Residency by component
| Component | Location | Detail |
|---|---|---|
| Application database | Türkiye | Accounts, projects, subscribers, campaigns, statistics |
| Database backups | Türkiye | Encrypted backups |
| Application and worker servers | Türkiye | API and queue workers |
| Application logs | Türkiye | Kept on the server; sensitive fields are redacted from logs |
| Web/mobile push delivery | Abroad | Google, Mozilla, Apple, Microsoft push services — technically unavoidable, content is delivered encrypted |
| Payments and billing | Abroad (UK/EU) | Paddle; card data never reaches us |
| SDK distribution (CDN) | Global | A static JavaScript file only; carries no personal data |
| Email delivery | Abroad (EU) | Transactional email (address verification, password reset, alerts) is sent through Brevo |
| Support requests | Türkiye | Messages from the panel and the site’s help box are stored in the database on our own server (email address + the text you write); the notification email goes through Brevo. Closed requests are deleted after 12 months. |
| Visit measurement (basic) | Türkiye | Cookie-free Umami hosted on our own server; requires no consent |
| Visit measurement (detailed) | Abroad (EU/US) | Google Analytics 4 — on the marketing site only; runs in cookieless mode and writes no cookie unless consent is given |
Transfers abroad
Transfer to push services is required to perform the service and is technically unavoidable: a notification can only reach a device through the browser vendor’s service. The data transferred consists of the endpoint address and the encrypted notification payload. Transfer to the payment provider is limited to carrying out the payment. Transfer to Google Analytics, by contrast, is not required to perform the service: it is done to measure visit statistics on the marketing site. Without consent the data transferred is limited to a cookieless page-view signal (including a truncated IP address); with consent a cookie identifier is added.
Retention periods
| Data | Purpose | Retention period |
|---|---|---|
| Account record (name, email, password hash) | Providing the service, authentication | Until the account is deleted; within 30 days of a deletion request |
| Subscriber record (push endpoint, encryption keys, tags, country, browser, operating system, language, time zone) | Sending and targeting notifications | Until the subscription ends or the project is deleted |
| Campaign content and send records | Reporting, debugging | Until the project is deleted |
| Delivery and click events | Performance statistics | 12 months (deleted automatically as monthly partitions) |
| Outgoing webhook delivery records | Integration debugging | 90 days (deleted automatically) |
| Session refresh tokens | Session continuity | 30 days (invalid once expired) |
| Invoice and payment records | Obligation under financial legislation | The period required by financial legislation (10 years) |