Uygulama / App: Worvento · Paket kimliği / Package name: com.worvento.app
Sürüm: 1.0 · Yürürlük: 8 Ağustos 2026 · Son güncelleme: 8 Ağustos 2026
Bu politika Worvento adlı mobil uygulama (Android paket adı com.worvento.app) ve https://api.worvento.com adresindeki sunucu hizmeti için geçerlidir.
Burada üç şeyi anlatıyoruz: hangi verinizi işliyoruz, neden işliyoruz, ne kadar süreyle tutuyoruz. Kısa tutmaya çalıştık; ama abartmadık. Uygulamanın gerçekte yaptığından fazlasını da azını da yazmadık — beyanlarımız kodla karşılaştırılarak yazıldı.
Bu belge Türkçe ve İngilizce olarak yayımlanmıştır. Çeviri bilgi amaçlıdır; çelişki hâlinde Türkçe metin geçerlidir.
Dağıtım bölgesi. Worvento; Avrupa Birliği/Avrupa Ekonomik Alanı, Birleşik Krallık, İsviçre, Japonya, Güney Kore, Çin ve Suudi Arabistan'da dağıtılmamaktadır ve bu ülkelerdeki kullanıcılara yönelik değildir. Bu nedenle bu politika Türk hukuku — özellikle 6698 sayılı Kişisel Verilerin Korunması Kanunu — esas alınarak yazılmıştır. Avrupa Birliği Genel Veri Koruma Tüzüğü (GDPR) ve Birleşik Krallık muadili bu metnin kapsamı dışındadır.
Aceleniz varsa yalnız bu tabloyu okuyun. Altındaki bölümler aynı bilgilerin ayrıntısıdır — denetim, mağaza formu ve hukuki başvuru için gereken tam beyan orada.
| Soru | Kısa yanıt |
|---|---|
| Kim işliyor? | Worvento'nun Türkiye'de yerleşik yayıncısı (gerçek kişi) — worvento.info@gmail.com (§1) |
| Hangi veri? | Hesap bilgileri, öğrenme ilerlemesi, oyunlaştırma/ekonomi, sosyal etkileşim, satın alma kaydı, güvenlik kayıtları, isteğe bağlı fotoğraf, reklam kimliği (§2, §3) |
| Neden? | Hizmeti sunmak (sözleşme), kötüye kullanımı önlemek (meşru menfaat), mali kayıt (hukuki yükümlülük), fotoğraf ve kişiselleştirilmiş reklam (açık rıza) — §2 |
| Verimi satıyor musunuz? | Hayır. Ama hizmeti çalıştırmak için sayılı alıcıyla paylaşıyoruz: barındırma, fotoğraf depolama, reklam, mağaza ödemesi, e-posta ve bildirim iletimi (§6) |
| Başkaları neyi görüyor? | Kullanıcı adı, XP, seviye, rozet, ısı haritası, avatar, son görülme, maç sonuçları — liderlikten çıkma ayarı yok (§4) |
| Nerede tutuluyor? | Sunucu Finlandiya'da (Hetzner); fotoğraflar Cloudflare'in küresel ağında, belirli bir ülkeye sabitlenmemiş (§7) |
| Ne kadar süre? | Loglar 7 gün, ısı haritası 400 gün, kodlar 15 dakika; çoğu kalem için kodda tanımlı süre yok → hesabınız açık kaldığı sürece (§12.1) |
| Hesabımı silersem? | Hesap kaydınız ve bağlı tablolar silinir; 12 kayıt türü ve cihazınızdaki yerel veriler silinmez — tam liste §12.2'de |
| Haklarım? | KVKK m.11'deki haklar; başvuru en geç 30 gün içinde sonuçlandırılır — worvento.info@gmail.com (§11) |
| Yaş sınırı? | 16+ (§9) |
Worvento'yu bir gerçek kişi yürütüyor. Arkasında şirket yok; sorumluluk doğrudan aşağıdaki kişiye aittir.
| Veri sorumlusu | Worvento'nun Türkiye'de yerleşik yayıncısı (bir gerçek kişi) — bu metinde kısaca "Yayıncı" |
| Veri koruma başvuruları için e-posta | worvento.info@gmail.com (tek kanal) |
| Destek e-postası | worvento.info@gmail.com |
| İnternet adresi | https://api.worvento.com |
Veri koruma iletişim noktası: worvento.info@gmail.com. Ayrıca atanmış bir veri koruma görevlisi yoktur; KVKK böyle bir atamayı zorunlu tutmuyor ve tek kişilik bir işletmede ayrı bir görevli atamak pratik bir karşılık üretmiyor. Bütün başvurular yukarıdaki adrese gelir.
Kişisel Veri İşleme Envanterine Kayıt (VERBİS): Bu politikada VERBİS kaydımızın bulunduğu yönünde bir beyan yer almıyor.
Worvento, Türkiye dışında da bazı ülkelerde yayınlanıyor (§Dağıtım bölgesi'nde sayılan ülkeler hariç). Yayın yapılan bazı ülkelerin kendi veri koruma yasaları var — örneğin Brezilya (LGPD), Hindistan (DPDP), Kanada (PIPEDA), Birleşik Arap Emirlikleri (PDPL). Bu politika 6698 sayılı Kanun esas alınarak yazıldı; şeffaflık, haklarınız ve verinizin silinmesi konularında bu yasaların istediklerini işlevsel olarak karşılıyor, ancak ülkeye özel ayrı bölümler içermiyor. Hangi ülkede olursanız olun başvuru kanalı aynıdır: worvento.info@gmail.com.
Amerika Birleşik Devletleri'nde yaşıyorsanız: Kaliforniya (CCPA/CPRA) ve benzeri eyalet yasalarının yıllık ciro (25 milyon ABD doları) ve tüketici sayısı (100.000) eşiklerinin çok altındayız, bu nedenle bu yasalar bakımından kapsamda değiliz. Bu yasaların en önemli noktası olan veri satışı konusunda tutumumuz her hâlde nettir: kişisel verilerinizi satmıyoruz (§6.3).
| Ne işliyoruz | Neden | Hukuki dayanak | Ne kadar tutuyoruz | Başkaları görür mü |
|---|---|---|---|---|
| Kullanıcı adı, e-posta, parola (şifrelenmiş özet) | Hesabınızı açmak, girişinizi doğrulamak | KVKK m.5/2-c | Hesabınız açık kaldığı sürece | Kullanıcı adı: evet · E-posta: hayır |
| Öğrenme verisi (kelime tekrar zamanları, doğru-yanlış, kategori ilerlemesi) | Kelime öğretmek, tekrar zamanlarını hesaplamak | KVKK m.5/2-c | Hesabınız açık kaldığı sürece | Hayır |
| XP, seviye, seri, rozet, ısı haritası, oyun skorları | Oyunlaştırma, liderlik, lig, sezon | KVKK m.5/2-c | Isı haritası 400 gün · diğerleri hesap ömrü | Evet (liderlik ve profil) |
| Altın, joker, kozmetik, pet, görev-sezon durumu | Uygulama içi ekonomiyi sunucuda yürütmek | KVKK m.5/2-c | Hesabınız açık kaldığı sürece | Kısmen (takılı görünüm, premium tacı) |
| Arkadaşlık, hediye, engelleme, düello ve maç sonuçları, ortak liste | Sosyal özellikleri çalıştırmak | KVKK m.5/2-c | Hesabınız açık kaldığı sürece | Evet (ilgili kişilere) |
| Satın alma kaydı (ürün kimliği, mağaza işlem numarası) | Satın aldığınızı teslim etmek, iadeyi yürütmek, mali kayıt tutmak | Teslim: KVKK m.5/2-c — Mali kayıt: KVKK m.5/2-ç | Mali mevzuatın gerektirdiği süre (bkz. §12) | Hayır |
| IP adresi, cihaz kimliği, kurulum kimliği, başarısız giriş sayacı | Çoklu hesap açmayı, davet kodu istismarını ve kaba kuvvet saldırısını engellemek | KVKK m.5/2-f | Kodda tanımlı süre yok (bkz. §12) | Hayır |
| Reklam kimliği ve reklam telemetrisi (Google AdMob toplar) | Ödüllü reklam göstermek | KVKK açık rıza (m.5/1) | Google'ın saklama sürelerine göre | Hayır |
| İsteğe bağlı profil fotoğrafı | Profilinizde ve listelerde avatar göstermek | KVKK açık rıza | Siz kaldırana, hesabınızı silene veya premium hakkınızın bitiminden 30 gün sonra (hangisi önce gerçekleşirse) — bkz. §5, §12 | Evet (küçük boy herkese) |
| Doğrulama, şifre sıfırlama ve hesap silme kodları | Kimliğinizi ve kritik işlemleri doğrulamak | KVKK m.5/2-c ve m.5/2-f ve m.6(1)(f) | 15 dakika | Hayır |
| Sunucu işletim logları | Hataları görmek, saldırıyı fark etmek | KVKK m.5/2-f | 7 günlük dosya döngüsü | Hayır |
| Destek mesajınız | Sorunuzu yanıtlamak | KVKK m.5/2-c | Destek posta kutusunda; kodda tanımlı süre yok | Hayır |
Toplama yöntemi: Yukarıdaki verilerin tamamı, uygulamayı kullanmanız sırasında tamamen otomatik yollarla — uygulama ile sunucumuz arasındaki bağlantı üzerinden — elde edilir. Kâğıt form, çağrı merkezi, veri satın alma gibi başka bir kaynağımız yok. Hiçbir veriyi veri brokerlerinden veya üçüncü kişilerden satın almıyoruz.
Meşru menfaat neyi ifade ediyor: Yukarıda KVKK m.5/2-f yazan tek satır güvenlik ve kötüye kullanımı önlemedir. Buradaki menfaatimiz somut olarak şudur: aynı kişinin onlarca hesap açıp ödül ve davet kodu sistemini sömürmesini engellemek, hesabınıza kaba kuvvetle girilmesini durdurmak, sunucunun ayakta kalmasını sağlamak. Bu işlemeye itiraz hakkınız var (bkz. §11).
Aşağıdaki listeler uygulamanın kodundan çıkarılmıştır. Her satır dört bilgi taşır: hangi veri, hangi amaç, hangi hukuki sebep, ne kadar süre.
| Veri | Amaç | Hukuki dayanak | Saklama |
|---|---|---|---|
| Kullanıcı adı (en çok 50 karakter, tekil) | Hesap kimliği; liderlik, arkadaş listesi, düello, lig ve hediye ekranlarında gösterim | KVKK m.5/2-c | Hesap ömrü |
| E-posta adresi | Giriş kimliği; doğrulama, şifre sıfırlama ve hesap silme kodlarının gönderimi; destek yanıtı | KVKK m.5/2-c | Hesap ömrü. Not: e-posta adresiniz oturum jetonunun (JWT) içinde de bir alan olarak taşınır |
| Parola | Girişinizi doğrulamak; hesap silmede kimlik teyidi | KVKK m.5/2-c | Parolanız düz metin olarak saklanmaz; yalnız BCrypt ile üretilmiş tek yönlü özeti tutulur |
| E-posta doğrulama kodunun özeti, gönderim anı, deneme sayacı | Hesabın gerçek bir e-posta adresine bağlı olduğunu doğrulamak; ödül ve karşılaşma özelliklerine erişim kapısı | KVKK m.5/2-c | Kod geçerlilik süresi 15 dakika |
| Şifre sıfırlama kodunun özeti, anı, deneme sayacı | Şifre sıfırlama akışını yürütmek | KVKK m.5/2-c ve m.5/2-f ve m.6(1)(f) | 15 dakika |
| Hesap silme onay kodunun özeti, anı, deneme sayacı | Hesap silmeyi iki adımda onaylatmak | KVKK m.5/2-c ve m.5/2-f ve m.6(1)(f) | 15 dakika |
| Erişim jetonu (JWT) | Her istekte kimliğinizi taşımak | KVKK m.5/2-c | 7 gün geçerli; sunucuda saklanmaz |
| Oturum yenileme jetonu (refresh token) | Oturumu 7 günden uzun sürdürmek; çıkışta ve banda oturumu iptal edebilmek | KVKK m.5/2-c | Geçerlilik 30 gün. Dürüst not: süresi geçmiş kayıt veritabanından silinmez, kayıt satırı tabloda kalır |
| Dil tercihleri, günlük XP hedefi, tanıtım turunun tamamlanma durumu | İkinci cihazda dil seçimini ve tanıtımı atlamak; karşılaşma içeriğini doğru dilde göstermek | KVKK m.5/2-c | Kodda tanımlı süre yok — hesap ömrü |
| Saat dilimi farkı (dakika) | Günlük hakların sizin yerel gece yarınızda sıfırlanması | KVKK m.5/2-c | Her açılışta güncellenir |
| Bildirim jetonu, cihaz platformu, arayüz dili | Size bildirim gönderebilmek | KVKK m.5/2-f | Çıkışta silinir; hesap silinince gider |
| Bildirim tercihiniz (arkadaş/oyun bildirimleri açık mı) | Kapalıysa sunucunun bildirim göndermemesi | KVKK m.5/2-f | Cihaz kaydı süresince |
| Seçtiğiniz sessiz saat aralığı | Bildirimin sizin belirlediğiniz saatlerde gönderilmemesi | KVKK m.5/2-f | Cihaz kaydı süresince |
Saat dilimi hakkında dürüst not: GPS veya ağ tabanlı konumunuzu toplamıyoruz. Ama saat dilimi farkınız kaba bir coğrafi çıkarım yapmaya yeter (örneğin "UTC+3" bilgisi kıtanızı daraltır). Bunu "konum toplamıyoruz" cümlesinin arkasına saklamıyoruz.
| Veri | Amaç | Hukuki dayanak | Saklama |
|---|---|---|---|
| Kelime bazlı tekrar durumu (kararlılık, zorluk, tekrar sayısı, unutma sayısı, sonraki tekrar zamanı) | Aralıklı tekrar algoritmasının çalışması; haftalık karne | KVKK m.5/2-c | Kodda tanımlı süre yok. Dürüst not: bu kayıtlar hesap silmede silinmiyor (bkz. §12.2) |
| Kelime ustalık işaretleri | Koleksiyon albümü, altın kelime, pet evresi | KVKK m.5/2-c | Kodda tanımlı süre yok. Hesap silmede silinmiyor |
| Karıştırma çiftleri (hangi iki kelimeyi karıştırdığınız) | Size özel hata analizi ve tekrar önerisi | KVKK m.5/2-c | Kodda tanımlı süre yok. Hesap silmede silinmiyor |
| Doğru-yanlış cevap sayaçları | İlerleme ve rozet hesabı | KVKK m.5/2-c | Hesap ömrü |
| Çalışma oturumu kayıtları (sınav oturumu imzası) | Ödülün gerçekten kazanıldığını doğrulamak | KVKK m.5/2-f | Oturum 1 saat, kullanıldı işareti 6 saat |
| Kendi eklediğiniz kelimeler (MyList) | Kendi listenizle çalışmak | KVKK m.5/2-c | Cihazınızda tutulur (bkz. §5) |
| Veri | Amaç | Hukuki dayanak | Saklama |
|---|---|---|---|
| Toplam XP, seviye, mevcut seri, en yüksek seri | İlerleme, liderlik, lig, sezon | KVKK m.5/2-c | Hesap ömrü |
| Günlük aktivite (ısı haritası) günlüğü | Süreklilik takvimi | KVKK m.5/2-c | 400 gün — bu pencerenin dışına düşen günler her eşitlemede budanır |
| Rozetler (en çok 200 rozet kimliği) | Başarım gösterimi | KVKK m.5/2-c | Hesap ömrü |
| Altın, jokerler, kozmetik sahipliği, takılı çerçeve ve avatar | Sunucu tarafında yürütülen ekonomi | KVKK m.5/2-c | Hesap ömrü |
| Seri onarma hakkı ve kalkan durumu | Seri onarma hakkının kötüye kullanılmasını engellemek | KVKK m.5/2-c ve m.5/2-f ve m.6(1)(f) | Hesap ömrü |
| Günlük hak sayaçları (reklam, çark, sınav, çalışma, giriş bonusu) | Günlük tavanları uygulamak; otomasyona karşı bekleme süresi | KVKK m.5/2-c ve m.5/2-f ve m.6(1)(f) | Yerel gece yarısında sıfırlanır |
| Sezon puanı, sezon kimliği, sezon premium durumu, günlük ve haftalık görevler | Sezon ilerlemesi ve görevler | KVKK m.5/2-c | Sezon değişiminde sıfırlanır |
| XP eşitleme denetim sayaçları | Sahte XP gönderimini engellemek | KVKK m.5/2-f | Gün değişiminde sıfırlanır |
| Günlük lig XP satırları | "Günün Kazananları" sıralaması | KVKK m.5/2-c | Kodda temizlik yok — eski günlerin satırları silinmiyor (bkz. §12.1) |
| Günlük yarışma sonuçları (60 saniye, wordle, mini çengel, günün kelimesi, boss, kule koşusu) | Günde tek deneme kuralı, skor tablosu, seri | KVKK m.5/2-c | Kodda tanımlı süre yok |
| Pet (Kelime Dostu) durumu ve sizin yazdığınız pet adı | Pet ekonomisinin cihazlar arasında eşitlenmesi | KVKK m.5/2-c | Hesap ömrü |
| Ödül tekrarlama engeli anahtar listeleri | Aynı ödülün iki kez verilmesini engellemek | KVKK m.5/2-f | Kodda tanımlı süre yok |
| Veri | Amaç | Hukuki dayanak | Saklama |
|---|---|---|---|
| Arkadaşlık kayıtları (istek, kabul, tarihler) | Arkadaş listesi; düello, hediye ve canlı maç yetkisi | KVKK m.5/2-c | Hesap ömrü |
| Engellediğiniz kullanıcılar | Etkileşimi kesmek | KVKK m.5/2-c | Hesap ömrü |
| Şikâyet kaydınız: serbest metin gerekçe (en çok 500 karakter), şikâyet edilen kişi, tarih, sonuç | Moderasyon | KVKK m.5/2-f | Kodda tanımlı süre yok. Yönetim ekranında şikâyet eden ve edilen kullanıcı adlarıyla birlikte görünür. Bu alana üçüncü kişiler hakkında hassas bilgi yazmayın |
| Aldığınız hediyeler ve gönderenin kullanıcı adı | Hediye geçmişi ve itibar | KVKK m.5/2-c | Geçmiş budanmıyor. Dürüst not: gönderen kişi hesabını silse bile kullanıcı adı sizin kaydınızda kalır |
| Hediye vitrini, itibar puanı, sahip olunan hediyeler | Profil vitrini | KVKK m.5/2-c | Hesap ömrü |
| Düello, canlı meydan okuma ve adam asmaca sonuçları | "Aranızdaki maçlar", son maçlar listesi | KVKK m.5/2-c | Kodda tanımlı süre yok. Hesap silmede silinmiyor |
| Meydan okuma zarfları (24 saatlik asenkron oyun daveti, kelime listesi ve skorlar) | Arkadaşa mini oyun daveti | KVKK m.5/2-c | Süresi geçince "süresi doldu" işaretlenir, satır silinmez. Hesap silmede silinmiyor |
| Ortak kelime listeleri (en çok 4 kişi): liste adı, üye kullanıcı adları, sizin yazdığınız özel kelimeler | Ortak çalışma listesi | KVKK m.5/2-c | Kelime silme = "silindi" işareti. Kodda bu işaretleri temizleyen bir iş yok, kayıt kalıcıdır |
| Davet kodunuz ve kullandığınız davet kodu | Arkadaşını getir kampanyası; cihaz başına davet sınırı | KVKK m.5/2-c ve m.5/2-f ve m.6(1)(f) | Hesap ömrü |
| Son görülme anı (presence) | Arkadaş listesinde "Çevrimiçi / son görülme" göstergesi | KVKK m.5/2-c | Son değer tutulur; canlı bağlantı kayıtları 12 saat |
| Aktif maç anlık görüntüsü: kullanıcı adları, verdiğiniz cevaplar, denediğiniz harfler, hedef kelime | Sunucu yeniden başlarsa oynanan maçı kaybetmemek | KVKK m.5/2-c | 6 saatten eskiler saatlik temizlenir; hızlı bellek kopyası 6 saat |
| Veri | Amaç | Hukuki dayanak | Saklama |
|---|---|---|---|
| Mağaza işlem numarası, ürün kimliği, platform, verilen altın, ilk alım bonusu, iade durumu | Aynı makbuzla iki kez ödül verilmesini engellemek; iadeyi işlemek | Teslim: KVKK m.5/2-c — Mali kayıt: KVKK m.5/2-ç | Kodda tanımlı süre yok; hesap silmede silinmiyor (bkz. §12.2) |
| Makbuz doğrulama verisi (satın alma jetonu) | Satın almanın gerçekliğini mağazaya doğrulatmak | KVKK m.5/2-c | Kalıcı saklanmaz; yalnız işlem numarası yoksa tekrarlama anahtarı olarak yazılır |
| Haklarınız kaydı (reklamsız erişim, süre paketi) | Satın aldığınız hakkı tanımak | KVKK m.5/2-c | Süresi geçmiş kayıt silinmez; hesap silmede silinmiyor |
Ödeme bilgileriniz bize hiç gelmiyor. Kart numarası, IBAN, fatura adresi, vergi bilgisi gibi verileri görmüyoruz ve saklamıyoruz. Tahsilatı Google (Play) veya Apple (App Store) yapar; bize yalnız ürün kimliği ve mağazanın işlem numarası ulaşır.
| Veri | Amaç (meşru menfaatimiz) | Hukuki dayanak | Saklama |
|---|---|---|---|
| Kayıt IP adresi, son giriş IP adresi | Aynı kişinin çok sayıda hesap açmasını fark etmek; hız sınırı uygulamak | KVKK m.5/2-f | Kodda silme veya maskeleme işi yok |
| Cihaz kimliği (uygulamanın ürettiği rastgele numara) | Cihaz başına hesap sınırı; davet kodu istismarını durdurmak; ban yayılımı | KVKK m.5/2-f | Kodda tanımlı süre yok |
| Kurulum kimliği (rastgele numara) | "Aynı cihaz, farklı kurulum" ayrımı | KVKK m.5/2-f | Kodda tanımlı süre yok |
| Başarısız giriş sayacı, hesap kilidi süresi | Kaba kuvvet ve çalınmış parola denemelerini durdurmak | KVKK m.5/2-f | Başarılı girişte sıfırlanır; kilit varsayılan 15 dakika |
| Doğum tarihi | 16 yaş sınırının uygulanması; uygulama içi satın alma ehliyeti; mağaza yaş derecelendirmesiyle tutarlılık | KVKK m.5/2-c ve m.5/2-f | Hesap ömrü — profilde gösterilmez, kimseyle paylaşılmaz |
| Askıya alma gerekçesi, tarihi ve kararın otomatik olup olmadığı | Kararı size bildirmek ve itiraz hakkınızı kullanabilmeniz (KVKK m.11/1-g) | KVKK m.5/2-f | Hesap ömrü |
| İtiraz metniniz | Askıya alma kararının insan tarafından incelenmesi | KVKK m.5/2-f | Hesap ömrü |
| Yönetim durumu, hesabın askıya alınmış olması | Moderasyon | KVKK m.5/2-f | Hesap ömrü |
| Sunucu işletim logları (istek yöntemi, yol, durum kodu, süre) | Hata ayıklama, saldırı tespiti | KVKK m.5/2-f | 7 günlük dosya döngüsü |
| Çoklu hesap uyarı logu (cihaz kimliği, kullanıcı adı, IP) | Kötüye kullanım analizi | KVKK m.5/2-f | 7 günlük dosya döngüsü |
| Ban logu (kullanıcı numarası, aynı cihazdaki diğer hesaplar) | Moderasyon izi | KVKK m.5/2-f | 7 günlük dosya döngüsü |
Cihaz kimliği hakkında dürüst not: Bu kimlik telefonunuzun donanımından okunmuyor — uygulama kurulduğunda rastgele üretilip cihazda saklanan bir numaradır. IMEI, MAC adresi, seri numarası veya reklam kimliği okumuyoruz. Uygulamayı kaldırdığınızda bu numara da silinir (iOS ve Android'de aynı şekilde), yani sıfırlanabilir bir kimliktir.
Eskiden iOS'ta bu numara Anahtar Zinciri'nde tutuluyordu ve uygulamayı silseniz bile cihazda kalıyordu. 2026-08-12'de değiştirildi: kimlik artık uygulama verisiyle birlikte gidiyor ve cihazda kalan eski kayıt da temizleniyor. Bunun bedelini biliyoruz — uygulamayı silip yeniden kuran biri bizim için yeni bir cihaz gibi görünür — ve bu bedeli sizin lehinize kabul ettik.
IP adresi hakkında dürüst not: Kaydettiğimiz IP adresi her zaman güvenilir olmayabilir; ters vekil yapılandırmasındaki bir eksiklik nedeniyle bu değer istemci tarafından etkilenebilir. Bu kusuru gidermek düzeltme listemizde.
| Veri | Amaç | Hukuki dayanak | Saklama |
|---|---|---|---|
| Reklam kimliği (Android'de AAID, iOS'ta IDFA), IP adresi, cihaz ve işletim sistemi bilgisi, reklam etkileşimi | Ödüllü reklam sunumu, ölçüm, geçersiz trafik tespiti | KVKK açık rıza (m.5/1) | Google'ın saklama sürelerine göre — bizim veritabanımıza girmez |
| Ödül doğrulama verisi: mağaza işlem numarası ve hesap numaranız | Ödülü sunucunun vermesi (istemcinin "izledim" demesine güvenilmemesi) | KVKK m.5/2-f | Ödül işlem kaydı silinmiyor; hesap silmede de silinmiyor |
Ayrıntı için bkz. §8.
| Veri | Amaç | Hukuki dayanak | Saklama |
|---|---|---|---|
| Destek mesajınızın konusu ve tam metni, kullanıcı adınız, hesap numaranız, e-posta adresiniz | Sorunuzu yanıtlamak | KVKK m.5/2-c | Mesaj veritabanına yazılmaz; e-posta olarak destek posta kutusuna gider ve orada kalır. Kodda tanımlı bir silme süresi yok |
| Giden e-postaların içeriği (doğrulama kodu, şifre sıfırlama kodu, hesap silme kodu, şifre değişikliği bildirimi) | Hesap işlemlerini doğrulamak | KVKK m.5/2-c | E-posta, Google'ın e-posta altyapısında ve sizin posta kutunuzda kalır |
Size pazarlama e-postası göndermiyoruz. Yukarıdaki e-postalar hizmetin işleyişine ait bildirimlerdir; 6563 sayılı Kanun anlamında ticari elektronik ileti değildir. Kampanya veya indirim duyurusu göndermeye başlarsak ayrıca onayınızı alacağız.
Size işletim sistemi seviyesinde bildirim gönderiyoruz. Bildirimler iki ayrı gruba ayrılır, ayrı ayrı açılıp kapatılır ve ikisi de Ayarlar → Bildirimler'den kapatılabilir:
arkadaşlık isteği, davet kabulü, maç sonucu, hediye. Bunları sunucumuz gönderir; bunun için cihazınıza ait bir bildirim jetonu (Firebase Cloud Messaging kaydı), cihaz platformu ve arayüz diliniz saklanır. Jeton hesabınız silinince silinir, çıkış yaptığınızda kaldırılır.
Bildirim Google üzerinden gider — bunu açıkça yazıyoruz. Bildirimi cihazınıza biz değil, Google'ın Firebase Cloud Messaging altyapısı ulaştırıyor. Yani hem jetonunuz hem de bildirimin başlığı ve gövdesi Google'ın sunucularından geçiyor ve bu bir yurt dışı aktarımdır (§6). Bazı bildirimlerin gövdesinde başka bir kullanıcının kullanıcı adı bulunur — "X davetini kabul etti", "X ile maçın bitti" gibi. Bildirim metnine bunun dışında bir bilgi (mesaj içeriği, skorunuz, e-posta adresiniz) koymuyoruz.
Ayarlar > Bildirimler'den tek dokunuşla kapatabilirsiniz) — gün serisi, kelime dostunuzun beslenme zamanı, gün içi çalışma önerileri. Bunlar cihazınızda kurulur ve tetiklenir; ne içerikleri ne de zamanları sunucumuza gider, sunucu bu bildirimlerden haberdar değildir.
Sınırlarımız: günde en fazla iki hatırlatıcı göndeririz ve o gün uygulamayı kullandıysanız o günün kalan hatırlatıcılarını iptal ederiz. Bildirimlerimizi uzun süre açmazsanız hatırlatıcıları kendiliğinden durdururuz.
Sürüm güncelleme duyuruları. Uygulamanın yeni bir sürümü yayımlandığında sizi bilgilendiririz: sunucumuz bir kez bildirim gönderir, ardından cihazınız güncellemeyi yapana kadar günde en fazla bir hatırlatma kurar. Bu duyurular hizmetin doğru ve güvenli çalışması için gereklidir — eski sürümlerde ödül, ödeme ve güvenlik akışları bozulabilir — bu nedenle uygulama içinden ayrıca kapatılamaz; dilediğiniz an cihazınızın sistem ayarlarından uygulamanın bildirimlerini kapatabilirsiniz. Bu duyurular da 22:00 – 08:00 arasında gönderilmez. Güncellemeyi yaptığınız anda durur; zaten güncel olan ya da güncellemeyi indirmiş cihazlara hiç gönderilmez.
Sessiz saatler. Bildirim istemediğiniz bir saat aralığı seçebilirsiniz (varsayılan 22:00 – 08:00; kapatabilir ya da değiştirebilirsiniz). Sunucudan gelen bildirimlerin de bu aralığa uyması gerektiği için seçtiğiniz aralık sunucumuzda saklanır — cihaz kaydınızın bir parçası olarak, saat dilimi farkınızla birlikte. Aynı şekilde arkadaş ve oyun bildirimlerini açık mı kapalı mı tuttuğunuz da sunucuda tutulur; aksi hâlde sunucu kapalı olduğunu bilemez ve yine bildirim gönderirdi.
Bu iki bilgi yalnız bildirim gönderilip gönderilmeyeceğine karar vermek için kullanılır; profilleme yapılmaz ve üçüncü tarafa gitmez.
Bunların yanında iki kanal daha var:
bağlantı üzerinden anında iletilir. Uygulama açıkken bildirim gönderilmez (aynı olayı iki kez görmezsiniz).
siz cevaplayana kadar gizli tutulur; ancak seri gün sayınız her tazelemede yazılır ve widget kilit ekranında görünüyorsa başkaları tarafından okunabilir. Şu an bunu uygulama içinden kapatacak bir ayar yok.
Bu bölümü ayrı yazdık, çünkü en çok yanlış anlaşılan konu bu. Aşağıdakiler diğer kullanıcılara görünür.
süreklilik ısı haritanız, premium tacınız ve sıralamanız. Şu anda liderlik tablosundan çıkmanızı sağlayan bir ayar yok. Kullanıcı adınızı gerçek adınız yapmamanızı öneririz.
profilinizi açanlara görünür. Bunu gizleyecek bir ayar yok.
profilinizde görünür.
rakibinizin kullanıcı adı gömülür ve seçtiğiniz uygulamaya (mesajlaşma, sosyal ağ, e-posta) gider. Rakibinize bunun için bildirim gitmez ve onayı alınmaz. Aynı şekilde birisi sizinle oynadığı maçı paylaşırsa sizin kullanıcı adınız** onun seçtiği uygulamaya gider.
kullanıcı adları diğer üyelere görünür.
gönderdiğini yalnız siz görürsünüz.
maçlar", "son maçlar").
görünür.
anlık durumunda tutulur; rakibinizin ekranında maç akışı olarak görünür.
Görünmeyenler: e-posta adresiniz, parolanız, satın alma geçmişiniz, altın ve joker bakiyeniz, IP adresiniz, cihaz kimliğiniz, engellediğiniz kişilerin listesi, şikâyetleriniz, pet adınız, kendi kelime listeniz (MyList), karıştırdığınız kelimeler ve tekrar zamanlarınız.
Profil fotoğrafı hakkında dürüst not: Fotoğraflar, adresi tahmin edilemeyecek kadar rastgele olan bir bağlantı üzerinden sunulur. Bu bir erişim kontrolü değil, adres gizliliğidir: o bağlantıyı bilen herkes — giriş yapmamış olsa bile — fotoğrafa erişebilir. Tam boy fotoğrafın adresi yalnız size ve premium görüntüleyene gönderilir; ama bu adres bir kere paylaşılırsa, paylaşan herkes fotoğrafa erişmeye devam eder. Bu nedenle "fotoğrafınızı yalnız premium kullanıcılar görebilir" demiyoruz.
Fotoğrafın silinmesi: Profil fotoğrafı yükleme bir Sezon Premium hakkıdır. Premium hakkınız sona erdikten sonra fotoğrafınız 30 gün daha saklanır; bu süre içinde premium yenilenmezse fotoğraf sunucudan (Cloudflare R2) silinir ve profilinize sahip olduğunuz avatarlardan biri takılır. Dilediğiniz an kendiniz de kaldırabilirsiniz.
Uygulama bazı verileri sizin cihazınızda tutar. Bunlar sunucumuza gitmez (aksi belirtilmedikçe).
| Nerede | Ne | Neden gerekli |
|---|---|---|
| Şifreli güvenli depo | Oturum jetonu, oturum yenileme jetonu, son giriş e-posta adresi, e-posta doğrulama bayrağı, cihaz kimliği, son eşitleme anlık görüntüsü | Oturumu sürdürmek; gereksiz eşitleme yapmamak; kötüye kullanımı önlemek |
Yerel veritabanı (words) | Kelime havuzu ve kendi eklediğiniz kelimeler (MyList) | İnternet olmadığında çalışabilmek |
Yerel veritabanı (categories, shared_list_cache) | Kategori kilit durumu; ortak listenin çevrimdışı kopyası | Çevrimdışı okuma |
Yerel veritabanı (user_stats) | XP, seri, rozet, dil, tema, hedef, öğrenme sayaçları; ayrıca yalnız cihazda kalan alışkanlık sayaçları (öğle arası çalışma, hafta sonu, sessiz test) | Oyunlaştırma ve rozet mantığı |
| Basit tercihler deposu | Kurulum kimliği, 12 mini oyunun kişisel rekoru, tanıtım turu bayrakları, kutlama ve banner bayrakları, pet evre bayrağı | Aynı ekranı iki kez göstermemek; yerel rekor göstermek |
| Geçici dizin | Paylaşım kartı resmi (PNG) ve fotoğraf kırpma dosyası | Paylaşım ve fotoğraf yükleme akışı |
| Uygulama belgeler dizini | my_words_export.csv (kelime listesi yedeği) | Kendi listenizin yedeği |
| Ana ekran widget'ı alanı | Günün kelimesi başlığı, seri gün sayısı | Widget gösterimi |
| Bellek (diske yazılmaz) | Kısa süreli API yanıt önbelleği (en çok 1 saat) | Aynı katalog verisini tekrar çekmemek |
Hangileri için onayınız gerekir. Cihazınızda bilgi saklamayı Kişisel Verileri Koruma Kurumu'nun Çerez Uygulamaları Hakkında Rehberi'ndeki ayrıma göre dört kategoriye ayırıyoruz:
| Kategori | Hangi kayıtlar | Onay gerekir mi |
|---|---|---|
| Hizmetin sunulması için kesinlikle gerekli | Oturum jetonu ve yenileme jetonu, son giriş e-posta adresi, doğrulama bayrağı, dil-tema-hedef tercihleri, kelime havuzu ve MyList, kategori kutusu, eşitleme anlık görüntüsü, kısa süreli yanıt önbelleği | Hayır — bu kayıtlar olmadan giriş, çevrimdışı çalışma ve tercih hatırlama mümkün değildir |
| Kötüye kullanımı önleme | Cihaz kimliği, kurulum kimliği | Onay değil, meşru menfaat (KVKK m.5/2-f) — gerekçe yazılı olarak tutuluyor |
| Reklam | Google AdMob yazılım bileşeninin cihazınıza yazdığı kayıtlar | Reklamların kişiselleştirilmesi için evet, açık rıza (§8) |
| Kolaylık kayıtları | Mini oyun rekorları, tanıtım turu ve kutlama bayrakları, banner bayrakları, pet evre bayrağı, widget alanı | Cihazınızdan çıkmaz; sunucuya gitmez |
Ayrıntılı liste ve her anahtarın tek tek gerekçesi Çerez ve SDK Politikası'nda yer alır (§17).
Hesap silmede cihazınızda kalanlar — dürüst liste. Hesabınızı sildiğinizde uygulama yalnız eşitleme anlık görüntüsünü ve user_stats kutusunu temizler. Şunlar cihazınızda kalır:
words),shared_list_cache), kategori kutusu,Bunları temizlemenin yolu cihazınızdan uygulamayı kaldırmak; artık cihaz kimliği de bununla birlikte gidiyor. Kalan tek istisna iOS Keychain'deki oturum jetonları — onlar çıkış yapınca ya da hesabınızı silince temizleniyor.
Aşağıdaki tablo, verinizin çıktığı her yeri gösteriyor. Dikkat edilecek nokta: sunucumuz Finlandiya'da, yani Türkiye'den bakıldığında hepsi yurt dışı aktarımdır — barındırma dahil. Bu, verinin güvensiz olduğu anlamına gelmez; ama KVKK m.9 bakımından her biri için ayrı bir hukuki dayanak gerektirir (§7).
| Alıcı | Rolü | Ülke / sözleşme tarafı | Ne gidiyor | KVKK m.9 durumu | Gizlilik politikası |
|---|---|---|---|---|---|
| Hetzner Online GmbH | veri işleyen (barındırma) | Hetzner Online GmbH (Almanya) — sunucumuz Finlandiya'da bulunuyor. | Sunucudaki tüm veri: veritabanı, hızlı bellek, log dosyaları | Yurt dışı aktarım | https://www.hetzner.com/legal/privacy |
| Cloudflare, Inc. | veri işleyen (profil fotoğrafı depolama) | Cloudflare, Inc. (ABD) — küresel altyapı; profil fotoğrafları belirli bir ülkeye sabitlenmemiştir. Aktarımda ve saklamada şifrelenir. | Profil fotoğrafının ham baytları; nesne yolunda hesap numaranız; isteğin IP adresi | Yurt dışı aktarım | https://www.cloudflare.com/privacypolicy/ |
| Google Ireland Ltd / Google LLC (AdMob) | bağımsız veri sorumlusu | İrlanda / ABD | Reklam kimliği, IP adresi, cihaz ve işletim sistemi bilgisi, reklam etkileşimi; ödül doğrulaması açıkken hesap numaranız | Yurt dışı aktarım | https://policies.google.com/technologies/partner-sites |
| Google Commerce Ltd (Play Billing) | bağımsız veri sorumlusu; Avrupa Ekonomik Alanı'nda kayıtlı satıcı | Dublin / ABD | Uygulama paket adı, ürün kimliği, satın alma jetonu | Yurt dışı aktarım | https://policies.google.com/privacy |
| Apple Distribution International Ltd | bağımsız veri sorumlusu; App Store işlemlerinde geliştiricinin ajanı veya komisyoncusu | İrlanda / ABD | İşlem numarası ve imzalı doğrulama isteği | Yurt dışı aktarım — iOS sürümü yayınlandığında geçerli olacak | https://www.apple.com/legal/privacy |
| Google (e-posta gönderimi — Gmail) | fiilen veri işleyen | ABD / küresel | Alıcı e-posta adresi, kullanıcı adı, doğrulama-şifre-silme kodu, destek mesajının tam metni | Yurt dışı aktarım | https://policies.google.com/privacy |
| Google LLC (Firebase Cloud Messaging) | veri işleyen (bildirim iletimi) | ABD / küresel | Cihaz bildirim jetonu, cihaz platformu, arayüz diliniz; bildirimin başlığı ve gövdesi | Yurt dışı aktarım | https://firebase.google.com/support/privacy |
| Cihazınızın metin okuma (TTS) motoru | bağımsız veri sorumlusu | Cihazınıza yüklü motora bağlı | Seslendirilecek kelime ve dil kodu | Cihazınızda kalır; motor buluta bağlanıyorsa dışarı çıkar | Motorun sağlayıcısına bağlı |
| Paylaşım için sizin seçtiğiniz uygulama | bağımsız veri sorumlusu | Seçiminize bağlı | Paylaşım kartı resmi ve metni | Sizin eyleminizle | Seçtiğiniz uygulamanın politikası |
Yukarıdaki alıcılarla aramızdaki veri işleme sözleşmelerinin durumu ve KVKK m.9 dayanağının nasıl kurulacağı §7'de anlatılıyor. Aktarım güvencelerinin bir kopyasını isteyebilirsiniz: worvento.info@gmail.com adresine yazın, §11'deki süreler içinde yanıtlarız.
Alıcı olmayan bir bağlantı: Sunucumuz, reklam ödülü doğrulaması için Google'ın gstatic.com adresinden açık doğrulama anahtarlarını indirir. Bu istekte kişisel veri gitmez; bu nedenle Google bu işlem bakımından bir "alıcı" olarak listelenmemiştir.
Kişisel verilerinizi satmıyoruz. Kiralamıyoruz, reklam borsalarına, veri brokerlerine veya puanlama şirketlerine vermiyoruz; karşılığında para, hizmet veya veri almadığımız hiçbir alıcı yok.
Buna karşılık "hiçbir veri dışarı çıkmıyor" demek doğru olmaz. Hizmeti çalıştırmak için §6.1 ve §6.2'de sayılan alıcılara şunları veriyoruz — tamamı budur:
| Alıcı | Ona giden tam liste |
|---|---|
| Google AdMob | Reklam kimliği, IP adresi, cihaz ve işletim sistemi sinyalleri, reklam etkileşimi; ödül doğrulaması etkinleştirildiğinde ayrıca hesap numaranız |
| Google Play / Apple App Store | Satın alma jetonu, ürün kimliği, mağaza işlem numarası (makbuz doğrulaması) |
| Cloudflare (R2) | Profil fotoğrafınızın baytları (veri işleyen — hizmet sağlayıcı) |
| Hetzner | Sunucudaki tüm veri, barındırma sağlayıcısı olarak (veri işleyen) |
| Google (Gmail ile e-posta) | E-posta adresiniz, 6 haneli kodlar, destek mesajınızın tam metni |
| Google (Firebase Cloud Messaging) | Bildirim jetonunuz ve gönderdiğimiz bildirimin metni |
Bu listeden farklı bir alıcıya veri gitmiyor. Reklam alanında Google bizim veri işleyenimiz değil, bağımsız bir veri sorumlusudur; yani veriyi bizim talimatımızla değil kendi amaçlarıyla işler. Mağaza formlarında "paylaşılan" olarak beyan edilen asıl kalem budur.
Uygulama, internetinizin gerçekten çalışıp çalışmadığını anlamak için (örneğin oturum açma gerektiren bir kafe ağına bağlıysanız bunu fark etmek için) düzenli olarak bir istek atıyor. Bu istek yalnız kendi sunucumuza gidiyor (/health), yaklaşık 45 saniyede bir. Üçüncü tarafa hiçbir şey gitmiyor.
Bunu neden yazıyoruz: eskiden bu kontrol, kullandığımız kütüphanenin varsayılanları değiştirilmediği için IP adresinizi dört üçüncü tarafa (one.one.one.one, icanhazip.com, jsonplaceholder.typicode.com, pokeapi.co) yaklaşık 10 saniyede bir gönderiyordu; ikisi veri işleme sözleşmesi olmayan ücretsiz topluluk servisiydi. Bu bir tasarım kusuruydu ve düzeltildi. Bu politikanın eski sürümünü okuduysanız, orada beyan edilen o dört aktarım artık yapılmıyor.
Kişisel Verileri Koruma Kurulu bugüne kadar hiçbir ülke için yeterlilik kararı vermemiştir. Bu nedenle §6.1'deki alıcıların hepsine yapılan aktarım, KVKK m.9/3-4'teki uygun güvencelerden birine dayanmak zorundadır. Bizim için beklenen yol, Kurul tarafından ilan edilen standart sözleşmenin ilgili modülünün imzalanması ve imza tarihinden itibaren beş iş günü içinde Kurum'a bildirilmesidir (KVKK m.9/5).
Barındırma ve depolama sürekli ve düzenli bir aktarım olduğu için m.9/6'daki "arızi haller" istisnasına dayanmıyoruz; bu istisna bizim durumumuzda kullanılamaz.
Sunucularımız Hetzner Online GmbH'de barındırılıyor: Hetzner Online GmbH (Almanya) — sunucumuz Finlandiya'da bulunuyor. Yani hesabınıza ait verinin ana yeri Finlandiya'dır.
Bunun dışında şu kanallarda Amerika Birleşik Devletleri'ne de veri gidiyor ve bunu saklamıyoruz: profil fotoğrafı depolaması (Cloudflare), reklamlar (Google AdMob), mağaza satın almaları (Google, Apple) ve e-posta gönderimi (Google).
Şeffaflık notu: Veri sorumlusu Türkiye'de yerleşiktir ve sunucuya Türkiye'den yönetim ve destek amacıyla erişir.
Profil fotoğraflarınız Cloudflare'in nesne depolama hizmetinde tutulur: Cloudflare, Inc. (ABD) — küresel altyapı; profil fotoğrafları belirli bir ülkeye sabitlenmemiştir. Aktarımda ve saklamada şifrelenir.
Bu bir güvenlik açığı beyanı değil, bir coğrafya beyanıdır: depolama şifrelidir, ama depolama alanı belirli bir yargı bölgesi seçilmeden oluşturulduğu için fotoğrafların hangi ülkede tutulduğunu size taahhüt edemeyiz. Bu nedenle "fotoğraflarınız Avrupa Birliği'nde saklanır" demiyoruz — söyleyemediğimiz bir şeyi yazmayız.
Cloudflare bir ABD şirketidir; ABD makamlarının veri taleplerine tabi olabilir. KVKK m.9 standart sözleşmesindeki "aktarılacak ülke" alanının bu belirsizlik nedeniyle doldurulamaması ayrıca §7.1'deki avukat notunun konusudur.
Uygulamada yalnız ödüllü reklam var: reklamı siz kendi isteğinizle, karşılığında bir ödül almak için başlatırsınız. Ekranınıza kendiliğinden açılan banner, geçiş reklamı veya açılış reklamı yok. Reklam izlemeden uygulamanın tamamını kullanabilirsiniz.
Reklamları Google AdMob sunar. AdMob'un yazılım bileşeni (SDK) kendi başına veri toplar: reklam kimliğiniz, IP adresiniz, cihaz ve işletim sistemi bilgileriniz, reklamla etkileşiminiz. Bu veriyi biz görmüyoruz; Google bu işleme bakımından bizim veri işleyenimiz değil, bağımsız bir veri sorumlusudur. Bu nedenle "reklam için kişisel veri işlenmiyor" gibi bir cümle yazmıyoruz — doğru olmaz.
Ödül doğrulaması: Ödülün gerçekten kazanıldığını istemciye değil sunucuya doğrulatan mekanizma etkinleştirildiğinde, reklam isteğine hesap numaranız eklenir ve Google üzerinden sunucumuza geri döner. Yani bu durumda hesap numaranız Google tarafına geçer. Bu numarayı kısa ömürlü ve tek kullanımlık bir jetonla değiştirmek düzeltme listemizde.
Onay ve kişiselleştirme. Ödüllü reklamlar, uygulamanın yayınlandığı tüm ülkelerde gösterilir. Reklamların kişiselleştirilmesi için açık rızanız gerekir. Rıza vermezseniz veya sonradan geri alırsanız reklamlar kişiselleştirilmeden gösterilmeye devam eder — ödül hakkınız kapanmaz. Reklam tercihi ekranı yayına girene kadar reklamlar kişiselleştirilmeden gösterilir.
Reklamsız erişim satın almak, rıza vermenin alternatifi değildir; ikisi birbirinden bağımsızdır.
Rızanızı her zaman geri alabilirsiniz: uygulama içindeki reklam ve gizlilik tercihleri girişinden seçiminizi değiştirebilirsiniz. Geri almak, vermek kadar kolaydır ve geri alma reklam isteklerine derhal yansır.
Worvento 16 yaş ve üzeri kullanıcılar içindir. 16 yaşından küçükseniz hesap açmayın ve uygulamayı kullanmayın.
Kayıt sırasında doğum tarihinizi soruyoruz ve 16 yaşından küçük hesap açılışını sunucuda engelliyoruz. Doğum tarihini yalnız bu yaş kontrolü, uygulama içi satın alma ehliyeti ve mağaza yaş derecelendirmesiyle tutarlılık için tutuyoruz; profilinizde gösterilmez ve kimseyle paylaşılmaz.
Dürüst not: Bu bir öz-beyandır. Yanlış tarih giren birini teknik olarak ayırt edemiyoruz. Bir hesabın 16 yaşından küçük birine ait olduğunu öğrenirsek:
16 yaşından küçük olduğunu düşündüğünüz bir hesabı worvento.info@gmail.com adresine bildirebilirsiniz.
Aşağıdakiler uygulamada gerçekten uygulanan tedbirlerdir. Uygulamadığımız bir tedbiri buraya yazmadık.
düz metin değil, tek yönlü özet olarak tutulur ve 15 dakikada geçersizleşir.
geçici olarak kilitlenir (varsayılan 15 dakika).
istemci değil sunucu verir; istemcinin "kazandım" demesine güvenilmez.
Keystore tabanlı depo, iOS'ta Anahtar Zinciri) tutulur.
üretilmiş bir numara kullanıyoruz. Uygulamada analitik veya çökme raporlama bileşeni yok.
geçer; tek dokunuşla silinemez.
Dürüst sınırlar. Hiçbir sistem yüzde yüz güvenli değildir. Ayrıca bilinen iki eksiğimizi saklamıyoruz:
mesajı metni düz metin olarak yer alabilir. Bu nedenle "kodlarınız yalnızca size gönderilir" gibi bir cümle yazmıyoruz. Bu kusuru gidermek düzeltme listemizin en üstünde.
bulunmuyoruz; böyle bir düzeneği gösteremiyoruz.
jetonun ara sunucuların erişim kayıtlarında görünmesine yol açabilir. Bunu jetonun başlık alanında taşımaya geçirmek düzeltme listemizde.
Haklarınız 6698 sayılı Kanun'un 11. maddesinde sayılıyor. Nerede yaşadığınıza bakmadan aynı kanaldan aynı hakları kullanabilirsiniz: worvento.info@gmail.com.
Veri sorumlusuna başvurarak:
a) kişisel verinizin işlenip işlenmediğini öğrenme, b) işlenmişse buna ilişkin bilgi talep etme, c) işlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme, ç) yurt içinde ve yurt dışında verinin aktarıldığı üçüncü kişileri bilme, d) eksik veya yanlış işlenmişse düzeltilmesini isteme, e) KVKK m.7'deki şartlar çerçevesinde silinmesini veya yok edilmesini isteme, f) (d) ve (e) kapsamındaki işlemlerin verinin aktarıldığı üçüncü kişilere bildirilmesini isteme, g) münhasıran otomatik sistemlerle analiz edilmesi sonucu aleyhinize bir sonuç doğmasına itiraz etme, ğ) kanuna aykırı işleme nedeniyle zarara uğramanız hâlinde zararın giderilmesini talep etme
hakkına sahipsiniz.
Nasıl başvurulur. Aşağıdaki kanallardan biriyle:
(Veri Sorumlusuna Başvuru Usul ve Esasları Hakkında Tebliğ m.5'in saydığı kanallardan biridir; posta adresi yayımlanmadığı için yazılı başvurular da bu kanaldan alınır),
göndererek.
Kayıtlı elektronik posta (KEP) adresimiz yok. Tebliğ KEP adresi edinmeyi zorunlu tutmuyor; yukarıdaki üç kanal açıktır ve başvurunuz bunlardan biriyle geçerli şekilde yapılır.
Başvurunuzda ad-soyadınız (yazılı başvuruda imzanız), T.C. kimlik numaranız (yabancı iseniz uyruk ile pasaport veya kimlik numaranız), tebligata esas yerleşim yeri veya iş yeri adresiniz, varsa bildirime esas e-posta adresiniz ile telefon numaranız ve talep konunuz bulunmalıdır. Konuya ilişkin belgeleri de ekleyebilirsiniz.
Başvuru dili: Veri Sorumlusuna Başvuru Usul ve Esasları Hakkında Tebliğ m.5 başvurunun Türkçe yapılmasını öngörür. Buna rağmen İngilizce başvuruları da kabul ediyoruz.
Süre ve ücret. Başvurunuzu en kısa sürede ve en geç 30 gün içinde sonuçlandırıp yazılı veya elektronik olarak yanıtlarız. Yanıt kural olarak ücretsizdir. İşlem ayrıca bir maliyet gerektiriyorsa Kurul tarifesi uygulanır: yazılı yanıtta ilk 10 sayfa ücretsizdir, 10 sayfanın üzerindeki her sayfa için 1 TL işlem ücreti alınabilir; CD veya taşınabilir bellek gibi bir kayıt ortamında verilecekse kayıt ortamının maliyeti talep edilebilir. Hata bizden kaynaklanıyorsa alınan ücret iade edilir.
Kurul'a şikâyet. Başvurunuz reddedilirse, yanıtı yetersiz bulursanız veya süresinde yanıt alamazsanız; yanıtı öğrendiğiniz tarihten itibaren 30 gün ve her hâlde başvuru tarihinden itibaren 60 gün içinde Kişisel Verileri Koruma Kurulu'na şikâyette bulunabilirsiniz (KVKK m.14). Kurum'un internet adresi: https://www.kvkk.gov.tr
Rızaya dayanan iki işleme var ve ikisini de her zaman geri alabilirsiniz:
seçiminizi değiştirin. (Bu ekran yayına girene kadar reklamlar zaten kişiselleştirilmeden gösterilir.)
Geri alma ileriye etkilidir: geri aldığınız andan sonra o işlemeye devam etmeyiz, ama o ana kadar yapılmış işleme hukuka aykırı hâle gelmez. Geri almak, vermek kadar kolaydır.
hesap olmadan kullanılamaz.
gönderilmezse davet kodu sınırı ve çoklu hesap tespiti çalışmaz.
hiçbir kısıtlama olmaz.
Aşağıdaki süreler kodda gerçekten tanımlı olanlardır. Kodda süre tanımlı olmayan kalemler için uydurma bir sayı yazmıyoruz; "hesabınız açık kaldığı sürece" diyoruz ve silme talebi yolunu gösteriyoruz.
| Veri | Süre |
|---|---|
| Sunucu logları | 7 günlük dosya döngüsü (dosya sayısı sınırı 7). Konsol çıktısının saklama süresi kodda tanımlı değildir |
| Günlük aktivite ısı haritası | 400 gün; pencerenin dışına düşen günler her eşitlemede budanır |
| Erişim jetonu (JWT) | 7 gün |
| Oturum yenileme jetonu | 30 gün geçerli; süresi geçmiş kayıt satırı silinmez |
| E-posta doğrulama, şifre sıfırlama ve hesap silme kodları | 15 dakika |
| Aktif maç anlık görüntüsü | 6 saatten eskiler saatlik temizlenir |
| Sınav oturumu (hızlı bellek) | Oturum 1 saat, kullanıldı işareti 6 saat |
| Canlı bağlantı kaydı (presence) | 12 saat; her bağlantıda tazelenir |
| Canlı maç durumu (hızlı bellek) | 6 saat |
| Profil fotoğrafının içerik ağı önbelleği | 1 yıl ve değiştirilemez işaretli — bu nedenle fotoğrafı sildikten sonra bir kopyası bir süre daha erişilebilir kalabilir |
| Diğer her şey | Kodda tanımlı değil — hesabınız açık kaldığı sürece. Silme talebi için §12.2 |
İmha yöntemimiz. Süresi dolan veya silinmesi gereken kayıtlar için kullandığımız yöntemler şunlardır: veritabanı kayıtları silinir (satır kaldırılır); profil fotoğrafı nesneleri depolama alanından silinir; cihazdaki kayıtlar için silme, uygulamanın yerel deposundan kaldırma yoluyla yapılır; log dosyaları döngü dolduğunda üzerine yazılarak yok edilir; hızlı bellekteki (Redis) kayıtlar süre dolduğunda kendiliğinden düşer. Anonim hale getirme yöntemini şu an hiçbir kalem için kullanmıyoruz; satın alma kayıtlarında hesap numarasını tanınamaz hâle getirmek düzeltme listemizde ve yapıldığında bu bölüm güncellenecektir.
Bilinen ve düzeltmeyi planladığımız durumlar: günlük lig satırları, süresi geçmiş oturum yenileme kayıtları, süresi dolmuş meydan okuma zarfları, reklam ödülü işlem kayıtları, ortak listedeki "silindi" işaretli kelimeler ve IP adresleri için kodda bir temizlik işi yoktur. Bunları gerçekte olduğu gibi yazıyoruz.
Nasıl silinir. Uygulama içinde Ayarlar bölümünden: (1) parolanızı girerek talep başlatılır, (2) e-posta adresinize bir kod gönderilir, (3) kodu girerek onaylarsınız. Tek dokunuşla silme yoktur; bu bilinçli bir güvenlik tercihidir. Uygulamayı kurmadan silme talebinde bulunmak için web sayfamızı kullanabilirsiniz: https://worvento.com/legal/veri-silme
Gerçekten silinenler. Hesap kaydınız (kullanıcı adı, e-posta adresi, parola özeti, XP, altın, rozetler, seriler, ısı haritası, IP adresleri, cihaz kimliği, kurulum kimliği, tercihler, pet, kozmetikler, sezon ve görev durumu bu kaydın alanlarıdır) ile birlikte: arkadaşlık kayıtları, engelleme kayıtları, taraf olduğunuz şikâyetler, oturum yenileme jetonları, günlük lig satırları, 60 saniye sonuçları, boss sonuçları, günün kelimesi sonuçları, wordle sonuçları, mini çengel sonuçları, kule koşuları, pet kaydı, davet kodunuz, ortak liste üyelikleriniz ve profil fotoğrafı nesneleri (elimizden geldiği ölçüde).
Silinmeyenler — dürüst liste. Aşağıdaki kayıtlar hesap kaydınıza teknik olarak bağlı olmadığı için hesabınız silindiğinde veritabanında kalır:
Ayrıca:
kalır.
kalır.
Bu listeyi kısaltmak — kayıtları hesap silmeye gerçekten bağlamak ve mali kayıtlarda hesap numarasını tanınamaz hâle getirmek — düzeltme listemizin en üstünde. Liste kısaldığında bu bölüm de kısalacak. Metnimizi koda uyduruyoruz.
Satın alma kayıtları, vergi ve muhasebe mevzuatı gereği en az 5 yıl saklanır (Vergi Usul Kanunu m.253).
Kendi kelime listenizi uygulama içinden CSV olarak dışa aktarabilirsiniz. Diğer verileriniz için worvento.info@gmail.com adresine yazın; §11'deki süre içinde yanıtlarız.
Size verebileceğimiz şey, bize verdiğiniz ve hesabınıza bağlı olarak tuttuğumuz veridir. Şunlar bu kapsamda değildir — bu yüzden "tüm verilerinizi indirebilirsiniz" demiyoruz:
(cihaz kimliği eşleşmeleri, çoklu hesap sinyalleri, moderasyon gerekçeleri),
aralığı katsayıları).
Kişisel verinizin hukuka aykırı olarak başkalarının eline geçtiğini öğrenirsek:
Türkiye — KVKK m.12/5. İhlali öğrendiğimiz andan itibaren gecikmeksizin ve en geç 72 saat içinde Kişisel Verileri Koruma Kurulu'na bildiririz (Kurul'un 24.01.2019 tarihli 2019/10 sayılı kararı). 72 saati aşarsak gecikmenin gerekçesini Kurul'a sunarız. Etkilenenleri belirledikten sonra makul olan en kısa sürede size doğrudan (e-posta veya uygulama içi bildirim) haber veririz; size ulaşamıyorsak internet sayfamızda ilan ederiz. Bildirimde ihlalin ne zaman gerçekleştiğini, hangi veri kategorilerinin etkilendiğini, olası sonuçlarını, aldığımız tedbirleri ve iletişim bilgilerimizi belirtiriz.
Kurul'a bildirilmeyenler dâhil tüm ihlalleri, gerekçesiyle birlikte iç kayıt defterimizde tutuyoruz. İhlal müdahale adımlarımız ayrı bir iç belgede yazılıdır.
Uygulamada birkaç karar insan müdahalesi olmadan verilir:
| Otomatik karar | Nasıl çalışır | Sonucu |
|---|---|---|
| Çoklu hesap sinyali | Aynı cihaz kimliğinde eşikten fazla hesap görülürse uyarı kaydı üretilir | Kayıt engellenmez; kayıt tutulur ve moderasyona girdi olur |
| Ban yayılımı | Bir hesap askıya alınırken aynı cihazdaki diğer hesaplar tespit edilir | Aynı cihazdaki hesaplar da askıya alınabilir |
| XP ve ödül tavanları | Günlük kabul tavanı aşılırsa fazla XP kabul edilmez ve uyarı kaydı yazılır | Ödül verilmez |
| Hesap kilidi | Belirli sayıda başarısız giriş denemesinden sonra hesap geçici kilitlenir | Varsayılan 15 dakika giriş yapılamaz |
| Davet kodu cihaz sınırı | Aynı cihazdan belirli sayıdan fazla davet kodu kullanımı engellenir | Kod kullanılamaz |
| Sınav ve maç doğrulaması | Ödülün oturum imzasıyla uyuşup uyuşmadığı kontrol edilir | Uyuşmazsa ödül verilmez |
Bu kararların mantığı yukarıda özetlenmiştir; hedef, aynı kişinin çok sayıda hesapla ödül ve davet sistemini sömürmesini engellemektir.
Haklarınız. Bir hesap askıya alma veya ödül reddi kararı sizi etkiliyorsa:
Talebinizi worvento.info@gmail.com adresine yazın; §11'deki süre içinde yanıtlarız. KVKK m.11/1-g size, münhasıran otomatik analiz sonucu aleyhinize bir sonuç doğmasına itiraz hakkı tanır.
Profil fotoğraflarına otomatik görüntü analizi uygulanmıyor; yüz tanıma yapmıyoruz.
Kullanıcıların en çok sorduğu şeyleri kısaca ve dürüstçe yanıtlıyoruz. Şunları toplamıyoruz: GPS veya ağ tabanlı konumunuz, rehberiniz veya kişi listeniz, telefon numaranız, cinsiyetiniz, sağlık ve fitness verileriniz, mikrofon kaydı veya sesiniz, kamera akışınız, takviminiz, SMS'leriniz, arama kaydınız, biyometrik işleme (yüz tanıma yapmıyoruz), cihazınızda kurulu uygulamaların listesi, panonuzun içeriği, ödeme kartı veya IBAN bilgileriniz. Uygulamada analitik veya çökme raporlama bileşeni yok; sosyal ağ hesabıyla giriş (federated giriş) yok. Donanım kimliği (IMEI, MAC adresi, seri numarası) okumuyoruz.
İstisnalar, dürüstçe: (1) Konum toplamıyoruz ama saat dilimi farkınızı işliyoruz ve bu kaba bir coğrafi çıkarım yapmaya yeter. (2) Doğum tarihinizi kayıt sırasında alıyoruz (16 yaş kontrolü — §9). (3) Bildirimlere izin verirseniz cihazınızın bildirim jetonu işlenir (§3'teki bildirim tablosu). (4) IP adresiniz bize gelir; bağlantı kontrolü de yalnız kendi sunucumuza gider (§6.4'te anlatılan dört üçüncü taraf aktarımı kaldırıldı).
Bu politikayı, uygulamada işlenen veri veya işleme amaçları değiştiğinde güncelleriz. Amaç değişikliğinde, yeni işleme başlamadan önce sizi bilgilendiririz. Her sürümün başında sürüm numarası, yürürlük tarihi ve son güncelleme tarihi bulunur. Önemli değişikliklerde uygulama içinde veya e-posta ile ayrıca haber veririz.
Sorularınız için: worvento.info@gmail.com Destek için: worvento.info@gmail.com Her tür başvuru (yazılı dâhil): worvento.info@gmail.com
Version: 1.0 · Effective: 8 August 2026 · Last updated: 8 August 2026
This is an information-only English translation. In case of any conflict, the Turkish original prevails.
This policy applies to the mobile application Worvento (Android package name com.worvento.app) and to the server service at https://api.worvento.com.
We explain three things here: what data of yours we process, why we process it, and how long we keep it. We tried to keep it short, but we did not water it down. We have not claimed more — or less — than the application actually does; every statement was written by comparing it against the source code.
This document is published in Turkish and English. The translation is for information only; in case of any conflict the Turkish text prevails.
Distribution territory. Worvento is not distributed in the European Union / European Economic Area, the United Kingdom, Switzerland, Japan, South Korea, China or Saudi Arabia, and is not directed at users in those countries. This policy is therefore written on the basis of Turkish law — in particular Law No. 6698 on the Protection of Personal Data. The EU General Data Protection Regulation (GDPR) and its United Kingdom counterpart are outside the scope of this text.
If you are in a hurry, read only this table. The sections below are the detail behind the same facts — the full disclosure needed for audits, store forms and legal requests lives there.
| Question | Short answer |
|---|---|
| Who processes the data? | The Türkiye-based publisher of Worvento (a natural person) — worvento.info@gmail.com (§1) |
| What data? | Account details, learning progress, gamification/economy, social interactions, purchase records, security records, an optional photo, advertising identifier (§2, §3) |
| Why? | To provide the service (contract), to prevent abuse (legitimate interests), financial records (legal obligation), photo and personalised advertising (explicit consent) — §2 |
| Do you sell my data? | No. But we do share a limited set with a limited number of recipients in order to run the service: hosting, photo storage, advertising, store payments, e-mail and notification delivery (§6) |
| What can other people see? | Username, XP, level, badges, activity heat map, avatar, last-seen status, match results — there is no setting to leave the leaderboard (§4) |
| Where is it stored? | The server is in Finland (Hetzner); photos sit on Cloudflare's global infrastructure and are not pinned to any specific country (§7) |
| For how long? | Logs 7 days, heat map 400 days, codes 15 minutes; for most items no retention period is defined in code → for as long as your account exists (§12.1) |
| If I delete my account? | Your account record and the tables linked to it are deleted; 12 categories of records and the local data on your device are not — full list in §12.2 |
| My rights? | The rights in Article 11 KVKK; requests are concluded within 30 days at the latest — worvento.info@gmail.com (§11) |
| Age limit? | 16+ (§9) |
Worvento is operated by an individual (a natural person). There is no company behind it; responsibility rests directly with the person named below.
| Data controller | The Türkiye-based publisher of Worvento (a natural person) — the "Publisher" in this document |
| E-mail for data protection requests | worvento.info@gmail.com |
| Support e-mail | worvento.info@gmail.com |
| Website | https://api.worvento.com |
Data protection contact point: worvento.info@gmail.com. No separate data protection officer has been appointed; the KVKK does not require such an appointment, and in a one-person operation a separate officer would not produce a practical counterpart. All requests reach the address above.
Registration with the Turkish data controllers' registry (VERBİS): This policy makes no claim that we are registered with VERBİS.
Worvento is published in some countries outside Türkiye (other than those listed under Distribution territory above). Some of those countries have their own data protection laws — for example Brazil (LGPD), India (DPDP), Canada (PIPEDA) and the United Arab Emirates (PDPL). This policy was written on the basis of Law No. 6698; in matters of transparency, your rights and the deletion of your data it meets what those laws require in substance, but it does not contain country-specific chapters. Wherever you are, the request channel is the same: worvento.info@gmail.com.
If you live in the United States: we are far below the annual revenue (USD 25 million) and consumer-count (100,000) thresholds of the California statutes (CCPA/CPRA) and comparable state laws, so we are out of their scope. On the point that matters most under those laws — the sale of data — our position is unambiguous in any case: we do not sell your personal data (§6.3).
| What we process | Why | Legal basis | How long we keep it | Visible to others |
|---|---|---|---|---|
| Username, e-mail address, password (hashed) | To create your account and authenticate you | KVKK Art. 5/2-c | As long as your account exists | Username: yes · E-mail: no |
| Learning data (word review schedules, right/wrong answers, category progress) | To teach vocabulary and compute review timing | KVKK Art. 5/2-c | As long as your account exists | No |
| XP, level, streak, badges, activity heatmap, game scores | Gamification, leaderboard, league, season | KVKK Art. 5/2-c | Heatmap 400 days · others, account lifetime | Yes (leaderboard and profile) |
| Gold, jokers, cosmetics, pet, quest and season state | To run the in-app economy on the server | KVKK Art. 5/2-c | As long as your account exists | Partly (equipped look, premium crown) |
| Friendships, gifts, blocks, duel and match results, shared lists | To operate the social features | KVKK Art. 5/2-c | As long as your account exists | Yes (to the people involved) |
| Purchase record (product ID, store transaction number) | To deliver what you bought, handle refunds, keep financial records | Delivery: KVKK Art. 5/2-c — Financial record: KVKK Art. 5/2-ç | The period required by tax legislation (see §12) | No |
| IP address, device identifier, install identifier, failed-login counter | To prevent multi-account abuse, referral-code abuse and brute-force attacks | KVKK Art. 5/2-f | No period defined in code (see §12) | No |
| Advertising identifier and ad telemetry (collected by Google AdMob) | To serve rewarded ads | KVKK explicit consent | Per Google's retention periods | No |
| Optional profile photo | To show an avatar on your profile and in lists | KVKK explicit consent | Until you remove it, delete your account, or 30 days after your premium entitlement ends — whichever comes first (see §5, §12) | Yes (thumbnail, to everyone) |
| Verification, password-reset and account-deletion codes | To verify your identity and critical actions | KVKK Art. 5/2-c and 5/2-f and 6(1)(f) | 15 minutes | No |
| Server operational logs | To detect errors and attacks | KVKK Art. 5/2-f | 7-file rolling window (7 days) | No |
| Your support message | To answer your question | KVKK Art. 5/2-c | In the support mailbox; no period defined in code | No |
Collection method: All of the above is obtained by fully automated means — through the connection between the app and our server — while you use the application. We have no other source such as paper forms, call centres or purchased data. We do not buy any data from data brokers or third parties.
What "legitimate interest" means here: The only rows relying on KVKK Art. 5/2-f concern security and abuse prevention. Concretely, our interest is: preventing one person from opening dozens of accounts to farm rewards and referral codes, stopping brute-force attempts against your account, and keeping the server available. You have the right to object to this processing (see §11).
The lists below are derived from the application's source code. Each row carries four pieces of information: which data, for which purpose, on which legal basis, for how long.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Username (max 50 characters, unique) | Account identity; shown on leaderboards, friend lists, duels, leagues and gift screens | KVKK Art. 5/2-c | Account lifetime |
| E-mail address | Login identity; delivery of verification, password-reset and account-deletion codes; support replies | KVKK Art. 5/2-c | Account lifetime. Note: your e-mail address is also carried as a field inside the session token (JWT) |
| Password | To authenticate you; identity confirmation when deleting your account | KVKK Art. 5/2-c | Your password is never stored in clear text; only a one-way BCrypt hash is kept |
| Hash of the e-mail verification code, time sent, attempt counter | To verify the account is tied to a real e-mail address; gate for rewards and competitive features | KVKK Art. 5/2-c | Code validity 15 minutes |
| Hash of the password-reset code, time, attempt counter | To run the password-reset flow | KVKK Art. 5/2-c and 5/2-f and 6(1)(f) | 15 minutes |
| Hash of the account-deletion code, time, attempt counter | To confirm account deletion in two steps | KVKK Art. 5/2-c and 5/2-f and 6(1)(f) | 15 minutes |
| Access token (JWT) | To carry your identity on each request | KVKK Art. 5/2-c | Valid 7 days; not stored on the server |
| Refresh token | To keep the session beyond 7 days; to revoke sessions on logout or ban | KVKK Art. 5/2-c | Valid 30 days. Honest note: expired records are not deleted from the database; the row remains |
| Language preferences, daily XP goal, onboarding completion state | To skip language selection and the tutorial on a second device; to render match content in the right language | KVKK Art. 5/2-c | No period defined in code — account lifetime |
| Time-zone offset (minutes) | So daily allowances reset at your local midnight | KVKK Art. 5/2-c | Overwritten on each launch |
| Notification token, device platform, interface language | So we can send you notifications | KVKK Art. 5/2-f | Deleted on sign-out; gone when the account is deleted |
| Your notification preference (friend/game notifications on or off) | So the server does not send when you have switched them off | KVKK Art. 5/2-f | For the life of the device record |
| The quiet-hours range you choose | So notifications are not sent during the hours you set | KVKK Art. 5/2-f | For the life of the device record |
An honest note about the time zone: We do not collect your GPS or network-based location. But your time-zone offset is enough for a coarse geographic inference (for example, "UTC+3" narrows down your continent). We are not hiding this behind the sentence "we do not collect location".
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Per-word review state (stability, difficulty, repetitions, lapses, next due time) | To run the spaced-repetition algorithm; weekly report | KVKK Art. 5/2-c | No period defined in code. Honest note: these records are not deleted when you delete your account (see §12.2) |
| Word mastery flags | Collection album, golden words, pet stage | KVKK Art. 5/2-c | No period defined in code. Not deleted on account deletion |
| Confusion pairs (which two words you mix up) | Personalised error analysis and drill suggestions | KVKK Art. 5/2-c | No period defined in code. Not deleted on account deletion |
| Correct/incorrect answer counters | Progress and badge calculation | KVKK Art. 5/2-c | Account lifetime |
| Study session records (exam session signature) | To verify a reward was genuinely earned | KVKK Art. 5/2-f | Session 1 hour, consumed marker 6 hours |
| Words you add yourself (MyList) | To study your own list | KVKK Art. 5/2-c | Stored on your device (see §5) |
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Total XP, level, current streak, highest streak | Progress, leaderboard, league, season | KVKK Art. 5/2-c | Account lifetime |
| Daily activity (heatmap) log | Consistency calendar | KVKK Art. 5/2-c | 400 days; days outside this window are pruned on each sync |
| Badges (up to 200 badge IDs) | Achievement display | KVKK Art. 5/2-c | Account lifetime |
| Gold, jokers, cosmetic ownership, equipped frame and avatar | Server-side economy | KVKK Art. 5/2-c | Account lifetime |
| Streak repair allowance and shield state | To prevent abuse of the streak-repair allowance | KVKK Art. 5/2-c and 5/2-f and 6(1)(f) | Account lifetime |
| Daily allowance counters (ads, wheel, exams, study, login bonus) | To enforce daily caps; cool-down against automation | KVKK Art. 5/2-c and 5/2-f and 6(1)(f) | Reset at your local midnight |
| Season points, season ID, season premium state, daily and weekly quests | Season progress and quests | KVKK Art. 5/2-c | Reset on season change |
| XP sync audit counters | To block forged XP submissions | KVKK Art. 5/2-f | Reset on day change |
| Daily league XP rows | "Winners of the Day" ranking | KVKK Art. 5/2-c | No cleanup in code — rows from past days are not deleted (see §12.1) |
| Daily contest results (60-second blitz, wordle, mini crossword, word of the day, boss, tower run) | One-attempt-per-day rule, score tables, streaks | KVKK Art. 5/2-c | No period defined in code |
| Pet (Word Companion) state and the pet name you type | To sync the pet economy across devices | KVKK Art. 5/2-c | Account lifetime |
| Reward idempotency key lists | To prevent the same reward being granted twice | KVKK Art. 5/2-f | No period defined in code |
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Friendship records (request, acceptance, dates) | Friend list; permission for duels, gifts and live matches | KVKK Art. 5/2-c | Account lifetime |
| Users you block | To cut off interaction | KVKK Art. 5/2-c | Account lifetime |
| Your report record: free-text reason (max 500 characters), reported person, date, outcome | Moderation | KVKK Art. 5/2-f | No period defined in code. Visible in the admin screen together with the usernames of both the reporter and the reported person. Do not write sensitive information about third parties in this field |
| Gifts you received and the sender's username | Gift history and reputation | KVKK Art. 5/2-c | History is not pruned. Honest note: if the sender deletes their account, their username remains in your record |
| Gift showcase, reputation points, owned gifts | Profile showcase | KVKK Art. 5/2-c | Account lifetime |
| Duel, live challenge and hangman results | "Matches between you", recent matches list | KVKK Art. 5/2-c | No period defined in code. Not deleted on account deletion |
| Challenge envelopes (24-hour asynchronous game invitation, word list and scores) | To challenge a friend to a mini game | KVKK Art. 5/2-c | Marked "expired" when it lapses; the row is not deleted. Not deleted on account deletion |
| Shared word lists (max 4 people): list name, member usernames, the custom words you write | Shared study list | KVKK Art. 5/2-c | Deleting a word only sets a "deleted" flag. No job in the code clears these flags; the record is permanent |
| Your referral code and the referral code you used | Refer-a-friend campaign; per-device referral limit | KVKK Art. 5/2-c and 5/2-f and 6(1)(f) | Account lifetime |
| Last-seen time (presence) | "Online / last seen" indicator in friend lists | KVKK Art. 5/2-c | Last value kept; live connection records 12 hours |
| Live match snapshot: usernames, the answers you gave, the letters you tried, target word | So an in-progress match is not lost if the server restarts | KVKK Art. 5/2-c | Rows older than 6 hours are pruned hourly; in-memory copy 6 hours |
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Store transaction number, product ID, platform, gold granted, first-purchase bonus, refund state | To prevent granting a reward twice for the same receipt; to process refunds | Delivery: KVKK Art. 5/2-c — Financial record: KVKK Art. 5/2-ç | No period defined in code; not deleted on account deletion (see §12.2) |
| Receipt verification data (purchase token) | To verify the purchase with the store | KVKK Art. 5/2-c | Not stored permanently; written only as an idempotency key when no transaction number is available |
| Entitlement record (ad-free access, time pack) | To recognise the entitlement you bought | KVKK Art. 5/2-c | Expired records are not deleted; not deleted on account deletion |
Your payment details never reach us. We do not see or store card numbers, IBANs, billing addresses or tax details. Payment is collected by Google (Play) or Apple (App Store); we only receive the product ID and the store's transaction number.
| Data | Purpose (our legitimate interest) | Legal basis | Retention |
|---|---|---|---|
| Registration IP address, last login IP address | To notice one person opening many accounts; to apply rate limits | KVKK Art. 5/2-f | No deletion or masking job in the code |
| Device identifier (a random number generated by the app) | Per-device account limit; stopping referral-code abuse; ban propagation | KVKK Art. 5/2-f | No period defined in code |
| Install identifier (random number) | To distinguish "same device, different install" | KVKK Art. 5/2-f | No period defined in code |
| Failed-login counter, account lockout period | To stop brute-force and credential-stuffing attempts | KVKK Art. 5/2-f | Reset on successful login; lockout defaults to 15 minutes |
| Administrator status, account suspension state | Moderation | KVKK Art. 5/2-f | Account lifetime |
| Server operational logs (request method, path, status code, duration) | Debugging, attack detection | KVKK Art. 5/2-f | 7-file rolling window (7 days) |
| Multi-account warning log (device identifier, username, IP) | Abuse analysis | KVKK Art. 5/2-f | 7-file rolling window |
| Ban log (user number, other accounts on the same device) | Moderation trail | KVKK Art. 5/2-f | 7-file rolling window |
An honest note about the device identifier: This identifier is not read from your phone's hardware — it is a random number generated when the app is installed and stored on the device. We do not read IMEI, MAC address, serial number or the advertising identifier. It is deleted when you uninstall the app (the same on iOS and Android), so it is a resettable identifier.
It used to be kept in the iOS Keychain and survived app deletion. That changed on 2026-08-12: the identifier now goes away with the app data, and any leftover Keychain record is purged. We know the cost — someone who reinstalls looks like a new device to us — and we accepted that cost in your favour.
An honest note about IP addresses: The IP address we record may not always be reliable; owing to a gap in the reverse-proxy configuration, this value can be influenced by the client. Fixing this is on our remediation list.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Advertising identifier (AAID on Android, IDFA on iOS), IP address, device and OS information, ad interaction | Serving rewarded ads, measurement, invalid-traffic detection | KVKK explicit consent (Art. 5/1) | Per Google's retention periods — it does not enter our database |
| Reward verification data: store transaction number and your account number | So the server, not the client, grants the reward (the client's claim that it "watched" is not trusted) | KVKK Art. 5/2-f | The ad reward transaction record is not deleted; not deleted on account deletion either |
For details, see §8.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Subject and full text of your support message, your username, account number and e-mail address | To answer your question | KVKK Art. 5/2-c | The message is not written to the database; it is sent by e-mail to the support mailbox and remains there. No deletion period is defined in the code |
| Content of outgoing e-mails (verification code, password-reset code, account-deletion code, password-change notice) | To verify account actions | KVKK Art. 5/2-c | The e-mail remains in Google's e-mail infrastructure and in your mailbox |
We do not send you marketing e-mails. The e-mails above are service notifications; they are not commercial electronic communications within the meaning of Turkish Law No. 6563. If we start sending campaign or discount announcements, we will ask for your consent separately.
We do send operating-system-level notifications. They are split into two groups that are turned on and off separately, and both can be disabled under Settings → Notifications:
friend requests, invitation acceptances, match results, gifts. These are sent by our server, which requires storing a notification token for your device (Firebase Cloud Messaging registration), the device platform and your interface language. The token is deleted when your account is deleted and removed when you sign out.
Notifications travel through Google — we state this plainly. The notification is delivered to your device not by us but by Google's Firebase Cloud Messaging infrastructure. This means both your token and the title and body of the notification pass through Google's servers, and that is a transfer abroad (§6). The body of some notifications contains another user's username — "X accepted your invitation", "your match with X has ended". We put nothing else in the notification text (no message content, no scores, no email address).
turn them off with a single tap in Settings > Notifications) — streak reminders, your word companion's feeding time, practice suggestions during the day. These are scheduled and triggered on your device; neither their content nor their timing reaches our server, and the server is not aware of them.
Our limits: we send at most two reminders per day, and we cancel the rest of the day's reminders if you have used the app that day. If you do not open our notifications for a long time, we stop the reminders automatically.
Quiet hours. You can choose a time range in which you want no notifications (default 22:00 – 08:00; you can change it or switch it off). Because notifications sent from the server must respect that range too, the range you choose is stored on our server — as part of your device record, together with your time-zone offset. Likewise whether you keep friend and game notifications on or off is stored on the server; otherwise the server could not know it was off and would still send.
These two pieces of information are used only to decide whether a notification may be sent. No profiling is done with them and they go to no third party.
There are two further channels:
delivered instantly over an open connection. While the app is open no notification is posted (you never see the same event twice).
is kept hidden until you answer it; however your streak day count is written on every refresh, and if the widget is visible on your lock screen it can be read by others. There is currently no in-app setting to turn this off.
We wrote this section separately, because it is the most misunderstood topic. The following is visible to other users.
premium crown and rank. There is currently no setting to opt out of the leaderboard. We recommend not using your real name as your username.
opens your profile. There is no setting to hide this.
leaderboard and on your profile.
generated image and goes to the app you choose (messaging, social network, e-mail). Your opponent receives no notification and is not asked for consent. Likewise, if someone shares a match they played with you, your username** goes to the app they choose.
member usernames are visible to the other members.
see who sent a gift.
you", "recent matches").
username.
the match state and appear in your opponent's match flow.
Not visible: your e-mail address, your password, your purchase history, your gold and joker balances, your IP address, your device identifier, your block list, your reports, your pet name, your own word list (MyList), the words you confuse and your review schedules.
An honest note about profile photos: Photos are served over a link whose address is random enough to be unguessable. This is not access control, it is address secrecy: anyone who knows that link can access the photo, even without being logged in. The address of the full-size photo is sent only to you and to premium viewers; but once that address is shared, everyone who has it can continue to access the photo. This is why we do not say "only premium users can see your photo."
Deleting the photo: Uploading a profile photo is a Season Premium right. After your premium entitlement ends, your photo is kept for 30 more days; if premium is not renewed within that window, the photo is deleted from the server (Cloudflare R2) and one of the avatars you own is set on your profile. You can also remove it yourself at any time.
The application keeps some data on your device. This data is not sent to our servers unless stated otherwise.
| Where | What | Why it is needed |
|---|---|---|
| Encrypted secure storage | Session token, refresh token, last login e-mail address, e-mail verification flag, device identifier, last sync snapshot | To keep you signed in; to avoid unnecessary syncs; to prevent abuse |
Local database (words) | Word pool and the words you added yourself (MyList) | So you can study without an internet connection |
Local database (categories, shared_list_cache) | Category unlock state; offline copy of a shared list | Offline reading |
Local database (user_stats) | XP, streak, badges, language, theme, goal, learning counters; plus habit counters that stay only on the device (lunch-break study, weekend, silent test) | Gamification and badge logic |
| Simple preferences store | Install identifier, personal best scores for 12 mini games, tutorial tour flags, celebration and banner flags, pet stage flag | To avoid showing the same screen twice; to display local records |
| Temporary directory | Share card image (PNG) and photo-cropping file | Sharing and photo upload flows |
| App documents directory | my_words_export.csv (backup of your word list) | Backup of your own list |
| Home-screen widget area | Word of the day title, streak day count | Widget display |
| Memory (never written to disk) | Short-lived API response cache (max 1 hour) | To avoid re-fetching the same catalogue data |
Which of these require your consent. Storing information on your device, or accessing information already stored there is divided into four categories following the distinction in the Turkish Personal Data Protection Authority's Guidelines on Cookie Practices:
| Category | Which records | Consent required |
|---|---|---|
| Strictly necessary to provide the service | Session and refresh tokens, last sign-in e-mail address, verification flag, language/theme/goal preferences, word pool and MyList, category box, sync snapshot, short-lived response cache | No — without these, sign-in, offline use and remembering preferences are impossible |
| Abuse prevention | Device identifier, installation identifier | Not consent but legitimate interests (Art. 5(2)(f) KVKK) — the reasoning is kept in writing |
| Advertising | Records written to your device by the Google AdMob software component | Yes for the personalisation of ads — explicit consent (§8) |
| Convenience records | Mini-game high scores, tour and celebration flags, banner flags, pet stage flag, widget area | These never leave your device and are not sent to the server |
The itemised list, with a justification for each key, is in the Cookie and SDK Policy (§17).
What stays on your device after account deletion — the honest list. When you delete your account, the app clears only the sync snapshot and the user_stats store. The following remain on your device:
words),shared_list_cache) and the category store,entire preferences store),
Today the way to clear these is to uninstall the application, which now removes the device identifier as well. Session tokens kept in the iOS Keychain are the remaining exception — those are cleared when you sign out or delete your account.
The table below shows every place your data leaves for. One point to note: our server is in Finland, so seen from Türkiye all of these are transfers abroad — hosting included. That does not mean the data is insecure; but under Article 9 KVKK each of them requires its own legal basis (§7).
| Recipient | Role | Country / contracting party | What is sent | KVKK Art. 9 status | Privacy policy |
|---|---|---|---|---|---|
| Hetzner Online GmbH | processor (hosting) | Hetzner Online GmbH (Germany) — our server is located in Finland. | All data on the server: database, in-memory store, log files | Transfer abroad | https://www.hetzner.com/legal/privacy |
| Cloudflare, Inc. | processor (profile photo storage) | Cloudflare, Inc. (USA) — global infrastructure; profile photos are not pinned to any specific country. They are encrypted in transit and at rest. | Raw bytes of the profile photo; your account number in the object path; the request's IP address | Transfer abroad | https://www.cloudflare.com/privacypolicy/ |
| Google Ireland Ltd / Google LLC (AdMob) | independent controller | Ireland / USA | Advertising identifier, IP address, device and OS information, ad interaction; your account number when reward verification is enabled | Transfer abroad | https://policies.google.com/technologies/partner-sites |
| Google Commerce Ltd (Play Billing) | independent controller; merchant of record in the European Economic Area | Dublin / USA | App package name, product ID, purchase token | Transfer abroad | https://policies.google.com/privacy |
| Apple Distribution International Ltd | independent controller; agent or commissionaire of the developer for App Store transactions | Ireland / USA | Transaction number and a signed verification request | Transfer abroad — applies once the iOS version is released | https://www.apple.com/legal/privacy |
| Google (e-mail delivery — Gmail) | processor in practice | USA / global | Recipient e-mail address, username, verification/password/deletion code, full text of support messages | Transfer abroad | https://policies.google.com/privacy |
| Google LLC (Firebase Cloud Messaging) | processor (notification delivery) | USA / global | Your device notification token, device platform, interface language; the title and body of the notification | Transfer abroad | https://firebase.google.com/support/privacy |
| Your device's text-to-speech engine | independent controller | Depends on the engine installed on your device | The word to be spoken and the language code | Stays on your device; leaves it if the engine uses the cloud | Depends on the engine's provider |
| The app you choose when sharing | independent controller | Your choice | Share card image and text | By your own action | The policy of the app you choose |
The status of the data processing agreements with the recipients above, and how the Article 9 KVKK basis is to be established, is described in §7. You may request a copy of the transfer safeguards: write to worvento.info@gmail.com and we will respond within the period set out in §11.
We do not sell your personal data. We do not rent it and we do not provide it to advertising exchanges, data brokers or scoring companies; there is no recipient from whom we receive money, services or data in return.
At the same time, it would be wrong to say "no data ever leaves". To run the service we pass the following to the recipients listed in §6.1 and §6.2 — and this is the complete list:
| Recipient | Exactly what goes there |
|---|---|
| Google AdMob | Advertising identifier, IP address, device and OS signals, ad interaction; plus your account number when reward verification is enabled |
| Google Play / Apple App Store | Purchase token, product ID, store transaction number (receipt verification) |
| Cloudflare (R2) | The bytes of your profile photo (processor — a service provider) |
| Hetzner | All data on the server, as our hosting provider (processor) |
| Google (e-mail via Gmail) | Your e-mail address, the 6-digit codes, the full text of your support message |
| Google (Firebase Cloud Messaging) | Your notification token and the text of the notification we send |
No data goes to any recipient outside this list. In the advertising context Google is not our processor but an independent controller; that is, it processes the data for its own purposes rather than on our instructions. This is the item declared as "shared" in the store forms.
To find out whether your internet connection actually works (for example, to detect that you are on a café network requiring sign-in), the application sends a request regularly. That request goes only to our own server (/health), roughly every 45 seconds. Nothing goes to any third party.
Why we mention it: this check used to send your IP address to four third-party addresses (one.one.one.one, icanhazip.com, jsonplaceholder.typicode.com, pokeapi.co) roughly every 10 seconds, because the defaults of the library we use had not been changed; two of them were free community services with no data processing agreement. That was a design flaw and it has been fixed. If you read an earlier version of this policy, those four transfers declared there no longer happen.
The Turkish Personal Data Protection Board has not issued an adequacy decision for any country to date. Transfers to the recipients in §6.1 must therefore rely on one of the appropriate safeguards in Article 9(3)-(4) KVKK. For us, the expected route is signing the relevant module of the standard contract published by the Board and notifying the Authority within five business days of signature (Article 9(5) KVKK).
Because hosting and storage are continuous and regular transfers, we do not rely on the "incidental cases" exception in Article 9(6); that exception cannot be used in our situation.
Our servers are hosted with Hetzner Online GmbH: Hetzner Online GmbH (Germany) — our server is located in Finland. So the primary location of the data belonging to your account is Finland.
Beyond that, data also goes to the United States through the following channels, and we are not hiding it: profile photo storage (Cloudflare), advertising (Google AdMob), store purchases (Google, Apple) and e-mail delivery (Google).
Transparency note: the data controller is established in Türkiye and accesses the server from Türkiye for administration and support purposes.
Your profile photos are held in Cloudflare's object storage: Cloudflare, Inc. (USA) — global infrastructure; profile photos are not pinned to any specific country. They are encrypted in transit and at rest.
This is a statement about geography, not about a security weakness: the storage is encrypted, but because the storage bucket was created without selecting a specific jurisdiction we cannot promise you which country the photos sit in. That is why we do not say "your photos are stored in the European Union" — we do not write things we cannot demonstrate.
Cloudflare is a US company and may be subject to data requests from US authorities. The fact that the "country of transfer" field of the KVKK Article 9 standard contract cannot be completed because of this uncertainty is also covered by the lawyer note in §7.1.
The application contains rewarded ads only: you start an ad yourself, of your own volition, in order to receive a reward. There are no banners, interstitials or app-open ads appearing on their own. You can use the entire application without watching any ads.
Ads are served by Google AdMob. AdMob's software component (SDK) collects data on its own account: your advertising identifier, IP address, device and OS information, and your interaction with the ad. We do not see this data; for that processing Google is not our processor but an independent controller. This is why we do not write a sentence such as "no personal data is processed for advertising" — it would not be true.
Reward verification: When the mechanism that has the server rather than the client verify that a reward was genuinely earned is enabled, your account number is attached to the ad request and comes back to our server via Google. In that case your account number is disclosed to Google. Replacing that number with a short-lived, single-use token is on our remediation list.
Consent and personalisation. Rewarded ads are shown in every country where the application is published. Your explicit consent is required for ads to be personalised. If you do not give consent, or later withdraw it, ads continue to be shown without personalisation — your reward entitlement is not switched off. Until the advertising preference screen ships, ads are served without personalisation.
Purchasing ad-free access is not an alternative to giving consent; the two are independent.
You can withdraw your consent at any time from the advertising and privacy preferences entry inside the app. Withdrawing is as easy as giving consent, and it takes effect on ad requests immediately.
Worvento is intended for users aged 16 and over. If you are under 16, do not create an account and do not use the application.
We ask for your date of birth during registration and the server blocks account creation for anyone under 16. We keep the date of birth solely for this age check, for purchase capacity and for consistency with store age ratings; it is not shown on your profile and is not shared with anyone.
Honest note: This is a self-declaration. We cannot technically tell if someone enters a false date. If we learn that an account belongs to someone under 16, we will:
You can report an account you believe belongs to someone under 16 to worvento.info@gmail.com.
The following are measures that are actually implemented in the application. We have not listed any measure we do not apply.
stored.
in the database as one-way hashes rather than clear text, and expire after 15 minutes.
exceeded the account is temporarily locked (15 minutes by default).
purchases are made by the server, not the client; the client's claim that it "won" is not trusted.
(Keystore-backed storage on Android, the Keychain on iOS).
number as the device identifier. The application contains no analytics or crash-reporting component.
code; it cannot happen with a single tap.
Honest limits. No system is one hundred percent secure. We are also not hiding two known gaps:
may appear in clear text. This is why we do not write a sentence such as "your codes are sent only to you." Fixing this is at the top of our remediation list.
demonstrate such an arrangement.
of the address.** This can cause the token to appear in intermediate servers' access logs. Moving the token into a request header is on our remediation list.
Your rights are listed in Article 11 of Law No. 6698. Wherever you live, you can exercise the same rights through the same channel: worvento.info@gmail.com.
By applying to the data controller, you have the right to:
a) learn whether your personal data is being processed, b) request information if it has been processed, c) learn the purpose of processing and whether the data is used in line with that purpose, ç) know the third parties in Türkiye and abroad to whom the data is transferred, d) request rectification if the data is incomplete or inaccurate, e) request erasure or destruction within the conditions of Article 7 KVKK, f) request that actions taken under (d) and (e) be notified to third parties to whom the data was transferred, g) object to an adverse outcome arising from analysis carried out solely by automated systems, ğ) claim compensation for damage suffered as a result of unlawful processing.
How to apply. Through one of the following channels:
(one of the channels expressly listed in Article 5 of the Turkish Communiqué on Application Procedures),
e-mail address above.
Because no postal address is published, the wet-signed postal channel is not operated; written applications are also received through the e-mail channel above.
We do not have a registered electronic mail (KEP) address. The Communiqué does not require one; the three channels above are open and an application made through any of them is valid.
Your application must include your full name (and signature if in writing), your Turkish identification number (or, if you are a foreign national, your nationality and passport or identity number), your address for service (residence or workplace), your notification e-mail address and telephone number if any, and the subject of your request. You may also attach supporting documents.
Language of applications: Article 5 of the Turkish Communiqué on Procedures for Applications to Data Controllers requires applications to be made in Turkish. Nevertheless we also accept applications in English.
Timing and fees. We will conclude your application as soon as possible and within 30 days at the latest, replying in writing or electronically. Replies are free of charge as a rule. If the operation entails an additional cost, the Board's tariff applies: for written replies the first 10 pages are free and a processing fee of TRY 1 may be charged for each page beyond 10; if the reply is provided on a recording medium such as a CD or flash drive, the cost of that medium may be charged. If the error is ours, any fee charged is refunded.
Complaint to the Board. If your application is rejected, you find the reply insufficient, or you receive no reply in time, you may lodge a complaint with the Turkish Personal Data Protection Board within 30 days of learning of the reply and in any event within 60 days of the date of your application (Article 14 KVKK). The Authority's website: https://www.kvkk.gov.tr
Two processing activities rest on consent, and you can withdraw either at any time:
entry inside the app. (Until that screen ships, ads are already served without personalisation.)
Withdrawal takes effect going forward: from the moment you withdraw we stop that processing, but processing carried out up to that point does not become unlawful. Withdrawing is as easy as giving consent.
created, and the application cannot be used without an account.
requests. Without them, the referral-code limit and multi-account detection do not work.
disabled.
there is no other restriction.
The periods below are the ones actually defined in the code. For items with no period defined in the code we do not invent a number; we say "as long as your account exists" and point you to the deletion route.
| Data | Period |
|---|---|
| Server logs | 7-file rolling window (a file-count limit of 7). The retention period of console output is not defined in the code |
| Daily activity heatmap | 400 days; days falling outside that window are pruned on each sync |
| Access token (JWT) | 7 days |
| Refresh token | Valid 30 days; the record row of an expired token is not deleted |
| E-mail verification, password-reset and account-deletion codes | 15 minutes |
| Live match snapshot | Rows older than 6 hours are pruned hourly |
| Exam session (in-memory store) | Session 1 hour, consumed marker 6 hours |
| Live connection record (presence) | 12 hours; refreshed on each connection |
| Live match state (in-memory store) | 6 hours |
| Content-delivery cache of the profile photo | 1 year, marked immutable — for this reason a copy of a deleted photo may remain accessible for some time |
| Everything else | Not defined in the code — as long as your account exists. For deletion, see §12.2 |
Our destruction methods. For records that expire or must be erased we use the following methods: database records are deleted (the row is removed); profile photo objects are deleted from object storage; on-device records are erased by removing them from the app's local store; log files are destroyed by being overwritten once the rotation cycle completes; records in the in-memory store (Redis) expire on their own when their time-to-live ends. We do not currently use anonymisation for any item; making the account number unidentifiable in purchase records is on our remediation list, and this section will be updated when that is done.
Known situations we plan to fix: there is no cleanup job in the code for daily league rows, expired refresh token records, lapsed challenge envelopes, ad reward transaction records, words flagged "deleted" in shared lists, or IP addresses. We state this exactly as it is.
How to delete. In the app, under Settings: (1) the request is started by entering your password, (2) a code is sent to your e-mail address, (3) you confirm by entering the code. There is no one-tap deletion; this is a deliberate security choice. To request deletion without installing the app, you can use our web page: https://worvento.com/legal/veri-silme
What is actually deleted. Your account record (your username, e-mail address, password hash, XP, gold, badges, streaks, heatmap, IP addresses, device identifier, install identifier, preferences, pet, cosmetics, season and quest state are fields of that record), together with: friendship records, block records, reports you are a party to, refresh tokens, daily league rows, 60-second blitz results, boss results, word-of-the-day results, wordle results, mini crossword results, tower runs, the pet record, your referral code, your shared list memberships, and the profile photo objects (on a best-effort basis).
What is not deleted — the honest list. The following records are not technically linked to your account record and therefore remain in the database after your account is deleted:
In addition:
if the app is deleted.
time.
Shortening this list — genuinely tying these records to account deletion and rendering the account number unrecognisable in financial records — is at the top of our remediation list. When the list gets shorter, so will this section. We make our text match the code.
Purchase records are retained for at least 5 years as required by tax and accounting legislation (Article 253 of the Turkish Tax Procedure Law).
You can export your own word list as CSV from within the app. For your other data, write to worvento.info@gmail.com; we will respond within the periods in §11. The scope of the portability right is set out in §11.2.
If we learn that your personal data has unlawfully come into the hands of others:
Türkiye — Article 12(5) KVKK. We will notify the Turkish Personal Data Protection Board without delay and within 72 hours at the latest from the moment we become aware of the breach (Board decision 2019/10 of 24 January 2019). If we exceed 72 hours, we will provide the Board with the reasons for the delay. After identifying those affected, we will inform you directly (by e-mail or in-app notification) as soon as reasonably possible; if we cannot reach you, we will publish a notice on our website. The notification will state when the breach occurred, which categories of data were affected, its likely consequences, the measures we have taken and our contact details.
We keep a record of all breaches — including those not notified to the Board — together with the reasoning, in our internal register. Our breach response steps are set out in a separate internal document.
Several decisions in the application are made without human intervention:
| Automated decision | How it works | Consequence |
|---|---|---|
| Multi-account signal | If more accounts than a threshold are seen under the same device identifier, a warning record is created | Registration is not blocked; a record is kept and feeds moderation |
| Ban propagation | When an account is suspended, other accounts on the same device are identified | Other accounts on the same device may also be suspended |
| XP and reward caps | If the daily acceptance cap is exceeded, the excess XP is not accepted and a warning record is written | No reward is granted |
| Account lockout | After a number of failed login attempts, the account is temporarily locked | No login for 15 minutes by default |
| Referral-code device limit | Use of more than a set number of referral codes from the same device is blocked | The code cannot be used |
| Exam and match verification | Whether the reward matches the session signature is checked | No reward is granted if it does not match |
The logic of these decisions is summarised above; the aim is to prevent one person from farming rewards and the referral system with many accounts.
Your rights. If a decision to suspend an account or refuse a reward affects you, you may:
Write to worvento.info@gmail.com; we will respond within the periods in §11. Article 11(1)(g) KVKK gives you the right to object to an adverse outcome resulting solely from automated analysis;
Profile photos are not subjected to automated image analysis; we do not perform facial recognition.
We answer the questions users ask most often, briefly and honestly. We do not collect: your GPS or network-based location, your address book or contact list, your telephone number, your gender, your health or fitness data, microphone recordings or your voice, your camera feed, your calendar, your SMS messages, your call log, biometric processing (we do not perform facial recognition), the list of applications installed on your device, the contents of your clipboard, or your payment card or IBAN details. The application contains no analytics or crash-reporting component; there is no social sign-in (federated login). We do not read hardware identifiers (IMEI, MAC address, serial number).
The exceptions, stated honestly: (1) we do not collect location, but we do process your time-zone offset, and that is enough for a coarse geographic inference. (2) We collect your date of birth at registration (the age-16 check — §9). (3) If you allow notifications, your device's notification token is processed (the notifications table in §3). (4) Your IP address reaches us; the connectivity check also goes only to our own server (the four third-party transfers described in §6.4 have been removed).
We update this policy when the data processed in the application or the purposes of processing change. Where the purpose changes, we will inform you before the new processing begins. Each version carries its version number, effective date and last-updated date at the top. For significant changes we will also notify you in the app or by e-mail.
Questions: worvento.info@gmail.com Support: worvento.info@gmail.com All applications (including written ones): worvento.info@gmail.com