Sürüm: tr-1.1.0 • Yürürlük Tarihi: 26 Temmuz 2026
Bu Gizlilik Politikası, VIOVELLA AI ("VIOVELLA", "Uygulama", "Hizmet", "biz") tarafından sunulan yapay zekâ destekli dijital stil hizmetlerini kullanırken kişisel verilerinizin nasıl toplandığını, işlendiğini, saklandığını, korunduğunu ve hangi amaçlarla kullanıldığını açıklar.
Bu politika, 6698 sayılı Kişisel Verilerin Korunması Kanunu ("KVKK"), Avrupa Birliği Genel Veri Koruma Tüzüğü ("GDPR") ve uygulanabilir diğer veri koruma mevzuatları dikkate alınarak hazırlanmıştır.
Bu politika veri işleme hakkında bilgilendirme sağlar. AI görsel işleme için gereken açık onay, kayıt ekranında ayrı bir kontrolle alınır.
1. Veri Sorumlusu
Veri Sorumlusu: NEXART TASARIM-NEBAHAT BİÇER
E-posta: info@viovella.com
KVKK ve kişisel verilerinizle ilgili talepleriniz için bizimle aynı e-posta adresi üzerinden iletişime geçebilirsiniz.
2. Topladığımız Veriler
Hizmetlerimizi sunabilmek amacıyla aşağıdaki veri kategorileri işlenebilir.
Hesap Bilgileri
- Ad ve soyad (varsa)
- E-posta adresi
- Firebase Kullanıcı Kimliği (UID)
- Apple veya Google ile giriş bilgileri
Hesap ve Abonelik Bilgileri
- Abonelik planı
- Kredi bakiyesi
- Satın alma geçmişi
- Hesap tercihleri
- Son giriş zamanı
- Abonelik durumu
Görseller
Kullanıcının yüklediği;
- Yüz fotoğrafları
- Vücut fotoğrafları
- Saç görselleri
- AI tarafından oluşturulan sonuç görselleri
yalnızca uygulamanın sunduğu yapay zekâ destekli hizmetlerin gerçekleştirilmesi amacıyla işlenebilir.
Teknik Veriler
Platformun güvenli şekilde çalışmasını sağlamak amacıyla aşağıdaki teknik bilgiler işlenebilir:
- Cihaz bilgileri
- İşletim sistemi
- Uygulama sürümü
- Dil tercihi
- Firebase App Check bütünlük sinyalleri ve güvenlik kayıtları
- Misafir kötüye kullanımını önlemek için FingerprintJS çıktısından sunucuda üretilen, yalnız bu Firebase projesi ve amaç için kapsamlandırılmış SHA-256 cihaz takma kimliği (ham FingerprintJS kimliği saklanmaz)
- Kimlik doğrulama kayıtları
- Güvenlik logları
Kullanım Verileri
Platformun geliştirilmesi amacıyla anonim veya toplulaştırılmış kullanım verileri analiz edilebilir.
Bunlar örneğin;
- kullanılan modüller,
- ziyaret edilen ekranlar,
- uygulama performansı,
- kullanım istatistikleri
gibi bilgileri içerebilir.
Destek, güvenlik ve AI raporları
- Sentry tarafından işlenen çökme, performans ve hata tanılama verileri
- AI sonucu hakkında gönderdiğiniz kategori, isteğe bağlı not, istek kimliği ve moderasyon durumu; kaynak veya sonuç görseli AI raporuna eklenmez
- Hesap silme işinin aşaması, deneme sayısı ve hata durumu
3. Fotoğraf ve AI Görsel İşleme
Yüz, saç veya vücut içeren fotoğraflar kişisel ve bağlama göre hassas olabilir. VIOVELLA bu sıradan fotoğrafları kimlik doğrulama, yüz tanıma, benzersiz biyometrik şablon çıkarma veya kişiyi teşhis etme amacıyla işlemez.
Bu görseller yalnızca;
- yapay zekâ destekli sanal prova,
- saç modeli,
- makyaj,
- stil önerileri,
- düğün provası,
- dijital gardırop
gibi VIOVELLA hizmetlerinin sunulması amacıyla işlenir.
Bu görseller;
- reklam amacıyla kullanılmaz,
- üçüncü kişilere satılmaz,
- profil oluşturma amacıyla kullanılmaz,
- AI modellerinin eğitimi amacıyla kullanılmaz.
Yüklediğiniz fotoğraflar siz paylaşmayı seçmediğiniz sürece diğer kullanıcılar tarafından görüntülenemez.
4. STYLIST (Kurumsal) Hesaplar
STYLIST veya eşdeğer kurumsal abonelik planlarında;
- ürün görselleri,
- ürün kodları,
- müşteri fotoğrafları,
- sanal prova sonuçları,
- müşteri adı,
- isteğe bağlı iletişim bilgileri
ilgili işletmenin hesabı kapsamında saklanabilir.
Bu veriler yalnızca ilgili işletmenin erişimine açıktır.
Müşterilerine ait kişisel verileri işleyen işletmeler, kendi müşterilerine karşı yürürlükteki veri koruma mevzuatı kapsamındaki yükümlülüklerinden sorumludur.
5. Verilerin İşlenme Amaçları
Toplanan veriler aşağıdaki amaçlarla kullanılabilir:
- Yapay zekâ destekli stil hizmetlerinin sunulması
- Hesap oluşturulması ve yönetilmesi
- Kimlik doğrulama
- Abonelik ve kredi yönetimi
- Platform güvenliğinin sağlanması
- Dolandırıcılık ve kötüye kullanımın önlenmesi
- Teknik sorunların giderilmesi
- Kullanıcı desteğinin sağlanması
- Hizmet kalitesinin geliştirilmesi
- Yasal yükümlülüklerin yerine getirilmesi
6. Yapay Zekâ Kullanımı
VIOVELLA, yüklediğiniz görseller üzerinde yapay zekâ destekli görsel üretimi gerçekleştirebilir.
Üretilen görseller dijital stil önerisi niteliğindedir.
Gerçek ürün, kumaş, renk, beden, doku veya görünüm ile tamamen aynı sonuçların elde edileceği garanti edilmez.
Yapay zekâ tarafından oluşturulan içerikler zaman zaman beklenmeyen veya hatalı sonuçlar üretebilir.
Kullanıcı verileri AI modellerini eğitmek amacıyla kullanılmaz.
7. Üçüncü Taraf Hizmetler
VIOVELLA aşağıdaki hizmet sağlayıcılardan yararlanabilir:
- Google Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions ve App Check: hesap, uygulama verisi, görsel saklama, sunucu işlemleri, erişim güvenliği ve bütünlük doğrulaması.
- Google Gemini: açıkça istediğiniz AI stil/sanal prova işlemi için seçtiğiniz görseller ve talimatlar.
- RevenueCat, Apple App Store ve Google Play: native abonelik, ürün, işlem ve entitlement durumları; Firebase UID veya sağlayıcı kullanıcı kimliğiyle hesabınıza bağlanabilir.
- iyzico: yalnız web ödeme akışında ödeme/abonelik referansları, tutar, para birimi, durum ve gerekli müşteri/iletişim alanları. Kart verisi iyzico tarafından işlenir.
- Sentry: çökme, performans ve hata tanılama; olaylar kişisel veri ve token riskini azaltmak için temizlenir, ancak teknik tanımlayıcılarla hesabınıza veya oturuma dolaylı bağlanabilir.
- FingerprintJS: misafir kötüye kullanımını sınırlamak için tarayıcı/cihaz sinyallerinden istemcide bir kimlik üretir. Sunucu yalnız proje ve amaç kapsamlı SHA-256 takma kimliği saklar.
Bu hizmet sağlayıcılar yalnızca kendi hizmetlerini sunabilmek amacıyla gerekli verileri işleyebilir ve kendi gizlilik politikalarına tabidir.
8. Ödemeler
VIOVELLA tam kredi kartı veya banka kartı numaranızı kendi Firestore/Storage veritabanında saklamaz. Kart verisi Apple, Google Play veya iyzico ödeme yüzeyinde ilgili sağlayıcı tarafından işlenir.
VIOVELLA ödeme bütünlüğü, entitlement, iade, uyuşmazlık ve muhasebe için sağlayıcı işlem kimlikleri, ürün, tutar, para birimi, durum, zaman ve hesabınıza bağlantıyı saklayabilir.
9. Veri Güvenliği
Kişisel verilerin korunması amacıyla makul teknik ve idari güvenlik önlemleri uygulanmaktadır.
Veriler, güvenli iletişim protokolleri, erişim kontrolleri, kimlik doğrulama mekanizmaları ve güvenlik kuralları kullanılarak korunur.
Her kullanıcı yalnızca kendi hesabına ait verilere erişebilir.
Bununla birlikte, internet üzerinden gerçekleştirilen hiçbir veri aktarımı veya elektronik depolama yöntemi tamamen güvenli olduğu garanti edilemez.
10. Verilerin Saklanması
- Hesap/profil ve özel Firestore/Storage verileri hesap açıkken veya özelliği sunmak için gerekli olduğu sürece tutulur.
- AI çıktıları, butik prova verileri ve süreli herkese açık paylaşımlar zamanlanmış süre/temizleme işleriyle silinir. Herkese açık paylaşım kayıtları süre sonunda okunamaz; temizleme hataları yeniden deneme için tutulur ve birikim durumu operasyonel inceleme için kaydedilir.
- AI sonuç raporları kaynak veya sonuç görselini değil, meta veri ve isteğe bağlı notu içerir. Yalnız yöneticilerin erişebildiği kiralamalı inceleme kuyruğunda yeniden deneme durumu ve denetim geçmişiyle işlenir; istemci üzerinden raporlayan veya rapor konusu kişi karar veremez. Raporlar güvenlik, moderasyon ve kötüye kullanım takibi için gerekli süre boyunca tutulur.
- Sentry tanılama verileri Sentry projesinde yapılandırılan saklama süresine tabidir; bu süre dashboard'da doğrulanmalıdır.
- Misafir cihaz takma kimliği hesap/misafir kaydıyla bağlantılıdır ve hesap silme işinde kullanıcı ağacıyla silinir. Deterministik hash, anonimleştirme değildir; proje içinde eşleştirilebilir bir takma kimliktir.
- Hesap silme isteği dayanıklı bir silme işi oluşturur; Firestore kullanıcı ağacı, Storage önekleri, AI verileri, lead/müşteri fotoğrafları, public share kayıt/varlıkları ve RevenueCat kaydı temizlenmeden Auth hesabı son adımda silinir. Başarısız zorunlu adımlar yeniden denenir. Silinen WebView/profil durumunun uygulama yedeğinden geri gelmemesi için Android uygulama yedeklemesi kapalıdır.
- Vergi, muhasebe, ödeme uyuşmazlığı ve sahtecilik önleme için zorunlu işlem defterleri en fazla 10 yıl tutulabilir; UID takma kimlikle değiştirilir ve gereksiz profil alanları kaldırılır.
11. Haklarınız
Yürürlükteki veri koruma mevzuatı kapsamında;
- verilerinize erişme,
- düzeltme talep etme,
- silinmesini isteme,
- veri işleme hakkında bilgi alma,
- uygun olduğu ölçüde veri taşınabilirliği talep etme,
- açık rızanızı geri çekme,
- mevzuatın tanıdığı diğer hakları kullanma
haklarına sahipsiniz.
Bu kapsamdaki taleplerinizi info@viovella.com adresine iletebilirsiniz.
12. Yaş Sınırı
VIOVELLA yalnızca 18 yaş ve üzerindeki kullanıcılar için tasarlanmıştır.
18 yaşından küçük kişilerin hesap oluşturmasına veya kişisel veri yüklemesine izin verilmez.
Bu durumun tespit edilmesi halinde ilgili hesap ve veriler silinebilir.
13. Güncellemeler
Bu Gizlilik Politikası, yasal gereklilikler, teknik değişiklikler veya hizmetlerde yapılan güncellemeler doğrultusunda zaman zaman değiştirilebilir.
Güncel sürüm Platform üzerinde yayımlandığı tarihte yürürlüğe girer.
Önemli değişiklikler hakkında uygulama içinde bildirim yapılır; açık onay gerektiren yeni bir amaç varsa ayrı onay alınır.
14. İletişim
Gizlilik Politikası veya kişisel verileriniz hakkında sorularınız için bizimle iletişime geçebilirsiniz.
E-posta: info@viovella.com
Version: en-1.1.0 • Effective Date: July 26, 2026
This Privacy Policy explains how VIOVELLA AI ("VIOVELLA", "Application", "Platform", "Service", "we", "our", or "us") collects, processes, stores, protects, and uses your personal information when you use our AI-powered digital styling services.
This Privacy Policy has been prepared in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the Turkish Personal Data Protection Law (KVKK), and other applicable privacy regulations.
This policy provides notice about data processing. The explicit confirmation required for AI image processing is collected through a separate control during registration.
1. Data Controller
Data Controller: NEXART TASARIM-NEBAHAT BİÇER
Email: info@viovella.com
For any requests regarding your personal data or your rights under applicable data protection laws, you may contact us using the email address above.
2. Information We Collect
To provide our services, VIOVELLA may process the following categories of information.
Account Information
- Name (if provided)
- Email address
- Firebase User ID (UID)
- Apple Sign In or Google Sign-In account information
Account and Subscription Information
- Subscription plan
- Credit balance
- Purchase history
- Account preferences
- Last sign-in time
- Subscription status
Images
Images uploaded by you, including:
- Face photos
- Full-body photos
- Hair images
- AI-generated result images
may be processed solely for providing AI-powered styling services.
Technical Information
To ensure the secure operation of the Platform, we may process:
- Device information
- Operating system information
- Application version
- Language preferences
- Firebase App Check integrity signals and security records
- A SHA-256 device pseudonym generated server-side from FingerprintJS output and scoped to this Firebase project and guest-abuse-prevention purpose (the raw FingerprintJS identifier is not stored)
- Authentication records
- Security logs
Usage Information
Anonymous or aggregated usage information may be analyzed to improve our services.
This may include:
- Features used
- Screens visited
- Application performance
- Usage statistics
Support, security, and AI reports
- Crash, performance, and error diagnostics processed by Sentry
- The category, optional note, request ID, and moderation state you submit when reporting an AI result; source and result images are not attached to the AI report
- Account-deletion job stage, attempt count, and error state
3. Photo and AI Image Processing
Photos containing a face, hair, or body are personal and may be sensitive depending on context. VIOVELLA does not process ordinary photos for identity verification, facial recognition, unique biometric-template extraction, or identification.
These images are processed solely for providing services such as:
- AI virtual try-on
- Hairstyle simulation
- Makeup simulation
- Style recommendations
- Wedding styling
- Digital wardrobe management
Your uploaded images are:
- never used for advertising,
- never sold to third parties,
- never used for profiling,
- never used to train AI models.
Images remain private and cannot be viewed by other users unless you explicitly choose to share them.
4. STYLIST (Business) Accounts
Business accounts using the STYLIST plan or equivalent subscription may store:
- Product images
- Product codes
- Customer photos
- AI-generated try-on results
- Customer names
- Optional customer contact information
These records remain accessible only to the respective business account.
Businesses processing customer information are responsible for complying with applicable privacy and data protection laws with respect to their own customers.
5. How We Use Your Information
Your information may be processed for the following purposes:
- Providing AI-powered styling services
- Managing user accounts
- Authenticating users
- Managing subscriptions and credit balances
- Maintaining platform security
- Preventing fraud and abuse
- Resolving technical issues
- Providing customer support
- Improving our services
- Complying with legal obligations
6. Artificial Intelligence Processing
VIOVELLA uses artificial intelligence to generate styling results based on the images you upload.
The generated images are intended solely as digital style recommendations.
Actual clothing, fabrics, colors, body fit, textures, and visual appearance may differ from the AI-generated results.
AI-generated content may occasionally contain inaccuracies or unexpected results.
Your uploaded images and personal data are not used to train AI models.
7. Third-Party Services
VIOVELLA may use the following service providers:
- Google Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, and App Check: accounts, app data, image storage, server processing, access security, and integrity validation.
- Google Gemini: images and instructions you select for the AI styling or virtual try-on request you initiate.
- RevenueCat, Apple App Store, and Google Play: native subscription, product, transaction, and entitlement state, which may be linked to your Firebase UID or provider user identifier.
- iyzico: for web payments only, payment/subscription references, amount, currency, status, and necessary customer/contact fields. iyzico processes card details.
- Sentry: crash, performance, and error diagnostics. Events are scrubbed to reduce personal-data and token exposure, but technical identifiers may indirectly link an event to an account or session.
- FingerprintJS: creates an identifier from browser/device signals to limit guest abuse. The server stores only a project- and purpose-scoped SHA-256 pseudonym.
These providers process information only as necessary to deliver their respective services and are subject to their own privacy policies.
8. Payment Information
VIOVELLA does not store full credit- or debit-card numbers in its own Firestore or Storage data. Card details are processed by Apple, Google Play, or iyzico on the provider's payment surface.
For payment integrity, entitlements, refunds, disputes, and accounting, VIOVELLA may retain provider transaction IDs, product, amount, currency, status, time, and the link to your account.
9. Data Security
We implement reasonable technical and organizational measures to protect your personal information.
Your data is protected using secure communication protocols, authentication mechanisms, access controls, and other appropriate security measures.
Each user may access only the information associated with their own account.
However, no method of electronic transmission or storage can be guaranteed to be completely secure.
10. Data Retention
- Account/profile and private Firestore/Storage data are retained while the account is open or while needed to provide the feature.
- AI outputs, boutique try-on data, and time-limited public shares are removed by scheduled expiry/purge jobs. Public-share records become unreadable at expiry; cleanup failures are retained for retry and purge backlog state is recorded for operational review.
- AI-result reports contain metadata and an optional note, not the source or result image. They enter an administrator-only leased review queue with retry state and audit history, and are retained only as needed for moderation, security review, and abuse prevention. Reporters and subjects cannot adjudicate reports from the client.
- Sentry diagnostics follow the retention configured in the Sentry project; that period must be verified in the dashboard.
- The guest device pseudonym is linked to the guest/account record and is deleted with the user tree. A deterministic hash is pseudonymization, not anonymization, and remains linkable within this project.
- An account deletion request creates a durable deletion job. It cleans the Firestore user tree, Storage prefixes, AI data, lead/customer photos, public-share records/assets, and the RevenueCat record before deleting Firebase Auth last. Required failures are retried. Android application backup is disabled so deleted WebView/profile state is not intentionally restored from app backup.
- Transaction ledgers required for tax, accounting, payment disputes, and fraud prevention may be retained for up to 10 years; the UID is replaced with a pseudonym and unnecessary profile fields are removed.
11. Your Rights
Subject to applicable data protection laws, you may have the right to:
- Access your personal information;
- Request correction of inaccurate information;
- Request deletion of your personal information where applicable;
- Obtain information about how your data is processed;
- Request data portability where applicable;
- Withdraw your consent where processing is based on consent;
- Exercise any other rights granted under applicable data protection laws.
Privacy-related requests may be submitted to info@viovella.com.
12. Age Requirement
VIOVELLA is intended only for individuals aged 18 years or older.
Users under the age of 18 are not permitted to create an account or upload personal information.
If we become aware that an underage user has created an account, the account and associated information may be removed.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal requirements, technical changes, or improvements to our services.
The updated version becomes effective upon publication on the Platform.
Material changes are notified in the application; a separate confirmation is obtained if a new purpose requires explicit consent.
14. Contact
If you have any questions regarding this Privacy Policy or the processing of your personal information, please contact us:
Email: info@viovella.com