Privacy Policy
Last Updated: January 9, 2026 | Effective Date: January 9, 2026
1. Scope
This Privacy Policy explains how personal data is processed when you use the Finito mobile application (the "App"). It covers App usage, account sign-in, cloud sync, subscriptions, product analytics, crash reporting, notifications, and support communications.
2. Data Controller & Contact
Data Controller: Selami Demir (a sole proprietorship operating under the Finito brand)
Address: Sırrıpaşa Mah. Uygar Sok. No: 16 Daire: 2 Derince Kocaeli Türkiye
Privacy & Support Contact: finito@netbilio.com
3. Data We Process
Depending on how you use the App, we may process:
3.1 Account & identity data (registered users)
- Email address (passwordless "magic link" sign-in)
- If you choose Google Sign-In: name and profile photo (if provided by Google)
3.2 In-app content
Daily achievements, notes, garden/progress data, in-app settings and preferences
Important: Please avoid entering sensitive personal data (health/financial data, etc.) into free-text fields.
3.3 Subscription & purchase-related data
Subscription status and purchase verification records (e.g., transaction identifiers, purchase tokens/receipts)
Important: Payments are processed by Google Play. We do not see or store your payment card details.
3.4 Technical data (minimum necessary)
- Device model, OS version, app version, language/region settings
- Session tokens and authentication tokens used for sign-in and security
- Limited security/service logs needed to operate and secure the App
3.5 Product analytics (PostHog – EU Cloud)
- Event-based usage data to improve the product (e.g., app open, onboarding completion, feature usage, paywall views)
- Privacy safeguards such as IP anonymization are applied
- Session Replay is disabled (no screen/session recordings are collected)
3.6 Crash reporting (Sentry – EU Data Center)
Technical crash/error reports to diagnose and fix issues (e.g., stack traces and app/device version data). We aim to minimize the collection of personal data and apply filtering/masking where feasible.
3.7 Notification data (Expo Push Notifications)
- Notification permission status
- Device push token (for delivery)
Notifications do not contain personal content and can be disabled in settings.
3.8 Support communications
The content you send via email/contact forms and records related to handling your request.
4. Anonymous vs Registered Use
Anonymous use (no sign-in): Your in-app content is stored locally on your device and is not synced to our cloud. However, limited technical, analytics, and crash-reporting data may still be processed (e.g., event-based analytics and error reports). In-app content (notes/achievements) is not synced unless you sign in.
Registered use: Your content remains on your device and may also be synced to the cloud for cross-device access.
5. Purposes
We process data to:
- Provide and operate the App (accounts, sync, core features)
- Manage subscriptions and verify purchases
- Maintain security and prevent abuse
- Improve the product (analytics) and fix issues (crash reporting)
- Provide customer support
- Send reminders/notifications if you allow them
Commitments:
- ❌ We do not sell personal data.
- ❌ We do not build profiles for behavioral/targeted advertising.
6. Legal Bases (KVKK / GDPR)
Depending on your location and applicable law, we rely on the following legal bases:
- Performance of a contract (GDPR 6(1)(b); KVKK 5/2-c): account access, core features, and cloud sync (for registered users)
- Legal obligations (GDPR 6(1)(c); KVKK 5/2-ç): responding to lawful requests and complying with mandatory record-keeping obligations
- Legitimate interests (GDPR 6(1)(f); KVKK 5/2-f): ensuring security, preventing abuse, improving product quality, analytics, and troubleshooting/crash reporting
- Consent/permission where required (GDPR 6(1)(a); KVKK 5/1): notifications and other optional features that require your consent
7. Sharing & Third Parties
We share data only as necessary with:
Service providers (processors):
- Supabase – AWS eu-central-1 (Frankfurt, Germany)
- RevenueCat – subscription management
- PostHog (EU Cloud) – product analytics with IP anonymization
- Sentry (EU Data Center) – crash reporting
Independent controllers:
Google (Google Sign-In / Google Play) may act as an independent controller; their privacy policies apply.
Notifications:
Expo Push Notifications uses Apple/Google notification systems for delivery.
8. International Transfers
Your data may be processed outside Türkiye (e.g., within the EEA) due to the location of our infrastructure providers (such as EU-based cloud services). The Data Controller is located in Türkiye, and access to data from Türkiye may occur for support and operations. We implement appropriate safeguards as required by applicable law. Where required, we may request additional consent or use other lawful transfer mechanisms.
9. Retention
- Registered accounts: 18 months inactive: notice; 24 months inactive: final notice; 25 months inactive: deletion
- Analytics and crash reports: 12 months
- Support communications: retained for a reasonable period after the request is closed (typically up to 12 months), unless a longer period is required to resolve disputes or comply with legal obligations
- Backups: 30–90 days after deletion to fully purge
10. Security
We apply reasonable technical and organizational measures (TLS/SSL, access controls). No system can be guaranteed 100% secure.
11. Your Rights & Requests
Contact us at finito@netbilio.com to exercise your rights under applicable laws (KVKK/GDPR). We may request identity verification for security. We aim to respond within 30 days (or within the timeframe required by law).
If processing is based on consent/permission, you can withdraw your consent at any time (for example, by disabling notifications in your device/app settings).
GDPR users may also lodge a complaint with their local supervisory authority.
12. Children
Finito is not intended for children under 13. We do not knowingly collect personal data from children and will delete it if we become aware.
13. Account Deletion
- In the App: Settings > Privacy > Delete Account
- Via the Web: finito.netbilio.com/delete-account
Deletion is subject to legal retention obligations. See Section 9 for backup timelines.
15. Website Analytics and Cookies (finito.netbilio.com)
We operate a website at finito.netbilio.com to provide information about the App and to publish our legal pages (such as this Privacy Policy, the Terms of Service, and the account deletion page).
We use PostHog (EU Cloud) on our website to understand how visitors use the site (e.g., page views, clicks, and basic usage patterns) and to improve the website and the App. IP anonymization is enabled.
We do not use website analytics for behavioral/targeted advertising.
You may be able to limit analytics by blocking cookies/similar technologies in your browser settings and/or enabling "Do Not Track" where supported. If we implement an explicit on-site analytics preference toggle, you can also use it to disable analytics.
16. Account Deletion Requests via the Website
If you submit an account deletion request via finito.netbilio.com/delete-account, we process the information you provide (typically your email address and any details included in your request) for the purpose of:
- verifying the request,
- communicating with you about the request, and
- completing account and data deletion.
We retain deletion request records for a reasonable period (typically up to 12 months) to process the request, prevent abuse, and handle disputes or legal obligations, after which they are deleted or anonymized where feasible.
17. Changes
We may update this Policy from time to time. If changes are material, we may notify you in-app and/or by email.