← Legal documents·Türkçe

Melyuna — Data Retention and Disposal Policy

Note: This is a translation of the Turkish original. In case of any discrepancy, the Turkish version prevails.
InformationValue
Data ControllerRamazan Karayıldız
Contact E-mailsupport@melyuna.com
Version2.0

1. Purpose and Scope

1.1 Purpose

This Personal Data Retention and Disposal Policy ("Policy") sets out the maximum retention periods for personal data processed through the Melyuna mobile/web application ("App"), the deletion, destruction and anonymization methods to be applied at the end of those periods or when the reason for processing ceases, the periodic disposal operations, and the units/persons responsible for these operations.

The Policy is prepared to fulfill the obligations under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the Regulation on the Deletion, Destruction or Anonymization of Personal Data, as well as — given Melyuna's global nature — the retention/disposal obligations under the European Union General Data Protection Regulation (GDPR).

1.2 Scope

This Policy covers all personal data of Melyuna users processed electronically (Supabase/Postgres database, Supabase Auth, Supabase Storage media store, Supabase Edge Functions and related system logs). The App is a global dating, friendship and language-exchange social application for adults aged 18 and over; it is not limited to any single country, university or student group. User authentication is multi-provider: e-mail (one-time code — Supabase Auth), Google, Apple, phone (SMS), Telegram and Facebook. No university '.edu.tr' e-mail, e-Government, national ID (TCKN), biometric or document verification is performed.

1.3 Relationship with Other Documents

This Policy is applied together with, and refers to, the Privacy Policy and the Privacy Notice. Details on the purposes and legal grounds for processing are set out in the Privacy Notice.


2. Definitions

TermDescription
DeletionRendering personal data inaccessible and unusable in any way for the relevant users (e.g., deleting a database record).
DestructionRendering personal data inaccessible, unrecoverable and unusable in any way (e.g., permanent destruction of the storage medium/object).
AnonymizationRendering data such that it can under no circumstances be associated with an identified/identifiable natural person, even if matched with other data.
DisposalThe whole of deletion, destruction or anonymization operations.
Periodic disposalEx officio disposal of data whose retention period has expired, at recurring intervals defined in the Policy.
Soft-deleteMarking the account as temporarily closed to access during a recovery window; at the end of the window it is converted to permanent deletion.
device_hashA salted SHA-256 digest of the device identifier; the raw device identifier is not stored. Used to prevent abuse and to apply device-uniqueness rules.
Ban hashA PEPPER'd (secret-keyed) hash of a banned e-mail/device value; no raw identity data is stored.

3. Legal/Technical Grounds Requiring Retention and Disposal

3.1 Grounds Requiring Retention

3.2 Grounds Requiring Disposal


4. Retention Periods and Disposal Methods by Data Category

The periods below are maximum periods; if the purpose of processing ceases earlier, the data is disposed of sooner. Periods shown in [ ] will be finalized upon founder/lawyer approval.
#Data CategoryExample DataRetention PeriodDisposal Method
1Account / authenticationAccount identity: e-mail/phone/provider identifier, auth user record, device identifier (device_hash)As long as the account is activeDeletion upon account deletion (auth user is deleted, dependents cascade)
2Age dataDate of birth (for 18+ check and age display on profile)As long as the account is activeDeletion upon account deletion
3Profile dataDisplay name, gender, biography, spoken languages + CEFR levels, interests, prompt answers, dating intent, privacy/matching preferencesAs long as the account is activeDeletion upon account deletion
4Profile data implying special categories (subject to explicit consent — KVKK Art. 6 / GDPR Art. 9)Dating intent/preference fields (fields that may hint at sexual orientation)As long as the account is active or until explicit consent is withdrawnDeletion upon consent withdrawal / account deletion
5Media: photos and voice promptSupabase Storage: profile and post photos and voice-prompt recordings in a public bucket; chat photos and voice messages in a private bucket (accessible only via a short-lived signed link)As long as the account is active (chat media for the duration of the relevant chat/account)Destruction (deletion) of Supabase Storage objects upon account deletion
6Location dataSnap-to-grid + jitter applied location (raw coordinates are not stored or returned)As long as the account is active / until updatedDeletion upon account deletion or update
7Messages (not E2EE)Chat texts, message metadataAs long as the account is activeDeletion of the relevant messages upon account deletion; for records visible to the counterparty, the sender's identity is SET NULL/anonymized (within 1 day)
8Moderation flags and complaint recordsReport/block records, moderation notes, OpenAI moderation scores/labelsUntil the reported account is deleted (deleted by cascade with the account); the conversation snapshot and media attached to the report: 90 daysDeletion at the end of the period; anonymization for statistical purposes
9Ban list (ban hash)PEPPER'd hash of the banned e-mail/device (no raw identity stored)For the duration of the sanction; for permanent sanctions until the justification ceases or permanent (see Section 5)Deletion at the end of the period / when the justification ceases
10IP / rate-limit recordsIP address, request counters, rate-limit recordsAs long as the related records are retained; IP addresses are not stored in the application database (they may only exist in the infrastructure provider's platform logs)Deletion or anonymization at the end of the period
11Security / system logsError logs, authentication attempts, edge function logsAs long as the infrastructure provider's platform log retention periodDeletion or anonymization at the end of the period
12Consent recordsApproved text version and date (version + date)For the duration of the burden of proof — As long as the account is active (deleted when the account is deleted)Deletion at the end of the period
13Notification tokensFCM and Web Push tokensAs long as the account is active / until the token becomes invalidDeletion upon account deletion or when the token becomes invalid
14CSAM/child-abuse report recordsRecords created under statutory reporting obligationsThe period prescribed by applicable legislationDeletion/destruction at the end of the statutory period
15World posts (feed)Post text, photo, audio and comments90 days (from the date of the post)Automatic deletion at the end of the period (daily scheduled job)
16KVKK/GDPR request recordsData-subject applications and responsesThe period prescribed by applicable legislation; requests are received and answered by e-mail, no separate request record is kept in the application databaseDeletion at the end of the period
Note (overseas processors): As stated in the Privacy Notice, some of the above data is also processed/stored by overseas data processors (Supabase — Postgres database + Auth + Storage + Edge Functions, EU — Ireland, eu-west-1; Cloudflare Pages — web hosting/CDN; Firebase Cloud Messaging + Web Push; OpenAI and Anthropic — moderation; Google — text translation at the user's request; Sentry — error diagnostics; Resend — verification e-mail; BigDataCloud and CARTO — location/maps). When a disposal instruction is issued, the relevant data is also disposed of / caused to be disposed of at these processors within the framework of KVKK Art. 9, GDPR and contractual undertakings.

5. Justification for Limited Retention (Ban Hash and Security Logs)

Certain data may be retained for a limited period on the grounds of legitimate interest (KVKK Art. 5/2-f, GDPR Art. 6/1-f) and abuse prevention, even if the user account is deleted:

The scope of this exceptional retention is kept purpose-limited and proportionate; when the justification for retention ceases, the data is disposed of.


6. Effect of In-App Account Deletion (Soft-delete + Cascade)

The App offers an in-app account deletion feature (as required by Apple App Store Guideline 5.1.1(v), the KVKK "right to be forgotten"/erasure request, and GDPR Art. 17). Account deletion operates on a soft-delete + 14-day recovery window followed by permanent deletion model. (Suspending/pausing the account is a separate operation.)

  1. Soft-delete: When the user deletes their account, the account is first closed to access and marked for deletion. For 14 days, the user can undo the operation and recover their account.
  2. Permanent deletion: When the recovery window (14 days) expires, the auth user is deleted (the primary identity record) and the data linked to the auth record is cleaned up in a chain:
  1. Media objects in Supabase Storage (photos and voice prompts) are asynchronously destroyed (deleted).
  2. A deletion instruction is also applied/caused to be applied to the relevant data held by overseas processors (Supabase, FCM/Web Push, OpenAI, etc.).
  3. Exceptions: The ban hash and minimal security logs described in Section 5 may be retained for the specified limited period on the grounds of legitimate interest. These records do not contain direct identity information.
After the permanent deletion operation, the user may be informed that the operation is complete and which limited data (if any) is retained and on what grounds. Maximum completion time for asynchronous cleanup operations: within 1 day from the end of the recovery window.

7. Periodic Disposal


8. Deletion/Destruction/Anonymization Methods (Technical)

MediumMethod
Postgres/Supabase database recordsDeletion of the relevant rows via DELETE; ON DELETE CASCADE / SET NULL for referential integrity. Data residing in backups is naturally disposed of at the end of the backup rotation period; if a restore is performed, disposal instructions are re-applied.
Supabase Storage (media)Object delete of the object; permanent destruction of photo and voice-prompt objects.
Logs / IP / rate-limitDeletion of expired records or anonymization by severing the link to the person.
FCM / Web Push tokensDeletion of the token record and cleanup of invalid tokens.
Overseas processorsSending/causing to be sent a deletion request within the scope of processor agreements (KVKK Art. 9, GDPR).
Important: Messages are not end-to-end encrypted (E2EE); they are encrypted in transit (TLS) and at rest, and the authorized technical/moderation team can access them. This is expressly stated in the Privacy Notice. Disposal also covers rendering encrypted-at-rest data permanently inaccessible.

9. Responsible Parties and Allocation of Duties

RoleResponsibility
Data ControllerDetermining, applying and overseeing the Policy; assessing whether a VERBIS registration obligation exists and fulfilling it where required.
Technical Team / System AdministratorSetting up and running the soft-delete → permanent-deletion conversion and periodic disposal tasks (cron/job); verifying cascade/SET NULL rules; keeping disposal records; tracking disposal at processors.
Moderation OfficerAuditing the justification and duration of retention for ban hash and moderation/complaint records; logging manual ban decisions.

10. Recording, Auditing and Updating


11. Rights of the Data Subject

Data subjects may exercise their rights under KVKK Art. 11 and GDPR (including deletion/destruction of data) through the methods set out in the Privacy Notice and Privacy Policy, via support@melyuna.com; they may also use the in-app account deletion feature. Applications are concluded within the period prescribed by legislation. The data subject's right to lodge a complaint with the Board/supervisory authority is reserved.

The Turkish version prevails in case of any discrepancy.