Privacy Policy
Last updated: 5 September 2026
This policy explains what personal data the bölüştür mobile app processes, why, and what rights you have over it.
1. Who is responsible
bölüştür is developed and published by Raci Eren Denizoğlu, an individual developer. He is the data controller for the personal data covered by this policy.
Contact: contact@bolustur.app
2. What the app does — and what it does not do
bölüştür is a record-keeping app that tracks shared expenses and shows who owes what to whom.
No money moves through the app. bölüştür is not a payment institution. It does not hold, transfer, or process funds. The app displays an IBAN and lets you copy it; you make the payment yourself from your own banking app, then return to the app and mark it as paid.
3. Personal data we process
Data you enter
| Data | Required | Purpose |
|---|---|---|
| Email address | Yes | Account creation and sign-in |
| Full name | Yes | So other users can identify you |
| IBAN | No | So others can pay you |
| IBAN account holder name | If IBAN is entered | So payments reach the right person |
| Expense records | — | The core function of the app |
| Group names and memberships | — | The core function of the app |
| Splits and settlements | — | Balance calculation |
Data the app generates
- Language and theme preferences — stored on your device and in your account
- Notification preferences — which notifications you want to receive
- Device push token — created only if you allow notifications; determines which device receives them
- Session data — sign-in codes and session tokens
Data we do not collect
We want to state these explicitly:
- No usage analytics. The app contains no analytics tooling. Which screens you use, how long, and when you open the app are not recorded.
- No crash reporting. We receive no automatic report when the app crashes.
- No advertising or tracking identifiers. No ads are shown and no data is shared with ad networks.
- No location data.
- No access to your contacts, photos, or camera.
- Fonts are bundled inside the app and are not downloaded at runtime, so opening the app does not send your IP address to a font server.
4. Who can see your data
This section matters, because by the nature of the app some of your information is visible to other users.
People who share a group or an expense with you can see:
- Your name
- Your IBAN and account holder name, if you have entered them
- Expenses, splits and settlements shared with you
- What they owe you, or what you owe them
A deliberate exception: if you leave a group but still have an open balance with someone from it, they can continue to see your IBAN. The reason is simple — someone who wants to pay you back needs to know where to send it.
What they cannot see: your email address is never shown to other users. Anyone who shares neither a group nor an expense with you can see nothing about you at all.
5. Service providers
We use the following services to run the app. No data is transferred to any third party beyond these.
Supabase — database and authentication
Server location: Frankfurt, Germany (European Union)
This is the only service the app communicates with directly. All the data listed above is stored and processed here.
Resend — email delivery
Server location: Ireland (European Union)
Delivers your sign-in codes and group invitations. The app does not contact this service directly; email is sent via Supabase. Your email address reaches this service.
Expo — notification infrastructure
When you allow notifications, a request is made to Expo's servers to create a device-specific push token. Expo receives a device identifier tied to your app. If you do not allow notifications, this never happens.
Apple Push Notification service (APNs)
The channel through which notifications reach your phone. Accessed via Expo; the app does not connect to it directly. Apple receives the device token and the notification content. This service is governed by Apple's own terms.
Out of scope
Downloading the app from the App Store is subject to Apple's own data practices and falls outside this policy.
6. Our legal bases for processing
- Performance of a contract — creating your account, recording expenses, calculating balances
- Your explicit consent — sending notifications (where permitted); storing your IBAN and showing it to people you share with
- Legitimate interests — keeping the service secure and preventing abuse
You are not required to enter an IBAN. Without one the app works normally; people paying you will simply have to ask for it another way.
7. Retention
- Account data — for as long as your account remains open
- Expense and settlement records — permanently, subject to the limits in section 8 below
- Pending invitations — deleted automatically after 7 days
- Sign-in codes — short-lived; invalid once used or expired
- Device push token — your device's registration is removed when you sign out
8. Deleting your account — and the limits of that deletion
You can delete your account from the Profile screen inside the app. This cannot be undone.
What is deleted:
Your name, email address, IBAN, account holder name and preferences are erased. Other users will see "Silinen kullanıcı" (deleted user) in place of your name.
What is not deleted:
Expense records, splits and settlements are not deleted.
We say this plainly because promising complete deletion would be inaccurate. The reason is that these records are not only yours. Deleting an expense would corrupt the balances of everyone who shared it — their own financial record would become wrong. The records therefore remain in place, stripped of your identity.
This is a deliberate limitation on your right to erasure, applied to protect the rights of others.
9. Your rights
Under Turkey's Personal Data Protection Law (KVKK, Law No. 6698) and the GDPR you have the right to:
- Learn whether your personal data is being processed
- Request information about that processing
- Learn the purpose of processing and whether the data is used accordingly
- Request correction of incomplete or inaccurate data
- Request erasure or destruction (subject to the limits in section 8)
- Request that correction, erasure or destruction be communicated to third parties the data was transferred to
- Object to a result reached solely through automated analysis of your data
- Claim compensation for damage arising from unlawful processing
To exercise these rights, write to contact@bolustur.app. We respond within 30 days at the latest.
You can already edit your name, email, IBAN and preferences at any time from the Profile screen in the app.
10. Security
- All communication runs over an encrypted connection (HTTPS/TLS)
- Session data is held in your device's operating-system secure storage
- Access rules are enforced at the database level: no user who shares neither a group nor an expense with you can reach your data
- No passwords are used; sign-in is by a one-time code sent to your email
No system is perfectly secure, and we do not claim otherwise.
11. Children's data
bölüştür is not designed for anyone under 18, and our terms of use set an 18 age limit. We do not knowingly collect data from anyone under 18. If we become aware of such an account we delete it and its data. If you believe your child has created an account without your knowledge, write to contact@bolustur.app.
12. International transfers
Your data is hosted within the European Union (Germany and Ireland). Because of the notification infrastructure, device identifiers may reach servers in the United States (Expo, Apple). This transfer is necessary to deliver notifications and only occurs if you have allowed them.
13. Changes
If we change this policy we will publish the current version on this page and update the date above. For significant changes we will notify you in the app or by email.
14. Contact
For questions, requests or complaints:
contact@bolustur.app
If you are resident in Turkey, you also retain the right to complain to the Personal Data Protection Authority (KVKK).