SecretMapHOMETERMS OF USE
LEGAL · SECRET MAP iOS

PRIVACY POLICY

This policy explains what data Secret Map processes and what it deliberately does not. The only reason we can keep it short is that the list of collected data really is short.

LAST UPDATED 2026-08-09
VERSION 1.3
FATİH GENÇ · KVKK + GDPR
01

IN SHORT

Secret Map does not ask you to open an account, does not ask for your name, does not take your email, and does not touch your contacts or photos. It shows no ads and uses no third-party tracking.

What we hold on our servers is this: the text of the secret you wrote, your location rounded to 5 km, the coarse place name derived from that area, the time it was written, the SAME count it collected, and the identifier linking the secret to your account. Nothing beyond that.

The data controller is Fatih Genç, an individual developer in Türkiye. There is no company behind this: one person builds and runs the app. This policy is written under Turkish Personal Data Protection Law no. 6698 (KVKK) and the EU General Data Protection Regulation (GDPR).

02

DATA WE COLLECT

The table below lists every item we process, why we process it and on what legal basis. We collect nothing that is not on this list.

SECRET TEXT
A title of up to 60 characters and a body of up to 1000. Processed so it can be shown on the map. Basis: performance of a contract.
ROUNDED LOCATION
Your location rounded to 5 km on the device. Determines which circle the secret joins; it is never sent to the client. Basis: performance of a contract.
PUBLISHED PLACE NAME
The coarse place name the author publishes with the secret ("somewhere near Lisbon"). The only location information ever shown to users. Basis: performance of a contract.
TIMESTAMP
For ordering secrets and showing relative times such as "14h ago". Basis: performance of a contract.
ACCOUNT IDENTIFIER
A number belonging to your account, derived from Sign in with Apple. Every secret is attached to it: seeing and deleting your own secrets, and applying the one-a-day, one-an-hour limits, both require that. It is never shown to other users. Basis: performance of a contract.
APPLE USER IDENTIFIER
The stable identifier Apple generates for you. Kept so your secrets follow you to a new device and so a closed account is harder to reopen. Name and email are never requested. Basis: performance of a contract.
SAME RECORDS
Which account pressed SAME on which secret is recorded; that is what stops the same secret being marked twice. Only the total is shown on the secret, and who pressed it is never shown to other users anywhere. Basis: performance of a contract.
REPORT RECORDS
The reported secret, one of seven chosen reasons, the time, and the account that sent it. The reporter's identity is kept so the same person cannot report the same secret twice, and it is never shown to the author under any circumstances. Basis: legitimate interest and legal obligation.
BLOCK LIST
The account identifiers of authors you have blocked, and a quote from the secret that made you block them. Authors have no names, so that quote is the only thing that tells you who is on the list. Kept on the server so your blocks follow you to a new phone. Basis: performance of a contract.
CRASH REPORTS
Device model and iOS version when the app crashes. Collected by Apple and reaching us only if you allow it. Basis: consent.
TIPS
An optional, one-off tip can be left in the app. Payment runs through Apple from beginning to end: your payment details never reach us, and no record of who tipped is kept on our servers. A tip unlocks nothing in the app.
03

HOW LOCATION DATA IS PROCESSED

5 KM
SHAREDCOARSE AREATHE PLACE NAME THE AUTHOR PUBLISHED
NEVER STOREDEXACT POINTNEVER LEAVES THE DEVICE

This is the most important section of the policy. The app requests location permission at the "while using the app" level, never tracks location in the background, and sends no push notifications.

Your location is read on your device and rounded to five kilometres before it reaches a server. Your latitude and longitude are never sent, never stored and never written to any record; they do not leave the device's memory.

A coarse place name is also derived from the rounded location. To do that, the centre of the cell — the middle of the rounded area, not the spot you are standing on — is sent to the operating system's address lookup service; on iOS that service is run by Apple and works over the network. The name that comes back is stored with the secret and shown to everyone who reads it: that is where "somewhere near Lisbon" comes from.

The rounded location itself stays on the server. The client is never told which cell a secret belongs to; the only location information you see in the app is the coarse place name above. No interaction inside the app — tapping, zooming, opening a list — can narrow a secret down to an area smaller than the circle it belongs to.

The zoom limit backs this up. The scale bar never shows anything under 50 kilometres, and about 200 kilometres fits across the width of the screen at the closest zoom level. The map itself has no street, district or city layer; all it draws is landmasses, country borders and country names.

Both the 5 km cell size and this zoom limit are fixed in the app. There is no setting, yours or ours, that changes them while it runs; changing them would take a new version of the app, and if that ever happens we update the date on this page.

We do not derive geographic location from IP addresses. Connection details such as the IP address are kept in our hosting provider's server logs for at most 7 days and used only for abuse detection.

04

RETENTION PERIODS

Secrets stay on the map until you delete them. The moment you do, the text, rounded location, place name and SAME count are removed from the database; clearing them from backups takes at most 30 days.

Server connection logs are kept for at most 7 days. Report records and your block list are not currently bound to a time limit: reports stay for as long as your account does, so that the same person cannot report the same secret twice, and the list of authors you have blocked stays until you unblock them.

"Delete all my data" removes every secret, your reports, your block list and your account identifier. The action cannot be undone, and it is the only way all of those records are erased.

05

SHARING OF DATA

We do not sell your data, do not share it with ad networks and do not transfer it to third parties for marketing.

Sharing arises in two cases only. The first is the hosting provider we use to run the app; it processes data solely on our instructions and keeps it on servers inside the European Union. The second is a properly issued, lawful request from competent authorities; in that case we can hand over only the technical records we hold, which contain neither your exact location nor your identity.

We publish the number of requests received from authorities on this page once a year.

06

THIRD-PARTY SERVICES

There is no ad network, analytics tool or social media plugin in the app. No tracking code from Facebook, Google or any comparable provider is present. There is no push notification infrastructure either; the app sends no notifications at all.

The only third-party components we use are: Sign in with Apple, Apple's address lookup service (for the coarse place name described above), Apple's crash reporting infrastructure (only if you allow it in device settings), Apple's purchase infrastructure for tips, and our hosting provider in the European Union.

The app draws the base map itself. No map SDK or tile server is used; the landmasses, country borders and country names ship with the app and no outbound request is made to draw them. No third party can see where you are looking.

The secrets on top of the map do come from our server: the bounds of the area on your screen are sent, and the circles in that area come back. That request repeats on every pan and zoom. So with no internet connection the map still draws, but no secrets appear on it.

07

SECURITY

All traffic between device and server is encrypted with TLS. The database is encrypted at rest. Access to the administration interface requires two-factor authentication, and the moderation team can see only the secret text and the report reason.

No system is absolutely secure. If a breach affecting personal data occurs, we notify the relevant authorities within 72 hours of becoming aware of it and inform affected users inside the app.

08

YOUR RIGHTS

Under KVKK and GDPR you have the right to access the data processed about you, to have it corrected, to have it erased, to restrict processing, to receive your data in a portable form, and to object to processing.

You can exercise the access and erasure rights instantly inside the app: the "My secrets" list is the entirety of your processed content, and "Delete all my data" carries out an erasure request without any waiting. For other requests write to support.secretmap@gmail.com; we answer within 30 days.

We cannot verify your identity when answering a request, because we do not know it. That is why the in-app tools are the fastest and most reliable route. If our answer does not satisfy you, you may complain to the Turkish Personal Data Protection Authority or to the data protection authority in your own country.

09

CHILDREN'S PRIVACY

The app is intended for people aged 18 and over and is rated accordingly on the App Store. Content and records we learn to belong to someone under 18 are deleted without delay. You can report such a case to support.secretmap@gmail.com.

10

CHANGES AND CONTACT

If we change this policy we will publish the new version on this page and update the date above. If the items collected or the way location is processed ever change, we will show a notice when the app opens before the change takes effect.

Data controller: Fatih Genç, Türkiye. For any question, request or complaint write to support.secretmap@gmail.com.

© 2026 FATİH GENÇ · SECRET MAP