Privacy Policy
This page explains, in plain language, what data yazar.io collects when you use the product, how it's used, and what rights you have. For details specific to Turkish personal data law, see the KVKK Notice.
Last updated:
Identity and contact details of the data controller
The operator of yazar.io and the data controller under this Privacy Policy is Mehmet Sait Adıbelli, a sole proprietorship based in Turkey.
For privacy questions, you can reach us at support@yazar.io. Business location: Narlıdere, İzmir, Türkiye. Tax identification number: 0070668716.
What personal data is collected
What we collect depends on which features you use. The categories below reflect the app's actual behavior as of the date this document was published.
Account data
When you sign up, we collect your full name and email address, and, if you register with email/password, a password (never readable by us; it is securely handled by our authentication provider, Supabase).
Tied to your account, we also store: your public username (chosen when you set up your Author Card), and your language preference (Turkish/English). Your theme preference is stored only in your browser (see below).
Data from our authentication provider
If you choose to sign in with Google, your Google account's email address and (if shared) your name are passed to us via our authentication provider, Supabase Auth. We never access any other Google data (contacts, files, calendar, etc.).
Your authenticated session is kept using a session cookie managed by Supabase - see the Cookie Policy for details.
Content you create
This is what yazar.io is for: your books, characters, locations, organizations, lore, family tree, notes, and timeline entries. By default, this content is visible only to you; it's protected at the database level (Row Level Security) so that only its owner can access it. The one exception is the Shareable Wiki you can turn on yourself, per book, in Book Settings - once you do, that book's Characters, Locations, Organizations, Lore, and similar sections become a public, read-only page; your Notes are never included, under any circumstances. See the Content and Intellectual Property Policy for details.
Descriptions of your entities (characters, locations, organizations, and similar), your notes, and your custom field values are also stored encrypted in the database - see "Our approach to data security" below for details.
Copyright and ownership of this content remains entirely yours - see the Content and Intellectual Property Policy for details.
Uploaded images
Images you upload (book covers, character/location images, your profile photo, Author Card images) are stored in a single storage bucket (Supabase Storage).
Every image you upload is resized and converted to WebP on our server; your original file is never kept, and metadata such as EXIF/location data is deliberately stripped. Files are saved under a randomly generated name that carries no personal information from your original filename.
Technical logs
Our infrastructure providers (Vercel, Supabase) keep standard server/access logs (IP address, browser information, request timing) as part of running and securing the service. The yazar.io codebase does not run a separate, custom activity-logging system beyond this.
Account and security emails
We send some account-related notices (other than sign-up/sign-in verification, e.g. a notice that your password was changed, confirmation and completion of an account deletion request, security notices when a book is removed or about to be permanently deleted, and messages you send us through the in-app feedback form) through our email delivery provider, Resend. Sign-up email verification, password reset, and email-address change verification go through our authentication provider Supabase Auth's own email infrastructure instead (see above) - these are two separate systems.
Depending on the message, these emails may include your email address, your name/display name, the subject and body of the email (e.g. the title of a removed book, account/book security links), and - only if you use the feedback form - the free text you write yourself. These are NOT marketing emails - they are required account/security notices; see the Communication Preferences page for details.
Locale and theme preferences
Your interface language preference (Turkish/English) is stored in a cookie and, if you're signed in, tied to your account.
Your light/dark theme preference is stored only in your browser's local storage; it is never sent to us or associated with your account.
Analytics data
We use PostHog (a product analytics service hosted in the European Union) to understand how to improve the product. Unlike most analytics setups, this is deliberately narrow:
- Autocapture (automatic click tracking), session recording, and heatmaps are all DISABLED - none of them are active anywhere in the codebase.
- Page views are sent only manually and in a restricted form: which page you visited (any URL portion that carries personal content, such as a book/character/location, is reduced to a fixed template rather than the real name or ID - e.g. "a book page" instead of the book's actual title) and which broad area of the site you're in (marketing, panel, public page, etc.). Query parameters in the address bar (e.g. sign-in/verification tokens) are NEVER sent.
- Only a specific, explicitly defined set of product events is sent: sign-up, login, creating/updating/deleting a book or entity, creating a relationship, opening the search box, exporting a book, updating your Author Card, and similar. These events carry only structural information (e.g. "a character was created") - no creative/fictional content such as a character's name, a book's title, or note text is EVER sent to analytics.
- When you first arrive at our site, only if you've consented to analytics, we record a limited one-time "first-touch" record to understand where our traffic comes from: campaign parameters if present (utm_source/utm_medium/utm_campaign), the name of the site that referred you (domain only, not the full address), and the first page you opened. This is stored in a first-party cookie (yzr_attr) for 30 days, captured only once, and never overwritten (see the Cookie Policy).
- To identify you in the analytics system, we use only your account ID (a randomly generated user number) and your account creation date - your email address, name, or any other personal information is never sent to the analytics provider.
- In addition to PostHog, we also use Google Analytics (GA4) for the same purpose, under the SAME cookie consent - there is no separate consent category, and Google Analytics never loads unless you approve Analytics. No creative/fictional content is sent to Google Analytics either - only standard, anonymous visit/page-view statistics are collected.
- You can withdraw analytics consent at any time; doing so clears both PostHog's data in your browser and the "first-touch" cookie, and stops new data being sent to both PostHog and Google Analytics.
Error tracking
We use Sentry (an error-tracking service) to detect and fix technical errors in the application. This is DIFFERENT from the product analytics above - because it tracks technical errors rather than user behavior, it is not gated by the Analytics consent in the cookie banner, and it can trigger if a background error occurs while you're using your account.
- Sentry may normally receive data such as the error message, its location in the code (stack trace), which page/action you were on, technical information about your browser/device, and your account's randomly generated, pseudonymous identifier.
- Your books, characters, notes, or any other creative/fictional content are DELIBERATELY never sent to Sentry.
- Before an error reaches Sentry, we use a technical layer that automatically strips (redacts) fields such as email addresses, session/authorization data (cookies/tokens), and unusually long free text. However, no automated scrubbing system can offer an absolute guarantee - in unexpected cases, a limited amount of technical information could unintentionally remain inside an error message.
- Because technical error tracking is necessary to keep the service secure and stable, Sentry runs regardless of your consent (unlike PostHog/Google Analytics).
Communication preferences
At sign-up, you can optionally check a separate box to receive news and updates about yazar.io. This preference is NOT a condition of creating an account. See the Communication Preferences page for details.
Onboarding introduction preferences
On your first login, you may see a short, entirely optional 5-question introduction survey (how you heard about yazar.io, what you write most, how you'd describe yourself, which country you live in, and what you want to do first on the platform). None of these questions are required; you can click "Skip" without answering any of them.
Your answers are only saved if you give your EXPLICIT CONSENT via a separate, unchecked-by-default checkbox - if you click "Finish" without checking it, none of your answers are written to our database. We only use these answers to understand our user base and improve yazar.io around what writers actually need - they are NOT used to send automated marketing messages. This survey never collects sensitive or special-category data such as your birth date, age, gender, phone number, full address, profession, income, or health information; your location is never detected automatically from your IP address, only the country you choose yourself is stored.
You can view, update, delete, or withdraw your consent for your answers at any time from the "Let's Get to Know You" section on the Settings page. Withdrawing consent never affects your ability to use the rest of yazar.io, and it does not automatically reopen the onboarding survey - if you skipped it or withdrew consent, you can voluntarily fill it in again and give new consent from the same section whenever you like.
Live chat support
Our homepage includes a live chat support tool (Crisp), but it does not load automatically when the page opens - it only loads and activates when you deliberately click the "Message us" button in the bottom-right corner.
When you start a chat, the messages you write and (if you share them) any contact details you give us are passed to us through Crisp's infrastructure, for the purpose of delivering your messages and running the chat session. We (the yazar.io team) reply to chats directly - no automated AI chatbot is used.
Starting a chat may also involve processing technical connection/session information (e.g. IP address, browser information) between your browser and Crisp's servers - this is a technical necessity for the service to work.
If you'd rather not use Crisp at all, you can simply not click the "Message us" button, and reach us directly at support@yazar.io instead.
Paddle (payment processing)
When you purchase Yazar Pro (the paid plan), the payment is handled by Paddle - our payment provider, acting as Merchant of Record (authorized reseller) for payment, tax, and invoicing. Some data (such as your card details and the full billing address you enter at checkout) is collected directly by Paddle's own payment form and never reaches yazar.io at all. Separately, the data yazar.io itself transmits to Paddle to initiate the purchase and manage your subscription is deliberately narrow:
- Your email address
- The plan you selected (Yazar Pro)
- Paddle's own customer, transaction, and subscription identifiers
- Your billing country and, where required, postal code
- Payment status (e.g. successful/failed/pending)
- Information related to any refund or chargeback request you make
- Information Paddle's own processes require for fraud prevention and regulatory compliance
Data sent to Paddle for a Yazar Pro Gift purchase
When you gift Yazar Pro to someone else, you are the party who pays and who is registered as a customer with Paddle; the invoice and payment receipt are issued to your account email. The recipient's email address is NOT sent to Paddle, and the recipient does not become a Paddle customer. The only gift-specific value sent to Paddle is an unguessable, opaque reference code that lets us resolve which gift a payment belongs to - it does not contain the recipient's identity, their email, or your name.
Your display name from your Yazar.io profile and, if you choose to write one, a short gift note are shown to the recipient so they can see who sent the gift; your email address is not shared with the recipient. For our team's internal tracking of the gift, your sender email is recorded only in an internal note in our admin panel; that note is not shown to the recipient or any third party.
How (and how not) your card details and content reach Paddle
Your credit/debit card details never pass through yazar.io's servers - the payment form is served directly by Paddle's own secure infrastructure; we never see or store your card number.
Your books, characters, locations, lore, notes, or any other creative content are NEVER sent to Paddle - Paddle only ever sees the narrow data set listed above, needed to process the payment.
As Merchant of Record, Paddle may separately process this data under its own privacy policy, in fulfillment of its own legal obligations (tax, accounting, fraud prevention, regulatory compliance) - see Paddle's own Privacy Notice for details. Paddle is an international group of companies; the specific Paddle entity that contracts with you for a given purchase is determined by your location, as described in Paddle's own Buyer Terms. As a result, your payment data may be transferred outside your country.
Simply visiting this page (Payment, Subscription, and Cancellation Terms), without making any purchase, causes Paddle's script (Paddle.js) to load in your browser - this is so the payment method update form can open automatically if you arrived through a payment notification link sent by Paddle. No email address, payment information, or Paddle customer/transaction ID is sent during this load; however, because the page connects to Paddle's CDN infrastructure, your IP address and standard browser information (such as user-agent and referer) may be transmitted as a natural part of that network request. No analytics or advertising purpose was observed for the cookie ("__cf_bm") that Paddle's infrastructure provider, Cloudflare, may set during this connection - it is created for technical security purposes.
Purposes of processing
- Creating your account, verifying your identity, and keeping your session secure
- Storing, displaying, and letting you edit your books, characters, and other content
- Serving your public Author Card, if you publish one, and any Shareable Wiki pages you turn on per book
- Optimizing and hosting the images you upload
- Improving the product by understanding which features are actually used (analytics)
- Understanding our user base and improving yazar.io by considering your optional onboarding introduction preferences
- Sending news and updates, if you've opted in
- Delivering and replying to your messages when you start a live chat
- Processing your payment through Paddle and managing your subscription, if you purchase Yazar Pro
- Sending security notices and other necessary account emails about your account or content
- Detecting and fixing technical errors in the application
- Keeping the service secure and preventing abuse
Third-party service providers we use
We rely on the following providers to run yazar.io. None of them use your data for their own marketing purposes. Except for Paddle, every provider below processes data on our behalf and under our instructions, for a specific service - see the Paddle entry below for its different, independent status.
- Supabase - database, authentication, and image storage infrastructure. Our project is hosted in the European Union (Frankfurt, Germany).
- Vercel - the server infrastructure that hosts the application.
- PostHog - the narrow-scope product analytics described above, hosted in the EU region.
- Google Analytics - the secondary product analytics described above, gated by the same consent as PostHog.
- Google - only if you choose the "Continue with Google" sign-in option, for authentication purposes. (This is a SEPARATE Google service from Google Analytics above.)
- Crisp - the live chat support described above, only activated if you click the "Message us" button.
- Resend - the account/security email delivery described above.
- Sentry - the error tracking described above, used to detect technical errors.
- Paddle - the payment processing described above is activated when you purchase Yazar Pro; simply visiting the Payment, Subscription, and Cancellation Terms page (without purchasing) can also cause Paddle's script to load in your browser and create the technical/security cookie described above. Paddle is not a processor acting on our behalf for this transaction, but an independent party acting as Merchant of Record under its own legal obligations.
Data retention periods
Your account and content data are kept for as long as your account is active. When you "remove a book from your library," it is not deleted immediately - it is marked with a reversible flag (soft delete); you can restore it yourself, or permanently delete it with email verification, from the Deleted Books page for at least 30 days. Security-focused email notices are sent both when a book is removed and before it is permanently deleted (see the Data Deletion and Account Closure Notice).
Notes have no such time limit: you can permanently delete or restore them yourself, at any time.
When you delete your account, your associated data is permanently deleted within a reasonable period; some records may be kept beyond that period where required by our legal obligations.
Our approach to data security
Your content is protected at the database level with row-level security - meaning even a query bug cannot expose another user's data, because the database itself enforces the boundary.
Beyond that, some of your content (descriptions of your entities, your notes, and your custom field values) is stored encrypted (AES-256-GCM) rather than as plain text in the database. The keys that encrypt this content are kept separately from the database, protected by Google Cloud's key management service (KMS). This is NOT end-to-end encryption (E2EE) - when you sign in to your own account and make an authorized request, our server decrypts the content and shows it to you normally; the purpose is to protect your content in case the database (or a backup taken from it) is compromised on its own. In case of infrastructure loss, these keys also have a separate recovery path independent of Google.
Uploaded images are validated server-side by their actual file signature (only genuine image files are accepted), size-limited, and you can only write to or list your own folder.
Elevated, security-boundary-bypassing access is used only on the server side, narrowly, for a handful of specific necessary cases (e.g. confirming account deletion, creating a payment-management link, resolving a support request, investigating abuse or a security incident, or complying with a legal obligation that requires accessing your encrypted content) - these elevated credentials are never sent to your browser or any client-side code.
No system is completely immune to breaches or errors; we cannot promise absolute security, but we apply and continue to improve the measures above.
Your rights
For users residing in Turkey, these rights arise under Law No. 6698 on the Protection of Personal Data - see the KVKK Notice for the full list. In summary, you have the right to learn whether your data is processed, request information about it, request correction if it's inaccurate or incomplete, and request deletion where legal conditions are met.
To exercise these rights, contact us at support@yazar.io.
Data deletion and account closure process
For the full, current description of this process, see our separate Data Deletion and Account Closure Notice. In short: you can delete your own account from the Settings page with email confirmation, or contact our support team if you prefer.
Changes to this policy
We may update this policy from time to time. For material changes, we update the "Last updated" date at the top of this page, and we try to announce changes we consider significant through an in-account notice or email.
Contact
For questions about this policy: support@yazar.io