Privacy Policy
Last updated: August 17, 2026
1. Data Controller
The company operating the PlanMEET application ("the Company", "we") acts as the data controller under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"). If you have questions about the processing of your personal data, you can reach us through the in-app support channels or our registered email address.
2. Personal Data We Collect
• Identity and contact information: full name, email, date of birth (for 18+ age verification), phone number (optional) • Profile information: photos, bio, interests, occupation • Location data: your approximate location (randomly offset by ±300m) and city — used to show you nearby plans • Biometric data: the selfie taken during profile verification is sent to AWS Rekognition solely to match it against your profile photo, and is permanently deleted after 30 days • Communication content: messages exchanged with users you've matched with, and call records (call duration only — calls are never recorded) • Payment information: your subscription payments are processed through the App Store/Google Play/RevenueCat; your card details are never stored on our servers • Usage data: your in-app interactions, device information, IP address, crash reports
3. Why We Process Your Data
• To create, verify, and secure your account • To show you nearby plans and potential matches • To provide messaging and calling features • To process your subscription and payments • To detect and prevent fake accounts, harassment, and fraud • To fulfill our legal obligations • To collect anonymized usage analytics to improve the product
4. Who We Share Your Data With
Your data is shared only to the extent necessary to provide the service, with the following service providers, and where legally required: • Cloudflare (R2) — photo and media storage • Amazon Web Services (Rekognition) — content moderation and profile verification • Agora — voice/video calling infrastructure (calls are never recorded) • RevenueCat / Apple / Google / iyzico — subscription and payment processing • Firebase (FCM) — push notifications • Resend — email notifications • Competent judicial/administrative authorities — where legally required Your data is never sold to third parties for marketing purposes.
5. How Long We Keep Your Data
• Account data: for as long as your account is active, and permanently deleted within 30 days of a deletion request • Verification selfies: kept for a maximum of 30 days, then automatically deleted • Messages: conversation history is archived even after a match ends, and is deleted upon the parties' request • Location history: only your most recent location is stored — no historical location log is kept
6. Your Rights Under KVKK
Under Article 11 of KVKK (Turkey's Personal Data Protection Law), you have the right to: learn whether your personal data is being processed; request information about it if so; learn the purpose of processing and whether it's used accordingly; know the third parties to whom it's transferred domestically or abroad; request correction if it's processed incompletely or incorrectly; request its deletion or destruction; object to a result that is to your detriment arising from analysis of your data exclusively through automated systems; and request compensation for damages arising from unlawful processing. You can exercise these rights — including requesting data export and account deletion — from Settings > Account.
7. Data Security
Your passwords are one-way hashed with the Argon2id algorithm and are never stored in plain text. All data transmission is encrypted with TLS. Your location data is stored with a random offset for privacy — raw coordinates are never sent to the client.
8. Children's Privacy
PlanMEET is intended only for users aged 18 and over. If we detect an account belonging to someone under 18, we immediately suspend it and delete the associated data.
9. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes via an in-app notification or email.