Last updated: August 30, 2026
"Graphia Studio" is the official name of the product; it is presented to users as "Graphia". Graphia is operated by Hasan KΔ±rtaΕ as a natural person; currently, there is no legal entity. Hasan KΔ±rtaΕ is responsible for the processing of your personal data as a data controller under KVKK (Turkey's Law on the Protection of Personal Data No. 6698). Contact information is located on our contact page at graphiastudio.com/contact. Location: Istanbul, Turkey.
For users accessing Graphia from the European Economic Area, the United Kingdom, or Switzerland, the same person acts as the data controller under the GDPR where applicable.
We collect the following categories of data, through the methods described:
Your data is processed for the following specific purposes, on the legal grounds indicated:
Your content is never shared or sold to third parties for advertising or marketing purposes.
When you use AI features (chat, source analysis, creating or editing cards), your writing and the relevant canvas content are transmitted through our model-routing infrastructure, OpenRouter, to the provider of the currently selected model (one of OpenAI, Google, DeepSeek, or Alibaba/Qwen) β which provider is in use is visible in the model picker in the interface and can be changed by you. Unless otherwise stated, these providers process your data solely to generate a response to your request.
When you add a web link, a server-side crawl runs to turn the page's content into readable text; this runs on our own infrastructure (a service hosted on Fly.io) and only retrieves the content of the publicly accessible page you added.
To improve service quality, your interactions may be anonymized and analyzed during system development; this analysis is not linked back to your identity.
Mandatory technical cookies/local storage are used to manage your session. Beyond that, we use the following third-party analytics and monitoring tools to keep the service reliable and usable:
None of these tools are used for advertising or marketing purposes, and your data is never shared with ad networks. You can block or clear cookies/local storage in your browser settings; doing so may cause parts of the service to not work correctly.
Your personal data is shared, only to the extent necessary to provide the service, with the following processors:
Each of these providers is subject to its own privacy policy and processes your data on our behalf, solely for the purposes described here.
The providers listed in Section 6 may operate servers outside Turkey (notably in the US and EU). Because Graphia's core functionality (account storage, AI processing, syncing) cannot be technically delivered without this infrastructure, your explicit consent is requested from users connecting from Turkey the first time you sign in, through a separate, dedicated consent step (independent of accepting the general terms) that states this technical necessity. For users connecting from the European Economic Area or elsewhere, data transfers rely on the safeguards required under the GDPR (including, where applicable, standard contractual clauses offered by the relevant provider).
Your data is retained for as long as your account remains active. To request deletion of your account and its contents, contact us via our contact page; your request will be fulfilled within 30 days at the latest, and your data will be permanently deleted from our systems. A limited set of data that we are legally required to retain (e.g. accounting records, if any) may be kept for the period required under applicable law.
Under KVKK Article 11, you have the right to: learn whether your personal data is being processed; request information about it if so; learn the purpose of processing and whether it's used consistently with that purpose; know the third parties to whom your data is transferred domestically or abroad; request correction of incomplete or inaccurate data; request deletion or destruction of your data; request that these actions be notified to third parties your data was transferred to; object to a result that is to your detriment arising solely from automated analysis of your data; and claim compensation for damages arising from unlawful processing.
Our users in the European Economic Area also have the right, under the GDPR, to data portability, restriction of processing, to object, on grounds relating to your particular situation, to processing carried out under Article 6(1)(f) (legitimate interest, see Section 3), and β if you believe your request has not been properly addressed β to lodge a complaint with the data protection authority in your country. Our users in Turkey may file a complaint with the Turkish Personal Data Protection Authority ("KVKK Kurumu") if they believe their request has not been properly addressed.
You can reach us via our contact page to exercise these rights; requests are answered within 30 days at the latest.
Graphia's general user base is adults. The service does not knowingly collect personal data from children under 13. For users connecting from the European Economic Area, the default age at which you can consent to an account on your own is 16 under GDPR Article 8; your EU/EEA country's own law may set this lower, down to a minimum of 13. Below that threshold, an account should only be opened with a parent's or guardian's consent and supervision. We generally recommend that all users between 13 and 18 use the service under parental or guardian supervision. If we become aware that a child has provided us with personal data without the required consent, we will delete it within a reasonable time.
Reasonable technical and administrative measures are taken to secure your data (including encrypted transport, access controls, rate limiting, and abuse detection); however, no transmission over the internet or electronic storage can be guaranteed to be 100% secure.
If we determine that your personal data has been obtained by third parties through unlawful means, we will notify the Turkish Personal Data Protection Authority and affected users as soon as possible, in accordance with KVKK Article 12(5). For our users in the European Economic Area, in the event of a breach likely to result in a high risk to your rights and freedoms, we will notify the competent authority and you without undue delay, in accordance with GDPR Articles 33 and 34.
This policy may be updated from time to time to reflect changes to the service or applicable law. In case of significant changes, information will be provided through the service or via email. The "last updated" date at the top of this page reflects the most recent revision.
For privacy-related questions, requests, or complaints, you can use our contact page at graphiastudio.com/contact.