Skip to content
Legal

Privacy Policy

Last updated: 9 August 2026

This is a courtesy translation of the Turkish original (“YazBunu Gizlilik Politikası”). In case of any discrepancy, the Turkish text prevails.

1. Purpose and Scope

This Privacy Policy explains how personal data and user content are processed, protected, stored and, where necessary, transferred while using the YazBunu service offered by Peracom Yazılım Danışmanlık A.Ş.

YazBunu is currently a mobile application distributed in Türkiye only. It runs on iPhone and Android phones; on iPhone it additionally offers extra recording channels through the Apple Watch and CarPlay extensions. A desktop or web application is not within the current scope of this Privacy Policy. The way audio is processed differs depending on the platform used; the details are set out in the table under “Audio Processing Paths”.

YazBunu is a digital note-taking and transcription service that allows the user to create voice notes, convert certain recordings into text, edit notes, generate summaries, decisions, tasks, titles and tags from transcripts, prepare follow-up e-mail drafts from meeting content, optionally back up selected text content in end-to-end encrypted form, and manage notes within the application.

This Privacy Policy covers:

This Policy must be read together with the Information Notice (Aydınlatma Metni) and the Explicit Consent Text (Açık Rıza Metni). The Information Notice explains for which purposes, on which legal grounds and to which recipient groups personal data may be transferred. The Explicit Consent Text is used for processing activities that require separate and optional consent.

2. Identity and Contact Details of the Data Controller

The data controller for the YazBunu service is:

Peracom Yazılım Danışmanlık A.Ş.

Address: Gülbahar Mah., Avni Dilligil Sok., Çelik İş Blokları A Blok, No: 11 Floor: 4 Office: 417, Şişli / İstanbul, Türkiye

E-mail: destek@peracom.net

Telephone: +90 212 243 10 80

Users may submit questions regarding the processing of their personal data, retention and deletion processes, their accounts, technical security practices or this Policy through the contact channels above.

Depending on the nature of the request, identity verification may be requested when assessing applications relating to the protection of personal data. The purpose of this practice is to prevent unauthorised persons from obtaining information about user accounts or user data.

This Privacy Policy explains YazBunu’s personal data and user content processing practices in general and technical terms.

The Information Notice explains:

The Explicit Consent Text is used for processing activities that are activated at the user’s choice and must be approved separately. In particular:

may be subject to separate consent or separate user preference screens.

The temporary upload of recordings created on Android phones to the server for transcription is, however, not a subject of the Explicit Consent Text. Because on Android phones the temporary upload of the audio file to the server for transcription is technically necessary for the service to be provided, this processing does not rely on explicit consent but on the performance of a contract under Article 5/2-c of the KVKK (processing of the personal data of the parties to a contract being necessary, provided that it is directly related to the establishment or performance of that contract); no separate explicit consent is sought for this operation. The legal ground for this operation is explained in the Information Notice.

Providing an information notice does not by itself mean that explicit consent has been obtained. Likewise, obtaining explicit consent does not remove the obligation to provide an information notice.

Consent or a user preference given for one feature does not mean that consent or preferences for other features have also been accepted.

4. YazBunu’s Basic Privacy Approach

YazBunu is designed on the principles of processing personal data on the device as far as possible, transferring only necessary data to the server, and keeping transferred data limited to the purpose.

Accordingly:

It should nevertheless be acknowledged that the application operates depending on the device, operating system, connection, third-party services and server infrastructure, and that no electronic system can provide absolute security.

5. Types of Data and Content Processed

Depending on the use of YazBunu and the features enabled, the following types of data and content may be processed:

YazBunu does not create, collect, store as separate data, or use for such purposes any voiceprint, biometric voice profile or biometric voice template.

6. Nature of User Content

The audio, notes, transcripts, meeting summaries, decisions, tasks, e-mail drafts and other texts that the user records in YazBunu are treated as user content.

The user is responsible for the nature and lawfulness of the content uploaded to or created in the application and for having obtained the necessary permissions. In particular, where a meeting, interview, training session, workplace meeting or multi-party conversation is recorded, the user must:

YazBunu does not automatically, completely and conclusively verify the lawfulness of the meeting content recorded by the user. Depending on the circumstances, providing the necessary notices and obtaining the necessary permissions in respect of meeting recording or sharing may be the user’s responsibility.

7. Audio Processing Paths

In YazBunu, audio processing is carried out through different paths depending on the platform used and the type of recording.

Type of recording Processing path Status of the audio file
Daily or work note on iPhone (live recognition) Audio may be processed using Apple’s on-device or Apple speech recognition services. Apple’s own privacy rules and policies may also apply to this process. The m4a audio file remains on the device.
Meeting Mode, CarPlay and Apple Watch The audio file is uploaded temporarily to the YazBunu server for transcription purposes. It may be held on Supabase Storage in the Frankfurt/European Union region and converted to text via AssemblyAI’s European region endpoint api.eu.assemblyai.com. The audio file is deleted from the server once processing is complete and in any event within 24 hours at the latest from the date of upload. The m4a file may also remain on the device.
All recordings created on Android phones (daily, work note and meeting) Because on-device Turkish speech recognition is not available on Android devices, the audio file is uploaded temporarily to the YazBunu server for transcription purposes regardless of the type of recording. It is held on Supabase Storage in the Frankfurt/European Union region and converted to text via AssemblyAI’s European region endpoint api.eu.assemblyai.com. The audio file is deleted from the server once processing is complete and in any event within 24 hours at the latest from the date of upload. The m4a file may also remain on the device.
Text structuring with artificial intelligence Only the transcript or the text selected by the user is sent in order to generate summaries, decisions, tasks, classifications or similar outputs. No audio file is sent at this stage.

In live recognition of daily or work notes, the technical method by which audio is processed may depend on Apple’s operating system and the relevant service configuration.

In Meeting Mode, CarPlay and Apple Watch recordings, audio is uploaded to the server solely for transcription purposes.

Because on-device Turkish speech recognition is not available on Android phones, in all recordings and regardless of the type of recording the audio file is uploaded temporarily to the server for transcription purposes and is subject to the same rules as the meeting flow: it is held in the Frankfurt/European Union region, converted to text via AssemblyAI’s European region endpoint, deleted once processing is complete and in any event within 24 hours at the latest, is not included in the end-to-end encrypted cloud backup, and no voiceprint is created. This temporary upload does not mean that the audio file is included in the cloud backup. Because on Android phones the temporary upload of the audio file to the server for transcription is technically necessary for the service to be provided, this processing does not rely on explicit consent but on the performance of a contract under Article 5/2-c of the KVKK (processing of the personal data of the parties to a contract being necessary, provided that it is directly related to the establishment or performance of that contract); no separate explicit consent is sought for this operation.

8. Meeting Mode, CarPlay and Apple Watch

Meeting Mode, CarPlay and Apple Watch are recording channels through which audio can be captured in different usage scenarios.

When these channels are used, the following may be processed:

In Meeting Mode, CarPlay and Apple Watch recordings, the audio file may be transferred temporarily to the YazBunu server for transcription purposes. This audio file may be held on Supabase Storage in the Frankfurt/European Union region and processed via AssemblyAI’s European region endpoint api.eu.assemblyai.com.

Once transcription is complete, and in any event within 24 hours at the latest from the upload of the audio file to the server, the audio file is deleted from the server. An hourly clean-up mechanism is used to carry out this deletion.

The user must inform meeting participants before recording starts. The presence of a recording indicator or an in-app warning does not remove any separate obligation the user may have to inform participants.

The user who starts a meeting recording is not authorised to give explicit consent on behalf of other participants. Depending on the nature of the meeting, the necessary legal assessment, notification and permission processes must be carried out separately.

9. Text Structuring with Artificial Intelligence

YazBunu may process the transcript or text content selected by the user with artificial intelligence supported systems in order to generate the following outputs:

As a rule, only the following are processed at the artificial intelligence structuring stage:

No audio file is sent at this stage.

Google Gemini may be used in YazBunu’s artificial intelligence supported processing service. Depending on the product configuration or technical requirements, alternative providers such as OpenAI or Anthropic may also be used.

The data sent to the artificial intelligence service provider is limited to the selected processing purpose. User content is not used to train artificial intelligence models or to build advertising profiles outside the purpose of the service.

There is no guarantee that outputs generated by artificial intelligence will be accurate, complete, up to date or fully appropriate to the context. The user must review any summary, decision, task or e-mail draft before sharing or sending it or using it in an important transaction.

Artificial intelligence outputs do not in themselves constitute legal, medical, financial or professional advice.

10. Cloud Backup and Synchronisation

Where the user separately enables it, YazBunu may provide an end-to-end encrypted cloud backup and cross-device synchronisation service.

Only the following, as selected by the user, may be backed up or synchronised:

Audio files, m4a recordings and raw audio files processed temporarily on the server for transcription purposes are not included in the end-to-end encrypted cloud backup.

Supabase’s authentication, encrypted backup and storage services may be used for the cloud backup and synchronisation service. The temporary audio file storage infrastructure is located in the Frankfurt/European Union region.

Within the scope of end-to-end encryption, the decryption key is protected by the user. Peracom Yazılım Danışmanlık A.Ş. cannot view, store or regenerate this password on the user’s behalf.

If the user loses the end-to-end encryption password or the necessary recovery information, it may be technically impossible to restore the encrypted backup. The user is responsible for storing the encryption password and recovery information securely.

Cloud backup is not a mandatory part of the basic local note-taking function. Where the user does not enable this feature, the user may continue to use the basic local note-taking functions, provided that the other legal and technical conditions are met.

11. E-mail Drafts and E-mail Sending

YazBunu may generate a follow-up e-mail draft from meeting or note content. The e-mail draft:

Before sending the e-mail, the user must check:

Where the user expressly approves before sending, the e-mail is sent through the user’s own e-mail (SMTP) account configured in the application. When sending through the user’s own e-mail account, the recipient, subject and body of the e-mail and the connection details of the user’s e-mail account pass through the YazBunu server so that the sending can be carried out. This information is not stored on the server; the e-mail account details are kept in an encrypted area on the user’s device.

Where an e-mail is sent, the recipient addresses, e-mail content, time of sending, result of sending and technical sending information may be processed.

YazBunu does not automatically send a meeting summary, transcript, decision, task list or e-mail draft to recipients unless the user approves before sending.

12. Third-Party Service Providers Used

The following service providers may be used in order to operate YazBunu technically:

The extent to which providers are used varies according to the feature enabled by the user and the processing activity carried out. The presence of a provider in this list does not mean that all of the user’s data is transferred to every provider.

For example, using only the artificial intelligence text structuring feature does not result in the audio file being sent to AssemblyAI. The temporary upload of an audio file to the server and its transfer to the transcription service is connected to the Meeting Mode, CarPlay or Apple Watch recording process, or to recording on an Android phone.

13. Cross-Border Data Transfers

Within YazBunu’s technical architecture, certain personal data may be processed through service providers located abroad or operated by companies abroad.

The principal operations that may give rise to cross-border transfers are:

In Meeting Mode, CarPlay and Apple Watch recordings, and in all recordings made on Android phones, the audio file may be transferred temporarily to the server for transcription purposes. At the artificial intelligence text structuring stage no audio file is sent; only the transcript or the text selected by the user is processed.

Cross-border transfers are carried out in a manner that is:

Cross-border transfer processes are assessed within the framework of the applicable legislation and technical security conditions, according to the nature of the transfer and the location of the relevant service provider.

The use of AssemblyAI’s European region endpoint aims to ensure that the audio processing request is carried out through the European region. Nevertheless, a separate assessment may be made in respect of the provider’s corporate headquarters, sub-processors, support infrastructure and data retention practices.

14. Sharing of Personal Data

Personal data may be transferred only to the extent required by the relevant processing purpose to the following persons or organisations:

Where meeting results are shared by the user, the transcript, meeting summary, decisions, task list, e-mail draft and the personal data contained in that content may be transferred to the recipients determined by the user.

YazBunu does not automatically send meeting outputs or e-mail drafts to recipients unless the user expressly approves before sending.

Where the user’s own SMTP account is used, it is acknowledged that the e-mail content may also be processed by the relevant SMTP service provider. The user’s own account and service terms may also apply to that provider’s data processing practices.

15. Diagnostic Logs Kept on the Device

YazBunu may keep limited technical diagnostic logs on the device in order to understand recording and connection errors technically.

For the application recording pipeline:

For CarPlay and vehicle connection:

These logs:

When the user wishes to share a log, masking is applied on the device; the masked version prepared for sharing is ensured not to contain:

The total size of the diagnostic logs is limited to approximately 1.5 MB (up to 512 KB per log file). When the limit is reached, the oldest records are deleted. If the application is removed from the device, the logs are also deleted from the device.

If the user wishes to share the logs for technical support purposes:

No “do not ask again” option is offered for sharing diagnostic logs. If the user does not approve, the log does not leave the device.

16. Subscription and In-App Purchase Information

YazBunu’s subscription or in-app purchase features may be managed through the Apple App Store, Google Play and RevenueCat.

In this context the following may be processed:

YazBunu does not take direct payment by credit card, digital wallet, bank transfer or FAST during an in-app purchase. Within the current product structure, sales and subscription transactions are carried out through the in-app purchase system of the store from which the application was downloaded (Apple App Store or Google Play).

Payment card details are not collected or stored directly by YazBunu. Payment transactions are carried out through the relevant application store’s own payment infrastructure.

Subscription and transaction records may be kept for a period limited to what is required by the relevant accounting, consumer, legal and technical obligations.

17. Personalisation and Usage Analysis

Where the user separately opts in, YazBunu may process the following in order to personalise the application experience and produce limited usage statistics:

Personalisation and usage analysis are not a mandatory part of the basic local note-taking service. These activities are carried out according to a separate preference or permission flow within the application.

Within the scope of personalisation and usage analysis:

18. Special Categories of Personal Data

YazBunu is not designed to process special categories of personal data. Nevertheless, the audio, notes, transcripts, meeting summaries or e-mail drafts recorded by the user may contain:

Where the user includes such data in the content, it may enter the relevant technical processing flow. YazBunu does not aim to collect or classify such data for an independent purpose.

Users should not record special categories of personal data unless necessary; they should review such data before sharing a meeting, transcript, summary or e-mail and delete or mask it where required.

Stricter access, security, minimisation and retention measures are applied to special categories of personal data.

19. Children’s Data

YazBunu is not a service designed specifically for children.

Where it is understood that children’s personal data are present in the application, within the framework of the applicable legislation, application store rules and technical possibilities:

Where children’s personal data are present in a meeting or audio recording, the user must separately assess the obligations relating to informing the relevant persons and their legal representatives and obtaining the necessary permissions.

The principles of purpose limitation, data minimisation, proportionality and short retention periods apply to children’s data.

20. Data Security Measures

Peracom Yazılım Danışmanlık A.Ş. applies appropriate technical and administrative measures to prevent the unlawful processing of personal data and unauthorised access to, loss, alteration, disclosure or destruction of such data.

Depending on the technical structure of the service, these measures may include:

When cloud backup is enabled, the note and transcript content selected by the user may be encrypted end to end. The decryption key is protected by the user.

In a structure designed so that Peracom Yazılım Danışmanlık A.Ş. cannot access the end-to-end encryption key, the company may be technically unable to read encrypted content stored in the cloud.

Temporary audio files on the server are kept for a period limited to what is necessary for transcription and are deleted within 24 hours at the latest.

On-device diagnostic logs are not sent to the server unless expressly shared by the user.

No electronic system provides an absolute guarantee of security. Users must protect their own devices, account details, access codes, encryption passwords and recovery information.

21. Retention and Deletion Periods

Personal data are retained for the period required by the processing purpose and within the framework of the applicable legal obligations.

Type of data or record Retention period and deletion method
Temporary audio file on the server Kept temporarily for transcription purposes. Deleted once processing is complete and in any event within a maximum of 24 hours from the date of upload. The clean-up job runs hourly.
m4a audio file on the device Depends on the user’s device and application use. May be deleted from the device by the user. Not included in the cloud backup.
Note text and transcript Kept according to the user’s local storage and end-to-end encrypted cloud backup preferences. Placed in the deletion process when deleted by the user or when the retention purpose ends.
Meeting summary, decisions and tasks Kept on the user’s device or in the end-to-end encrypted backup chosen by the user. Placed in the deletion process when deleted by the user or when the retention purpose ends.
E-mail drafts May be kept on the relevant device or within the selected backup until sent, edited or deleted by the user.
Error and crash records Kept for a maximum of 90 days and deleted automatically.
Support and feedback records together with attached screenshots Kept for a maximum of 90 days and deleted automatically.
On-device diagnostic logs Kept on the device within a limit of approximately 1.5 MB. When the limit is reached, the oldest records are deleted. The logs are deleted when the application is removed.
Subscription and transaction records Kept for a period limited to what is required by the Apple App Store, Google Play, RevenueCat and the relevant accounting, consumer or legal obligations.
Account and contact data Kept while the account is active and, after the account is deleted, for a period limited to what is necessary for the applicable legal obligations and the management of disputes.
E-mail sending records Kept for a period limited to what is necessary in terms of sending, security, support and legal requirements.

For temporary audio files on the server, 24 hours is an absolute upper limit. The hourly clean-up mechanism is designed to prevent this period from being exceeded.

Where the retention period expires or the processing purpose ceases to exist, personal data are deleted, destroyed or anonymised.

Where there is a statutory retention obligation, an ongoing dispute or a need for legal defence, certain data may be kept only for the necessary period and with restricted access.

22. Account Deletion and Data Deletion

The user may give an instruction for immediate deletion through the account deletion function within the application.

Within the scope of account deletion, and within the framework of the applicable technical structure and legal obligations, the following may be placed in the deletion process:

Deletion of m4a audio files present on the device may be carried out through the device operating system or the in-app deletion function, separately from the account deletion process within the application.

Subscription and transaction records kept by the Apple App Store, Google Play or RevenueCat may be outside Peracom’s direct control and may be kept for as long as the relevant legal, accounting or consumer obligations continue.

Where there is an ongoing dispute, legal claim or statutory retention obligation, certain records may not be deleted immediately. In that case the data are kept only for the relevant purpose and for the necessary period.

23. Rights of the User

Under the applicable personal data protection legislation, data subjects may have the right to:

Users may also, from within the application or through the support channel:

24. Application Procedure

Requests relating to the processing of personal data may be submitted through the following channels:

The application must state:

Applications are assessed within the procedures and time limits set out in the applicable legislation. Additional information may be requested for security and identity verification purposes.

25. The User’s Privacy and Security Responsibilities

The user must:

Third parties who gain access to the user’s device may be able to access the m4a audio files, notes or transcripts stored locally on the device. For this reason, the device lock, operating system security and application access security must be ensured by the user.

26. Cookies and Similar Technologies

YazBunu’s current service is offered through the iOS and Android mobile application. Classic cookies specific to a website may not be used within the application.

In the services offered through YazBunu’s website (yazbunu.com.tr), Google Analytics, Meta Pixel cookies and similar technologies may be used to improve the user experience, analyse website traffic and carry out marketing activities. These cookies are activated only subject to the consent you give through the cookie banner on the website; unless consent is given, analytics and marketing cookies are not activated.

Nevertheless, on-device identifiers, session information or similar technical technologies may be used for the technical operation of the application, session management, authentication, determination of subscription status, security, error detection or monitoring of application performance.

This technical data may be used only for the purposes of:

Non-mandatory activities such as usage analysis or personalisation may be subject to separate preference or permission mechanisms within the application.

YazBunu does not use user content or audio recordings to build advertising profiles.

27. Privacy Practices of Third-Party Services

The third-party service providers used by YazBunu may have their own privacy policies, terms of use and data processing practices.

The user should take the following into account:

When selecting third-party services, Peracom aims to take into account criteria such as the purpose of the service, security, data minimisation, access limits, retention periods and technical competence.

28. Privacy Breaches and Security Incidents

Where it is understood that personal data may have been affected by unauthorised access, loss, disclosure, alteration or another security incident, Peracom operates technical and administrative processes to assess the nature and impact of the incident.

Where deemed necessary:

Users must immediately report suspicious account activity, the possibility of unauthorised access or a security vulnerability to destek@peracom.net.

29. Changes to the Policy

This Privacy Policy may be updated in the event of:

The current text is published within the application or through the official communication channels relating to YazBunu.

Where a change has significant consequences for the processing of personal data, the user may be notified by in-app notification, e-mail or another appropriate method. Depending on the nature of the change, a new information notice or new explicit consent may be required.

The user is not obliged to review the current Policy regularly; however, the user should take into account the important updates displayed within the application before continuing to use the service.

30. Effective Date and Last Update

This Privacy Policy enters into force on the effective date stated below.

Effective Date: 9 September 2026

Last Updated: 9 September 2026

Data Controller: Peracom Yazılım Danışmanlık A.Ş.

Address: Gülbahar Mahallesi, Avni Dilligil Sokak, Çelik İş Blokları A Blok, No: 11 Floor: 4 Office: 417, Şişli / İstanbul, Türkiye

E-mail: destek@peracom.net

Telephone: +90 212 243 10 80