1. Data controller
FinaX is built and published by Mustafa Evleksiz acting as a natural person, not under a registered company; that person is the data controller. There is no registered trade name or tax number. Contact is by e-mail only: mustafa@mustafaevleksiz.com
2. Personal data processed
Once you create an account and sign in, the following is processed:
- Identity and contact: your e-mail address — the sign-in method itself — and, if you want, your name, which you may leave blank.
- User identifier: a UUID generated by the server. It is not an advertising identifier or a device fingerprint.
- Financial records: the accounts, balances, card limits, transactions and ledger entries you enter yourself.
Nothing else is collected. The app contains no analytics SDK, no ad network and no crash-reporting service, and never touches the advertising identifier.
3. Purposes of processing
The data is processed only for the app's own function: identifying your account and keeping you signed in, storing the financial records you enter and keeping them consistent across your devices, computing the cash-flow projection, and applying the daily exchange rate. There is no profiling, no marketing and no sale to third parties.
4. Legal basis
Processing rests on Article 5(2)(c) of the KVKK: it is directly related to the conclusion or performance of a contract. Holding your account and your records is necessary for you to use the app at all, and because data is processed for no other purpose, no separate explicit consent is taken.
5. Transfers, including abroad
Data is never sold and never shared for marketing. Three pieces of infrastructure are used to make the app work:
- Supabase — the database, authentication and the rate function run here. The servers are in AWS eu-west-2 (London), which is where your data physically rests, so a transfer abroad does take place.
- Apple — if you use "Sign in with Apple", Apple performs the authentication and the app receives only an identity token and, if you choose to share it, your e-mail address.
- Open Exchange Rates — sees currency codes only, and nothing connected to your account.
In addition, if a valid legal demand arrives (a court order, say), as much as the law requires may have to be given up; where the law does not forbid it, you will be told.
6. Retention
Your data is kept until you delete it; nothing expires on its own, because the app exists to remember your history. You can delete records individually, or remove the account entirely from Settings → Delete account, which takes the server rows with it.
7. Your rights
Under Article 11 of the KVKK you have the right to learn whether your personal data is processed, to request information about it, to learn the purpose of processing and whether it is used accordingly, to know the third parties it is transferred to at home or abroad, to have it corrected if it is incomplete or wrong, to request its deletion or destruction, to have those actions notified to the third parties it was transferred to, to object to a result reached solely by automated analysis that works against you, and to claim compensation for damage. You can export your data and delete your account from inside the app; for anything else, write to the address above and you will have a reply within thirty days at the latest.
8. Security
No system is flawless, so this does not say "your data is absolutely safe". What it can say is: row-level security policies mean only the owner can read a record, all network traffic goes over HTTPS, and no keys are embedded in the app bundle.
9. Changes and contact
If this notice changes, the date above is updated. For any question or request: mustafa@mustafaevleksiz.com
10. Legal note
This notice is an engineering statement of what the app actually does; it is not legal advice. A lawyer should be consulted for a final compliance view.