Effective · 7 September 2026
Privacy Notice
This notice explains what data is processed when you use the TripRoll mobile app, why it is processed, where it is held, how long it is kept, and what rights you have over it. Turkish version: Gizlilik Bildirimi.
In short: TripRoll runs in two modes. In guest mode there is no account and no data leaves your device. In account mode you sign in with your email address; roll details and the frames themselves are uploaded to our server in the European Union so that friends can join the same roll from their own phones. Frames are kept in a private bucket, and a frame from an undeveloped roll is visible only to the person who shot it. There is no advertising, we never sell your data, photo content is never sent to analytics, and you can permanently delete your account from inside the app.
1. Who is responsible
Dode Yazılım
Email: destek@dodeyazilim.com
Web: triproll.dodeyazilim.com
We act as the “controller” under the EU General Data Protection Regulation (GDPR) and as “veri sorumlusu” under Turkish Law No. 6698 on the Protection of Personal Data (KVKK). The email address above is the single point of contact for every privacy request.
2. The app runs in two modes
What is processed depends on how you use the app. You choose the mode, and you can change it at any time from inside the app.
a) Guest mode — no account
If you use the app without signing in, everything runs on your device. The rolls you create, their invite codes, participant names, the frames you shoot and your preferences are stored in the app's own storage area. In this mode no data is sent to a server, we cannot see it and we cannot recover it for you. If you lose the device, remove the app or clear its data, those rolls cannot be restored.
b) Account mode — the shared roll
To let friends join the same roll from their own phones you need an account. An account is opened with an email address: you never set a password, you enter the six-digit one-time code sent to your address. In this mode the following is uploaded to the server:
- Roll details: trip name, destination text, start and end dates, frame capacity (24/36/48), the film mood you picked, the invite code, and the roll's state (active / developed).
- Membership details: which user joined which roll and when, and whether they are the host.
- Profile details: your email address, account identifier, the display name you type in the app, your initials, avatar colour and language preference. You are never required to use your real name.
- The frames themselves: the photo files you shoot or pick, along with their note (if any), the prompt they answer, their order and date.
- Favourite marks and — if you use them — block and content-report records.
Who can reach the frames: frames are kept in a private storage bucket; no public address is ever handed out and reads happen only through short-lived signed links. The access rule is enforced at the database level: a frame from an undeveloped roll is visible only to the person who shot it. Once the roll is developed the frames open to the members of that roll; frames from people you have blocked are not shown to you. This is guaranteed by row-level security policies, not by the app's interface.
c) Crash and error reports
When the app crashes or hits an error, a technical report is created and delivered to us through Sentry. It typically contains the error message and stack trace, the app version and build number, device model, operating-system version, device language, the time of the event and a randomly generated session identifier. Photo content, frame files, roll names and invite codes are not included. If you turn measurement off inside the app, no crash report is sent either.
d) Anonymous usage events
To understand which screens work and where people get stuck, anonymous product events are collected through PostHog. Example events: roll created, joined with an invite code, frame added, reveal completed, frame favourited, data exported, language changed. Each event carries the platform (iOS/Android), app version, device language and country. Photos, frame notes, roll names and invite codes are never part of these events. You can turn measurement off under Settings › Analytics; while it is off, neither events nor crash reports are sent.
e) Content reports and blocks
When you report a frame, a person or a roll, the identifier of the reported content, the reason you selected, any description you wrote (up to 500 characters), the date of the report and your account identifier are stored in the reports table on the server and reviewed by us. When you block someone, only the identifiers of the blocking and blocked accounts and the date are stored; the blocked person is not notified.
f) What you send us directly
If you write to our support address, your email address and the content of your message are processed only to answer your request.
3. What we never collect
- Location. The app never asks for location permission and never reads GPS. EXIF location data is stripped from every frame on the device before it is uploaded.
- Contacts, calendar, health and file data. Access is never requested.
- Microphone and audio. No microphone permission is requested; on Android the audio-recording permission is explicitly blocked.
- Broad photo-library access. The system photo picker is used, so only the frame you choose reaches the app and your library is never scanned.
- Advertising identifiers (IDFA/AAID) and ad tracking. There is no ad SDK, no App Tracking Transparency prompt, and we do not track you across other companies' apps or websites.
- Passwords. You never set one and we never store one; sign-in uses a one-time code.
- Name, date of birth, phone number, payment details. Never requested, never stored. (If in-app purchases are offered, payment is handled entirely by Apple or Google and your card details never reach us.)
- Photo content in analytics. No image you shoot is included in crash reports or analytics events.
We do not sell, rent or share your personal data for advertising purposes.
4. Purposes and legal bases
| Data | Purpose | Legal basis |
|---|---|---|
| Guest-mode roll and frame data | Providing the core function of the app | The data never leaves your device, so it is not processed by us. |
| Email address and account identifier | Opening the account, verifying sign-in, authorising access to a roll | GDPR Art. 6(1)(b) performance of a contract · KVKK Art. 5(2)(c) |
| Roll details, memberships, frames and frame notes | Running the shared roll, storing frames, opening them to the group at the reveal | GDPR Art. 6(1)(b) performance of a contract · KVKK Art. 5(2)(c) |
| Content reports | Reviewing unlawful and rule-breaking content, protecting users | GDPR Art. 6(1)(c) legal obligation and 6(1)(f) legitimate interests · KVKK Art. 5(2)(ç) and 5(2)(f) |
| Block records | Hiding the frames of a blocked person | GDPR Art. 6(1)(b) · KVKK Art. 5(2)(c) |
| Crash and error reports | Fixing crashes, security and stability | GDPR Art. 6(1)(f) legitimate interests · KVKK Art. 5(2)(f) |
| Anonymous usage events | Measuring and improving the product | GDPR Art. 6(1)(f) legitimate interests · KVKK Art. 5(2)(f) |
| Support correspondence | Answering your request | GDPR Art. 6(1)(b) and 6(1)(f) · KVKK Art. 5(2)(c) and 5(2)(f) |
You have the right to object to the processing of crash and usage data, and the quickest way to exercise it is the Settings › Analytics switch. You may also write to destek@dodeyazilim.com.
5. Retention
| Data | Where | Kept for |
|---|---|---|
| Guest-mode rolls, frames, preferences | Your device only | Until you delete them or remove the app |
| Account, profile, rolls, memberships, frames and notes | Supabase (EU, Ireland) | Until the account is deleted. Deleting the account removes them permanently |
| Content reports | Supabase (EU, Ireland) | Up to 12 months after the review is closed; a report may be kept in anonymised form even after an account is deleted, so that repeated abuse can be tracked |
| Crash reports | Sentry (EU region) | 90 days maximum |
| Anonymous usage events | PostHog (EU Cloud) | 12 months maximum |
| Support correspondence | Our email provider | 24 months maximum |
At the end of these periods records are deleted or irreversibly aggregated.
6. Your rights
Under GDPR Art. 15-22 and KVKK Art. 11 you have the right to be informed, to access your data, to have it corrected or erased, to restrict processing, to object to processing, to receive your data in a portable format, and to seek compensation for damages.
Export your data as a JSON file from inside the app: Settings › Data › Export data. You can save the file or share it with any app you like.
Delete your account permanently from inside the app: Settings › Account › Delete account. Step by step: account and data deletion page.
You can change your display name and language preference in the app. For any other correction, write to our support address.
Turning off the analytics switch is the fastest way to object to crash and usage collection.
For a copy of the records we hold, write to our support address; we verify your identity through the email address on your account.
Requests are answered free of charge within 30 days at the latest.
If we do not act on your request or you are unhappy with our answer, you may lodge a complaint with your national data protection authority in the EU, or with the Turkish Personal Data Protection Authority (KVKK) in Türkiye.
7. User content: reporting and blocking
Because you can see frames shot by other people in account mode, the app carries two safeguards:
- Reporting content. You can report a frame, a person or a roll for nudity, violence, harassment, hate, illegal content, spam or another reason. The report is recorded on the server and reviewed. Content found to break the rules is removed, and the account behind it may be suspended or closed.
- Blocking a person. Once you block someone, their frames are never shown to you again. You can see and undo your blocks under Settings › Blocked people.
If you see unlawful content, use the in-app report flow; you can also write to destek@dodeyazilim.com.
8. Children's privacy
TripRoll is not directed at children under 13, and we do not knowingly collect data from anyone under 13. Where the age of digital consent in your country is higher (up to 16 in parts of the European Union), that higher age applies. If you believe a child's data has reached us, write to destek@dodeyazilim.com and we will delete the account and its records without delay. The app shows no advertising to anyone, children included.
9. Third-party processors
| Service | Role | Data processed | Hosting |
|---|---|---|---|
| Supabase (Supabase, Inc.) | Authentication, database and frame storage | Email address, account identifier, profile, rolls, memberships, frame files and notes, report and block records | European Union (AWS eu-west-1, Ireland) |
| Sentry (Functional Software, Inc.) | Crash and error monitoring | Stack traces, app/device versions, anonymous session id | European Union |
| PostHog (PostHog, Inc.) | Product analytics | Anonymous event names, platform, language, app version | European Union |
| Apple App Store / Google Play | Distribution and any purchases | Download, version and store-collected data | Apple and Google infrastructure |
Supabase, Sentry and PostHog act as processors on our documented instructions and are not permitted to use your data for their own purposes. A data processing agreement (DPA) is in place with all three, and all three are configured in the European Union region. Apple and Google act as independent controllers for their store services under their own privacy policies.
10. Server location and international transfers
Account, roll and frame data is hosted in the European Union (AWS eu-west-1, Ireland). Crash and analytics data is also held in the European Union region. Because these companies are headquartered in the United States, limited access from outside the EU can occur for purposes such as technical support. Such transfers are covered by the European Commission's Standard Contractual Clauses (SCCs) together with supplementary technical measures. Under KVKK, transfers abroad are made in line with the conditions set out in the applicable legislation, including your explicit consent where it is required.
11. Security
App data on your device is protected by the operating system's application sandbox and device encryption. Every request to and from the server is encrypted with TLS. The frame bucket is private and files are read only through short-lived signed links. Who can see which row and which file is defined in the database's row-level security policies rather than in app code; the client is never trusted. Administrative access is limited to the people who need it. No system is perfectly secure; if you find a vulnerability, please report it to destek@dodeyazilim.com.
12. Changes to this notice
This notice is updated as the app changes. The effective date at the top always identifies the current version. If an update materially changes how data is processed, we will announce it inside the app before it takes effect, and ask for your consent where that is required.
13. Contact
For anything related to privacy, including GDPR and KVKK requests:
This notice is provided for information; it is not legal advice.