Privacy Policy

This English text is for information only. In case of discrepancy, the Turkish version prevails.

At gerekli.tr, we respect your privacy and are committed to protecting your personal data. This policy explains how your data is collected, used, and safeguarded when you use our platform. For detailed disclosure under the Personal Data Protection Law (KVKK) No. 6698, see our Privacy Notice (KVKK).

1. Data Categories

gerekli.tr may process the following categories of data:

  • Authentication and contact data: Supabase Auth user identifier (UUID), email address, full name, and session information
  • Profile information: Department (required for Cloud Sync); optional, unverified Hacettepe institutional email (@hacettepe.edu.tr) stored for possible future university-specific features (currently grants no access or privileges)
  • Academic History data: User-approved transcript/course-attempt records, grades, ECTS, and term GPAs. In the current public product, this data stays in browser local storage; the separate Academic History cloud-sync capability is not enabled
  • gerekli.tr cloud/app data: Selected courses, schedule templates, GPA calculations, and preserved semester/attendance records; a Supabase copy of supported planning data after sign-in and required department setup, when Cloud Sync becomes ready
  • Share link data: Course schedule content created through the sharing feature
  • Preference data: Theme (light/dark), language selection, display settings, cookie preferences
  • Technical data: Session cookies, IP address (for authentication and service security)
  • Consent and acknowledgement records: KVKK notice acknowledgement record, terms of use acceptance, and cookie preference timestamps
  • Consented usage measurements: course code, section, academic year/term, department, and timestamp for direct course add/remove actions, using pseudonymous user/session references without names, email, or device identifiers

Academic catalogue data: Course code, course name, schedule, classroom, section, and instructor name/surname may be collected from university-published academic catalogues. Because instructor information may identify real persons, it is displayed only in a limited and proportionate way for schedule planning, viewing, sharing, and export.

2. localStorage Transparency

gerekli.tr uses your browser's localStorage to provide full functionality even before you create an account. Before Cloud Sync is ready, this data is stored only on your device and is not automatically sent to our servers.

localStorage keys in use:

  • gerekli.schedule.v2 — Course schedules, GPA rows, active plan ID, theme and language preferences, catalog department preference, and preserved lifecycle state
  • gerekli.semester.v1 — Preserved semester configuration and attendance entries; active attendance tracking is not currently offered in the public product
  • gerekli.semesterArchive.v1 — Completed-term archive snapshots on this device
  • gerekli.academicHistory.v1 — User-approved academic history snapshot (course attempts, ECTS, term GPAs). Raw PDF/clipboard content and identity fields are not stored
  • gerekli.deviceOwnerUserId.v1 — Device-owner marker (guest or account id) to prevent cross-account merge of leftover drafts
  • gerekli.consent.v1 — Your cookie and analytics preferences
  • gerekli.profile_prompt_dismissed_at.{userId} — Profile completion prompt dismiss timestamp (per account)
  • gerekli.analytics.app_active.v1 — Local-only analytics dedup markers (not uploaded)

Related cookies: gerekli.dept (department preference hint), gerekli_consent (consent mirror), theme, NEXT_LOCALE.

After you sign in and choose a department in your profile, Cloud Sync becomes ready automatically. It first loads the current cloud data; after that succeeds, changes to course plans and GPA calculator rows are synced automatically over an encrypted connection. Preserved semester/attendance records may use the same sync path for compatibility. A local copy remains in this browser for offline use. The separate Academic History cloud-sync capability is currently disabled in the public product, so transcript and Academic History records stay only in this browser and do not join Cloud Sync. On Account → Local data on this device you can export/import a backup or clear local planner data only. Clearing local planner data while signed in is not permanent cloud deletion — cloud data may download again after you explicitly sync. Local deletion and deletion of gerekli.tr cloud/app data are separate actions.

The current public product focuses on course planning, GPA, the academic calendar, transcript tools, and schedule sharing. Attendance tracking and semester-lifecycle transitions are currently dormant. Related local or cloud fields may remain for historical compatibility and are not presented as active public tools.

Product analytics (with consent): guests stay anonymous in PostHog; after sign-in we attach a pseudonymous account identifier (Supabase user id) without email or name. Sign-out resets that analytics identity. Share capability URLs (/p/…) are redacted before analytics/error reporting; guest share snapshots are stored on the server only when you create a share link.

Course usage measurements use a separate Supabase flow only while you have granted analytics consent, and only for real add/remove actions in the planner. We store catalog dimensions (course id/code, section, department, academic year/term, and server time); user/session and plan references are pseudonymized in the database. Hydration, restore, import, and React lifecycle activity do not create records.

3. Third-Party Tools

We use the following third-party services to deliver our service:

  • Supabase (determined by project configuration): Authentication, PostgreSQL database, and supported planner/GPA cloud synchronization
  • Google OAuth (USA): Optional "Sign in with Google" — email, name, profile photo. Google's privacy policy applies.
  • PostHog (EU): Product analytics with your consent; session replay is disabled in the current public product (eu.i.posthog.com)
  • Google Analytics 4: Page view and basic traffic measurement with your analytics consent; Google Signals and advertising personalization signals are disabled
  • Sentry (Germany / DE): Server error logs (legitimate interest); client error reporting (with performance preference)
  • Vercel: Website hosting, secure delivery, and service availability
  • Vercel Analytics / Speed Insights: Traffic and performance measurement only where the relevant analytics/performance preference allows it

Fonts (Inter, Poppins, Outfit) are self-hosted at build time; no requests are sent to Google Fonts or similar external font servers during visits.

Each of these tools is used only for the stated purposes and in line with the data minimization principle. Your data is not shared with third parties for advertising or marketing purposes.

4. Share Links

When you share your course schedule, the content is temporarily stored on our servers and becomes accessible via a public URL. You create and share the link; anyone with the URL can access the content. You do not need to sign in to use this feature. Share links expire at academic term end + 60 days, or 180 days after creation when academic calendar data is unavailable, unless deleted earlier. You are responsible for the confidentiality of link content.

Shared or exported schedules may show instructor names in full (share links, QR, ICS calendar, PDF detail table). Schedule image exports may show only the instructor's surname. Consider carefully what you share.

5. Children's Privacy

The platform is primarily intended for university students. If you are under 18, you must use the service with your legal guardian's consent.

Parents or legal guardians who identify an account belonging to a child may contact us at hacettepeliyegerekli@gmail.com.

6. Data Security

We take the following measures to protect your data:

  • All data transfers are protected with TLS/HTTPS encryption
  • Supabase Row Level Security (RLS) ensures users can access only their own data
  • Passwords and session management are handled by Supabase Auth; plaintext passwords are not stored
  • Database access is restricted to authorized service accounts only
  • Regular security updates and dependency audits are performed

While no system is 100% secure, we follow industry-standard security practices and commit to notifying affected users as quickly as possible in the event of a breach.

7. Retention Periods

Summary retention periods:

  • gerekli.tr cloud/app data: Course plans, semester/attendance and GPA data, profile, share links owned by the account, and account-linked course-usage records are deleted when the data deletion action completes successfully. Academic History is currently kept in browser local storage, not in this cloud data category
  • Authentication identity (Supabase Auth): Not deleted by the in-app data deletion action
  • PostHog: 90 days
  • Sentry error records: 90 days
  • Share links: academic term end + 60 days (180 days when calendar data is unavailable)
  • Consent records: at least 10 years with a pseudonymous reference for legal proof

When deletion of gerekli.tr cloud/app data completes, course plans, semester/attendance data, GPA, profile data, share links owned by that account, and account-linked course-usage records are deleted. Academic History is currently local, and its copy on this device is cleared as part of the same action. If a previously created Academic History cloud copy is present, the same deletion action removes it. Cookie/analytics preferences and browser data outside this scope remain. The Supabase authentication identity and Google account are not deleted by this action.

Consent records kept for legal proof may have the direct user id removed while retaining a pseudonymous reference, document version, and timestamp for a limited period. These records are not anonymous; they are pseudonymous records kept for legal proof. Existing external analytics, platform telemetry, and error records are also not retroactively deleted by this action; system and provider retention periods apply.

Consented course-usage records use pseudonymous user and plan references; records belonging to an account are deleted when gerekli.tr cloud/app data is deleted. Only aggregate groups with at least 10 distinct users/sessions are exposed as insights. Withdrawing analytics consent stops new records.

Withdrawal of analytics consent applies going forward. Anonymous aggregate results that already passed the small-group thresholds before withdrawal may remain because they cannot be separated back into individual contributions.

For detailed periods, see Section 7 of the Privacy Notice (KVKK).

8. Your Rights

For all rights under the Personal Data Protection Law (KVKK) No. 6698 (access, rectification, erasure, objection, etc.), see our Privacy Notice (KVKK) and Data Subject Application (KVKK) pages.

Actions you can take in the app:

  • View and edit your profile information (My Account page)
  • Delete gerekli.tr cloud/app data (My Account → Permanently Delete gerekli.tr Data)
  • Clear local planner data on this device (in-app option or browser settings)
  • Change cookie preferences (Cookie Preferences link in the page footer)

Deletion of the Supabase authentication identity is not included in the in-app data deletion action; use the instructions on the Data Subject Application (KVKK) page to request it.

9. Policy Changes

We may update this privacy policy from time to time. When significant changes are made, we will display a notification in the app. The effective date of the current policy is shown at the bottom of the page.

For questions about policy changes, contact hacettepeliyegerekli@gmail.com.

Related documents: Privacy Notice (KVKK) · Cookie Policy · Terms of Use