1. Data controller
PrismaFX is built and published by Mustafa Evleksiz acting as a natural person, not under a registered company; that person is the data controller. Contact is by e-mail only: mustafa@mustafaevleksiz.com
Document version 1.0 — 25 August 2026 · translation of the Turkish original
This notice is written under Türkiye's Personal Data Protection Law No. 6698 (KVKK) and restates, under the headings the law asks for, what the privacy policy already discloses. Where the two disagree, the privacy policy governs.
PrismaFX is built and published by Mustafa Evleksiz acting as a natural person, not under a registered company; that person is the data controller. Contact is by e-mail only: mustafa@mustafaevleksiz.com
PrismaFX has no sign-up, no sign-in and no in-app purchases. Your name, address, phone number and payment details are therefore never asked for and never collected. Your portfolio, expenses and notes stay only on your device, in the app's own container, and are never uploaded — not even as a backup. The app does not sync with iCloud.
The only category leaving your device that could count as personal data under the KVKK is diagnostic data:
There is no ad network and the advertising identifier is never accessed. Contacts, photos, calendar, microphone and camera are never requested.
Diagnostic data is processed only to find faults and to understand which features are used so the app can be improved. Rate requests exist so that conversion — the app's actual function — works. There is no profiling, no marketing and no sale of data.
Rate requests fall under Article 5(2)(c) of the KVKK, being directly related to performance of the contract. Diagnostic data rests on the legitimate interest of running the app without faults (Article 5(2)(f)), kept to technical data that carries no identity and does not harm your fundamental rights and freedoms.
Diagnostic data is processed on Google Firebase (Google Ireland Limited / Google LLC), whose servers are outside Türkiye, so a transfer abroad does take place. Rate providers see only the request itself and the IP address. Beyond that, no data is transferred, sold or shared for marketing.
What is on your device stays until you remove it; deleting the app removes all of it. Diagnostic records on Firebase are kept for Google's own retention periods. From the app's Settings you can export everything as CSV or JSON, clear the cache, or reset all content.
Under Article 11 of the KVKK you have the right to learn whether your data is processed, to request information, to learn the purpose, to know the third parties it is transferred to, to have it corrected, deleted or destroyed, to object to a result reached solely by automated analysis that works against you, and to claim compensation for damage. Because there is no account, no record on our side can be linked to you; you may nonetheless write to the address above about any request and will have a reply within thirty days at the latest.
Data sits in the app's container, protected by iOS and your device passcode. The keys used to reach the rate providers are held in the iOS Keychain, and all network requests go over HTTPS.
If this notice changes, the date above is updated. For any question or request: mustafa@mustafaevleksiz.com
This notice is an engineering statement of what the app actually does; it is not legal advice. A lawyer should be consulted for a final compliance view.