Privacy Policy
Last updated: 9 August 2026
This is a courtesy translation of the Turkish original (“YazBunu Gizlilik Politikası”). In case of any discrepancy, the Turkish text prevails.
1. Purpose and Scope
This Privacy Policy explains how personal data and user content are processed, protected, stored and, where necessary, transferred while using the YazBunu service offered by Peracom Yazılım Danışmanlık A.Ş.
YazBunu is currently a mobile application distributed in Türkiye only. It runs on iPhone and Android phones; on iPhone it additionally offers extra recording channels through the Apple Watch and CarPlay extensions. A desktop or web application is not within the current scope of this Privacy Policy. The way audio is processed differs depending on the platform used; the details are set out in the table under “Audio Processing Paths”.
YazBunu is a digital note-taking and transcription service that allows the user to create voice notes, convert certain recordings into text, edit notes, generate summaries, decisions, tasks, titles and tags from transcripts, prepare follow-up e-mail drafts from meeting content, optionally back up selected text content in end-to-end encrypted form, and manage notes within the application.
This Privacy Policy covers:
- daily and work notes created on iPhone and Android phones,
- Meeting Mode,
- recordings created via CarPlay,
- recordings created via Apple Watch,
- speech-to-text processes,
- text structuring activities performed with artificial intelligence,
- the optional end-to-end encrypted cloud backup and cross-device synchronisation,
- e-mail draft creation and e-mail sending processes,
- subscription and in-app purchase transactions,
- technical support and error reporting processes,
- technical diagnostic logs kept on the device,
- the third-party technical service providers used by the application.
This Policy must be read together with the Information Notice (Aydınlatma Metni) and the Explicit Consent Text (Açık Rıza Metni). The Information Notice explains for which purposes, on which legal grounds and to which recipient groups personal data may be transferred. The Explicit Consent Text is used for processing activities that require separate and optional consent.
2. Identity and Contact Details of the Data Controller
The data controller for the YazBunu service is:
Peracom Yazılım Danışmanlık A.Ş.
Address: Gülbahar Mah., Avni Dilligil Sok., Çelik İş Blokları A Blok, No: 11 Floor: 4 Office: 417, Şişli / İstanbul, Türkiye
E-mail: destek@peracom.net
Telephone: +90 212 243 10 80
Users may submit questions regarding the processing of their personal data, retention and deletion processes, their accounts, technical security practices or this Policy through the contact channels above.
Depending on the nature of the request, identity verification may be requested when assessing applications relating to the protection of personal data. The purpose of this practice is to prevent unauthorised persons from obtaining information about user accounts or user data.
3. Relationship with the Information Notice and the Explicit Consent Text
This Privacy Policy explains YazBunu’s personal data and user content processing practices in general and technical terms.
The Information Notice explains:
- the categories of personal data processed,
- the methods by which personal data are obtained,
- the purposes of processing,
- the legal grounds for the processing activities,
- the recipient groups to which data may be transferred,
- the retention periods,
- the rights of data subjects.
The Explicit Consent Text is used for processing activities that are activated at the user’s choice and must be approved separately. In particular:
- transcription of Meeting Mode, CarPlay and Apple Watch recordings,
- text structuring with artificial intelligence,
- optional end-to-end encrypted cloud backup,
- cross-device synchronisation,
- certain cross-border transfer scenarios,
- optional personalisation and usage analysis,
- sharing by e-mail
may be subject to separate consent or separate user preference screens.
The temporary upload of recordings created on Android phones to the server for transcription is, however, not a subject of the Explicit Consent Text. Because on Android phones the temporary upload of the audio file to the server for transcription is technically necessary for the service to be provided, this processing does not rely on explicit consent but on the performance of a contract under Article 5/2-c of the KVKK (processing of the personal data of the parties to a contract being necessary, provided that it is directly related to the establishment or performance of that contract); no separate explicit consent is sought for this operation. The legal ground for this operation is explained in the Information Notice.
Providing an information notice does not by itself mean that explicit consent has been obtained. Likewise, obtaining explicit consent does not remove the obligation to provide an information notice.
Consent or a user preference given for one feature does not mean that consent or preferences for other features have also been accepted.
4. YazBunu’s Basic Privacy Approach
YazBunu is designed on the principles of processing personal data on the device as far as possible, transferring only necessary data to the server, and keeping transferred data limited to the purpose.
Accordingly:
- on iPhone, voice content in the nature of daily or work notes is processed on the device as far as possible,
- in Meeting Mode, CarPlay and Apple Watch recordings, raw audio files transferred to the server are kept temporarily and solely for transcription purposes,
- temporary audio files are deleted once processing is complete and in any event within 24 hours at the latest,
- audio files, m4a recordings and raw audio recordings are not included in the end-to-end encrypted cloud backup,
- no audio file is sent during the artificial intelligence text structuring stage,
- no voiceprint or biometric voice profile is created,
- on-device diagnostic logs are not sent to the server automatically,
- user content is not used for advertising or for training artificial intelligence models outside the purpose of the service,
- features that require separate consent or a separate user preference are offered independently of one another as far as possible.
It should nevertheless be acknowledged that the application operates depending on the device, operating system, connection, third-party services and server infrastructure, and that no electronic system can provide absolute security.
5. Types of Data and Content Processed
Depending on the use of YazBunu and the features enabled, the following types of data and content may be processed:
- first name, surname, username and account identifier,
- e-mail address and contact details,
- account login and authentication information,
- audio recordings taken via iPhone, Android phone, Apple Watch or CarPlay,
- technical information about the audio file,
- transcripts,
- note texts,
- meeting summaries,
- decisions and action items,
- to-do lists,
- task assignments,
- titles and tags,
- meeting date, time, duration and title,
- participant information,
- follow-up e-mail drafts,
- e-mail recipients and sending information,
- text excerpts the user selects for structuring with artificial intelligence,
- cloud backup data in respect of the text content selected by the user,
- subscription status, renewal and in-app purchase information,
- Apple App Store, Google Play or RevenueCat transaction identifiers,
- device model, operating system version and application version,
- session, connection, performance, error and crash information,
- security logs,
- in-app settings and usage preferences,
- support, complaint and feedback content,
- screenshots or files added by the user,
- the
diag.logandcarplay.loglogs kept on the device, - the voices, speech, names, roles, opinions and contact details of other persons present in a meeting or recording,
- special categories of personal data that may be present in the content recorded by the user.
YazBunu does not create, collect, store as separate data, or use for such purposes any voiceprint, biometric voice profile or biometric voice template.
6. Nature of User Content
The audio, notes, transcripts, meeting summaries, decisions, tasks, e-mail drafts and other texts that the user records in YazBunu are treated as user content.
The user is responsible for the nature and lawfulness of the content uploaded to or created in the application and for having obtained the necessary permissions. In particular, where a meeting, interview, training session, workplace meeting or multi-party conversation is recorded, the user must:
- inform participants about the recording,
- where necessary, obtain permission or explicit consent from the relevant persons,
- explain the purpose and scope of the meeting recording,
- review the transcript, summary and task lists generated before sharing them,
- delete or mask unnecessary personal data,
- avoid including special categories of personal data in the recording as far as possible,
- check recipients and content before sending an e-mail.
YazBunu does not automatically, completely and conclusively verify the lawfulness of the meeting content recorded by the user. Depending on the circumstances, providing the necessary notices and obtaining the necessary permissions in respect of meeting recording or sharing may be the user’s responsibility.
7. Audio Processing Paths
In YazBunu, audio processing is carried out through different paths depending on the platform used and the type of recording.
| Type of recording | Processing path | Status of the audio file |
|---|---|---|
| Daily or work note on iPhone (live recognition) | Audio may be processed using Apple’s on-device or Apple speech recognition services. Apple’s own privacy rules and policies may also apply to this process. | The m4a audio file remains on the device. |
| Meeting Mode, CarPlay and Apple Watch | The audio file is uploaded temporarily to the YazBunu server for transcription purposes. It may be held on Supabase Storage in the Frankfurt/European Union region and converted to text via AssemblyAI’s European region endpoint api.eu.assemblyai.com. | The audio file is deleted from the server once processing is complete and in any event within 24 hours at the latest from the date of upload. The m4a file may also remain on the device. |
| All recordings created on Android phones (daily, work note and meeting) | Because on-device Turkish speech recognition is not available on Android devices, the audio file is uploaded temporarily to the YazBunu server for transcription purposes regardless of the type of recording. It is held on Supabase Storage in the Frankfurt/European Union region and converted to text via AssemblyAI’s European region endpoint api.eu.assemblyai.com. | The audio file is deleted from the server once processing is complete and in any event within 24 hours at the latest from the date of upload. The m4a file may also remain on the device. |
| Text structuring with artificial intelligence | Only the transcript or the text selected by the user is sent in order to generate summaries, decisions, tasks, classifications or similar outputs. | No audio file is sent at this stage. |
In live recognition of daily or work notes, the technical method by which audio is processed may depend on Apple’s operating system and the relevant service configuration.
In Meeting Mode, CarPlay and Apple Watch recordings, audio is uploaded to the server solely for transcription purposes.
Because on-device Turkish speech recognition is not available on Android phones, in all recordings and regardless of the type of recording the audio file is uploaded temporarily to the server for transcription purposes and is subject to the same rules as the meeting flow: it is held in the Frankfurt/European Union region, converted to text via AssemblyAI’s European region endpoint, deleted once processing is complete and in any event within 24 hours at the latest, is not included in the end-to-end encrypted cloud backup, and no voiceprint is created. This temporary upload does not mean that the audio file is included in the cloud backup. Because on Android phones the temporary upload of the audio file to the server for transcription is technically necessary for the service to be provided, this processing does not rely on explicit consent but on the performance of a contract under Article 5/2-c of the KVKK (processing of the personal data of the parties to a contract being necessary, provided that it is directly related to the establishment or performance of that contract); no separate explicit consent is sought for this operation.
8. Meeting Mode, CarPlay and Apple Watch
Meeting Mode, CarPlay and Apple Watch are recording channels through which audio can be captured in different usage scenarios.
When these channels are used, the following may be processed:
- the user’s voice,
- the voices of other persons participating in the recording,
- the content of conversations,
- the person, role and contact details mentioned in the meeting,
- meeting date, time, duration and title,
- the transcript,
- the meeting summary,
- decisions,
- task and action items,
- the follow-up e-mail draft.
In Meeting Mode, CarPlay and Apple Watch recordings, the audio file may be transferred temporarily to the YazBunu server for transcription purposes. This audio file may be held on Supabase Storage in the Frankfurt/European Union region and processed via AssemblyAI’s European region endpoint api.eu.assemblyai.com.
Once transcription is complete, and in any event within 24 hours at the latest from the upload of the audio file to the server, the audio file is deleted from the server. An hourly clean-up mechanism is used to carry out this deletion.
The user must inform meeting participants before recording starts. The presence of a recording indicator or an in-app warning does not remove any separate obligation the user may have to inform participants.
The user who starts a meeting recording is not authorised to give explicit consent on behalf of other participants. Depending on the nature of the meeting, the necessary legal assessment, notification and permission processes must be carried out separately.
9. Text Structuring with Artificial Intelligence
YazBunu may process the transcript or text content selected by the user with artificial intelligence supported systems in order to generate the following outputs:
- summary,
- decision,
- action item,
- to-do list,
- task assignment,
- title,
- tag,
- classified text,
- follow-up e-mail draft.
As a rule, only the following are processed at the artificial intelligence structuring stage:
- the transcript,
- text entered directly by the user,
- text excerpts selected by the user,
- the limited meeting information required for structuring.
No audio file is sent at this stage.
Google Gemini may be used in YazBunu’s artificial intelligence supported processing service. Depending on the product configuration or technical requirements, alternative providers such as OpenAI or Anthropic may also be used.
The data sent to the artificial intelligence service provider is limited to the selected processing purpose. User content is not used to train artificial intelligence models or to build advertising profiles outside the purpose of the service.
There is no guarantee that outputs generated by artificial intelligence will be accurate, complete, up to date or fully appropriate to the context. The user must review any summary, decision, task or e-mail draft before sharing or sending it or using it in an important transaction.
Artificial intelligence outputs do not in themselves constitute legal, medical, financial or professional advice.
10. Cloud Backup and Synchronisation
Where the user separately enables it, YazBunu may provide an end-to-end encrypted cloud backup and cross-device synchronisation service.
Only the following, as selected by the user, may be backed up or synchronised:
- note texts,
- transcripts,
- folders,
- tags,
- other appropriate text content.
Audio files, m4a recordings and raw audio files processed temporarily on the server for transcription purposes are not included in the end-to-end encrypted cloud backup.
Supabase’s authentication, encrypted backup and storage services may be used for the cloud backup and synchronisation service. The temporary audio file storage infrastructure is located in the Frankfurt/European Union region.
Within the scope of end-to-end encryption, the decryption key is protected by the user. Peracom Yazılım Danışmanlık A.Ş. cannot view, store or regenerate this password on the user’s behalf.
If the user loses the end-to-end encryption password or the necessary recovery information, it may be technically impossible to restore the encrypted backup. The user is responsible for storing the encryption password and recovery information securely.
Cloud backup is not a mandatory part of the basic local note-taking function. Where the user does not enable this feature, the user may continue to use the basic local note-taking functions, provided that the other legal and technical conditions are met.
11. E-mail Drafts and E-mail Sending
YazBunu may generate a follow-up e-mail draft from meeting or note content. The e-mail draft:
- can be viewed by the user,
- can be edited by the user,
- can be deleted by the user,
- is not sent unless the user expressly approves it.
Before sending the e-mail, the user must check:
- the recipient addresses,
- the e-mail subject,
- the e-mail body,
- attachments,
- the personal data contained in the meeting or note content.
Where the user expressly approves before sending, the e-mail is sent through the user’s own e-mail (SMTP) account configured in the application. When sending through the user’s own e-mail account, the recipient, subject and body of the e-mail and the connection details of the user’s e-mail account pass through the YazBunu server so that the sending can be carried out. This information is not stored on the server; the e-mail account details are kept in an encrypted area on the user’s device.
Where an e-mail is sent, the recipient addresses, e-mail content, time of sending, result of sending and technical sending information may be processed.
YazBunu does not automatically send a meeting summary, transcript, decision, task list or e-mail draft to recipients unless the user approves before sending.
12. Third-Party Service Providers Used
The following service providers may be used in order to operate YazBunu technically:
- Supabase: Authentication, end-to-end encrypted cloud backup and temporary audio file storage services. The temporary audio storage infrastructure is in the Frankfurt/European Union region.
- AssemblyAI: Transcription of meeting, CarPlay and Apple Watch recordings, and of Android recordings. The operation is carried out via the European region endpoint
api.eu.assemblyai.com. - Google Gemini: Structuring of transcripts or text content selected by the user with artificial intelligence.
- OpenAI or Anthropic: Artificial intelligence services that may be used as an alternative to Google Gemini for text structuring, depending on the product configuration or technical requirements.
- RevenueCat: Management of subscription status and in-app purchase information.
- Railway: Server hosting and technical operation of the application.
- Resend: Sending of account e-mails.
- The user’s own SMTP account: E-mail sending initiated by the user from within the application is carried out through this account. The sending information passes through the YazBunu server so that the operation can be carried out and is not stored on the server.
The extent to which providers are used varies according to the feature enabled by the user and the processing activity carried out. The presence of a provider in this list does not mean that all of the user’s data is transferred to every provider.
For example, using only the artificial intelligence text structuring feature does not result in the audio file being sent to AssemblyAI. The temporary upload of an audio file to the server and its transfer to the transcription service is connected to the Meeting Mode, CarPlay or Apple Watch recording process, or to recording on an Android phone.
13. Cross-Border Data Transfers
Within YazBunu’s technical architecture, certain personal data may be processed through service providers located abroad or operated by companies abroad.
The principal operations that may give rise to cross-border transfers are:
- transcription,
- text structuring with artificial intelligence,
- authentication,
- cloud storage,
- server hosting,
- subscription management,
- e-mail sending,
- technical support and security services.
In Meeting Mode, CarPlay and Apple Watch recordings, and in all recordings made on Android phones, the audio file may be transferred temporarily to the server for transcription purposes. At the artificial intelligence text structuring stage no audio file is sent; only the transcript or the text selected by the user is processed.
Cross-border transfers are carried out in a manner that is:
- connected to the purpose,
- necessary,
- proportionate,
- limited to the least data possible.
Cross-border transfer processes are assessed within the framework of the applicable legislation and technical security conditions, according to the nature of the transfer and the location of the relevant service provider.
The use of AssemblyAI’s European region endpoint aims to ensure that the audio processing request is carried out through the European region. Nevertheless, a separate assessment may be made in respect of the provider’s corporate headquarters, sub-processors, support infrastructure and data retention practices.
14. Sharing of Personal Data
Personal data may be transferred only to the extent required by the relevant processing purpose to the following persons or organisations:
- authentication and cloud storage service providers,
- transcription and speech recognition service providers,
- artificial intelligence service providers,
- server hosting providers,
- subscription and in-app purchase services,
- e-mail and notification service providers,
- technical support, security and error detection service providers,
- legal, financial and technical advisers,
- competent public institutions and organisations,
- in the event of a dispute, judicial authorities and legally competent bodies,
- where corporate services are offered in the future, the authorised corporate units limited to the scope of the relevant service.
Where meeting results are shared by the user, the transcript, meeting summary, decisions, task list, e-mail draft and the personal data contained in that content may be transferred to the recipients determined by the user.
YazBunu does not automatically send meeting outputs or e-mail drafts to recipients unless the user expressly approves before sending.
Where the user’s own SMTP account is used, it is acknowledged that the e-mail content may also be processed by the relevant SMTP service provider. The user’s own account and service terms may also apply to that provider’s data processing practices.
15. Diagnostic Logs Kept on the Device
YazBunu may keep limited technical diagnostic logs on the device in order to understand recording and connection errors technically.
For the application recording pipeline:
- diag.log
For CarPlay and vehicle connection:
- carplay.log
These logs:
- do not leave the device by themselves,
- are not uploaded to the server,
- are not included in the cloud backup,
- are not sent in the background,
- are not transferred to Peracom unless the user separately shares them.
When the user wishes to share a log, masking is applied on the device; the masked version prepared for sharing is ensured not to contain:
- note text,
- transcript,
- meeting summary,
- participant name,
- audio file path,
- user identifier.
The total size of the diagnostic logs is limited to approximately 1.5 MB (up to 512 KB per log file). When the limit is reached, the oldest records are deleted. If the application is removed from the device, the logs are also deleted from the device.
If the user wishes to share the logs for technical support purposes:
- the log is masked on the device,
- the masked version is displayed on screen in full,
- separate approval is obtained for each act of sharing,
- the user chooses the application through which it will be sent.
No “do not ask again” option is offered for sharing diagnostic logs. If the user does not approve, the log does not leave the device.
16. Subscription and In-App Purchase Information
YazBunu’s subscription or in-app purchase features may be managed through the Apple App Store, Google Play and RevenueCat.
In this context the following may be processed:
- subscription status,
- purchase or renewal information,
- subscription type,
- in-app product identifier,
- transaction or store identifier,
- refund or cancellation status,
- subscription start and end information.
YazBunu does not take direct payment by credit card, digital wallet, bank transfer or FAST during an in-app purchase. Within the current product structure, sales and subscription transactions are carried out through the in-app purchase system of the store from which the application was downloaded (Apple App Store or Google Play).
Payment card details are not collected or stored directly by YazBunu. Payment transactions are carried out through the relevant application store’s own payment infrastructure.
Subscription and transaction records may be kept for a period limited to what is required by the relevant accounting, consumer, legal and technical obligations.
17. Personalisation and Usage Analysis
Where the user separately opts in, YazBunu may process the following in order to personalise the application experience and produce limited usage statistics:
- in-app preferences,
- enabled features,
- frequency of feature use,
- session and usage durations,
- the limited technical data required for device and application compatibility.
Personalisation and usage analysis are not a mandatory part of the basic local note-taking service. These activities are carried out according to a separate preference or permission flow within the application.
Within the scope of personalisation and usage analysis:
- audio files are not used for advertising purposes,
- no voiceprint is created,
- user content is not used to build advertising profiles,
- user content is not used to train artificial intelligence models outside the purpose of the service.
18. Special Categories of Personal Data
YazBunu is not designed to process special categories of personal data. Nevertheless, the audio, notes, transcripts, meeting summaries or e-mail drafts recorded by the user may contain:
- health information,
- religious or philosophical beliefs,
- political opinions,
- trade union or association membership,
- information relating to sexual life,
- information relating to criminal convictions and security measures,
- other data deemed to be special categories under the legislation.
Where the user includes such data in the content, it may enter the relevant technical processing flow. YazBunu does not aim to collect or classify such data for an independent purpose.
Users should not record special categories of personal data unless necessary; they should review such data before sharing a meeting, transcript, summary or e-mail and delete or mask it where required.
Stricter access, security, minimisation and retention measures are applied to special categories of personal data.
19. Children’s Data
YazBunu is not a service designed specifically for children.
Where it is understood that children’s personal data are present in the application, within the framework of the applicable legislation, application store rules and technical possibilities:
- the relevant feature may be restricted,
- data processing may be stopped,
- additional information or the approval of a legal representative may be requested,
- deletion of the data may be considered.
Where children’s personal data are present in a meeting or audio recording, the user must separately assess the obligations relating to informing the relevant persons and their legal representatives and obtaining the necessary permissions.
The principles of purpose limitation, data minimisation, proportionality and short retention periods apply to children’s data.
20. Data Security Measures
Peracom Yazılım Danışmanlık A.Ş. applies appropriate technical and administrative measures to prevent the unlawful processing of personal data and unauthorised access to, loss, alteration, disclosure or destruction of such data.
Depending on the technical structure of the service, these measures may include:
- encryption,
- end-to-end encryption,
- authentication,
- access control,
- the principle of least privilege,
- authorisation,
- security logs,
- error and access monitoring,
- software security testing,
- infrastructure security testing,
- backup security,
- sub-processor and service provider assessments,
- contractual confidentiality obligations,
- automatic deletion and destruction mechanisms,
- restriction of technical access.
When cloud backup is enabled, the note and transcript content selected by the user may be encrypted end to end. The decryption key is protected by the user.
In a structure designed so that Peracom Yazılım Danışmanlık A.Ş. cannot access the end-to-end encryption key, the company may be technically unable to read encrypted content stored in the cloud.
Temporary audio files on the server are kept for a period limited to what is necessary for transcription and are deleted within 24 hours at the latest.
On-device diagnostic logs are not sent to the server unless expressly shared by the user.
No electronic system provides an absolute guarantee of security. Users must protect their own devices, account details, access codes, encryption passwords and recovery information.
21. Retention and Deletion Periods
Personal data are retained for the period required by the processing purpose and within the framework of the applicable legal obligations.
| Type of data or record | Retention period and deletion method |
|---|---|
| Temporary audio file on the server | Kept temporarily for transcription purposes. Deleted once processing is complete and in any event within a maximum of 24 hours from the date of upload. The clean-up job runs hourly. |
| m4a audio file on the device | Depends on the user’s device and application use. May be deleted from the device by the user. Not included in the cloud backup. |
| Note text and transcript | Kept according to the user’s local storage and end-to-end encrypted cloud backup preferences. Placed in the deletion process when deleted by the user or when the retention purpose ends. |
| Meeting summary, decisions and tasks | Kept on the user’s device or in the end-to-end encrypted backup chosen by the user. Placed in the deletion process when deleted by the user or when the retention purpose ends. |
| E-mail drafts | May be kept on the relevant device or within the selected backup until sent, edited or deleted by the user. |
| Error and crash records | Kept for a maximum of 90 days and deleted automatically. |
| Support and feedback records together with attached screenshots | Kept for a maximum of 90 days and deleted automatically. |
| On-device diagnostic logs | Kept on the device within a limit of approximately 1.5 MB. When the limit is reached, the oldest records are deleted. The logs are deleted when the application is removed. |
| Subscription and transaction records | Kept for a period limited to what is required by the Apple App Store, Google Play, RevenueCat and the relevant accounting, consumer or legal obligations. |
| Account and contact data | Kept while the account is active and, after the account is deleted, for a period limited to what is necessary for the applicable legal obligations and the management of disputes. |
| E-mail sending records | Kept for a period limited to what is necessary in terms of sending, security, support and legal requirements. |
For temporary audio files on the server, 24 hours is an absolute upper limit. The hourly clean-up mechanism is designed to prevent this period from being exceeded.
Where the retention period expires or the processing purpose ceases to exist, personal data are deleted, destroyed or anonymised.
Where there is a statutory retention obligation, an ongoing dispute or a need for legal defence, certain data may be kept only for the necessary period and with restricted access.
22. Account Deletion and Data Deletion
The user may give an instruction for immediate deletion through the account deletion function within the application.
Within the scope of account deletion, and within the framework of the applicable technical structure and legal obligations, the following may be placed in the deletion process:
- the user account,
- user information linked to the account,
- end-to-end encrypted cloud backups,
- synchronisation records,
- appropriate text content created by the user.
Deletion of m4a audio files present on the device may be carried out through the device operating system or the in-app deletion function, separately from the account deletion process within the application.
Subscription and transaction records kept by the Apple App Store, Google Play or RevenueCat may be outside Peracom’s direct control and may be kept for as long as the relevant legal, accounting or consumer obligations continue.
Where there is an ongoing dispute, legal claim or statutory retention obligation, certain records may not be deleted immediately. In that case the data are kept only for the relevant purpose and for the necessary period.
23. Rights of the User
Under the applicable personal data protection legislation, data subjects may have the right to:
- learn whether their personal data are processed,
- request information if their personal data have been processed,
- learn the purpose of processing of personal data,
- learn whether personal data are used in accordance with their purpose,
- know the third parties to whom personal data are transferred,
- request the correction of personal data that have been processed incompletely or incorrectly,
- request the erasure or destruction of personal data where the legal conditions are met,
- request that correction, erasure or destruction operations be notified to third parties to whom the data have been transferred,
- object to an adverse outcome arising from analysis carried out exclusively by automated systems,
- claim compensation for damage arising from unlawful processing.
Users may also, from within the application or through the support channel:
- delete their accounts,
- delete their local content,
- turn off cloud backup and synchronisation,
- change their separate consent preferences,
- withdraw their explicit consent,
- refuse to share technical logs.
24. Application Procedure
Requests relating to the processing of personal data may be submitted through the following channels:
- E-mail: destek@peracom.net
- In-app support or application form,
- An application made from the e-mail address registered in our system,
- Other methods suitable for identity verification.
The application must state:
- which right is being exercised,
- the request in clear and comprehensible terms,
- information enabling identity verification,
- as much explanation as possible about the data or transaction concerned.
Applications are assessed within the procedures and time limits set out in the applicable legislation. Additional information may be requested for security and identity verification purposes.
25. The User’s Privacy and Security Responsibilities
The user must:
- keep account details confidential,
- ensure the security of their device,
- protect the end-to-end encryption password and recovery information,
- inform meeting participants about the recording,
- obtain permission or explicit consent where necessary,
- review user content before sharing it,
- delete or mask unnecessary personal data,
- avoid recording special categories of personal data as far as possible,
- check e-mail recipients and the content to be sent,
- not use the application for unlawful purposes,
- not infringe the private life, personal data or other rights of third parties.
Third parties who gain access to the user’s device may be able to access the m4a audio files, notes or transcripts stored locally on the device. For this reason, the device lock, operating system security and application access security must be ensured by the user.
26. Cookies and Similar Technologies
YazBunu’s current service is offered through the iOS and Android mobile application. Classic cookies specific to a website may not be used within the application.
In the services offered through YazBunu’s website (yazbunu.com.tr), Google Analytics, Meta Pixel cookies and similar technologies may be used to improve the user experience, analyse website traffic and carry out marketing activities. These cookies are activated only subject to the consent you give through the cookie banner on the website; unless consent is given, analytics and marketing cookies are not activated.
Nevertheless, on-device identifiers, session information or similar technical technologies may be used for the technical operation of the application, session management, authentication, determination of subscription status, security, error detection or monitoring of application performance.
This technical data may be used only for the purposes of:
- operating the application,
- account security,
- protecting the session,
- verifying subscription status,
- error and crash detection,
- preventing security breaches.
Non-mandatory activities such as usage analysis or personalisation may be subject to separate preference or permission mechanisms within the application.
YazBunu does not use user content or audio recordings to build advertising profiles.
27. Privacy Practices of Third-Party Services
The third-party service providers used by YazBunu may have their own privacy policies, terms of use and data processing practices.
The user should take the following into account:
- Apple’s own rules may apply in respect of Apple services,
- Apple’s or Google’s payment and subscription infrastructure may be used in respect of application store transactions,
- where the user’s own SMTP account is used, the rules of the relevant e-mail provider may apply,
- artificial intelligence and transcription services may involve the technical configurations and sub-processors of the relevant providers,
- the inclusion of third-party providers in the list does not mean that all data is transferred to every provider.
When selecting third-party services, Peracom aims to take into account criteria such as the purpose of the service, security, data minimisation, access limits, retention periods and technical competence.
28. Privacy Breaches and Security Incidents
Where it is understood that personal data may have been affected by unauthorised access, loss, disclosure, alteration or another security incident, Peracom operates technical and administrative processes to assess the nature and impact of the incident.
Where deemed necessary:
- the source of the incident may be investigated,
- the affected systems or accounts may be restricted,
- access credentials may be renewed,
- temporary service restrictions may be applied,
- data subjects or competent authorities may be informed within the framework of the applicable legislation.
Users must immediately report suspicious account activity, the possibility of unauthorised access or a security vulnerability to destek@peracom.net.
29. Changes to the Policy
This Privacy Policy may be updated in the event of:
- a change in the technical infrastructure,
- the addition of a new feature,
- the use of a new service provider,
- a change in the purposes of data processing,
- an update to retention periods,
- a change in the applicable legislation.
The current text is published within the application or through the official communication channels relating to YazBunu.
Where a change has significant consequences for the processing of personal data, the user may be notified by in-app notification, e-mail or another appropriate method. Depending on the nature of the change, a new information notice or new explicit consent may be required.
The user is not obliged to review the current Policy regularly; however, the user should take into account the important updates displayed within the application before continuing to use the service.
30. Effective Date and Last Update
This Privacy Policy enters into force on the effective date stated below.
Effective Date: 9 September 2026
Last Updated: 9 September 2026
Data Controller: Peracom Yazılım Danışmanlık A.Ş.
Address: Gülbahar Mahallesi, Avni Dilligil Sokak, Çelik İş Blokları A Blok, No: 11 Floor: 4 Office: 417, Şişli / İstanbul, Türkiye
E-mail: destek@peracom.net
Telephone: +90 212 243 10 80