Ferla Privacy Policy
Effective: 3 August 2026
Version: 3.0
Data controller
Name: 3AN CREATIVE STUDIO
Address: Kartaltepe Mah. Malazgirt Cad. No:10, B Blok Daire 134, 34295 Küçükçekmece / İstanbul, Türkiye
Country: Türkiye
Tax / registry no: 9960463053
KEP (registered e-mail, Türkiye only): None
VERBİS registration: Not required
EU representative (GDPR Art. 27): None
Contact for all privacy requests: info@ferla.app
1. What this policy covers
This policy explains what Ferla ("the app") collects, why, who it is shared
with, how long it is kept, and what you can do about it. It applies to the iOS
and Android apps published under the bundle identifier com.ferla.app and to
the Ferla backend services.
Ferla is a personal bookkeeping app. It is not a bank, and it does not
connect to your bank account.
2. Data we collect
| Data | Why we need it | Legal basis | Where it is stored | Kept for |
|---|---|---|---|---|
| Email address | To create your account and sign you in | Contract | Supabase (EU, Ireland) | Until you delete your account |
| Password (hashed, never readable) | To sign you in | Contract | Supabase (EU) | Until you delete your account |
| Display name, profile photo | To personalise the app and show you to family members you invite | Contract | Supabase (EU) | Until you delete them or your account |
| Transactions: amount, currency, date, category, note, account | This is the core function of the app | Contract | Supabase (EU) | Until you delete them or your account |
| Goals, budgets, debts, receivables, subscriptions, portfolio holdings | Same — the records you keep | Contract | Supabase (EU) | Until you delete them or your account |
| Location attached to a transaction: coordinates + place name | Only added to a transaction you are recording, so the spending map can show where you spent. Optional; the app works fully without it | Consent | Supabase (EU), on the transaction row, and synced to your devices | Until you delete that transaction |
| Receipt photo | Sent for text extraction so amount, date and merchant can be filled in | Consent | Sent to the AI provider for processing only; never stored by Ferla, never stored in the app's file storage | Not retained after processing |
| Voice audio | Sent to the speech provider while the assistant is listening, so your spoken request can be understood | Consent | Streamed to the AI provider; never stored by Ferla | Not retained after the session |
| Assistant messages (your question, the answer) | To answer you and show your chat history | Contract | Supabase (EU) | Until you delete your account |
| Financial summary sent with an assistant question (e.g. this month's total) | So the answer matches your real numbers | Contract | Sent to the AI provider for that one request | Not retained after the request |
| Push notification token (a device address, not your identity) | To deliver the reminders you turned on | Consent | Supabase (EU) | Until you turn notifications off or delete your account |
| Device model, OS version, app version, crash stack | Crash diagnostics and support | Legitimate interest | Sentry | 90 days |
| Product usage events (screen opened, feature used) | To improve the app. Only with your explicit consent, and never containing amounts, names, emails or note text | Consent | PostHog (EU) | 12 months |
| Subscription status, purchase and renewal history | To unlock paid features, honour restores, and meet tax/bookkeeping duties | Contract + legal obligation | RevenueCat, Apple, Google | Duration of the commercial relationship, then the statutory retention period |
| Family/group membership and the entries you add to a shared budget | So invited members can see the shared ledger they agreed to share | Contract | Supabase (EU) | Until you leave the family or delete your account |
Biometrics: if you turn on Face ID, Touch ID or fingerprint unlock, the check
happens inside your phone's own security chip. Ferla receives a yes/no
answer only. We never see, receive or store your fingerprint or face data.
We do not collect: your contacts, health data, browsing history, advertising
identifiers, precise background location, or bank login credentials.
3. Tracking and advertising
Ferla does no cross-app or cross-site tracking, shows no advertising,
and never sells or rents your personal data. The app does not use Apple's
App Tracking Transparency prompt because it has nothing to track.
4. Legal basis (GDPR Art. 6 / KVKK Art. 5)
| Purpose | GDPR legal basis | KVKK basis (Turkish law) |
|---|---|---|
| Running your account, storing your records, syncing your devices | Performance of a contract, Art. 6(1)(b) | Performance of a contract, art. 5/2-c |
| Crash diagnostics, abuse prevention, service security | Legitimate interest, Art. 6(1)(f) | Legitimate interest, art. 5/2-f |
| Product analytics | Consent, Art. 6(1)(a) — opt-in, off by default, revocable | Explicit consent, art. 5/1 |
| Location on a transaction | Consent, Art. 6(1)(a) — OS permission, revocable | Explicit consent, art. 5/1 |
| Receipt scanning, voice assistant, AI answers | Consent, Art. 6(1)(a) — you start each one | Explicit consent, art. 5/1 |
| Push notifications | Consent, Art. 6(1)(a) | Explicit consent, art. 5/1 |
| Keeping purchase records for tax and accounting | Legal obligation, Art. 6(1)(c) | Legal obligation, art. 5/2-ç |
Withdrawing consent stops future processing; it does not make earlier
processing unlawful.
5. Who processes your data (sub-processors)
| Processor | What it does | Where |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | European Union (Ireland) |
| Google (Gemini API, Gemini Live API) | Receipt text extraction, AI assistant answers, live voice conversation | United States / Google Cloud regions |
| Groq | Speech-to-text, and fallback AI answers when the primary provider fails | United States |
| Anthropic (Claude API) | AI assistant answers on paid plans | United States |
| OpenAI | Natural-sounding voice output for the assistant | United States |
| Sentry | Crash and error reporting | European Union |
| PostHog | Product analytics, only with your consent | European Union |
| RevenueCat | Subscription and purchase management | United States |
| Expo (EAS) | App updates and push notification delivery | United States |
| Apple / Google | App distribution, payment, push delivery | Global |
AI providers do not use your data to train their models. AI requests go
through Ferla's own servers, carry only the context that the request needs, and
never carry your email address or password.
6. International transfers
Your account, records and analytics are hosted inside the European Union.
Some processing happens outside the EU and outside Türkiye, mainly in the
United States: AI answers, receipt reading, speech-to-text, spoken replies,
subscription checks, and app updates. This means that when you use the
assistant, scan a receipt or speak to Ferla, that request leaves the country.
- GDPR (Art. 44–49): transfers rest on the providers' Standard Contractual
Clauses and their data processing agreements.
- KVKK (Art. 9): these transfers are made on the basis of your **explicit
consent** for the optional features (assistant, receipt scan, voice), and on
standard contract undertakings for the rest. If you never use the AI features,
no personal data of yours goes to those providers.
- If you do not want data leaving the country, do not enable the assistant,
receipt scanning or the voice features; every other feature keeps working.
7. Security
- All traffic is encrypted in transit; stored data is encrypted by the hosting
provider.
- Every database table has row-level access rules: one account cannot read
another account's rows.
- Sign-in keys are kept in the phone's secure hardware store (iOS Keychain /
Android Keystore), never in plain files.
- The app can be locked with Face ID, Touch ID, fingerprint or a device
passcode.
- Crash reports are stripped of personal details before they are sent.
- No security is perfect. If a breach affects your rights we notify you and the
competent authority within 72 hours (GDPR Art. 33–34; KVKK: without undue delay).
8. Your rights
Under KVKK Art. 11 and GDPR Art. 15–22 you can, at any time and free of charge:
| Right | How to use it |
|---|---|
| Learn whether your data is processed, and request information about it | Read this policy, or write to info@ferla.app |
| Access and receive a copy (portability) | Settings → Manage my data → Export. You get a CSV file and a full JSON file, on the spot |
| Correct data that is wrong or incomplete | Edit the record in the app |
| Erase your data / be forgotten | Settings → Manage my data → Delete account |
| Object to processing based on legitimate interest | Write to info@ferla.app |
| Withdraw consent | Analytics: Settings → Privacy. Location: your phone's Settings → Ferla → Location. Notifications: Settings → Notifications. Assistant, receipt scan and voice: simply stop using them |
| Restrict processing | Write to info@ferla.app |
| Learn who your data was transferred to, at home or abroad | Sections 5 and 6 above |
| Ask that any automatic analysis be reviewed by a person, and claim damages if the law was broken | Write to info@ferla.app |
| Complain to a supervisory authority | Türkiye: Kişisel Verileri Koruma Kurumu (kvkk.gov.tr). EU: your national data protection authority |
How to apply: send your request to info@ferla.app from the email
address on your account, or in writing to the postal address at the top of this
document. We reply within 30 days (KVKK Art. 13). We do not charge for this,
unless a request is clearly excessive or repetitive.
Ferla does not make any decision about you that produces a legal or similarly
significant effect purely by automated means.
9. Children
You must be at least 16 years old to create a Ferla account. This single
threshold is used in every country, because it is the highest age of digital
consent under GDPR Art. 8 and it is above the US COPPA threshold of 13.
Ferla is not directed at children, and we do not knowingly collect data from
anyone under 16. If a parent or guardian believes a child has created an
account, write to info@ferla.app and we will delete the account and its
data.
10. Analytics consent and cookies
The app is not a website and sets **no advertising cookies and no tracking
pixels**.
The only optional measurement is product analytics (PostHog). It is **off until
you say yes**: on first launch a plain-language card asks whether Ferla may
collect anonymous usage statistics, with a clear decline option. Declining
changes nothing about the app. You can change your answer at any time in
Settings → Privacy, and turning it off stops collection immediately.
Analytics events carry only an anonymous identifier plus non-personal context
(which screen, which feature). Amounts, names, notes and email addresses are
stripped automatically before anything is sent.
Aggregate statistics and benchmarks
If you have given analytics consent, we may also combine those measurements into
aggregate statistics — for example what share of people reach a savings goal,
or how spending typically spreads across categories — and use them to improve
Ferla and to show anonymous comparisons inside the app ("people with a similar
income save about X%").
These statistics describe groups, never a person. They are produced from data
that has been aggregated and stripped of identifiers first, and the result cannot
be traced back to you or to any single user. Withdrawing your consent stops your
data feeding new statistics; figures already aggregated contain nothing personal
and therefore cannot be unmixed.
We do not use the content of your transactions, notes, receipts or assistant
conversations to train artificial-intelligence models — neither ours nor anyone
else's. Our AI providers are contractually barred from training on what we send
them (see section 5).
11. Changes to this policy
If this policy changes in a way that matters, we show a notice inside the app
before the change takes effect, and we update the version number and the
effective date at the top. Older versions are kept on request.
12. Contact
info@ferla.app — we answer within 30 days.