Son güncelleme: 18 Ağustos 2026 · Yürürlük tarihi: 18 Ağustos 2026 · Sürüm 1.0
Bu özet bilgilendirme amaçlıdır; bağlayıcı olan aşağıdaki tam metindir.
FanFini (“FanFini”, “biz”), bu politikada açıklanan kişisel verilerin veri sorumlusudur (6698 sayılı KVKK m.3 ve GDPR m.4/7 anlamında).
Bu politika; FanFini mobil uygulamasını, api.fanfini.app adresindeki arka uç servisini ve bu web sitesini kapsar.
Uygulamanın ilk açılışında gösterilen Açık Rıza Metni, oyunun kuralları, 18 yaş sınırı ve oyuncuların birbirine karşı sorumluluğu hakkındadır. Elinizdeki Gizlilik Politikası ise kişisel verilerinizin nasıl işlendiğini anlatır. İkisi birbirini tamamlar; ikisini de okumanızı öneririz.
FanFini’de kişisel veri toplama ilkesi basittir: oyunun çalışması için gerekli olan en az veri. Aşağıdaki tablo işlenen tüm veri kategorilerini gösterir.
| Veri | Ne zaman | Neden |
|---|---|---|
| Cihaz kaydı | Uygulamanın ilk açılışında | Cihaz için üretilen rastgele kimlik (Cihaz Kimliği), platform (iOS/Android), uygulama sürümü, seçtiğin dil, kayıt ve son görülme zamanı. Hesap açmadan oynayabilmen, yarım kalan oyununa geri dönebilmen ve kötüye kullanımın engellenmesi için gereklidir. |
| Oturum anahtarı | Her girişte | Cihazını doğrulayan anahtar sunucuda yalnızca şifrelenmiş özeti (hash) ile tutulur; anahtarın kendisi saklanmaz. Geçerlilik süresi dolduğunda veya çıkış yapıldığında iptal edilir. |
| Hesap bilgileri (isteğe bağlı) | Google veya Apple ile giriş yaparsan | Firebase kullanıcı kimliği, e-posta adresin ve görünen adın. Yalnızca coin bakiyenin, hediye coinlerin, Premium üyeliğinin ve satın alımlarının yeni bir telefonda geri gelmesi için kullanılır. Apple ile girişte “e-postamı gizle” seçeneğini kullanırsan bize yalnızca Apple’ın ürettiği yönlendirme adresi ulaşır. |
| Oyun verisi | Oda kurarken ve oynarken | Oda kodu, o oyunda kullandığın takma ad, oyun türü ve dili, zar sonuçları, sana gösterilen ve seçilen/atlanan soruların kimlikleri, joker kullanımların, tur sayıları ve zaman damgaları. Oyunun iki oyuncuda da senkron ilerlemesi ve aynı sorunun tekrar gelmemesi için gereklidir. |
| Favoriler | Bir soruyu favorilere eklediğinde | Sorunun o anki metni, kategorisi ve cevabı veren oyuncunun takma adı. Favoriler ekranında sana gösterilir. |
| Soru önerileri | “Soru Öner” ekranından gönderdiğinde | Yazdığın soru metni, seçtiğin oyun türü ve kategori, öneriyi gönderen hesap. Önerinin değerlendirilmesi ve tekrar/kötüye kullanımın önlenmesi için hesabınla ilişkilendirilir. Bir öneri oyuna eklenirse adınla ya da hesabınla birlikte yayınlanmaz. |
| Satın alma ve abonelik | Coin veya Premium aldığında | Mağazadan gelen satın alma olayları (ürün kodu, tarih, durum), coin bakiyen, Premium üyeliğin ve bitiş tarihi. Kart numarası, IBAN ve fatura adresi bize hiçbir zaman ulaşmaz — ödemeyi Apple ve Google alır. |
| Reklam olayları | Ücretsiz oyunlarda | Reklamın istendiği, gösterildiği ve tamamlandığı bilgisi — ücretsiz oyun hakkının doğru işlemesi için. Reklamın kendisi Google AdMob tarafından sunulur ve Google kendi tanımlayıcılarını kullanır (bkz. bölüm 7). |
| Analitik ve hata kayıtları | Uygulamayı kullanırken | Firebase Analytics olayları (ör. “oyun başladı”, “oda kuruldu”) ve Crashlytics çökme raporları (cihaz modeli, işletim sistemi sürümü, hata yığını). Hataları görmek ve oyunu iyileştirmek için. |
| Teknik sunucu kayıtları | Her istekte | IP adresi ve istek yolu. IP adresi yalnızca istek sınırlama (rate limiting) ve kötüye kullanım engelleme amacıyla, kısa ömürlü bir önbellekte tutulur; oyun kayıtlarınla birleştirilmez ve profil oluşturmak için kullanılmaz. |
Cihaz Kimliğini uygulama içinde Hesap ekranından görebilir ve kopyalayabilirsin. Bir talep gönderirken bu kimliği eklemen, kayıtlarını bulmamızı kolaylaştırır.
Oyun sırasında verdiğin cevaplar hiçbir şekilde kaydedilmez. FanFini’de cevaplar yazılmaz, karşındaki kişiye sesli söylenir. Uygulama mikrofonu açmaz, ses veya görüntü kaydı almaz, cevabın metnini sunucuya göndermez. Sunucuda tutulan tek şey hangi sorunun seçildiği veya atlandığı bilgisidir — cevabın kendisi değil.
Ayrıca şunları toplamıyoruz:
| Amaç | KVKK m.5 | GDPR m.6 |
|---|---|---|
| Oyunun kurulması, odanın açılması ve oyunun yürütülmesi | Sözleşmenin ifası — m.5/2-c | 6(1)(b) |
| Hesap açma, coin bakiyesi, satın alma ve geri yükleme | Sözleşmenin ifası — m.5/2-c | 6(1)(b) |
| Kötüye kullanım, sahtecilik ve istek sınırlama (güvenlik) | Meşru menfaat — m.5/2-f | 6(1)(f) |
| Hata kayıtları ve ürünün iyileştirilmesi | Meşru menfaat — m.5/2-f | 6(1)(f) |
| Kişiselleştirilmiş reklam ve ölçümleme | Açık rıza — m.5/1 | 6(1)(a) |
| Yasal yükümlülüklerin yerine getirilmesi (ör. mali kayıtlar) | Hukuki yükümlülük — m.5/2-ç | 6(1)(c) |
Açık rızaya dayanan işlemeleri (kişiselleştirilmiş reklam) dilediğin zaman geri alabilirsin; bunun için bölüm 7’ye bak.
Kişisel verilerini satmıyoruz ve reklam amacıyla üçüncü taraflara pazarlamıyoruz. Verilerin yalnızca hizmetin çalışması için gerekli olduğu ölçüde, aşağıdaki sağlayıcılar tarafından ve bizim adımıza işlenir:
| Sağlayıcı | Ne için | Nerede |
|---|---|---|
| Supabase Inc. | Veritabanı barındırma (oyun, hesap ve coin kayıtları) | Londra, Birleşik Krallık |
| DigitalOcean LLC | Uygulama sunucuları ve yük dengeleyici | Frankfurt, Almanya |
| Google LLC — Firebase Authentication | Google ile giriş, hesap kimliği | AB / ABD |
| Google LLC — Firebase Analytics & Crashlytics | Kullanım istatistikleri ve çökme raporları | AB / ABD |
| Google LLC — AdMob & UMP | Reklam gösterimi ve reklam izni yönetimi | AB / ABD |
| Google Play Billing / Apple App Store | Satın alma ve abonelik tahsilatı | AB / ABD |
| RevenueCat, Inc. | Satın alma doğrulama ve abonelik durumu | ABD |
Bunların dışında verilerin yalnızca (a) yasal olarak yetkili bir makamın usulüne uygun talebi üzerine veya (b) hakların tesisi, kullanılması ya da korunması için zorunlu olduğunda paylaşılır.
Google’ın veri uygulamaları: policies.google.com/privacy · Apple: apple.com/legal/privacy · RevenueCat: revenuecat.com/privacy · Supabase: supabase.com/privacy
FanFini ücretsiz oynanabilir. Ücretsiz oyunlar Google AdMob reklamlarıyla desteklenir. Reklamları tamamen kaldırmak istersen coin satın alabilir veya Premium üye olabilirsin — bu durumda oyun içinde reklam gösterilmez.
Avrupa Ekonomik Alanı, Birleşik Krallık ve İsviçre’deki kullanıcılara, uygulamanın ilk açılışında Google’ın UMP (User Messaging Platform) izin ekranı gösterilir. Kişiselleştirilmiş reklam yalnızca burada onay verirsen gösterilir; onay vermezsen reklamlar kişiselleştirilmemiş olarak sunulur ve oyun aynı şekilde çalışmaya devam eder.
iOS’ta ayrıca Apple’ın App Tracking Transparency izni sorulur. Reklam izin tercihini istediğin zaman cihazının ayarlarından değiştirebilirsin:
Uygulama sunucularımız Almanya’da (Frankfurt), veritabanımız Birleşik Krallık’ta (Londra) barındırılır. Google, Apple ve RevenueCat gibi sağlayıcılar verileri ayrıca Amerika Birleşik Devletleri’nde işleyebilir.
Bu aktarımlar; KVKK m.9 kapsamında açık rızanız ve/veya taahhütname ile, GDPR kapsamında ise Avrupa Komisyonu’nun Standart Sözleşme Hükümleri (SCC) ve sağlayıcıların veri işleme sözleşmeleri temelinde yapılır.
KVKK m.11 ve GDPR m.15–22 uyarınca aşağıdaki haklara sahipsin:
Taleplerini utku.ayan@outlook.com adresine gönderebilirsin. Talebini bulabilmemiz için uygulamadaki Cihaz Kimliğini (Hesap ekranından kopyalanabilir) ve varsa giriş yaptığın e-posta adresini eklemeni rica ederiz. Talepler en geç 30 gün içinde ücretsiz olarak sonuçlandırılır.
Hesabının ve verilerinin silinmesi için utku.ayan@outlook.com adresine “Veri silme talebi” konulu bir e-posta gönder. E-postana şunları ekle:
Talebini aldıktan sonra en geç 30 gün içinde hesabını, cihaz kaydını, oyun geçmişini, favorilerini ve soru önerilerini kalıcı olarak sileriz ve seni e-posta ile bilgilendiririz.
Not: Uygulamadan çıkış yapmak (Hesap → Çıkış yap) verilerini silmez, yalnızca cihazın hesapla bağlantısını keser. Uygulamayı silmek de sunucudaki kayıtları kaldırmaz — bunun için yukarıdaki talebi göndermelisin.
FanFini yalnızca 18 yaş ve üzeri kullanıcılar içindir. Uygulamayı ilk açtığında yaş sınırını onaylaman istenir. Bilerek 18 yaşından küçüklerden veri toplamayız. 18 yaşından küçük birine ait veri işlendiğini öğrenirsek kaydı gecikmeksizin sileriz; böyle bir durumu utku.ayan@outlook.com adresine bildirebilirsin.
Hiçbir sistem %100 güvenli değildir; bir güvenlik açığı fark edersen lütfen utku.ayan@outlook.com adresinden bize bildir.
Bu politikayı zaman zaman güncelleyebiliriz. Güncel sürüm her zaman privacy.fanfini.app adresinde yayınlanır ve yukarıdaki “son güncelleme” tarihi değişir. Verilerin işlenme biçiminde esaslı bir değişiklik olursa, değişiklik yürürlüğe girmeden önce uygulama içinde bilgilendirilirsin ve gerekiyorsa yeniden onayın istenir.
Gizlilikle ilgili her türlü soru, talep ve şikâyet için:
Last updated: 18 August 2026 · Effective: 18 August 2026 · Version 1.0
This summary is for convenience only; the full text below is what applies.
FanFini (“FanFini”, “we”, “us”) is the data controller for the personal data described in this policy, within the meaning of the Turkish Personal Data Protection Law No. 6698 (KVKK) art. 3 and the GDPR art. 4(7).
This policy covers the FanFini mobile app, the backend service at api.fanfini.app, and this website.
The Consent Statement shown when you first open the app is about the rules of the game, the 18+ age limit and how players are expected to treat each other. This Privacy Policy is about how your personal data is handled. The two complement each other and we recommend reading both.
The principle is simple: the least data the game needs in order to work. The table below lists every category of data we process.
| Data | When | Why |
|---|---|---|
| Device registration | On first launch | A random identifier generated for your device (Device ID), platform (iOS/Android), app version, chosen language, first-seen and last-seen timestamps. Needed so you can play without an account, return to an unfinished game, and so abuse can be blocked. |
| Session token | On every sign-in | The token that authenticates your device is stored on the server only as a cryptographic hash — never the token itself. It is revoked when it expires or when you sign out. |
| Account details (optional) | If you sign in with Google or Apple | Your Firebase user ID, email address and display name. Used only so your coin balance, gift coins, Premium membership and purchases follow you to a new phone. If you use Apple’s “Hide My Email”, all we receive is the relay address Apple generates. |
| Game data | When creating a room and playing | Room code, the nickname you use in that game, game mode and language, dice results, the IDs of the questions shown to you and the one selected or skipped, joker usage, turn counts and timestamps. Needed to keep both players in sync and to avoid repeating questions. |
| Favourites | When you favourite a question | The text of the question at that moment, its category, and the nickname of the player who answered it. Shown back to you on the Favourites screen. |
| Question suggestions | When you submit one from “Suggest a question” | The question text you wrote, the game mode and category you picked, and the submitting account. Linked to your account so suggestions can be reviewed and abuse prevented. If a suggestion makes it into the game it is never published together with your name or account. |
| Purchases and subscriptions | When you buy coins or Premium | Purchase events from the store (product code, date, status), your coin balance, Premium status and expiry date. Card numbers, bank details and billing addresses never reach us — Apple and Google handle the payment. |
| Ad events | In free games | Whether an ad was requested, shown and completed — so that free games are counted correctly. The ad itself is served by Google AdMob, which uses its own identifiers (see section 7). |
| Analytics and crash reports | While using the app | Firebase Analytics events (e.g. “game started”, “room created”) and Crashlytics crash reports (device model, OS version, stack trace). Used to spot failures and improve the game. |
| Technical server logs | On every request | IP address and request path. The IP address is held in a short-lived cache purely for rate limiting and abuse prevention; it is not joined to your game records and is not used for profiling. |
You can see and copy your Device ID inside the app on the Account screen. Including it in a request helps us find your records.
Answers given during a game are never recorded. In FanFini answers are spoken out loud, not typed. The app does not open the microphone, does not record audio or video, and does not send the text of an answer to any server. All the server keeps is which question was selected or skipped — never the answer itself.
We also do not collect:
| Purpose | KVKK art. 5 | GDPR art. 6 |
|---|---|---|
| Creating rooms and running the game | Performance of a contract — 5/2-c | 6(1)(b) |
| Accounts, coin balances, purchases and restores | Performance of a contract — 5/2-c | 6(1)(b) |
| Abuse prevention, fraud prevention, rate limiting | Legitimate interest — 5/2-f | 6(1)(f) |
| Crash reporting and product improvement | Legitimate interest — 5/2-f | 6(1)(f) |
| Personalised advertising and measurement | Explicit consent — 5/1 | 6(1)(a) |
| Complying with legal obligations (e.g. tax records) | Legal obligation — 5/2-ç | 6(1)(c) |
Where we rely on consent (personalised advertising) you may withdraw it at any time — see section 7.
We do not sell your personal data and we do not market it to third parties. Data is processed on our behalf, only as far as the service requires, by the following providers:
| Provider | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database hosting (game, account and coin records) | London, United Kingdom |
| DigitalOcean LLC | Application servers and load balancer | Frankfurt, Germany |
| Google LLC — Firebase Authentication | Sign in with Google, account identity | EU / USA |
| Google LLC — Firebase Analytics & Crashlytics | Usage statistics and crash reports | EU / USA |
| Google LLC — AdMob & UMP | Serving ads and managing ad consent | EU / USA |
| Google Play Billing / Apple App Store | Purchases and subscription billing | EU / USA |
| RevenueCat, Inc. | Purchase validation and subscription status | USA |
Beyond these, data is shared only (a) in response to a lawful request from a competent authority, or (b) where strictly necessary to establish, exercise or defend legal claims.
Google’s practices: policies.google.com/privacy · Apple: apple.com/legal/privacy · RevenueCat: revenuecat.com/privacy · Supabase: supabase.com/privacy
FanFini is free to play. Free games are supported by Google AdMob ads. If you would rather not see them at all, you can buy coins or subscribe to Premium — no ads are shown inside those games.
Users in the European Economic Area, the United Kingdom and Switzerland are shown Google’s UMP (User Messaging Platform) consent form on first launch. Personalised ads are only served if you consent there; if you decline, ads are served non-personalised and the game works exactly the same.
On iOS, Apple’s App Tracking Transparency prompt is shown as well. You can change your advertising preferences at any time in your device settings:
Our application servers are hosted in Germany (Frankfurt) and our database in the United Kingdom (London). Providers such as Google, Apple and RevenueCat may also process data in the United States.
These transfers take place on the basis of your explicit consent and/or an undertaking under KVKK art. 9, and — for the GDPR — the European Commission’s Standard Contractual Clauses (SCCs) together with our providers’ data processing agreements.
Under KVKK art. 11 and GDPR art. 15–22 you have the right to:
Send requests to utku.ayan@outlook.com. To help us find your records, please include your Device ID from the app (copyable on the Account screen) and, if you signed in, the email address of your account. Requests are handled free of charge within 30 days at the latest.
To have your account and data deleted, send an email titled “Data deletion request” to utku.ayan@outlook.com and include:
We will permanently delete your account, device registration, game history, favourites and question suggestions within 30 days of receiving your request, and confirm by email once it is done.
Note: signing out (Account → Sign out) does not delete your data — it only unlinks this device from your account. Uninstalling the app does not remove server-side records either; you need to send the request above.
FanFini is intended for users aged 18 and over only. You are asked to confirm the age limit the first time you open the app. We do not knowingly collect data from anyone under 18. If we learn that we hold data belonging to someone under 18 we delete it without delay — you can report such a case to utku.ayan@outlook.com.
No system is 100% secure. If you find a vulnerability, please report it to utku.ayan@outlook.com.
We may update this policy from time to time. The current version is always published at privacy.fanfini.app, with the “last updated” date above adjusted accordingly. If we make a material change to how your data is processed, you will be informed inside the app before it takes effect and, where required, asked to consent again.
For any privacy question, request or complaint: