Gizlilik Politikası
Son güncelleme: 14 Ağustos 2026
Bu Gizlilik Politikası, Piklabs Yazılım ve Teknoloji Hizmetleri Limited Şirketi tarafından işletilen piCue mobil uygulamasını, picue.app internet sitesini ve bunlarla bağlantılı dijital hizmetleri kullanırken kişisel verilerinin nasıl toplandığını, işlendiğini, saklandığını, aktarıldığını ve korunduğunu açıklar.
Bu metin; 6698 sayılı Kişisel Verilerin Korunması Kanunu, ilgili ikincil mevzuat ve uygulanabildiği ölçüde Avrupa Birliği Genel Veri Koruma Tüzüğü dikkate alınarak hazırlanmıştır.
Avrupa Birliği Genel Veri Koruma Tüzüğü, her kullanıcı bakımından otomatik olarak uygulanmaz. Tüzüğün uygulanıp uygulanmayacağı; kullanıcının bulunduğu ülke, hizmetin Avrupa Birliği veya Avrupa Ekonomik Alanı’ndaki kişilere sunulup sunulmadığı, şirketin Avrupa’daki faaliyetleri, kişisel verilerin işlenme biçimi ve hizmetin ilgili pazarı hedefleyip hedeflemediği dikkate alınarak ayrıca değerlendirilir. Bu nedenle Avrupa Birliği Genel Veri Koruma Tüzüğü’ne yapılan atıflar, Türkiye’de bulunan tüm kullanıcılar bakımından otomatik olarak Tüzük kapsamının bulunduğu anlamına gelmez.
Bu Gizlilik Politikası, kişisel verilerinin işlenmesine ilişkin genel açıklamaları içerir. Belirli bir veri toplama faaliyeti sırasında ayrıca bir KVKK aydınlatma metni, açık rıza metni, çerez bildirimi, abonelik koşulu veya kullanıcı sözleşmesi sunulması hâlinde, ilgili özel metin de dikkate alınır.
1. Veri sorumlusu ve iletişim bilgileri
Kişisel verilerinin işleme amaçlarını ve araçlarını belirleyen veri sorumlusu:
Ticaret unvanı: Piklabs Yazılım ve Teknoloji Hizmetleri Limited Şirketi
Şirket türü: Limited şirket
Merkez adresi: Gayrettepe Mah. Nurgül Sk. Polat 8 Apt. No: 8 İç Kapı No: 2, Beşiktaş/İstanbul
İnternet sitesi: picue.app
Kişisel veri talepleri ve başvurular: hey@picue.app
Kullanıcı destek ve moderasyon: support@picue.app
Piklabs Yazılım ve Teknoloji Hizmetleri Limited Şirketi, piCue mobil uygulaması, picue.app internet sitesi ve bunlarla bağlantılı dijital hizmetler kapsamında kişisel verilerin işleme amaçlarını ve araçlarını belirlediği ölçüde veri sorumlusu sıfatıyla hareket eder.
Kişisel veri başvuruları hey@picue.app adresine; kullanıcı içerikleri, moderasyon kararları, hesap güvenliği, teknik destek ve topluluk işlemleriyle ilgili başvurular ise support@picue.app adresine iletilebilir.
Şirket, başvuru sahibinin kimliğini doğrulamaya ve üçüncü kişilere ait kişisel verilere erişimi önlemeye elverişli ölçüde ek bilgi isteyebilir. Kimlik doğrulama amacıyla istenen bilgiler, yalnızca başvurunun değerlendirilmesi ve güvenli biçimde sonuçlandırılması için kullanılır.
2. Bu politika hangi hizmetler için geçerlidir?
Bu Gizlilik Politikası aşağıdaki hizmetler için geçerlidir:
- piCue mobil uygulaması,
- picue.app internet sitesi,
- kullanıcı hesabı ve hesap yönetimi,
- İzleme DNA özelliği,
- Picsona özelliği,
- film ve dizi öneri sistemleri,
- kullanıcı profilleri,
- başlık ve yorum alanları,
- takip ve takipçi özellikleri,
- favoriler, izleme listeleri ve koleksiyonlar,
- CueMates eşleşmeleri,
- uygulama içi oyunlar ve puanlama sistemleri,
- Plus aboneliği,
- uygulama içi bildirimler,
- reklam gösterimi ve reklam ölçüm faaliyetleri,
- kullanıcı destek hizmetleri,
- şikâyet, moderasyon ve topluluk güvenliği süreçleri,
- picue.app üzerindeki hesap ve içerik işlevleri.
Üçüncü kişiler tarafından işletilen uygulama mağazaları, ödeme altyapıları, reklam platformları, içerik sağlayıcıları, harici internet siteleri ve bağlantı verilen diğer hizmetlerin kendi kişisel veri işleme faaliyetleri bu politikanın kapsamı dışındadır. Bu kuruluşlar kendi gizlilik politikaları, kullanıcı sözleşmeleri ve veri işleme kurallarından sorumludur.
Bununla birlikte, Piklabs’ın üçüncü taraf hizmet sağlayıcılarla yaptığı sözleşmeler ve veri aktarım düzenlemeleri kapsamında gerekli teknik ve hukuki kontroller yapılır.
3. Hangi kişisel verileri işliyoruz?
Kullandığın özelliklere ve piCue ile olan ilişkine bağlı olarak aşağıdaki kişisel veri kategorileri işlenebilir.
- Kimlik ve hesap verileri: Kullanıcı adı, görünen ad, hesap kimliği, profil bilgileri, hesap oluşturma tarihi, hesap durumu, hesap kapatma kaydı ve hesapla ilişkilendirilen teknik tanımlayıcılar.
- İletişim verileri: E-posta adresi, doğrulama bilgileri, destek taleplerinde paylaşılan iletişim bilgileri ve hesap güvenliği amacıyla kullanılan iletişim kayıtları.
- Profil ve görsel veriler: Profil fotoğrafı, kapak fotoğrafı, kullanıcının yüklediği görseller, görsellerle bağlantılı açıklamalar ve bu içeriklerin görünürlük tercihleri.
- Yaş ve bölge verileri: Doğum tarihi, yaş bilgisi veya yaş doğrulama sonucu ile kullanıcının kendisinin girdiği il ve ilçe bilgileri. Mevcut hizmet tasarımı bakımından GPS, hassas konum veya sürekli gerçek zamanlı konum bilgisi toplanması amaçlanmaz.
- İçerik ve tercih verileri: İzleme DNA testine verilen cevaplar, kart seçimleri, favoriler, izlenen içerikler, izleme listeleri, koleksiyonlar, film ve dizi tercihleri, öneri sonuçları ve kullanıcının hizmet içindeki etkileşimleri.
- Topluluk verileri: Başlıklar, yorumlar, oylar, takip edilen hesaplar, takipçiler, CueMates eşleşmeleri, oyun puanları, kullanıcı tarafından herkese açık hâle getirilen koleksiyonlar ve topluluk içindeki diğer faaliyetler.
- Destek ve moderasyon verileri: Kullanıcı şikâyetleri, şikâyet nedeni, şikâyet açıklaması, inceleme kayıtları, moderasyon kararları, kaldırılan içerikler, uyarılar, geçici uzaklaştırmalar, hesap kapatma kayıtları ve kararlara ilişkin itirazlar.
- Abonelik ve işlem verileri: Plus aboneliğinin aktif olup olmadığı, abonelik türü, abonelik başlangıç ve bitiş bilgileri, uygulama mağazası işlem kimliği, satın alma doğrulama kayıtları ve abonelik durumunun yönetilmesi için gerekli teknik bilgiler.
Ödeme işleminin Apple veya Google gibi uygulama mağazaları tarafından yürütüldüğü modelde banka kartı numarası, kredi kartı numarası, kart güvenlik kodu veya banka hesabı bilgileri Piklabs tarafından alınmaz. Bu bilgilerin hangi kuruluş tarafından işlendiği, ilgili uygulama mağazasının kendi politikalarına göre belirlenir.
- Cihaz ve teknik veriler: Cihaz modeli, işletim sistemi, uygulama sürümü, IP adresi, oturum bilgileri, güvenlik kayıtları, cihaz tanımlayıcısı, bildirim cihaz jetonu, hata kayıtları, erişim zamanları ve hizmetin çalışması için gerekli teknik günlük kayıtları.
- Reklam ve ölçüm verileri: Reklam tanımlayıcısı, reklam gösterimi ve etkileşim bilgileri, reklam tercihi, uygulama kullanımına ilişkin sınırlı ölçüm verileri ve kişiselleştirilmiş reklam izniyle ilgili kayıtlar.
Bu kategorilerden hangilerinin işleneceği, kullandığın özelliğe, verdiğin izinlere, hesap ayarlarına, cihazına ve uygulamanın teknik yapılandırmasına göre değişebilir.
4. Toplamadığımız veya kural olarak işlemeyeceğimiz veriler
Hizmetin mevcut tasarımı bakımından aşağıdaki verilerin toplanması veya işlenmesi amaçlanmaz:
- GPS verisi,
- hassas veya sürekli konum verisi,
- rehber ve kişi listesi,
- takvim bilgileri,
- mikrofon kayıtları,
- kamera üzerinden sürekli görüntü veya ses kaydı,
- cihaz galerisinin tamamı,
- sağlık bilgileri,
- ırk veya etnik köken bilgisi,
- siyasi düşünce,
- dinî veya felsefi inanç,
- cinsel hayat veya cinsel yönelim,
- biyometrik veri,
- genetik veri.
Fotoğraf yükleme özelliğini kullandığında, seçtiğin dosyanın uygulamaya iletilmesi amaçlanır. Cihazın galerisinin tamamına erişilmesi amaçlanmaz. Bununla birlikte, kullandığın cihazın işletim sistemi izinleri ve üçüncü taraf yazılım geliştirme kitleri bakımından teknik denetimler düzenli olarak yapılır.
Kullanıcıların başlık, yorum veya profil alanlarına özel nitelikli kişisel veri yazması hâlinde bu verilerin işlenmesi piCue’nin amacı değildir. Ancak kullanıcının kendi iradesiyle herkese açık biçimde paylaştığı içerik diğer kullanıcılar tarafından görülebilir. Bu nedenle kullanıcıların kendilerine veya üçüncü kişilere ait hassas kişisel verileri topluluk alanlarında paylaşmaması gerekir.
Bir kullanıcı tarafından platforma özel nitelikli kişisel veri yüklenmesi hâlinde, Piklabs bu içeriği kural ihlali, güvenlik, şikâyet, hukuki yükümlülük veya içerik moderasyonu kapsamında değerlendirmek zorunda kalabilir.
5. Kişisel verileri hangi amaçlarla işliyoruz?
Kişisel verilerini aşağıdaki amaçlarla işleriz:
- Kullanıcı hesabı oluşturmak,
- Kullanıcı hesabını yönetmek,
- Oturum açma işlemini gerçekleştirmek,
- Hesap güvenliğini sağlamak,
- Yaş koşullarını ve hizmete erişim sınırlamalarını uygulamak,
- İzleme DNA özelliğini çalıştırmak,
- Picsona özelliğini sunmak,
- Film ve dizi önerileri üretmek,
- Kullanıcı tercihlerini uygulamak,
- Başlık, yorum, takip, koleksiyon ve oyun özelliklerini sağlamak,
- CueMates eşleşmelerini yürütmek,
- Kullanıcı içeriklerini ilgili görünürlük tercihleri doğrultusunda yayımlamak,
- Kullanıcıların şikâyetlerini değerlendirmek,
- Kötüye kullanım, spam, sahte hesap ve dolandırıcılık faaliyetlerini önlemek,
- Platform güvenliğini sağlamak,
- Plus aboneliğini doğrulamak,
- Abonelik özelliklerini sunmak,
- Reklam göstermek,
- Reklam gösteriminin ölçümünü yapmak,
- Kişiselleştirilmiş reklam tercihlerini uygulamak,
- Kullanıcının izinleri doğrultusunda bildirim göndermek,
- Teknik sorunları tespit etmek ve gidermek,
- Uygulama performansını ölçmek,
- Ürün ve hizmetleri geliştirmek,
- Kullanıcı destek taleplerini cevaplamak,
- Moderasyon ve topluluk güvenliği faaliyetlerini yürütmek,
- Bilgi güvenliği ve siber güvenlik süreçlerini yürütmek,
- Hukuki yükümlülükleri yerine getirmek,
- Yetkili kurum ve kuruluşların hukuka uygun taleplerine cevap vermek,
- Hukuki uyuşmazlıklarda delil oluşturmak,
- Bir hakkın tesisi, kullanılması veya korunmasını sağlamak,
- Hizmetin kötüye kullanılmasını önlemek,
- Uygulamanın teknik ve ticari sürekliliğini sağlamak.
Yeni bir amaçla veri işlenmesi gerektiğinde, yeni amaç mevcut işleme amacıyla uyumlu değilse gerekli bilgilendirme yapılır ve hukuken gerekli olması hâlinde ayrıca açık rıza alınır.
6. Kişisel verilerin işlenmesindeki hukuki sebepler
Kişisel verilerin işlenmesinde her faaliyet bakımından aynı hukuki sebep kullanılmaz. İşleme faaliyetinin niteliğine göre aşağıdaki hukuki sebeplerden biri veya birkaçı uygulanabilir:
- Sözleşmenin kurulması veya ifası: Hesap oluşturulması, oturum açılması, piCue’nin temel özelliklerinin sunulması, kullanıcı tercihleri doğrultusunda öneri üretilmesi, topluluk özelliklerinin çalıştırılması ve Plus aboneliğinin tanınması için gerekli veriler bu hukuki sebebe dayanabilir.
- Veri sorumlusunun meşru menfaati: Hizmet güvenliğinin sağlanması, kötüye kullanımın önlenmesi, sahte hesaplarla mücadele, teknik sorunların giderilmesi, sistemlerin geliştirilmesi ve platformun güvenli işletilmesi bakımından gerekli veriler, kullanıcının temel hak ve özgürlüklerine zarar vermemek kaydıyla bu hukuki sebebe dayanabilir.
- Hukuki yükümlülük: Mali ve ticari kayıtların tutulması, yetkili kamu kurumlarının hukuka uygun taleplerinin karşılanması, mevzuattan doğan saklama ve bildirim yükümlülüklerinin yerine getirilmesi bakımından veri işlenebilir.
- Bir hakkın tesisi, kullanılması veya korunması: Şikâyetlerin değerlendirilmesi, moderasyon kararları, güvenlik soruşturmaları, dolandırıcılık incelemeleri, uyuşmazlıkların yönetilmesi ve hukuki taleplerin değerlendirilmesi bakımından gerekli veriler bu hukuki sebebe dayanabilir.
- Açık rıza: Kişiselleştirilmiş reklam, isteğe bağlı pazarlama iletişimi, isteğe bağlı tanıtım bildirimleri veya mevzuat gereği açık rıza alınması gereken diğer faaliyetler bakımından açık rıza alınabilir.
Açık rıza vermemen, açık rıza gerektirmeyen temel hizmetlerin sunulmasını kural olarak engellemez. Açık rızanı her zaman geri çekebilirsin. Rızanın geri çekilmesi, geri çekilmeden önce rızaya dayanılarak gerçekleştirilmiş işlemlerin hukuka uygunluğunu ortadan kaldırmaz.
7. Kişisel verilerin elde edilme yöntemleri
Kişisel verilerin aşağıdaki yöntemlerle elde edilmesi mümkündür:
- Uygulama içindeki hesap oluşturma ekranları,
- İnternet sitesindeki üyelik ve iletişim formları,
- Kullanıcının uygulama içinde yaptığı tercihler,
- İzleme DNA ve Picsona cevapları,
- Başlık, yorum ve topluluk içerikleri,
- Destek ve moderasyon başvuruları,
- Hesap silme veya veri talebi başvuruları,
- Cihaz ve uygulama kullanım kayıtları,
- Uygulama mağazası abonelik doğrulamaları,
- Reklam ve bildirim izinleri,
- Çerezler, yerel depolama ve benzeri internet teknolojileri,
- Hizmet sağlayıcılardan alınan abonelik veya teknik doğrulama kayıtları,
- Yetkili kamu kurumlarından gelen hukuka uygun bildirimler.
Kişisel veriler mümkün olduğu ölçüde doğrudan kullanıcıdan alınır. Üçüncü taraf hizmet sağlayıcılardan alınan veriler, yalnızca ilgili hizmetin yürütülmesi için gerekli kapsamla sınırlı tutulur.
8. Profilde ve topluluk alanlarında görünen bilgiler
Profil ve topluluk özelliklerinin kullanımına bağlı olarak aşağıdaki bilgiler diğer kullanıcılar tarafından görülebilir:
- Kullanıcı adı,
- görünen ad,
- profil fotoğrafı,
- kapak fotoğrafı,
- paylaşılan başlıklar,
- yorumlar,
- herkese açık listeler,
- takip ve takipçi ilişkileri,
- herkese açık koleksiyonlar,
- görünürlük ayarı açık olan Picsona kartı,
- kullanıcı tarafından topluluk alanlarında yayımlanan diğer içerikler.
E-posta adresin, doğum tarihin, hesap güvenliği kayıtların ve şikâyet gönderen kişinin kimliği herkese açık profil alanında gösterilmez.
Bununla birlikte, kullanıcı tarafından başlık, yorum, profil veya koleksiyon alanlarında yayımlanan içerikler, ilgili özelliğin yapısına göre diğer kullanıcılara gösterilebilir. Kullanıcılar, üçüncü kişilere ait kişisel verileri, özel yazışmaları, iletişim bilgilerini veya hassas bilgileri hukuka aykırı biçimde paylaşmamalıdır.
Picsona kartının veya benzeri profil bilgilerinin görünürlük ayarlarını uygulama içindeki ilgili ayarlardan değiştirebilirsin.
9. Hizmet sağlayıcılar
piCue hizmetinin sunulabilmesi için sınırlı sayıda hizmet sağlayıcıdan yararlanılabilir. Bu hizmet sağlayıcılar aşağıdaki işlevleri yerine getirebilir:
- Supabase: Kimlik doğrulama, veri tabanı hizmetleri, dosya saklama ve uygulama altyapısı.
- TMDB: Film ve dizi künyeleri, afişler ve içerik bilgileri için sorgulama hizmeti. Kullanıcıya ait kişisel veriler TMDB’ye gönderilmez; gerekli içerik sorguları kullanıcıyla ilişkilendirilemeyecek biçimde yürütülür.
- Apple ve Google: Uygulama mağazası, uygulama içi satın alma, abonelik doğrulaması, bildirim ve cihaz altyapısı.
- Google AdMob: Reklam gösterimi, reklam ölçümü ve reklam tercihleri. Kişiselleştirilmiş reklam bakımından cihaz ve işletim sistemi izinleri uygulanır.
- RevenueCat: Abonelik durumunun doğrulanması ve abonelik yönetimi. Ödeme işleminin uygulama mağazası üzerinden yapıldığı modelde kart bilgileri RevenueCat’e gönderilmez.
- PostHog: Uygulamanın nasıl kullanıldığının ölçülmesi ve hizmetin geliştirilmesi. Hangi ekranların açıldığı, hangi özelliklerin kullanıldığı, uygulamanın açılma ve arka plana alınma zamanları ile oturum süresine ilişkin kayıtlar işlenir. Bu kayıtlar kullanıcı hesabıyla ilişkilendirilir; hesap kimliği, kullanıcı adı, görünen ad ve Plus aboneliğinin bulunup bulunmadığı bilgisi hizmet sağlayıcıya aktarılır. Kullanıcının yazdığı başlık, yorum ve arama metinleri bu hizmete gönderilmez. Bu işleme faaliyeti, hizmetin geliştirilmesi ve hata kaynaklarının tespiti bakımından Piklabs’ın meşru menfaatine dayanır. Kullanıcı, uygulama içindeki Ayarlar → Gizlilik bölümünden kullanım analitiğini kapatabilir; kapatıldığında bu hizmete veri gönderilmez. Hizmet sağlayıcının sunucuları Amerika Birleşik Devletleri’nde bulunur.
- AppsFlyer: Uygulamanın hangi kaynaktan indirildiğinin ölçülmesi ve pazarlama faaliyetlerinin başarısının değerlendirilmesi. Kuruluma aracılık eden bağlantı, kampanya bilgisi, cihaz ve işletim sistemi bilgileri ile hesap kimliği ve kayıt olma, abonelik başlatma, oyun oynama gibi sınırlı sayıda uygulama içi olay hizmet sağlayıcıya aktarılır. Kullanıcının yazdığı başlık, yorum ve arama metinleri bu hizmete gönderilmez. iOS cihazlarında reklam tanımlayıcısı yalnızca uygulama izleme izni verilmişse işlenir; izin verilmediğinde ölçüm, Apple’ın sağladığı ve kişiye bağlanamayan toplu veriyle sınırlı kalır. Bu işleme faaliyeti, pazarlama faaliyetlerinin ölçülmesi bakımından Piklabs’ın meşru menfaatine dayanır. Hizmet sağlayıcının sunucuları yurt dışında bulunur.
- Google (yapay zekâ modeli hizmeti): Uygulamadaki karakter hesaplarının kullanıcı mesajlarına otomatik yanıt üretmesi. Kullanıcı bir karakter hesabını etiketlediğinde; etiketleyen kişinin yazdığı metin, başlığın adı ve gövdesi, aynı başlıktaki diğer yorumlar ve bu içerikleri yazan kullanıcıların görünen adları, yanıt üretilmek üzere hizmet sağlayıcıya gönderilir. E-posta adresi, kullanıcı adı ve hesap kimliği gönderilmez. Hizmet sağlayıcının ücretli kullanım koşulları uyarınca gönderilen veriler yapay zekâ modellerinin eğitilmesinde kullanılmaz. Veri gönderimi kullanıcının kendi işlemiyle başlar; bir karakter hesabı etiketlenmediği sürece bu hizmete veri aktarılmaz. Hizmet sağlayıcının sunucuları yurt dışında bulunur.
- Google Firebase Cloud Messaging: Android cihazlara bildirim iletilmesi. Bildirimin ulaştırılabilmesi için cihaz bildirim jetonu ve bildirim içeriği hizmet sağlayıcıya iletilir. Bu hizmet yalnızca bildirim gönderimi için kullanılır; kullanım ölçümü veya reklam amacıyla veri işlenmez.
- Resend veya kullanılan eşdeğer e-posta hizmeti: Doğrulama, hesap güvenliği, hizmet bilgilendirmesi ve destek e-postalarının gönderimi.
Hizmet sağlayıcılar kendilerine aktarılan verileri, Piklabs’ın talimatları doğrultusunda ve belirlenen amaçlarla sınırlı olarak işlemek üzere yetkilendirilir. Hizmet sağlayıcıların kendi bağımsız veri işleme faaliyetleri bakımından kendi gizlilik politikaları uygulanabilir.
10. Yurt dışına veri aktarımı
Supabase sunucularının Avrupa Birliği’nde bulunması veya Apple, Google, RevenueCat, Resend, AdMob, PostHog, AppsFlyer ve benzeri sağlayıcıların küresel altyapı kullanması hâlinde kişisel veriler yurt dışına aktarılabilir veya yurt dışında işlenebilir.
Yurt dışına veri aktarımından önce aşağıdaki hususlar değerlendirilir:
- Aktarılacak veri kategorileri,
- Aktarımın amacı,
- Verinin aktarılacağı hizmet sağlayıcı,
- Verinin işlenebileceği ülke veya ülkeler,
- Hizmet sağlayıcının alt işleyen kullanıp kullanmadığı,
- Aktarımın süresi,
- Aktarım için uygulanacak hukuki güvence,
- İlgili kişinin temel hak ve özgürlüklerine yönelik riskler,
- Verinin aktarım sonrası korunma düzeyi.
Yurt dışına aktarım, yürürlükteki KVKK hükümleri ve ilgili ikincil düzenlemeler çerçevesinde gerçekleştirilir. Aktarımın niteliğine göre yeterlilik kararı, uygun güvence yöntemleri, standart sözleşme, bağlayıcı şirket kuralları veya mevzuatta öngörülen diğer mekanizmalar kullanılabilir.
Piklabs, veri aktarım süreçlerini veri işleme envanteri, hizmet sağlayıcı sözleşmeleri ve yurt dışı aktarım kayıtlarıyla belgelendirir.
11. Reklamlar ve reklam tercihleri
Plus aboneliğin bulunmuyorsa uygulama içinde reklam gösterilebilir. Reklam gösterimi kapsamında cihazının reklam tanımlayıcısı ve reklam sunumu için gerekli sınırlı teknik bilgiler işlenebilir.
Kişiselleştirilmiş reklam gösterimi, kullanılan işletim sistemi, reklam sağlayıcısı ve ilgili izin mekanizmalarına tabidir. Kişiselleştirilmiş reklam izni vermemen hâlinde reklamlar gösterilebilir; ancak reklamlar ilgi alanlarına göre kişiselleştirilmeyebilir.
iOS cihazlarında uygulama izleme izni ve cihaz ayarları; Android cihazlarında işletim sistemi ve reklam ayarları uygulanır. Bu izinlerin reddedilmesi, hesabın oluşturulması veya temel piCue hizmetlerinin kullanılması için zorunlu olmayan reklam kişiselleştirmesini etkiler.
Reklam tanımlayıcısı, reklam sağlayıcısına aktarılabilecek teknik bilgiler ve reklam ölçüm faaliyetleri, kullanılan yazılım geliştirme kitlerinin gerçek yapılandırmasına göre belirlenir. Piklabs, reklam ve analiz hizmetlerini düzenli olarak gözden geçirir.
12. Bildirimler
Bildirim göndermek için cihaz jetonu, bildirim tercihleri ve bildirim gönderim kayıtları işlenebilir.
Bildirimler aşağıdaki amaçlarla gönderilebilir:
- Hesap güvenliği,
- E-posta doğrulama,
- Şifre veya hesap işlemleri,
- Abonelik durumu,
- Hizmetin çalışması,
- Topluluk faaliyetleri,
- Takip ve etkileşim bildirimleri,
- Kullanıcının tercihleri doğrultusunda ürün bilgilendirmesi,
- İsteğe bağlı tanıtım ve pazarlama iletileri.
Hizmetin çalışması için zorunlu bildirimler ile isteğe bağlı pazarlama bildirimleri birbirinden ayrılır. Bildirim iznini cihaz ayarlarından veya uygulama içindeki bildirim tercihleri bölümünden değiştirebilirsin.
Pazarlama iletişimleri bakımından ayrıca uygulanması gereken elektronik ileti izinleri ve ticari ileti mevzuatı hükümleri saklıdır.
13. Şikâyet ve moderasyon kayıtları
Bir başlık, yorum veya profil hakkında şikâyette bulunduğunda aşağıdaki veriler kaydedilebilir:
- Şikâyeti gönderen hesabın kimliği,
- Şikâyet edilen içerik,
- Şikâyet nedeni,
- Kullanıcının yazdığı açıklama,
- Şikâyet tarihi,
- İnceleme ve moderasyon sonucu,
- Gerekli hâllerde uygulanan yaptırım,
- İtiraz veya yeniden değerlendirme kayıtları.
Şikâyeti gönderen kişinin kimliği, kural olarak şikâyet edilen kullanıcıyla paylaşılmaz. Ancak yetkili makam talebi, kanuni yükümlülük, yargısal süreç, savunma hakkı veya bir hakkın tesisi ve korunması bakımından zorunlu hâller saklıdır.
Moderasyon sonucu içeriğin kaldırılması, hesabın uyarılması, geçici olarak askıya alınması veya kapatılması hâlinde karar ve kararın gerekçesi, platform güvenliği ve hesap yönetimi amacıyla kaydedilebilir.
Moderasyon kayıtları, işleme amacı için gerekli olan süreyle sınırlı olarak saklanır. Son 90 günlük ihlal kayıtlarının yaptırım hesaplamasında dikkate alınacağı belirtiliyorsa, teknik sistemin bu kurala uygun çalışması gerekir. Daha uzun süreli saklama yapılacaksa farklı saklama amacı ve süresi ayrıca belirlenmelidir.
14. Hesap silme
Hesabını uygulama içindeki “Hesabımı sil” seçeneğini kullanarak silebilirsin.
Hesabın silinmesi hâlinde, hukuken veya teknik olarak saklanmasını gerektiren bir durum bulunmadıkça aşağıdaki veriler silinir veya kimliğinle ilişkilendirilemeyecek hâle getirilir:
- Profil bilgileri,
- Profil ve kapak fotoğrafları,
- Listeler,
- Koleksiyonlar,
- Başlıklar,
- Yorumlar,
- Takip ilişkileri,
- Kullanıcı tercihleri,
- Hesapla ilişkilendirilen içerikler.
Hesap silme işlemi, mevzuat gereği saklanması gereken kayıtları, devam eden uyuşmazlıkları, güvenlik incelemelerini, mali kayıtları veya bir hakkın tesisi ve korunması için zorunlu verileri otomatik olarak ortadan kaldırmayabilir.
Kalıcı olarak kapatılan hesapların e-posta adresinin yeniden hesap oluşturulmasını önlemek amacıyla kara listeye alınması planlanıyorsa, bu uygulama ayrıca sınırlandırılır. Kara liste bakımından yalnızca gerekli veri tutulur, erişim yetkileri kısıtlanır ve saklama süresi belirlenir. Kara liste verileri süresiz tutulmaz; gereklilik değerlendirmesi düzenli aralıklarla yapılır.
Aktif sistemlerden silinen verilerin teknik yedeklerde bir süre bulunması mümkündür. Yedeklerdeki veriler, yedekleme döngüsünün gerektirdiği azami süre sonunda silinir veya üzerine yazılır. Bu süre Piklabs’ın iç saklama ve imha planında belirlenir.
15. Saklama süreleri
Kişisel veriler yalnızca işleme amacı için gerekli olduğu ve mevzuatın öngördüğü süre boyunca saklanır.
Saklama süresi belirlenirken aşağıdaki hususlar dikkate alınır:
- Verinin işlenme amacı,
- Hizmet ilişkisinin devam edip etmediği,
- Hesabın açık veya kapalı olması,
- Mali ve ticari saklama yükümlülükleri,
- Hukuki uyuşmazlık veya inceleme bulunup bulunmadığı,
- Güvenlik ve kötüye kullanım riskleri,
- Veri sahibinin silme talebi,
- Yedekleme sisteminin teknik döngüsü,
- Verinin başka bir amaçla tutulmasını gerektiren hukuki sebep.
Piklabs, veri kategorileri bakımından bir saklama ve imha planı oluşturur. Bu plan en azından hesap verileri, iletişim verileri, abonelik kayıtları, moderasyon kayıtları, destek kayıtları, güvenlik günlükleri, açık rıza kayıtları, reklam tercihleri, yedekler ve hukuki uyuşmazlık dosyalarını kapsar.
“Hesap açık olduğu sürece” ifadesi, hesabın kapanmasından sonra uygulanacak saklama süresini tek başına açıklamaz. Bu nedenle her veri kategorisi için işleme amacının sona ermesinden sonra uygulanacak azami süre ayrıca belirlenir.
16. Veri güvenliği
Piklabs, kişisel verilerin hukuka aykırı olarak işlenmesini ve erişilmesini, verilerin hukuka aykırı olarak aktarılmasını, kaybolmasını veya yok olmasını önlemek amacıyla uygun teknik ve idari tedbirleri uygular.
Tedbirler, hizmetin teknik yapısına göre aşağıdakileri içerebilir:
- Uygulama ve sunucu arasındaki veri aktarımının şifrelenmesi,
- Parolaların açık metin olarak tutulmaması,
- Erişim yetkilerinin görev ve ihtiyaç esasına göre sınırlandırılması,
- Veri tabanı erişim kurallarının uygulanması,
- Yönetici erişimlerinin kayıt altına alınması,
- Güvenlik güncellemelerinin yapılması,
- Yedekleme ve kurtarma prosedürlerinin uygulanması,
- Hizmet sağlayıcıların güvenlik şartlarının incelenmesi,
- Çalışanların gizlilik yükümlülükleri hakkında bilgilendirilmesi,
- Güvenlik olaylarının izlenmesi,
- Düzenli risk değerlendirmesi,
- Yetki ve erişim kontrollerinin periyodik olarak gözden geçirilmesi.
Hiçbir elektronik sistem mutlak biçimde güvenli değildir. Kişisel verilerin kanuni olmayan yollarla elde edildiği bir veri güvenliği ihlali tespit edilirse, olayın niteliği ve etkileri değerlendirilir. Gerekli bildirimler yürürlükteki mevzuata uygun şekilde Kişisel Verileri Koruma Kuruluna ve etkilenmesi muhtemel kişilere yapılır.
Türkiye bakımından her veri güvenliği olayı için otomatik ve genel bir “72 saat içinde bildirim” kuralı varmış gibi hareket edilmez. Bildirim yükümlülüğü, olayın niteliği, etkisi, kapsamı ve yürürlükteki düzenlemeler esas alınarak değerlendirilir.
17. Otomatik değerlendirme ve kişiselleştirme
İzleme DNA, Picsona ve benzeri özellikler, kullanıcı tarafından sağlanan tercihlerden hareketle film ve dizi önerileri veya eşleştirme sonuçları üretebilir.
Bu sistemlerin temel amacı, kullanıcı deneyimini kişiselleştirmek ve içerik önerileri sunmaktır. Sistem, kullanıcı hakkında hukuki sonuç doğuran veya benzeri şekilde önemli bir karar vermek üzere tasarlanmaz.
Kişiselleştirme sistemleri; kullanıcının verdiği cevapları, kart seçimlerini, favorilerini, izleme listesini, izlediği içerikleri ve benzeri tercih verilerini kullanabilir. Bu veriler öneri üretmek amacıyla analiz edilebilir.
Piklabs, kullanıcıların temel haklarını önemli ölçüde etkileyen otomatik karar mekanizmaları kullanacak olursa, ilgili kişilere kararın niteliği, kullanılan veri kategorileri, muhtemel sonuçları ve uygulanabilir itiraz yöntemleri hakkında ayrıca bilgi verir.
Kullanıcı, kendisi hakkında oluşturulan önerilerin hatalı olduğunu düşünüyorsa tercihlerini değiştirebilir veya support@picue.app adresinden destek talebinde bulunabilir.
18. Kullanıcı hakları
Yürürlükteki kişisel verilerin korunması mevzuatı kapsamında, şartları oluştuğu ölçüde aşağıdaki haklara sahipsin:
- Kişisel verilerinin işlenip işlenmediğini öğrenme,
- Kişisel verilerin işlenmişse buna ilişkin bilgi talep etme,
- Kişisel verilerin işlenme amacını ve amaca uygun kullanılıp kullanılmadığını öğrenme,
- Kişisel verilerin yurt içinde veya yurt dışında aktarıldığı üçüncü kişileri bilme,
- Eksik veya yanlış işlenen kişisel verilerin düzeltilmesini isteme,
- Kanuni şartlar oluştuğunda kişisel verilerin silinmesini veya yok edilmesini isteme,
- Düzeltme, silme veya yok etme işlemlerinin aktarılan üçüncü kişilere bildirilmesini isteme,
- İşlenen verilerin münhasıran otomatik sistemler aracılığıyla analiz edilmesi sonucunda aleyhine bir sonuç ortaya çıkmasına itiraz etme,
- Kişisel verilerin kanuna aykırı işlenmesi nedeniyle zararın giderilmesini talep etme,
- Açık rızaya dayalı işleme faaliyetlerinde rızayı geri çekme.
Profil bilgilerini uygulama içinden değiştirebilir, hesabını “Hesabımı sil” seçeneği üzerinden kapatabilirsin.
Diğer veri taleplerini hey@picue.app adresine iletebilirsin. Başvurunun değerlendirilmesi için talebini açıkça belirtmen ve gerektiğinde kimlik doğrulamaya elverişli bilgi sunman gerekebilir.
Başvurular yürürlükteki mevzuatta öngörülen usul ve süreler içinde değerlendirilir. Başvurunun reddedilmesi, verilen cevabın yetersiz bulunması veya süresinde cevap verilmemesi hâlinde, yürürlükteki mevzuat kapsamındaki başvuru ve şikâyet hakların saklıdır.
19. Açık rızanın geri alınması
Aşağıdaki tercihleri, kullanılan teknik yönteme bağlı olarak istediğin zaman değiştirebilirsin:
- Bildirim izni,
- Kişiselleştirilmiş reklam izni,
- İsteğe bağlı pazarlama iletişimi,
- Profil görünürlük tercihleri,
- Picsona kartının görünürlük tercihi,
- İsteğe bağlı analiz veya kişiselleştirme tercihleri.
Rızanı cihaz ayarlarından, uygulama içindeki tercih ekranlarından veya hey@picue.app adresine başvurarak geri çekebilirsin.
Bir işleme faaliyeti açık rızaya değil, sözleşmenin ifası, hukuki yükümlülük, meşru menfaat veya başka bir kanuni işleme şartına dayanıyorsa, rızanın geri çekilmesi söz konusu işleme faaliyetini kendiliğinden sona erdirmeyebilir.
Rızanın geri çekilmesi, geri çekilme tarihinden önce rızaya dayanılarak gerçekleştirilen işlemlerin hukuka uygunluğunu etkilemez.
20. Yaş sınırı ve çocuklara ait veriler
piCue’nin hizmet yaş sınırı, uygulama mağazalarındaki yaş sınıflandırmaları ve uygulamanın gerçek teknik işleyişiyle uyumlu olmalıdır.
piCue’yi kullanmak için en az 16 yaşında olmak gerekir. Yaş bilgisi hesap oluşturulurken kullanıcının beyan ettiği doğum tarihi üzerinden alınır ve bu şartı sağlamayan hesaplar oluşturulamaz. Doğum tarihi, yaş şartının doğrulanması ve hizmetin yaşa uygun sunulması amacıyla saklanır. Uygulama mağazalarındaki yaş sınıflandırması da bu sınırla uyumlu olarak belirlenmiştir. Ebeveyn veya yasal temsilci doğrulaması gerektiren bir işleme faaliyeti yürütülmemektedir.
16 yaşından küçük bir kişiye ait verinin hukuka aykırı veya gereğinden fazla işlendiği tespit edilirse hesap sınırlandırılabilir ve veriler, saklanmasını gerektiren başka bir hukuki sebep bulunmadığı sürece silinebilir veya anonim hâle getirilebilir.
Bir çocuğa ait kişisel verinin piCue üzerinde hukuka aykırı biçimde işlendiğini düşünüyorsan hey@picue.app adresine bildirimde bulunabilirsin.
21. Çerezler ve internet sitesi teknolojileri
Mobil uygulamada klasik internet çerezleri kullanılmayabilir. Bununla birlikte, uygulama içinde yerel depolama, cihaz tanımlayıcıları, yazılım geliştirme kitleri, reklam teknolojileri veya analiz araçları kullanılabilir.
picue.app internet sitesinde dil tercihi, oturum veya kullanıcı ayarlarının hatırlanması için zorunlu yerel depolama teknolojileri kullanılabilir.
Reklam, analiz veya izleme amacı taşıyan çerezler ya da benzeri teknolojiler kullanılıyorsa, bu teknolojiler ayrı bir çerez politikası veya tercih yönetim aracıyla açıklanır. Kullanıcıya zorunlu olmayan teknolojiler bakımından gerekli tercih imkânı sağlanır.
Üçüncü taraf internet sitelerine verilen bağlantılar Piklabs tarafından işletilmiyorsa, bu sitelerin veri işleme faaliyetlerinden Piklabs sorumlu değildir. Bu siteleri kullanmadan önce ilgili kuruluşların kendi gizlilik politikalarını incelemelisin.
22. Kullanıcı içerikleri ve üçüncü kişilere ait veriler
Başlık, yorum, profil, koleksiyon veya görsel alanlarında paylaştığın içerikler, ilgili özelliğin görünürlük ayarlarına göre diğer kullanıcılar tarafından görülebilir.
Aşağıdaki verileri üçüncü kişilerin hukuka uygun izni olmaksızın paylaşmamalısın:
- E-posta adresi,
- Telefon numarası,
- Kimlik bilgisi,
- Özel yazışmalar,
- Sağlık bilgisi,
- Finansal bilgiler,
- Konum bilgisi,
- Çocuklara ait görüntü veya kişisel bilgiler,
- Hesap şifreleri,
- Özel hayatın gizliliği kapsamındaki bilgiler.
Bir içeriğin kişisel veri ihlali, taciz, tehdit, özel hayatın ihlali, telif hakkı ihlali veya başka bir kural ihlali oluşturduğunu düşünüyorsan uygulama içindeki şikâyet araçlarını kullanabilir veya support@picue.app adresine başvurabilirsin.
Piklabs, şikâyet edilen içeriği topluluk güvenliği, hukuki yükümlülük, kullanıcı güvenliği veya hizmet kuralları kapsamında inceleyebilir.
23. Politika değişiklikleri
Bu Gizlilik Politikası, hizmetlerdeki, teknik altyapıdaki, hizmet sağlayıcılardaki veya mevzuattaki değişikliklere bağlı olarak güncellenebilir.
Güncelleme yapıldığında metnin başındaki “son güncelleme” tarihi değiştirilir. Kullanıcıların haklarını, işlenen veri kategorilerini, veri aktarım alıcılarını, saklama sürelerini veya hukuki sebepleri önemli ölçüde etkileyen değişiklikler bakımından uygulama içi bildirim, e-posta veya uygun başka bir iletişim yöntemi kullanılabilir.
Önemli değişiklikler yürürlüğe girmeden önce, gerekli hâllerde kullanıcıların güncel metni incelemesine imkân tanınır.
Politikanın güncellenmiş hâli yayımlandığı tarihten itibaren, değişikliğin niteliğine göre mevcut ve yeni kullanıcılar bakımından uygulanabilir.
24. İletişim ve başvuru
Kişisel veri talepleri, gizlilik soruları, veri güvenliği bildirimleri ve KVKK kapsamındaki başvurular için:
Piklabs Yazılım ve Teknoloji Hizmetleri Limited Şirketi
Adres: Gayrettepe Mah. Nurgül Sk. Polat 8 Apt. No: 8 İç Kapı No: 2, Beşiktaş/İstanbul
E-posta: hey@picue.app
Kullanıcı içerikleri, moderasyon kararları, hesap güvenliği ve teknik destek talepleri için:
E-posta: support@picue.app
Başvuruların değerlendirilmesi sırasında başvuru sahibinin kimliğinin doğrulanması ve talebin kapsamının belirlenmesi için ek bilgi istenebilir. Kimlik doğrulama amacıyla alınan bilgiler yalnızca başvurunun güvenli biçimde sonuçlandırılması amacıyla kullanılır.
Piklabs’ın cevabının yeterli bulunmaması, talebin reddedilmesi veya mevzuatta öngörülen süre içinde cevap verilmemesi hâlinde, ilgili kişinin Kişisel Verileri Koruma Kuruluna başvurma veya şikâyet etme hakkı saklıdır.
Yürürlük tarihi: 14 Ağustos 2026 · Versiyon: 2.0
Privacy Policy
Last updated: 14 August 2026
This Privacy Policy explains how your personal data is collected, processed, stored, transferred and protected when you use the piCue mobile application, the picue.app website and the connected digital services operated by Piklabs Yazılım ve Teknoloji Hizmetleri Limited Şirketi.
This text has been prepared taking into account Law No. 6698 on the Protection of Personal Data, the relevant secondary legislation and, to the extent applicable, the European Union General Data Protection Regulation.
The European Union General Data Protection Regulation does not apply automatically to every user. Whether the Regulation applies is assessed separately, taking into account the country in which the user is located, whether the service is offered to persons in the European Union or the European Economic Area, the company’s activities in Europe, the manner in which personal data is processed and whether the service targets the relevant market. For this reason, references to the European Union General Data Protection Regulation do not automatically mean that the Regulation applies to all users located in Türkiye.
This Privacy Policy contains general explanations regarding the processing of your personal data. Where a KVKK Privacy Notice, an explicit consent text, a cookie notice, a subscription term or a user agreement is also presented during a specific data collection activity, that specific text is taken into account as well.
1. Data controller and contact details
The data controller determining the purposes and means of processing your personal data:
Trade name: Piklabs Yazılım ve Teknoloji Hizmetleri Limited Şirketi
Company type: Limited liability company
Registered address: Gayrettepe Mah. Nurgül Sk. Polat 8 Apt. No: 8 İç Kapı No: 2, Beşiktaş/İstanbul
Website: picue.app
Personal data requests and applications: hey@picue.app
User support and moderation: support@picue.app
Piklabs Yazılım ve Teknoloji Hizmetleri Limited Şirketi acts as data controller to the extent that it determines the purposes and means of processing personal data within the scope of the piCue mobile application, the picue.app website and the connected digital services.
Personal data applications may be sent to hey@picue.app; applications concerning user content, moderation decisions, account security, technical support and community matters may be sent to support@picue.app.
Piklabs’s current MERSİS number, trade registry directorate and trade registry/file number must be matched with the company’s current registry record before this text is published. Unless this information is verified, no MERSİS or registry information that does not belong to Piklabs is used in this text.
The company may request additional information to the extent suitable for verifying the identity of the applicant and preventing access to personal data belonging to third parties. Information requested for identity verification purposes is used solely to evaluate and securely conclude the application.
2. Which services does this policy apply to?
This Privacy Policy applies to the following services:
- the piCue mobile application,
- the picue.app website,
- user accounts and account management,
- the İzleme DNA feature,
- the Picsona feature,
- film and series recommendation systems,
- user profiles,
- thread and comment areas,
- follow and follower features,
- favourites, watchlists and collections,
- CueMates matches,
- in-app games and scoring systems,
- the Plus subscription,
- in-app notifications,
- ad display and ad measurement activities,
- user support services,
- complaint, moderation and community safety processes,
- account and content functions on picue.app.
The personal data processing activities of application stores, payment infrastructures, advertising platforms, content providers, external websites and other linked services operated by third parties fall outside the scope of this policy. Those organisations are responsible for their own privacy policies, user agreements and data processing rules.
That said, the necessary technical and legal controls are carried out under the agreements and data transfer arrangements that Piklabs enters into with third party service providers.
3. Which personal data do we process?
Depending on the features you use and your relationship with piCue, the following categories of personal data may be processed.
- Identity and account data: Username, display name, account ID, profile information, account creation date, account status, account closure records and the technical identifiers associated with the account.
- Contact data: E-mail address, verification details, contact details shared in support requests and contact records used for account security purposes.
- Profile and image data: Profile photo, cover photo, images uploaded by the user, descriptions linked to those images and the visibility preferences for such content.
- Age and region data: Date of birth, age information or the result of age verification, together with the province and district information entered by the user. Under the current design of the service, the collection of GPS data, precise location or continuous real-time location information is not intended.
- Content and preference data: Answers given in the İzleme DNA test, card selections, favourites, watched content, watchlists, collections, film and series preferences, recommendation results and the user’s interactions within the service.
- Community data: Threads, comments, votes, followed accounts, followers, CueMates matches, game scores, collections made public by the user and other activities within the community.
- Support and moderation data: User complaints, the reason for the complaint, the complaint description, review records, moderation decisions, removed content, warnings, temporary suspensions, account closure records and objections to decisions.
- Subscription and transaction data: Whether the Plus subscription is active, the subscription type, subscription start and end information, the application store transaction ID, purchase verification records and the technical information required to manage the subscription status.
In the model where the payment transaction is carried out by application stores such as Apple or Google, Piklabs does not receive debit card numbers, credit card numbers, card security codes or bank account details. Which organisation processes such information is determined by the policies of the relevant application store.
- Device and technical data: Device model, operating system, application version, IP address, session information, security records, device identifier, device push token, error logs, access times and the technical log records required for the service to operate.
- Advertising and measurement data: Advertising identifier, ad display and interaction information, ad preferences, limited measurement data relating to application usage and records concerning consent to personalised advertising.
Which of these categories are processed may vary according to the feature you use, the permissions you grant, your account settings, your device and the technical configuration of the application.
4. Data we do not collect or, as a rule, will not process
Under the current design of the service, the collection or processing of the following data is not intended:
- GPS data,
- precise or continuous location data,
- address book and contact lists,
- calendar information,
- microphone recordings,
- continuous image or audio recording through the camera,
- the entire device gallery,
- health information,
- racial or ethnic origin,
- political opinions,
- religious or philosophical beliefs,
- sex life or sexual orientation,
- biometric data,
- genetic data.
When you use the photo upload feature, the intention is that the file you select is transmitted to the application. Access to the entire gallery of your device is not intended. Nevertheless, technical reviews are carried out regularly with regard to the operating system permissions of the device you use and third party software development kits.
Processing special categories of personal data that users write into thread, comment or profile fields is not the purpose of piCue. However, content that a user publishes publicly of their own volition can be seen by other users. For this reason, users should not share sensitive personal data belonging to themselves or to third parties in community areas.
If a user uploads special categories of personal data to the platform, Piklabs may have to review such content within the scope of rule violations, security, complaints, legal obligations or content moderation.
5. For which purposes do we process personal data?
We process your personal data for the following purposes:
- To create a user account,
- To manage the user account,
- To carry out the sign-in process,
- To ensure account security,
- To apply age requirements and service access restrictions,
- To operate the İzleme DNA feature,
- To provide the Picsona feature,
- To generate film and series recommendations,
- To apply user preferences,
- To provide thread, comment, follow, collection and game features,
- To run CueMates matches,
- To publish user content in line with the relevant visibility preferences,
- To evaluate user complaints,
- To prevent misuse, spam, fake accounts and fraudulent activity,
- To ensure platform security,
- To verify the Plus subscription,
- To provide subscription features,
- To display advertisements,
- To measure ad display,
- To apply personalised advertising preferences,
- To send notifications in line with the user’s permissions,
- To detect and resolve technical issues,
- To measure application performance,
- To improve products and services,
- To respond to user support requests,
- To carry out moderation and community safety activities,
- To carry out information security and cyber security processes,
- To fulfil legal obligations,
- To respond to lawful requests from authorised institutions and organisations,
- To create evidence in legal disputes,
- To establish, exercise or protect a right,
- To prevent misuse of the service,
- To ensure the technical and commercial continuity of the application.
Where data needs to be processed for a new purpose, if the new purpose is not compatible with the existing processing purpose, the necessary information is provided and, where legally required, explicit consent is also obtained.
6. Legal bases for processing personal data
The same legal basis is not used for every processing activity. Depending on the nature of the processing activity, one or more of the following legal bases may apply:
- Establishment or performance of a contract: The data required for creating an account, signing in, providing piCue’s core features, generating recommendations in line with user preferences, operating community features and granting the Plus subscription may rely on this legal basis.
- Legitimate interest of the data controller: The data required for ensuring the security of the service, preventing misuse, combating fake accounts, resolving technical issues, developing systems and operating the platform securely may rely on this legal basis, provided that the fundamental rights and freedoms of the user are not harmed.
- Legal obligation: Data may be processed for the purposes of keeping financial and commercial records, responding to lawful requests from authorised public institutions and fulfilling the retention and notification obligations arising from legislation.
- Establishment, exercise or protection of a right: The data required for evaluating complaints, moderation decisions, security investigations, fraud reviews, managing disputes and assessing legal claims may rely on this legal basis.
- Explicit consent: Explicit consent may be obtained for personalised advertising, optional marketing communications, optional promotional notifications or other activities for which explicit consent is required under the legislation.
Not giving explicit consent does not, as a rule, prevent the provision of the core services that do not require explicit consent. You can withdraw your explicit consent at any time. Withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of that consent before the withdrawal.
7. Methods of collecting personal data
Personal data may be collected through the following methods:
- Account creation screens within the application,
- Membership and contact forms on the website,
- Preferences made by the user within the application,
- İzleme DNA and Picsona answers,
- Threads, comments and community content,
- Support and moderation applications,
- Account deletion or data request applications,
- Device and application usage records,
- Application store subscription verifications,
- Advertising and notification permissions,
- Cookies, local storage and similar internet technologies,
- Subscription or technical verification records received from service providers,
- Lawful notices received from authorised public institutions.
Personal data is collected directly from the user to the extent possible. Data received from third party service providers is limited to the scope necessary for carrying out the relevant service.
8. Information visible on your profile and in community areas
Depending on the use of the profile and community features, the following information may be seen by other users:
- Username,
- display name,
- profile photo,
- cover photo,
- published threads,
- comments,
- public lists,
- follow and follower relationships,
- public collections,
- the Picsona card where its visibility setting is on,
- other content published by the user in community areas.
Your e-mail address, your date of birth, your account security records and the identity of the person submitting a complaint are not shown in the public profile area.
That said, content published by a user in thread, comment, profile or collection areas may be shown to other users depending on the structure of the relevant feature. Users must not unlawfully share personal data, private correspondence, contact details or sensitive information belonging to third parties.
You can change the visibility settings of the Picsona card or similar profile information from the relevant settings within the application.
9. Service providers
A limited number of service providers may be used in order to provide the piCue service. These service providers may perform the following functions:
- Supabase: Authentication, database services, file storage and application infrastructure.
- TMDB: A query service for film and series credits, posters and content information. No personal data belonging to the user is sent to TMDB; the necessary content queries are carried out in a way that cannot be associated with the user.
- Apple and Google: Application store, in-app purchase, subscription verification, notification and device infrastructure.
- Google AdMob: Ad display, ad measurement and ad preferences. Device and operating system permissions apply with regard to personalised advertising.
- RevenueCat: Verification of subscription status and subscription management. In the model where the payment transaction is made through the application store, card details are not sent to RevenueCat.
- PostHog: Measuring how the application is used and improving the service. Records of which screens are opened, which features are used, the times at which the application is opened and moved to the background, and session duration are processed. These records are associated with the user account; the account ID, the username, the display name and whether a Plus subscription exists are transferred to the service provider. Threads, comments and search text written by the user are not sent to this service. This processing activity relies on Piklabs’s legitimate interest in improving the service and identifying the sources of errors. The user can turn off usage analytics from the Settings → Privacy section within the application; when it is turned off, no data is sent to this service. The service provider’s servers are located in the United States of America.
- AppsFlyer: Measuring which source the application was downloaded from and evaluating the performance of marketing activities. The link that led to the installation, campaign information, device and operating system information, together with the account ID and a limited number of in-app events such as registration, starting a subscription and playing a game, are transferred to the service provider. Threads, comments and search text written by the user are not sent to this service. On iOS devices the advertising identifier is processed only if app tracking permission has been granted; where permission is not granted, measurement is limited to aggregated data provided by Apple that cannot be linked to an individual. This processing activity relies on Piklabs’s legitimate interest in measuring marketing activities. The service provider’s servers are located outside Türkiye.
- Google (artificial intelligence model service): Automatic generation of replies by the character accounts in the application to user messages. When a user tags a character account, the text written by the person doing the tagging, the name and body of the thread, the other comments in the same thread and the display names of the users who wrote that content are sent to the service provider in order to generate a reply. E-mail addresses, usernames and account IDs are not sent. Under the service provider’s paid usage terms, the data sent is not used to train artificial intelligence models. The transmission of data starts with the user’s own action; unless a character account is tagged, no data is transferred to this service. The service provider’s servers are located abroad.
- Google Firebase Cloud Messaging: Delivering notifications to Android devices. In order for a notification to be delivered, the device push token and the content of the notification are transmitted to the service provider. This service is used only for sending notifications; no data is processed for usage measurement or advertising purposes.
- Resend or the equivalent e-mail service used: Sending verification, account security, service information and support e-mails.
Service providers are authorised to process the data transferred to them in line with Piklabs’s instructions and limited to the specified purposes. Service providers’ own independent data processing activities may be subject to their own privacy policies.
10. International data transfers
Where Supabase servers are located in the European Union, or where providers such as Apple, Google, RevenueCat, Resend, AdMob, PostHog, AppsFlyer and similar use global infrastructure, personal data may be transferred abroad or processed abroad.
The following matters are assessed before any transfer abroad:
- The categories of data to be transferred,
- The purpose of the transfer,
- The service provider to which the data will be transferred,
- The country or countries in which the data may be processed,
- Whether the service provider uses sub-processors,
- The duration of the transfer,
- The legal safeguard to be applied to the transfer,
- The risks to the fundamental rights and freedoms of the data subject,
- The level of protection of the data after the transfer.
Transfers abroad are carried out within the framework of the KVKK provisions in force and the relevant secondary regulations. Depending on the nature of the transfer, an adequacy decision, appropriate safeguard methods, standard contracts, binding corporate rules or other mechanisms provided for in the legislation may be used.
A general statement such as “data is transferred abroad with safeguards compliant with the legislation” does not remove the obligation to determine the transfer mechanism separately in the company’s internal records. Piklabs documents its data transfer processes through the data processing inventory, service provider agreements and records of transfers abroad.
11. Advertisements and ad preferences
If you do not have a Plus subscription, advertisements may be displayed within the application. Within the scope of ad display, your device’s advertising identifier and the limited technical information required for serving ads may be processed.
The display of personalised advertising is subject to the operating system used, the ad provider and the relevant permission mechanisms. If you do not grant permission for personalised advertising, advertisements may still be displayed; however, they may not be personalised according to your interests.
On iOS devices, app tracking permission and device settings apply; on Android devices, the operating system and advertising settings apply. Refusing these permissions affects ad personalisation, which is not mandatory for creating an account or using the core piCue services.
The advertising identifier, the technical information that may be transferred to the ad provider and ad measurement activities are determined according to the actual configuration of the software development kits used. Piklabs reviews its advertising and analytics services regularly.
12. Notifications
In order to send notifications, the device token, notification preferences and notification delivery records may be processed.
Notifications may be sent for the following purposes:
- Account security,
- E-mail verification,
- Password or account operations,
- Subscription status,
- Operation of the service,
- Community activities,
- Follow and interaction notifications,
- Product information in line with the user’s preferences,
- Optional promotional and marketing messages.
Notifications that are mandatory for the operation of the service are kept separate from optional marketing notifications. You can change your notification permission from your device settings or from the notification preferences section within the application.
The electronic message consents and the commercial electronic message legislation that must additionally be applied to marketing communications are reserved.
13. Complaint and moderation records
When you submit a complaint about a thread, a comment or a profile, the following data may be recorded:
- The identity of the account submitting the complaint,
- The content complained of,
- The reason for the complaint,
- The description written by the user,
- The date of the complaint,
- The outcome of the review and moderation,
- The sanction applied where necessary,
- Objection or re-evaluation records.
The identity of the person submitting a complaint is not, as a rule, shared with the user complained of. However, cases where this is mandatory due to a request from an authorised authority, a legal obligation, judicial proceedings, the right of defence or the establishment and protection of a right are reserved.
Where, as a result of moderation, content is removed or an account is warned, temporarily suspended or closed, the decision and the grounds for the decision may be recorded for platform security and account management purposes.
Moderation records are retained only for the period necessary for the processing purpose. If it is stated that violation records from the last 90 days will be taken into account when calculating sanctions, the technical system must operate in accordance with that rule. If data is to be retained for a longer period, a different retention purpose and period must be determined separately.
14. Account deletion
You can delete your account using the “Delete my account” option within the application.
If your account is deleted, the following data is deleted or rendered incapable of being associated with your identity, unless there is a legal or technical requirement to retain it:
- Profile information,
- Profile and cover photos,
- Lists,
- Collections,
- Threads,
- Comments,
- Follow relationships,
- User preferences,
- Content associated with the account.
Deleting an account may not automatically remove records that must be retained under legislation, ongoing disputes, security reviews, financial records or data that is mandatory for the establishment and protection of a right.
If it is planned to blacklist the e-mail address of permanently closed accounts in order to prevent a new account from being created, that practice is also subject to limits. Only the necessary data is kept for the blacklist, access permissions are restricted and a retention period is set. Blacklist data is not kept indefinitely; a necessity assessment is carried out at regular intervals.
Data deleted from active systems may remain in technical backups for a period. Data in backups is deleted or overwritten at the end of the maximum period required by the backup cycle. This period is set out in Piklabs’s internal retention and erasure plan.
15. Retention periods
Personal data is retained only for as long as it is necessary for the processing purpose and for the period prescribed by legislation.
The following matters are taken into account when determining the retention period:
- The purpose for which the data is processed,
- Whether the service relationship is continuing,
- Whether the account is open or closed,
- Financial and commercial retention obligations,
- Whether there is a legal dispute or investigation,
- Security and misuse risks,
- The data subject’s deletion request,
- The technical cycle of the backup system,
- Any legal basis requiring the data to be kept for another purpose.
Piklabs establishes a retention and erasure plan for the categories of data. This plan covers at least account data, contact data, subscription records, moderation records, support records, security logs, explicit consent records, advertising preferences, backups and legal dispute files.
The phrase “for as long as the account is open” does not on its own explain the retention period that will apply after the account is closed. For this reason, the maximum period to be applied after the processing purpose ends is determined separately for each category of data.
16. Data security
Piklabs applies appropriate technical and administrative measures to prevent the unlawful processing of and access to personal data and the unlawful transfer, loss or destruction of data.
Depending on the technical structure of the service, the measures may include the following:
- Encryption of data transmission between the application and the server,
- Not storing passwords in plain text,
- Limiting access permissions on a role and need-to-know basis,
- Applying database access rules,
- Logging administrator access,
- Applying security updates,
- Applying backup and recovery procedures,
- Reviewing the security requirements of service providers,
- Informing employees about their confidentiality obligations,
- Monitoring security incidents,
- Regular risk assessment,
- Periodically reviewing authorisation and access controls.
No electronic system is absolutely secure. If a data security breach in which personal data has been obtained by unlawful means is detected, the nature and effects of the incident are assessed. The necessary notifications are made to the Personal Data Protection Board and to the persons likely to be affected, in accordance with the legislation in force.
For Türkiye, it is not assumed that an automatic and general “notification within 72 hours” rule applies to every data security incident. The notification obligation is assessed on the basis of the nature, effect and scope of the incident and the regulations in force.
17. Automated evaluation and personalisation
İzleme DNA, Picsona and similar features may generate film and series recommendations or matching results based on the preferences provided by the user.
The main purpose of these systems is to personalise the user experience and to offer content recommendations. The system is not designed to make a decision that produces legal effects concerning the user or that is similarly significant.
Personalisation systems may use the answers given by the user, card selections, favourites, watchlists, watched content and similar preference data. This data may be analysed for the purpose of generating recommendations.
If Piklabs is to use automated decision-making mechanisms that significantly affect users’ fundamental rights, it will separately inform data subjects about the nature of the decision, the categories of data used, the likely consequences and the available means of objection.
If a user believes that the recommendations generated about them are incorrect, they can change their preferences or submit a support request to support@picue.app.
18. User rights
Under the personal data protection legislation in force, and to the extent the conditions are met, you have the following rights:
- To learn whether your personal data is being processed,
- To request information if your personal data has been processed,
- To learn the purpose of processing your personal data and whether it is used in line with that purpose,
- To know the third parties to whom your personal data is transferred in Türkiye or abroad,
- To request the correction of personal data that has been processed incompletely or incorrectly,
- To request the erasure or destruction of your personal data where the statutory conditions are met,
- To request that correction, erasure or destruction operations be notified to the third parties to whom the data was transferred,
- To object to an adverse outcome arising from the analysis of processed data solely by automated systems,
- To claim compensation for damage suffered due to the unlawful processing of your personal data,
- To withdraw your consent in processing activities based on explicit consent.
You can change your profile information within the application and close your account using the “Delete my account” option.
You can send your other data requests to hey@picue.app. In order for your application to be evaluated, you may need to state your request clearly and, where necessary, provide information suitable for identity verification.
Applications are evaluated within the procedures and periods prescribed by the legislation in force. If your application is rejected, if the response given is found insufficient or if no response is given within the time limit, your rights of application and complaint under the legislation in force are reserved.
19. Withdrawal of explicit consent
You can change the following preferences at any time, depending on the technical method used:
- Notification permission,
- Personalised advertising permission,
- Optional marketing communications,
- Profile visibility preferences,
- The visibility preference of the Picsona card,
- Optional analytics or personalisation preferences.
You can withdraw your consent from your device settings, from the preference screens within the application or by applying to hey@picue.app.
If a processing activity is based not on explicit consent but on the performance of a contract, a legal obligation, a legitimate interest or another statutory processing condition, withdrawing consent may not automatically bring that processing activity to an end.
Withdrawal of consent does not affect the lawfulness of the processing carried out on the basis of consent before the date of withdrawal.
20. Age limit and children’s data
piCue’s service age limit must be consistent with the age ratings in the application stores and with the actual technical operation of the application.
You must be at least 16 years old to use piCue. Age information is collected through the date of birth you declare when creating an account, and accounts that do not meet this requirement cannot be created. The date of birth is retained for the purpose of verifying the age requirement and providing the service in an age-appropriate manner. The age classification in the app stores has also been set in line with this limit. No processing activity requiring parental or legal guardian verification is carried out.
If it is determined that data belonging to a person under the age of 16 has been processed unlawfully or excessively, the account may be restricted and the data may be deleted or anonymised, unless there is another legal basis requiring its retention.
If you believe that a child’s personal data is being processed unlawfully on piCue, you can send a notification to hey@picue.app.
21. Cookies and website technologies
Classic internet cookies may not be used in the mobile application. However, local storage, device identifiers, software development kits, advertising technologies or analytics tools may be used within the application.
On the picue.app website, mandatory local storage technologies may be used to remember language preferences, sessions or user settings.
Where cookies or similar technologies serving advertising, analytics or tracking purposes are used, those technologies are explained in a separate cookie policy or preference management tool. Users are given the necessary choice with regard to non-mandatory technologies.
Where links to third party websites are not operated by Piklabs, Piklabs is not responsible for the data processing activities of those sites. You should review the privacy policies of the relevant organisations before using those sites.
22. User content and data belonging to third parties
Content you share in thread, comment, profile, collection or image areas may be seen by other users according to the visibility settings of the relevant feature.
You must not share the following data without the lawful consent of the third parties concerned:
- E-mail addresses,
- Telephone numbers,
- Identity information,
- Private correspondence,
- Health information,
- Financial information,
- Location information,
- Images or personal information belonging to children,
- Account passwords,
- Information falling within the privacy of private life.
If you believe that content constitutes a personal data breach, harassment, a threat, a violation of private life, a copyright infringement or another rule violation, you can use the complaint tools within the application or contact support@picue.app.
Piklabs may review the content complained of within the scope of community safety, legal obligations, user safety or the service rules.
23. Changes to the policy
This Privacy Policy may be updated in line with changes in the services, the technical infrastructure, the service providers or the legislation.
When an update is made, the “last updated” date at the beginning of the text is changed. For changes that significantly affect users’ rights, the categories of data processed, the recipients of data transfers, retention periods or legal bases, an in-app notification, an e-mail or another appropriate means of communication may be used.
Before significant changes take effect, users are given the opportunity to review the current text where necessary.
The updated version of the policy may apply to existing and new users, depending on the nature of the change, as of the date on which it is published.
24. Contact and applications
For personal data requests, privacy questions, data security notifications and applications under the KVKK:
Piklabs Yazılım ve Teknoloji Hizmetleri Limited Şirketi
Address: Gayrettepe Mah. Nurgül Sk. Polat 8 Apt. No: 8 İç Kapı No: 2, Beşiktaş/İstanbul
E-mail: hey@picue.app
For user content, moderation decisions, account security and technical support requests:
E-mail: support@picue.app
During the evaluation of applications, additional information may be requested in order to verify the identity of the applicant and to determine the scope of the request. Information obtained for identity verification purposes is used solely for the purpose of securely concluding the application.
If Piklabs’s response is found insufficient, if the request is rejected or if no response is given within the period prescribed by legislation, the data subject’s right to apply or complain to the Personal Data Protection Board is reserved.
Effective date: 14 August 2026 · Version: 2.0