Flok
Privacy Policy
Last updated: October 5, 2026
This English version is provided for convenience. If it conflicts with the Turkish version, the Turkish version prevails.
This Privacy Policy covers the personal data processed through the Flok mobile app and the website at flok.ist (together, the “Service”). It serves as the privacy notice required by Article 10 of Turkey's Personal Data Protection Law No. 6698 (“KVKK”) and also applies to users covered by the European Union General Data Protection Regulation (“GDPR”). The rules for using the Service are set out in the Terms of Use.
1. Data controller
Your personal data is processed by Serhat Taşdemir (“Flok”, “we”) as the data controller. For any request about this Policy or your personal data, you can reach us at destek@flok.ist.
2. Personal data we process
2.1. Account and identity information
- The email address, user ID and session information for the account you create with Apple, Google or email.
- The password you set when signing up with email; your password is only stored in an irreversibly encrypted (hashed) form.
- The name and email address that Apple or Google share with us when you sign in with them. If you choose to hide your email address when signing in with Apple, we receive the relay address Apple creates.
2.2. Profile information
- Display name, bio, profile photo and interests.
- Date of birth.
- Karma score, user title and profile privacy preference.
2.3. Event and participation information
- For events you organize: title, description, rules, schedule, date and time, address and map coordinates, cover image, capacity and age limit.
- Your applications to events, waitlist and approval status.
- The QR ticket issued to you, your check-in time at the door, and your attendance and no-show records.
2.4. Communications and shared content
- Messages, replies and announcements you send in event chats.
- Suggestions and event reports you send to organizers, and organizers' replies to them.
- Event photos and captions you share, photo tags and likes.
2.5. Social interaction and safety information
- Users you follow, users who follow you, and follow requests.
- Users you have blocked.
- Reports you make about other users (reason and description) and reports made about you.
2.6. Location information
- If you grant location permission on your device, your location is used to show nearby events on the Discover and map screens.
- If you turn on nearby event notifications, your most recently shared location and the time it was captured are stored on our servers; we do not keep a location history.
2.7. Usage information
- Events you see in the feed and open (on a daily basis).
- Your read status in chats and your in-app notification records.
2.8. Device information
- Your device's notification token, platform and app version, so we can send push notifications.
- Preferences such as language and appearance, and data such as the ticket cache, are stored only on your device.
2.9. Purchase information
If paid features are offered in the Service, your subscription status and the entitlements you purchase (e.g. Boost) are recorded. Payments are collected by Apple through the App Store; we do not access or store your card or payment details.
2.10. Website information
- If you fill in the waitlist form, your email address and the section of the page where you filled it in.
- When you access the website, technical logs such as your IP address are created on the servers of GitHub, which hosts the site.
We do not collect advertising identifiers, we do not use your data for advertising, and we do not use third-party analytics or advertising tools. The website does not use cookies.
3. Purposes and legal bases for processing
We process your personal data for the following purposes, based on the legal grounds listed in Article 5 of the KVKK (Article 6 of the GDPR):
- Creating your account, letting you sign in and providing the Service: establishing and performing the contract (KVKK Art. 5/2-c; GDPR Art. 6/1-b).
- Running event discovery, applications, approvals, QR tickets and check-in, event chat, photo sharing and follow features: performance of the contract (KVKK Art. 5/2-c; GDPR Art. 6/1-b).
- Using your date of birth to apply the minimum age requirement and events' age limits: performance of the contract and compliance with our legal obligations (KVKK Art. 5/2-c, ç; GDPR Art. 6/1-b, c).
- Sending location-based notifications about nearby events and push notifications: your explicit consent (KVKK Art. 5/1; GDPR Art. 6/1-a). You can withdraw your consent at any time in your device settings or in the app.
- Allowing organizers to manage applications, check tickets at the door and reply to you: performance of the contract (KVKK Art. 5/2-c; GDPR Art. 6/1-b).
- Maintaining community trust through karma scores and no-show records, reviewing reports, preventing abuse and fraud, and keeping the Service secure: our legitimate interest (KVKK Art. 5/2-f; GDPR Art. 6/1-f).
- Providing organizers with aggregate statistics about their events and improving the Service: our legitimate interest (KVKK Art. 5/2-f; GDPR Art. 6/1-f).
- Notifying you through the website waitlist when the app launches: your explicit consent (KVKK Art. 5/1; GDPR Art. 6/1-a).
- Complying with our legal obligations, responding to requests from competent authorities and protecting our rights in potential disputes: legal obligation and the establishment, exercise or defense of a right (KVKK Art. 5/2-ç, e; GDPR Art. 6/1-c, f).
We do not use your personal data to make decisions about you that produce legal effects through automated decision-making or profiling.
4. Information other users can see
- Profile: Your display name, bio, profile photo, interests, karma score and title are visible to Flok users. If you organize a public event, this information may also be shown to visitors without an account.
- Private information: Your email address, date of birth and location are not shared with other users.
- Events: For public events, the title, description, address, date, organizer and the profile photos of up to four attendees are shown on the event page.
- Organizers: The organizer of an event you apply to can see your name, profile photo, karma score, application status, check-in time and no-show history.
- Chats: Your messages in an event chat are seen by that event's attendees and organizer.
- Photos: Event photos you share may appear in the event gallery and on the profiles of people tagged in them; anyone with the photo's link can access it.
- Reports and feedback: Your event reports are passed to the organizer without revealing your identity; you can choose to send suggestions anonymously. A report you make about a user is not shared with that user.
5. Service providers and international transfers
We do not sell your personal data. We share your data only with the service providers below, and only to the extent needed to provide the Service:
- Supabase Inc.: database, authentication, file storage and server functions. Your data is stored on Supabase servers in the European Union (Paris, France).
- Apple Inc.: Sign in with Apple, delivery of push notifications, address search via Apple Maps and App Store payments. Push notifications may include the sender's name, the event name and a short preview of the message.
- Google LLC: Sign in with Google.
- Resend: emailing you organizers' replies to your suggestions and reports. For this, your email address, the organizer's name, the event name and the relevant messages are shared; your email address is not shown to the organizer.
- RevenueCat, Inc.: verifying your subscription status if paid features are offered; your user ID is shared for this purpose.
- Pexels: the event title and category, to find a suitable cover image for the event.
- Open-Meteo: the event's location and date, to show the weather on the event page. Your own location is not shared.
- GitHub, Inc.: website hosting.
Because these providers' servers are located outside Turkey (in the European Union and the United States), your personal data is transferred abroad. Transfers are carried out in accordance with the transfer mechanisms set out in Article 9 of the KVKK. We may also share your personal data with public authorities and institutions legally entitled to request it, when they make a duly issued request.
6. Retention periods
- We keep your personal data for as long as your account is open.
- When you delete your account, your account, profile, the events you organize (including their applications, chats and photos), your applications, tickets, messages, photos, follow relationships, blocks, report records, location and notification tokens are deleted.
- After your account is deleted, a short excerpt of your message and your name quoted in other users' chat replies, and entries in other users' notification inboxes (without your name), may remain.
- Data we are legally required to keep, or that is needed for potential disputes, is kept for the relevant period.
- Copies remaining in technical backups are deleted within the backup cycle.
- Notification tokens that become invalid are deleted automatically.
- Your email address on the waitlist is deleted after we notify you that the app has launched, or upon your request.
7. Data security
To protect your data, we apply technical and organizational measures such as encrypted connections (TLS), row-level access rules, making sensitive fields accessible only to the account owner, and storing sensitive data on your device in the Keychain. No system is completely secure; if you suspect unauthorized access to your account, please let us know right away.
8. Children's privacy
The Service is not intended for people under 13, and they cannot create an account. Users who are at least 13 but under 18 must use the Service with the consent of a parent or guardian. If we learn that we are processing data belonging to a user under 13, we will delete the account and the data.
9. Your rights
Under Article 11 of the KVKK, you have the right to:
- learn whether your personal data is processed,
- request information about it if it has been processed,
- learn the purpose of the processing and whether the data is used in line with that purpose,
- know the third parties in Turkey or abroad to whom your data is transferred,
- request correction if your data is incomplete or inaccurate,
- request deletion or destruction of your data under the conditions in Article 7 of the KVKK,
- request that corrections, deletions and destructions be notified to the third parties to whom your data was transferred,
- object to an outcome against you that arises from analysis carried out exclusively by automated systems,
- claim compensation if you suffer damage due to unlawful processing.
Users covered by the GDPR also have the right to data portability, the right to restrict processing and the right to object to processing based on legitimate interest.
You can send your requests, with information that allows us to verify your identity, from the email address registered to your account to destek@flok.ist. Requests are resolved free of charge within 30 days at the latest. If your request is rejected, you find the response insufficient, or we do not respond in time, you can file a complaint with Turkey's Personal Data Protection Board; users covered by the GDPR can contact the data protection authority in their country.
You can also exercise some of your rights directly in the app:
- You can edit your profile information on the Profile screen.
- You can permanently delete your account and data in Settings → Delete My Account.
- You can turn off location, camera, photo and notification permissions at any time in your device settings.
- You can delete photos and reports you've shared, and hide photos you're tagged in from your profile.
10. Changes
We may update this Policy to reflect changes in the Service or in the law. The current version is always published on this page with its update date. We will also announce significant changes in the app.
11. Contact
For questions about this Policy or your personal data: destek@flok.ist