1 Summary (Plain Language)
Floorly is an offline-first app. The home, room, photo, voice-note, checklist, and floor-plan data you create is stored locally on your device and is not uploaded to our servers.
However, Floorly is not a "nothing ever leaves your device" app. To run ads, understand crashes, measure usage, and process subscriptions, the app integrates third-party SDKs that transmit specific technical data off the device:
- Advertising SDKs (Google AdMob, AppLovin MAX) collect your advertising identifier and device/ad-interaction data to serve ads, including personalized ads, subject to your explicit consent.
- Firebase Analytics, Crashlytics, and Performance Monitoring send usage events, crash/diagnostic data, and performance traces to Google.
- RevenueCat and the App Store / Google Play process your purchase and subscription state.
- If you are a Pro user and enable Cloud Backup, your backup file is uploaded directly to your own Google Drive (Android) or iCloud (iOS) — not to us.
2 Data Controller
Data Controller: İMAN HÜSEYNLİ, an individual indie developer residing in Ankara, Turkey (referred to as "Insep", "we", "us", or "our").
Because Floorly operates entirely without backend servers, we do not directly receive, store, access, or process your property data, photos, voice notes, or any other user content created inside the App. The only personal data we directly receive is communications you voluntarily send to our support email address.
For the data transmitted to third-party SDKs listed in Section 4, we act as an Independent Data Controller solely for the phase of collection and initial transmission from the application. Once transmitted, the respective third-party SDK providers process this data as independent controllers under their own privacy policies, linked in Section 5.
3 Data Stored Only on Your Device (local-only)
The following structured information and media files are created by you and stored locally within the app's secure sandbox database (SQLite/Drift) and private media folder. We do not have access to, nor do we collect or store this data:
- Property records: name/nickname, address, price, deal type (sale/rent), room configuration, gross/net area, floor, building age, monthly dues, notes, star rating, visit date.
- Property location coordinates (latitude/longitude), only if you explicitly trigger the location capture feature (see Section 6).
- Facade orientation captured locally from the device compass.
- Rooms: type, custom name, dimensions, modifiers, doors/windows, tags, notes.
- Photos you attach (stored locally as binary files).
- Voice notes: Creating new voice notes is a Pro/Premium feature. Users on the free tier can only play existing voice notes.
- Checklists, scoring weights, and 2D floor-plan layouts.
This data remains on your device unless you actively choose to export it, share it via the system share sheet (Section 8), or enable Cloud Backup (Section 7). Uninstalling the App deletes this local data permanently from the device.
4 Data That Leaves Your Device & Legal Bases
We map the specific data elements transmitted off your device to their exact legal bases under GDPR Article 6 and KVKK Article 5:
| Data Type | Purpose | Sent To | GDPR Legal Basis | KVKK Legal Basis |
|---|---|---|---|---|
| Advertising identifier (AAID/IDFA), device & network info, ad interactions | Serving and measuring personalized or contextual ads | Google AdMob, AppLovin MAX | Consent (Art. 6(1)(a)) via App Tracking Transparency (iOS) or Consent Dialogs | Açık Rıza (Md. 5(1)) |
| App usage events, screen views, app-generated analytics user ID | Product analytics to monitor and optimize user experience | Firebase Analytics (Google) | Consent (Art. 6(1)(a)) via initial user setup prompt | Açık Rıza (Md. 5(1)) |
| Crash reports, stack traces, device hardware state at time of crash | Diagnosing and resolving system bugs/crashes | Firebase Crashlytics (Google) | Consent (Art. 6(1)(a)) via the in-app consent dialog | Açık Rıza (Md. 5(1)) |
| Performance traces (e.g., export timing), network latency metrics | Monitoring internal application runtime performance | Firebase Performance Monitoring | Consent (Art. 6(1)(a)) via the in-app consent dialog | Açık Rıza (Md. 5(1)) |
| Subscription status, anonymized transaction ID, expiration timestamps | Validating and activating Pro features | RevenueCat, Apple App Store, Google Play | Performance of a Contract (Art. 6(1)(b)) | Sözleşmenin İfası (Md. 5(2)(c)) |
| Your Google account email address | Displaying the currently authenticated account for cloud backup; processed locally on-device via Google Sign-In SDK. This data is temporary and never transmitted to or stored on the Developer's servers. | Processed locally on device | Performance of a Contract (Art. 6(1)(b)) | Sözleşmenin İfası (Md. 5(2)(c)) |
| Your backup archive file (copy of local database and media) | Optional user-initiated secure cloud backup & restoration | Your own Google Drive (Android) or iCloud (iOS) | Performance of a Contract (Art. 6(1)(b)) | Sözleşmenin İfası (Md. 5(2)(c)) |
Note: We do not sell, rent, or trade your personal data.
RevenueCat: We utilize RevenueCat to synchronize your subscription state across devices and validate your Pro tier access. RevenueCat processes anonymized transaction metadata on our behalf as a Data Processor. We do not receive or store any raw payment identifiers (credit card numbers, bank account details, or full billing addresses). The data processed is limited strictly to subscription tokens required to deliver the service you have purchased.
5 Third-Party SDKs and Privacy Policies
Floorly integrates the following third-party operational SDKs. Their data processing operations are governed by their respective privacy disclosures:
6 Permissions and Device Resource Access
Floorly requests runtime device permissions only when you explicitly interact with a feature requiring that permission. You can revoke permissions at any time via your operating system settings.
7 Cloud Backup & Google API Limited Use Disclosure
If you upgrade to Pro and enable Cloud Backup, a local backup archive is transmitted directly to your own personal cloud account.
- Android (Google Drive): Backup data is confined strictly to a hidden, isolated private application data folder via the
drive.appdatascope. This folder is completely inaccessible to other applications, is not visible in your standard Google Drive view, and is never accessed, read, or pooled by the Developer. - iOS (iCloud): Backup data is saved securely to your personal iCloud container tied to your Apple ID.
Google API Services User Data Policy Compliance (Limited Use): Floorly's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements thereof. We do not use Google user data for serving ads, building user profiles, tracking behavior, training artificial intelligence (AI) models, or transmitting information to third parties outside of executing your automated personal backup storage.
8 Sharing and Export
When executing a PDF/PNG export or manual backup export, the application generates the file locally and passes it to the native system share sheet. The file is transmitted exclusively to the destination endpoint selected entirely by you (e.g., instant messaging apps, email clients, or external cloud providers). This transfer occurs outside of our software layer and is governed by your destination provider's terms.
9 Advertising Identifiers and Opt-Out Mechanisms
Free-tier users who have confirmed they are 18 or older may be shown advertisements. Subject to your consent (collected via the Google User Messaging Platform (UMP) / IAB TCF dialog and, on iOS, the App Tracking Transparency prompt), ad networks may use your device's hardware advertising identifier (IDFA on iOS, AAID on Android) to measure ad interactions and personalize ads. If you decline consent, you are shown only non-personalized (contextual) advertisements.
- Consent Frameworks: We implement the standardized Google User Messaging Platform (UMP) complying with the IAB Europe Transparency and Consent Framework. Users in the EEA/UK and Turkey can configure, restrict, or deny tracking permissions directly via the consent banner.
- OS-Level Control: You can reset or fully opt out of personalized tracking via:
- iOS: Settings → Privacy & Security → Tracking (App Tracking Transparency).
- Android: Settings → Google → Ads → Delete/Reset Advertising ID.
- Pro Tier: Purchasing any Pro subscription completely bypasses and deactivates all advertising SDK initialization blocks, eliminating ad tracking entirely.
10 Data Retention
- On-Device Data: Retained indefinitely inside the application sandbox until you clear app data, manually delete records within the app, or uninstall Floorly.
- Cloud Backups: Managed entirely by you; retained in your personal Google Drive or iCloud container until deleted by you.
- Telemetry and Crash Analytics: Retained by Google Firebase for up to 14 months before automated deletion, according to standard Firebase retention parameters.
- Financial Receipts: Transaction states are logged securely by RevenueCat and the app stores in accordance with financial retention laws.
11 Your Rights and Regulatory Compliance
11.1 KVKK (Turkey) Compliance — Law No. 6698
Pursuant to Article 11 of the KVKK, users located in Turkey have the right to contact us at insep9597@gmail.com to:
- Learn whether their personal data is being processed,
- Request information if their data has been processed,
- Learn the purpose of data processing and whether data is used in accordance with its purpose,
- Know the third parties to whom personal data is transferred domestically or abroad,
- Request rectification of incomplete or inaccurate data,
- Request erasure or destruction of personal data under the conditions laid down in Article 7 of the KVKK,
- Object to processing operations executed exclusively via automated systems which produce negative legal consequences for them.
International Data Transfer (Yurt Dışına Veri Aktarımı): Our integrated infrastructure partners (Google Firebase, AdMob, AppLovin, RevenueCat) maintain cloud infrastructure outside the territory of the Republic of Turkey, necessitating the international transfer of certain data.
Pursuant to the amended Article 9 of the Personal Data Protection Law (KVKK, No. 6698), these cross-border technical data transfers are executed based on your Explicit Consent (Açık Rıza, Art. 5(1)), which you provide via the in-app consent management platform before these services are initialized. In addition to your explicit consent, we ensure these transfers remain under Appropriate Safeguards (Uygun Güvenceler) by adhering to the Data Processing Addendums (DPA) and Standard Contractual Clauses (SCCs) provided by our global infrastructure partners. These mechanisms ensure an adequate level of data protection equivalent to that required under Turkish legislation.
11.2 GDPR (EEA/UK) Compliance
For users operating within the European Economic Area (EEA) and the United Kingdom, you possess the rights of access (Art. 15), rectification (Art. 16), erasure/forgetting (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection to processing (Art. 21).
To the extent that Insep acts as a controller under GDPR for the collection and instantaneous transit of SDK telemetry, our legal bases are explicitly itemized in Section 4. Where data resides downstream with third parties (Google, AppLovin, RevenueCat), you may exercise your rights directly against them or contact us at insep9597@gmail.com to facilitate your requests. You have the right to lodge a complaint with an EU Supervisory Authority (Data Protection Authority) in your country of habitual residence.
11.3 United States — State Privacy Rights (e.g., California / CCPA-CPRA)
Floorly is a small, offline-first application and does not meet the revenue or volume thresholds that trigger the California Consumer Privacy Act (CCPA/CPRA) or comparable U.S. state privacy laws. Nonetheless, to the extent any such law applies to you:
- We do not sell your personal data for money.
- Sharing your advertising identifier (IDFA/AAID) with ad networks to serve personalized ads may be treated as "selling" or "sharing" under certain U.S. state laws. You can opt out at any time by declining consent in the in-app privacy/ads dialog (Google UMP) or by using your device's "Limit Ad Tracking" / "Reset Advertising ID" controls described in Section 9.
- We do not knowingly process the personal data of U.S. residents under 18 for targeted advertising; users who indicate they are under 18 receive no advertising or analytics processing (see Section 13).
12 International Data Transfers (Non-Turkey / Non-EEA)
Data processed by third-party SDK providers is transferred to and stored on servers located outside your home jurisdiction, primarily within the United States. These cross-border transfers are protected via appropriate legal frameworks, including the execution of standard contractual clauses (SCCs) approved by the European Commission, ensuring an equivalent level of data protection.
13 Children's Privacy
Floorly is designed and intended for adults aged 18 and over. We do not target, market to, or knowingly collect personal data from anyone under 18.
During the initial onboarding flow, before any advertising or analytics SDK is initialized, the App presents a neutral age-confirmation screen. We store only a single on-device flag indicating whether you confirmed that you are 18 or older. We do not collect or store your date of birth.
If a user indicates they are under 18:
- No advertising SDKs (Google AdMob, AppLovin MAX) are initialized, and no advertisements are served.
- No advertising identifiers (IDFA/AAID) are accessed or transmitted.
- Firebase Analytics collection is disabled (
setAnalyticsCollectionEnabled(false)) and behavioral tracking is suppressed. - Access to the App is restricted to users aged 18 and over.
We do not direct any data about users who indicate they are under 18 to AppLovin, Google AdMob, Firebase, or any other third-party SDK provider.
If you are a parent or legal guardian and believe a minor has provided personal data through Floorly, please contact us at insep9597@gmail.com and we will delete it.
14 Data Security
Local application files are isolated inside the operating system's application sandbox, benefiting from native full-disk hardware encryption, biometric access constraints, and passcode protection enabled at the OS layer. Internally, the SQLite/Drift database abstraction layer strictly utilizes parameterized query compiling to structurally eliminate any risk of local SQL Injection (SQLi) vulnerabilities. All network traffic generated by third-party SDKs enforces Transport Layer Security (TLS/HTTPS) protocols to protect data in transit against interception.
15 Changes to This Privacy Policy
We reserve the right to revise this Privacy Policy to align with functional application updates or shifting statutory legal mandates. Material revisions will be signaled to users via prominent in-app notification flags or through clear version logs within our App Store and Google Play store listings before the changes take effect. Your continued use of Floorly following the posting of modifications indicates your acknowledgement of the updated terms.
16 Regulatory Contact Info
Insep Data Protection Desk
Lead Developer: İMAN HÜSEYNLİ
For comprehensive data verification requests, privacy complaints, or to execute statutory data access rights.
17 Data Erasure & In-App Data Deletion
Since Floorly operates as an offline-first application and does not store your content on centralized backend servers, you maintain absolute control over your records. You can permanently and irreversibly erase all your local data at any time by navigating to Settings > Delete My Data within the App interface.
Executing the "Delete My Data" protocol triggers a complete, end-to-end purge sequence that:
- Permanently destroys the local database (SQLite/Drift), deleting all stored properties, rooms, metric models, checklists, and local app configurations.
- Purges the app's local private sandbox directory, fully deleting all attached room photographs and audio voice notes.
- Automatically drops/invalidates memory states and volatile telemetry, ensuring that past analytical tracking vectors (Firebase Analytics IDs) are entirely disassociated from future device activity.
If you have enabled Cloud Backups via Google Drive or iCloud, you can disconnect your account and purge all stored backup files directly from within the App by navigating to **Backup & Export > Delete Cloud Backup**. This action triggers an automated API call that permanently deletes the Floorly sandbox folder (drive.appdata or the iCloud container) from your personal cloud storage. Alternatively, you may revoke access at any time via your Google Account Security settings or Apple ID settings.