←Home

    Privacy Policy

    Last updated: August 30, 2026

    1. Identity of the Data Controller

    "Graphia Studio" is the official name of the product; it is presented to users as "Graphia". Graphia is operated by Hasan Kırtaş as a natural person; currently, there is no legal entity. Hasan Kırtaş is responsible for the processing of your personal data as a data controller under KVKK (Turkey's Law on the Protection of Personal Data No. 6698). Contact information is located on our contact page at graphiastudio.com/contact. Location: Istanbul, Turkey.

    For users accessing Graphia from the European Economic Area, the United Kingdom, or Switzerland, the same person acts as the data controller under the GDPR where applicable.

    2. Data We Collect

    We collect the following categories of data, through the methods described:

    • Account information: When you sign in with Google or Microsoft, we receive your name, email address, and profile photo (if available) from that provider. Graphia never collects or stores passwords β€” sign-in is exclusively via Google/Microsoft OAuth.
    • Canvas content: The cards you create, the text you write, documents you upload (PDF, Word, PowerPoint, Markdown, plain text), images, and web links you add.
    • AI interactions: Your past conversations with the AI assistant, including your questions and the responses you receive.
    • Usage and device data: Technical data such as IP address, browser type, operating system, page views, click interactions, and session duration β€” see Section 5 (Analytics, Error Tracking, and Cookies).
    • Feedback content: Messages and any attached images you submit through the in-app feedback form.

    3. Purposes and Legal Grounds for Processing

    Your data is processed for the following specific purposes, on the legal grounds indicated:

    • Creating your account, authenticating you, and syncing/storing your canvas content β€” KVKK Art. 5/2-c (performance of a contract), GDPR Article 6(1)(b).
    • Transmitting your content to the relevant AI provider so the assistant can answer your questions and act on the canvas β€” KVKK Art. 5/2-c, GDPR Article 6(1)(b).
    • Analyzing usage data to keep the service secure (abuse/rate-limit detection), diagnose errors, and improve the product β€” KVKK Art. 5/2-f (legitimate interest), GDPR Article 6(1)(f).
    • Reviewing your early-access feedback and responding to you β€” KVKK Art. 5/2-c, GDPR Article 6(1)(b).
    • For users connecting from Turkey, transferring data abroad β€” your explicit consent (KVKK Art. 9); see Section 7.

    Your content is never shared or sold to third parties for advertising or marketing purposes.

    4. Artificial Intelligence Processing

    When you use AI features (chat, source analysis, creating or editing cards), your writing and the relevant canvas content are transmitted through our model-routing infrastructure, OpenRouter, to the provider of the currently selected model (one of OpenAI, Google, DeepSeek, or Alibaba/Qwen) β€” which provider is in use is visible in the model picker in the interface and can be changed by you. Unless otherwise stated, these providers process your data solely to generate a response to your request.

    When you add a web link, a server-side crawl runs to turn the page's content into readable text; this runs on our own infrastructure (a service hosted on Fly.io) and only retrieves the content of the publicly accessible page you added.

    To improve service quality, your interactions may be anonymized and analyzed during system development; this analysis is not linked back to your identity.

    5. Analytics, Error Tracking, and Cookies

    Mandatory technical cookies/local storage are used to manage your session. Beyond that, we use the following third-party analytics and monitoring tools to keep the service reliable and usable:

    • PostHog (product analytics): collects page views, click interactions, and β€” for signed-in users β€” session replay. Password fields and all form inputs are masked by default.
    • Sentry (error tracking): collects application errors, performance data, and session replay associated with errors, so we can diagnose and fix issues.
    • Vercel Analytics and Speed Insights: aggregated, non-identifying site performance and traffic statistics.

    None of these tools are used for advertising or marketing purposes, and your data is never shared with ad networks. You can block or clear cookies/local storage in your browser settings; doing so may cause parts of the service to not work correctly.

    6. Parties We Share Data With

    Your personal data is shared, only to the extent necessary to provide the service, with the following processors:

    • Supabase β€” database, authentication, and file storage infrastructure.
    • Vercel β€” website hosting and content delivery.
    • Fly.io β€” hosts the crawling service that turns web link content into readable text.
    • OpenRouter and the provider of whichever AI model you select (OpenAI, Google, DeepSeek, or Alibaba/Qwen) β€” see Section 4.
    • PostHog and Sentry β€” see Section 5.
    • Resend β€” sends feedback replies and other account-related transactional emails.
    • Google / Microsoft β€” for sign-in (OAuth) only; Graphia never requests or stores your password for these accounts.

    Each of these providers is subject to its own privacy policy and processes your data on our behalf, solely for the purposes described here.

    7. Cross-Border Data Transfer

    The providers listed in Section 6 may operate servers outside Turkey (notably in the US and EU). Because Graphia's core functionality (account storage, AI processing, syncing) cannot be technically delivered without this infrastructure, your explicit consent is requested from users connecting from Turkey the first time you sign in, through a separate, dedicated consent step (independent of accepting the general terms) that states this technical necessity. For users connecting from the European Economic Area or elsewhere, data transfers rely on the safeguards required under the GDPR (including, where applicable, standard contractual clauses offered by the relevant provider).

    8. Data Retention and Deletion

    Your data is retained for as long as your account remains active. To request deletion of your account and its contents, contact us via our contact page; your request will be fulfilled within 30 days at the latest, and your data will be permanently deleted from our systems. A limited set of data that we are legally required to retain (e.g. accounting records, if any) may be kept for the period required under applicable law.

    9. Your Rights

    Under KVKK Article 11, you have the right to: learn whether your personal data is being processed; request information about it if so; learn the purpose of processing and whether it's used consistently with that purpose; know the third parties to whom your data is transferred domestically or abroad; request correction of incomplete or inaccurate data; request deletion or destruction of your data; request that these actions be notified to third parties your data was transferred to; object to a result that is to your detriment arising solely from automated analysis of your data; and claim compensation for damages arising from unlawful processing.

    Our users in the European Economic Area also have the right, under the GDPR, to data portability, restriction of processing, to object, on grounds relating to your particular situation, to processing carried out under Article 6(1)(f) (legitimate interest, see Section 3), and β€” if you believe your request has not been properly addressed β€” to lodge a complaint with the data protection authority in your country. Our users in Turkey may file a complaint with the Turkish Personal Data Protection Authority ("KVKK Kurumu") if they believe their request has not been properly addressed.

    You can reach us via our contact page to exercise these rights; requests are answered within 30 days at the latest.

    10. Minors

    Graphia's general user base is adults. The service does not knowingly collect personal data from children under 13. For users connecting from the European Economic Area, the default age at which you can consent to an account on your own is 16 under GDPR Article 8; your EU/EEA country's own law may set this lower, down to a minimum of 13. Below that threshold, an account should only be opened with a parent's or guardian's consent and supervision. We generally recommend that all users between 13 and 18 use the service under parental or guardian supervision. If we become aware that a child has provided us with personal data without the required consent, we will delete it within a reasonable time.

    11. Data Security

    Reasonable technical and administrative measures are taken to secure your data (including encrypted transport, access controls, rate limiting, and abuse detection); however, no transmission over the internet or electronic storage can be guaranteed to be 100% secure.

    If we determine that your personal data has been obtained by third parties through unlawful means, we will notify the Turkish Personal Data Protection Authority and affected users as soon as possible, in accordance with KVKK Article 12(5). For our users in the European Economic Area, in the event of a breach likely to result in a high risk to your rights and freedoms, we will notify the competent authority and you without undue delay, in accordance with GDPR Articles 33 and 34.

    12. Changes to This Policy

    This policy may be updated from time to time to reflect changes to the service or applicable law. In case of significant changes, information will be provided through the service or via email. The "last updated" date at the top of this page reflects the most recent revision.

    13. Contact

    For privacy-related questions, requests, or complaints, you can use our contact page at graphiastudio.com/contact.