Privacy Policy#
Effective Date: September 24, 2026
Last Updated: September 24, 2026
1. Introduction#
This Privacy Policy explains how MCCLabs ("we", "us", or "our") collects, uses, shares, retains, and protects personal information when you use the Timofy mobile application, the website at https://timofy.site, and related services (together, the "Service").
Timofy is a social app for sharing and keeping memories with the people who matter to you. The Service includes profiles, posts, 24-hour stories, direct messaging (including photos, videos, voice messages, and GIFs), a Memory Book, shared memories and memory games, a Memory Map, search, notifications, and optional paid subscriptions.
This Privacy Policy covers Timofy as published on Google Play by Mahmut Can Çönger. Please read it together with our Terms of Use, available at https://timofy.site/kullanim-kosullari.
If you do not agree with this Privacy Policy, please do not use the Service. Where applicable law requires your consent for a specific activity, we ask for it separately, and you can withdraw it at any time.
2. Who We Are and How to Contact Us#
- Data controller: MCCLabs, İstiklal Mahallesi, Piyaleoğlu Caddesi No: 141, Turgutlu, Manisa, Türkiye
- Privacy questions and data requests: destek@timofy.site
- General support: destek@timofy.site
- Child safety concerns: destek@timofy.site
- Website: https://timofy.site
For users in Türkiye, MCCLabs is the data controller (veri sorumlusu) under Personal Data Protection Law No. 6698 ("KVKK"). For users in the European Economic Area ("EEA"), the United Kingdom, and Switzerland, MCCLabs is the controller under the General Data Protection Regulation ("GDPR") and the UK GDPR. Where the law requires us to appoint a representative, their details are: Not appointed.
3. Summary of Key Points#
- We collect the information needed to run a social app: your account details, the content you create and send, and technical data that keeps the Service reliable and secure.
- We request device permissions (camera, microphone, location, photos and videos, notifications) only when you use a feature that needs them, and we explain why before Android shows its permission prompt.
- We do not sell your personal information, we do not show third-party ads, and we do not use your data for advertising.
- Your content and messages are encrypted in transit and at rest on our cloud infrastructure. Messages are not end-to-end encrypted.
- You can download a copy of your data, turn off analytics and crash reporting, and delete your account at any time, either in the app or at https://timofy.site/hesap-silme without reinstalling the app.
- Timofy is not directed to children. You must be at least 13 years old to use it.
4. Information We Collect#
4.1 Account and Profile Information#
- Registration details: your email address and password when you register with email. Passwords are handled by Firebase Authentication and stored only in hashed form; we never see them in plain text.
- Google Sign-In: if you choose to sign in with Google, we receive your name, email address, profile photo, and Google account identifier, as allowed by the permissions you approve on Google's consent screen.
- Profile: your username, display name, profile photo, bio, and any other profile details you choose to add.
- Account identifiers: a unique user ID that we assign to your account.
- Settings and preferences: account privacy (public or private), story audience and close-friends lists, who can interact with you, read receipt settings, notification preferences and quiet hours, muted and blocked accounts, hidden authors, language, and theme.
4.2 Content You Create and Share#
- Posts: photos, videos, captions, and the audience you choose.
- Stories: photos, videos, text, stickers, any location you add, and the list of people who viewed your story.
- Interactions: comments, likes, reactions, saves, and shares.
- Memory features: Memory Book entries you save from messages and comments, your notes and custom categories, shared memories, time capsules, memory games and their results, and collages or covers generated in the app.
- GIFs: GIF favorites and collections you save.
- Reports: reports you submit about content or users, including the reason you select.
Your content may include information about other people (for example, a person in a photo). Please share content about others only when you have the right to do so.
4.3 Messages and Communications#
- Direct messages: text, photos, videos, voice messages, GIFs, reactions, and posts or profiles you share in a conversation.
- Message metadata: sender and recipients, timestamps, delivery and read status (where enabled), typing indicators, unread counts, and conversation settings such as muted or cleared chats.
- Communications with us: the content of support emails, feedback, and our replies.
- Transactional emails: we send service emails, such as password reset messages, to the email address on your account.
Messages are stored on our servers so they can be delivered and synced across your devices. Clearing a conversation removes it from your view only; the other participant keeps their copy.
4.4 Location Information#
- Device location: precise or approximate location, collected only when you choose to use a location feature (for example, adding a location to a post or story, choosing a place on the map, or searching for nearby places) and only after you grant permission. On Android 12 and later, you can choose to share approximate location instead of precise location.
- Places you select: the name, address, and coordinates of a place you attach to your content.
- Photo location metadata: when you upload a photo, the app reads its embedded metadata, such as the capture date and, if present, GPS coordinates. We remove GPS coordinates from the image file before it is uploaded. If a feature uses a photo's location (for example, placing a memory on your Memory Map), the coordinates are stored separately in our access-controlled database and shown only in line with your privacy settings.
- IP-based location: our infrastructure and service providers may infer an approximate location (such as country or city) from your IP address for security, fraud prevention, and aggregated statistics.
We never collect your location in the background.
4.5 Photos, Videos, and Audio on Your Device#
- We access only the photos and videos you select or capture with the in-app camera. On supported Android versions, you can grant access to selected photos and videos only.
- We record audio only while you are actively recording a voice message or a video with sound.
- We do not scan your gallery, and we never upload media you have not chosen to share. Before upload, images are resized and compressed on your device.
4.6 Purchases and Subscriptions#
- Payments are processed by Google Play. We do not receive or store your full payment card details.
- We receive purchase information from Google Play and from our subscription management provider, RevenueCat: product and subscription identifiers, purchase tokens, transaction dates, price and currency, and renewal, cancellation, or refund status. This information is linked to your account so we can provide the features you paid for.
- We keep a record of your plan and related entitlements, such as your storage allowance.
4.7 Information Collected Automatically#
- Device and app information: device model and manufacturer, operating system version, app version and build, language, time zone, and network type.
- Identifiers: Firebase installation ID, Google Analytics for Firebase app instance ID, push notification token, subscription customer ID, and app integrity tokens (Firebase App Check with Google Play Integrity).
- Usage information (app activity): features and screens you use, interactions, session information, and searches you perform in the app.
- Crash logs and diagnostics: crash stack traces, device state at the time of a crash, app version, and your user ID, so we can fix problems affecting your account. Diagnostic information you choose to send from the in-app Diagnostics screen.
- Performance data: app start-up time, screen rendering, and network request performance.
- Server logs: IP address, request times, and error information recorded by our cloud infrastructure.
- Derived information: signals we calculate from your activity with other users, such as bond scores, top-friends statistics, and "For You" recommendations, used to personalize features in the app.
You can turn off analytics and crash reporting at any time in Settings > Privacy and Data.
4.8 Information From Other Users and Third Parties#
- Other users may provide information about you, for example when they mention or tag you, send you a message, add you to a close-friends list, share your content, or report your account.
- Google provides sign-in information if you use Google Sign-In, and purchase information through Google Play.
- RevenueCat provides subscription status information.
4.9 Information We Do Not Collect#
- We do not access your contacts, call logs, or SMS messages.
- We do not collect location in the background.
- We do not receive your full payment card details.
- We do not use facial recognition or collect biometric data.
- We do not use advertising identifiers for advertising or ad personalization.
5. How We Use Your Information#
- Provide and operate the Service: create and authenticate your account, display your profile, publish your content to the audience you choose, deliver your messages, and sync data across devices.
- Personalize your experience: organize your feed, suggest content and people, calculate bond scores and top-friends statistics, and resurface past memories.
- Send notifications: deliver push and in-app notifications according to your notification preferences and quiet hours.
- Enable search: index usernames, display names, profile photos, and posts that are eligible to appear in search, so people can find each other and content.
- Process purchases: verify subscriptions, grant entitlements, and manage storage allowances.
- Keep the Service safe: verify that requests come from genuine copies of the app; detect and prevent spam, fraud, and abuse; review reports; and enforce our Terms of Use.
- Maintain and improve the Service: diagnose crashes, monitor performance, and understand in aggregate how features are used.
- Communicate with you: send service messages, password reset emails, replies to support requests, and notices about important changes.
- Honor your requests: fulfil data export, correction, and deletion requests.
- Comply with the law: meet legal obligations such as tax and accounting requirements, respond to lawful requests, and establish, exercise, or defend legal claims.
We do not use your personal information for third-party advertising, and we do not make decisions that produce legal or similarly significant effects about you based solely on automated processing.
6. Legal Bases for Processing (EEA, UK, and Türkiye)#
- Performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)): to provide the Service you signed up for, including your account, content, messaging, and subscriptions.
- Legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)): to keep the Service secure, prevent abuse, personalize features, and improve the app through analytics and crash reporting. You can object at any time, including by turning off analytics and crash reporting in the app.
- Consent (GDPR Art. 6(1)(a); KVKK Art. 5(1)): for optional processing that requires it, such as access to your device location. You can withdraw consent at any time; this does not affect processing carried out before you withdrew it.
- Legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)): to meet tax, accounting, and other legal requirements and to respond to lawful requests.
- Establishing, exercising, or defending legal claims (GDPR Art. 6(1)(f); KVKK Art. 5(2)(e)).
7. App Permissions and Prominent Disclosure#
7.1 How We Request Permissions#
- In context: we request a permission only when you start using a feature that needs it, not all at once when you first open the app.
- Disclosure first: before Android shows its permission prompt for camera, microphone, location, or media access, Timofy shows an in-app notice explaining what data will be accessed, why, and whether it will leave your device. You can continue or decline.
- Your choice: if you decline, the rest of the app keeps working; only the feature that needs the permission is unavailable.
- Minimum access: we request the narrowest access that makes a feature work, and we never use the camera, microphone, or location in the background.
7.2 Camera#
- Permission:
android.permission.CAMERA - When we ask: when you open the in-app camera to take a photo or video for a post, story, message, or profile photo.
- What we access: the camera feed, only while the camera screen is open.
- How it is used and shared: only the photos and videos you choose to share are uploaded, and they are shown only to the audience you select.
7.3 Microphone#
- Permission:
android.permission.RECORD_AUDIO - When we ask: the first time you record a voice message or a video with sound.
- What we access: audio, only while you are actively recording.
- How it is used and shared: recordings are uploaded only when you send or post them, and are shared only with the recipients or audience you choose.
7.4 Location#
- Permissions:
android.permission.ACCESS_FINE_LOCATION(precise) andandroid.permission.ACCESS_COARSE_LOCATION(approximate) - When we ask: when you choose to add a location to a post or story, open the map, or search for nearby places.
- Precise or approximate: approximate location is enough to show your general area. Precise location is used only to suggest nearby places accurately. You can choose approximate location in Android's prompt.
- How it is used and shared: your coordinates are sent to our map and place-search providers (MapTiler and Foursquare) to display maps, convert coordinates into place names, and list nearby places. A location you attach to content is visible to that content's audience.
- Limits: location is accessed only while you use these features, never in the background, and never for advertising.
7.5 Photos and Videos#
- Permissions:
android.permission.READ_MEDIA_IMAGES,android.permission.READ_MEDIA_VIDEO, andandroid.permission.READ_MEDIA_VISUAL_USER_SELECTED(Android 13 and later);android.permission.READ_EXTERNAL_STORAGE(Android 12 and earlier) - When we ask: when you choose photos or videos from your gallery for a post, story, message, or profile photo.
- Selected access: on Android 14 and later, you can allow access to selected photos and videos only.
- How it is used and shared: only the items you select are uploaded. We read the metadata of selected items as described in Section 4.4.
7.6 Notifications#
- Permission:
android.permission.POST_NOTIFICATIONS(Android 13 and later) - Purpose: to notify you about messages, comments, follows, memories, and other activity. You can choose notification types and quiet hours in the app, and you can turn notifications off in Android settings.
7.7 Network Access#
- Permissions:
android.permission.INTERNETandandroid.permission.ACCESS_NETWORK_STATE - Purpose: these standard permissions are granted automatically. They let the app connect to our servers and adapt media quality to your connection.
7.8 Managing Permissions#
You can review or revoke permissions at any time in Android Settings > Apps > Timofy > Permissions. Revoking a permission stops future access; it does not delete content you have already shared. To delete that content, see Section 11.
8. How We Share Your Information#
8.1 With Other Users#
- Profile information: your username, display name, and profile photo are visible to other users and can appear in search results, even if your account is private.
- Content: posts and stories are visible to the audience you choose (for example, everyone, your followers, or your close friends). If your account is private, only approved followers can see your posts.
- Messages: messages are visible to the participants of the conversation.
- Activity: depending on your settings, others may see that you read a message, are typing, viewed their story, or reacted to their content.
- Shared features: shared memories, memory games, and their results are visible to the participants.
- Links: you and others can share links to posts, profiles, stories, and memories. Content opened through a link remains subject to its visibility settings.
Other users can copy, screenshot, or re-share content they can see. Please think carefully before sharing.
8.2 With Service Providers#
We share information with service providers that process it on our behalf under contracts requiring them to protect it and to use it only to provide their services to us. These include providers of cloud hosting, databases, file storage, authentication, message and notification delivery, analytics, crash reporting, search, subscription management, email delivery, maps and places, and GIFs. Section 9 lists them.
8.3 For Legal, Safety, and Business Reasons#
- Legal requirements: when we believe in good faith that disclosure is required by law, regulation, legal process, or an enforceable governmental request.
- Safety: to protect the rights, property, or safety of our users, the public, or MCCLabs, including reporting child sexual abuse material to the National Center for Missing & Exploited Children (NCMEC) and other competent authorities.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Privacy Policy. We will notify you before your information becomes subject to a different privacy policy.
- With your consent or at your direction.
8.4 No Sale of Personal Information and No Advertising#
- We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law.
- The app contains no third-party advertising SDKs, and we do not show ads.
- Google Analytics for Firebase is configured with advertising storage, ad user data, and ad personalization turned off.
9. Third-Party Services and SDKs#
Each provider below processes data under its own privacy policy and, where it acts on our behalf, under a data processing agreement with us.
9.1 Google Firebase and Google Cloud#
- Services: Firebase Authentication, Cloud Firestore, Firebase Realtime Database, Cloud Storage for Firebase, Cloud Functions for Firebase, Firebase Cloud Messaging, Firebase Remote Config, and Firebase App Check
- Data processed: account and profile data, content, messages, uploaded media, identifiers, push notification tokens, app integrity signals, and server logs
- Purpose: hosting, database, file storage, authentication, real-time features, notifications, remote configuration, and protecting our backend from abuse
- Privacy information: https://firebase.google.com/support/privacy and https://policies.google.com/privacy
9.2 Google Analytics for Firebase#
- Data processed: app instance ID, user ID, app interactions, device information, and approximate location derived from IP address
- Purpose: aggregated usage analytics that help us understand and improve features
- Your control: you can turn it off in Settings > Privacy and Data. Advertising features are disabled.
- Privacy information: https://policies.google.com/privacy
9.3 Firebase Crashlytics#
- Data processed: crash logs, stack traces, device state, installation ID, and user ID
- Purpose: detecting and fixing crashes and stability problems
- Your control: you can turn it off in Settings > Privacy and Data.
- Privacy information: https://firebase.google.com/support/privacy
9.4 Firebase Performance Monitoring#
- Data processed: performance traces (app start-up, screen rendering, and network request timing), device information, and installation ID
- Purpose: monitoring and improving speed and reliability
- Privacy information: https://firebase.google.com/support/privacy
9.5 Google Sign-In and Google Play Services#
- Services: Google Sign-In (through Android Credential Manager), Google Play Billing, Google Play Integrity, and Google Play services location
- Data processed: Google account information you authorize, purchase information, device integrity signals, and location when you use location features
- Purpose: sign-in, payments, app integrity checks, and location features
- Privacy information: https://policies.google.com/privacy
9.6 RevenueCat#
- Data processed: subscription customer ID linked to your user ID, purchase and subscription history, device and app information, and IP address
- Purpose: managing subscriptions and verifying purchase status
- Privacy information: https://www.revenuecat.com/privacy/
9.7 Algolia#
- Data processed: usernames, display names, profile photo links, content eligible to appear in search, search queries, and IP address
- Purpose: fast search for people and content
- Privacy information: https://www.algolia.com/policies/privacy
9.8 GIPHY and Tenor#
- Data processed: GIF search terms, IP address, and device and app information included in requests
- Purpose: searching for and displaying GIFs in messages and content
- Privacy information: GIPHY: https://giphy.com/privacy; Tenor (a Google service): https://policies.google.com/privacy
9.9 MapTiler, CARTO, and MapLibre#
- Data processed: the map area being displayed, coordinates or place search text for geocoding, and IP address
- Purpose: displaying maps and converting coordinates into place names
- Note: MapLibre is an open-source map-rendering library that runs on your device and does not send data to the MapLibre project. Map tiles are loaded from MapTiler and CARTO.
- Privacy information: MapTiler: https://www.maptiler.com/privacy-policy/; CARTO: https://carto.com/privacy
9.10 Foursquare#
- Data processed: coordinates and search text for places near you, and IP address
- Purpose: suggesting nearby places you can attach to your content
- Privacy information: https://foursquare.com/legal/privacy/
9.11 Resend#
- Data processed: your email address and the content of the service email
- Purpose: delivering transactional emails such as password reset messages
- Privacy information: https://resend.com/legal/privacy-policy
We will update this list when we add or change service providers.
10. Google Play Data Safety Alignment#
The Data Safety section of our Google Play listing is based on this Privacy Policy and describes the same practices.
10.1 Data Types We Collect#
- Personal info: name (optional), email address (required), user IDs (required)
- Financial info: purchase history (only if you make a purchase)
- Location: approximate location and precise location (optional; only when you use location features)
- Messages: other in-app messages (optional; only when you use messaging)
- Photos and videos: photos and videos you choose to share (optional)
- Audio: voice or sound recordings, such as voice messages and videos with sound (optional)
- App activity: app interactions, in-app search history, and other user-generated content
- App info and performance: crash logs, diagnostics, and other app performance data (you can turn off analytics and crash reporting)
- Device or other IDs: Firebase installation ID, app instance ID, and push notification token
10.2 Why We Collect Data#
App functionality, analytics, developer communications, fraud prevention, security and compliance, personalization, and account management. We do not collect or use data for advertising or marketing.
10.3 Data Sharing#
We do not sell user data. Under Google Play's definitions, data processed by service providers on our behalf (Section 9), transfers you initiate (such as sending a message to another user), and disclosures required by law are not considered "sharing". Any data that a third party processes under its own terms (for example, search terms sent to GIF providers) is declared as shared in our Data Safety section.
10.4 Security Practices#
- Data is encrypted in transit using TLS.
- You can request deletion of your data in the app or at https://timofy.site/hesap-silme.
- Location, audio, photos, videos, and messages are collected only when you use the related features.
If you notice a difference between this Privacy Policy and our Data Safety section, please let us know at destek@timofy.site.
11. Data Retention and Deletion Policy#
11.1 How Long We Keep Your Information#
We keep personal information only for as long as we need it for the purposes described in this Privacy Policy.
- Account and profile information: for as long as your account is active.
- Posts, comments, Memory Book entries, and other content: until you delete them or delete your account.
- Stories: shown to your audience for 24 hours. After that they are no longer visible to others, but they remain stored in your account until you delete them or delete your account.
- Messages and voice messages: kept so that participants can access their conversation history, until the conversation is deleted. Clearing a chat hides it for you only. When a participant deletes their account, the conversation is deleted for all participants.
- Search index entries: updated when you change your profile or delete content, and removed when you delete your account.
- Data export files: the download link is valid for 7 days, and the file is deleted automatically after 8 days.
- Crash reports: 90 days.
- Analytics data: user-level and event-level data are kept for 2 months; aggregated reports that do not identify you may be kept longer.
- Server logs: 30 days.
- Reports and moderation records: 2 years, or longer where needed to address an ongoing safety issue or a legal obligation.
- Purchase and transaction records: 10 years, as required by tax and accounting laws.
- Backups: deleted data is removed from our backups within 30 days.
We may keep information longer when the law requires it or when it is needed to resolve disputes, enforce our agreements, or protect safety (for example, under a legal hold).
11.2 How to Delete Your Account in the App#
- Step 1: Open Timofy and sign in.
- Step 2: Go to Settings > Delete my account.
- Step 3: Confirm by typing your username when asked.
Deletion starts immediately and cannot be undone. Download a copy of your data first if you want to keep it (see Section 12).
11.3 How to Request Deletion Without the App#
If you no longer have the app or cannot sign in, you can request deletion of your account and associated data at https://timofy.site/hesap-silme. You do not need to reinstall the app.
- Open https://timofy.site/hesap-silme and use the deletion request button there, or email destek@timofy.site directly from the email address registered to your account with the subject "Account Deletion Request".
- Include the email address and username associated with your account.
- To protect you from unauthorized deletion, we will verify that you control the account, for example by sending a confirmation link to your registered email address.
- We complete deletion within 30 days of verification and confirm by email.
11.4 What We Delete#
When your account is deleted, we delete:
- your sign-in credentials and authentication record;
- your profile, username, settings, Memory Book entries, and other data stored under your account;
- your posts, including the comments and likes on them;
- your stories and their viewer lists;
- your follow relationships and friend requests, and your user ID from other users' follower, following, block, mute, and hidden lists;
- conversations you took part in, including their messages, media, and voice messages, for all participants;
- photos, videos, profile photos, and other files you uploaded;
- your profile and posts in our search index.
11.5 Information We May Keep After Deletion#
- Interactions on other people's content: comments or reactions you left on other users' posts, and records of stories you viewed, may remain and will appear as coming from a deleted account. You can delete your comments individually before deleting your account.
- Reports and moderation records: for the period in Section 11.1, to protect users from abuse and to meet legal obligations.
- Purchase records: held by us, Google Play, and RevenueCat as required for tax, accounting, and fraud prevention.
- Analytics and crash data: for the periods in Section 11.1, associated with pseudonymous identifiers.
- Backups: residual copies until they are removed as described in Section 11.1.
- Legal requirements: information we must keep by law or to establish, exercise, or defend legal claims.
- Copies held by others: content other users saved, copied, or captured (for example, screenshots), which we cannot control.
11.6 Deleting Specific Data Without Deleting Your Account#
- Delete individual posts, stories, comments, and Memory Book entries from their menus.
- Clear a conversation from your own view.
- Edit or remove profile information at any time.
- Turn off analytics and crash reporting in Settings > Privacy and Data.
- Ask us to delete specific data without deleting your account by contacting destek@timofy.site or using https://timofy.site/hesap-silme.
11.7 Subscriptions Are Not Cancelled Automatically#
Deleting your account does not cancel an active Google Play subscription. To avoid further charges, cancel it in the Google Play Store under Profile > Payments & subscriptions > Subscriptions before you delete your account.
12. Your Privacy Choices and Controls#
- Account privacy: make your account private, choose your story audience, and manage close-friends lists.
- Interactions: control who can interact with you and whether read receipts are shown.
- Safety tools: block, mute, or hide accounts at any time.
- Notifications: choose notification types and set quiet hours.
- Analytics and crash reporting: turn them on or off in Settings > Privacy and Data.
- Device permissions: grant or revoke them in Android settings (see Section 7.8).
- Data export: download a copy of your data from Settings > Privacy and Data. The export is a machine-readable JSON file containing your profile, settings, posts, stories, and the messages you sent. You can request a new export once every 24 hours.
13. Your Rights#
13.1 Rights Available to All Users#
Wherever you live, you can access, download, correct, and delete your personal information using the tools in the app or by contacting us at destek@timofy.site.
13.2 EEA, UK, and Switzerland#
You have the right to:
- access your personal data;
- have inaccurate data corrected;
- have your data erased;
- restrict processing;
- receive your data in a portable format;
- object to processing based on legitimate interests;
- withdraw consent at any time;
- lodge a complaint with your local data protection supervisory authority.
13.3 Türkiye (KVKK)#
Under Article 11 of KVKK, you have the right to:
- learn whether your personal data is processed;
- request information about the processing;
- learn the purpose of the processing and whether data is used for that purpose;
- know the third parties in Türkiye or abroad to whom your data is transferred;
- request correction of incomplete or inaccurate data;
- request erasure or destruction of your data under the conditions in Article 7 of KVKK;
- request that third parties to whom your data was transferred be notified of any correction or erasure;
- object to a result that is against you and arises from analysis made exclusively through automated systems;
- claim compensation for damages arising from unlawful processing.
You can send your request in writing to İstiklal Mahallesi, Piyaleoğlu Caddesi No: 141, Turgutlu, Manisa, Türkiye, by registered electronic mail (KEP), with a secure electronic or mobile signature, or from the email address registered in your Timofy account to destek@timofy.site, as provided in the Communiqué on the Procedures and Principles of Application to the Data Controller. We respond within 30 days, free of charge, unless the response involves an additional cost under the tariff set by the Personal Data Protection Board. You may also file a complaint with the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu).
13.4 California and Other U.S. States#
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, "CCPA"), gives you the right to:
- know the categories and specific pieces of personal information we have collected about you;
- delete personal information;
- correct inaccurate personal information;
- opt out of the sale or sharing of personal information (we do not sell or share personal information);
- limit the use of sensitive personal information (we use sensitive personal information only as needed to provide the Service);
- not be discriminated against for exercising these rights.
In the past 12 months we have collected the following categories of personal information, from the sources and for the purposes described in Sections 4 and 5: identifiers; customer records; commercial information (purchase history); internet or other electronic network activity; geolocation data; audio and visual information; inferences used to personalize the Service; and sensitive personal information (account login credentials, precise geolocation, and the contents of messages). We disclose these categories only to the service providers and in the circumstances described in Sections 8 and 9.
Residents of other U.S. states with comprehensive privacy laws (such as Virginia, Colorado, Connecticut, Oregon, and Texas) have similar rights. If we deny your request, you can appeal by emailing destek@timofy.site with the subject "Privacy Request Appeal".
You may use an authorized agent to submit a request on your behalf. We may ask the agent for proof of authorization and ask you to verify your identity directly with us.
13.5 How to Exercise Your Rights#
- Use the in-app tools described in Sections 11 and 12, or contact destek@timofy.site.
- We will verify your identity before acting on a request, usually by confirming control of the email address registered to your account.
- We respond within the time required by applicable law (for example, one month under the GDPR, 30 days under KVKK, and 45 days under the CCPA). If we need more time, we will tell you why.
14. Data Security#
We use administrative, technical, and organizational measures designed to protect your information, including:
- encryption in transit using TLS and encryption at rest provided by our cloud infrastructure;
- database and storage security rules that limit each user to the data they are permitted to access;
- app integrity checks (Firebase App Check with Google Play Integrity) that help block requests from modified or unauthorized apps;
- time-limited, signed links for data exports and voice message uploads;
- removal of GPS coordinates from uploaded image files;
- access to administrative tools limited to authorized personnel.
Messages are not end-to-end encrypted. Authorized personnel access message content only where necessary to investigate reports of abuse, protect safety, keep the Service secure, or comply with the law.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please use a strong, unique password and keep your sign-in details private. If a data breach affects your personal information, we will notify you and the relevant authorities as required by law.
15. International Data Transfers#
MCCLabs is based in Türkiye. Our primary data is stored in the United States (Google Cloud region us-central1), and our service providers may process personal information in other countries, including the United States and member states of the EEA.
When we transfer personal information across borders, we rely on appropriate safeguards, such as:
- adequacy decisions;
- the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum;
- the EU-U.S. Data Privacy Framework, where the recipient is certified;
- for data transferred from Türkiye, the mechanisms in Article 9 of KVKK, including adequacy decisions, standard contracts notified to the Personal Data Protection Authority, and, for occasional transfers, the exceptions set out in that Article.
You can ask for more information about these safeguards at destek@timofy.site.
16. Children's Privacy#
- Minimum age: Timofy is not directed to children. You must be at least 13 years old, and at least the minimum age of digital consent in your country (up to 16 in some EEA countries), to create an account.
- COPPA: we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, or from a child below the applicable age of digital consent without the required parental consent, we will delete the account and associated data promptly.
- Google Play Families Policy: the target audience declared for Timofy in Google Play Console does not include children, and the app is not designed to appeal to children.
- Age assurance: where required by law, we may use age signals from app stores (such as Google Play) or other age assurance measures to apply age-appropriate protections or restrict access.
- Parents and guardians: if you believe a child has provided us with personal information, contact destek@timofy.site or destek@timofy.site and we will take prompt action.
- Child safety: we have zero tolerance for child sexual abuse and exploitation. Our Child Safety Standards are set out in Section 7 of our Terms of Use.
17. Links to Other Websites and Services#
The Service may contain links to, or content from, websites and services operated by third parties. We are not responsible for their privacy practices. Please review their privacy policies before sharing information with them.
18. Changes to This Privacy Policy#
We may update this Privacy Policy from time to time. When we do, we will change the "Last Updated" date at the top. If we make material changes, we will notify you in the app or by email at least 15 days before they take effect, and we will ask for your consent where the law requires it.
19. Contact Us#
- Company: MCCLabs
- Address: İstiklal Mahallesi, Piyaleoğlu Caddesi No: 141, Turgutlu, Manisa, Türkiye
- Privacy and data requests: destek@timofy.site
- Support: destek@timofy.site
- Child safety: destek@timofy.site
- Account deletion: https://timofy.site/hesap-silme
- Website: https://timofy.site