Privacy Policy
Last Updated: February 12, 2026
KVKK Compliance: Nori operates in full compliance with Turkey's Personal Data Protection Law No. 6698 (KVKK). Personal data of our users in Turkey is protected by law. Your data is stored encrypted, never sold to third parties, and all your rights under KVKK are protected.
1. INTRODUCTION AND SCOPE
This Privacy Policy ("Policy") explains how your personal data is collected, processed, stored, and protected when you use the Nori app and related services ("Services").
By using our Services, you are deemed to have accepted this Policy. If you do not accept it, please do not use the Services.
Contact: info@getnoriapp.com | Address: Istanbul, Türkiye
2. DATA WE COLLECT
2.1 Data You Provide Directly
Data you voluntarily provide when creating an account:
- Email address
- Username
- Profile photo
- Password (stored encrypted using strong hashing algorithms)
- Phone number (optional)
- Date of birth (optional)
2.2 App Permissions Data
We may request the following permissions from your device settings:
Location Data (GPS): We only process your instantaneous location when you use the app and add a memory. We do not track your location continuously in the background. This data is stored encrypted on our servers. You can revoke this permission at any time.
Media Access: We only access photos/videos that you specifically select and upload to the app. We do not scan or copy your entire gallery.
Contacts: We may optionally request access to your contact list so you can find your friends.
Notifications: We may request push notification permission for friend requests, memory reminders, and system notifications.
Calendar: We may request access to calendar data to process the date information of your memories.
2.3 Data Collected Automatically
The following data is automatically collected while using the Services:
- IP Address: To determine the origin of your connection
- Device Information: Model, manufacturer, unique identifier (IDFA/AAID)
- Operating System: Version, language, region settings
- App Version: For updates and compatibility checks
- Usage Statistics: Which features you use and how much time you spend
- Crash and Error Reports: To improve app stability
- Connection Information: Internet type (WiFi/mobile), connection quality
2.4 Cookies and Similar Technologies
We may use the following technologies on Nori's web version (if applicable):
- Session Cookies: To keep your session active
- Preference Cookies: To remember your settings such as language and theme
- Analytics Cookies: To collect usage data via Google Analytics 4
- Tracking Pixels: To measure campaign effectiveness
You can disable cookies in your browser settings, though this may affect some features.
2.5 Data Received From Third Parties
Social Login (OAuth): If you sign in via Google or other providers, we only receive basic profile information (name, email, profile picture). We do not request any other data.
Analytics Providers: Google Firebase provides us with aggregate usage data.
3. PURPOSE OF DATA PROCESSING
We process your data for the following purposes:
3.1 Providing the Service
- Account creation and authentication
- Saving your memories and storing them encrypted on secure servers
- Building maps based on your location data
- Social features (following, sharing memories, comments)
- Search and filtering functions
3.2 Improving the Service
- Usage analysis and performance measurement
- Bug detection and resolution
- New feature development
- User experience optimization
3.3 Communication
- Account verification and password reset
- Important security notices
- Feedback requests (as long as you consent)
- Information about product updates
3.4 Security and Fraud Prevention
- Detecting unauthorized access
- Preventing malicious activity
- Monitoring spam and abuse
- Data breach investigation
3.5 Legal Obligations
- KVKK and GDPR compliance
- Court orders and legal requests
- Tax and accounting records
- Business and transaction records
3.6 Legal Basis
We rely on the following legal bases to process your personal data:
- KVKK Article 5: Performance of the service agreement
- GDPR Article 6: Legitimate interest and contractual obligation
- Explicit Consent: For marketing communications (you may withdraw this at any time)
4. DATA SHARING AND TRANSFER
4.1 Service Providers (Processors)
Your data may be shared with the following service providers:
| Provider | Purpose | Data Type | Location |
|---|---|---|---|
| Google Firebase | Database, storage, authentication | All app data | USA, EU |
| Google Maps Platform | Mapping services | Location data | USA, EU |
| Google Analytics 4 | Usage analytics | Aggregate data | USA, EU |
These providers process your data but may not use it for their own purposes. Data Processing Agreements (DPA) have been signed with them.
4.2 Other Users
Memories you share may be visible to other users depending on your sharing settings:
- Only Me: Visible only to you
- Friends Only: Visible to people you follow. IMPORTANT: "Daily" posts, due to our privacy-first design, can be viewed ONLY by your friends.
- Public: Visible to all users of the Service (except Daily posts)
You can change your sharing settings or withdraw consent at any time.
4.3 Legal Requirements
We may share your data with competent authorities in the following circumstances:
- A valid court order or legal counsel request
- When required by laws or regulations
- To protect public safety or the safety of others
Wherever possible, we try to notify you of the relevant request.
4.4 Business Transfer
In the event Nori is acquired, merged, or its assets sold, your data may be transferred to the acquiring company. We will notify you in such a case.
4.5 International Data Transfer
Your data may be transferred to the USA and EU countries through Google services. Google is GDPR-compliant under Standard Contractual Clauses (SCC).
5. DATA RETENTION
5.1 Retention Periods
| Data Type | Retention Period | Rationale |
|---|---|---|
| Account Information | As long as membership continues | Service delivery |
| Memories and Photos | As long as membership continues | User content |
| Location Data | Last 90 days | Performance and mapping |
| Analytics Data | 14 months | Google Analytics retention policy |
| System Logs | 6 months | Security and error resolution |
| Backup Copies | 30 days | Data recovery purposes |
5.2 After Account Deletion
When you delete your account:
- Your personal information is deleted immediately
- Your memories and media files are permanently deleted within 30 days
- System backups are purged after 30 days
- Data sent to third-party providers is managed according to their own retention policy
Right to Erasure: Under GDPR, your deletion request is fulfilled within 30 days.
6. DATA SECURITY
6.1 Technical Security Measures
- Data Security: Your data is protected with strong encryption in transit (TLS/SSL) and at rest (AES-256 or similar).
- HTTPS/TLS: All data communication is encrypted with SSL/TLS 1.2 or higher
- Hashing Algorithm: Passwords are hashed with bcrypt (minimum 12 rounds)
- API Security: OAuth 2.0 and JWT token-based authentication
- DDoS Protection: Via Google Cloud Infrastructure
6.2 Operational Security
- Employee training: All team members receive privacy and security training
- Access Control: Limited access based on the principle of least privilege
- Data Processing Agreements: Signed DPAs with all providers
- Permission System: Employees can only access necessary data types
6.3 Incident Response Plan
- In the event of a data breach, KVKK/GDPR authorities are notified within 72 hours
- Affected users are notified immediately
- Root cause analysis is performed
- Preventive measures are taken
6.4 Disclaimer
The internet and electronic communications are never completely secure. While we strive to protect your data with maximum security, we cannot guarantee 100% security.
7. USER RIGHTS
7.1 Rights Under KVKK
If you reside in Türkiye, under the KVKK Law you have:
- Right of Access: The right to learn what data of yours is processed
- Right to Rectification: The right to request correction of inaccurate data
- Right to Erasure: The right to request deletion of your data
- Right to Object to Processing: The right to object to unlawful processing
- Right to Portability: The right to transfer your data to another provider
7.2 Rights Under GDPR
If you reside in an EU country, under GDPR you have additional rights:
- Withdrawal of Consent: Opt out of marketing communications at any time
- Objection to Automated Decision-Making: Request exemption from algorithm-based decisions
- Data Portability: Receive your data in a machine-readable format (CSV, JSON)
7.3 How to Submit a Rights Request
Write to info@getnoriapp.com and provide the following information:
- Your full name and email address
- A copy of identification (ID, passport, etc.)
- The right you are requesting (access, rectification, erasure, etc.)
- The reason for the request (optional)
Response Time: Answered within 30 days. Complex requests may be extended up to 90 days.
7.4 Request Rejection
If your request is rejected, the reasons will be explained and your right to object is preserved.
8. CHILDREN'S DATA
Nori is not directed at children under the age of 13. We do not knowingly collect data from anyone under 13. If we become aware of such a case, we will delete the data immediately.
For parental/guardian concerns: info@getnoriapp.com
9. THIRD-PARTY LINKS
Nori may contain links to other websites or apps. This privacy policy applies only to Nori. You are responsible for the privacy policies of third-party services.
10. CHANGES TO THIS POLICY
We may update this policy from time to time. You will be notified by email in the event of material changes. Continuing to use the app after the new policy takes effect means you accept the new policy.
Update Dates: Found at the top of the page.
11. MARKETING AND ADVERTISING
11.1 Consent-Based Communication
Marketing communications are only sent with your explicit consent:
- Notifications about new features
- Promotions and special offers
- Product updates
- Research and feedback requests
You can unsubscribe at any time from account settings or via the "Unsubscribe" link in emails.
11.2 Advertising Platforms
Nori currently does not contain ads. If ad integration is added in the future:
- It will be via Google AdMob (non-personally-identifying ads)
- Personal data will not be sold for commercial purposes
12. PRIVACY BY DESIGN AND DATA PROTECTION IMPACT ASSESSMENT
12.1 Privacy by Design Principle
The Nori app is developed according to privacy-by-design principles:
- Data is collected at a minimum level (data minimization)
- Default settings include the safest option
- Users are given control options
- Data processing is transparent
12.2 Data Protection Impact Assessment (DPIA)
DPIAs are performed for high-risk data processing:
- Location data processing: Risk analysis completed
- Social relationship database: Security assessment performed
- Data sharing features: Privacy impact reviewed
Assessment results are kept by the privacy team and may be shared upon request.
13. DATA PROCESSING CONTROLS
13.1 Automated Decision-Making and Profiling
Nori does not make fully automated decisions. However:
- Spam detection algorithm: Sends a warning, does not automatically close accounts
- Content recommendation: A recommendation system is used, it is not mandatory
- Relevance score: Used to improve user experience (not for commercial purposes)
These processes have been evaluated under GDPR Article 22 and human intervention is guaranteed.
13.2 Right to Explanation
If you request an explanation regarding automated decisions, the machine learning models involved will be identified and their effect explained.
14. DATA PROTECTION REPRESENTATIVE
14.1 Operations in the EU
Nori has a data controller representative to protect the privacy rights of users in the EU:
Representative Name: [Representative Name To Be Specified] Email: [Representative Email] Phone: [Phone Number]
If you reside in the EU, you may apply to the representative under GDPR Article 27.
14.2 Representative Under KVKK
Under KVKK Article 13, applications from those residing outside Türkiye may be made to our representative.
15. DATA PROCESSING AGREEMENTS
15.1 Third-Party Agreements
Agreements have been signed with all data processors covering the following:
- Data Processing Agreement (DPA): GDPR Article 28 compliant
- Sub-processor Notification: Second-tier providers require authorization
- Right to Audit: Nori may conduct audits
- Data Portability: Data is returned if the agreement ends
- Confidentiality Obligations: Employee confidentiality agreements are in place
15.2 Subprocessors
| Subprocessor | Service | GDPR Compliant |
|---|---|---|
| Google LLC | Cloud Hosting | Yes |
| Stripe (Payments) | Payment Processing | Yes |
| SendGrid (Email) | Email Delivery | Yes |
You can reach out to info@getnoriapp.com for information on subprocessors and updates.
16. COMPLIANCE AND CERTIFICATIONS
16.1 KVKK Compliance
Nori is committed to providing services in compliance with the Personal Data Protection Law (KVKK):
- Data subject consent is obtained
- Data processing purposes are defined
- Security measures are implemented
- Rights to audit and intervention are provided
16.2 GDPR Compliance
Nori, operating in the EU, is fully compliant with GDPR:
- Legal basis is clearly stated
- User rights are respected
- Data breaches are reported within 72 hours
- Data protection impacts are assessed
16.3 ISO 27001 Readiness
Nori manages its information security processes in line with industry standards.
17. DATA BREACHES AND INCIDENTS
17.1 Data Breach Notification
In the event of a data breach (hacking, unauthorized access, etc.):
- Rapid Response: The system can be shut down immediately
- Investigation: Root cause analysis begins within 24 hours
- User Notification: Affected users are notified immediately
- Authority Notification: KVKK and GDPR authorities are notified within 72 hours
- Public Notification: The public may be notified (if necessary)
17.2 Definition of an Incident
A "data breach" means the unauthorized processing, exposure, or loss of personal data.
17.3 Your Responsibility
- Keep your account information confidential
- Report suspicious activity
- Notify us if your device is lost
- Use strong passwords
18. EXTERNAL MONITORING AND TRACKING
18.1 External Tracking
Nori may use external tracking services (pixels, beacons):
- Google Analytics 4: To measure aggregate usage data
- Firebase Analytics: To monitor app performance
18.2 Do Not Track (DNT) Requests
If your browser has "Do Not Track" enabled, we will respect it. However, minimum tracking required by legal obligation may continue.
18.3 Targeting
Nori does not perform preference-based targeting to build personal profiles. We only use aggregate metrics.
19. CROSS-BORDER DATA TRANSFER POLICIES
19.1 Atypical Data Flows
Nori does not transfer your personal data except in the following circumstances:
- To service providers (for technical reasons)
- To data shared by the user (social)
- As required by law
19.2 Confidentiality Contracts
All parties sign a confidentiality agreement before any data sharing.
20. FINAL PROVISIONS
20.1 Right to Information
If you have questions about this policy, you can write to info@getnoriapp.com.
20.2 Dispute Resolution
To resolve privacy issues:
- Contact Nori (30 days)
- Apply to the KVKK authority
- If taken to court, Turkish law applies
20.3 Channels for Complaints
- KVKK: kvkk.gov.tr
- Turkish Cargo and Logistics Association: TKD
- Nori Customer Support: info@getnoriapp.com
Policy Date: February 12, 2026 Next Review: February 12, 2027