Privacy Policy
This page explains, in plain language, what data yazar.io collects when you use the product, how it's used, and what rights you have. For details specific to Turkish personal data law, see the KVKK Notice.
Last updated:
Identity and contact details of the data controller
The operator of yazar.io and the data controller under this Privacy Policy is BY AGENCY LLC, a company established in Wyoming, United States.
For privacy questions, you can reach us at support@yazar.io. Our formal business address is 30 N Gould St, STE 22815, Sheridan, WY 82801, United States.
What personal data is collected
What we collect depends on which features you use. The categories below reflect the app's actual behavior as of the date this document was published.
Account data
When you sign up, we collect your full name and email address, and, if you register with email/password, a password (never readable by us; it is securely handled by our authentication provider, Supabase).
Tied to your account, we also store: your public username (chosen when you set up your Author Card), and your language preference (Turkish/English). Your theme preference is stored only in your browser (see below).
Data from our authentication provider
If you choose to sign in with Google, your Google account's email address and (if shared) your name are passed to us via our authentication provider, Supabase Auth. We never access any other Google data (contacts, files, calendar, etc.).
Your authenticated session is kept using a session cookie managed by Supabase - see the Cookie Policy for details.
Content you create
This is what yazar.io is for: your books, characters, locations, organizations, lore, family tree, notes, and timeline entries. This content is visible only to you; it's protected at the database level (Row Level Security) so that only its owner can access it.
Copyright and ownership of this content remains entirely yours - see the Content and Intellectual Property Policy for details.
Uploaded images
Images you upload (book covers, character/location images, your profile photo, Author Card images) are stored in a single storage bucket (Supabase Storage).
Every image you upload is resized and converted to WebP on our server; your original file is never kept, and metadata such as EXIF/location data is deliberately stripped. Files are saved under a randomly generated name that carries no personal information from your original filename.
Technical logs
Our infrastructure providers (Vercel, Supabase) keep standard server/access logs (IP address, browser information, request timing) as part of running and securing the service. The yazar.io codebase does not run a separate, custom activity-logging system beyond this.
Locale and theme preferences
Your interface language preference (Turkish/English) is stored in a cookie and, if you're signed in, tied to your account.
Your light/dark theme preference is stored only in your browser's local storage; it is never sent to us or associated with your account.
Analytics data
We use PostHog (a product analytics service hosted in the European Union) to understand how to improve the product. Unlike most analytics setups, this is deliberately narrow:
- Autocapture (automatic click tracking), session recording, and heatmaps are all DISABLED - none of them are active anywhere in the codebase.
- Page views are sent only manually and in a restricted form: which page you visited (any URL portion that carries personal content, such as a book/character/location, is reduced to a fixed template rather than the real name or ID - e.g. "a book page" instead of the book's actual title) and which broad area of the site you're in (marketing, panel, public page, etc.). Query parameters in the address bar (e.g. sign-in/verification tokens) are NEVER sent.
- Only a specific, explicitly defined set of product events is sent: sign-up, login, creating/updating/deleting a book or entity, creating a relationship, opening the search box, exporting a book, updating your Author Card, and similar. These events carry only structural information (e.g. "a character was created") - no creative/fictional content such as a character's name, a book's title, or note text is EVER sent to analytics.
- When you first arrive at our site, only if you've consented to analytics, we record a limited one-time "first-touch" record to understand where our traffic comes from: campaign parameters if present (utm_source/utm_medium/utm_campaign), the name of the site that referred you (domain only, not the full address), and the first page you opened. This is stored in a first-party cookie (yzr_attr) for 30 days, captured only once, and never overwritten (see the Cookie Policy).
- To identify you in the analytics system, we use only your account ID (a randomly generated user number) and your account creation date - your email address, name, or any other personal information is never sent to the analytics provider.
- You can withdraw analytics consent at any time; doing so clears both PostHog's data in your browser and the "first-touch" cookie.
Communication preferences
At sign-up, you can optionally check a separate box to receive news and updates about yazar.io. This preference is NOT a condition of creating an account. See the Communication Preferences page for details.
Onboarding introduction preferences
On your first login, you may see a short, entirely optional 5-question introduction survey (how you heard about yazar.io, what you write most, how you'd describe yourself, which country you live in, and what you want to do first on the platform). None of these questions are required; you can click "Skip" without answering any of them.
Your answers are only saved if you give your EXPLICIT CONSENT via a separate, unchecked-by-default checkbox - if you click "Finish" without checking it, none of your answers are written to our database. We only use these answers to understand our user base and improve yazar.io around what writers actually need - they are NOT used to send automated marketing messages. This survey never collects sensitive or special-category data such as your birth date, age, gender, phone number, full address, profession, income, or health information; your location is never detected automatically from your IP address, only the country you choose yourself is stored.
You can view, update, delete, or withdraw your consent for your answers at any time from the "Let's Get to Know You" section on the Settings page. Withdrawing consent never affects your ability to use the rest of yazar.io, and it does not automatically reopen the onboarding survey - if you skipped it or withdrew consent, you can voluntarily fill it in again and give new consent from the same section whenever you like.
Live chat support
Our homepage includes a live chat support tool (Crisp), but it does not load automatically when the page opens - it only loads and activates when you deliberately click the "Message us" button in the bottom-right corner.
When you start a chat, the messages you write and (if you share them) any contact details you give us are passed to us through Crisp's infrastructure, for the purpose of delivering your messages and running the chat session. We (the yazar.io team) reply to chats directly - no automated AI chatbot is used.
Starting a chat may also involve processing technical connection/session information (e.g. IP address, browser information) between your browser and Crisp's servers - this is a technical necessity for the service to work.
If you'd rather not use Crisp at all, you can simply not click the "Message us" button, and reach us directly at support@yazar.io instead.
Purposes of processing
- Creating your account, verifying your identity, and keeping your session secure
- Storing, displaying, and letting you edit your books, characters, and other content
- Serving your public Author Card, if you publish one
- Optimizing and hosting the images you upload
- Improving the product by understanding which features are actually used (analytics)
- Understanding our user base and improving yazar.io by considering your optional onboarding introduction preferences
- Sending news and updates, if you've opted in
- Delivering and replying to your messages when you start a live chat
- Keeping the service secure and preventing abuse
Third-party service providers we use
We rely on the following providers to run yazar.io. None of them use your data for their own marketing purposes; each processes data on our behalf, for a specific service.
- Supabase - database, authentication, and image storage infrastructure. Our project is hosted in the European Union (Frankfurt, Germany).
- Vercel - the server infrastructure that hosts the application.
- PostHog - the narrow-scope product analytics described above, hosted in the EU region.
- Google - only if you choose the "Continue with Google" sign-in option, for authentication purposes.
- Crisp - the live chat support described above, only activated if you click the "Message us" button.
Data retention periods
Your account and content data are kept for as long as your account is active. When you "remove a book from your library," it is not deleted immediately - it is marked with a reversible flag (soft delete); you can restore it yourself, or permanently delete it with email verification, from the Deleted Books page for at least 30 days. Security-focused email notices are sent both when a book is removed and before it is permanently deleted (see the Data Deletion and Account Closure Notice).
Notes have no such time limit: you can permanently delete or restore them yourself, at any time.
When you delete your account, your associated data is permanently deleted within a reasonable period; some records may be kept beyond that period where required by our legal obligations.
Our approach to data security
Your content is protected at the database level with row-level security - meaning even a query bug cannot expose another user's data, because the database itself enforces the boundary.
Uploaded images are validated server-side by their actual file signature (only genuine image files are accepted), size-limited, and you can only write to or list your own folder.
Elevated credentials capable of bypassing these security boundaries (such as a service-role key) are not used in any application query.
No system is completely immune to breaches or errors; we cannot promise absolute security, but we apply and continue to improve the measures above.
Your rights
For users residing in Turkey, these rights arise under Law No. 6698 on the Protection of Personal Data - see the KVKK Notice for the full list. In summary, you have the right to learn whether your data is processed, request information about it, request correction if it's inaccurate or incomplete, and request deletion where legal conditions are met.
To exercise these rights, contact us at support@yazar.io.
Data deletion and account closure process
For the full, current description of this process, see our separate Data Deletion and Account Closure Notice. In short: you can delete your own account from the Settings page with email confirmation, or contact our support team if you prefer.
Changes to this policy
We may update this policy from time to time. For material changes, we update the "Last updated" date at the top of this page, and we try to announce changes we consider significant through an in-account notice or email.
Contact
For questions about this policy: support@yazar.io