1. Data we collect
Kidelon processes the following data categories to provide the service:
- Account data: name, email, password hash, phone (optional).
- Family structure: family members, role (admin/member), invitation records.
- Child profile: name, age, avatar (entered by the parent).
- Usage metrics: app name + screen time + visited domain. Content (messages, video, games) is NOT captured.
- Location: only entry/exit events for the geofences you defined.
- Device technical data: model, OS version, battery percentage (anti-uninstall + diagnostics).
2. How we use the data
Only to: deliver the parental-control service, unlock premium features for paying users, provide customer support, and meet legal obligations.
3. Where we store data
Primary: Hetzner Falkenstein (EU, GDPR adequacy). Backup: Türkiye-based HK Solutions server. All data is AES-256 encrypted at rest and TLS 1.3 in transit.
4. Children's privacy
For under-13s (COPPA) and under-18s (KVKK, GDPR Article 8): no advertising profiles without parental consent, no third-party marketing sharing, child data minimised to what is strictly necessary.
5. Third-party services
- Firebase (Google, push notifications): device token
- RevenueCat (subscriptions): purchase receipt
- Sentry (crash reporting): error stack trace + device version
- Diyanet API (prayer-time mode): city name (anonymous)
None of them has access to child-data content.
6. Your rights
Under KVKK Article 11 and GDPR Articles 15-22: access, rectification, erasure, portability, objection. Send requests to dpo@kidelon.com — handled within 30 days. See the full privacy notice.
7. Retention
- Account data: until deletion + 30-day grace period.
- Usage logs: 180 days (then anonymous aggregate).
- Audit log: 7 years (KVKK + financial obligation).
To delete your account or specific data categories: Account deletion · Data deletion.
8. Contact
Data-protection contact: dpo@kidelon.com · Main contact: hasanomerkocakaya@gmail.com