Vortie Privacy Policy

Effective date: 1 August 2026 Last updated: 1 August 2026

1. Who We Are

Vortie ("Vortie", "we", "us") is a social discovery and dating app where you share thoughts, vote on other people's thoughts, and connect with people based on how compatible your views are.

The service is operated by Sait Ergün, an individual acting as the data controller (veri sorumlusu), at Balat Mah., Nilüfer, Bursa, Türkiye.

Privacy contact: vortieapp@gmail.com

This policy covers the Vortie mobile apps (iOS and Android) and our website at vortie.app. Section 14.1 applies specifically to users in Türkiye, Section 14.2 to US residents, and Section 14.3 to EEA/UK visitors; everything else applies to everyone. Vortie is for adults only: you must be at least 18 years old to use it.

2. At a Glance

3. Data We Collect

We tag each item with who can see it: (Public) = visible to other users; (Limited) = visible to some users under rules you control; (Private) = visible only to you and us.

3.1 Data you give us

3.2 Data we collect automatically

3.3 Data from sign-in providers

You sign in with Google or Apple. The provider sends us: a provider user ID, your email address and whether it is verified, your display name, and a profile photo URL. We do not save your Google/Apple profile photo to your account. The raw sign-in record is deleted when you complete sign-up; abandoned records expire after 15 minutes and are removed in routine cleanup.

3.4 Data from other users

Other users may generate data about you: reports concerning your content or behaviour, blocks, and anonymous questions sent to your profile.

3.5 What we do NOT collect

No contact list access. No camera or microphone access. No background location tracking. No advertising identifiers. No third-party analytics or advertising SDKs. No cross-app tracking. No payment card data (there are currently no paid features; if we introduce them, payments will be processed by Apple's App Store or Google Play and we will receive only non-identifying transaction confirmations — this policy will be updated first). Our website uses only strictly necessary cookies (session and security) — no advertising or analytics cookies.

4. Sensitive Data

Because Vortie is a dating context, some of what you share needs special care:

We process special-category data only with your explicit consent, which you give through a separate consent step — separate from the Terms of Use and from this notice — when you provide the data. Opinion-revealing content that you choose to publish openly (public thought cards) is additionally processed on the basis that you have manifestly made it public (GDPR Art. 9(2)(e); KVKK Art. 6(3)). We use this data only to operate the features described in this policy — never for advertising, and never shared with third parties except the infrastructure providers in Section 8.

You can withdraw consent at any time: remove optional data (such as the belief field) from your profile and the related display disappears. For data that matching cannot work without (such as who you want to meet), withdrawing consent means you can no longer use the matching features — you can do so by deleting your account. Withdrawal does not affect the lawfulness of processing before withdrawal. We apply enhanced security measures to sensitive data, including the measures required for special categories under Turkish law (Section 12).

US state residents: we use sensitive personal information only for the purposes permitted without opt-out under applicable state law (providing the service you request, security, and legal compliance). We do not use it to infer characteristics for advertising and we do not sell or share it.

5. How We Use Your Data

Your personal data is collected through the mobile apps and our web channels by automated means, and processed for the purposes and on the legal bases below (KVKK Arts. 5–6; GDPR Arts. 6 and 9):

PurposeData usedLegal basis (GDPR / KVKK)
Create and operate your account and profileAccount, profile, photos, locationContract (Art. 6(1)(b) / KVKK 5(2)(c)); explicit consent for special-category fields (Art. 9(2)(a) / KVKK 6)
Matching: compatibility scores, suggestions, discoverVotes, preferences, age, gender, location, activityContract; explicit consent for special-category inputs
Messaging and chat requestsMessages, compatibility scores, settingsContract
Notifications (messages, questions, suggestions, profile views, like/vote milestones)Push token, activity, notification settingsContract; consent (device-level permission) — every type can be switched off individually in settings
Safety and moderation: handling reports, blocks, enforcing our rules, preventing banned users from returningReports, blocks, content, IP addresses, account statusLegitimate interest (Art. 6(1)(f) / KVKK 5(2)(f)): keeping our community safe; for opinion-revealing content, also your explicit consent and — for content you posted publicly — Art. 9(2)(e) / KVKK 6(3)
Security: session management, rate limiting, abuse and fraud preventionIP addresses, user agent, session recordsLegitimate interest: protecting the service and our users
Trend ranking and feed language: ranking popular thought cards, detecting content languageViews, votes, statement textLegitimate interest: making the feed relevant; for opinion-revealing content, the bases in the safety row above
Service improvement and troubleshootingCrash reports (Sentry), aggregate usageLegitimate interest: keeping the app working
Legal compliance and defence of claimsWhatever the obligation requiresLegal obligation (Art. 6(1)(c) / KVKK 5(2)(a, ç))

We do not use your data for third-party advertising, we do not send marketing emails, and we do not sell personal data.

6. Automated Matching and Profiling

Vortie's core feature is automated matching. In plain terms:

We do not make automated decisions with legal or similarly significant effects about you beyond what is described here. If you believe an automated outcome (for example an account restriction) is wrong, contact us (Section 17) and a human will review it. California residents may additionally request information about how our matching technology processed their data (Section 14.2); you can limit its inputs by choosing what you vote on and share, or stop it entirely by deleting your account.

7. Who Can See What

Other users can seeOther users can never see
First name, username, age, zodiac sign, gender, city/district names, match intentionsEmail address, phone/contact data, birth date, exact coordinates
Profile photo; gallery photos per your visibility settings (blurred if locked)Your seeking preference and preferred age range
Biography, prompt answers, profile facts and lifestyle habits you addedYour individual vote on a thought card (except its author — see below), your view history, your reports and blocks
Your thought cards (or "anonymous" without your name), aggregate vote percentages, comments, answered profile questionsPrivate messages (only the recipient sees them)
A compatibility percentage between you and themWho viewed your profile (notifications are anonymous)

Three honest caveats: (1) "Anonymous" features are anonymous to other users, not to us — we keep authorship of anonymous thought cards and questions internally so we can act on abuse. (2) The author of a thought card can see how you voted on their card. (3) Profiles and thought cards are not published on the open web and are not indexed by search engines; the only exception is a share link you yourself create, which shows the already-public version of that content. And as with any social app: other people can screenshot what you show them; be thoughtful about what you put on your profile.

8. How We Share Data

We share personal data only with the service providers (processors) that run Vortie's infrastructure, each bound by a data-processing agreement:

ProviderWhat it processesWhy
Supabase (database, file storage, realtime)All service data described above; photos in a private bucket served via short-lived (10-minute) signed URLs; chat messages relayed over authorized private realtime channelsHosting and operating the service
Hetzner (server hosting, Germany) and Cloudflare (DNS/CDN/proxy)Encrypted traffic, access logs (IP, user agent)Running and protecting the API
Expo push service → Apple APNs / Google FCMPush token; notification content — for chat pushes this includes the sender's name and a preview of the message textDelivering notifications
SentryCrash/error reports and anonymous app-health session counts (configured not to send personal identifiers or IPs)Fixing bugs
Amazon Web Services (Comprehend, Frankfurt)Thought-card text onlyDetecting the language of posts for feed targeting
Upstash (Redis)Rate-limit counters keyed by user ID or IP addressAbuse prevention
Google / AppleYour sign-in (identity token verification); on Android, the map view and place-name lookup use Google Maps/geocoding; on iOS, Apple's geocodingSign-in; showing the location picker map

Beyond processors, we disclose data only: (a) to authorities where a valid legal request compels us; (b) to advisers and successors in a merger, acquisition or similar corporate transaction (this policy would continue to apply); (c) with your direction (e.g. share links you create expose the already-public version of a profile or thought card on the web).

We do not sell personal data and we do not share it for cross-context behavioural advertising. No dating-context data is ever given to ad networks.

9. International Data Transfers

Our core infrastructure is hosted in the European Union: our database, file storage and realtime run on Supabase in Frankfurt, Germany (eu-central-1); our API runs on Hetzner servers in Germany; and language detection runs on AWS in Frankfurt (eu-central-1). Some other providers (Cloudflare, Expo, Sentry, Upstash, Google, Apple) may process data in the United States or other countries.

10. How Long We Keep Your Data

DataRetention
Account, profile, photos, preferencesUntil you delete your account (then see Section 11)
Raw sign-in attempt from Google/AppleDeleted when you complete sign-up; abandoned records expire after 15 minutes and are removed in routine cleanup
Sign-in sessionsAccess tokens expire after 24 hours; refresh sessions expire after 30 days of inactivity and are revoked on logout; session records (IP address, device info) are kept until you delete your account
MessagesUntil you delete your account; the text of messages you sent is removed when your account is deleted
Reports, blocks and moderation recordsFor the life of the account and afterwards as needed to keep the platform safe and comply with law
Consent and legal-compliance recordsAs required by applicable law
Server access logs (IP, user agent)30 days
Activity records (profile views, thought-card views, passed suggestions, score reveals)While your account exists; after deletion they are no longer shown to anyone and remain linked only to a deactivated, scrubbed account record

When a retention purpose lapses, we delete, destroy or irreversibly anonymize the data in periodic cycles in line with our retention and destruction practices.

11. Deleting Your Account

You can delete your account any time in the app: Settings → Delete My Account (two-step confirmation). You can also request deletion at vortie.app/delete-account or by emailing vortieapp@gmail.com.

Deletion is immediate and permanent — there is no deactivation-only option and no restore window. What happens:

Erased: your profile (name, biography, birth date, gender, height/weight, email, location data, matching preferences, sign-in identifiers), profile photo and all gallery photos including stored files, prompt answers, profile facts, lifestyle habits, intentions, likes and reactions, blocks, reports you made, notifications, notification settings, push registrations, and all sign-in sessions. The text of messages you sent is removed from conversations.

Anonymized or detached: thought cards you authored remain in the app as anonymous system posts with no account link to you; your votes, comments and profile questions are deactivated and no longer shown to anyone; thought-card view records are unlinked from you; other activity records (profile views, passed suggestions) remain linked only to the deactivated, scrubbed account record.

Retained: records we need for platform safety (e.g. reports filed about your conduct) and anything we must keep to comply with law or resolve disputes, kept only as long as those purposes require.

12. Security

We take measures appropriate to the sensitivity of dating data: TLS encryption in transit; photos in a private storage bucket accessible only through 10-minute signed URLs; realtime chat channels protected by row-level security so only conversation participants can read or send; short-lived, user-scoped realtime tokens; refresh-token rotation with reuse detection (a stolen token invalidates the whole session family); passwords — where used — stored only as strong salted hashes; per-user and per-IP rate limiting; internal access restricted on a need-to-know basis; and enhanced controls for sensitive data categories as required for special categories under Turkish law. Photo metadata is stripped on your device before upload.

No internet service can promise perfect security. If a breach affects your data, we will notify the competent authority and, where required, you, in line with applicable law (GDPR Art. 33–34, KVKK Art. 12).

13. Safety, Moderation and an Important Disclaimer

You can report any user, thought card, comment or question in-app and block any user (blocking also ends any match between you). Reports are reviewed by our moderation team, which can warn, restrict or ban accounts; we retain ban records to prevent banned users from returning.

We do not run criminal background checks and we do not verify the identity of users. Photos and profiles are user-submitted. Use the same judgment you would with any stranger, especially when meeting in person.

14. Your Rights

Everyone can: access the data we hold about them, correct it (most corrections you can make yourself by editing your profile), delete it (Section 11), object to or restrict certain processing, withdraw any consent, and receive a portable copy of their data. Write to vortieapp@gmail.com — we may ask you to verify your identity first. Exercising your rights never leads to discriminatory treatment.

14.1 Türkiye (KVKK)

Under Article 11 of Law No. 6698 you may: learn whether your data is processed; request information; learn the purpose and whether it is used accordingly; know the third parties to whom it is transferred, in Türkiye or abroad; request correction; request deletion or destruction; request that corrections/deletions be notified to recipients; object to a result produced exclusively by automated analysis; and claim damages for unlawful processing. Apply by email to vortieapp@gmail.com or in writing to Sait Ergün, Balat Mah., Nilüfer, Bursa, Türkiye. We respond free of charge within 30 days. If unsatisfied, you may complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu). (The Turkish version of this policy serves as our aydınlatma metni and is authoritative for users in Türkiye.)

14.2 United States (state privacy laws)

For US residents, Sections 3, 5, 8 and 10 of this policy serve as our notice at collection. Depending on your state, you have the rights to know/access, correct, delete, obtain a portable copy, opt out of sale/sharing and targeted advertising, and limit use of sensitive personal information. We do not sell or share personal information and do not use it for targeted advertising, so there is nothing to opt out of, and a Global Privacy Control signal requires no additional action from us. Categories we collect and disclose to service providers are listed in Sections 3 and 8; we have not sold or shared personal information in the preceding 12 months. Submit requests by email at vortieapp@gmail.com or through our web form at vortie.app/delete-account; an authorized agent may act for you with proof of authorization. We respond within 45 days (extendable once by 45 days). If we deny a request, you may appeal by replying with "Privacy Request Appeal"; if the appeal fails, you may contact your state Attorney General.

14.3 EEA / UK

If GDPR applies to you, the rights above map to Articles 15–22, including the right not to be subject to solely automated decisions with legal or similar effect, and you may lodge a complaint with your local supervisory authority.

15. Children

Vortie is strictly 18+. We require your birth date at sign-up and block registration of anyone under 18; we do not knowingly process data of anyone under 18. If you believe a user is underage, report them in-app; we delete underage accounts and their data.

16. Changes to This Policy

We will post updates here with a new "last updated" date and, for material changes, notify you in the app before they take effect. We review this policy at least every 12 months.

17. Contact

Sait Ergün (data controller) Balat Mah., Nilüfer, Bursa, Türkiye vortieapp@gmail.com