Privacy Policy

Last updated: 28.07.2026

This policy explains how your personal data is processed when you use the AURCAM mobile app, the desktop app and the aurcam.com website. Our aim is not to hand you a pile of legal text but to explain what we actually do, in terms you can follow. If any section is unclear, write to us and we will fix the wording.

In short: the five things that matter most

In short
We do not sell your data. We do not build advertising profiles for third parties. Your location is shared only if you allow it, and only with the people you choose. You can permanently delete your account and all your content from inside the app.
  1. No data sales. We never sell your personal data or pass it to data brokers, under any circumstances.
  2. Location is entirely under your control. By default only your friends see it; “ghost mode” switches it off completely and you can restrict it person by person.
  3. Your messages are not scanned for advertising. Direct messages are processed only to provide the service, to meet legal obligations and to review reported abuse.
  4. Deletion really means deletion. After you ask to delete your account your content is removed from the production database; clearing it from backups takes at most 30 days.
  5. Our servers are in Germany. Data is hosted inside the European Union, in a data centre covered by the GDPR.

1. Data controller and scope

AURCAM is a social media platform operated by Halid Tosun, acting as the data controller under the Turkish Personal Data Protection Law no. 6698 (KVKK) and as the controller under the EU General Data Protection Regulation (GDPR). Contact: privacy@aurcam.com

This policy covers the following products: the iOS and Android mobile apps, the macOS and Windows desktop apps, the aurcam.com web interface and the back-end systems serving them. Third-party links reached from inside the app (for example an external link shared by a user) fall outside this policy.

2. The data we collect

2.1 Data you give us directly

Account details
Email address, username, display name, date of birth (for age verification), profile photo, bio and optional gender.
Authentication
Your password is stored only as a cryptographic hash (bcrypt); we have no access to the plaintext. If you enable two-step verification, verification codes are held temporarily.
Content you share
Posts, stories, reels, comments, photos and videos, voice notes, audio/video room recordings (if you chose to record) and direct messages.
Profile preferences
Privacy settings, theme, language, notification preferences, autoplay and data-saving choices.
Support correspondence
Messages and attachments you send us by email or through the support form.

2.2 Data generated automatically as you use the service

Device and technical data
Device model, operating system version, app version, language setting, IP address, connection type.
Session records
Sign-in time, session identifier, device fingerprint (so you can manage your sessions and we can detect suspicious sign-ins).
Interaction signals
Which posts you like, who you follow, what content you view. This data is used to personalise the ranking of your feed.
Error logs
Technical records created when the app crashes. They do not contain the text of your content.

2.3 Advertising and the advertising identifier

The app shows REWARDED ads only: you open an ad yourself by tapping "watch and earn coins". No ads are placed in your feed, stories or messages. Ads are served by Google AdMob, and AdMob uses your device's advertising identifier (IDFA on iOS, AAID on Android) when requesting an ad.

  • On iOS the advertising identifier is accessed only if you tap "Allow" in the system tracking prompt. If you decline, you are shown non-personalised ads and no tracking takes place. You can change your choice at any time under iOS Settings → Privacy & Security → Tracking.
  • On Android ads are requested as non-personalised. You can reset or delete your advertising ID under Android Settings → Google → Ads.
  • Beyond serving these ads we do not use the advertising identifier to follow you across third-party apps and websites, and we do not build or sell profiles about you.

2.4 Data we do not collect

  • We do not upload your contact list automatically. Only if you start the "find friends from contacts" feature yourself, phone numbers are hashed one-way on your device (sha256) and only those hashes are sent for matching; raw numbers never reach the server.
  • We do not place pixels that follow your browsing on third-party sites.
  • We do not collect biometric data (identification through face recognition). The camera's AR filters run on your device; face data is never sent to the server.

3. Purposes of processing and legal bases

We process each category of data for a specific purpose and on a specific legal basis. The equivalents under KVKK art. 5 and GDPR art. 6 are summarised below.

Providing the service (performance of a contract)
Creating your account, showing your feed, delivering messages, running audio/video rooms. Basis: formation and performance of the contract.
Security and abuse prevention (legitimate interest)
Detecting spam, harassment, fake accounts and unlawful content; moderation; session security. Basis: legitimate interest and legal obligation.
Personalisation (legitimate interest / explicit consent)
Feed ranking, suggested accounts, interest-based discover content. You can restrict this in Settings.
Location-based features (explicit consent)
Map, digital footprint, nearby memories. Only with your explicit permission, which you can withdraw at any time.
Communication (legitimate interest / explicit consent)
Service notifications are mandatory; marketing emails are sent only if you opt in, and every email carries an unsubscribe link.
Legal obligations
Responding to properly made requests from competent authorities and retaining financial records. Basis: legal obligation.

4. Location data and the map

Location is the most sensitive kind of data on AURCAM, so we explain it in its own section. Location sharing is off by default and works only after you grant the device permission.

  • You choose who sees it: everyone, friends only, people you pick, or nobody.
  • Ghost mode: hides your location from the map completely with one tap. Timed options (3 hours / 24 hours) are available and revert to your previous setting when they expire.
  • Footprint: the countries/cities you have visited can be shown on your profile. Your raw coordinates are never shared and this feature is off by default.
  • No raw coordinate logging: we do not write your precise coordinates to our server logs.
  • Map tiles: map imagery is served through OpenFreeMap. Tile requests do not associate your location with your user identity.
Turning location off completely
Settings → Privacy → Location → “Off” stops location collection entirely. You can also revoke the app's location permission in your operating system settings; map-related features then stop working, but the rest of the app is used as normal.

5. Device permissions (camera, microphone, gallery, notifications)

Camera
Used only while taking photos/videos and during video calls. There is no background camera access.
Microphone
Used during voice notes, audio rooms and video calls. Recording happens only when you start it.
Photo gallery
Only the media you select is accessed; your whole gallery is not scanned.
Notifications
For message, like, follow and call notifications. You can turn each type off individually in Settings.
Motion/sensors
Only for camera effects and the map's heading indicator; motion data is not sent to the server.

All permissions are requested at operating-system level and can be withdrawn at any time. If a permission is denied the app does not crash; only that feature is disabled.

6. Data sharing and third parties

We do not sell your personal data and we do not transfer it to third parties for marketing. Data is processed only in the following limited cases:

Infrastructure providers
Server hosting (Germany, netcup GmbH), database and cache services. These providers act as processors and are bound by contract.
Deezer
For music previews and cover art. Only the track you search for is transmitted; your identity is not shared.
GIPHY
For GIF and sticker search. The search term is transmitted; it is not linked to your account.
OpenFreeMap
For map tiles. Used without a key and without an account.
LiveKit
Audio and video room infrastructure. Hosted on our own server (self-hosted); audio/video streams do not go to a third company.
Apple / Google
For in-app purchase verification and notification delivery (APNs / FCM), with the minimum data required.
Dodo Payments
For Aurcam Plus payments made on the web. Your card details never reach us; they are processed by the payment provider.
Competent authorities
Only on a properly made, written and legally binding request. We publish such requests as aggregate figures in our transparency report.

7. International transfers

Our primary servers are in Germany (inside the European Union). Some service providers (for example Apple's notification service) may process data outside the EU. In those cases the transfer takes place under standard contractual clauses pursuant to GDPR art. 46 and with the safeguards required by KVKK art. 9.

8. Retention periods

Account data
For as long as your account is open. After you request deletion it is removed from production systems immediately and from backups within 30 days at the latest.
Content (posts, stories, messages)
Until you delete it. Stories are archived automatically after 24 hours; timed messages are deleted after the period you chose.
Session records
90 days. They may be held longer for incidents requiring a security investigation.
Moderation records
Violation records and complaint files for 2 years. This is necessary to detect repeated breaches.
Invoice and payment records
10 years, as required by tax legislation.
Error logs
30 days.

9. Data security

  • All traffic is encrypted with TLS 1.2+; no data is accepted over HTTP.
  • Passwords are hashed with bcrypt; they are never stored or logged in plaintext.
  • Optional two-step verification (email code) is available.
  • You can view your sessions and end them remotely.
  • Intrusion detection and automatic IP blocking (fail2ban) run at server level.
  • Access to the admin panel is role-based and every administrator action is written to an audit log.
  • The database is backed up nightly and backups are kept encrypted.
If you have found a security vulnerability
Please report it to security@aurcam.com before disclosing it publicly. We do not take legal action against good-faith researchers and we respond to findings within 72 hours.

10. Your rights and how to exercise them

Under KVKK art. 11 and GDPR arts. 15–22 you have the following rights:

  • Information and access: to learn which of your data is processed and to request a copy.
  • Rectification: to have inaccurate or incomplete data corrected.
  • Erasure (right to be forgotten): to request deletion of your data.
  • Restriction and objection: to object to particular processing activities.
  • Data portability: to receive your data in a structured, machine-readable format.
  • Objection to automated decisions: to object to decisions taken solely by automated systems that significantly affect you.
  • Complaint: to lodge a complaint with the Turkish Personal Data Protection Authority or the data protection authority of your EU country.

What you can do instantly from inside the app

  • Download my data: Settings → Privacy → Download my data. All data belonging to your account is prepared as JSON.
  • Delete my account: Settings → Privacy → Delete account. It asks for password confirmation and cannot be undone.
  • Manage sessions: Settings → Security → Sessions.

For any other request write to privacy@aurcam.com. We answer your request free of charge within 30 days at the latest.

11. Children's privacy

AURCAM is not directed at users under 13 and we do not knowingly collect data from users under 13. A date of birth is requested at registration. If we learn that an account belongs to someone under 13 we close the account and delete the data. In some countries the age limit is higher; local legislation applies.

If you believe your child has an account, write to privacy@aurcam.com. You can find the safety guide we prepared for parents on the Parents' Guide page.

12. Cookies and similar technologies

On the web interface we use only the cookies necessary for the service to work (session token, theme preference, language choice). We use no advertising or third-party tracking cookies. For details see the Cookie Policy page.

13. Changes to this policy

We may update this policy in line with changes to the service and with legislation. For significant changes we send an in-app notification and announce them at least 14 days before they take effect. The “last updated” date at the top of the page always shows the version in force.

14. Contact

Privacy and data requests
privacy@aurcam.com
General support
support@aurcam.com
Security vulnerability reports
security@aurcam.com
Legal notices
legal@aurcam.com

15. Responsibility framework and your responsibilities

Data security is a shared responsibility. The framework below clarifies who is responsible for what. This section does not limit our obligations under KVKK and the GDPR; it only explains how responsibility is distributed.

15.1 What is your responsibility

  • Account security: keeping your password confidential and protecting access to your account is yours. We are not liable for unauthorised access resulting from you sharing your password or using a weak one. We recommend enabling two-step verification.
  • Content you share: a post, story or profile detail you share publicly is treated as made public. Our technical control over the consequences of others seeing, saving or screenshotting it is limited.
  • Other people's data: if you share another person's photo, voice or personal information, you must have obtained the necessary consent. That obligation is yours.
  • Your privacy settings: you can configure location, message, comment and tagging settings however you wish. We are not liable for visibility resulting from your not changing the default settings.
  • Device security: your device lock, operating system updates and physical access to your device are your responsibility.
  • Your contact details: you must keep your email address current; account recovery and security notices are sent to it.

15.2 The scope of our responsibility

  • We take appropriate and reasonable technical and organisational measures to protect your personal data (see section 9). Our obligation is to provide the level of security required by law; it is a technical fact that no system offers absolute security.
  • We are not liable, to the extent we are not at fault, for consequences arising from events beyond our control (force majeure, an outage or breach originating with a third-party provider, or the user's own negligence).
  • We are not responsible for the data-processing practices of the integrated third-party services (Deezer, GIPHY, OpenFreeMap, Apple, Google, payment providers); those services are governed by their own privacy policies.
  • In the event of a data breach we inform the relevant supervisory authority and the affected users within the periods laid down by law. Meeting our notification obligation cannot be construed as an admission of fault.
  • We are not a party to privacy disputes between users; we do, however, assess reported breaches under the community guidelines.

The general limits of liability for the service are set out in Terms of Service — Limitation of liability. Wilful misconduct, gross negligence and any liability that cannot be limited by law are reserved in every case.

15.3 Changes and entry into force

We may update this policy in line with changes to the service, technical requirements and legislation. We announce material changes at least 14 days before they take effect. Continuing to use the service after an update means you are aware of the current policy. For processing based on explicit consent a new consent is obtained; your existing consent is not extended automatically.

Language

This English text is a translation provided for information. The binding version is the Turkish text at /privacy; in the event of any conflict, the Turkish text prevails.

Questions? support@aurcam.com · Contact page

Privacy Policy — AURCAM | How your data is processed