Legal Framework
This Privacy Policy is prepared in accordance with Turkey's Personal Data Protection Law No. 6698 (KVKK) and the EU General Data Protection Regulation 2016/679 (GDPR). The policy covers the management of personal data stored on the user's device and processed via optional cloud/AI features.
Data Controller
With respect to clients' personal data, the data controller within the meaning of KVKK and GDPR is the user (the therapist) who processes that data in the course of their professional practice. This data is stored on the user's device; even when the optional synchronization and artificial intelligence features are used, the data is transferred only through the user's own accounts (their own Google Drive space, their own API key). The developer has no access to this data and is neither a data controller nor a data processor with respect to it — only a tool provider. Any obligations the user owes their clients under applicable law rest with the user, regardless of which tool they use. With respect to the limited data concerning the application itself (support e-mails the user initiates and the Installation ID sent with them, and the random user identifier used for subscription verification), the data controller is the developer, Mustafa Can. For questions regarding these data processing activities, you can get in touch at info@psyagenda.app.
Data Ownership
All data created and stored within the application (client records, appointments, session notes, financial records, tests, images) is entirely the property of the user. The developer makes no claim over this data; it is not analyzed, sold, licensed, or shared with any third party.
Data Collected and Processed
The application stores the following data categories locally on your device only:
- Client information: Name (required); phone, email, date of birth, gender, marital status, education, profession, and therapist notes (all optional).
- Appointment and session data: Date, time, duration, session notes, pre/post-session notes.
- Test data: Rorschach, drawing test, and manual test records, images, and AI evaluations.
- Financial data: Session fees, income-expense records, payment tracking.
- Settings and preferences: Language, currency, calendar preferences, notification templates.
Data Storage
- Client, appointment, session note, test and financial records are stored in an encrypted local database on the device (SQLCipher/AES-256). Session and test images are kept outside the database, as separate files within the application's private data area; those are encrypted with AES-256 as well. All of this data lives only on the user's device.
- The encryption key is held in the device's own secure key store and is wrapped with your App Lock password; image files are encrypted with keys derived from that same key. The operating system's application sandbox and — where enabled — device encryption apply on top of this.
- The developer cannot access this data. Optional synchronization encrypts the data on the device and sends it only to the user's own Google Drive account; nothing reaches the developer. Support emails do reach the developer, but they carry technical records only — no client or session content. Data sharing by the optional AI features is described separately below.
Synchronization and Cloud Storage
- Synchronization is entirely optional and disabled by default.
- When enabled, data is encrypted with the user's chosen synchronization password using the AES-256-GCM standard before it leaves the device, and is uploaded only to the private app data folder (appDataFolder) in the user's own Google Drive account.
- Other devices signed in with the same Google account and the same synchronization password download this encrypted data and decrypt it only on the device itself; the decrypted data is written into that device's encrypted database. Synchronization between devices therefore happens without the data ever travelling unencrypted.
- The encryption key is never transmitted anywhere; it is derived solely on the user's device from the synchronization password. No party, including Google and the developer, can decrypt the data.
AI Usage and Data Sharing
- AI features are entirely optional. Users enter their own API key and decide which data to process.
- When AI is used, only the relevant session notes, test data, or images are sent to the Google Gemini API.
- Client identity details (full name, phone, e-mail, address) are not sent to the AI service by the application; those record fields are never included in any analysis. However, free-text fields such as session notes, test responses and the notes on the client card are included in the analysis as they are — it is the user's responsibility not to enter information that could reveal the client's identity into those fields.
- Google's data usage policies vary depending on the user's API plan (free/paid). Detailed information is available in the in-app API guide.
Bug Reports and Technical Records
- The application generates technical records to help diagnose problems — covering not only errors but also the trail of steps leading up to them — and stores them locally on your device only (a sliding window of approximately 1 MB; older entries are automatically discarded).
- These logs contain only: error messages and technical stack traces, action types within the app (e.g. "screen changed", "modal opened/closed", "notification toast displayed", "synchronization started/completed", "license state changed", "AI button clicked", "native system operation (file save/delete, notification scheduling) result"), the active screen name, device platform, app version, language, license type, network status, and a technical code indicating the local database encryption/migration state.
- These logs do not contain client identifying information, phone numbers, emails, addresses, session note content, appointment titles, financial records, photos, or any other client/session content — this is technically guaranteed by the application architecture: every log point that could carry user content is designed to record only short static identifiers rather than the content itself. Only the type of action is recorded — never its content.
- Technical records stay on your device. They are sent to info@psyagenda.app only when you use About > Support/Feedback > "I'm having a problem" and tap Send — together with the description you wrote. The email also includes the device-specific random Installation ID (so we can look up your subscription status for support) and browser/device info (User-Agent).
- Before sending, the email client opens so you can review, edit, or cancel the message. This feature is fully under your control; no automatic or background submissions occur.
Third-Party Services
- Google Gemini API: Optional AI analysis (with the user's own API key).
- Google Drive: Optional encrypted synchronization (the user's own account).
- Google Play / App Store: App distribution and license verification.
- RevenueCat: A device-specific random user identifier (App User ID) and the store purchase receipt are shared for the subscription purchase flow, receipt validation, and verification of subscription/license status at app launch. Gift licenses are also granted via this identifier. No personal data (name, email, session notes, confidential client information) is shared.
- The app also performs a periodic reachability check, carrying no user data, to detect whether an internet connection is available. Beyond these, and beyond support emails the user voluntarily initiates via About > Support/Feedback, no data is transferred to any third-party service.
No Advertising or Tracking
- PsyAgenda displays no advertisements. There is no integration with any ad network.
- It contains no analytics services (Google Analytics, Firebase Analytics, Mixpanel, etc.); no usage statistics are collected.
- Under Apple's App Tracking Transparency (ATT), no tracking is performed; advertising identifiers such as IDFA are not requested.
- No crash reporting / automatic error reporting service is used. Technical error records are transmitted only via support emails the user manually initiates.
Age Restriction and Children's Data
- PsyAgenda is designed for professional use by adult therapists (psychologists, psychiatrists, counselors). It does not present content or interaction directed at children and does not collect data directly from children.
- If the user (therapist) enters information about a minor client, this occurs under the parent/guardian's consent and within the user's own professional/ethical responsibility. The developer is not involved in this consent process.
Encryption and Export Compliance
- The application uses only standard, publicly available encryption algorithms: AES-256-GCM (synchronization, backup and image file encryption), SQLCipher/AES-256 (local database at-rest encryption), PBKDF2-HMAC-SHA-256 and HKDF-SHA-256 (key derivation), SHA-256 (integrity verification), and optional traditional ZIP password protection (ZipCrypto) for exports.
- These algorithms fall under the 'standard exempt' category under U.S. export regulations; the export compliance declaration provided to app stores reflects this. The application does not implement any proprietary cryptographic algorithm.
Data Retention
- Data is stored locally on the device until the user deletes it themselves. There is no automatic deletion.
- The user can permanently delete all device data via Settings > Storage > Danger Zone > 'Delete All Local Data' and cloud data via Settings > Sync > Danger Zone > 'Delete All Drive Data'.
- Technical error records (DIAG_ERRORS and DIAG_BREADCRUMBS) are kept in a sliding window of approximately 1 MB; older entries are automatically discarded.
Device Permissions
The app may request the following device permissions in order to provide certain features. All permissions other than internet access are optional and are requested only when the related feature is used; the internet permission is granted by the operating system at installation and is never requested separately:
- Internet (INTERNET): Used to connect to Google Drive sync and Gemini AI features. The internet is also used for a periodic connectivity check that carries no user data, and for verifying license status (RevenueCat) at app launch.
- Camera (CAMERA): Used to attach photos to session notes or test records.
- Notifications (POST_NOTIFICATIONS): Used to send appointment reminder notifications.
- Exact Alarms (SCHEDULE_EXACT_ALARM): Used to trigger appointment reminders at the exact scheduled time.
- Contacts (READ_CONTACTS): Used for the add-from-contacts feature. The contact list is shown by the operating system's own picker; the app reads only the name, phone number, and email of the contact you select. No other contacts in your address book are read, and no contact data is transmitted outside the device.
- External Storage (WRITE_EXTERNAL_STORAGE — only on Android 9 and below): Used to save report downloads (PDF/DOCX) to the device's "Downloads" folder. This permission is not needed on Android 10 and later.
- Biometric Authentication (Face ID / Touch ID / fingerprint): Used for optional quick unlock; biometric data stays within the operating system — the app never accesses, stores, or transmits it.
- Photo Library: Only the photos you select are read, to attach images to session/test records; write access is used to save camera photos to your library.
- Denying a permission disables the related feature; the rest of the application remains unaffected.
User Rights (KVKK Art. 11 / GDPR Art. 15-22)
All data is under the user's control. Users may exercise the following rights at any time:
- Backup and portability (GDPR Art. 20): Export data as an encrypted .thnbak backup.
- Right to erasure (KVKK Art. 7 / GDPR Art. 17): Permanently delete all data on the device via Settings > Storage > Danger Zone > 'Delete All Local Data'.
- Deleting the cloud copy: Can permanently delete the cloud copy via Settings > Synchronization > Danger Zone > 'Delete All Data on Drive'. Merely disconnecting synchronization does not delete the data in the cloud.
- Right to object (GDPR Art. 21): Stop using AI and synchronization features; both are optional and disabled by default.
- Right of access (KVKK Art. 11 / GDPR Art. 15): All stored data can be viewed directly in the app interface and copied out through the export options (client card, reports, Excel, encrypted backup). Since the developer holds no copy of the data, exercising this right requires no request to anyone.
- Right to rectification (KVKK Art. 11 / GDPR Art. 16): Edit all client, appointment, financial, and other records directly in the app.
- Right to object and lodge a complaint: The items above describe the user's control over their own data. For the limited data for which the developer is the controller (support emails, Installation ID, subscription verification identifier), any request or complaint may first be sent to info@psyagenda.app; if no reply is received or the request is not met, the user retains the right to lodge a complaint with the competent data protection authority in their country.
Contact
For questions regarding the privacy policy, you can contact info@psyagenda.app.