MİAT Global Privacy Policy
This Privacy Policy explains how MİAT ("Application", "Service", "We", "Us") collects, processes, and protects your personal data when you use the website (miat.app) and our iOS/Android mobile applications.
1. Categories of Data Processed
- Account Information: User ID (Firebase UID), email address, and authentication provider identifiers (Apple Sign-In, Google Sign-In).
- User Generated Content: User-entered reminder titles, expiration dates, custom notes, category tags, and country selection.
- Device and Technical Telemetry: Push notification tokens (Apple APNs / Google FCM), operating system version, device model, language setting, and crash diagnosis logs.
- Subscription Verification Data: Anonymous receipt validation tokens via RevenueCat. (MİAT stores NO payment card numbers, CVVs, or bank credentials.)
2. Strict Zero-Credential Architecture
MİAT strictly enforces a zero-credential policy: we never request, access, or store government login credentials (e.g., e-Devlet, Metrash2, Gov.uk, FranceConnect passwords), biometric data, or government identity scans.
3. Legal Bases and Processing Purposes
Under GDPR Article 6 and equivalent international frameworks, personal data is processed on the following grounds:
- Performance of a Contract: To manage user accounts, deliver reminder alerts, and maintain encrypted cloud sync.
- Legitimate Interests: To detect crashes, safeguard network security, and prevent abusive bot behavior.
- Compliance with Legal Obligations: To adhere to accounting, consumer protection, and statutory data subject requirements.
4. Third-Party Infrastructure & Data Transfers
Data processing is conducted using enterprise-grade providers adhering to SOC 2, ISO 27001, and standard contractual clauses:
- Database & Authentication: Google Cloud / Firebase (Firestore).
- Subscription Management: RevenueCat Inc.
- CDN & Security: Cloudflare Inc.
- Storefront & Delivery: Apple Inc. and Google LLC.
5. Regional Privacy Rights (Country Addenda)
🇪🇺 European Union (GDPR) & 🇬🇧 United Kingdom (UK GDPR)
You enjoy statutory rights including: Right of Access (Art. 15), Right to Rectification (Art. 16), Right to Erasure / To Be Forgotten (Art. 17), Right to Restriction (Art. 18), and Right to Data Portability (Art. 20). Contact us at kvkk@miat.app to exercise your rights.
🇶🇦 State of Qatar & GCC (Law No. 13 of 2016 - PDPPL)
In compliance with Qatar Personal Data Privacy Protection Law, data processing is strictly limited to consented notification purposes. Data subjects have the right to withdraw consent and request immediate deletion.
🇺🇸 California (CCPA / CPRA)
We do not "sell" or "share" personal information as defined by the CCPA. California residents have the right to know what personal data is collected and request deletion without discrimination.
6. Data Retention & Deletion
Your data is stored only while your account remains active. When you delete your account via Profile > Account & Security > Delete Account, all your records, notes, and profile data are immediately and permanently purged from our production databases.
7. Contact Us
For data protection inquiries, email kvkk@miat.app.