Note: This is a translation of the Turkish original. In case of any discrepancy, the Turkish version prevails.
| Information | Value |
|---|---|
| Data Controller | Ramazan Karayıldız |
| Contact E-mail | support@melyuna.com |
| Version | 2.0 |
This Personal Data Retention and Disposal Policy ("Policy") sets out the maximum retention periods for personal data processed through the Melyuna mobile/web application ("App"), the deletion, destruction and anonymization methods to be applied at the end of those periods or when the reason for processing ceases, the periodic disposal operations, and the units/persons responsible for these operations.
The Policy is prepared to fulfill the obligations under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the Regulation on the Deletion, Destruction or Anonymization of Personal Data, as well as — given Melyuna's global nature — the retention/disposal obligations under the European Union General Data Protection Regulation (GDPR).
This Policy covers all personal data of Melyuna users processed electronically (Supabase/Postgres database, Supabase Auth, Supabase Storage media store, Supabase Edge Functions and related system logs). The App is a global dating, friendship and language-exchange social application for adults aged 18 and over; it is not limited to any single country, university or student group. User authentication is multi-provider: e-mail (one-time code — Supabase Auth), Google, Apple, phone (SMS), Telegram and Facebook. No university '.edu.tr' e-mail, e-Government, national ID (TCKN), biometric or document verification is performed.
This Policy is applied together with, and refers to, the Privacy Policy and the Privacy Notice. Details on the purposes and legal grounds for processing are set out in the Privacy Notice.
| Term | Description |
|---|---|
| Deletion | Rendering personal data inaccessible and unusable in any way for the relevant users (e.g., deleting a database record). |
| Destruction | Rendering personal data inaccessible, unrecoverable and unusable in any way (e.g., permanent destruction of the storage medium/object). |
| Anonymization | Rendering data such that it can under no circumstances be associated with an identified/identifiable natural person, even if matched with other data. |
| Disposal | The whole of deletion, destruction or anonymization operations. |
| Periodic disposal | Ex officio disposal of data whose retention period has expired, at recurring intervals defined in the Policy. |
| Soft-delete | Marking the account as temporarily closed to access during a recovery window; at the end of the window it is converted to permanent deletion. |
| device_hash | A salted SHA-256 digest of the device identifier; the raw device identifier is not stored. Used to prevent abuse and to apply device-uniqueness rules. |
| Ban hash | A PEPPER'd (secret-keyed) hash of a banned e-mail/device value; no raw identity data is stored. |
The periods below are maximum periods; if the purpose of processing ceases earlier, the data is disposed of sooner. Periods shown in [ ] will be finalized upon founder/lawyer approval.
| # | Data Category | Example Data | Retention Period | Disposal Method |
|---|---|---|---|---|
| 1 | Account / authentication | Account identity: e-mail/phone/provider identifier, auth user record, device identifier (device_hash) | As long as the account is active | Deletion upon account deletion (auth user is deleted, dependents cascade) |
| 2 | Age data | Date of birth (for 18+ check and age display on profile) | As long as the account is active | Deletion upon account deletion |
| 3 | Profile data | Display name, gender, biography, spoken languages + CEFR levels, interests, prompt answers, dating intent, privacy/matching preferences | As long as the account is active | Deletion upon account deletion |
| 4 | Profile data implying special categories (subject to explicit consent — KVKK Art. 6 / GDPR Art. 9) | Dating intent/preference fields (fields that may hint at sexual orientation) | As long as the account is active or until explicit consent is withdrawn | Deletion upon consent withdrawal / account deletion |
| 5 | Media: photos and voice prompt | Supabase Storage: profile and post photos and voice-prompt recordings in a public bucket; chat photos and voice messages in a private bucket (accessible only via a short-lived signed link) | As long as the account is active (chat media for the duration of the relevant chat/account) | Destruction (deletion) of Supabase Storage objects upon account deletion |
| 6 | Location data | Snap-to-grid + jitter applied location (raw coordinates are not stored or returned) | As long as the account is active / until updated | Deletion upon account deletion or update |
| 7 | Messages (not E2EE) | Chat texts, message metadata | As long as the account is active | Deletion of the relevant messages upon account deletion; for records visible to the counterparty, the sender's identity is SET NULL/anonymized (within 1 day) |
| 8 | Moderation flags and complaint records | Report/block records, moderation notes, OpenAI moderation scores/labels | Until the reported account is deleted (deleted by cascade with the account); the conversation snapshot and media attached to the report: 90 days | Deletion at the end of the period; anonymization for statistical purposes |
| 9 | Ban list (ban hash) | PEPPER'd hash of the banned e-mail/device (no raw identity stored) | For the duration of the sanction; for permanent sanctions until the justification ceases or permanent (see Section 5) | Deletion at the end of the period / when the justification ceases |
| 10 | IP / rate-limit records | IP address, request counters, rate-limit records | As long as the related records are retained; IP addresses are not stored in the application database (they may only exist in the infrastructure provider's platform logs) | Deletion or anonymization at the end of the period |
| 11 | Security / system logs | Error logs, authentication attempts, edge function logs | As long as the infrastructure provider's platform log retention period | Deletion or anonymization at the end of the period |
| 12 | Consent records | Approved text version and date (version + date) | For the duration of the burden of proof — As long as the account is active (deleted when the account is deleted) | Deletion at the end of the period |
| 13 | Notification tokens | FCM and Web Push tokens | As long as the account is active / until the token becomes invalid | Deletion upon account deletion or when the token becomes invalid |
| 14 | CSAM/child-abuse report records | Records created under statutory reporting obligations | The period prescribed by applicable legislation | Deletion/destruction at the end of the statutory period |
| 15 | World posts (feed) | Post text, photo, audio and comments | 90 days (from the date of the post) | Automatic deletion at the end of the period (daily scheduled job) |
| 16 | KVKK/GDPR request records | Data-subject applications and responses | The period prescribed by applicable legislation; requests are received and answered by e-mail, no separate request record is kept in the application database | Deletion at the end of the period |
Note (overseas processors): As stated in the Privacy Notice, some of the above data is also processed/stored by overseas data processors (Supabase — Postgres database + Auth + Storage + Edge Functions, EU — Ireland, eu-west-1; Cloudflare Pages — web hosting/CDN; Firebase Cloud Messaging + Web Push; OpenAI and Anthropic — moderation; Google — text translation at the user's request; Sentry — error diagnostics; Resend — verification e-mail; BigDataCloud and CARTO — location/maps). When a disposal instruction is issued, the relevant data is also disposed of / caused to be disposed of at these processors within the framework of KVKK Art. 9, GDPR and contractual undertakings.
Certain data may be retained for a limited period on the grounds of legitimate interest (KVKK Art. 5/2-f, GDPR Art. 6/1-f) and abuse prevention, even if the user account is deleted:
The scope of this exceptional retention is kept purpose-limited and proportionate; when the justification for retention ceases, the data is disposed of.
The App offers an in-app account deletion feature (as required by Apple App Store Guideline 5.1.1(v), the KVKK "right to be forgotten"/erasure request, and GDPR Art. 17). Account deletion operates on a soft-delete + 14-day recovery window followed by permanent deletion model. (Suspending/pausing the account is a separate operation.)
After the permanent deletion operation, the user may be informed that the operation is complete and which limited data (if any) is retained and on what grounds. Maximum completion time for asynchronous cleanup operations: within 1 day from the end of the recovery window.
| Medium | Method |
|---|---|
| Postgres/Supabase database records | Deletion of the relevant rows via DELETE; ON DELETE CASCADE / SET NULL for referential integrity. Data residing in backups is naturally disposed of at the end of the backup rotation period; if a restore is performed, disposal instructions are re-applied. |
| Supabase Storage (media) | Object delete of the object; permanent destruction of photo and voice-prompt objects. |
| Logs / IP / rate-limit | Deletion of expired records or anonymization by severing the link to the person. |
| FCM / Web Push tokens | Deletion of the token record and cleanup of invalid tokens. |
| Overseas processors | Sending/causing to be sent a deletion request within the scope of processor agreements (KVKK Art. 9, GDPR). |
Important: Messages are not end-to-end encrypted (E2EE); they are encrypted in transit (TLS) and at rest, and the authorized technical/moderation team can access them. This is expressly stated in the Privacy Notice. Disposal also covers rendering encrypted-at-rest data permanently inaccessible.
| Role | Responsibility |
|---|---|
| Data Controller | Determining, applying and overseeing the Policy; assessing whether a VERBIS registration obligation exists and fulfilling it where required. |
| Technical Team / System Administrator | Setting up and running the soft-delete → permanent-deletion conversion and periodic disposal tasks (cron/job); verifying cascade/SET NULL rules; keeping disposal records; tracking disposal at processors. |
| Moderation Officer | Auditing the justification and duration of retention for ban hash and moderation/complaint records; logging manual ban decisions. |
Data subjects may exercise their rights under KVKK Art. 11 and GDPR (including deletion/destruction of data) through the methods set out in the Privacy Notice and Privacy Policy, via support@melyuna.com; they may also use the in-app account deletion feature. Applications are concluded within the period prescribed by legislation. The data subject's right to lodge a complaint with the Board/supervisory authority is reserved.