Privacy Policy
Last updated: 28.07.2026
In short: the five things that matter most
- No data sales. We never sell your personal data or pass it to data brokers, under any circumstances.
- Location is entirely under your control. By default only your friends see it; “ghost mode” switches it off completely and you can restrict it person by person.
- Your messages are not scanned for advertising. Direct messages are processed only to provide the service, to meet legal obligations and to review reported abuse.
- Deletion really means deletion. After you ask to delete your account your content is removed from the production database; clearing it from backups takes at most 30 days.
- Our servers are in Germany. Data is hosted inside the European Union, in a data centre covered by the GDPR.
1. Data controller and scope
AURCAM is a social media platform operated by Halid Tosun, acting as the data controller under the Turkish Personal Data Protection Law no. 6698 (KVKK) and as the controller under the EU General Data Protection Regulation (GDPR). Contact: privacy@aurcam.com
This policy covers the following products: the iOS and Android mobile apps, the macOS and Windows desktop apps, the aurcam.com web interface and the back-end systems serving them. Third-party links reached from inside the app (for example an external link shared by a user) fall outside this policy.
2. The data we collect
2.1 Data you give us directly
- Account details
- Email address, username, display name, date of birth (for age verification), profile photo, bio and optional gender.
- Authentication
- Your password is stored only as a cryptographic hash (bcrypt); we have no access to the plaintext. If you enable two-step verification, verification codes are held temporarily.
- Content you share
- Posts, stories, reels, comments, photos and videos, voice notes, audio/video room recordings (if you chose to record) and direct messages.
- Profile preferences
- Privacy settings, theme, language, notification preferences, autoplay and data-saving choices.
- Support correspondence
- Messages and attachments you send us by email or through the support form.
2.2 Data generated automatically as you use the service
- Device and technical data
- Device model, operating system version, app version, language setting, IP address, connection type.
- Session records
- Sign-in time, session identifier, device fingerprint (so you can manage your sessions and we can detect suspicious sign-ins).
- Interaction signals
- Which posts you like, who you follow, what content you view. This data is used to personalise the ranking of your feed.
- Error logs
- Technical records created when the app crashes. They do not contain the text of your content.
2.3 Advertising and the advertising identifier
The app shows REWARDED ads only: you open an ad yourself by tapping "watch and earn coins". No ads are placed in your feed, stories or messages. Ads are served by Google AdMob, and AdMob uses your device's advertising identifier (IDFA on iOS, AAID on Android) when requesting an ad.
- On iOS the advertising identifier is accessed only if you tap "Allow" in the system tracking prompt. If you decline, you are shown non-personalised ads and no tracking takes place. You can change your choice at any time under iOS Settings → Privacy & Security → Tracking.
- On Android ads are requested as non-personalised. You can reset or delete your advertising ID under Android Settings → Google → Ads.
- Beyond serving these ads we do not use the advertising identifier to follow you across third-party apps and websites, and we do not build or sell profiles about you.
2.4 Data we do not collect
- We do not upload your contact list automatically. Only if you start the "find friends from contacts" feature yourself, phone numbers are hashed one-way on your device (sha256) and only those hashes are sent for matching; raw numbers never reach the server.
- We do not place pixels that follow your browsing on third-party sites.
- We do not collect biometric data (identification through face recognition). The camera's AR filters run on your device; face data is never sent to the server.
3. Purposes of processing and legal bases
We process each category of data for a specific purpose and on a specific legal basis. The equivalents under KVKK art. 5 and GDPR art. 6 are summarised below.
- Providing the service (performance of a contract)
- Creating your account, showing your feed, delivering messages, running audio/video rooms. Basis: formation and performance of the contract.
- Security and abuse prevention (legitimate interest)
- Detecting spam, harassment, fake accounts and unlawful content; moderation; session security. Basis: legitimate interest and legal obligation.
- Personalisation (legitimate interest / explicit consent)
- Feed ranking, suggested accounts, interest-based discover content. You can restrict this in Settings.
- Location-based features (explicit consent)
- Map, digital footprint, nearby memories. Only with your explicit permission, which you can withdraw at any time.
- Communication (legitimate interest / explicit consent)
- Service notifications are mandatory; marketing emails are sent only if you opt in, and every email carries an unsubscribe link.
- Legal obligations
- Responding to properly made requests from competent authorities and retaining financial records. Basis: legal obligation.
4. Location data and the map
Location is the most sensitive kind of data on AURCAM, so we explain it in its own section. Location sharing is off by default and works only after you grant the device permission.
- You choose who sees it: everyone, friends only, people you pick, or nobody.
- Ghost mode: hides your location from the map completely with one tap. Timed options (3 hours / 24 hours) are available and revert to your previous setting when they expire.
- Footprint: the countries/cities you have visited can be shown on your profile. Your raw coordinates are never shared and this feature is off by default.
- No raw coordinate logging: we do not write your precise coordinates to our server logs.
- Map tiles: map imagery is served through OpenFreeMap. Tile requests do not associate your location with your user identity.
5. Device permissions (camera, microphone, gallery, notifications)
- Camera
- Used only while taking photos/videos and during video calls. There is no background camera access.
- Microphone
- Used during voice notes, audio rooms and video calls. Recording happens only when you start it.
- Photo gallery
- Only the media you select is accessed; your whole gallery is not scanned.
- Notifications
- For message, like, follow and call notifications. You can turn each type off individually in Settings.
- Motion/sensors
- Only for camera effects and the map's heading indicator; motion data is not sent to the server.
All permissions are requested at operating-system level and can be withdrawn at any time. If a permission is denied the app does not crash; only that feature is disabled.
6. Data sharing and third parties
We do not sell your personal data and we do not transfer it to third parties for marketing. Data is processed only in the following limited cases:
- Infrastructure providers
- Server hosting (Germany, netcup GmbH), database and cache services. These providers act as processors and are bound by contract.
- Deezer
- For music previews and cover art. Only the track you search for is transmitted; your identity is not shared.
- GIPHY
- For GIF and sticker search. The search term is transmitted; it is not linked to your account.
- OpenFreeMap
- For map tiles. Used without a key and without an account.
- LiveKit
- Audio and video room infrastructure. Hosted on our own server (self-hosted); audio/video streams do not go to a third company.
- Apple / Google
- For in-app purchase verification and notification delivery (APNs / FCM), with the minimum data required.
- Dodo Payments
- For Aurcam Plus payments made on the web. Your card details never reach us; they are processed by the payment provider.
- Competent authorities
- Only on a properly made, written and legally binding request. We publish such requests as aggregate figures in our transparency report.
7. International transfers
Our primary servers are in Germany (inside the European Union). Some service providers (for example Apple's notification service) may process data outside the EU. In those cases the transfer takes place under standard contractual clauses pursuant to GDPR art. 46 and with the safeguards required by KVKK art. 9.
8. Retention periods
- Account data
- For as long as your account is open. After you request deletion it is removed from production systems immediately and from backups within 30 days at the latest.
- Content (posts, stories, messages)
- Until you delete it. Stories are archived automatically after 24 hours; timed messages are deleted after the period you chose.
- Session records
- 90 days. They may be held longer for incidents requiring a security investigation.
- Moderation records
- Violation records and complaint files for 2 years. This is necessary to detect repeated breaches.
- Invoice and payment records
- 10 years, as required by tax legislation.
- Error logs
- 30 days.
9. Data security
- All traffic is encrypted with TLS 1.2+; no data is accepted over HTTP.
- Passwords are hashed with bcrypt; they are never stored or logged in plaintext.
- Optional two-step verification (email code) is available.
- You can view your sessions and end them remotely.
- Intrusion detection and automatic IP blocking (fail2ban) run at server level.
- Access to the admin panel is role-based and every administrator action is written to an audit log.
- The database is backed up nightly and backups are kept encrypted.
10. Your rights and how to exercise them
Under KVKK art. 11 and GDPR arts. 15–22 you have the following rights:
- Information and access: to learn which of your data is processed and to request a copy.
- Rectification: to have inaccurate or incomplete data corrected.
- Erasure (right to be forgotten): to request deletion of your data.
- Restriction and objection: to object to particular processing activities.
- Data portability: to receive your data in a structured, machine-readable format.
- Objection to automated decisions: to object to decisions taken solely by automated systems that significantly affect you.
- Complaint: to lodge a complaint with the Turkish Personal Data Protection Authority or the data protection authority of your EU country.
What you can do instantly from inside the app
- Download my data: Settings → Privacy → Download my data. All data belonging to your account is prepared as JSON.
- Delete my account: Settings → Privacy → Delete account. It asks for password confirmation and cannot be undone.
- Manage sessions: Settings → Security → Sessions.
For any other request write to privacy@aurcam.com. We answer your request free of charge within 30 days at the latest.
11. Children's privacy
AURCAM is not directed at users under 13 and we do not knowingly collect data from users under 13. A date of birth is requested at registration. If we learn that an account belongs to someone under 13 we close the account and delete the data. In some countries the age limit is higher; local legislation applies.
If you believe your child has an account, write to privacy@aurcam.com. You can find the safety guide we prepared for parents on the Parents' Guide page.
12. Cookies and similar technologies
On the web interface we use only the cookies necessary for the service to work (session token, theme preference, language choice). We use no advertising or third-party tracking cookies. For details see the Cookie Policy page.
13. Changes to this policy
We may update this policy in line with changes to the service and with legislation. For significant changes we send an in-app notification and announce them at least 14 days before they take effect. The “last updated” date at the top of the page always shows the version in force.
14. Contact
- Privacy and data requests
- privacy@aurcam.com
- General support
- support@aurcam.com
- Security vulnerability reports
- security@aurcam.com
- Legal notices
- legal@aurcam.com
15. Responsibility framework and your responsibilities
Data security is a shared responsibility. The framework below clarifies who is responsible for what. This section does not limit our obligations under KVKK and the GDPR; it only explains how responsibility is distributed.
15.1 What is your responsibility
- Account security: keeping your password confidential and protecting access to your account is yours. We are not liable for unauthorised access resulting from you sharing your password or using a weak one. We recommend enabling two-step verification.
- Content you share: a post, story or profile detail you share publicly is treated as made public. Our technical control over the consequences of others seeing, saving or screenshotting it is limited.
- Other people's data: if you share another person's photo, voice or personal information, you must have obtained the necessary consent. That obligation is yours.
- Your privacy settings: you can configure location, message, comment and tagging settings however you wish. We are not liable for visibility resulting from your not changing the default settings.
- Device security: your device lock, operating system updates and physical access to your device are your responsibility.
- Your contact details: you must keep your email address current; account recovery and security notices are sent to it.
15.2 The scope of our responsibility
- We take appropriate and reasonable technical and organisational measures to protect your personal data (see section 9). Our obligation is to provide the level of security required by law; it is a technical fact that no system offers absolute security.
- We are not liable, to the extent we are not at fault, for consequences arising from events beyond our control (force majeure, an outage or breach originating with a third-party provider, or the user's own negligence).
- We are not responsible for the data-processing practices of the integrated third-party services (Deezer, GIPHY, OpenFreeMap, Apple, Google, payment providers); those services are governed by their own privacy policies.
- In the event of a data breach we inform the relevant supervisory authority and the affected users within the periods laid down by law. Meeting our notification obligation cannot be construed as an admission of fault.
- We are not a party to privacy disputes between users; we do, however, assess reported breaches under the community guidelines.
The general limits of liability for the service are set out in Terms of Service — Limitation of liability. Wilful misconduct, gross negligence and any liability that cannot be limited by law are reserved in every case.
15.3 Changes and entry into force
We may update this policy in line with changes to the service, technical requirements and legislation. We announce material changes at least 14 days before they take effect. Continuing to use the service after an update means you are aware of the current policy. For processing based on explicit consent a new consent is obtained; your existing consent is not extended automatically.
Language
This English text is a translation provided for information. The binding version is the Turkish text at /privacy; in the event of any conflict, the Turkish text prevails.
Questions? support@aurcam.com · Contact page