Skip to content
Odyssey JournalEst. 2026
English EN Türkçe TR Español ES Français FR Deutsch DE Português PT Italiano IT Русский RU 日本語 JA 한국어 KO 中文 ZH العربية AR
Get the App
✦
Legal Dispatch

Privacy Policy

How Odyssey Journal collects, stores and protects your data — written to comply with KVKK (Law No. 6698), the GDPR and the CCPA.

✦Last updated: September 2026

Contents
  1. 01Introduction & Data Controller
  2. 02Information We Collect
  3. 03Infrastructure & Supabase Data Architecture
  4. 04How We Use Your Information & Legal Basis
  5. 05Third-Party Sub-Processors
  6. 06User-Generated Content & Third-Party Privacy
  7. 07International Data Transfers
  8. 08Data Retention & Deletion
  9. 09Rights Under Turkish Law (KVKK Article 11)
  10. 10Rights Under GDPR (EEA & UK Users)
  11. 11California Privacy Rights (CCPA / CPRA)
  12. 12Children's Privacy
  13. 13Cookies & Local Storage
  14. 14Changes to This Privacy Policy
  15. 15Contact Information

01Introduction & Data Controller

Welcome to Odyssey Journal ("we," "our," "us," or the "App"). We respect your privacy and are committed to protecting your personal data in full compliance with the Turkish Law on the Protection of Personal Data (KVKK - Law No. 6698), the General Data Protection Regulation (GDPR - EU 2016/679), and the California Consumer Privacy Act (CCPA).

This Privacy Policy explains how we collect, use, store, process, and protect your information when you use our mobile application and related web services at odysseyjournal.app.

  • Data Controller: Odyssey Journal / Arif Gültaş
  • Data Protection & Privacy Contact: privacy@odysseyjournal.app
  • General Support: support@odysseyjournal.app
  • Official Website: odysseyjournal.app

By creating an account, downloading, or using Odyssey Journal, you acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy and our Terms of Service.

02Information We Collect

A. Information You Voluntarily Provide

  • Account Credentials: Email address, password (securely hashed and salted via Supabase Auth), username, full name, profile bio, avatar image.
  • User-Generated Content (UGC): Travel posts, stories, photographs, comments, bookmarks, collections, reactions (likes), travel dates, and optional location names/destinations.
  • Direct Communications: In-app private direct messages between travelers and support communications sent to our email addresses.

B. Automatically Collected Technical Data

  • Device Information: Device model, manufacturer, operating system and version, unique device identifiers, preferred language, time zone.
  • Diagnostic & Crash Data: Crash logs, stack traces, and application performance metrics collected through Sentry (strictly scrubbed of Personally Identifiable Information - PII).
  • Network & Session Data: IP address (anonymized/scrubbed where possible), connection status, app launch timestamps.

C. Location Information

  • Precise Location (GPS): Only requested when you explicitly tag a travel post with your current location. We never track your location in the background or continuously. You may revoke location permissions at any time through your device settings.

03Infrastructure & Supabase Data Architecture

Odyssey Journal uses Supabase (supabase.com) as its core cloud backend, database, authentication engine, and media storage provider.

Supabase Security & Storage Specifications:

  • Server Region: Our primary production database and media storage are hosted on Supabase enterprise infrastructure (AWS EU region - Frankfurt, Germany).
  • Encryption in Transit: All communications between the mobile application, web clients, and Supabase servers are encrypted using TLS 1.3 / HTTPS.
  • Encryption at Rest: All database tables, user records, and uploaded media files are encrypted at rest using industry-standard AES-256 encryption.
  • Row Level Security (RLS): Strict granular database policies enforce access isolation. Users can only read, insert, update, or delete data permitted by verified cryptographic authentication tokens (JWT).
  • Token Security: Authentication tokens are stored locally on user devices using secure native storage mechanisms (iOS Keychain and Android Keystore / EncryptedSharedPreferences via Expo Secure/Async Storage).
  • Automated Backups: Backups are performed automatically on our Supabase Pro tier, with point-in-time recovery to prevent data corruption.

04How We Use Your Information & Legal Basis

We process personal data under the lawful bases defined in KVKK Article 5 & 6 and GDPR Article 6:

PurposeCategory of DataLegal Basis (KVKK & GDPR)
Creating and managing your accountEmail, username, passwordPerformance of Contract
Publishing travel posts, photos, commentsUser Content, photos, locationsPerformance of Contract & Explicit Consent
Interactive map & nearby destination taggingGPS coordinates (per-post)Explicit Consent
Sending push notifications (likes, follows, chat)Push notification tokenExplicit Consent & Legitimate Interest
Application stability, crash triage, bug fixesAnonymized crash logs (Sentry)Legitimate Interests
Preventing spam, abuse, security violationsIP, account identifiersLegal Obligation & Security

05Third-Party Sub-Processors

We partner only with reputable third-party service providers that maintain strict data security and privacy standards:

  1. Supabase, Inc.: Cloud database, user authentication, object storage for photos. (Servers: AWS Frankfurt, Germany - EU).
  2. Sentry (Functional Software, Inc.): Real-time error monitoring and crash diagnostics. Client-side PII scrubbing is enabled to prevent transmission of emails, usernames, or sensitive payload data.
  3. Google LLC (Google Maps Platform): Reverse geocoding and interactive map tiles.
  4. Google LLC (Google Workspace): Enterprise email hosting for customer support and privacy inquiries.
  5. Expo / 650 Industries, Inc.: Application framework and push notification gateway (Expo Push Service).

We do NOT sell, rent, or trade your personal data to data brokers, advertisers, or any commercial third parties.

06User-Generated Content & Third-Party Privacy

IMPORTANT

Odyssey Journal is a social travel documentation platform. When creating posts and sharing photos:

  • You are strictly responsible for ensuring that you have full legal rights, copyright, and authorization for all photos, text, and media you upload.
  • Third-Party Personal Data & Images: You must NOT post recognizable faces, private moments, identity details, or license plates of other individuals without their explicit, informed consent.
  • Indemnification & Recourse: In the event of any administrative fines, regulatory penalties (including KVKK fines), civil claims, or damages asserted against Odyssey Journal / the developer arising from content you published, you agree to indemnify, hold harmless, and defend us in full, and reimburse all damages, legal fees, and costs.
  • We reserve the right to review, moderate, hide, or permanently remove any content reported for violating privacy, copyright, or community guidelines, and to terminate repeat offender accounts without notice.

07International Data Transfers

To provide globally accessible, high-performance services, your data is processed on secure cloud infrastructure hosted in the European Union (Frankfurt, Germany) and the United States by our certified sub-processors (Supabase, Sentry, Google, Expo).

  • Under KVKK (Article 9): By registering an account and using Odyssey Journal, you provide explicit consent to the transfer of your account data, travel posts, and technical metadata to our secure international cloud servers for the performance of the service contract.
  • Under GDPR (Chapter V): Transfers to sub-processors outside the EEA are governed by European Commission Standard Contractual Clauses (SCCs) and adequacy decisions.

08Data Retention & Deletion

  • Active Accounts: We retain your personal data and travel journal entries for as long as your account remains active.
  • Account Deletion: You can permanently delete your account and all associated posts, photos, comments, and messages directly in the App at: Settings > Account > Delete Account.
  • Purge Timeline: Upon account deletion, your profile and posts are immediately removed from public view and permanently purged from our Supabase database and storage buckets within thirty (30) days, except where retention is legally required by applicable statute of limitations.

09Rights Under Turkish Law (KVKK Article 11)

Under Article 11 of Law No. 6698 of the Republic of Türkiye on the Protection of Personal Data ("KVKK"), you have the following rights as a data subject:

  1. to learn whether your personal data is being processed;
  2. to request information about the processing, if your data has been processed;
  3. to learn the purpose of the processing and whether your data is used in accordance with that purpose;
  4. to know the third parties within Türkiye or abroad to whom your personal data has been transferred;
  5. to request that incomplete or inaccurate personal data be corrected;
  6. to request the erasure or destruction of your personal data under the conditions set out in Article 7 of the KVKK;
  7. to request that any correction, erasure or destruction be notified to the third parties to whom your data was transferred;
  8. to object to an outcome to your detriment that arises from the analysis of your data exclusively by automated means;
  9. to claim compensation for damage suffered as a result of unlawful processing of your personal data.

How to Submit a Request: You may send your KVKK requests, together with information confirming your identity, to privacy@odysseyjournal.app. Depending on their nature, requests are concluded free of charge within thirty (30) days at the latest.

10Rights Under GDPR (EEA & UK Users)

If you are a resident of the European Economic Area (EEA) or United Kingdom, you have the following rights under GDPR:

  • Right of Access (Article 15)
  • Right to Rectification (Article 16)
  • Right to Erasure / Right to be Forgotten (Article 17)
  • Right to Restriction of Processing (Article 18)
  • Right to Data Portability (Article 20)
  • Right to Object (Article 21)
  • Right to Lodge a Complaint with your local Data Protection Supervisory Authority.

To exercise these rights, contact privacy@odysseyjournal.app.

11California Privacy Rights (CCPA / CPRA)

California residents have the right to request disclosure of personal information collected, request deletion of personal information, opt-out of the sale of personal information (we do not sell personal information), and not be discriminated against for exercising these rights. Inquiries should be sent to privacy@odysseyjournal.app.

12Children's Privacy

Odyssey Journal is not intended for or directed to children under the age of 13 (or under 16 in certain jurisdictions). We do not knowingly collect personal data from children. If we discover that a child has provided us with personal data, we will immediately delete such data from our servers. Parents or guardians who believe their child's data has been collected can contact privacy@odysseyjournal.app.

13Cookies & Local Storage

Odyssey Journal sets no advertising, analytics, profiling, or cross-site tracking cookies on either the mobile application or odysseyjournal.app. We run no third-party ad networks and no behavioural analytics scripts, which is why you will not see a cookie consent banner.

The only browser storage this website uses is strictly necessary and stays on your own device:

  • oj-theme — remembers whether you chose the light (Parchment) or dark (Sepia Night) reading theme.
  • oj-lang — remembers your preferred site language.

These values are written to your browser's localStorage, are never transmitted to our servers or to any third party, and can be cleared at any time by clearing your browser's site data.

Within the mobile application, your authentication session token is stored in secure native storage (iOS Keychain / Android Keystore) as described in Section 3. It is required to keep you signed in and is deleted when you sign out or delete your account.

14Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect modifications in our services, technologies, or legal obligations. When significant changes occur, we will notify you through in-app notifications and update the "Last Updated" date at the top of this document. Continued use of the App following the notification constitutes your acceptance of the revised policy.

15Contact Information

For any inquiries, questions, or requests regarding this Privacy Policy or your personal data:

  • Privacy & KVKK Requests: privacy@odysseyjournal.app
  • Customer Support: support@odysseyjournal.app
  • General Inquiries: hello@odysseyjournal.app
  • Postal & Digital Verification: Gultas Software / Arif Gültaş, Istanbul, Türkiye
  • Website: odysseyjournal.app/privacy-policy

By downloading or using Odyssey Journal, you acknowledge and agree to this Privacy Policy.

Also read Terms of Service The agreement covering your account, the content you publish, and how disputes are handled.

← Back to home

© 2026 Odyssey Journal. All journeys reserved. 41.0082° N, 28.9784° E • Crafted with wanderlust.