Privacy Policy
Last updated: September 26, 2026
Avrora is a travel guide application for people visiting Istanbul. This page explains what data is collected, why, who it is shared with, and what rights you have over it.
The operator and data controller is Mehmet Aşkın Şengül, Istanbul, Türkiye. Contact: masengul@gmail.com
This policy is written to meet Türkiye’s Personal Data Protection Law (KVKK, no. 6698) and the European Union General Data Protection Regulation (GDPR).
1. What is collected
The application collects only what it needs in order to work.
| Data | Why |
|---|---|
| E-mail address | This is your account identity; sign-in, invitation and confirmation links go there. |
| Full name | To address you in the app and to tell you apart in your guide’s customer list. |
| Password | Only a bcrypt hash is stored. The password itself is never kept and cannot be read by us. |
| Language preference | Sets the language of the interface and of the e-mails sent to you. |
| Phone and notes (optional) | Only the tour guide who invited you can enter these, for their own customer records. |
| Places you ticked off | So you can mark which places you have seen. |
| Place pages you opened | Which places you looked at, so the guide can suggest ones that suit you. How long you stayed or what you read is not recorded — only which place, and how many times. |
| Your day plan | The itinerary your tour guide prepared for you. |
| Share links you create | So you can send a set of places to someone else. |
2. Your location never leaves your device
When you use the “near me” filter or show yourself on the map, your browser asks for location permission. It is asked only when you press that button, never on page load.
Your position is not sent to our servers and not stored. Distances and ordering are calculated entirely inside your device, and the information is gone when you close the app.
3. What is stored on your device
So that it works without a signal, the application keeps a copy of the guide on your device (the browser’s IndexedDB storage). That includes places, practical notes, your day plan and your ticks.
Your session keys and your language and appearance preferences are kept in the browser’s local storage. All of it is deleted from the device when you sign out.
4. Cookies and analytics
The application uses no advertising cookies. The keys that keep you signed in are not cookies; they live in the browser’s local storage.
Google Analytics 4 (measurement id G-G5ZVJP4RPW) is used for visit statistics and that service sets its own cookies. It is there to show, in aggregate, which pages are visited.
Secrets in the address bar are redacted before anything reaches Google: an invitation link is reported as /invite/:token and a share link as /s/:token. The tokens themselves never reach Google.
5. Who the data is shared with
We do not sell your data. These services are used to run the application:
| Service | For what |
|---|---|
| Amazon Web Services (Lightsail, Frankfurt) | Server and database. Data is held inside the European Union. |
| Google Analytics (Google Ireland/LLC) | Visit statistics: your IP address and the redacted page path. |
| Sign in with Google (if you use it) | Authentication. Only your e-mail address, name and account id are taken from Google. |
| OpenStreetMap | Your browser downloads map tiles directly, so they see your IP address. |
| Wikimedia Commons | Some place photographs load from there, and they likewise see your IP address. |
| Anthropic (Claude) | Writing the wording of recommendations. Only place names are sent; not your identity. |
| E-mail server (SMTP) | Delivering invitation and confirmation mail. |
6. Recommendations and AI
The application suggests places to you based on the ones you have opened and the ones you have seen. Those suggestions are chosen from the guide’s own catalogue; nothing is searched on the web.
Anthropic’s Claude model is used to write the wording of the suggestions. Your name, e-mail address and identity are not sent to the model: only which places you looked at and which you visited, by name. Anthropic does not use this data to train its models.
If AI is not configured, or the call fails, the suggestions are produced entirely on our own server by simple scoring and no data leaves it.
7. Share links are public
When you share a list of places or a day plan, a long, unguessable address is created. Anyone holding that address can see that list, with or without an account.
The shared page shows only the first word of your name; your e-mail, phone and other plans are not shown. You can switch a link off from the app at any time.
8. How long data is kept
- Your account data is kept for as long as the account exists.
- Session refresh keys are deleted automatically one day after they expire.
- If you ask for your account to be deleted, your personal data is removed; clearing it from backups takes up to 30 days.
- Server access logs, including IP addresses, are kept briefly for security.
9. Your rights
Under KVKK and GDPR you may access your data, ask for it to be corrected, ask for it to be deleted, obtain a portable copy, and object to its processing.
To exercise any of these, write to masengul@gmail.com. You will receive a reply within 30 days. If you are not satisfied, you may complain to the Personal Data Protection Authority in Türkiye, or to your national data protection authority in the European Union.
10. Children
The application is not intended for people under 16 and does not knowingly collect data from them. If we learn that such an account exists, we delete it.
11. Security
- All traffic is encrypted with HTTPS.
- Passwords are hashed with bcrypt and never stored in plain text.
- Invitation and confirmation links are single-use and expire.
- Only a hash of each session refresh key is stored, and the key is rotated on every use.
12. Changes
When this text changes, the date above is updated. If a change is significant, it will be announced inside the application.
13. Governing version
This policy is published in Turkish and English. If the two differ, the Turkish text governs.