oigochat Privacy Policy
This policy explains how your personal data is processed when you use the oigochat mobile app, under applicable privacy laws including Turkey’s KVKK and the GDPR. The data controller is oigoworks, the developer of oigochat.
01Data We Process
- Account: username, email address or phone number, password hash (the password itself is never stored).
- Profile: display name, date of birth, gender, bio, interests, profile answers, profile photo and gallery images, the country/city you state.
- Content: messages, stories, photos/videos/audio you upload, game responses.
- Technical: hashed IP address, device and session information, push token, last login, app version, crash and error reports.
- Safety: reports, trust score events, moderation and automatic scanning records.
- Purchases: store transaction IDs and the product bought. Your card details never reach us; payments are processed by Google Play / the App Store.
We do not collect your device’s GPS location, contacts, calendar or call history.
02Purposes and Legal Bases
- Providing the service and managing your account (performance of contract).
- Running chat, profile, media and game features (performance of contract).
- Detecting and preventing abuse, spam, fake accounts and illegal content; protecting children (legitimate interest, legal obligation).
- Meeting legal obligations and responding to lawful requests from authorities (legal obligation).
- Measuring service quality and fixing errors (legitimate interest).
03Automatic Content Scanning
- To protect children and block illegal content, text you write in groups, rooms, KonuBul, profiles, private messages and games is automatically scanned on our own servers.
- Private messages and games are scanned only for child safety and plainly illegal content (such as illegal sales or plans for an attack). This scanning runs entirely on our own servers and nothing is sent to any third party for it.
- Consensual sexual content and fiction between adults is not what this scanning looks for, and it is not flagged.
- Scanning is not used for advertising, profiling or any other purpose.
- Scanning does not by itself show your text to anyone. A text is reviewed by an authorized moderator only if it is automatically flagged or reported; for private messages the moderator sees only that one message. Every review is logged.
- On a clear child-safety match, content may be hidden before it is published (not deleted) and the account’s ability to send messages may be paused until the review ends. If the match was wrong, the hidden content is restored and the restriction lifted. A person always makes the decision to close an account. Details: Child Safety Standards.
04Reports and Moderation
- When you report a message, the reviewing moderator sees only that message; the rest of the conversation is not opened to the moderation panel.
- The account behind an anonymous sender is not shown to moderators.
- AI is used only to prioritize reports and suggest to a moderator; it never closes an account, lowers a trust score or dismisses a report on its own.
- Uploaded photos and videos are automatically scanned for safety risks. Images showing genitals or sexual acts, and graphic violence, are blocked; uncertain content goes to a person.
05Service Providers
We do not sell your personal data or rent it for marketing. We work with the providers below, sharing only the minimum needed to run the service:
- Hetzner (EU data centre): servers, database and media storage, on servers we operate ourselves.
- Google Drive: database and media backups, encrypted on our server before upload; Google cannot read the content.
- Firebase Cloud Messaging (Google): push notifications.
- Twilio / email provider: delivering verification codes.
- Sentry: app crash and error reports.
- OpenAI: safety scanning of uploaded images and videos; suggestions to moderators using limited context from reported content (emails, phone numbers and links are redacted first); and, only when you use paid translation, the message text you ask to translate. OpenAI may retain content sent through its API for up to 30 days for abuse monitoring. The automatic scanning of private messages is not sent to OpenAI.
- Google Play / App Store: processing in-app purchases.
- Authorities: only where the law requires and on a lawful request.
06International Transfers
Our servers are in the EU. Some of the providers above (e.g. OpenAI, Sentry, Google) may process data outside the EU, including in the US. These transfers rely on the safeguards provided for under KVKK and the GDPR.
07Retention
- Account data: while your account is active.
- Account deletion: 30 days after your request your messages, media and profile are permanently deleted; you can cancel the request within that period.
- View-once media: closes for both sides when opened; it is kept, shown to no one, for 48 hours in case of a report, then deleted. View-once media never opened is deleted after 7 days. Reported content is kept until the review ends.
- Logs: technical logs are anonymized after 90 days.
- Sanctioned accounts: when an account suspended for violating the rules is deleted, its email and phone are kept only as an irreversible hash (HMAC) to prevent re-registration with the same details.
- Child sexual abuse records: records and evidence relating to child sexual abuse may be retained for as long as the law requires, even after the account is deleted, and reported to the authorities.
08Voice Calls
Voice calls are not recorded, stored or listened to; only who called whom and when is logged.
09Security
- Passwords are hashed with bcrypt.
- All traffic between the app and our servers is encrypted with TLS (HTTPS).
- Backups are encrypted before they leave the server.
- Staff access to moderation is role-based and logged.
No system is 100% secure. If a data breach occurs, we make the notifications the law requires.
10Children
oigochat is only for people aged 18 or over. If a user under 18 is identified, the account is closed and its data deleted.
11Your Rights
Under KVKK Article 11 and the GDPR you have the right to:
- learn whether your data is processed and request information about it,
- learn the purpose of processing and whether data is used accordingly,
- know the third parties it is transferred to, in Turkey or abroad,
- request correction, deletion or restriction of processing,
- data portability and to object to processing,
- object to an outcome against you resulting from automated analysis,
- claim compensation for unlawful processing and lodge a complaint with a data protection authority.
You can delete your account and edit your profile inside the app (see Account & Data Control). Send requests to contact@oigoworks.com; they are answered within 30 days at the latest.
12Changes
This policy may be updated. Material changes are announced in the app; the date at the top of this page shows the latest update.
13Contact
For privacy, data requests and child safety reports:
- Company: oigoworks
- Email: contact@oigoworks.com
- Address: Antalya, Turkey
