Privacy Policy
Last updated: 27 July 2026
What data we collect and why, how long we keep it, and why your exact location is never shown on the map.
In short
- Your real location is never shown on the map; it is rounded to roughly a 3 km area.
- Location updates only when you open the app. There is no background tracking.
- Your answers are used for matching; you can hide any of them from your profile.
- We do not sell your data for advertising or share it with third parties for marketing.
- You can delete your account from inside the app; personal data is permanently erased after 30 days.
1. Who is responsible
The operator of the Ruh Eşi app is the data controller. For any question or request about this policy, write to destek@ruhesi.net.
2. What we collect
Account information
- Email address (for signing in)
- If you signed in with Apple or Google: the provider's stable user identifier and your email address if you shared it
- First and last name, date of birth, optional display name
Profile and matching data
- Your answers to questions and how important each one is to you
- The interests you select
- Photos you upload and, if requested, a verification selfie
- The short text you write about yourself
Messages and the interests you suggest
- The text of the messages you exchange with other users, and when they were sent
- The text you send when you suggest an interest that is missing from the list
We do not read your messages and we do not use their content for advertising or profiling. When a message is reported, though, our moderation team sees the text of that message so the report can be reviewed; the detail is under "What other users see" below.
Location
Each time you open the app we read the location your device reports. Before storing it we round it to three decimal places (about 110 metres); we never keep a more precise record. The point shown on the map is coarser still: your location is snapped to a cell of roughly 3 kilometres and placed inside that cell with a fixed offset unique to you.
The offset being fixed is deliberate. If it were random on every request, someone querying you repeatedly could average the readings and recover your real position. With a fixed offset, querying again reveals nothing new.
Technical data
- Device type and operating system, app version
- IP address — not stored raw, kept as a salted hash
- Device notification token, so we can send you notifications
3. Sensitive data
Some questions may touch on belief, political opinion, health or similar sensitive topics. Answering them is entirely optional and we ask for separate explicit consent. If you do not consent, those questions are never shown to you and are not used in matching. You can withdraw consent at any time; the related answers are deleted when you do.
4. Why we process your data
| Purpose | Legal basis |
|---|---|
| Creating your account and signing you in | Performance of a contract |
| Calculating compatibility and showing matches | Performance of a contract |
| Showing people near you | Consent (location permission) |
| Processing questions on sensitive topics | Separate explicit consent |
| Preventing abuse and reviewing reports | Legitimate interest and legal obligation |
| Managing subscriptions and purchases | Performance of a contract |
| Sending product announcements | Consent — off by default |
5. What other users see
- By default only your initials are visible ("A. Y."). If you set a display name, that is shown instead.
- Your full name appears only when someone reveals you, or when you become connected.
- Your age is shown; your date of birth is not.
- Distance is shown as a range such as "~3 km"; a precise distance is never shared.
- Answers you mark as hidden are shown to nobody; they are used only in the compatibility calculation.
- Photos that have not been approved are visible to nobody.
- Your messages are shown to nobody but the person you are writing to. Reports are the one exception: when a message is reported, the moderation team reviewing that report sees the text of the message.
6. Who we share with
We do not sell your data for advertising. We share it only with the service providers needed to run the service, and only as much as needed:
- Hosting and database provider
- Email provider (sign-in codes and essential notices only)
- Notification provider (device token and notification text only)
- Subscription verification provider and the stores (Apple, Google)
- Competent authorities where we are legally required
7. Transfers outside your country
The app is available worldwide. Some of the providers we rely on to run the service may sit outside your country or outside the European Economic Area, which means your data is transferred to another country.
The plan is to keep the servers and the database inside the European Union. The provider and the country of the data centre are not settled yet; rather than name an unverified country or provider, we leave this open. Once it is settled it goes both here and on the Legal notice page.
Where a transfer does happen, we work through this order:
- If there is an adequacy decision for the destination country — for EU users, a decision of the European Commission — the transfer relies on that.
- Where there is no adequacy decision, we rely on appropriate safeguards: usually the European Commission's Standard Contractual Clauses (SCCs), with additional technical and organisational measures where they are needed.
- Transfers from Türkiye additionally follow the order set out in article 9 of Law No. 6698; the detail is in the Data Protection Notice.
You can ask which mechanism a given transfer relies on, and request a copy of the safeguards in place, by writing to destek@ruhesi.net. We may redact commercially confidential or security-sensitive parts of those contracts.
8. How long we keep it
- Account and profile data: for as long as your account is open
- After a deletion request: 30 days (you can change your mind), then personal data is permanently erased
- Sign-in codes: 10 minutes
- Reports and moderation records: kept for a limited period even after an account closes, so repeat abuse can be detected
- Billing and purchase records: for the legally required retention period
9. Your rights
You have the right to access, correct, delete, restrict processing of and port your data, and to object to processing. Most of these you can exercise directly in the app; for the rest, write to destek@ruhesi.net. We respond within 30 days at the latest.
Complaining to a supervisory authority
If you are not satisfied with our answer, or we do not answer at all, you have the right to lodge a complaint with a supervisory authority:
- If you live in the European Union or the European Economic Area: with the data protection authority in your country. That is usually the authority where you habitually live, where you work, or where you believe the infringement took place.
- If you are in Türkiye: with the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu). Law No. 6698 requires you to come to us, the controller, first; a complaint to the Board follows only if we reject your request, you find our answer inadequate, or we fail to answer in time.
That right always stands. We would still rather sort the problem out with you first — write to destek@ruhesi.net.
10. Children
Ruh Eşi is not for anyone under 13. Where your country sets a higher age, that higher age applies. If we find an account belonging to someone under 13 we close it and delete the data.
11. Security
- Passwords are hashed with Argon2id and never stored in plain text
- Session refresh tokens are stored as hashes, not in plain form
- If a used session token is presented again, all sessions are revoked
- IP addresses are stored as salted hashes
- Precise location data is never stored at full precision
12. Changes
If we update this policy we will tell you in the app. Where a change is meaningful we will ask for your consent again.