Privacy Policy
Effective Date: February 14, 2025
1. Introduction
Welcome to Rutinly ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application ("App") and related services.
By using Rutinly, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use the App.
2. Information We Collect
2.1 Personal Information
We collect the following types of personal information:
- Email Address: Used for account authentication and important service communications
- Habit and Routine Data: The routines you create, track, and share
- User ID: A unique identifier generated for friend connections
- Profile Information: Optional display name and avatar
2.2 Automatically Collected Information
- Device Information: Device type, operating system version, unique device identifiers
- Usage Data: App features used, session duration, interaction patterns
- Push Notification Tokens: For delivering notifications (if you opt-in)
- Analytics Data: Collected via Firebase Analytics to improve app performance
- Advertising Data: Device advertising ID collected by Google AdMob for personalized ads
2.3 Information You Provide
- Content you create (routines, notes, shared content with friends)
- Support requests and feedback you submit
3. How We Use Your Information
We use the collected information for the following purposes:
- Service Delivery: To provide, maintain, and improve the App functionality
- Authentication: To verify your identity and manage your account
- Social Features: To enable friend connections and shared routines
- Notifications: To send you reminders, updates, and important service announcements
- Analytics: To understand how users interact with the App and improve user experience
- Advertising: To display relevant ads through Google AdMob
- Support: To respond to your inquiries and provide customer support
- Security: To detect, prevent, and address technical issues and fraudulent activity
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), our legal basis for collecting and using your information includes:
- Consent: You have given explicit consent for specific processing activities (e.g., push notifications, personalized ads)
- Contract Performance: Processing is necessary to provide the services you requested
- Legitimate Interest: We have a legitimate interest in improving our services, preventing fraud, and ensuring security
- Legal Obligation: Processing is required to comply with legal requirements
5. Third-Party Services
We use the following third-party services that may collect, process, or store your data:
5.1 Firebase (Google Cloud Platform)
- Purpose: Authentication, database, analytics, and push notifications
- Data Shared: Email, user ID, usage data, device information
- Privacy Policy: firebase.google.com/support/privacy
5.2 Google AdMob
- Purpose: Advertising
- Data Shared: Device advertising ID, IP address, usage data
- Privacy Policy: policies.google.com/privacy
- Opt-out: You can opt-out of personalized ads via your device settings (iOS: Settings > Privacy > Advertising; Android: Settings > Google > Ads)
5.3 Apple Push Notification Service (APNs)
- Purpose: Delivering push notifications on iOS devices
- Data Shared: Device token, notification content
- Privacy Policy: apple.com/legal/privacy
6. Data Security
We implement industry-standard security measures to protect your personal information, including:
- Encryption of data in transit using TLS/SSL
- Encryption of data at rest on Firebase servers
- Secure authentication protocols
- Regular security audits and updates
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Data Retention and Deletion
We retain your personal data only as long as necessary for the purposes outlined in this policy or as required by law.
- Active Accounts: Data is retained while your account is active
- Account Deletion: Upon deleting your account through the App settings, all personal data is permanently deleted within 30 days
- Backup Data: Backup copies are deleted within 90 days of account deletion
Some data may be retained for longer periods if required by law or for legitimate business purposes (e.g., fraud prevention, legal compliance).
8. Your Rights
8.1 GDPR Rights (EEA Users)
If you are located in the EEA, you have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to certain processing activities
- Right to Restrict Processing: Request limitation of data processing
- Right to Withdraw Consent: Withdraw consent at any time (where processing is based on consent)
8.2 KVKK Rights (Turkish Users)
Türkiye'de bulunan kullanıcılar aşağıdaki haklara sahiptir:
- Kişisel verilerinizin işlenip işlenmediğini öğrenme
- İşlenmişse bilgi talep etme
- İşlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme
- Yurt içinde veya yurt dışında aktarıldığı üçüncü kişileri bilme
- Eksik veya yanlış işlenmişse düzeltilmesini isteme
- KVKK'nın 7. maddesinde öngörülen şartlar çerçevesinde silinmesini veya yok edilmesini isteme
- Aktarıldığı üçüncü kişilere yukarıdaki işlemlerin bildirilmesini isteme
- Münhasıran otomatik sistemler ile analiz edilmesi nedeniyle aleyhinize bir sonucun ortaya çıkmasına itiraz etme
- Kanuna aykırı olarak işlenmesi sebebiyle zarara uğramanız halinde zararın giderilmesini talep etme
8.3 Exercising Your Rights
To exercise any of these rights, please contact us at: info@ipektech.dev
We will respond to your request within 30 days. You may also have the right to lodge a complaint with a supervisory authority.
9. Children's Privacy
Rutinly is NOT intended for children under the age of 13.
We do not knowingly collect personal information from children under 13. If you are under 13, please do not use this App or provide any information.
If we discover that we have collected personal information from a child under 13 without parental consent, we will delete that information immediately.
Parents or guardians who believe we have collected information from a child under 13 should contact us at info@ipektech.dev.
10. International Data Transfers
Your data is stored on Firebase servers operated by Google Cloud Platform, which may be located in various countries worldwide.
Google complies with the EU-U.S. Data Privacy Framework and implements appropriate safeguards for international data transfers.
By using Rutinly, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection laws.
11. Cookies and Tracking Technologies
Our website (rutinly.app) uses cookies and similar tracking technologies to improve user experience and analyze site usage.
- Essential Cookies: Required for the website to function (e.g., language preference)
- Analytics Cookies: Google Analytics to understand how visitors use our website
You can control cookies through your browser settings. However, disabling cookies may affect website functionality.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will:
- Update the "Effective Date" at the top of this policy
- Notify you through the App or via email (for material changes)
- Post the updated policy on our website
Your continued use of the App after changes take effect constitutes acceptance of the updated Privacy Policy.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: info@ipektech.dev
Website: rutinly.app
14. Supervisory Authority
For EEA Users: You have the right to lodge a complaint with your local data protection authority.
For Turkish Users: Kişisel Verileri Koruma Kurumu (KVKK) - kvkk.gov.tr