TALEMARK PRIVACY POLICY
Last updated: 27 July 2026 Effective date: 27 July 2026 Document version: 1.0
This Privacy Policy explains how your personal data is collected, used, stored, transferred and protected when you use the Talemark mobile application, the related services offered by Talemark and the support channels connected to those services.
Talemark is a film and book journaling platform where users can log the films they watch and the books they read, rate and review them, create lists and quotes, and interact with other users.
This policy is not a contract or a blanket explicit consent form. It is prepared to inform you about the processing of your personal data. For processing activities that require your explicit consent, a separate choice based on your free will is offered within the application.
1. Data controller and contact
The data controller who determines the purposes and means of processing personal data within Talemark:
- Service and brand: Talemark
- Data controller: Gökhan Kara
- Privacy and personal data requests: privacy@talemark.app
- General support: support@talemark.app
You can contact us through the channels above regarding this Privacy Policy, your personal data or your rights.
2. Scope and core principles
We aim to process your personal data in a manner that is:
- lawful and compliant with the rules of good faith,
- accurate and, where necessary, up to date,
- connected to specific, explicit and legitimate purposes,
- limited to and proportionate with the purposes for which they are processed,
- retained only for the period required,
- protected with appropriate technical and administrative measures.
Talemark is free of charge and currently does not offer in-app purchases or payment transactions. For this reason, we do not collect payment card or bank account data. We do not request precise GPS location, biometric data or identity document data.
Talemark does not ask you for special categories of personal data and does not intend to process such data. Nevertheless, it is possible for you to write sensitive information such as health, belief, political opinion or similar into free-text fields such as biography, review, comment, quote or private note, at your own choice. We recommend that you do not share special categories of information that are not necessary for the use of the service.
3. Personal data we process
3.1 Account and identity data
To create your account, enable you to sign in securely and carry out your account operations, we may process the following data:
- email address,
- the username you choose,
- account creation and account status information,
- technical records relating to email verification and password reset operations,
- if you sign in with Google, the name, email address and profile picture shared by Google,
- the sign-in method you use and identity provider connection information.
We do not access your Google password and we do not request other content in your Google account.
3.2 Profile data
At your choice, you may add the following profile information:
- profile photo and profile banner,
- biography,
- social media or internet links,
- application language preference.
Your username, profile photo, profile banner, biography and social links may be part of your public profile.
3.3 User content and culture journal data
We may process the following content you create on Talemark:
- watch and reading journals,
- ratings and dates,
- film and book reviews,
- replies, likes and list comments,
- lists and list items,
- book quotes,
- favorites,
- follow and follower relationships,
- reading progress,
- reading goals,
- agenda and personal notes.
Reviews, public lists, comments, quotes, favorites and follow relationships may be shown to other users as part of community features. Reading progress, reading goals and agenda notes, on the other hand, are private areas accessible only from your account unless otherwise clearly stated in the product design.
3.4 Community safety and moderation data
In order to enforce the community guidelines and protect users and the platform, we may process the following data:
- records relating to accounts you have blocked or that have blocked you,
- reports you have submitted or that have been submitted about you,
- the content subject to the report and the reason for the report,
- moderation reviews and decisions,
- records of warnings, content hiding, temporary restriction, suspension or account closure,
- appeals and appeal outcomes,
- transaction dates and necessary audit records.
3.5 Device, notification and technical data
For the operation and security of the application and the delivery of notifications, we may process the following technical data:
- Firebase Cloud Messaging notification token,
- operating system and application version,
- the device's general technical characteristics,
- application language,
- notification preferences,
- information on the creation, renewal or invalidation of the token,
- IP address for security and rate-limiting purposes,
- request time, response status and necessary security logs.
The notification identifier for the device (FCM token) is generated when the application starts and is saved in association with your account only when you sign in; it is deleted when you sign out, updated when the token is renewed and cleared when you delete your account. The delivery of notifications to your device also depends on your operating system notification permission.
The approximate region derived from the device country code may be used within the session to filter the "where to watch" results by country; it is not saved to your Talemark profile as precise location. We do not access your precise GPS location.
3.6 Analytics data
If you give explicit consent, the following types of data may be processed through Firebase Analytics in order to understand how the application is used and to improve the product:
- usage events such as signing up and signing in,
- creating a journal entry,
- writing a review,
- performing a search,
- saving a film or book,
- interaction with application screens,
- device and operating system information,
- approximate region,
- pseudonymous technical identifiers generated by Firebase and tied to the application installation.
We do not send your email address, username or Talemark account ID to Firebase Analytics and we do not use the setUserId feature. Nevertheless, Firebase may use pseudonymous application instance identifiers to distinguish a particular application installation. For this reason, analytics data is treated not as "directly anonymous" but as pseudonymous technical data that is not directly matched with your Talemark account ID.
You can withdraw your analytics consent at any time from the application settings. Withdrawing your consent does not affect the processing lawfully carried out before the withdrawal.
3.7 Crash and diagnostic data
Only in release versions, we may use Sentry in order to detect application errors and improve stability. In this context, the following may be processed:
- stack trace and error message,
- application version,
- operating system and device model,
- error time,
- the technical process flow in which the error occurred.
We do not intentionally add email, username or Talemark user ID to Sentry records. Nevertheless, we apply data filtering and masking measures against the possibility that an error message or technical context may unexpectedly contain personal data.
3.8 Contract and compliance records
We may retain records of which version of the Terms of Use, Community Guidelines or other applicable documents you accepted and when. These records generally consist of:
- user account ID,
- document name,
- document version,
- date and time of acceptance.
The presentation of the Privacy Policy to you is not an explicit consent operation. For analytics or similar optional processing that requires explicit consent, a separate choice is obtained.
4. How do we collect data?
We collect your personal data through the following methods:
- directly from you during registration, profile editing and content creation,
- from the Google identity service if you sign in with Google,
- automatically while you use the application and community features,
- through your device and Firebase Cloud Messaging if you grant notification permission,
- through Firebase Analytics if you grant analytics permission,
- through Sentry in the event of an application error,
- from the support and moderation channels if you contact us or submit a report.
5. Purposes of processing and legal grounds
To the extent applicable, we process personal data under Personal Data Protection Law No. 6698 ("KVKK") and the General Data Protection Regulation ("GDPR"), relying on the following purposes and legal grounds:
| Purpose of processing | Data examples | Processing condition under KVKK | Legal basis under GDPR |
|---|---|---|---|
| Creation and management of the account | Email, username, sign-in information | Necessity for the establishment or performance of a contract | Establishment and performance of a contract |
| Provision of journal, review, list and other core features | User content, favorites, follows | Necessity for the performance of a contract | Performance of a contract |
| Display of the public profile and community content | Username, avatar, bio, reviews, lists | Necessity for the performance of a contract | Performance of a contract |
| Sending verification and password reset emails | Email and transaction content | Necessity for the performance of a contract | Performance of a contract |
| Optional analytics | Usage events, pseudonymous technical identifier | Explicit consent | Explicit consent |
| Optional community and interaction notifications | Notification token, notification preference | Explicit consent and device permission | Explicit consent |
| Account security, rate limiting and prevention of abuse | IP address, security logs | The legitimate interest of the data controller | Legitimate interest |
| Resolving error and stability issues | Sentry diagnostic data | The legitimate interest of the data controller | Legitimate interest |
| Reviewing reports and enforcing the community guidelines | Report and moderation records | Performance of a contract, legitimate interest and the establishment, exercise or protection of a right | Performance of a contract, legitimate interest and protection of legal claims |
| Keeping records of contract acceptance | Document version and time of acceptance | Legal obligation and the establishment, exercise or protection of a right | Legal obligation and legitimate interest |
| Responding to requests of competent authorities | Records within the scope of the request | Legal obligation | Legal obligation |
| Responding to data subject requests | Request and identity verification information | Legal obligation | Legal obligation |
If a processing activity that is not necessary for the provision of core services relies on your explicit consent, not giving consent or later withdrawing it does not prevent you from using the core functions of your account.
We do not sell your personal data. We do not allow your data to be used by third parties for their own advertising purposes and we do not engage in cross-context behavioral advertising.
6. Public content and your responsibility
Talemark is a social culture journal platform. The username, profile information, reviews, lists, comments, quotes, favorites and follow relationships that you share publicly may be viewed by other users.
You are responsible for ensuring that the content you share does not contain personal data, information belonging to third parties, copyright-protected content or confidential information. Before sharing personal data belonging to another person, you must have the necessary legal authority or permission.
If you delete a public piece of content, the content is removed from Talemark's active systems. However, the content may have previously been viewed, screenshotted, quoted, shared by other users or temporarily held in third-party caches. Talemark cannot in every case delete independent copies outside its own control.
7. Parties with whom we share data
We may share personal data only to the extent necessary to provide the service, with the following groups of recipients:
| Service or recipient | Function | Data that may be processed |
|---|---|---|
| Supabase | Database, authentication, file storage and server functions | Account, profile, user content, images, notification tokens and technical records |
| Google Firebase Analytics | Consent-based usage analytics | Usage events, application instance identifier and technical device data |
| Google Firebase Cloud Messaging | Notification delivery | Notification token, application- and device-related technical data |
| Sentry | Error and crash diagnostics | Stack trace, error context, device and operating system information |
| Resend | Transactional email delivery | Recipient email address, subject and email content |
| Google Sign-In / OAuth | Optional identity provider | Name, email and profile picture shared by Google |
| TMDB | Film search and content data | Search term and necessary technical query parameters transmitted through the proxy |
| Google Books | Book search and content data | Search term and necessary technical query parameters transmitted through the proxy |
| Competent public institutions and judicial authorities | Fulfillment of legal obligations | Data limited to the scope of the legal request |
Providers such as Supabase, Sentry and Resend may act as data processors on behalf of Talemark according to the service they provide. Google Sign-In or certain Google services may also act as an independent data controller under their own terms when providing their own services.
TMDB and Google Books queries are sent through Talemark's server-side proxy services. Talemark does not transmit the end-user IP address or the Talemark account ID directly to these providers. Nevertheless, the search term you type is sent to these providers so that the relevant results can be retrieved.
We may also share personal data where necessary and proportionate:
- where required by an applicable law, court decision or binding request of a competent authority,
- to protect the rights and safety of users, Talemark or third parties,
- to establish, exercise or defend legal rights in a dispute.
8. International data transfers
Talemark's main database is hosted in Supabase's Frankfurt, Germany (eu-central-1) region.
Google, Sentry, Resend and certain other service providers may process data in countries outside Turkey, the European Economic Area or the country in which you reside. During international transfers, we comply with the requirements set out by applicable data protection legislation.
For personal data transfers from Turkey abroad, the adequacy decisions, appropriate safeguards, standard contracts or other applicable transfer mechanisms regulated under Article 9 of the KVKK may be used; for transfers within the European Economic Area, adequacy decisions, European Commission standard contractual clauses or other applicable safeguards may be used.
To obtain information about the country to which data is transferred, the recipient, the categories of data and the safeguard used, you can contact privacy@talemark.app.
9. Retention periods
We do not keep personal data longer than necessary for the purpose of processing. Our main retention criteria are set out below:
| Data category | Retention period or criterion |
|---|---|
| Account and profile data | For as long as your account is open; deleted from active systems once the account deletion is completed |
| User content | Until you delete the content or close your account |
| Private journal, progress and agenda data | Until you delete it or close your account |
| Notification tokens | Until you disable notifications, the token becomes invalid, it is removed on sign-out or you delete your account |
| IP and rate-limiting records | Only for the period necessary for the relevant rate-limiting window and security control; ordinarily not exceeding 24 hours |
| Analytics events | For as long as consent continues, and with a maximum 2-month user/event retention setting on Firebase Analytics |
| Sentry error and diagnostic records | For the period necessary to investigate the error; ordinarily no more than 30 days |
| Resend email delivery data | Within the provider's standard retention period, ordinarily 30 days |
| Report and moderation records | As a rule up to 3 years after the transaction is completed, for appeal, security and dispute needs; in the event of a legal dispute, until the relevant process ends |
| Contract acceptance and compliance records | Throughout the account relationship and thereafter for the applicable legal obligation and limitation periods |
| Data subject requests | For the period necessary to conclude the request and to prove the fulfillment of legal obligations |
| Security backups | Throughout the configured backup cycle; inaccessible in the ordinary course and for a maximum of 30 days |
These periods may be extended only to the necessary scope and duration where the relevant data is the subject of a legal dispute, an official request, a security incident or a statutory retention obligation.
When the retention period expires, the data is deleted, destroyed or irreversibly anonymized.
10. Deletion of the account and data
You can delete your account directly from within the application at any time:
Settings → Profile → Account → Delete Account
When you confirm the account deletion:
- your profile record,
- your authentication account,
- your journal entries,
- your reviews,
- your lists and list items,
- your comments and replies,
- your quotes,
- your favorites,
- your follow relationships,
- your private reading progress and agenda records,
- the avatar, profile banner and list covers you uploaded to Talemark storage
are deleted from the active systems.
Account deletion cannot be undone. Records contained in security backups created before the deletion may remain only throughout the backup cycle and are deleted or overwritten at the end of that period. Data in backups is not used for the ordinary provision of the service, for reconstructing the profile or for marketing purposes.
The following limited records may be kept for a certain period after the account deletion:
- records that must be retained by law,
- compliance records showing that the data deletion has been carried out,
- records necessary for an ongoing dispute or security investigation,
- Firebase Analytics events that are not directly matched with your Talemark account ID,
- technical records held in the Sentry and Resend systems until their own limited retention periods expire.
We may not be able to delete independent copies, screenshots of your public content previously taken by other users, or caches outside Talemark's control.
If you cannot access your account, you can send your deletion request to privacy@talemark.app. We may request reasonable additional information to verify that the account belongs to you.
11. Your choices and consent management
Analytics
Firebase Analytics is enabled only if you give explicit consent. You can turn analytics off from the privacy or usage data setting in the application. Turning off analytics does not prevent you from using Talemark's core features.
Notifications
You can manage the notification permission from your device's operating system settings or from the Talemark notification preferences screen. When you turn off notifications, the sending of new notifications to your device is stopped. Mandatory notifications relating to security and account access may be sent through other channels such as email to the extent appropriate.
Public profile and content
You decide which optional information to display on your profile. You can delete or edit your public content from the relevant content screen.
Google account
You can remove the Google sign-in connection from your Google account settings. Removing the Google connection does not automatically delete your Talemark account. To delete your Talemark account, you must use the account deletion path in Section 10.
12. Your rights
Depending on the applicable legislation and the country you are in, you may have the following rights:
- to learn whether personal data about you is being processed,
- to access the personal data processed and request a copy of it,
- to request the correction of incomplete or inaccurate data,
- to request the deletion or destruction of the data where the legal conditions are met,
- to request the restriction of processing,
- to object to processing based on legitimate interest,
- to withdraw your consent in processing based on consent,
- to receive your data in a structured and portable format where appropriate,
- to request information about the groups of recipients to which your data is transferred,
- to object to a result arising against you solely as a result of automated processing,
- to claim compensation if you suffer damage due to unlawful processing,
- to lodge a complaint with the competent data protection authority.
You can send your request to privacy@talemark.app. In order to conclude the request securely, we may need to verify your identity and that the relevant account belongs to you. Your request is answered within the period foreseen in the applicable legislation; for KVKK requests in Turkey, as a rule within 30 days at the latest.
Where a request is manifestly unfounded, excessive or repetitive, or affects the rights and freedoms of others, the limitations permitted by the applicable legislation may apply.
Users in Turkey may lodge a complaint with the Personal Data Protection Board once the conditions are met following the process of applying to the data controller; users in the European Economic Area may lodge a complaint with the competent data protection authority in the place where they live or work.
13. Children's privacy and age limit
Talemark is designed for users aged 16 and over. We do not offer a parental consent verification system for persons below the age at which parental or legal guardian consent is required.
If you are under 16 or have not reached the independent consent age applicable to digital services in your country, you should not create an account on Talemark.
If we learn that we have unknowingly collected personal data belonging to a child below the age limit, we may review the account, restrict access and delete the data in accordance with our legal obligations.
If you are a parent or legal guardian and believe that a child below the age limit has a Talemark account, you can contact us at privacy@talemark.app.
14. Security
We apply technical and administrative measures proportionate to the risk in order to protect personal data against unauthorized access, loss, misuse, alteration or disclosure. These measures may, where appropriate, include the following:
- encrypted connections during transmission,
- user and administrator access controls,
- Supabase row-level security rules,
- the principle of least privilege,
- authentication and session security,
- transaction and moderation records,
- system updates and security patches,
- data minimization,
- masking in error and diagnostic data,
- security incident response processes.
No electronic system can provide absolute security. Nevertheless, we regularly review appropriate measures to reduce risks and protect data.
If a security breach affecting personal data occurs, we conduct the necessary investigation according to the nature of the incident and make the necessary notifications to the relevant persons and competent authorities in accordance with the applicable legislation.
15. Automated decision-making
Talemark does not carry out solely automated decision-making or profiling activities that produce legal effects concerning users or that similarly significantly affect them.
Where automated systems such as content ranking, recommendation or abuse signals are used, they are not used on their own to make a decision that has legal or similarly significant effects on a user. In situations requiring account restriction or a permanent sanction, human review is provided to the extent appropriate.
16. Third-party links
Talemark may contain links to TMDB, Google Books, film watch providers, book sellers, social media accounts or other external services. The data processing practices of the third-party services accessed through these links are subject to their own privacy policies.
Talemark is not responsible for the independent data processing activities of third parties. We recommend that you review the privacy disclosures of the relevant service before using an external service.
17. Changes to the policy
We may update this Privacy Policy when product features, service providers or legal requirements change.
For significant changes:
- we change the "Last updated" date and the document version,
- where appropriate, we inform you through an in-app notification or email,
- if there is a processing activity that requires new explicit consent, we request your consent separately.
We do not consider a change in the Privacy Policy to have been given explicit consent merely on the basis that you have continued to use the application.
Previous versions may be requested from privacy@talemark.app to the extent legally and technically possible.
18. Contact
For questions about this Privacy Policy, your personal data or your rights:
- Privacy and personal data requests: privacy@talemark.app
- General support: support@talemark.app
While reviewing your request, we may ask for reasonable information or verification to confirm that the account belongs to you and to protect the data of others.