Skip to content
← Back to Sharefold

Privacy Policy

Effective from: 26 August 2026

This policy explains what Sharefold does with your data. It is the information notice required by the EU General Data Protection Regulation (GDPR) and by Türkiye’s Personal Data Protection Law No. 6698 — commonly called KVKK after its Turkish name, Kişisel Verilerin Korunması Kanunu.

1. Who is responsible for your data

The data controller is Taha Furkan Aydoğmuş, an individual established in Türkiye, operating the Sharefold application and this website.

Contact for every privacy question or request: support@sharefold.app.

2. The short version

  • Your e-mail address is not stored in Sharefold’s own database. Sign-in is handled by Google Firebase Authentication, which holds it; our database only ever keeps a pseudonymous account id — one that carries no name and no address, but is still linked to you and is therefore not anonymous.
  • What we store is what you write: spaces, expenses, amounts, balances, lists, planned payments, and the display names used inside a space.
  • Your data is never sold, never handed to a data broker, and never used to train a model. Those do not change. Advertising, analytics and crash reporting are a separate question, answered honestly below: there is none of any of them today, and this page is what tells you if that changes.
  • You can export everything from the app, and you can delete your account from the app.

3. What we collect, and where it lives

DataWhere it is heldWhy
E-mail address, password, name given at sign-up, Google account identityGoogle Firebase Authentication — not a field in Sharefold’s database. It reaches our servers inside the sign-in token, where it is checked and not written down, and it reaches us again if you write to usTo let you sign in, verify your address and recover your account
A pseudonymous account id, and which provider it came fromSharefold’s databaseTo connect your sign-in to your data
Guest device credential (a secret generated on your device)Your device’s secure storage; only its derived identifier reaches usTo let you use Sharefold without an account
The display name you use inside a spaceSharefold’s databaseSo other members can tell who is who
Spaces, expenses, amounts, currencies, splits, balances, settlements, categories, notes, shared lists, planned payments, whiteboardsSharefold’s database, and a cache on your deviceThis is the product
Notification token, if you turn notifications onSharefold’s databaseTo deliver notifications to that device
A problem report you choose to send: your message, app version, platform, device model and Android/iOS versionTwo places. It is stored in Sharefold’s database *and* forwarded to us as a Telegram message. Whatever you type into it goes to both — so it is the one field in Sharefold where you decide what we see about you or anybody elseTo reproduce and fix what you reported
While a deletion is being completed: the identifier your sign-in provider knows you by, and nothing elseSharefold’s database, until the provider confirms the deletionIt is the only way to finish erasing you at the provider; the row is removed as soon as that succeeds
Technical connection data — IP address, timestamps, error logsServer and infrastructure logs, kept brieflySecurity, abuse prevention and debugging

A problem report includes the device model (for example `SM-S936B`), never the device name. Diagnostics attached to a report are sanitised before they leave the app.

4. What we do not do — and what could change

Two lists, because they are not the same kind of promise, and running them together would be the easiest way to mislead you.

These do not change. They are about what your content is for, and that is not a product decision we intend to revisit:

  • We do not sell or rent personal data to anybody, for any purpose.
  • We do not pass your data to data brokers.
  • We do not use what you record in Sharefold — your expenses, amounts, balances, notes or lists — to train machine-learning models.
  • If advertising ever appears in Sharefold, it will not be targeted using what you record here, and we will say so before it happens.

True on this policy’s effective date. Any of it may change as the product does, and if it does, this page changes first:

  • The app contains no analytics SDK and no attribution SDK. None — not a disabled one, not one behind a flag.
  • The app contains no crash-reporting SDK. Diagnostics are written to a log on your phone, and leave it only inside a problem report you choose to send.
  • There is no advertising anywhere in Sharefold, no advertising library is bundled, and no advertising identifier is read.
  • Sharefold does not track you across other apps or websites, and does not profile you or make automated decisions about you.
  • Sharefold does not connect to a bank and collects no bank account, card or payment data.
  • Sharefold asks for no location, no contacts, no photos, no microphone and no camera.
  • Push notifications are delivered through Google Firebase Cloud Messaging (FCM) when you enable them. FCM receives a device token and a machine-readable event reference; Sharefold writes the visible sentence on your device in your chosen language.

Sharefold will change. Crash reporting and push delivery are already planned, because a defect nobody can reproduce is a defect that stays, and a feature people ask for may well need a permission this list currently rules out. The rule we hold ourselves to is the order of events: before a new category of data, a new purpose, a new provider or a new sharing activity is switched on, this page is updated and given a new effective date, and where the law requires consent we ask for it rather than assume it. What we will not do is quietly widen this section and hope you do not read it again.

5. Why we use it, and on what legal basis

PurposeGDPR basisKVKK basis
Providing the app, your account and your spacesArt. 6(1)(b) — performance of a contractArt. 5/2-c — necessary for performing a contract
Keeping the service secure and preventing abuseArt. 6(1)(f) — legitimate interestsArt. 5/2-f — legitimate interests
Answering your messages and fixing reported problemsArt. 6(1)(b) and 6(1)(f)Art. 5/2-c and 5/2-f
Meeting a legal obligation, or responding to a lawful requestArt. 6(1)(c)Art. 5/2-a and 5/2-ç
Sending push notifications, where you enabled themArt. 6(1)(a) — consent, withdrawable at any timeArt. 5/1 — explicit consent

6. Who else processes it

We use as few providers as the service can run on. Today they are:

ProviderWhat it doesWhat it sees
Google (Firebase Authentication, Google Sign-In)Authentication, e-mail verification, password resetYour e-mail address, password hash, name and Google account identity
Google (Firebase Cloud Messaging)Delivers push notifications you enabledA device token, Firebase project id and a machine-readable event reference — not the readable notification text
Cloudflare, Inc.Hosting and delivery of this website and invitation linksTechnical request data such as IP address and user agent
Google Cloud (Cloud Run and Cloud SQL, region europe-west3, Frankfurt)Runs the Sharefold API and its databaseEverything listed as held in “Sharefold’s database” above
Resend (Plus Five Five, Inc.)Delivers the account e-mails — address verification and password resetYour e-mail address and the contents of those messages
Telegram MessengerCarries problem reports to us. The report is stored in our database and sent as a Telegram message; it is not one or the otherEverything in that report — your message in your own words, and the device fields

Beyond these, we disclose personal data only where the law requires it, or to establish, exercise or defend a legal claim.

7. Transfers abroad

Google, Cloudflare, Resend and Telegram operate globally, so your data is processed outside Türkiye and, for some of it, outside the European Economic Area. The Sharefold API and its database run in Google Cloud’s europe-west3 (Frankfurt) region, so that part stays inside the EEA; sign-in, e-mail delivery, this website and problem reports do not. These are regular transfers, not occasional ones, and we use each provider’s data processing terms and standard contractual clauses.

Under KVKK as amended in 2024, a regular transfer abroad needs an adequacy decision or an appropriate safeguard recognised by the Authority — a standard contract between the parties, notified to it — rather than a provider’s own clauses alone, and explicit consent is meant for occasional transfers rather than as a standing basis. That paperwork is not complete. Saying so is more use to you than a sentence implying it is: it is being worked through before public release, and this section will name exactly which mechanism covers which provider when it is.

8. How long we keep it

  • Account and content — for as long as your account exists.
  • Financial records inside a shared space — kept after you leave or delete your account, with the direct identifiers removed, because they are also the other members’ records and destroying them would silently change somebody else’s balance. See Deleting your account.
  • Problem reports — 24 months. This one is enforced by code that runs daily and deletes anything older, not by intention.
  • Notification tokens — until you turn notifications off or the token stops working.
  • The deletion queue — a row lives only until your sign-in provider confirms the deletion, and is removed the moment it does.

Sharefold now runs in production on Google Cloud. Infrastructure logs and managed database backups may therefore contain personal data for limited operational, security and recovery periods set in the relevant cloud configuration. We do not invent a fixed retention number here until that configuration is both final and independently verified; you may ask us for the current period at any time.

9. Your rights

Under Article 11 of Türkiye’s Personal Data Protection Law No. 6698 (KVKK) and under the GDPR, you can ask us to:

  • tell you whether we hold data about you, and give you a copy;
  • correct data that is wrong or incomplete;
  • delete data, where the law allows it;
  • restrict or object to a particular use;
  • hand your data over in a portable format — the app does this itself, from Account → Export;
  • tell you who your data has been passed to;
  • withdraw a consent you gave, without affecting what was done before you withdrew it.

Write to support@sharefold.app and we will answer within 30 days — the limit set by KVKK, and by the GDPR for a one-month response.

A formal request under Law No. 6698 must identify you and follow the Communiqué on the Procedures and Principles of Application to the Data Controller. If you are unhappy with our answer, you may complain to Türkiye’s Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) or, in the EEA, to your local supervisory authority.

10. How we protect it

  • All traffic between the app and our servers is encrypted in transit (TLS).
  • Credentials on your device are held in the platform’s secure storage — Android Keystore, iOS Keychain.
  • The app can be locked behind your device’s biometric or PIN lock.
  • Database access is restricted to the roles that need it. Financial records are not silently edited or deleted in normal use: a correction is a reversing entry plus a new one, so the history stays readable. Erasure that the law requires is done by removing the direct identifiers, which is the exception that rule is built to allow.
  • Passwords are never seen by us: they are held and verified by Google Firebase Authentication.

No system is perfectly secure. If a breach ever affects your rights we will notify you and the competent authority as the law requires.

11. Children

Sharefold is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has given us personal data, write to support@sharefold.app and we will delete it.

12. Cookies and this website

This website sets no cookies and runs no analytics. It stores two preferences in your browser’s local storage — your language and your light/dark choice — and nothing else. Neither leaves your browser, which is why you are not being asked to consent to anything here.

13. Changes to this policy

When this policy changes, the new text and a new effective date appear on this page. A material change is shown in the app before it takes effect.