1. Özet
1. Summary
Chromasel, bir Android boyama uygulamasıdır. Bu politika, uygulamanın hangi verileri topladığını, neden topladığını ve nasıl koruduğunu açıklar.
Chromasel is an Android coloring application. This policy explains what data the app collects, why it collects it, and how it is protected.
2. Topladığımız Veriler
2. Data We Collect
Google Hesabı ile Giriş (İsteğe Bağlı)
Google hesabınızla giriş yaptığınızda, Google Sign-In aracılığıyla aşağıdaki veriler alınır:
- Ad ve soyadınız — karşılama ve profil için
- E-posta adresiniz — hesap tanımlaması için
- Profil fotoğraf URL'si — profil için (fotoğraf indirilmez, yalnızca bağlantı)
- Firebase UID — verilerinizi hesabınıza bağlamak için
Bu veriler Firebase Authentication sunucularında (Google altyapısı) saklanır. Üçüncü taraflarla paylaşılmaz (aşağıdaki bölümler hariç).
Misafir Kullanımı
Giriş yapmadan kullandığınızda, yalnızca cihazınızda rastgele oluşturulan anonim bir kimlik (local_XXXXXXXX) kullanılır. Bu kimlik, boyama ilerlemenizi yerel olarak saklamak için kullanılır ve sunucuya gönderilmez.
Boyama İlerlemesi ve Uygulama Etkinliği
Giriş yapmış kullanıcılar için aşağıdaki veriler Firebase'e bulut yedekleme amaçlı senkronize edilir:
- Tamamlanan boyamalar listesi
- XP puanı, seviye, günlük ve haftalık seriler (streak)
- Boyama ilerlemesi (renk verileri) ve küçük resimler
- Tema, dil ve müzik tercihleri
Misafir kullanıcılarda bu veriler yalnızca cihazda tutulur.
Kullanıcı Yüklemeleri (İsteğe Bağlı)
Kendi fotoğrafınızı boyama sayfasına dönüştürmek için yüklediğinizde:
- Görsel Firebase Cloud Storage'a yüklenir (
users/{uid}/progress/) - AI dönüştürmeyi seçerseniz görsel Google Gemini API'ye gönderilir (bkz. Bölüm 8)
Satın Alma / Premium
Premium satın aldığınızda abonelik durumu (aktif/sona ermiş, ürün ID) RevenueCat aracılığıyla doğrulanır ve Firebase'e kaydedilir. Google Play'in kendi satın alma kaydı doğrudan Google tarafından tutulur.
Yerel Cihaz Verileri
Cihazınızda (AsyncStorage) saklanan, sunucuya gönderilmeyen veriler:
- Yaş kategorisi (bucket): CHILD / TEEN / ADULT / UNKNOWN
- Bildirim tercihi
- Reklam tamamlanma sayacı
- Ücretsiz AI dönüştürme günlük sayacı
- Tema sesi tercihi
Sign-in with Google (Optional)
When you sign in with your Google account, the following information is received via Google Sign-In:
- Your display name — for greetings and profile
- Your email address — for account identification
- Profile photo URL — for profile display (photo not downloaded, only the link)
- Firebase UID — to link your data to your account
These are stored in Firebase Authentication servers (Google infrastructure). They are not shared with third parties (except as described in the sections below).
Guest Mode
When used without signing in, only a randomly generated anonymous identifier (local_XXXXXXXX) is used on your device. This identifier is used to save your coloring progress locally and is not sent to any server.
Coloring Progress and App Activity
For signed-in users, the following data is synced to Firebase for cloud backup:
- List of completed colorings
- XP points, level, daily and weekly streaks
- Coloring progress (pixel data) and thumbnails
- Theme, language, and music preferences
For guest users, this data is stored on-device only.
User Uploads (Optional)
When you upload your own photo to convert into a coloring page:
- The image is uploaded to Firebase Cloud Storage (
users/{uid}/progress/) - If you select AI conversion, the image is sent to Google Gemini API (see Section 8)
Purchases / Premium
When you purchase premium, the subscription status (active/expired, product ID) is verified through RevenueCat and stored in Firebase. Google Play's own purchase record is maintained directly by Google.
Local Device Data
Data stored locally on your device (AsyncStorage), not sent to any server:
- Age category (bucket): CHILD / TEEN / ADULT / UNKNOWN
- Notification preference
- Ad completion counter
- Free daily AI conversion counter
- Theme audio preference
3. Üçüncü Taraf Hizmetler
3. Third-Party Services
Uygulama aşağıdaki üçüncü taraf hizmetlerini kullanmaktadır. Her biri kendi gizlilik politikasına tabidir.
| Hizmet | Sağlayıcı | Amaç | Gönderilen Veri |
|---|---|---|---|
| Firebase Authentication | Google LLC | Hesap yönetimi | E-posta, ad, Google UID |
| Firestore | Google LLC | Bulut yedekleme | Oyun durumu, ilerleme meta |
| Cloud Storage | Google LLC | Dosya depolama | Boyama dosyaları, küçük resimler |
| Google Sign-In | Google LLC | Kimlik doğrulama | OAuth token (geçici) |
| Google AdMob | Google LLC | Reklam gösterimi | Reklam tanımlayıcısı (yetişkin, rıza ile) |
| Google UMP | Google LLC | GDPR/CCPA rıza | Rıza kararı |
| Google Gemini API | Google LLC | AI görsel dönüştürme | Kullanıcı fotoğrafı (base64), yalnızca AI kullanımında |
| RevenueCat | RevenueCat, Inc. | Abonelik yönetimi | Firebase UID, satın alma durumu |
| expo-notifications / FCM | Google LLC | Yerel bildirim altyapısı | Bildirim tokeni (cihaz tanımlayıcısı) |
The app uses the following third-party services. Each is subject to its own privacy policy.
| Service | Provider | Purpose | Data Sent |
|---|---|---|---|
| Firebase Authentication | Google LLC | Account management | Email, name, Google UID |
| Firestore | Google LLC | Cloud backup | Game state, progress metadata |
| Cloud Storage | Google LLC | File storage | Coloring files, thumbnails |
| Google Sign-In | Google LLC | Authentication | OAuth token (temporary) |
| Google AdMob | Google LLC | Ad display | Ad identifier (adult users, with consent) |
| Google UMP | Google LLC | GDPR/CCPA consent | Consent decision |
| Google Gemini API | Google LLC | AI image conversion | User photo (base64), only when AI feature is used |
| RevenueCat | RevenueCat, Inc. | Subscription management | Firebase UID, purchase status |
| expo-notifications / FCM | Google LLC | Local notification infrastructure | Notification token (device identifier) |
4. Çocuk ve Genç Koruması
4. Child and Teen Safety
Chromasel, her yaştan kullanıcıya hitap eden bir boyama uygulamasıdır. Çocuk ve genç kullanıcılar için güçlü korumalar uygulanmaktadır:
- Yaş ekranında ÇOCUK veya BILINMIYOR kategorisi saptandığında AdMob
tagForChildDirectedTreatment: trueolarak ayarlanır → Reklam kimliği (GAID) kullanılmaz. - GENÇ kategorisinde
tagForUnderAgeOfConsent: trueayarlanır. - Tüm kategoriler için maksimum reklam içerik derecelendirmesi
G(herkese uygun) olarak sabitlenmiştir. - ÇOCUK ve GENÇ kullanıcılara GDPR rıza akışı gösterilmez.
- Kişiselleştirilmiş reklam hiçbir kullanıcı kategorisi için kullanılmaz (
requestNonPersonalizedAdsOnly: true). - Çocuklardan Google hesap bilgisi veya kişisel veri toplanmaz.
Chromasel is a coloring app for users of all ages. Strong protections are in place for child and teen users:
- When the CHILD or UNKNOWN category is detected at the age gate, AdMob is configured with
tagForChildDirectedTreatment: true→ No ad identifier (GAID) is used. - For the TEEN category,
tagForUnderAgeOfConsent: trueis set. - The maximum ad content rating is fixed at
G(suitable for all) for all categories. - The GDPR consent flow is not shown to CHILD or TEEN users.
- Personalized advertising is not used for any user category (
requestNonPersonalizedAdsOnly: true). - No Google account information or personal data is collected from children.
5. Yaş Ekranı ve Doğum Tarihi
5. Age Gate and Date of Birth
Uygulama ilk açıldığında bir yaş ekranı gösterilir. Bu ekranda gün, ay ve yıl bilgisi girmeniz istenir.
Yalnızca türetilmiş yaş kategorisi (ÇOCUK / GENÇ / YETİŞKİN / BILINMIYOR) cihazınızdaki yerel depolamada tutulur. Bu kategori, reklamları yaşa uygun şekilde yapılandırmak ve içerik ayarları için kullanılır.
Doğum tarihi bilgisi analitik verilerine, loglara veya herhangi bir sunucuya gönderilmez. Tam yaş da dahil olmak üzere hiçbir şekilde saklanmaz.
An age gate screen is shown when the app is first opened. You are asked to enter your day, month, and year of birth.
Only the derived age category (CHILD / TEEN / ADULT / UNKNOWN) is kept in local storage on your device. This category is used to configure age-appropriate advertising and content settings.
Date of birth information is not sent to analytics, logs, or any server. Neither the full date nor the exact age is stored in any form.
6. Reklam ve Rıza
6. Advertising and Consent
Uygulama, ücretsiz kullanıcılara Google AdMob aracılığıyla reklam göstermektedir (banner, geçiş reklamı, ödüllü reklam).
- Yetişkin kullanıcılar: Google'ın UMP (Kullanıcı Mesajlaşma Platformu) aracılığıyla GDPR/CCPA uyumlu rıza alınır.
- Çocuk / Genç kullanıcılar: Rıza akışı gösterilmez; reklam kimliği kullanılmaz.
- Kişiselleştirilmiş reklam: Tüm kullanıcılar için devre dışı. Uygulama her zaman
requestNonPersonalizedAdsOnly: truekullanır. - Premium kullanıcılar: Reklam gösterilmez.
Rıza tercihlerinizi Ayarlar → Reklam Gizlilik Tercihleri bölümünden güncelleyebilirsiniz (GDPR kapsamındaki yetişkin kullanıcılar için).
The app shows ads to free users via Google AdMob (banner, interstitial, rewarded ads).
- Adult users: GDPR/CCPA-compliant consent is obtained via Google's UMP (User Messaging Platform).
- Child / Teen users: No consent flow is shown; no ad identifier is used.
- Personalized ads: Disabled for all users. The app always uses
requestNonPersonalizedAdsOnly: true. - Premium users: No ads are shown.
You can update your consent preferences via Settings → Ad Privacy Preferences (for adult users within GDPR scope).
7. Bildirimler
7. Notifications
Chromasel yalnızca yerel bildirimler kullanır (3 gün ve 7 gün hareketsizlik hatırlatıcısı). Uzak sunucudan push bildirimi gönderilmez.
Bildirimler için POST_NOTIFICATIONS izni istenir. Bu izni reddedebilir veya Ayarlar'dan devre dışı bırakabilirsiniz.
Chromasel uses only local notifications (3-day and 7-day inactivity reminders). No server-side push notifications are sent.
The POST_NOTIFICATIONS permission is requested for notifications. You can deny this permission or disable it in Settings.
8. AI Görsel Dönüştürme (Gemini)
8. AI Image Conversion (Gemini)
Kendi fotoğrafınızı boyama sayfasına dönüştürmek için AI özelliğini kullandığınızda fotoğrafınız Google Gemini API'ye gönderilir.
- Yalnızca AI dönüştürmeyi aktive ettiğinizde gerçekleşir — otomatik değildir.
- Görsel; Google'ın
generativelanguage.googleapis.comadresine HTTPS üzerinden iletilir. - Gönderide kullanıcı kimliği (UID, e-posta) bulunmaz — yalnızca görsel ve stil talimatı.
- Google'ın veri işleme politikası: ai.google.dev/gemini-api/terms
When you use the AI feature to convert your photo into a coloring page, your photo is sent to Google Gemini API.
- This only happens when you actively trigger AI conversion — it is not automatic.
- The image is transmitted via HTTPS to Google's
generativelanguage.googleapis.com. - No user identifier (UID, email) is included in the request — only the image and a style instruction.
- Google's data processing policy: ai.google.dev/gemini-api/terms
9. Premium Satın Alma
9. Premium Purchases
Uygulama içi satın almalar Google Play üzerinden gerçekleşir. Ödeme bilgileri (kart numarası vb.) hiçbir zaman uygulama tarafından görülmez veya saklanmaz.
Abonelik durumunuz RevenueCat aracılığıyla doğrulanır. RevenueCat'e gönderilen veriler: Firebase UID ve satın alma token'ı (Google Play'den). RevenueCat'in gizlilik politikası: revenuecat.com/privacy
In-app purchases are processed through Google Play. Payment information (card numbers, etc.) is never seen or stored by the app.
Your subscription status is verified through RevenueCat. Data sent to RevenueCat: Firebase UID and purchase token (from Google Play). RevenueCat privacy policy: revenuecat.com/privacy
10. Veri Saklama Süreleri
10. Data Retention
| Veri | Saklama Süresi |
|---|---|
| Firebase hesap bilgileri (ad, e-posta) | Hesap silinene kadar |
| Firestore oyun verileri | Hesap silinene kadar |
| Cloud Storage boyama dosyaları | Hesap silinene kadar |
| RevenueCat abonelik kaydı | RevenueCat politikasına göre (hesap silindiğinde logOut yapılır) |
| Google Play satın alma geçmişi | Google'ın yasal saklama politikasına göre (silinemiyor) |
| Yerel cihaz verileri (AsyncStorage) | Uygulama silinene veya veri sıfırlanana kadar |
| Yaş kategorisi (bucket) | Cihaz verileri sıfırlanana kadar (yerel) |
| FCM bildirim tokeni | Firebase politikasına göre |
| Data | Retention Period |
|---|---|
| Firebase account info (name, email) | Until account deletion |
| Firestore game data | Until account deletion |
| Cloud Storage coloring files | Until account deletion |
| RevenueCat subscription record | Per RevenueCat policy (logOut called on deletion) |
| Google Play purchase history | Per Google's legal retention policy (cannot be deleted) |
| Local device data (AsyncStorage) | Until app uninstall or data reset |
| Age category (bucket) | Until device data reset (local only) |
| FCM notification token | Per Firebase policy |
11. Hesap ve Veri Silme
11. Account and Data Deletion
Uygulama İçinden Silme
Bu işlem aşağıdaki verileri anında siler:
Web Üzerinden Silme
Uygulamaya erişiminiz yoksa e-posta ile talepte bulunabilirsiniz:
Deleting from the App
This action immediately deletes the following:
Web Deletion Request
If you cannot access the app, you may submit a request by email:
🔗 Account Deletion Request Page
12. Kullanıcı Hakları ve Uluslararası İşleme
12. Your Rights and International Processing
GDPR, CCPA ve diğer ilgili mevzuatlar kapsamında aşağıdaki haklara sahipsiniz:
Bu haklardan herhangi birini kullanmak için: ugur.akdeniz.12@gmail.com
Uluslararası Veri İşleme
Firebase, AdMob, RevenueCat ve Gemini API, verilerinizi Google ve ilgili sağlayıcıların sunucularında (ABD başta olmak üzere çeşitli ülkelerde) işleyebilir. Bu transferler, ilgili sağlayıcıların uygunluk mekanizmaları (Standart Sözleşme Maddeleri, vb.) çerçevesinde gerçekleşir.
Under GDPR, CCPA, and other applicable regulations, you have the following rights:
To exercise any of these rights: ugur.akdeniz.12@gmail.com
International Data Processing
Firebase, AdMob, RevenueCat, and Gemini API may process your data on Google's and respective providers' servers (primarily in the US and other countries). These transfers are carried out under each provider's compliance mechanisms (Standard Contractual Clauses, etc.).
13. İletişim
13. Contact
Gizlilik politikamıza ilişkin sorularınız için:
Hesap silme için: Hesap Silme Sayfası
Bu politika zaman zaman güncellenebilir. Önemli değişiklikler uygulama içi bildirimle duyurulur. Politikanın son sürümü her zaman bu sayfada bulunur.
For questions regarding our privacy policy:
For account deletion: Account Deletion Page
This policy may be updated from time to time. Material changes will be announced via an in-app notification. The latest version will always be available on this page.