Privacy Policy
Last updated: January 7, 2025
1. Introduction and General Information
This privacy policy explains how personal information collected by the Falona mobile application ("Application") is processed. As Gamma Software ("Company", "we", "our"), we have prepared this policy to protect our users' privacy and provide transparency in compliance with Google Play Console requirements.
By using this application, you accept the data processing practices described in this privacy policy. Our application is published on Google Play Store and is fully compliant with Google Play Developer Program Policies.
2. Personal and Sensitive Data Collected
2.1 Personal Information
Our application may collect the following personal information:
- Account Information: Email address, username, profile photo
- Profile Information: Name, birth date, birth time, birth place (for astrology analysis)
- Fortune Data: Tarot card selections, palm reading photos, coffee reading photos, dream records
- Usage Data: In-app activities, preferences, settings, favorite cards
2.2 Sensitive User Data
Sensitive data according to Google Play Console definition:
- Device Information: Device model, operating system, unique device identifier
- Usage Statistics: App launch times, feature usage, error reports
- Location Information: General location information (optional, for astrology - with user permission)
- Technical Information: IP address, browser type, application version
- Media Files: Palm reading and coffee reading photos (uploaded by users)
2.3 Automatically Collected Information
- Firebase Analytics: App usage analysis and performance metrics
- Crashlytics: Error reporting and app stability analysis
- Google Mobile Ads: Ad performance analysis and personalization
- Local Storage: App preferences and temporary data
3. Data Collection Purposes and Legal Basis
Collected data is used for the following purposes:
- Service Provision: Fortune analysis, personalized content delivery, AI-powered interpretations
- Account Management: Creation, management and security of user accounts
- App Development: Performance analysis, bug fixes, new feature development
- Security: Fraud prevention, account security, abuse detection
- Communication: User support, important updates, marketing (with permission)
- Advertising: Personalized ad display (Google Mobile Ads)
3.1 Legal Basis (GDPR Compliant)
- Consent: Explicit user consent for fortune analysis and marketing
- Contract: Data processing necessary for service provision
- Legitimate Interest: Data processing for app development and security
- Legal Obligation: Fulfillment of legal requirements
4. Third-Party Services and SDKs
Our application uses the following trusted third-party services:
4.1 Google Services
- Firebase: Database, authentication, storage, analytics
- Google Sign-In: Social media login
- Google Mobile Ads: Ad display and analysis
- Google Play Services: App updates and services
4.2 SDK Security Commitments
All SDKs we use:
- Operate in compliance with Google Play Developer Program Policies
- Do not sell or share your personal data with third parties
- Follow secure data processing standards
- Meet KVKK and GDPR requirements
4.3 Data Sharing
Your personal data may be shared in the following situations:
- Service Providers: Trusted third-party services like Firebase, Google
- Legal Requirements: Court orders, legal processes, public safety
- Security: Fraud prevention, security breaches, abuse
- Business Partnerships: Anonymized analytics data (no personal information)
Important: Your fortune analysis and personal fortune data are never shared with or sold to third parties.
5. Data Security and Protection Measures
We take the following measures to ensure the security of your data:
5.1 Technical Security Measures
- Encryption: Your data is stored encrypted (AES-256)
- Secure Connections: HTTPS protocol and TLS 1.3 usage
- Access Control: Limited personnel access and multi-factor authentication
- Regular Security Updates: System security updates
- Firebase Security: Google's enterprise-grade security infrastructure
5.2 Organizational Security Measures
- Staff Training: Data protection and security training
- Access Management: Role-based access control
- Auditing: Regular security audits and penetration tests
- Incident Response: Security breach response plan
6. Children's Privacy and COPPA Compliance
We do not knowingly collect personal information from children under 13. We are fully compliant with COPPA (Children's Online Privacy Protection Act) requirements.
If you are a parent or guardian and believe your child has shared personal information with us, please contact us immediately. In such cases, we will delete the data immediately.
Users aged 13-18: Parental consent is recommended for users in this age group.
7. User Rights (KVKK and GDPR)
Under KVKK and GDPR, you have the following rights:
7.1 Basic Rights
- Right of Access: Request access to your personal data
- Right of Rectification: Correct incorrect information
- Right of Erasure: Request deletion of your personal data
- Right of Restriction: Request restriction of data processing
- Right of Portability: Transfer your data to another service
- Right to Object: Object to data processing
7.2 Exercising Your Rights
To exercise these rights, you can send an email to gammasoftware0@gmail.com. We will respond to your request within 30 days.
7.3 Account Deletion
When you want to delete your account, you can easily initiate it from within the app or from our website. When the account is deleted, all personal data associated with your account is also deleted.
8. Cookies and Tracking Technologies
Our application uses the following technologies:
8.1 Technologies Used
- Firebase Analytics: App usage analysis and performance measurement
- Crashlytics: Error reporting and app stability analysis
- Google Mobile Ads: Ad performance analysis and personalization
- Local Storage: App preferences and temporary data
- Session Storage: Session information and temporary data
8.2 Cookie Management
You can manage your cookie settings within the app. However, some cookies are necessary for the basic functionality of the application.
9. Data Retention Periods
We retain your data for the following periods:
- Account Information: As long as the account is active
- Fortune Data: Until the account is deleted
- Analytics Data: 2 years (anonymized)
- Error Reports: 1 year
- Communication Records: 3 years
- Security Logs: 1 year
We may be required to retain some data for longer periods due to our legal obligations.
10. International Data Transfer
Your data may be stored on international servers through Firebase and Google services. These transfers are carried out within the framework of appropriate security measures and legal regulations.
GDPR Compliance: Adequate protection level is provided for data transfers from the EU or appropriate transfer mechanisms are used.
11. Data Security Breach Notification
If we detect a breach that affects the security of your personal data:
- We notify relevant authorities within 72 hours
- We immediately inform affected users
- We take necessary measures to minimize the impact of the breach
- We investigate the incident in detail
12. Policy Changes
We may update this privacy policy from time to time. In case of significant changes, we will inform you through in-app notifications or email. The date when changes take effect is stated at the top of this page.
We recommend checking this page regularly to keep track of policy changes.
13. Contact and Complaints
If you have questions about this privacy policy or want to exercise your data protection rights, please contact us:
Gamma Software
Data Protection Officer: gammasoftware0@gmail.com
General Contact: gammasoftware0@gmail.com
Mailing Address: İzmir, Turkey
13.1 Right to Complain
If you believe your data protection rights have been violated, you can file a complaint with your local data protection authority.
14. Google Play Console Compliance
This privacy policy is fully compliant with Google Play Console requirements:
- Compliant with Google Play Developer Program Policies
- Meets User Data Policy requirements
- Compliant with sensitive data processing terms
- Compliant with child protection policies
- Compliant with data security standards