Privacy Policy
Last updated: July 21, 2026
Coparoo is a mobile app that helps separated and divorced parents manage
their children's calendar, communication, expenses and documents in one
place. This is a sensitive domain (children's data, health information,
custody records), and we treat privacy as a cornerstone of the product.
Data controller: Ali DİNÇ (Developer), Eskişehir,
Türkiye. Contact:
[email protected].
1. Data we collect
We collect only what is needed to provide the service, to the extent you
enter it:
- Account: email address, password (stored only as a
secure hash), display name, calendar color.
- Children's information: name, birth date, school,
teacher and doctor contacts, allergies, medications, clothing sizes, notes
and an optional photo.
- Documents: files you upload (report cards,
prescriptions, court orders, ID documents, etc.).
- Calendar: events, custody blocks, custody plans, swap
requests.
- Messages: messages you send to your co-parent, with
timestamps and a "first viewed" record.
- Expenses: amount, category, date, split percentage and
an optional receipt photo.
- Family and invites: family memberships, role, and the
email address of invites you send.
- Notifications: a device (APNs) token to deliver push
notifications.
- Subscription: premium status and a subscription
management identifier (we do not see your payment card details;
see §5).
We do not collect an advertising
identifier, location tracking, contacts access, or third-party
analytics/tracking data.
2. How we use data
- To provide the service: storing calendar, messages, expenses and
documents so you and (if any) your co-parent can access them.
- To send push notifications (new message, swap request, expense, etc.).
- To email you a password-reset code.
- To generate a verifiable PDF report at your request.
- To keep the service secure (including protection against brute-force
attacks).
3. Privacy by design: our deliberate choices
- Photo location data is stripped. Receipt and document
photos are cleared of EXIF/GPS metadata on your device before upload, so
your home address cannot leak to the other party.
- The tone assistant runs on-device. Suggestions to
soften a draft are generated entirely on your device; drafts are
never sent to our servers and never stored anywhere.
- The server is a "neutral notary." Messages are
append-only, timestamped and hash-chained. Because this verification
requires access to content, end-to-end encryption (E2EE) is
deliberately not used; we state this openly.
- Documents are in private storage. Uploaded files are
kept in private storage and accessed only via short-lived signed links; no
permanent public URL is created.
- Lawyer access is read-only. A viewer-role user cannot
change any record and cannot see secret data such as invites.
All traffic is encrypted in transit with TLS (HTTPS); passwords are stored
as secure hashes; our hosting and file providers encrypt data at rest.
Additional application-layer encryption of specific
sensitive fields is a planned improvement on our roadmap and is not yet
active; this policy describes only practices currently in effect.
4. Shared space vs. private space
If you share a family with your co-parent, records in that family
(calendar, messages, expenses, documents) are by definition visible to both
parties — that is the purpose of the service. If you use it solo, your
records are private; if the other party later accepts an invite, only the
shared space opens, not your private solo-era records.
5. Who we share data with
We do not sell your data. We share it only with the
service providers (processors) required to run the service:
- Hosting and database (Railway) — application server
and database.
- File storage (Cloudflare R2) — receipt and document
photos, in private storage.
- Push notifications (Apple Push Notification service).
- Subscription management (Apple App Store and
RevenueCat) — payment is processed by Apple; we do not see your
card details. An anonymous subscription identifier is used to track
status.
- Email — an email service used only for transactional
emails such as password reset.
We may also disclose data to authorities where required by a legal
obligation (e.g., a court order).
6. Retention and deletion
- Account deletion = real deletion. You can delete your
account from within the app. If you use it solo, your data (including
files) is permanently deleted.
- In a shared family, records are also your co-parent's
record; in that case content is preserved but your identity is
anonymized (name and email) and your account is closed.
- Your records are yours. You can export them as a
verifiable PDF report, available with Coparoo Premium, and delete your
account at any time from within the app.
7. Children's privacy
Coparoo is not directed to children; accounts are opened by adult parents
and information about a child is entered by the parent. Children do
not use the app directly.
8. Your rights (KVKK / GDPR)
Under applicable law (KVKK in Türkiye, GDPR in Europe) you have the right
to access, correct, delete, restrict processing of, and port your data. You
can exercise these rights with in-app tools (editing, export, account
deletion) or by contacting us at
[email protected].
9. Changes
We may update this policy from time to time; for material changes we will
notify you in the app or by email. The current version is always published
at this address.
Gizlilik Politikası
Son güncelleme: 21 Temmuz 2026
Coparoo, ayrılmış veya boşanmış ebeveynlerin çocuklarıyla ilgili takvim,
iletişim, masraf ve belgeleri tek bir yerde yönetmesini sağlayan bir mobil
uygulamadır. Bu alan hassastır (çocuk verisi, sağlık bilgisi, velayet
kaydı); gizliliği ürünün temel taşı olarak ele alıyoruz.
Veri sorumlusu: Ali DİNÇ (Developer), Eskişehir,
Türkiye. İletişim:
[email protected].
1. Topladığımız veriler
Yalnızca hizmeti sunmak için gereken verileri, sizin girdiğiniz ölçüde
toplarız:
- Hesap: e-posta adresi, şifre (yalnızca güvenli özet /
hash biçiminde saklanır), görünen ad, takvim rengi.
- Çocuk bilgileri: ad, doğum tarihi, okul, öğretmen ve
doktor iletişimi, alerjiler, ilaçlar, beden ölçüleri, notlar ve isteğe
bağlı fotoğraf.
- Belgeler: yüklediğiniz dosyalar (karne, reçete,
mahkeme kararı, kimlik belgesi vb.).
- Takvim: etkinlikler, velayet blokları, velayet
planları, takas talepleri.
- Mesajlar: eş-ebeveyninize gönderdiğiniz iletiler,
zaman damgaları ve "ilk görüntülenme" kaydı.
- Masraflar: tutar, kategori, tarih, bölüşüm oranı ve
isteğe bağlı fiş fotoğrafı.
- Aile ve davetler: aile üyelikleri, rol bilgisi,
gönderdiğiniz davetlerin e-posta adresi.
- Bildirim: anlık bildirim gönderebilmek için cihaz
(APNs) belirteci.
- Abonelik: premium abonelik durumu ve abonelik yönetim
kimliği (ödeme kartı bilgilerinizi görmüyoruz; bkz. §5).
Reklam kimliği, konum takibi, rehber erişimi veya üçüncü
taraf analitik/izleme verisi toplamıyoruz.
2. Verileri nasıl kullanırız
- Hizmeti sunmak: takvim, mesaj, masraf ve belgelerin sizin ve (varsa)
eş-ebeveyninizin erişebileceği şekilde saklanması.
- Anlık bildirim göndermek (yeni mesaj, takas talebi, masraf vb.).
- Şifre sıfırlama kodunu e-posta ile iletmek.
- Talebiniz üzerine doğrulanabilir PDF rapor üretmek.
- Hizmetin güvenliğini sağlamak (kaba kuvvet saldırılarına karşı koruma
dâhil).
3. Gizlilik tasarımı: bilinçli kararlarımız
- Fotoğraf konum verisi silinir. Fiş ve belge
fotoğrafları yüklenmeden önce cihazınızda EXIF/GPS meta verisinden
temizlenir — böylece ev adresiniz karşı tarafa sızmaz.
- Üslup asistanı cihazda çalışır. Mesaj taslağınızı
yumuşatma önerisi tamamen cihazınızda üretilir; taslaklar sunucuya
gönderilmez ve hiçbir yere kaydedilmez.
- Sunucu "tarafsız noter"dir. Mesajlar değiştirilemez
(append-only), zaman damgalı ve hash zinciriyle korunur. Bu doğrulama
işlevi içeriğe erişim gerektirdiğinden, uçtan uca şifreleme (E2EE)
bilinçli olarak uygulanmaz; bunu açıkça belirtiriz.
- Belgeler özel depolamada. Yüklenen dosyalar özel bir
depoda tutulur ve yalnızca kısa ömürlü, imzalı bağlantılarla erişilir;
herkese açık kalıcı URL üretilmez.
- Avukat erişimi salt-okunurdur. Görüntüleyici
rolündeki bir kullanıcı hiçbir kaydı değiştiremez ve davet gibi sır
niteliğindeki verileri göremez.
Aktarım sırasında tüm trafik TLS (HTTPS) ile şifrelenir; şifreler güvenli
özetle saklanır; barındırma ve dosya sağlayıcılarımız verileri beklemede
(at rest) şifreler. Belirli hassas alanlar için
uygulama katmanında ek şifreleme, yol haritamızdaki bir geliştirmedir ve
henüz devrede değildir; bu politika yalnızca hâlihazırda geçerli olan
uygulamaları tanımlar.
4. Paylaşılan alan ile özel alan
Eş-ebeveyninizle aynı ailedeyseniz, o aileye ait kayıtlar (takvim, mesaj,
masraf, belge) tanımı gereği iki taraf için de görünürdür — hizmetin amacı
budur. Tek başına (solo) kullanıyorsanız kayıtlarınız özeldir; karşı taraf
daveti sonradan kabul ederse yalnızca paylaşılan alan açılır, solo döneme
ait özel kayıtlarınız açılmaz.
5. Verileri kimlerle paylaşırız
Verilerinizi satmayız. Yalnızca hizmeti çalıştırmak için
gereken hizmet sağlayıcılarla (veri işleyenlerle) paylaşırız:
- Barındırma ve veritabanı (Railway) — uygulama
sunucusu ve veritabanı.
- Dosya depolama (Cloudflare R2) — fiş ve belge
fotoğrafları, özel depoda.
- Anlık bildirim (Apple Push Notification service).
- Abonelik yönetimi (Apple App Store ve RevenueCat) —
ödeme Apple üzerinden gerçekleşir; kart bilgilerinizi biz
görmeyiz. Abonelik durumunu takip etmek için takma (anonim) bir abonelik
kimliği kullanılır.
- E-posta — yalnızca şifre sıfırlama gibi işlemsel
e-postaları iletmek için bir e-posta hizmeti.
Ayrıca yasal bir yükümlülük (mahkeme kararı vb.) hâlinde gerekli veriyi
yetkili mercilerle paylaşabiliriz.
6. Saklama ve silme
- Hesap silme = gerçek silme. Uygulama içinden
hesabınızı silebilirsiniz. Tek başına kullanıyorsanız verileriniz (dosyalar
dâhil) kalıcı olarak silinir.
- Paylaşılan ailede kayıtlar aynı zamanda
eş-ebeveyninizin kaydıdır; bu durumda içerik korunur ancak kimliğiniz
anonimleştirilir (ad ve e-posta) ve hesabınız kapatılır.
- Kayıtlarınız sizindir. Kayıtlarınızı, Coparoo Premium
ile sunulan doğrulanabilir bir PDF rapor olarak dışa aktarabilir ve
hesabınızı uygulama içinden istediğiniz zaman silebilirsiniz.
7. Çocukların gizliliği
Coparoo çocuklara yönelik değildir; hesabı yetişkin ebeveynler açar ve
çocuğa ait bilgileri ebeveyn girer. Uygulamayı çocuklar doğrudan
kullanmaz.
8. Haklarınız (KVKK / GDPR)
Yürürlükteki mevzuata (Türkiye'de KVKK, Avrupa'da GDPR) göre; verilerinize
erişme, düzeltme, silme, işlemeyi kısıtlama ve taşınabilirlik haklarına
sahipsiniz. Bu hakları uygulama içi araçlarla (düzenleme, dışa aktarım, hesap
silme) kullanabilir veya
[email protected] adresinden bize
başvurabilirsiniz.
9. Değişiklikler
Bu politikayı zaman zaman güncelleyebiliriz; önemli değişikliklerde
uygulama içinde veya e-posta ile bilgilendiririz. Güncel sürüm her zaman bu
adreste yayımlanır.