Privacy Policy

This English text is for information only. In case of discrepancy, the Turkish version prevails.

At gerekli.tr, we respect your privacy and are committed to protecting your personal data. This policy explains how your data is collected, used, and safeguarded when you use our platform. For detailed disclosure under the Personal Data Protection Law (KVKK) No. 6698, see our Privacy Notice (KVKK).

1. Data Categories

gerekli.tr may process the following categories of data:

  • Account information: Email address, full name, user identifier
  • Profile information (optional): Department; optional, unverified Hacettepe institutional email (@hacettepe.edu.tr) stored for possible future university-specific features (currently grants no access or privileges)
  • Academic planning data: Selected courses, schedule templates, GPA calculations, attendance records
  • Share link data: Course schedule content created through the sharing feature
  • Preference data: Theme (light/dark), language selection, display settings, cookie preferences
  • Technical data: Session cookies, IP address (for authentication and service security)
  • Consent and acknowledgement records: KVKK notice acknowledgement record, terms of use acceptance, and cookie preference timestamps

Academic catalogue data: Course code, course name, schedule, classroom, section, and instructor name/surname may be collected from university-published academic catalogues. Because instructor information may identify real persons, it is displayed only in a limited and proportionate way for schedule planning, viewing, sharing, and export.

2. localStorage Transparency

gerekli.tr uses your browser's localStorage to provide full functionality even before you create an account. This data is stored only on your device and is not automatically sent to our servers.

localStorage keys in use:

  • gerekli.schedule.v2 — Course schedules, GPA rows, active plan ID, theme and language preferences, application phase (planning / active semester), catalog department preference
  • gerekli.semester.v1 — Locked semester configuration and attendance entries
  • gerekli.semesterArchive.v1 — Completed-term archive snapshots on this device
  • gerekli.academicHistory.v1 — User-approved academic history snapshot (course attempts, ECTS, term GPAs). Raw PDF/clipboard content and identity fields are not stored
  • gerekli.deviceOwnerUserId.v1 — Device-owner marker (guest or account id) to prevent cross-account merge of leftover drafts
  • gerekli.consent.v1 — Your cookie and analytics preferences
  • gerekli.profile_prompt_dismissed_at.{userId} — Profile completion prompt dismiss timestamp (per account)
  • gerekli.analytics.app_active.v1 — Local-only analytics dedup markers (not uploaded)

Related cookies: gerekli.dept (department preference hint), gerekli_consent (consent mirror), theme, NEXT_LOCALE.

When you enable cloud synchronization (by signing in), your planning data is copied to the Supabase database over an encrypted connection. This includes course plans, semester/attendance records, and GPA calculator rows. On Account → Data on this device you can export/import a backup, clear planner and attendance data on this device only, or open cookie preferences. Clearing local planner data while signed in removes the copy on this browser; it is not permanent cloud deletion — cloud data may download again after you explicitly sync. Permanent deletion remains a separate cloud-account action.

Product analytics (with consent): guests stay anonymous in PostHog; after sign-in we attach a pseudonymous account identifier (Supabase user id) without email or name. Sign-out resets that analytics identity. Share capability URLs (/p/…) are redacted before analytics/error reporting; guest share snapshots are stored on the server only when you create a share link.

3. Third-Party Tools

We use the following third-party services to deliver our service:

  • Supabase (determined by project configuration): Authentication, PostgreSQL database, and cloud synchronization
  • Google OAuth (USA): Optional "Sign in with Google" — email, name, profile photo. Google's privacy policy applies.
  • PostHog (EU): Product analytics with your consent; session recording, if enabled, is sampled only (eu.i.posthog.com)
  • Sentry (Germany / DE): Server error logs (legitimate interest); client error reporting (with performance preference)
  • Vercel: Website hosting, secure delivery, and service availability
  • Vercel Analytics / Speed Insights: Traffic and performance measurement only where the relevant analytics/performance preference allows it

Fonts (Inter, Poppins, Outfit) are self-hosted at build time; no requests are sent to Google Fonts or similar external font servers during visits.

Each of these tools is used only for the stated purposes and in line with the data minimization principle. Your data is not shared with third parties for advertising or marketing purposes.

4. Share Links

When you share your course schedule, the content is temporarily stored on our servers and becomes accessible via a public URL. You create and share the link; anyone with the URL can access the content. You do not need to sign in to use this feature. Share links expire at academic term end + 60 days, or 180 days after creation when academic calendar data is unavailable, unless deleted earlier. You are responsible for the confidentiality of link content.

Shared or exported schedules may show instructor names in full (share links, QR, ICS calendar, PDF detail table). Schedule image exports may show only the instructor's surname. Consider carefully what you share.

5. Children's Privacy

The platform is primarily intended for university students. If you are under 18, you must use the service with your legal guardian's consent.

Parents or legal guardians who identify an account belonging to a child may contact us at destek@gerekli.tr.

6. Data Security

We take the following measures to protect your data:

  • All data transfers are protected with TLS/HTTPS encryption
  • Supabase Row Level Security (RLS) ensures users can access only their own data
  • Passwords and session management are handled by Supabase Auth; plaintext passwords are not stored
  • Database access is restricted to authorized service accounts only
  • Regular security updates and dependency audits are performed

While no system is 100% secure, we follow industry-standard security practices and commit to notifying affected users as quickly as possible in the event of a breach.

7. Retention Periods

Summary retention periods:

  • Account data: 30 days from deletion request
  • PostHog: 90 days
  • Sentry error records: 90 days
  • Share links: academic term end + 60 days (180 days when calendar data is unavailable)
  • Consent records: at least 10 years with a pseudonymous reference for legal proof

When you delete your account or cloud data, your academic planning data is deleted. Consent records kept for legal proof may have the direct user id removed while retaining a pseudonymous reference, document version, and timestamp for a limited period.

Withdrawal of analytics consent applies going forward. Anonymous aggregate results that already passed the small-group thresholds before withdrawal may remain because they cannot be separated back into individual contributions.

For detailed periods, see Section 7 of the Privacy Notice (KVKK).

8. Your Rights

For all rights under the Personal Data Protection Law (KVKK) No. 6698 (access, rectification, erasure, objection, etc.), see our Privacy Notice (KVKK) and Data Subject Application (KVKK) pages.

Actions you can take in the app:

  • View and edit your profile information (My Account page)
  • Delete your cloud data (My Account → Delete Cloud Data)
  • Clear local data (browser settings or in-app options)
  • Change cookie preferences (Cookie Preferences link in the page footer)
  • Permanently delete your account and all associated data

9. Policy Changes

We may update this privacy policy from time to time. When significant changes are made, we will display a notification in the app. The effective date of the current policy is shown at the bottom of the page.

For questions about policy changes, contact destek@gerekli.tr.

Related documents: Privacy Notice (KVKK) · Cookie Policy · Terms of Use