UniNet Privacy Policy
Last Updated: 30 July 2026 Version: 2.1
This Privacy Policy explains how the UniNet application collects, uses, stores, and shares your personal data. By using the UniNet mobile application (iOS & Android), you can access the current version of this policy at any time from within the app.
This policy has been prepared to fulfill the disclosure obligation under Law No. 6698 on the Protection of Personal Data (KVKK).
1. Data Controllers
Name: Ali Efe Sarıoğlu, Ahmet Gül, Emre Üstündağ (jointly, on behalf of the UniNet Platform) Address: Serdivan/Sakarya, Türkiye E-mail: iletisim@uninettr.com Platform: UniNet — Campus Social Network for University Students (iOS & Android)
The individuals named above jointly decide on the purposes and means of processing personal data during the founding phase of the UniNet Platform, and jointly hold the status of joint data controller under this policy.
2. Personal Data We Collect
2.1 Registration Data (Mandatory)
- First and last name
- Institutional e-mail address with a .edu.tr extension
- University information
- Password (stored using cryptographic hashing; never stored in plain text)
- Camera access: used momentarily during QR code verification; no image is recorded.
Optional Demographic Data (For User Experience)
The following information is entirely optional; not providing it does not prevent registration or use of the platform's services:
- Gender (Male / Female / Other / Prefer not to say)
- Date of birth
- Department information
2.2 Location Data (Optional)
- Event location: The coordinate you select on the map when creating an event. Permanently deleted when the event is deleted.
- Check-in location: Your device's GPS coordinate when you actively check in. Permanently deleted when the check-in is deleted.
Your map camera position is stored only on your device and is not transmitted to our servers.
2.3 In-App Interaction Data
- Friendships and friend requests
- Club memberships and applications
- Club matching answers
- Event participation records
- Posts, likes, and poll responses
- Notification history
- Complaint records
2.4 Optional Profile Data
- Profile photo (if you choose to upload one)
- Event cover image and post photos
2.5 Diagnostic and Crash Data (Enabled by Default — Can Be Turned Off)
Only at the moment of a crash/error: device model, OS and app version, crash stack trace, error logs, and the name of the screen shown at the time of the crash. UniNet does not knowingly include your name or e-mail address in these reports and does not use this data for advertising purposes. You can turn this off at any time from Settings → Privacy.
3. Purposes and Legal Bases for Processing Your Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Registration data | Account creation and provision of the service | KVKK Article 5/2-(c) — Performance of a contract |
| .edu.tr e-mail | Restricting access to university students only | Performance of a contract + Legitimate interest |
| Gender, date of birth, department (optional) | User experience and personalization | KVKK Article 5/1 — Explicit consent |
| Location data | Creating events and checking in | KVKK Article 5/1 — Explicit consent |
| Profile and post images | Profile personalization, content sharing | Performance of a contract |
| Interaction data | Operation of social features | Performance of a contract |
| Notifications | Event and club notifications | KVKK Article 5/1 — Explicit consent |
| Diagnostic/crash data | App stability and troubleshooting | KVKK Article 5/2-(f) — Legitimate interest (can be turned off) |
| Event approval records (creator, deciding administrator, decision time, rejection reason) | Pre-publication safety review of individually created events | KVKK Article 5/2-(f) — Legitimate interest |
4. Third-Party Service Providers and International Transfer
To provide UniNet, we work with a small number of trusted third-party service providers in certain areas. Any sharing is always limited to what the relevant service requires. Your personal data is never sold, and is never shared with third parties for advertising purposes.
Supabase — We use Supabase's infrastructure to run account creation, authentication, profile, event, and club features. Your name, university e-mail, university information, optional profile information, the content you create, and your account security records are processed and stored on Supabase's infrastructure. Your device location is not shared as part of this.
Mapbox — To power in-app map features, your map interaction data is shared with Mapbox. Name or e-mail information is not knowingly included in map requests.
Google Fonts — Your IP address is automatically transmitted when the app's fonts are loaded.
Resend — To deliver your notification and event e-mails, your e-mail address and notification content are shared with Resend.
Firebase Crashlytics (Google) — If the app encounters an error, technical information such as device model, error logs, and screen name is automatically sent to Google. Your name or e-mail is not knowingly included in these reports, and you can turn this off anytime from Settings → Privacy. These transfers are carried out within each provider's own contractual and technical safeguards.
5. Method of Collecting Personal Data
- Registration form: Information you enter yourself during registration.
- GPS/location permissions: Real-time coordinates obtained from your device's GPS after you explicitly grant permission (check-in feature only).
- Map interaction: Location selected on the map when creating an event (device GPS is not used).
- App usage: Data generated automatically while using social features.
- Image upload: Profile photo or content image you upload.
- Camera permission: Only for QR code reading; no image is stored or transmitted.
The UniNet mobile application does not use browser cookies. Local data is stored only in device memory (SharedPreferences).
6. How Location Data Is Processed
- Event location: Manual selection on the map. Permanently deleted when the event is deleted. Device GPS is not used.
- Check-in location: Your device's real-time GPS coordinate at the time of active check-in. Permanently deleted when the check-in is deleted.
If you do not grant location permission, only the features that require location (creating events and checking in) become unavailable; all other services remain usable.
7. Data Retention Periods
For the Duration of an Active Account
Personal data is retained for as long as necessary to provide the service.
Automatic Deletion Rules
- Notifications: Read notifications are deleted shortly after being read; other notifications are deleted after 180 days at the latest.
- Event location: Permanently deleted when the related event is deleted.
- Check-in location: Permanently deleted when the related check-in is deleted, or after 30 days at the latest.
Upon Account Deletion
When you delete your account, the following data directly associated with your account is permanently deleted as part of the deletion process:
- Profile information (name, e-mail, gender, age, department, university)
- Profile photo and uploaded images
- Check-in history and locations
- Friendships, club memberships
- Notifications, settings, posts, likes, poll responses
The following data continues to be retained in anonymized form:
- Events you created: owner information is removed; the event content remains in the system anonymously.
- Clubs you owned: owner information is removed.
- Legal transaction records: account identifier is removed; the document version and transaction time are retained under a pseudonym for evidentiary purposes.
You can delete your account via Settings → Delete My Account or by writing to iletisim@uninettr.com.
8. Your Privacy Controls
From Account Settings → Privacy, you can at any time:
- Make your profile fully private
- Hide your check-in history
- Hide the events and club memberships you've joined
- Turn off diagnostic and crash reports (telemetry)
- Block any user
9. Children's Privacy
UniNet is intended for users aged 18 and over only. We do not knowingly collect personal data from users under 18. If a user under 18 is identified, the account is immediately closed and all data is permanently deleted.
10. Child Safety and CSAM Policy
UniNet enforces a zero-tolerance policy against Child Sexual Abuse and Exploitation (CSAE) and Child Sexual Abuse Material (CSAM).
The account of any user who shares, distributes, or promotes CSAM on the platform is immediately and permanently closed. Relevant data is preserved, and incident and user information is proactively reported to the competent authorities and law enforcement in accordance with legal obligations.
If you encounter any content or behavior that raises concerns related to CSAE or CSAM, please report it immediately:
E-mail: iletisim@uninettr.com In-app: Use the "Report" button on the relevant post, profile, or event.
11. Your Rights Under the KVKK
Under Article 11 of the KVKK, you have the right to:
- Learn whether your personal data is being processed
- Request information about the processing, if any
- Learn the purpose of processing and whether the data is used in accordance with that purpose
- Know the third parties to whom your data is transferred, domestically or abroad
- Request correction of incomplete or inaccurate data
- Request deletion or destruction of your data
- Request that correction and deletion be notified to third parties to whom the data was transferred
- Object to a result that is to your detriment arising from analysis of the data exclusively through automated systems
- Request compensation for damages arising from unlawful processing of your personal data
12. Data Security
- All data transmission is encrypted with TLS
- Passwords are stored using cryptographic hashing
- Row Level Security (RLS) policies are applied at the database level
- API keys are kept in secure server-side environment variables
- Database access is restricted based on identity, role, record ownership, and visibility preferences
If a breach affecting personal data is detected, the incident is recorded; the Personal Data Protection Board is notified within 72 (seventy-two) hours at the latest from the date the breach becomes known, and affected data subjects are informed in accordance with the applicable legislation and the Board's procedures.
13. Contact and Applications
To exercise your rights or for any privacy-related request:
E-mail: iletisim@uninettr.com In-app: Account Settings → Privacy → Data Request Web: https://uninettr.com/
Your application will be answered within 30 days at the latest. If you find our response inadequate, you may file a complaint with the Personal Data Protection Board at kvkk.gov.tr.
Last Updated: 30 July 2026 Version: 2.1
© UniNet | iletisim@uninettr.com