the codeYesNo

4.4 Files

filewhat it holdswhereremoved when the app is deletedcleared on account deletion
wordmaster_share.pngThe image of the last share card you produced (score, XP, streak, referral code; in a duel, your opponent's username). Written under a fixed name and not deleted after sharingTemporary directoryYesNo
Crop temporary fileThe cropped version of your profile photo before uploadTemporary directoryYesNo
my_words_export.csvYour word list produced by CSV export (source word, target word, type, category). This directory is app-private; you cannot see the file from a file managerThe app's Documents directoryYesNo

4.5 The reality of account deletion on your device

When you delete your account, only these are cleared on the device: the four session keys (auth_jwt_token, auth_refresh_token, auth_email, auth_email_verified), sync_meta_user_stats_v1 and the user_stats Hive box.

What remains on the device: device_fingerprint (on iOS even if you delete the app), install_id, words (the words you added), categories, shared_list_cache, 12 mini-game high scores, all tour/celebration/banner flags, ya5BackfillDone, home screen widget data and the files in §4.4.

Fixing this is one of the highest-priority items in our remediation record. What account deletion does and does not delete on the server side is written out item by item in a separate document: Data Deletion.


5. Identifiers

identifierwhat it iswho reads itcan it be resetwhat it is used for
Advertising identifier (GAID/AAID on Android, IDFA on iOS)A number the operating system provides for advertising, which you can resetThe app's code does not read this number. Google's advertising library reads it itself. On Android the com.google.android.gms.permission.AD_ID permission is added by that libraryYes. Android: Settings > Google > All services > Ads. iOS: Settings > Privacy & Security > Tracking (if you refuse permission, the IDFA is all zeros)Rewarded ad delivery, ad attribution, measurement — only with your consent
Device fingerprint (device_fingerprint)A random UUID we generate. No information is read from the hardware: no IMEI, serial number, MAC address, Android ID or device modelOur own server onlyYes. Uninstalling the app or clearing app data resets the number — the same on iOS and AndroidReferral-code device limit, multi-account warning record, ban propagation. Nothing to do with advertising; goes to no third party
Installation id (install_id)A random UUID we generateOur own server onlyYes — reinstalling the app or clearing app data regenerates itDistinguishing "same device, different installation". Nothing to do with advertising
Your server account id (userId)The number of your account row on the serverOur own server and Google, during rewarded ad verificationNo — it stays fixed for the life of your accountAccount operations. ⚠️ During rewarded ad verification this number goes to Google in plain text (see §3.1)

Why we do not use a hardware identifier. A signature derived from device model and operating system information collides across thousands of people using the same phone; real hardware identifiers such as IMEI require extra permissions. A number generated randomly and stored on the device is both more accurate and cleaner for privacy. No package like device_info_plus is present in the app; none of the fingerprinting techniques (canvas, font, WebGL) is used; your installed app list is not queried (no QUERY_ALL_PACKAGES permission); your clipboard is not read (we only write the referral code to it).


Accessing the advertising identifier and letting the advertising library write to your device requires your explicit consent for the personalisation of ads.

The ground is the Turkish Data Protection Authority's Guidelines on Cookie Practices and Board decision no. 2022/229 of 10 March 2022: tracking technologies used for advertising and marketing are subject to explicit consent, and legitimate interest cannot be used there.

One note: Google requires a certified consent management platform (CMP) for traffic from the European Economic Area and the United Kingdom. Worvento is not distributed in those regions, so that requirement does not apply to us; obtaining consent for personalisation is nevertheless required under the KVKK, and will be provided through an in-app preference switch.

6.2 The difference between personalised and non-personalised ads

personalisednon-personalised
How the ad is selectedBy an interest profile tied to your advertising identifierBy context only (app category, language, country)
Is the advertising identifier readYesNo (the IDFA is not requested on iOS)
Does it fall under Apple's "tracking" definitionYes — Google combines device data collected from this app with data collected from other developers' appsNo
Is consent requiredYes — explicit consentNo — legitimate interest in funding the service (see the note in §3.1)
Does it affect your reward—No. Your reward entitlement is the same if you refuse consent; the app keeps working fully

That last row is a commitment: refusing consent or withdrawing it does not disable any of your features, does not reduce your reward entitlement and does not prevent you from using the app.

When the consent screen ships, these rules will apply:

behind a menu counts as a dark pattern and will not be done.

A permanent "Ad and privacy preferences" entry will exist in the app's menu.

burden of proving consent lies with the controller.

The text of the consent items in the same scope lives in a separate document: Explicit Consent Statement. Under principle decision no. 2026/347 of 18 February 2026 of the Turkish Personal Data Protection Board, the privacy notice and the explicit consent statement are separate documents and cannot be presented under a single approval.

6.4 The role of ATT on iOS and the correct order

Apple's App Tracking Transparency (ATT) permission is a separate and additional layer on top of KVKK consent: it is Apple's own platform rule and applies regardless of distribution territory. The recommended order:

  1. Read the in-app advertising preference state.
  2. Show Google's IDFA explainer message (explaining why ATT is being requested).
  3. Show the ATT permission dialog (requestTrackingAuthorization). This dialog appears

only once per device.

  1. Initialise the advertising library and load the first ad.

If you refuse ATT, the IDFA is all zeros and personalised ads cannot be shown. Source: <https://developers.google.com/admob/flutter/privacy/idfa>

The honest position on iOS: Worvento has never been submitted to the App Store. ATT permission is not requested on iOS today: there is no requestTrackingAuthorization call in the code. Although a permission string and 46 SKAdNetwork identifiers are declared in Info.plist, no dialog ever appears because there is no permission flow. When the iOS version is released, this section will be updated either with the ATT flow or with advertising being disabled entirely on iOS.

6.5 Age and advertising

Worvento is for ages 16 and over. This has two consequences on the advertising side:

advertising library, or advertising is switched off entirely.

unsuitable for a 16+ audience are not shown.


7. Analytics and crash reporting: we have none

Worvento contains no analytics or crash reporting library whatsoever. This was verified three ways: pubspec.yaml was read line by line, all 170 resolved packages were listed, and the entire application code was scanned case-insensitively.

Not present: Firebase (Analytics, Crashlytics, Messaging), Sentry, Amplitude, Mixpanel, AppsFlyer, Adjust, Facebook App Events, PostHog, Datadog, Bugsnag, OneSignal, Segment.

What this means for you:

tapped which button, or your session durations.

the crash goes nowhere.

or a measurement company — because we never collect that data.

usage data declaration is made as "product interaction → app functionality."

Notifications. The app uses two notification mechanisms, both of which can be switched off independently under Settings → Notifications:

notifications. A notification token is generated for the device and stored on our server (deleted when the account is deleted, removed on sign-out). The token is a device registration, not an advertising identifier; it is not used for tracking or profiling and is not shared with ad networks.

happens on the device, no data leaves it, and no third party is involved.

On Android the POST_NOTIFICATIONS permission is requested (Android 13+); if it is denied the app works normally. In addition, live match and duel events arrive while the app is open over the SignalR WebSocket connection (§3.2), and the home screen widget updates its data on the device (§4.2).

An honest limit — we are not hiding this either. Google's advertising library collects diagnostic and ad-interaction data on its own account and sends it to Google. That is not our analytics layer, and we have no access to that data. But technically it is a telemetry stream leaving your device, and it starts when advertising consent is given. While advertising is off, so is that stream.

If we ever add our own error reporting, we will update this document, the privacy policy and the store forms at the same time.


8. Caching

In-app cache (dio_cache_interceptor). We keep server responses in RAM only (MemCacheStore); no response is written to disk. The cache disappears when you close the app.

The policy is CachePolicy.request: only endpoints where the server sends a Cache-Control header are cached. Today these are only catalogue endpoints (gift list, spin wheel list; max-age=300, i.e. 5 minutes). The maximum staleness allowed is 1 hour.

What is not cached — verified in code: the leaderboard, the league, profiles and the friend list send no Cache-Control header, so they always come fresh from the network. That means other people's usernames and statistics are not cached on your device.

Profile photo delivery cache (Cloudflare R2). Profile photos are kept in Cloudflare R2 object storage. Cloudflare, Inc. (USA) — global infrastructure; profile photos are not pinned to a specific country. They are encrypted in transit and at rest. Photos are served with an instruction to cache them for 1 year as immutable (public,max-age=31536000,immutable). The honest consequence: after you delete your photo, a copy may keep living for a while in the delivery network cache or a browser cache. Your deletion request targets the object at the origin; cached copies expire on their own.


9. How to manage your preferences

9.1 From inside the app

what you want to dowhere
Change your ad and privacy preferencesSettings > Ad and privacy preferences — ⚠️ This entry does NOT exist in the app today. It will be added together with the consent screen. For now, no ads are shown until the consent screen ships
Turn off sound, haptics, pronunciation or themeSettings
Clear the intro tour flagsSettings > Reset tours
Remove your profile photoProfile screen — removing the photo also deletes the objects on the server
Get your word list as CSVSettings > Export CSV — ⚠️ honest warning: the file is written to the app's own Documents directory and you cannot reach it with a file manager. Delivering the file to you is an open item in our remediation record
Delete your accountSettings > Delete account — two steps: password confirmation, then a code sent by email. What is and is not deleted is written out item by item in Data Deletion
Read the legal documentsSettings > Legal — ⚠️ this link currently points to an address that is not live; the real legal pages are under https://worvento.com/legal/. An open item in our remediation record

9.2 Resetting your advertising identifier from device settings

The advertising identifier is a number provided by the operating system; you manage it independently of the app.

Android

entirely; from that moment apps see a string of zeros instead of an identifier.

Advertising ID policy prohibits linking a deleted or reset identifier with data derived from the previous identifier.

iOS

Track", no app can even ask for permission and the IDFA is all zeros.

advertising.

9.3 Deleting what remains on the device

Uninstalling the app deletes the Hive boxes, the shared_preferences contents and the temporary files on both platforms. But Keychain records survive on iOS (§4.1); on iOS the only reliable way to delete keys such as device_fingerprint is to reset the device. On Android, Settings > Apps > Worvento > Storage > Clear data also clears the encrypted store.


10. Operating system permissions

The app requests no sensitive permission that would produce a permission dialog. None of the camera, gallery, microphone, location, contacts, calendar, SMS or notification permissions is present in the release package. The practical consequence: the app never asks you a runtime permission question, and because it never asks, no feature breaks if you refuse.

All permissions present in the release package, and why they are there:

permissionwho requests itwhat for
INTERNETthe appCommunication with the server. The app works online
ACCESS_NETWORK_STATEthe appReading connectivity state
com.android.vending.BILLINGin_app_purchaseIn-app purchases
com.google.android.gms.permission.AD_IDadded by the advertising libraryAccess to the advertising identifier. Used only with your consent
ACCESS_ADSERVICES_AD_ID · ACCESS_ADSERVICES_ATTRIBUTION · ACCESS_ADSERVICES_TOPICSadded by the advertising libraryAndroid Privacy Sandbox ad measurement
WAKE_LOCK · FOREGROUND_SERVICEadded by the advertising libraryKeeping the screen on during video ad playback
DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSIONAndroid librariesKeeping broadcast receivers from being exposed outside the app (a security measure)

When you pick a profile photo, image_picker uses the Android Photo Picker or a camera intent; this is the permission-free route and does not grant access to your whole gallery. For CSV import, file_picker uses the system file picker; no broad storage permission is requested. We see only the file you pick individually.

Data we do not collect. We collect none of the following: GPS or network-based location, your contacts, your phone number, health and fitness data, microphone recordings, calendar, SMS and call logs, biometric data, your installed app list, analytics and crash reports, push notification tokens, sign-in with Google/Apple/Facebook. The one honest exception: we send your time zone offset (in minutes) to the server so that daily limits reset at your local midnight. That is not GPS location, but it does allow a coarse geographic inference; we chose not to hide it while saying "we do not collect location."


11. When this document changes

When we add a new SDK, when an item we store on your device changes, or when the way advertising consent works changes, we update this document and change the version and last updated date above. Article 5/1-b of the Communiqué on Privacy Notice requires a fresh privacy notice before processing when the purpose of processing changes; that is why the text is updated before a new data flow goes live.


Data controller: the publisher of Worvento (Türkiye) · worvento.info@gmail.com Data protection requests and support: worvento.info@gmail.com Published address: https://worvento.com/legal/izleme-teknolojileri

Third parties' own privacy documents: Google (advertising partners) <https://policies.google.com/technologies/partner-sites> · Google (general) <https://policies.google.com/privacy> · Cloudflare <https://www.cloudflare.com/privacypolicy/> · Hetzner <https://www.hetzner.com/legal/privacy> · Apple <https://www.apple.com/legal/privacy>