Vortie Privacy Policy
Effective date: 1 August 2026 Last updated: 1 August 2026
1. Who We Are
Vortie ("Vortie", "we", "us") is a social discovery and dating app where you share thoughts, vote on other people's thoughts, and connect with people based on how compatible your views are.
The service is operated by Sait Ergün, an individual acting as the data controller (veri sorumlusu), at Balat Mah., Nilüfer, Bursa, Türkiye.
Privacy contact: vortieapp@gmail.com
This policy covers the Vortie mobile apps (iOS and Android) and our website at vortie.app. Section 14.1 applies specifically to users in Türkiye, Section 14.2 to US residents, and Section 14.3 to EEA/UK visitors; everything else applies to everyone. Vortie is for adults only: you must be at least 18 years old to use it.
2. At a Glance
- We don't sell your data. We don't show ads. We don't use third-party analytics or advertising trackers. Data leaves our systems only to the infrastructure providers listed in Section 8 — never for marketing.
- You choose what's visible. Your exact location coordinates, birth date, email, seeking preference, votes and private messages are never shown to other users. Your profile, photos, thought cards and general location (city) are visible by design — that's how the app works.
- Matching is automated. Your compatibility score with another user is calculated from how similarly you both voted on the same thought cards. Scores gate messaging and photo unlocking. Section 6 explains exactly how.
- Deleting your account erases your personal data. You can delete your account in-app at any time; Section 11 lists precisely what is erased and the little that remains.
3. Data We Collect
We tag each item with who can see it: (Public) = visible to other users; (Limited) = visible to some users under rules you control; (Private) = visible only to you and us.
3.1 Data you give us
- Account data: your first name (Public), an automatically generated username (Public), your email address as provided by Google or Apple (Private), and your birth date (Private — other users see only your age and zodiac sign, which we derive from it**)**.
- Gender and matching preferences: your gender (Public), who you want to meet (men / women / everyone) (Private), your preferred partner age range (Private), and your match intentions (e.g. meeting new people, flirting, something casual, a long-term relationship) (Public).
- Profile details — all optional: biography, profile prompt answers (short written answers to profile prompts), height and weight, lifestyle habits (e.g. smoking, alcohol, sports, screen habits), and profile facts such as education, occupation, pets, diet, whether you have or want children, and belief/religion and religiosity (Public — you choose what to add, and everything you add is shown on your profile). See Section 4 on sensitive data before adding these.
- Photos: a profile photo and up to 12 gallery photos. Profile photos are (Public). For each gallery photo you choose a visibility: public, unlocked at a minimum compatibility score, or matches only (Limited) — locked viewers see only a heavily blurred preview. We strip photo metadata (EXIF, including any embedded location) on your device before upload.
- Location: where you live, and optionally your hometown. You can set these by GPS ("locate me") or by tapping the map — GPS permission is optional. We store the coordinates you set and the resolved place names. Other users see only place names (e.g. city/district) (Public); your coordinates are (Private) and are used for distance-based suggestions (Section 6).
- Content you create: thought cards (statements) (Public) — optionally posted as "anonymous", in which case other users never see your name but we retain authorship internally for safety and moderation; your agree/disagree votes on thought cards (Limited — other users see aggregate percentages; your individual vote on a card is visible only to you and to that card's author**); comments and likes (Public); and anonymous profile questions and answers (Limited — the answer is public on the recipient's profile; the asker's identity is hidden from users but stored internally)**.
- Messages: private messages and chat requests you exchange with other users (Private — visible only to you and the recipient**)**. Our staff do not read your conversations except where a conversation or its participant is reported to us, or where we are legally required to.
- Reports and blocks: if you report content or a user, we store the report, its reason and any note you add; if you block someone, we store the block (Private).
3.2 Data we collect automatically
- Device and connection data: IP address and browser/device user-agent recorded on sign-in sessions and attached to content and actions (posts, votes, likes, comments, messages, questions and answers, reports, blocks, score reveals) for security and abuse prevention; device platform (iOS/Android); device language; app version (Private).
- Push notification token: if you enable notifications, an Expo push token identifying your device (Private).
- Activity data: a coarse "last active" timestamp; which profiles you view and which thought cards you see (used for trend ranking and the notifications described in Section 6); which suggested profiles you pass on or decline and why; when you reveal a compatibility score (Private).
- Crash and error data: if the app crashes or errors, a technical report is sent to Sentry, along with anonymous app-health session counts. We have configured this to exclude performance tracing, session replay, and personal identifiers or IP addresses (Private).
3.3 Data from sign-in providers
You sign in with Google or Apple. The provider sends us: a provider user ID, your email address and whether it is verified, your display name, and a profile photo URL. We do not save your Google/Apple profile photo to your account. The raw sign-in record is deleted when you complete sign-up; abandoned records expire after 15 minutes and are removed in routine cleanup.
3.4 Data from other users
Other users may generate data about you: reports concerning your content or behaviour, blocks, and anonymous questions sent to your profile.
3.5 What we do NOT collect
No contact list access. No camera or microphone access. No background location tracking. No advertising identifiers. No third-party analytics or advertising SDKs. No cross-app tracking. No payment card data (there are currently no paid features; if we introduce them, payments will be processed by Apple's App Store or Google Play and we will receive only non-identifying transaction confirmations — this policy will be updated first). Our website uses only strictly necessary cookies (session and security) — no advertising or analytics cookies.
4. Sensitive Data
Because Vortie is a dating context, some of what you share needs special care:
- Special-category data (GDPR Article 9; KVKK Article 6): your matching preferences (who you want to meet) can imply sexual orientation; the optional belief/religion profile fields directly reveal religious belief; optional lifestyle details (smoking, alcohol, diet) are health-adjacent and we treat them with the same care; and thought cards, prompt answers and votes may reveal opinions and beliefs, including political or religious ones.
- Precise location coordinates are not special-category data under GDPR/KVKK, but they are "sensitive personal information" under US state laws; we process them under our contract with you, solely for the distance-based features in Section 6.
We process special-category data only with your explicit consent, which you give through a separate consent step — separate from the Terms of Use and from this notice — when you provide the data. Opinion-revealing content that you choose to publish openly (public thought cards) is additionally processed on the basis that you have manifestly made it public (GDPR Art. 9(2)(e); KVKK Art. 6(3)). We use this data only to operate the features described in this policy — never for advertising, and never shared with third parties except the infrastructure providers in Section 8.
You can withdraw consent at any time: remove optional data (such as the belief field) from your profile and the related display disappears. For data that matching cannot work without (such as who you want to meet), withdrawing consent means you can no longer use the matching features — you can do so by deleting your account. Withdrawal does not affect the lawfulness of processing before withdrawal. We apply enhanced security measures to sensitive data, including the measures required for special categories under Turkish law (Section 12).
US state residents: we use sensitive personal information only for the purposes permitted without opt-out under applicable state law (providing the service you request, security, and legal compliance). We do not use it to infer characteristics for advertising and we do not sell or share it.
5. How We Use Your Data
Your personal data is collected through the mobile apps and our web channels by automated means, and processed for the purposes and on the legal bases below (KVKK Arts. 5–6; GDPR Arts. 6 and 9):
| Purpose | Data used | Legal basis (GDPR / KVKK) |
|---|---|---|
| Create and operate your account and profile | Account, profile, photos, location | Contract (Art. 6(1)(b) / KVKK 5(2)(c)); explicit consent for special-category fields (Art. 9(2)(a) / KVKK 6) |
| Matching: compatibility scores, suggestions, discover | Votes, preferences, age, gender, location, activity | Contract; explicit consent for special-category inputs |
| Messaging and chat requests | Messages, compatibility scores, settings | Contract |
| Notifications (messages, questions, suggestions, profile views, like/vote milestones) | Push token, activity, notification settings | Contract; consent (device-level permission) — every type can be switched off individually in settings |
| Safety and moderation: handling reports, blocks, enforcing our rules, preventing banned users from returning | Reports, blocks, content, IP addresses, account status | Legitimate interest (Art. 6(1)(f) / KVKK 5(2)(f)): keeping our community safe; for opinion-revealing content, also your explicit consent and — for content you posted publicly — Art. 9(2)(e) / KVKK 6(3) |
| Security: session management, rate limiting, abuse and fraud prevention | IP addresses, user agent, session records | Legitimate interest: protecting the service and our users |
| Trend ranking and feed language: ranking popular thought cards, detecting content language | Views, votes, statement text | Legitimate interest: making the feed relevant; for opinion-revealing content, the bases in the safety row above |
| Service improvement and troubleshooting | Crash reports (Sentry), aggregate usage | Legitimate interest: keeping the app working |
| Legal compliance and defence of claims | Whatever the obligation requires | Legal obligation (Art. 6(1)(c) / KVKK 5(2)(a, ç)) |
We do not use your data for third-party advertising, we do not send marketing emails, and we do not sell personal data.
6. Automated Matching and Profiling
Vortie's core feature is automated matching. In plain terms:
- Compatibility score. When you and another user have voted on enough of the same thought cards, we compute a 0–100 compatibility score from how similarly you voted: identical answers raise it, opposite answers lower it. Scores are recalculated as you both keep voting, and we keep a history of recalculations.
- What the score does. (a) Messaging: you can send someone a chat request only if your pairwise score meets the recipient's own minimum-score setting (and a minimum number of common voted cards). The check happens when a conversation starts; an existing conversation is not closed if the score later drops. (b) Photo unlocking: gallery photos set to "minimum score" visibility unlock for viewers whose score with the owner passes the owner's threshold. (c) Score reveals: you can reveal your score with a limited number of profiles per day, and we record each reveal.
- Suggestions and Discover. We periodically suggest profiles filtered by mutual gender preference and age range, above a minimum compatibility floor, searching an expanding radius around your living location (roughly 30 km, then 60, then 90, then country-wide) — this is why we store your coordinates. Discover shows the nearest eligible profiles, optionally narrowed by filters you choose; unlike suggestions, it applies no minimum compatibility score.
- Notifications. Like/vote milestone notifications fire at algorithmic thresholds (5, 10, 20, 50, …). If someone views your profile you may get an anonymous "your profile was viewed" notification that may include general attributes such as age and gender but never the viewer's identity.
We do not make automated decisions with legal or similarly significant effects about you beyond what is described here. If you believe an automated outcome (for example an account restriction) is wrong, contact us (Section 17) and a human will review it. California residents may additionally request information about how our matching technology processed their data (Section 14.2); you can limit its inputs by choosing what you vote on and share, or stop it entirely by deleting your account.
7. Who Can See What
| Other users can see | Other users can never see |
|---|---|
| First name, username, age, zodiac sign, gender, city/district names, match intentions | Email address, phone/contact data, birth date, exact coordinates |
| Profile photo; gallery photos per your visibility settings (blurred if locked) | Your seeking preference and preferred age range |
| Biography, prompt answers, profile facts and lifestyle habits you added | Your individual vote on a thought card (except its author — see below), your view history, your reports and blocks |
| Your thought cards (or "anonymous" without your name), aggregate vote percentages, comments, answered profile questions | Private messages (only the recipient sees them) |
| A compatibility percentage between you and them | Who viewed your profile (notifications are anonymous) |
Three honest caveats: (1) "Anonymous" features are anonymous to other users, not to us — we keep authorship of anonymous thought cards and questions internally so we can act on abuse. (2) The author of a thought card can see how you voted on their card. (3) Profiles and thought cards are not published on the open web and are not indexed by search engines; the only exception is a share link you yourself create, which shows the already-public version of that content. And as with any social app: other people can screenshot what you show them; be thoughtful about what you put on your profile.
8. How We Share Data
We share personal data only with the service providers (processors) that run Vortie's infrastructure, each bound by a data-processing agreement:
| Provider | What it processes | Why |
|---|---|---|
| Supabase (database, file storage, realtime) | All service data described above; photos in a private bucket served via short-lived (10-minute) signed URLs; chat messages relayed over authorized private realtime channels | Hosting and operating the service |
| Hetzner (server hosting, Germany) and Cloudflare (DNS/CDN/proxy) | Encrypted traffic, access logs (IP, user agent) | Running and protecting the API |
| Expo push service → Apple APNs / Google FCM | Push token; notification content — for chat pushes this includes the sender's name and a preview of the message text | Delivering notifications |
| Sentry | Crash/error reports and anonymous app-health session counts (configured not to send personal identifiers or IPs) | Fixing bugs |
| Amazon Web Services (Comprehend, Frankfurt) | Thought-card text only | Detecting the language of posts for feed targeting |
| Upstash (Redis) | Rate-limit counters keyed by user ID or IP address | Abuse prevention |
| Google / Apple | Your sign-in (identity token verification); on Android, the map view and place-name lookup use Google Maps/geocoding; on iOS, Apple's geocoding | Sign-in; showing the location picker map |
Beyond processors, we disclose data only: (a) to authorities where a valid legal request compels us; (b) to advisers and successors in a merger, acquisition or similar corporate transaction (this policy would continue to apply); (c) with your direction (e.g. share links you create expose the already-public version of a profile or thought card on the web).
We do not sell personal data and we do not share it for cross-context behavioural advertising. No dating-context data is ever given to ad networks.
9. International Data Transfers
Our core infrastructure is hosted in the European Union: our database, file storage and realtime run on Supabase in Frankfurt, Germany (eu-central-1); our API runs on Hetzner servers in Germany; and language detection runs on AWS in Frankfurt (eu-central-1). Some other providers (Cloudflare, Expo, Sentry, Upstash, Google, Apple) may process data in the United States or other countries.
- For users in Türkiye: because all of these providers are located outside Türkiye, transfers abroad are made under KVKK Article 9 on the basis of the Standard Contractual Clauses published by the Personal Data Protection Authority, signed with each foreign recipient and notified to the Authority.
- For EEA/UK visitors: the core infrastructure stays within the EU; where any provider processes data outside the EEA, transfers rely on adequacy decisions where available and otherwise on the European Commission's Standard Contractual Clauses (and the UK addendum).
10. How Long We Keep Your Data
| Data | Retention |
|---|---|
| Account, profile, photos, preferences | Until you delete your account (then see Section 11) |
| Raw sign-in attempt from Google/Apple | Deleted when you complete sign-up; abandoned records expire after 15 minutes and are removed in routine cleanup |
| Sign-in sessions | Access tokens expire after 24 hours; refresh sessions expire after 30 days of inactivity and are revoked on logout; session records (IP address, device info) are kept until you delete your account |
| Messages | Until you delete your account; the text of messages you sent is removed when your account is deleted |
| Reports, blocks and moderation records | For the life of the account and afterwards as needed to keep the platform safe and comply with law |
| Consent and legal-compliance records | As required by applicable law |
| Server access logs (IP, user agent) | 30 days |
| Activity records (profile views, thought-card views, passed suggestions, score reveals) | While your account exists; after deletion they are no longer shown to anyone and remain linked only to a deactivated, scrubbed account record |
When a retention purpose lapses, we delete, destroy or irreversibly anonymize the data in periodic cycles in line with our retention and destruction practices.
11. Deleting Your Account
You can delete your account any time in the app: Settings → Delete My Account (two-step confirmation). You can also request deletion at vortie.app/delete-account or by emailing vortieapp@gmail.com.
Deletion is immediate and permanent — there is no deactivation-only option and no restore window. What happens:
Erased: your profile (name, biography, birth date, gender, height/weight, email, location data, matching preferences, sign-in identifiers), profile photo and all gallery photos including stored files, prompt answers, profile facts, lifestyle habits, intentions, likes and reactions, blocks, reports you made, notifications, notification settings, push registrations, and all sign-in sessions. The text of messages you sent is removed from conversations.
Anonymized or detached: thought cards you authored remain in the app as anonymous system posts with no account link to you; your votes, comments and profile questions are deactivated and no longer shown to anyone; thought-card view records are unlinked from you; other activity records (profile views, passed suggestions) remain linked only to the deactivated, scrubbed account record.
Retained: records we need for platform safety (e.g. reports filed about your conduct) and anything we must keep to comply with law or resolve disputes, kept only as long as those purposes require.
12. Security
We take measures appropriate to the sensitivity of dating data: TLS encryption in transit; photos in a private storage bucket accessible only through 10-minute signed URLs; realtime chat channels protected by row-level security so only conversation participants can read or send; short-lived, user-scoped realtime tokens; refresh-token rotation with reuse detection (a stolen token invalidates the whole session family); passwords — where used — stored only as strong salted hashes; per-user and per-IP rate limiting; internal access restricted on a need-to-know basis; and enhanced controls for sensitive data categories as required for special categories under Turkish law. Photo metadata is stripped on your device before upload.
No internet service can promise perfect security. If a breach affects your data, we will notify the competent authority and, where required, you, in line with applicable law (GDPR Art. 33–34, KVKK Art. 12).
13. Safety, Moderation and an Important Disclaimer
You can report any user, thought card, comment or question in-app and block any user (blocking also ends any match between you). Reports are reviewed by our moderation team, which can warn, restrict or ban accounts; we retain ban records to prevent banned users from returning.
We do not run criminal background checks and we do not verify the identity of users. Photos and profiles are user-submitted. Use the same judgment you would with any stranger, especially when meeting in person.
14. Your Rights
Everyone can: access the data we hold about them, correct it (most corrections you can make yourself by editing your profile), delete it (Section 11), object to or restrict certain processing, withdraw any consent, and receive a portable copy of their data. Write to vortieapp@gmail.com — we may ask you to verify your identity first. Exercising your rights never leads to discriminatory treatment.
14.1 Türkiye (KVKK)
Under Article 11 of Law No. 6698 you may: learn whether your data is processed; request information; learn the purpose and whether it is used accordingly; know the third parties to whom it is transferred, in Türkiye or abroad; request correction; request deletion or destruction; request that corrections/deletions be notified to recipients; object to a result produced exclusively by automated analysis; and claim damages for unlawful processing. Apply by email to vortieapp@gmail.com or in writing to Sait Ergün, Balat Mah., Nilüfer, Bursa, Türkiye. We respond free of charge within 30 days. If unsatisfied, you may complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu). (The Turkish version of this policy serves as our aydınlatma metni and is authoritative for users in Türkiye.)
14.2 United States (state privacy laws)
For US residents, Sections 3, 5, 8 and 10 of this policy serve as our notice at collection. Depending on your state, you have the rights to know/access, correct, delete, obtain a portable copy, opt out of sale/sharing and targeted advertising, and limit use of sensitive personal information. We do not sell or share personal information and do not use it for targeted advertising, so there is nothing to opt out of, and a Global Privacy Control signal requires no additional action from us. Categories we collect and disclose to service providers are listed in Sections 3 and 8; we have not sold or shared personal information in the preceding 12 months. Submit requests by email at vortieapp@gmail.com or through our web form at vortie.app/delete-account; an authorized agent may act for you with proof of authorization. We respond within 45 days (extendable once by 45 days). If we deny a request, you may appeal by replying with "Privacy Request Appeal"; if the appeal fails, you may contact your state Attorney General.
14.3 EEA / UK
If GDPR applies to you, the rights above map to Articles 15–22, including the right not to be subject to solely automated decisions with legal or similar effect, and you may lodge a complaint with your local supervisory authority.
15. Children
Vortie is strictly 18+. We require your birth date at sign-up and block registration of anyone under 18; we do not knowingly process data of anyone under 18. If you believe a user is underage, report them in-app; we delete underage accounts and their data.
16. Changes to This Policy
We will post updates here with a new "last updated" date and, for material changes, notify you in the app before they take effect. We review this policy at least every 12 months.
17. Contact
Sait Ergün (data controller) Balat Mah., Nilüfer, Bursa, Türkiye vortieapp@gmail.com