MARLOG, kıyı denizcileri için keşif, öğrenme ve başvuru uygulamasıdır. Gizliliğine saygı duyuyoruz ve yalnızca uygulamanın çalışması için gereken veriyi topluyoruz. Bu belge ne topladığımızı, neden topladığımızı ve hangi haklara sahip olduğunu açıklar.
· Hesap bilgileri — e-posta adresin (giriş için zorunlu), isteğe bağlı görünen ad ve ana liman.
· Konum — cihazının GPS verisi; Ana Sayfa, Tahmin ve Atlas ekranları açıkken, sana en yakın hava durumu ve mekânları gösterebilmek için okunur. Ayrıca "Ziyaret kaydet" düğmesine bastığında mekânın 200 metre yakınında olduğunu doğrulamak için kullanılır. Son konumun, bu ekranlar yeni bir sinyal beklemeden açılabilsin diye cihazında saklanır. Tahmin ekranında bir ana liman belirlersen, deniz durumu uyarılarının nereye bakacağını bilmesi için bu koordinatlar hesabına kaydedilir; Bildirim ayarlarından temizleyebilirsin. Sürekli bir konum geçmişi tutmuyoruz.
· Etkinlik — kaydettiğin ziyaretler, tamamladığın dersler, gözden geçirdiğin kelime kartları, kaydettiğin makaleler ve kazandığın rozetler. Profilini ve keşif döngüsünü besleyen veriler bunlardır.
· Yapay zekâ konuşmaları — uygulama içi asistana (marlog) yazdığın mesajlar, yanıt üretmek için Groq'un API'sine gönderilir. Bir sohbete başladığında, asistanın nerede olduğunu sormadan yakınındaki koşulları yanıtlayabilmesi için yaklaşık koordinatların da gönderilir. Servis yoğun olduğunda sorun Google'ın Gemini API'si üzerinden işlenebilir; böylece asistan "meşgulüm" demek yerine yanıt vermeyi sürdürür. Bu mesajların uzun vadeli arşivini tutmuyoruz; son bağlam cihazında kalır.
· Kullanım — uygulamanın beklediğimiz gibi çalışıp çalışmadığını görmemizi sağlayan birkaç ürün kaydı: uygulamanın açıldığı, tanıtımın ne kadarının izlendiği, haritaya ya da bir derse ulaşılıp ulaşılmadığı, Destekçi ekranının gösterilip gösterilmediği ve bunu neyin tetiklediği, bir satın almanın tamamlanıp tamamlanmadığı ve bir oturumun beklenmedik biçimde kapanıp kapanmadığı. Her kayıt uygulama sürümünü ve platformu taşır. Bunlar cihazında oluşturulan rastgele bir kimlikle sayılır — reklam kimliğinle değil — ve giriş yaptıktan sonra hesabınla da ilişkilendirilir; böylece tamamlanan bir kaydı yarıda bırakılandan ayırabiliriz. Kendi sunucularımızın dışına çıkmaz; hangi ekranlarda gezindiğinin ya da ne okuduğunun kaydını tutmayız.
Rehberini, fotoğraf galerini ya da mikrofon kaydını toplamıyoruz — dikte özelliği yalnızca metin döndürür, hiçbir ses dosyası saklanmaz veya yüklenmez. Cihazındaki diğer uygulamalardan da veri toplamıyoruz. İsteğe bağlı Destekçi aboneliğinin ödemesi tamamen Apple tarafından işlenir — kart bilgilerini hiçbir zaman görmeyiz, yalnızca aboneliğin etkin olup olmadığını biliriz.
Seni hesaba bağlamak, mekândaki ziyaretini doğrulamak (200m yakınlık kontrolü), keşif oyununu (rozetler, haritan, ziyaret geçmişin) çalıştırmak ve Akademi, Haberler ile yapay zekâ asistanını işler kılmak için.
· Supabase — arka uç altyapımız. Hesap, profil ve etkinlik verilerini AB sunucularında saklar. Supabase'in gizlilik politikasına tabidir.
· Apple ile Giriş — Apple kimliğinle giriş yaparsan Apple bize bir tanımlayıcı, izin verirsen adını ve e-postanı verir. Ayrıca sunucumuzda tek bir amaç için bir Apple anahtarı tutarız: Apple, hesabını silmenin bu anahtarı da iptal etmesini şart koşuyor ve bu anahtar olmadan iptal edemeyiz. Uygulama onu hiçbir zaman okuyamaz; hesabınla birlikte silinir.
· Apple Weather — uygulama içindeki hava tahminini sağlar. Koordinatların, senin adına Apple'ın WeatherKit API'sinden veri isteyen sunucumuza gönderilir; hesap verisi paylaşılmaz.
· MET Norway — artık uygulama içi tahmini değil, sunucu tarafındaki deniz durumu uyarı bildirimlerini besler. Yalnızca anonim koordinat alır, hesap verisi paylaşılmaz.
· Groq — yapay zekâ asistanını çalıştırır. Mesajların ve sohbet başında gönderilen koordinatların, Groq, Inc. (ABD) tarafından, Groq'un bu verilerle model eğitmesini yasaklayan hizmet sözleşmesi kapsamında işlenir. Hesap verisi gönderilmez. Groq yoğun olduğunda sorular Google Gemini'ye yönlenir ve Google'ın gizlilik politikası doğrultusunda işlenir.
· Copernicus Marine Service — dalga yüksekliği, deniz suyu sıcaklığı ve akıntı verisi. Yalnızca koordinat alır, hesap verisi paylaşılmaz.
· OBIS — Okyanus Biyoçeşitlilik Arşivi — Canlı Deniz'deki ve asistandaki tür listelerini sağlar. Cihazın, görüntülediğin noktanın koordinatlarıyla OBIS'i doğrudan sorgular; her web isteğinde olduğu gibi OBIS, IP adresini de görür. Hesap verisi gönderilmez.
· OpenStreetMap Nominatim & Photon (Komoot) — yer aramasını sağlar. Yazdığın arama metni bu servislere sunucumuz üzerinden gönderilir; hesap verisi veya IP adresin onlarla paylaşılmaz.
· RevenueCat — isteğe bağlı Destekçi aboneliğini yönetir. Desteğinin cihazlar arasında tanınması için hesap kimliğini ve App Store abonelik durumunu alır. Ödemenin kendisi Apple tarafından işlenir.
· Expo — anlık bildirimleri iletir. Cihazının bildirim jetonu ve bildirim içeriği (bağlama limanının adı ve deniz durumu geçebilir) Expo'nun bildirim servisi üzerinden yönlendirilir.
· Resend — hesap e-postalarını (giriş kodları ve hesap bildirimleri) iletir; bu nedenle e-posta adresini işler.
· Google Cloud Text-to-Speech — Kaptan Brifingi'ni sese çevirir. Sunucumuz üzerinden yalnızca brifing metnini alır — kimliğini veya konumunu asla.
· BigDataCloud — Ana Sayfa, Tahmin ve Atlas başlıklarında görünen yer adını bulmak için koordinatlarını yer adına çevirir. Yaklaşık konumunu ve — her web isteğinde olduğu gibi — IP adresini alır. Hesap verisi gönderilmez.
· Sentry — çökme ve hata raporlaması; böylece tekrar üretemediğimiz sorunları düzeltebiliyoruz. Raporlar hesap kimliğine bağlanır (e-posta adresine asla) ve hatanın oluştuğu ekranı ile performans ölçümlerini içerebilir. Rapordaki konum, gönderilmeden önce yaklaşık 11 km'ye yuvarlanır; arama kutusuna yazdığın metin ise hiçbir zaman gönderilmez, yalnızca kaç karakter olduğu.
· MapLibre, OpenFreeMap, OpenSeaMap, Esri — harita ve uydu görüntüsü sunucuları. Yalnızca görüntülediğiniz bölge için anonim istek alır. Ana ekrandaki küçük harita, Esri'den çevredeki bir alanın tek bir görüntüsünü ister: konumunuz önce yaklaşık 5 km'ye yuvarlanır, yani istek tam konumunuzu değil bir alanı tarif eder. Hesap veya cihaz kimliği gönderilmez.
Verilerine her zaman erişebilir, dışa aktarabilir ya da silebilirsin. Silme talebi için Ayarlar → Hesabı sil yolunu kullan veya bize e-posta at. KVKK ve GDPR kapsamında ayrıca yanlış verileri düzeltme ve denetim makamına şikâyette bulunma hakkına da sahipsin.
MARLOG 13 yaş altı çocuklara yönelik değildir. Bilerek bu yaş grubundan veri toplamayız.
MARLOG Türkiye'den yürütülür. Verileri Türkiye'nin KVKK'sına ve AB'nin GDPR'ına uygun şekilde işlemeyi hedefliyoruz.
Bu politikada önemli bir değişiklik olursa yukarıdaki tarihi güncelleriz ve bir sonraki açılışında uygulama içinde sana haber veririz.
Sorular, talepler veya endişeler için: support@marlog.app
MARLOG is a maritime discovery, learning, and reference app for coastal mariners. We respect your privacy and only collect what we need to make the app work. This document explains what we collect, why, and what control you have.
· Account info — your email address (required for sign-in) and an optional display name and home port.
· Location — your device GPS is read while the Home, Forecast and Atlas screens are open, so we can show the weather and the places near you, and to confirm you are within 200 meters of a place when you tap "Log visit". Your last position is cached on your device so those screens can open without waiting for a new fix. If you set a home port on the Forecast screen, those coordinates are saved to your account so sea-condition alerts know where to check; you can clear it in Notification settings. We do not keep a continuous location history.
· Activity — visits you log, lessons you complete, flashcards you review, articles you save, and badges you earn. This is what powers your profile and the discovery loop.
· AI conversations — messages you send to the in-app assistant (marlog) are sent to Groq's API to generate replies. When you start a conversation, your approximate coordinates are sent with it, so the assistant can answer questions about conditions near you without asking where you are. When the service is saturated, your question may be processed by Google's Gemini API instead, so the assistant keeps answering rather than telling you it is busy. We do not store a long-term archive of these messages; recent context is kept on your device.
· Usage — a handful of product events that tell us whether the app is working as intended: that it was opened, how far through the introduction people get, whether they reach the map or a lesson, whether the Supporter screen was shown and what prompted it, whether a purchase completed, and whether a session ended unexpectedly. Each carries the app version and platform. They are counted against a random identifier created on your device — not your advertising ID — and, once you are signed in, they are also linked to your account, so we can tell a completed sign-up from an abandoned one. They never leave our own servers, and we do not keep a screen-by-screen trail of where you browse or what you read.
We do not collect contacts, your photo library, or microphone recordings — the dictation feature returns text only, and no audio file is stored or uploaded. We collect no data from other apps on your device. Payments for the optional Supporter subscription are processed entirely by Apple — we never see your card details, only whether a subscription is active.
To sign you in, to verify visits at a place (the 200m proximity check), to power the discovery game (badges, your map, your visit history), and to make Academy, News, and the AI assistant work.
· Supabase — our backend. Stores your account, profile, and activity data on EU servers. Subject to Supabase's privacy policy.
· Sign in with Apple — if you sign in with your Apple ID, Apple gives us an identifier and, if you allow it, your name and email. We also keep one Apple token on our server for a single purpose: Apple requires that deleting your account also revokes it, and we cannot do that without it. It is never readable by the app, and it is deleted with your account.
· Apple Weather — powers the in-app forecast. Your coordinates are sent to our server, which requests forecast data from Apple's WeatherKit API on your behalf; no account data is shared.
· MET Norway — powers the server-side sea-condition alert notifications, not the in-app forecast. Receives anonymous coordinates only, no account data.
· Groq — powers the AI assistant. Your messages, and the coordinates sent at the start of a conversation, are processed by Groq, Inc. (US) under its services agreement, which bars Groq from training on them. No account data is sent. When Groq is saturated, questions fall back to Google Gemini, processed per Google's privacy policy.
· Copernicus Marine Service — wave height, sea temperature and currents. Receives coordinates only, no account data.
· OBIS — Ocean Biodiversity Information System — powers the species lists in The Living Sea and the assistant. Your device queries OBIS directly with the coordinates of the point you are viewing, and — as with any web request — OBIS also sees your IP address. No account data is sent.
· OpenStreetMap Nominatim & Photon (Komoot) — power the place search. The text you type is sent to these services through our server; no account data or IP address is shared with them.
· RevenueCat — manages the optional Supporter subscription. Receives your account identifier and App Store subscription status so your support is recognised across devices. Payment itself is handled by Apple.
· Expo — delivers push notifications. Your device's push token and notification content (which can include your home-port name and sea conditions) are routed through Expo's push service.
· Resend — delivers account emails (sign-in codes and account notices) and therefore processes your email address.
· Google Cloud Text-to-Speech — turns the Captain's Brief into audio. Receives only the brief's text through our server — never your identity or location.
· BigDataCloud — turns your coordinates into a place name for the Home, Forecast and Atlas headers. Receives your approximate position and, as with any web request, your IP address. No account data is sent.
· Sentry — crash and error reporting, so we can fix problems we cannot reproduce. Reports are tied to your account identifier (never your email address), and may include the screen you were on and performance timings. Any position in a report is rounded to about 11 km before it is sent, and what you typed into a search box is never sent — only how long it was.
· MapLibre, OpenFreeMap, OpenSeaMap, Esri — map and satellite imagery servers. Receive anonymous requests for the area you are viewing. The Home dashboard thumbnail asks Esri for one image of a surrounding cell: your position is rounded to about 5 km first, so the request describes an area, never your exact location. No account or device identifier is sent.
You can access, export, or delete your data at any time. Use Settings → Delete account to request deletion, or email us. Under KVKK and GDPR you also have the right to rectify inaccurate data and to lodge a complaint with your data protection authority.
MARLOG is not directed at children under 13. We do not knowingly collect data from them.
MARLOG is operated from Türkiye. We aim to handle data in line with Türkiye's KVKK and the EU's GDPR.
If we make significant changes to this policy, we'll update the date above and notify you in the app the next time you open it.
Questions, requests, or concerns: support@marlog.app