Gizlilik Politikası
Psephos iOS uygulaması ve sunucusu · Yürürlük: 2 Ekim 2026
Psephos, yapay zekâ ajanlarının senden onay istemesini sağlar: ajanın bir istek gönderir, telefonuna Onayla/Reddet butonlu bir bildirim düşer, cevabın ajana döner. Bu sayfa bunun için hangi verilerin işlendiğini anlatır. Kısaca: hesap yok, ad, e-posta ya da telefon numarası istenmez; reklam, analiz ve takip yok; veri satılmaz.
Sorumlu
Psephos'u bireysel geliştirici Hamit Çevik geliştirir ve işletir. İletişim: destek@psephos.dev.
İşlenen veriler
| Veri | Neden |
|---|---|
| Rastgele bir kullanıcı kimliği, uygulamaya özel bir cihaz anahtarı ve senin API anahtarın | Uygulama ilk açılışta bunları kendisi oluşturur; seni ve cihazını başka kullanıcılardan ayırmak için. Cihaz anahtarı ve API anahtarı sunucuda yalnızca tek yönlü özet (SHA-256) olarak tutulur; açık hâlleri telefonundaki iOS Anahtar Zinciri'ndedir. |
| Cihazının bildirim adresi (Expo push token) | Bildirimleri telefonuna ulaştırmak için. Bildirim izni vermezsen alınmaz. |
| Ajanlarının gönderdiği bildirim ve onay isteklerinin başlığı ve metni, proje adları | Bildirimi göstermek ve uygulamadaki geçmişte listelemek için. Bu içeriği sen ve ajanların yazarsınız; şifre gibi hassas bilgileri bildirimlere koymamanı öneririz. |
| Cevabın (onay/red), okundu bilgisi ve zaman damgaları | Cevabını ajana iletmek ve uygulamada durumu göstermek için. |
| IP adresi | Yalnızca yeni kimlik oluşturmadaki kötüye kullanımı sınırlamak için, sunucunun belleğinde en fazla 2 saat sayaç olarak; diske yazılmaz. Web sunucusu erişim günlüğü tutmaz. |
Konum, rehber, fotoğraf, reklam kimliği ya da cihazındaki başka hiçbir veri okunmaz.
Verinin tutulduğu ve geçtiği yerler
- Sunucu: Contabo GmbH'nin Fransa'daki veri merkezinde bir sanal sunucu.
- Veritabanı: Supabase, Avrupa Birliği (Frankfurt, eu-central-1).
- Bildirim iletimi: Bildirimin başlığı ve metni, telefonuna ulaşmak için Expo'nun bildirim servisinden ve Apple'ın bildirim servisinden (APNs) geçer.
Bu hizmet sağlayıcılar verini yalnızca Psephos adına barındırmak ve iletmek için işler. Başka hiç kimseyle paylaşılmaz.
Saklama ve silme
Verin, sen silene kadar tutulur. Cevaplanmayan test onayları 10 dakikada geçersiz olur ama geçmişte kalır.
Her şeyi silmek için: Uygulamada Ayarlar → Kimliği sil. Kimliğin, cihaz kaydın, projelerin, bütün bildirim ve onay geçmişin ve API anahtarın sunucudaki veritabanından hemen ve kalıcı olarak silinir; o anahtarı kullanan ajanlar artık sana ulaşamaz.
Dikkat: Uygulamayı telefondan silmek sunucudaki verini silmez (iOS, Anahtar Zinciri'ndeki kimliği bile koruyabilir). Önce Kimliği sil'i kullan.
Sunucunun teknik günlükleri (hatalar, kayıt numaraları) bildirim içeriği taşımaz ve en fazla 30 gün tutulur.
Güvenlik
Bütün bağlantılar HTTPS ile şifrelenir. Cihaz anahtarı ve API anahtarı sunucuda açık hâliyle tutulmaz. Her kullanıcı yalnızca kendi verisine erişebilir; bir ajan kendi isteğini cevaplayamaz ve geçmişini okuyamaz.
Çocuklar
Psephos yazılım geliştiriciler ve yapay zekâ ajanı kullananlar içindir; 13 yaşından küçükler için tasarlanmamıştır.
Hakların
Verine uygulamadan ulaşabilir ve onu istediğin an silebilirsin. Sorular ve KVKK ya da GDPR kapsamındaki talepler için destek@psephos.dev adresine yaz. Hesap olmadığı için seni tanıyabilmemiz adına mesajına Ayarlar'daki Kimlik no'yu ekle.
Değişiklikler
Bu politika değişirse güncel hâli bu sayfada, yeni yürürlük tarihiyle yayınlanır.
Privacy Policy
Psephos iOS app and server · Effective: 2 October 2026
Psephos lets AI agents ask for your approval: your agent sends a request, your phone gets a notification with Approve/Reject buttons, and your answer goes back to the agent. In short: no account, no name, email or phone number; no ads, analytics or tracking; your data is never sold.
Who is responsible
Psephos is built and run by independent developer Hamit Çevik. Contact: destek@psephos.dev.
Data we process
- A random user ID, an app-specific device key and your API key, created by the app on first launch to tell you and your device apart from other users. The device key and API key are stored on the server only as one-way hashes (SHA-256); the plain values live in the iOS Keychain on your phone.
- Your device's push address (Expo push token), to deliver notifications. Not collected if you don't allow notifications.
- Titles and texts of the notifications and approval requests your agents send, and project names, to show them and list them in the app's history. You and your agents write this content; please don't put secrets such as passwords in notifications.
- Your answers (approve/reject), read status and timestamps, to return your answer to the agent and show the status in the app.
- IP address, only to rate-limit the creation of new identities: kept in the server's memory as a counter for at most 2 hours, never written to disk. The web server keeps no access logs.
No location, contacts, photos, advertising identifier or any other data on your device is read.
Where it is stored and passes through
- Server: a virtual server at Contabo GmbH's data centre in France.
- Database: Supabase, European Union (Frankfurt, eu-central-1).
- Notification delivery: a notification's title and text pass through Expo's push service and Apple's Push Notification service (APNs) on the way to your phone.
These providers process your data only to host and deliver it for Psephos. It is not shared with anyone else.
Retention and deletion
Your data is kept until you delete it. Unanswered test approvals expire after 10 minutes but stay in your history.
To delete everything: in the app, Ayarlar (Settings) → Kimliği sil (Delete identity). Your identity, device record, projects, full notification and approval history and API key are removed from the server's database immediately and permanently; agents using that key can no longer reach you.
Note: deleting the app from your phone does not delete your data on the server (iOS may even keep the identity in the Keychain). Use Kimliği sil first.
The server's technical logs (errors, record numbers) contain no notification content and are kept for at most 30 days.
Security
All connections are encrypted with HTTPS. Device keys and API keys are never stored in plain form on the server. Each user can reach only their own data; an agent cannot answer its own requests or read your history.
Children
Psephos is meant for software developers and people who use AI agents; it is not designed for children under 13.
Your rights
You can see your data in the app and delete it at any time. For questions or requests under the GDPR or Turkey's KVKK, write to destek@psephos.dev. As there is no account, include the Kimlik no (identity number) from Settings so we can find your data.
Changes
If this policy changes, the current version is published on this page with a new effective date.