Privacy Policy

Last updated: 28 September 2026

Privacy and data requests: plakapp@outlook.com

This policy explains how personal data is processed in the Plak mobile app and on Plak’s support and legal pages. In Plak you can create digital records tied to songs, leave them at places chosen by our team, open records you find at a place, design your profile and shelf, and share posts and comments. Some of these actions require an account and location verification.

This English version is provided for convenience. If it differs from the Turkish version, the Turkish version prevails, without prejudice to any mandatory rights you have where you live.

1Information we process and why

InformationHow we get itWhat it’s used for
Account and profileThe user identifier, name and email address (or Apple’s private relay address) from Sign in with Apple; the username, display name, avatar, bio and optional neighbourhood you chooseCreating your account, managing sessions, showing your profile, handling support and security
Content you createRecord designs and notes, the title/artist/link of the song you choose, photos and GIFs you upload, page and shelf designs, Wall posts, commentsPublishing, sharing and displaying content, and moderation
Social activityFollows, reactions, blocks, reports, record openings and their timesRunning social features, sending notifications, preventing abuse
Location verificationWith your permission, while the app is open, your device’s precise current coordinates and location accuracyShowing you on the map; confirming you are near a place so you can drop or open a record; preparing nearby notifications if you turned them on
Notification and device informationExpo push token, platform, time zone, notification preferences and delivery informationDelivering the notifications you allowed and respecting your quiet hours
Technical and security recordsIP address, request and session times, user agent/device information and security events; infrastructure logs kept by service providersProviding the service, session security, rate limiting, troubleshooting and investigating abuse
Support requestsThe messages you send us and the information you provideAnswering your request and looking into disputes

Plak does not use advertising identifiers and does not do third-party advertising, behavioural ad tracking or data selling. The app contains no product analytics such as Firebase or Mixpanel and no separate crash-reporting SDK. Service providers may still keep standard technical logs.

How location is used

We only ask for location permission while you use the app; we never track your location in the background. Other users can’t see your own location marker on the map. When you drop or open a record, your precise coordinates and accuracy value are sent to our server for a one-time check; we don’t store the coordinates in Plak’s database as a permanent field tied to your account. The result of the check, the place and the record ID are stored. The time a record is opened is recorded to the second; the date shown on a dropped record is to the day.

If you turned on “new records nearby” notifications, then while a screen that uses location is open we look up the places around you with your coordinates at most once every 30 minutes. Instead of coordinates, we store the IDs of places within about 1.5 km, linked to your account, for at most 14 days; this list could allow inferences about roughly where you are. When you turn this notification off, the list is deleted. You can turn off location permission in iOS Settings; if you do, dropping and opening records, which require being at the place, may not work.

Photos, the clipboard and data kept on your device

We only use the photo you pick. Before upload, photos are re-encoded on your device as JPEG of at most 1024 pixels, which removes their EXIF/GPS metadata. GIF files are uploaded unconverted so the animation is kept; check their content before sharing. We don’t access the camera or microphone. We read the clipboard only when you start a “Paste” action, to get a song link.

Unsaved drafts, some stickers, trophies, appearance preferences and local reminders stay on your device. The app also keeps offline copies of server content and session tokens on your device. The record artwork and song information you choose for the widget are passed to an iOS App Group container. “Sign out”, “Reset this device” and “Delete account” clear the related local data; after “Reset this device”, server data can be downloaded again when you sign back in.

2Who can see your content?

Your username, display name, optional neighbourhood, avatar, profile page and shelf, as well as Wall posts and comments, are visible to other signed-in users. Follower counts are visible; the list of people you follow is shown only to you. Reactions are shown to others as counts, not as lists of people.

The full content of a record can be seen by the person who left it and by the people who open it at that place. Before it’s opened, other users only see hints such as the sleeve colour, the place and the month; the identity of whoever left it stays hidden until it’s opened. The identity of someone who opens your record may appear to you in a notification. If you send a share card outside the app, the sharing action on your device decides who or which service receives it. Other users can take screenshots of content they can see.

Only the authorised team reviews reports. For moderation and support, the authorised team can access content, account information, reports and activity records to the extent needed. Content and interactions of someone you block are hidden in both directions; they aren’t told about the block.

3Service providers and external links

  • Supabase: authentication, database, private media storage, real-time features and server functions. Account, content, activity and related technical records are processed here. Media links are served as time-limited signed URLs.
  • Apple: Sign in with Apple, Apple Maps/MapKit, App Store subscriptions and APNs notification delivery. Information Apple processes in its own services is also subject to Apple’s terms and privacy disclosures. The map region you view may be sent to Apple Maps.
  • Expo: the notification title/text and Expo push token for delivering push notifications; platform and version information when checking for app updates. Expo’s services may involve processing in the United States.
  • Apple iTunes Search/Lookup API: the song search you type and a country code are sent from your device to Apple to fetch results.
  • Spotify oEmbed / link resolution: if you paste a Spotify link, the link is sent from your device to Spotify to get the song’s details. We don’t connect your Spotify account to Plak.
  • Our web hosting provider: standard web server logs may be created when you visit the support, admin or legal pages.

Data is passed to the providers above and to authorised staff when needed to provide the service. If an official legal request or legal obligation arises, we may share only the necessary information with the competent authorities. We don’t sell personal data to advertisers or data brokers. Putting appropriate data protection and security arrangements in place with our service providers is our responsibility.

Your data may be processed outside Türkiye. Ensuring the legal conditions and safeguards required by applicable data protection rules for these transfers is our responsibility.

4Legal bases

For users in Türkiye, we process data needed to run your account, your records and the other features you request on the basis of entering into or performing a contract; data needed for security, moderation and protecting the service on the basis of legitimate interest, provided it doesn’t harm your rights; and mandatory records and requests on the basis of a legal obligation or the establishment, exercise or protection of a right. Optional profile content, notifications and location features are enabled by your choice; iOS permissions are requested separately. Where the law requires explicit consent for a specific processing activity, we obtain it as a separate and free choice. The mandatory data protection rules of the country you’re in also apply.

5Retention and deletion

Your account and the content you publish are kept for as long as your account stays open, or until you or our team delete the content. Signing out doesn’t delete your account. You can delete your account in Settings → Account → Delete account. This revokes your Sign in with Apple authorisation; your account, profile, records, posts, comments, follows, opening records, notification preferences, push devices and user media files are deleted from the main service areas. Deleting your account doesn’t cancel a subscription bought through Apple; you need to manage that separately in your iOS subscription settings.

Exceptions and periods:

RecordRetention
Rate-limit events and push delivery receiptsAbout 2 days
Nearby place IDsAt most 14 days; sooner if nearby notifications are turned off
In-app notificationsAbout 90 days
Most notification de-duplication eventsAbout 180 days
Follow notification de-duplication keys in the follow: formatNo automatic deletion period in the current system; may contain user IDs
Authorised team audit recordsNo automatic deletion period in the current system; may contain action details and, for events such as account deletion, an email address
Infrastructure providers’ technical logsDepends on the retention settings and periods of the provider concerned

Even after an account is deleted, a report may remain in certain cases with the reporter’s identity removed. Because the audit records and follow: keys above aren’t cleared automatically in the current system, we don’t promise that “everything about your account is deleted instantly and completely”. You can send access or deletion requests about them to the address below; we’ll review applicable legal obligations and technical options and reply.

6Your choices and rights

You can manage your profile and content with the tools in the app, turn off notification categories, block people, and withdraw location and notification permissions in iOS Settings. Turning off a permission doesn’t by itself delete data that was lawfully processed before. To ask about, or exercise, your rights to access, correct, delete, restrict processing of or port your data, to object, or any other applicable rights, write to plakapp@outlook.com. We may ask for reasonable additional information to verify your identity.

Your rights under Article 11 of Türkiye’s Law No. 6698 are reserved. We reply to requests as soon as possible depending on their nature, and within 30 days at the latest; your right to complain to the Board under the relevant legislation is also reserved. If you have additional rights in other countries, we honour those too.

7Security, children and changes

We limit data access with authorised team roles, and use private media storage, time-limited access links and two-factor authentication in the admin panel. No internet service can guarantee absolute security. Take care not to share your home address, phone number or other people’s sensitive information on your profile, records or photos.

Plak is not directed at people under 13. The app doesn’t currently verify age; age-related data protection requirements need to be assessed separately. To tell us about an account or data belonging to a child, contact us at plakapp@outlook.com.

We update this policy when our data practices change. We announce important changes appropriately in the app or through another reasonable channel, and show the current date here. If new purposes require additional permission, we ask for it.