Privacy Policy
Version 1.0 · Effective date: August 24, 2026 · Last updated: August 24, 2026
Türkçe · KVKK Aydınlatma Metni
ArtistiCo is a social network for artists. This policy explains what personal data the ArtistiCo mobile app and its backend collect, why, how long it is kept, who it is shared with, and what you can do about it.
The short version. We collect the email address you sign in with, the profile and content you choose to publish, and the technical minimum needed to deliver messages and fix crashes. There is no advertising, no ad network, no third-party analytics SDK, and no cross-app or cross-site tracking in ArtistiCo. We do not sell personal data, and we never have.
1. Who is responsible for your data
The data controller is Sude Hereklioğlu (founder of ArtistiCo), acting as a natural person under Turkish law, based in Türkiye.
| Purpose | Contact |
|---|---|
| Privacy questions, data subject requests | privacy@artisticoapp.com |
| Support, reports, appeals | support@artisticoapp.com |
ArtistiCo is expected to be incorporated as a company in the future. If the controller changes, this policy will be updated and you will be told in the app before the change takes effect.
If you are in Türkiye, the Turkish-language KVKK Disclosure Notice (Aydınlatma Metni) is the controlling document for your rights under Law No. 6698. In case of conflict between translations, the Turkish text prevails for users in Türkiye.
2. What we collect
2.1 Data you give us directly
| Category | What exactly | Required? |
|---|---|---|
| Account identity | Email address; whether it has been verified; the date you joined | Required — it is how you sign in |
| Sign-in with Apple / Google | The stable user identifier (sub) issued by Apple or Google, and the email address they release to us |
Only if you choose that sign-in method |
| Password | An optional password, stored only as a salted hash. ArtistiCo works without one — a one-time emailed code is the default | Optional |
| Public profile | Handle, display name, bio, city, artistic disciplines, avatar and banner images, links to your other sites and social accounts | Handle and display name required; the rest optional |
| Professional history | Experience (role, organisation, employment type, start and end dates), education (school, degree, years), featured work and portfolio items | Optional |
| Content you publish | Posts, captions, comments, likes, listings (jobs, orders, equipment, venues, workshops) including any compensation figures you enter, communities you create or join | Optional |
| Photos and video | Images and video you pick from your photo library or shoot with the camera | Optional |
| Direct messages | The content of conversations you have with other members, and read/delivery status | Optional |
| Reports and blocks | Who you reported or blocked, the reason category, and any note you wrote | Optional |
| Settings | Private-account and show-city preferences; per-category push notification preferences | Defaults applied if untouched |
2.2 Data collected automatically
| Category | What exactly | Why |
|---|---|---|
| Session tokens | Access and refresh tokens. On your device they are held in the iOS Keychain / Android Keystore, not in ordinary app storage | To keep you signed in without re-entering a code |
| One-time codes | A hash of each 6-digit code, its expiry, and the number of attempts. The code itself is never stored. | To verify your email address and to rate-limit guessing |
| Push registration | Platform (iOS/Android), push token, app version, last-seen timestamp — one record per install | To deliver notifications you asked for |
| Crash reports | Error type, message, stack trace, the screen it happened on, platform, app version, and the identifier of the most recent member who hit it | To fix bugs. See §5 — this is self-hosted, not sent to a third party |
| Server logs | Standard web-server records including IP address, timestamp and the endpoint called | Security, abuse prevention, debugging |
| Social graph | Who you follow, who follows you, communities you belong to, and counts derived from them | To build your feed and show your profile |
2.3 What we deliberately do not collect
- Precise or background location. ArtistiCo never requests location permission. The “city” on your profile is free text you type; it is not derived from GPS, Wi-Fi or your IP address, and you can leave it blank or hide it in Settings → Privacy.
- Your contacts or address book. Never requested, never uploaded.
- Advertising identifiers (IDFA / GAID) and any form of ad targeting or measurement.
- Third-party analytics or attribution SDKs. The app ships with no analytics, crash-reporting, attribution or ad-network SDK of any kind.
- Government identity documents. We do not ask for, and will not store, scans or photographs of ID cards, passports or driving licences.
- Health, biometric, religious, political or other special-category data. We do not ask for it. Please do not put it in your profile or posts.
2.4 Photo metadata is removed
Photos taken on a phone usually carry embedded metadata (EXIF), which can include the date, the camera model, and — if location tagging is enabled in your camera app — the exact GPS coordinates where the photo was taken.
ArtistiCo removes this. Every uploaded image is re-encoded on our servers before it is published, which strips EXIF from the stored file and from every thumbnail and resized copy generated from it. The coordinates of the place you took a photo are not published with it, and are not retained.
The image you see is unaffected: dimensions and orientation are preserved.
3. Why we use it, and on what legal basis
| Purpose | Data used | Legal basis (KVKK Art. 5 / GDPR Art. 6) |
|---|---|---|
| Creating and running your account | Email, tokens, one-time codes | Necessary for performance of the contract between us |
| Showing your profile and content to other members | Profile, posts, listings, portfolio | Performance of the contract; your own act of publishing |
| Delivering messages and notifications | Messages, push token, notification preferences | Performance of the contract; consent for the OS-level push permission |
| Keeping the platform safe — reports, blocks, moderation, rate limits | Reports, blocks, logs, IP address | Legitimate interest in a safe service; compliance with legal obligations |
| Fixing crashes and improving reliability | Crash reports, app version, platform | Legitimate interest in a working product |
| Answering support requests | Whatever you send us | Performance of the contract; legitimate interest |
| Complying with the law | As required by a valid legal request | Legal obligation |
| Transferring data outside Türkiye to run the service | Effectively all of the above | Your explicit consent — see §5.2 |
We do not carry out profiling that produces legal effects for you, and we make no automated decisions about you without human involvement.
4. What other people can see
ArtistiCo is a public professional network. By design:
- Your handle, display name, avatar, banner, bio, disciplines, experience, education, portfolio, posts, listings, follower and following counts are visible to anyone using the app, and, where a link is shared, to anyone who opens that link.
- Your city is visible unless you turn off “Show city” in Settings → Privacy.
- Turning on “Private account” restricts who can see your content going forward. It does not retract copies other people already saw, screenshotted or saved.
- Direct messages are visible to the people in the conversation. They are not end-to-end encrypted — they are encrypted in transit and at rest, but the platform is technically able to access them, and will do so where a report or a valid legal order requires it.
- Your email address is never shown to other members.
5. Who we share it with
5.1 Service providers
ArtistiCo runs on infrastructure operated by other companies. They process data on our instructions only, and are not permitted to use it for their own purposes.
| Provider | What it handles | Where |
|---|---|---|
| DigitalOcean | Application servers and the PostgreSQL database — the whole service, including profiles, posts, listings and messages | Frankfurt, Germany (EU) |
| Cloudflare (R2) | Photos, video and their generated thumbnails; delivery of those files | EU / global edge network |
| Resend | Sending transactional email — sign-in codes and account notices. Receives your email address and the message body | United States |
| Apple, Google | App distribution; push notification delivery; sign-in verification if you use Sign in with Apple or Google | United States and global |
Crash reporting is self-hosted on the same infrastructure — it is not sent to Sentry, Crashlytics or any other third-party service.
5.2 Transfers outside Türkiye
Because our servers are in Frankfurt and some providers are established in the United States, using ArtistiCo necessarily involves transferring your personal data abroad. Türkiye has not issued an adequacy decision for these countries. We therefore rely on your explicit consent (açık rıza) under Article 9 of Law No. 6698, and we are working to put the standard contractual clauses under Article 9/3 in place as the longer-term basis.
If you do not want your data transferred abroad, ArtistiCo cannot be provided to you, because there is no version of the service that runs without this infrastructure.
5.3 Other disclosures
- Legal requests. We disclose data where a court order, prosecutor’s request or other legally binding demand requires it. We check that a request is valid and disclose no more than it asks for.
- Safety. We may disclose data to prevent imminent harm to a person.
- Business transfer. If ArtistiCo is incorporated, merged or acquired, personal data may transfer to the successor entity under this policy. You will be told in the app before that happens.
- We do not sell personal data, and we do not share it for advertising or marketing by anyone else.
6. How long we keep it
| Data | Retention |
|---|---|
| Account and profile | For as long as your account exists |
| Deleted account | Deactivated immediately; permanently deleted after 30 days. Signing in during those 30 days restores the account |
| Posts, listings, comments, portfolio | Until you delete them, or until your account is permanently deleted |
| Direct messages | Until the conversation is deleted or the account is permanently deleted. When your account is permanently deleted, the messages you sent are removed from the recipient’s conversation too |
| One-time sign-in codes | 10 minutes, then expired |
| Push registrations | Deleted when you sign out or delete your account |
| Reports and moderation records | Kept after the report is resolved, so repeat behaviour can be recognised and decisions can be appealed |
| Crash reports | Kept while the bug is open. The member link is severed — not deleted along with the report — when an account is deleted |
| Server logs | Short-lived, on the hosting provider’s rolling cycle |
7. Deleting your account
Open the app and go to Settings → Manage Account → Delete account. Your account is deactivated immediately and permanently deleted after 30 days; signing in within that window restores it. If you cannot get into the app, email privacy@artisticoapp.com from your registered address. Full instructions: Deleting your ArtistiCo account.
8. Your rights
Under Article 11 of Turkish Law No. 6698 (KVKK) — and, if you are in the EEA or UK, under the GDPR — you may:
- learn whether we process your personal data, and request information about it;
- learn the purpose of processing and whether it is used accordingly;
- know the third parties, in Türkiye or abroad, to whom it is transferred;
- request that incomplete or inaccurate data be corrected;
- request erasure or destruction, and that any third party we transferred it to be told;
- object to a result produced solely by automated analysis;
- claim compensation for damage caused by unlawful processing;
- and, under the GDPR additionally: restrict processing, receive your data in a portable format, and withdraw consent at any time without affecting processing already carried out.
Write to privacy@artisticoapp.com from the address on your account. We answer within 30 days and free of charge, as Article 13 of the KVKK requires. If you are unhappy with the answer, you may complain to the Turkish Personal Data Protection Authority at kvkk.gov.tr, or to your local supervisory authority in the EEA or UK.
9. Security
- All traffic between the app and our servers uses HTTPS/TLS; the app refuses unencrypted connections in release builds.
- Session tokens are stored in the iOS Keychain and the Android Keystore, not in plain app storage.
- Sign-in codes are stored only as salted hashes, expire after 10 minutes, and lock out after 5 failed attempts.
- Passwords, where set, are stored as salted hashes and never in plain text.
- Uploads are validated by actual content type, not by filename.
- Deleting your account blacklists every outstanding token, so other signed-in devices lose access.
No system is perfectly secure. If we discover a breach that presents a risk to you, we will notify you and the KVKK Authority within the periods the law requires (72 hours to the Authority, as soon as reasonably possible to you).
10. Children
ArtistiCo is not for children. You must be at least 13 years old to use it, and if you are under 18 you may only use it with the consent of a parent or guardian. We do not knowingly collect data from children under 13. If you believe a child under 13 has an account, write to privacy@artisticoapp.com and we will delete it.
11. Changes
We will post any change here with a new version number and date. For a change that materially affects your rights, we will notify you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.
12. Contact
Sude Hereklioğlu — ArtistiCo · Türkiye Privacy: privacy@artisticoapp.com Support: support@artisticoapp.com