1. Scope
This Privacy Policy describes how Ankaa handles information when you use the Ankaa mobile application in its current release. Ankaa is operated by Ahmet Kılıç.
2. What Ankaa is
Ankaa is a personal thinking and conversation app. It may use AI-assisted responses and optional astrology-related features. Ankaa is not a medical, legal, financial, or therapeutic service.
3. Accounts: guest and Sign in with Apple
- You can continue without creating a permanent account. Guest access uses anonymous authentication with our backend (Supabase Auth) so chat remains protected by a signed session token. Guests can use basic AI chat and safety features.
- Saved Memory, birth profile, charts, and cross-device continuity remain account-only and require Sign in with Apple (when offered). These boundaries are enforced on the server. This release does not offer paid purchases.
- If you Sign in with Apple, we process account identifiers and session tokens. Apple may share a relay email or your email depending on your Apple choices. Guest data is not silently merged into an Apple account.
4. Information we may process
- Authentication identifiers: guest anonymous user IDs and, when you sign in with Apple, permanent account user IDs and optional relay/email addresses.
- Chat / conversation content: Messages you send (guest or signed-in) may be transmitted to our backend for processing when backend chat is enabled. Message content needed to generate a response may be processed by configured AI / model providers under our service agreements. Provider API secrets are never shipped in the app. If the backend or provider is unavailable, chat may not complete.
- Saved Memory (optional, account-only when enforced): Facts you explicitly save on this device. When Memory is on, a small set of approved, relevant facts may be sent with a chat request as low-authority context. Chat history is not treated as Memory. Turning Memory off stops future use; deleting a saved fact removes it from future context.
- Optional birth-profile / astrology data (account-only): Date, time, and place information you choose to enter. Birth place entry uses place search — Ankaa does not require device GPS. Chart-aware answers require verified calculations; mock or unverified data is not presented as verified.
- App-scoped installation identifier: On first launch the app may create a random installation ID stored only in local app storage. It is not a hardware advertising ID (IDFA/IDFV). For guest chat abuse and quota protection, the app may send this value to our backend. The server stores a truncated hash in short-lived in-memory rate-limit windows — raw installation IDs are not kept as durable product analytics.
- IP-derived rate-limit signals: Our edge/backend may use your network address (for example from forwarding headers) to apply coarse abuse limits. Addresses are normalized (such as an IPv4 /24 class) and hashed before bucketing. Raw IP addresses are not written to user-facing product telemetry.
- Profile and preferences: Settings such as language and appearance stored locally and, for permanent accounts, associated with your account scope.
- Operational reliability metrics: When backend services are enabled, Ankaa may record privacy-safe technical metrics about whether chat and sign-in requests succeed, how long responses take (latency buckets), coarse error categories, and whether a session is guest (anonymous) or permanent (Apple). These metrics are for operating the service — not advertising profiles.
- Token and cost estimates: The backend may record approximate model token counts and estimated provider cost figures for cost control. Estimates may be labeled as provider-reported or character-based estimates; unknown or unpriced models are treated as unavailable rather than invented. These figures are operational estimates, not invoices or precise billing statements.
5. Information we do not collect in this release
- Camera, microphone, contacts, or photo library permissions are not requested.
- Advertising analytics, cross-app tracking, and sale of personal data are not implemented.
- Operational metrics do not include chat message text, Memory contents, birth data, email addresses, Apple subject identifiers, bearer tokens, raw user IDs, raw IP addresses, or raw installation IDs.
- Ankaa does not claim end-to-end encryption of chat content unless separately documented for a specific release.
- Health data categories (medical records, clinical diagnoses) are not collected. Optional birth data is calendar/place context for symbolic astrology features only — not health research.
- Precise device location (GPS) is not required for birthplace entry.
- In-app purchases are disabled; purchase history is not collected by Ankaa in this release.
6. Where data is stored
- On your device: chat threads, Memory, preferences, optional birth data, and the app-scoped installation ID may be stored locally.
- On our backend (including Supabase): when backend services are enabled and you have an authenticated session (guest anonymous or Apple), chat content and related account data may be stored in cloud infrastructure accessed through authenticated APIs.
- With service providers: AI providers process message content needed to generate replies; authentication is handled via Apple and Supabase as configured for your build.
7. How we use information
- Provide and secure the service (authentication, chat delivery, guest abuse/quota protection, account management).
- Honor optional birth-data and chart-related requests only when verified calculations are available and the feature is account-allowed.
- Operate saved Memory controls; only approved relevant facts may be used when Memory is on.
- Operate privacy-safe reliability, security, abuse-prevention, and cost-control metrics (latency and error categories, anonymous versus permanent session-class aggregates, and token/cost estimates). These metrics are not used for advertising or cross-app tracking.
- Respond to permanent-account deletion and privacy requests you initiate.
8. Retention and deletion
Device-local data remains until you delete it, remove the app, or sign out of an account scope that clears local cache for that scope. Uninstalling the app removes the local installation ID.
Guest (anonymous) sessions are ephemeral product accounts. Server-side guest chat data follows backend retention for that authenticated user id until purged by normal lifecycle controls; there is no separate permanent “guest account deletion” flow comparable to Apple account deletion.
In-memory abuse/rate-limit buckets (hashed installation and IP-class signals) are short-lived (about one-hour rolling windows) and clear on process restart. Raw installation IDs and raw IPs are not retained as durable analytics datasets for this release.
Operational reliability metrics are retained for about seven days for reliability, security, abuse prevention, and cost control, then deleted or overwritten by normal retention pruning. Aggregates may summarize anonymous versus permanent session classes without treating those aggregates as fully anonymous personal profiles.
Permanent Apple account backend data is retained while your account is active unless you delete your account or deletion is required by law.
Account deletion: when backend deletion is available, permanent-account users can delete their account from Settings. Deletion removes associated server-side account data described in the deletion flow. You may also email kilicahmett99@gmail.com with subject “Ankaa account deletion request”. Deleting your Ankaa account does not automatically cancel an App Store subscription if subscriptions are later offered.
9. Your choices and rights
- Continue as a guest for basic chat, or Sign in with Apple for account-only features and continuity.
- Review and delete Memory, edit or remove optional birth data, and delete local conversations when those features are available to your account type.
- Delete a permanent account when backend deletion is enabled (Settings) or by emailing the privacy contact below.
- Depending on your location, you may have additional privacy rights (access, correction, erasure, restriction, portability, objection). Contact kilicahmett99@gmail.com to exercise applicable rights. Full GDPR / KVKK mapping may be refined by counsel; this page does not claim complete regulatory certification on its own.
10. Children
Ankaa is not directed to children under 13 (or the minimum age required in your jurisdiction). Do not use Ankaa if you are below the minimum age required to consent to data processing where you live.
11. Security limitations
We use reasonable technical and organizational measures, but no method of transmission or storage is completely secure. Do not use Ankaa to share highly sensitive credentials or emergency information.
12. Changes
We may update this policy as the product changes. Material updates will be reflected by a new effective date and version. Continued use after an update means you have read the updated policy.
13. Contact
Privacy questions, rights requests, and account deletion requests:
kilicahmett99@gmail.com
Operator / founder: Ahmet Kılıç · Product: Ankaa
14. Founder / Contact
For partnerships, investment or sponsorship interest, professional opportunities, and press or collaboration requests, contact kilicahmett99@gmail.com (Founder: Ahmet Kılıç · Product: Ankaa).