Privacy Policy

Effective date: 13 September 2026

Hobby Tracker is developed by Ahmet Türk, operating as Main Thread Studios ("we", "us"), based in Türkiye. This policy explains what data the Hobby Tracker app handles, where it goes, and what your choices are. Contact: support@mainthreadstudios.com.

The short version: the app works fully offline and without an account — your library lives on your device. An account is optional and adds cloud sync. The AI Assistant requires an account and your consent, because it sends a summary of your activity to OpenAI to generate a recommendation. An optional PRO subscription, billed by the App Store or Google Play, raises the Assistant's monthly limit. We show no ads and never sell your data. The app sends a small set of anonymous usage events (never a title) to help us improve it; you can switch this off in Settings.

1. Data stored on your device

Everything you put into the app — titles you add (movies, TV series, books, games), their status and progress, your ratings, focus-timer sessions and completion history — is stored in a local database on your device. If you never create an account, this data never leaves your device, except for the metadata lookups described in section 4.

2. Account and cloud sync

Creating an account is optional. If you sign up, we process:

  • Email address and password. Authentication is handled by Supabase; passwords are stored only in hashed form. Your app language is stored with your account so account emails arrive in your language.
  • Your library, when signed in. The items, progress events, completion events and focus sessions described above are synced to a database hosted by Supabase in the European Union (Frankfurt, Germany) so they can follow you across devices, together with your collections and your settings (app language, content region, chosen streaming services, excluded genres and the recommendations you asked us not to repeat).
  • Shared collections. If you share a collection by invite link, the people who join see its name and titles, and the collection's owner and members see each other's account email addresses in the member list. You choose whom to send the link to; the owner can revoke the link and remove members at any time, and a member can leave.
  • Verification and password-reset emails are sent through Resend (our email delivery provider), using your email address and your app language.

3. The Assistant and OpenAI

The Assistant ("Asistan") generates a single recommendation on request. It requires sign-in, and asks for your explicit consent the first time you use it. When you ask for a recommendation, the app sends the following through our server (a Cloudflare Worker) to OpenAI, which generates the answer:

  • a summary of your recent activity: titles, dates, minutes spent, episode/page counts, whether you finished something, and how you felt about it (derived from your ratings);
  • the filters you chose for that question (category, genre, mood, source), a shortlist of candidate titles, your app language, the date and the part of day.

Under OpenAI's API terms, data sent to the API is not used to train their models. Our server keeps a monthly usage counter keyed to your account id (stored with Cloudflare); the content of your questions and answers is not stored on our server. The most recent answers are kept on your device so you can revisit them. You can withdraw consent at any time by simply not using the Assistant — no data is sent unless you tap the ask button.

4. Metadata lookups

To show posters, descriptions and ratings, the app queries third-party catalogues: TMDB (movies/TV) and Open Library (books) directly from your device, and IGDB (games) and OMDb (external review scores) through our proxy server. These queries carry the search text or title id and your device's IP address as a technical necessity; they are not linked to your account by us. Each service processes them under its own privacy policy.

5. Crash reports

To find and fix crashes, the app uses Sentry (hosted in the EU). When a crash occurs, the report includes technical details (device model, OS version, app version, stack trace). Your IP address is processed at ingest to deliver the report. Crash reports contain no account or library data.

5a. Usage analytics

To understand how the app is used and which parts need work, the app sends PostHog (hosted in the EU) a small set of usage events: which tab or screen was opened, and actions such as adding, starting or completing a title, saving a focus session or asking the Assistant — each with the category (film, series, book, game) and the outcome, never the title, your rating or any other library text. The events carry a random device identifier, your device model, OS and app version, language and country; when you are signed in they are linked to your account id (not your email) so a person using two devices is counted once. There is no session recording, no advertising identifier and no cross-app tracking. You can switch this off at any time under Profile → Settings → Usage data; the app works exactly the same either way. Data is kept for one year.

6. Subscriptions (Hobby Tracker PRO)

Hobby Tracker PRO is an optional auto-renewing subscription bought through the App Store or Google Play. Payment is handled entirely by the store: we never see your card or bank details. To know which account is entitled to PRO, we use RevenueCat, which receives the store's purchase record (a store transaction id, product, purchase and expiry dates) together with your account id, and relays it to our server, where your subscription status is stored next to your account. PRO requires an account for this reason. This data is processed to provide the subscription you bought (performance of contract) and is kept while the subscription and the account exist; deleting your account removes it from our systems, while the store keeps its own purchase history under its terms.

7. What we don't do

  • No advertising, no ad SDKs.
  • No cross-app or advertising tracking; the usage analytics above can be switched off in the app.
  • No sale or sharing of personal data for marketing.

8. Processors

We use these service providers to run Hobby Tracker: Supabase (accounts and sync database, hosted in the EU — Frankfurt), Cloudflare (our server, usage counters and this website), OpenAI (Assistant recommendations), Resend (account emails), RevenueCat (subscription status), Sentry (crash reports, EU region) and PostHog (usage analytics, EU region). Some of these providers process data outside your country, including in the United States; where required, transfers rely on the safeguards these providers offer, such as standard contractual clauses.

9. Retention and deletion

Synced data is kept until you delete your account. You can delete your account inside the app (Profile → Settings) or on the account deletion page; deletion removes your account and all synced data from our systems. Data on your device is under your control and is removed by deleting the app or its data. Crash reports expire automatically per Sentry's retention (90 days); usage events are kept for one year.

10. Legal bases

Where the GDPR or Türkiye's KVKK applies: we process account, sync and subscription data to provide the service you signed up for (performance of contract); Assistant data on your consent; crash reports, usage analytics and abuse-prevention counters on our legitimate interest in keeping the app working, fair and improving — with usage analytics you can object at any time by switching it off in the app (section 5a).

11. Your rights

Depending on where you live, you have the right to access, correct, delete and receive a copy of your personal data, to object to or restrict processing, and to withdraw consent. Under KVKK Article 11 you may also request information about whether and how your data is processed. Write to support@mainthreadstudios.com and we will respond. You may also lodge a complaint with your local supervisory authority.

12. Children

Hobby Tracker is not directed at children under 13, and we do not knowingly collect data from them.

13. Notice under Türkiye's KVKK

For users in Türkiye, this section restates the disclosure required by Law No. 6698 (KVKK) Article 10. The data controller is Ahmet Türk, a natural person operating under the Main Thread Studios name (contact: support@mainthreadstudios.com). Personal data is collected electronically, directly from you (sign-up form, the content you add) and by automated means (crash reports, usage events), for the purposes listed in sections 1–6, including 5a. The legal bases under KVKK Article 5 are: establishment and performance of a contract (account, sync and subscription), your explicit consent (the Assistant's OpenAI transfer), and our legitimate interest (crash reporting, usage analytics and abuse prevention). The processors named in section 8 are established outside Türkiye, so using an account, the Assistant, a subscription, account emails, crash reporting or usage analytics involves a transfer of personal data abroad — to the named recipients, for the named purposes only. Your rights under KVKK Article 11 (learning whether and how your data is processed, requesting correction or deletion, objecting, and the others listed in that article) can be exercised by writing to support@mainthreadstudios.com.

14. Changes

If this policy changes, the new version will be published on this page with an updated effective date. Material changes will be announced in the app.

Gizlilik Politikası

Yürürlük tarihi: 13 Eylül 2026

Hobby Tracker, Türkiye'de yerleşik, Main Thread Studios adıyla faaliyet gösteren Ahmet Türk ("biz") tarafından geliştirilmektedir. Bu politika, Hobby Tracker uygulamasının hangi verileri işlediğini, bu verilerin nereye gittiğini ve seçeneklerinin neler olduğunu açıklar. İletişim: support@mainthreadstudios.com.

Kısaca: uygulama tamamen çevrimdışı ve hesapsız çalışır — kütüphanen cihazında yaşar. Hesap isteğe bağlıdır ve bulut eşitleme ekler. Yapay zekâ Asistanı hesap ve açık rızanı gerektirir; çünkü bir öneri üretmek için aktivite özetini OpenAI'a gönderir. İsteğe bağlı PRO aboneliği App Store veya Google Play üzerinden faturalandırılır ve Asistan'ın aylık sınırını yükseltir. Reklam göstermeyiz, verini asla satmayız. Uygulama, geliştirmemize yardımcı olması için az sayıda anonim kullanım olayı gönderir (asla bir başlık adı değil); bunu Ayarlar'dan kapatabilirsin.

1. Cihazında saklanan veriler

Uygulamaya koyduğun her şey — eklediğin başlıklar (film, dizi, kitap, oyun), durumları ve ilerlemeleri, puanların, odak zamanlayıcısı oturumların ve tamamlama geçmişin — cihazındaki yerel bir veritabanında saklanır. Hiç hesap açmazsan bu veriler, 4. bölümde anlatılan katalog sorguları dışında cihazından çıkmaz.

2. Hesap ve bulut eşitleme

Hesap oluşturmak isteğe bağlıdır. Kaydolursan şunları işleriz:

  • E-posta adresi ve parola. Kimlik doğrulamayı Supabase yürütür; parolalar yalnızca özetlenmiş (hash) hâlde saklanır. Hesap e-postaların kendi dilinde gelsin diye uygulama dilin hesabınla birlikte tutulur.
  • Giriş yaptığında kütüphanen. Yukarıda sayılan öğeler, ilerleme kayıtları, tamamlama kayıtları ve odak oturumları, cihazların arasında seni takip edebilsin diye Supabase'in Avrupa Birliği'nde (Frankfurt, Almanya) barındırdığı bir veritabanına eşitlenir; yanında koleksiyonların ve ayarların (uygulama dili, içerik bölgesi, seçtiğin yayın platformları, hariç tuttuğun türler ve tekrar önerilmemesini istediğin başlıklar) taşınır.
  • Paylaşılan koleksiyonlar. Bir koleksiyonu davet bağlantısıyla paylaşırsan katılanlar adını ve başlıklarını görür; koleksiyonun sahibi ve üyeleri, üye listesinde birbirlerinin hesap e-posta adreslerini görür. Bağlantıyı kime göndereceğine sen karar verirsin; sahip bağlantıyı istediği an iptal edip üyeleri çıkarabilir, üye de ayrılabilir.
  • Doğrulama ve parola sıfırlama e-postaları, e-posta adresin ve uygulama dilin kullanılarak Resend (e-posta iletim sağlayıcımız) üzerinden gönderilir.

3. Asistan ve OpenAI

Asistan, istek üzerine tek bir öneri üretir. Giriş gerektirir ve ilk kullanımda açık rızanı ister. Bir öneri istediğinde uygulama, sunucumuz (bir Cloudflare Worker) üzerinden OpenAI'a şunları gönderir ve yanıtı OpenAI üretir:

  • yakın dönem aktivite özetin: başlıklar, tarihler, harcanan dakikalar, bölüm/sayfa sayıları, bir şeyi bitirip bitirmediğin ve (puanlarından türetilerek) onun hakkında ne hissettiğin;
  • o soru için seçtiğin filtreler (kategori, tür, ruh hâli, kaynak), aday başlık listesi, uygulama dilin, tarih ve günün bölümü.

OpenAI'ın API koşullarına göre API'ye gönderilen veriler modellerinin eğitiminde kullanılmaz. Sunucumuz, hesap kimliğine bağlı aylık bir kullanım sayacı tutar (Cloudflare'de saklanır); soru ve yanıtların içeriği sunucumuzda saklanmaz. Son yanıtlar, geri dönüp bakabilesin diye cihazında tutulur. Rızanı istediğin an, Asistanı kullanmayarak geri çekebilirsin — öneri düğmesine dokunmadıkça hiçbir veri gönderilmez.

4. Katalog sorguları

Poster, açıklama ve puanları göstermek için uygulama üçüncü taraf katalogları sorgular: TMDB (film/dizi) ve Open Library (kitap) doğrudan cihazından; IGDB (oyun) ve OMDb (harici puanlar) ise vekil sunucumuz üzerinden. Bu sorgular arama metnini veya başlık kimliğini ve teknik bir zorunluluk olarak cihazının IP adresini taşır; tarafımızca hesabınla ilişkilendirilmez. Her servis bunları kendi gizlilik politikasına göre işler.

5. Çökme raporları

Çökmeleri bulup düzeltmek için uygulama Sentry kullanır (AB'de barındırılır). Bir çökme olduğunda rapor teknik ayrıntıları içerir (cihaz modeli, işletim sistemi sürümü, uygulama sürümü, hata yığını). IP adresin, raporun iletilmesi için alım anında işlenir. Çökme raporları hesap veya kütüphane verisi içermez.

5a. Kullanım analitiği

Uygulamanın nasıl kullanıldığını ve hangi kısımlarının iyileştirilmesi gerektiğini anlamak için uygulama PostHog'a (AB'de barındırılır) küçük bir kullanım olayı kümesi gönderir: hangi sekme veya ekranın açıldığı; bir başlığı ekleme, odağa alma veya bitirme, odak oturumu kaydetme, Asistan'a sorma gibi eylemler — her biri kategoriyle (film, dizi, kitap, oyun) ve sonucuyla, hiçbir zaman başlığın adı, puanın veya kütüphanendeki başka bir metinle değil. Olaylar rastgele bir cihaz tanımlayıcısı, cihaz modeli, işletim sistemi ve uygulama sürümü, dil ve ülke bilgisi taşır; giriş yaptığında iki cihaz kullanan bir kişinin bir kez sayılması için hesap kimliğine (e-postana değil) bağlanır. Oturum kaydı, reklam tanımlayıcısı veya uygulamalar arası takip yoktur. Bunu istediğin zaman Profil → Ayarlar → Kullanım verisi altından kapatabilirsin; uygulama her iki durumda da aynı çalışır. Veri bir yıl tutulur.

6. Abonelikler (Hobby Tracker PRO)

Hobby Tracker PRO, App Store veya Google Play üzerinden satın alınan isteğe bağlı ve otomatik yenilenen bir aboneliktir. Ödeme tamamen mağaza tarafından yürütülür; kart veya banka bilgilerini hiçbir zaman görmeyiz. Hangi hesabın PRO hakkına sahip olduğunu bilmek için RevenueCat kullanırız: RevenueCat, mağazanın satın alma kaydını (mağaza işlem kimliği, ürün, satın alma ve bitiş tarihleri) hesap kimliğinle birlikte alır ve sunucumuza iletir; abonelik durumun orada hesabının yanında saklanır. PRO'nun hesap gerektirmesinin nedeni budur. Bu veri, satın aldığın aboneliği sunmak için (sözleşmenin ifası) işlenir ve abonelik ile hesap var olduğu sürece tutulur; hesabını silmen bu veriyi sistemlerimizden kaldırır, mağaza ise kendi satın alma geçmişini kendi koşullarına göre tutar.

7. Yapmadıklarımız

  • Reklam yok, reklam SDK'sı yok.
  • Uygulamalar arası veya reklam amaçlı takip yok; yukarıdaki kullanım analitiği uygulama içinden kapatılabilir.
  • Kişisel verinin pazarlama amacıyla satışı veya paylaşımı yok.

8. Veri işleyenler

Hobby Tracker'ı çalıştırmak için şu hizmet sağlayıcıları kullanırız: Supabase (hesaplar ve eşitleme veritabanı, AB'de — Frankfurt — barındırılır), Cloudflare (sunucumuz, kullanım sayaçları ve bu web sitesi), OpenAI (Asistan önerileri), Resend (hesap e-postaları), RevenueCat (abonelik durumu), Sentry (çökme raporları, AB bölgesi) ve PostHog (kullanım analitiği, AB bölgesi). Bu sağlayıcıların bir kısmı veriyi ülkenin dışında, ABD dâhil, işleyebilir; gerektiğinde aktarımlar bu sağlayıcıların sunduğu standart sözleşme hükümleri gibi güvencelere dayanır.

9. Saklama ve silme

Eşitlenen veriler hesabını silene kadar tutulur. Hesabını uygulamanın içinden (Profil → Ayarlar) veya hesap silme sayfasından silebilirsin; silme, hesabını ve eşitlenmiş tüm veriyi sistemlerimizden kaldırır. Cihazındaki veri senin kontrolündedir; uygulamayı veya verisini silerek kaldırılır. Çökme raporları Sentry'nin saklama süresine göre (90 gün) kendiliğinden silinir; kullanım olayları bir yıl tutulur.

10. Hukuki dayanaklar

GDPR veya KVKK'nın uygulandığı hâllerde: hesap, eşitleme ve abonelik verisini kaydolduğun hizmeti sunmak için (sözleşmenin ifası), Asistan verisini açık rızana dayanarak, çökme raporlarını, kullanım analitiğini ve kötüye kullanım önleme sayaçlarını ise uygulamayı çalışır, adil ve gelişir tutmaktaki meşru menfaatimize dayanarak işleriz; kullanım analitiğine, uygulama içinden kapatarak istediğin an itiraz edebilirsin (bölüm 5a).

11. Hakların

Yaşadığın yere bağlı olarak kişisel verine erişme, düzeltme, silme ve bir kopyasını alma, işlemeye itiraz etme veya kısıtlanmasını isteme ve rızanı geri çekme hakların vardır. KVKK'nın 11. maddesi uyarınca verinin işlenip işlenmediğini ve nasıl işlendiğini öğrenmeyi de talep edebilirsin. support@mainthreadstudios.com adresine yaz, yanıtlayalım. Ayrıca yetkili denetim makamına (Türkiye'de Kişisel Verileri Koruma Kurumu) şikâyette bulunabilirsin.

12. Çocuklar

Hobby Tracker 13 yaş altı çocuklara yönelik değildir ve onlardan bilerek veri toplamayız.

13. KVKK aydınlatması (Türkiye)

Türkiye'deki kullanıcılar için bu bölüm, 6698 sayılı KVKK'nın 10. maddesi uyarınca yapılması gereken aydınlatmayı bir arada sunar. Veri sorumlusu, Main Thread Studios adıyla faaliyet gösteren gerçek kişi Ahmet Türk'tür (iletişim: support@mainthreadstudios.com). Kişisel veriler elektronik ortamda, doğrudan senden (kayıt formu, uygulamaya eklediğin içerikler) ve otomatik yollarla (çökme raporları, kullanım olayları), 5a dâhil 1–6. bölümlerde sayılan amaçlarla toplanır. KVKK'nın 5. maddesindeki hukuki sebepler şunlardır: bir sözleşmenin kurulması ve ifası (hesap, eşitleme ve abonelik), açık rızan (Asistan'ın OpenAI aktarımı) ve meşru menfaatimiz (çökme raporlama, kullanım analitiği ve kötüye kullanım önleme). 8. bölümde adları sayılan hizmet sağlayıcılar Türkiye dışında yerleşiktir; bu nedenle hesap, Asistan, abonelik, hesap e-postaları, çökme raporlama veya kullanım analitiği kullanıldığında kişisel veriler yurt dışına — yalnızca adı geçen alıcılara ve sayılan amaçlarla — aktarılır. KVKK'nın 11. maddesindeki haklarını (verinin işlenip işlenmediğini ve nasıl işlendiğini öğrenme, düzeltme veya silme isteme, itiraz ve maddede sayılan diğerleri) support@mainthreadstudios.com adresine yazarak kullanabilirsin.

14. Değişiklikler

Bu politika değişirse yeni sürüm, güncellenmiş yürürlük tarihiyle bu sayfada yayımlanır. Önemli değişiklikler uygulama içinde duyurulur.