Privacy Policy
This policy explains which personal data is processed when you use the Coffy mobile app (the “App”), why, who it is shared with and what your rights are. It serves as the privacy notice under the Turkish Personal Data Protection Law No. 6698 (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR). If this English version differs from the Turkish version, the Turkish version prevails.
1. Data controller
[DATA CONTROLLER: full name / company name], [address].
Contact: support@coffyapp.com
2. Account: no e-mail or password
Coffy has no Apple, Google or e-mail sign-in. On first launch the App creates a random app identifier and stores it in your device’s secure storage (iOS Keychain / Android Keystore). Your account is created anonymously with this identifier. It is not your advertising ID, phone number or hardware serial number.
3. Data we process
| Data | Examples | Purpose |
|---|---|---|
| Account and device | App identifier, platform (iOS/Android), app version, language, time zone, account creation and last sign-in time, credit balance | Running your account, session security, credits |
| Profile | Nickname and date of birth (required); time of birth and its accuracy, place of birth (city, coordinates, time zone), gender, relationship status (optional); your zodiac sign | Personalising readings, astrological calculations |
| Readings and content | Coffee cup/saucer photos, dream texts, questions and intentions, tarot card choices, generated readings, favourites, “was this helpful” votes and comments, journal entries | Generating the reading you request, showing your history and journal, improving quality |
| Information you enter about other people | Another person’s name and date of birth entered for compatibility or spiritual readings | Only to generate the reading you request |
| Rewarded ads | Time and status of a reward session, AdMob transaction ID | Verifying your credit when you watch an ad to the end, preventing abuse |
Before entering information about another person, make sure they are aware of it. We recommend that you do not enter special categories of data such as health, religion or political opinions.
The App uses no analytics or crash-reporting tools (e.g. Firebase Analytics). Our servers do not store IP addresses in application logs.
4. AI-generated readings
Readings are generated with Google’s Gemini API. When you request a reading, its inputs (e.g. cup photos, dream text, birth details from your profile) are sent to Google to generate it. Google processes this data under the Gemini API Additional Terms of Service. Readings are generated automatically for entertainment; no automated decision with legal effect is made about you.
5. Advertising
You may optionally watch rewarded ads to earn free credits. Ads are served by Google AdMob. AdMob processes data such as the advertising identifier (IDFA on iOS if you allow it, the advertising ID on Android), device information and IP address to show and measure ads and prevent fraud.
- In the European Economic Area, the UK and Switzerland, Google’s consent form is shown before ads. You can change your choice with the “Ad privacy choices” button on the Profile screen.
- On iOS, tracking permission (App Tracking Transparency) is only requested when you choose to watch an ad; if you decline you can still watch rewarded ads, which are shown without your advertising ID.
- Only an anonymous user ID and a session ID are passed to AdMob to verify the reward; your profile and readings are not shared with the ad network.
Details: How Google uses information from sites or apps that use its services.
6. Recipients
- netcup GmbH (Germany): application server and database.
- Cloudflare, Inc.: domain/DNS and file storage (cup photos and database backups, stored encrypted by Cloudflare).
- Google LLC / Google Ireland Ltd.: Gemini API (reading generation) and AdMob (ads).
Some of these providers may process data outside Türkiye and the EU (e.g. in the USA). Such transfers are made under Article 9 of the KVKK and appropriate GDPR safeguards (e.g. standard contractual clauses). We do not sell your data.
7. Legal bases
- Providing the service and the readings you request: performance of a contract (KVKK Art. 5/2-c; GDPR Art. 6/1-b).
- Security, abuse prevention, backups: legitimate interests (KVKK Art. 5/2-f; GDPR Art. 6/1-f).
- Personalised advertising and tracking: consent (KVKK Art. 5/1; GDPR Art. 6/1-a). You may withdraw it at any time.
8. Retention
- Account data is kept while your account exists.
- When you delete a reading, its photos are deleted from storage.
- When you delete your account, all your data is removed from live systems immediately and your photos are permanently deleted shortly after. It may remain in database backups for up to 30 more days, after which it is deleted automatically.
- Server logs are rotated and overwritten after a short time.
9. Security
All traffic is encrypted with HTTPS (TLS). Your session keys are kept in secure storage on your device and server access is restricted. No system is 100% secure, but we take reasonable technical and organisational measures to protect your data.
10. Your rights
Under Article 11 of the KVKK and the GDPR you have the right to know whether your data is processed, to request information and a copy, rectification, erasure, restriction or objection, portability, and to withdraw consent.
- You can edit your profile in the App.
- You can delete your account and all your data in the App: Account & data deletion.
- For other requests, write to support@coffyapp.com including the support ID shown on your Profile screen. We reply within 30 days.
You may also lodge a complaint with the Turkish Personal Data Protection Board or the data protection authority in your country.
11. Children
The App is not directed to children under 13 and we do not knowingly collect data from them. If you become aware of such a case, contact us and we will delete the data.
12. Changes
We may update this policy. We will announce significant changes in the App; the current version is always on this page.