Privacy Policy
Last updated
This is an English translation provided for convenience. The Turkish version is the original and binding text; if the two differ, the Turkish version prevails.
- Effective date
- September 13, 2026
- Last updated
- September 24, 2026
- App
- Sabri (iOS and Android)
- Data controller
- SelfTech (selftech.co)
- Contact
- hello@selftech.co
1. Summary
- To use Sabri, you sign in with Apple or Google. For your account, we store your email address and the name your provider shares.
- Your plan and progress — your reason, your promise, your triggers, the records of your cravings, your urge cards — are stored on our server, linked to your account; they are not lost when you change phones or reinstall the app.
- We measure how you use the app (for example, which step you completed) on our own server. The texts you write never go into this measurement.
- Your subscription is verified by a service called RevenueCat and linked to your account.
- No ads, no ad tracking, no third-party analytics. We do not sell your data.
- You can delete your account at any time from inside the app: Settings → Account → Delete account.
This entire text can be read inside the app, even without an internet connection.
2. What data we collect
“Collect” means that data leaves your device and is stored; this is also Apple's and Google's definition. Under this definition, the only data we collect is the following:
2.1 Account information
- Email address
- The address Apple or Google passes to us. If you choose “Hide My Email” when signing in with Apple, we receive a forwarding address generated by Apple; we do not see your real address.
- Name
- If the provider shares it. Apple passes your name only on the first sign-in and only if you allow it. When you sign in with Google, the name and profile photo link that Google shares are also saved.
- Provider identifier
- The identifier Apple or Google generates for your account, and whether your email is verified. Used to recognize you when you sign in again.
- Account times
- When the account was created and when you last signed in.
- Session information
- For each open session, the IP address and device/browser information (User-Agent). Used to protect your session and to tell abuse apart. Deleted when you sign out and when you delete your account.
2.2 Notification token
If you allow notifications, your device's notification token (push token) and the device's platform (iOS/Android) are stored, linked to your account. The program's daily reminders are scheduled on the device itself. Some notifications are sent from the server and chosen based on how you use the app: for example, if you looked at a feature, if you haven't opened the app for a while, or if your subscription payment didn't go through. These notifications may include a time-limited offer for Sabri Pro. Nothing you type freely goes into a notification's text; answers you selected during onboarding (for example, the moment that is hardest for you) may. You can turn notifications off from the app's Settings screen or from your phone's settings. Expo's notification service (USA) is used to obtain the token and to deliver notifications sent from the server to your device. The token is deleted when you sign out and when you delete your account.
2.3 Subscription information
- The purchased product, subscription and introductory offer status, renewal and expiry times, country and currency.
- Apple receipt information or Google purchase token.
- Device type, operating system and app version.
This information goes to RevenueCat. RevenueCat also notifies our server of subscription changes; our server stores your subscription status matched to your account. This way, your subscription is recognized when you sign in with the same account on another device.
2.4 Device information
For each device you sign in on, the device's brand and model (e.g. “iPhone 11”), operating system and version (e.g. iOS 26), the app version, a random identifier the app generates for this installation, and when the device was first and last seen are stored, linked to your account. We do this to answer your support requests and to find which device or version an error occurs on. The device's hardware identifier, advertising identifier and the name you gave your device are not collected.
2.5 Security logs
For every request to our server, the IP address, device/browser information, requested address, time and result code are logged. These logs are only for security and fault detection and are kept for at most 30 days. Authentication headers are not written to the logs.
2.6 Plan and progress data
This is the data the app actually works with. It is stored on our server, linked to your account, so that your plan and your days are waiting for you when you sign in with the same account on a new phone:
- Your smoking status, daily count and pack price, your quit date and your preparation period
- Your onboarding answers (triggers, reasons for quitting, concerns, previous attempts) and your dependence questionnaire score
- Your “why I'm quitting” text, your Quit Day promise, your new habit and your reward goal
- Your daily logs, your usage (smoking) logs and their context (place, who you were with, feeling)
- Your completed SOS sessions: trigger, your 0-10 ratings, duration, the tools you used and your conversation with Sabri (your replies are ready-made answers chosen from a list)
- Your prep tasks and the texts you write in them, your urge cards, the chats you've read, the name you write on your support card, your settings and your game scores
Part of this content may be considered sensitive because it relates to your smoking habit. It can be read only with your account: every row on the server is locked to your account and no other user can access it. It travels between the app and the server over an encrypted connection. We may review this data in aggregate to improve the product; we do not use it for advertising, sale or profiling.
2.7 Usage measurement
To understand which step of the app people struggle with, we record usage events on our own server: e.g. which onboarding step you saw and how long it took you to get through it, that you completed a prep task, that an SOS session started and how it ended, that you saw the paywall. Events carry only numbers, yes/no values and labels chosen from a list (e.g. “selected 3 triggers”, “wrote a reason: yes”); no text you write goes into any event. No third-party analytics service is used.
2.8 Crash reports
When the app crashes or a screen fails to open, we send a technical record of the error to the error tracking tool on our own server (Bugsink): the type of error and where in the code it occurred, the app and operating system version, the device model. This record is not associated with you: your account identifier, your email, your IP address and the texts you write are not sent. No screenshots are taken and how you use the app is not tracked. Its only purpose is to find and fix the error.
3. What data we don't collect
- Phone number, address, date of birth — not asked.
- Location — no location permission is requested. The “where” you choose in the SOS flow is a label chosen from a list (e.g. “home”, “car”); it is not a GPS location.
- HealthKit or Google Fit data — no integration. What you enter about your smoking habit is stored only as described in 2.6.
- Contacts, photos, microphone, camera — no access to any of them is requested.
- Advertising identifier (IDFA / AAID) — not used. There are no ads in the app.
- Third-party analytics SDKs (Firebase, Amplitude, Mixpanel, etc.) — none. Usage measurement is on our own server (2.7).
- Tracking — in Apple's definition, we do not link your data with other companies' data for advertising purposes, and we do not give it to data brokers.
- Your payment details — we never see your card or bank details. Apple or Google takes the payment.
4. Content that stays on your device
An SOS session in progress and unfinished drafts stay only on your phone; when the session closes, the information in 2.6, together with its conversation, is saved to your account. A copy of your plan is also kept on your phone, so the app works without internet and syncs with your account when a connection is available. App data is not included in Android's automatic backup.
5. Purposes of use
- To create your account, recognize you and protect your session
- To save your plan and progress to your account and carry them between your devices
- To measure which step of the app people struggle with and improve the product (without the texts you write)
- To answer support requests and find which device or version errors occur on
- To verify your subscription, recognize it on another device with the same account, and make “Restore purchases” work
- To tell apart erroneous or fraudulent purchase attempts
- To keep the service secure and detect faults
- If you allowed notifications, to send reminders and notifications suited to your usage (including the Sabri Pro offer)
Your data is not sold, is not used for third-party advertising, and no marketing emails are sent to you.
6. Who processes the data
- Our server — Contabo GmbH
- Account, plan and progress data, usage events, the notification token, device information, subscription status, security logs and crash reports are stored on a server that we manage, located in the European Union and rented from Contabo GmbH. Contabo provides the infrastructure; it does not access the data.
- RevenueCat, Inc. — USA
- Subscription verification. Acts as a data processor; states that it processes data in AWS data centers in the USA. Policy: https://www.revenuecat.com/privacy
- Expo (650 Industries, Inc.) — USA
- Generating the notification token and delivering notifications sent from the server to the device. Policy: https://expo.dev/privacy
- Apple and Google
- Sign-in and payment. You sign in and pay with their accounts; for these operations they act under their own policies: https://www.apple.com/legal/privacy/ · https://policies.google.com/privacy
Apart from these, we do not transfer your data to any third party. If a legally authorized authority requests it in due form, we share only the data requested.
7. Retention periods
- Account information, plan and progress data, notification token, device information and subscription status: as long as your account remains open. Deleted immediately when you delete the account. “Start over” in Settings deletes plan and progress data without closing the account.
- Usage events: linked to your account while it is open. When you delete the account, the link to you is removed; they remain as anonymous numbers with no way back to a person.
- Session information (IP, device information): until the session closes or the account is deleted.
- Security logs: at most 30 days.
- Crash reports: at most 90 days; not associated with a person.
- Server backups: taken every night, kept for 7 days and restored only in a disaster. The backup copy of a deleted account disappears on its own within 8 days at the latest.
- The subscription record at RevenueCat: as long as the subscription and related financial obligations continue. RevenueCat states in its own policy that it may keep it for up to six years after the customer account ends.
- The copy on your device: on your device until you delete it or uninstall the app.
When the period ends, the data is deleted, destroyed or anonymized (KVKK Art. 7).
8. Deleting your account and data
- In the app, tap Settings → Account → Delete account and confirm.
- Your account, your plan and progress data on the server, your notification token, your device information, your subscription record on the server and the personal content in event records received from RevenueCat are deleted immediately. The link between usage events and you is removed. If you sign in again with the same Apple or Google account, a new, empty account is created.
- The copy on your phone is not deleted by deleting the account; to delete it as well, use “Start over” in Settings or uninstall the app.
Deleting the account does not cancel your subscription. To stop being charged, you need to cancel the subscription from your App Store or Google Play account. If you also want the record at RevenueCat deleted, write to hello@selftech.co.
If you cannot access the app, you can send your deletion request from your account's email address to hello@selftech.co.
9. Children
Sabri is designed for people aged 18 and over and is rated accordingly in the stores. It is not directed at children. If you notice that someone under 18 has created an account, write to hello@selftech.co and we will delete the account.
10. KVKK Privacy Notice
This section has been prepared in accordance with Article 10 of Law No. 6698 on the Protection of Personal Data (KVKK) and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform.
10.1 Data controller
- Data controller
- SelfTech (selftech.co)
- Contact
- hello@selftech.co
10.2 Categories of personal data processed
- Identity
- Name (if the provider shares it)
- Contact
- Email address
- Transaction security
- Provider identifier, session IP address and device information, security logs, notification token, device brand and model, operating system and app version, installation identifier
- Customer transaction
- Subscription product, status and times, receipt/purchase token, country and currency
We do not collect any special category of personal data (KVKK Art. 6), including health data. Content that stays on the device is not transferred to us.
10.3 Purposes and legal grounds
- Creating and managing the account; verifying the subscription and linking it to the account; being able to send notifications
- KVKK Art. 5(2)(c): being directly related to the formation or performance of a contract
- Session security, security logs, detecting fraudulent purchase attempts; answering support requests and finding errors by device or version
- KVKK Art. 5(2)(f): the legitimate interest of the data controller, provided it does not harm your fundamental rights and freedoms
- Requests of authorized authorities made in due form
- KVKK Art. 5(2)(ç): fulfilling a legal obligation
Method of collection: The data is obtained by automated means and electronically — from Apple or Google when you sign in with these providers, through the software kits inside the app (RevenueCat, Expo), and from requests to our server.
10.4 Transfer
There is no transfer to a recipient within Turkey. The data is transferred abroad to the service providers listed in section 6: to the European Union for server hosting (Contabo GmbH), to the USA for subscription verification (RevenueCat, Inc.) and to the USA for the notification token (Expo). The transfer is made in accordance with the procedures set out in KVKK Art. 9 and is limited to the purposes written in this section.
10.5 Your rights (KVKK Art. 11) and how to apply
By applying to the data controller, you have the right to:
- a) learn whether your personal data is processed,
- b) request information about it if it has been processed,
- c) learn the purpose of processing and whether it is used in line with that purpose,
- ç) know the third parties to whom it is transferred in Turkey or abroad,
- d) request correction if it is incomplete or inaccurate,
- e) request its deletion or destruction within the framework of KVKK Art. 7,
- f) request that the operations carried out under (d) and (e) be notified to the third parties to whom it was transferred,
- g) object to a result against you arising from analysis exclusively by automated systems,
- ğ) request compensation for damage if you suffer damage due to unlawful processing
These are your rights.
You can send your applications to hello@selftech.co, preferably from your account's email address. Your application will be concluded free of charge within thirty days at the latest; if the process requires an additional cost, the fee in the tariff set by the Board may be charged (KVKK Art. 13). If your application is rejected, the answer is found insufficient or no answer is given in time, you can file a complaint with the Personal Data Protection Board (KVKK Art. 14).
11. Users in the European Union
The app is currently offered in the Turkish market. If you are in the European Union, you can exercise your rights of access, rectification, erasure, restriction of processing, data portability and objection under the GDPR by applying to the same address, and you can lodge a complaint with the supervisory authority of the country you are in. The legal bases correspond to those in 10.3: performance of a contract (Art. 6(1)(b)), legitimate interest (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)).
12. Security
- All traffic between the app and our server travels over an encrypted connection (HTTPS).
- In the database, each user can read only their own rows; this rule is enforced by the database itself (row-level security).
- The server is open only on the necessary ports; repeated failed access attempts are blocked automatically.
- The data on your device is protected by the operating system's app isolation and device encryption; the screen lock is the most effective part of this protection.
No system is completely secure. If a security breach affects your account, we will notify the Board and you in accordance with KVKK Art. 12.
13. Changes to this policy
- When we change it, we update the last updated date at the top of the document.
- We will separately notify you inside the app of any change that expands the type of data we collect or the purpose of processing, before that processing starts.
- We share previous versions on request.
14. Contact
For any question about this policy or your data: hello@selftech.co
Sources
Sources 1–13 were read directly on September 5, 2026, and sources 14–15 on September 13, 2026.
- 1. Apple, App Review Guidelines — 5.1.1 (Data Collection and Storage), 5.1.4 (Kids), 1.4.1 (Physical Harm), 3.1.2 (Subscriptions)
- https://developer.apple.com/app-store/review/guidelines/
- 2. Apple, App Privacy Details on the App Store — definitions of “collect” and “tracking”, data type categories, responsibility for third-party SDKs
- https://developer.apple.com/app-store/app-privacy-details/
- 3. Google Play, Provide information for Google Play's Data safety section — definitions of “collected”/“shared”, exemption for on-device processing
- https://support.google.com/googleplay/android-developer/answer/10787469
- 4. Google Play, User Data policy — requirement for the privacy policy to be both in the store listing and inside the app
- https://support.google.com/googleplay/android-developer/answer/10144311
- 5. RevenueCat, Privacy Policy — end-user data categories, AWS data centers in the USA, data processor role, six-year retention
- https://www.revenuecat.com/privacy
- 6. RevenueCat, Apple App Privacy — which data to declare
- https://www.revenuecat.com/docs/platform-resources/apple-platform-resources/apple-app-privacy
- 7. RevenueCat, Google Play's Data Safety — Financial Info declaration, deletion requests
- https://www.revenuecat.com/docs/platform-resources/google-platform-resources/google-plays-data-safety
- 8. Law No. 6698 on the Protection of Personal Data — Art. 5, 6, 7, 9 (as amended by Law No. 7499), 10, 11, 13, 14, 16
- https://www.mevzuat.gov.tr/mevzuatmetin/1.5.6698.pdf
- 9. Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform (Official Gazette 10/3/2018, No. 30356) — Art. 4, 5
- https://www.resmigazete.gov.tr/eskiler/2018/03/20180310-5.htm
- 10. KVKK, Transfers Abroad — no adequacy decision has been issued yet
- https://www.kvkk.gov.tr/Icerik/2053/Yurtdisina-Aktarim
- 11. KVKK, Public Announcement — exemption criterion for registration with the Data Controllers' Registry (2023/1154)
- https://www.kvkk.gov.tr/Icerik/7646/Kamuoyu-Duyurusu-Veri-Sorumlulari-Siciline-Kayit-Yukumlulugune-Iliskin-Istisna-Kriterinde-Degisiklik-Yapilmasi-Hakkinda-
- 12. GDPR Art. 3 (Territorial scope) and Art. 27 (Representatives)
- https://gdpr-info.eu/art-3-gdpr/ · https://gdpr-info.eu/art-27-gdpr/
- 13. Apple, Request a refund for apps or content
- https://support.apple.com/en-us/118223
- 14. Expo, Privacy Policy — notification token service
- https://expo.dev/privacy
- 15. Apple, Offering account deletion in your app (5.1.1(v))
- https://developer.apple.com/support/offering-account-deletion-in-your-app/