Privacy Policy and Data Protection Notice
Last updated: 7 September 2026
1. Who We Are
1.1. The controller of your personal data is Süleyman Burak Sak, an individual established in Türkiye, operating the Falmira mobile application ("Falmira", "we", "us").
1.2. For any question, request or complaint about your personal data, write to appfalmira@gmail.com.
1.3. This policy explains what we do with your personal data and what rights you have. It applies to everyone who uses Falmira, and it is written to meet the information duties in Articles 13 and 14 of the UK and EU General Data Protection Regulation (GDPR).
2. Scope of This Policy
2.1. This policy covers the Falmira mobile application and the falmira.app website.
2.2. It does not cover the app stores through which you download Falmira or pay for it. Apple and Google act as sellers of record and handle payments under their own privacy policies.
3. Personal Data We Process
3.1. Account data. Depending on how you sign in, we process your email address or your phone number. If you sign in with Apple or Google, we also process the identifier those services pass to us.
3.2. Profile data. We process your name, date of birth, place of birth and relationship status; your time of birth and gender are optional. These are used to produce readings that are specific to you rather than generic.
3.3. What you put into the app. Photographs of your coffee cup and of your palm (taken with your camera or chosen from your gallery), the tarot cards you pick, the dream you describe, the questions you ask and the messages you send in chat. Everything you write as free text (questions, dreams, chat messages) is stored encrypted; your photographs are kept in a private storage area (see section 10).
3.4. What the app produces for you. The reading texts generated for you and the record of which session they belong to. Reading texts are stored encrypted, like your inputs (see section 10).
3.5. Purchase data. The state of your subscription and your token balance. We never see, collect or store your card details; payment happens entirely within the Apple App Store or Google Play.
3.6. Device and usage data. Your device's notification key so we can send notifications, a technical device marker so the first-launch gift can be given once per device, the advertising identifier generated by your device's operating system, event records describing how the app is used, and error reports.
3.7. Referral data. Your own referral code and, if there is one, the code of the person who invited you.
3.8. Dictation. If you tap the microphone icon in a text field, what you say is converted to text by your device's operating system, and only the resulting text reaches the app. We do not capture, store or transmit any audio recording; for where the audio itself goes, see section 8.2(i). If you never use this feature, no voice data is processed.
4. Why We Process It
4.1. To create your account, sign you in and manage your account.
4.2. To produce readings and self-reflection content for you. This is the core purpose of the app.
4.3. To keep your chat history encrypted so you can pick up where you left off.
4.4. To grant your token and subscription entitlements correctly and record your purchases.
4.5. To send notifications, if you have allowed them.
4.6. To find and fix faults, prevent abuse and fraud, and keep the service secure.
4.7. To understand which parts of the app are used and how much, so we can improve it.
4.8. To meet our legal obligations.
4.9. To measure whether our own advertising works. This measurement exists so we can count which installs and purchases came from which campaign. It is not used to show you personalised advertising.
5. Legal Bases
5.1. We rely on the following legal bases under Article 6(1) GDPR:
5.2. Performance of a contract, Article 6(1)(b). Your profile data, the content you enter, the readings produced for you, your chat history, and your token and subscription records. Without these the service you asked for cannot be delivered.
5.3. Our legitimate interests, Article 6(1)(f). Error reports, security and abuse prevention, usage statistics, and measurement of our own advertising. We have considered your rights and freedoms in each case and use the minimum data that answers the question. You may object to processing based on this ground at any time, as described in section 13.
5.4. Legal obligation, Article 6(1)(c). Records we are required by law to keep, including financial records relating to purchases.
5.5. Explicit consent, Article 9(2)(a). Only for special category data that you choose to include in free text, as described in section 6.3.
5.6. Providing your profile data is a contractual requirement: without a name and date of birth, a personal reading cannot be produced. Time of birth and gender are optional, and leaving them out only makes the reading less detailed.
6. Three Things That Need Saying Plainly
6.1. Your palm photograph. The photograph of your palm is used only to produce a written reading. We do not use it to identify you, we do not derive a biometric template from it, and we never compare it with any other photograph. A photograph becomes biometric data only when it is processed technically for the purpose of uniquely identifying someone; our use is not of that kind, so it is not special category data under Article 9.
6.2. What you share in chat or in a dream. In free text fields you may end up mentioning your health, your beliefs, your political views or details of your relationships. We do not ask you for any of this and it is not needed for the service to work.
6.3. If you do share it, that information falls under Article 9 GDPR. By choosing to write it, you give your explicit consent for it to be processed for the single purpose of producing your reading or reply. It is stored encrypted with a key belonging only to your account. You can withdraw that consent at any time by deleting the conversation or your account; when your account is deleted the key is destroyed and the content cannot be recovered. Withdrawing consent does not affect processing that already took place.
6.4. Choosing not to share information of this kind does not make your reading any worse.
6.5. Distress signals. When you send a message, it is checked at that moment only for signs of self-harm or acute distress, so that a signpost to professional support can be added to that one reply.
6.6. The result of that check is never recorded anywhere. It is not written to your profile, not kept as a flag, and never seen by any person.
7. Use of Artificial Intelligence
7.1. Readings are generated by AI language models. To do this, your inputs (your photograph, your dream, your question, your chat message) and the profile data that describes you are sent to the relevant AI provider.
7.2. Your data is not used to train or improve AI models — neither by us nor by the providers. We operate under enterprise service terms that prohibit that use.
7.3. No decision producing legal effects concerning you, or similarly significantly affecting you, is made solely by automated means within the meaning of Article 22 GDPR. The texts produced are interpretations; nothing about your access to the service changes because of them.
7.4. The app calculates a daily aura value from your birth details and the positions of the sky on that day. It is shown to you and used to set the tone of your readings; it is not stored, and is recalculated each day.
8. Who We Share It With
8.1. We do not sell your data. Your readings, chats, photographs and free text are never sent anywhere for advertising purposes. Only the limited data listed in 8.2(j) is shared so that our own advertising can be measured.
8.2. We use the following processors and third parties. Each receives only what it needs to do its job:
(a) Google (AI generation) — the photograph, dream, question and chat messages you enter, together with the profile data describing you (your name, age, signs, place of birth, relationship status, gender), are sent so that your reading can be produced.
(b) Supabase (database and authentication) — your account, profile, readings, chats and photographs are hosted here. The servers are in the European Union (Frankfurt, Germany).
(c) OpenAI (fallback AI provider) — only when the primary provider cannot be reached, the same content is sent so that a reading can still be produced.
(d) RevenueCat (purchase management) — your account identifier and purchase state. No card details are sent. Your purchase events are passed on to Meta for the measurement described in (j).
(e) PostHog (usage analytics) — your account identifier, event records such as which screens are used, and categorical attributes such as your sign, gender, relationship status and premium status. Your name, date of birth, photographs, readings and chats are not sent. Its servers are in the European Union.
(f) Expo (notification delivery) — if you have allowed notifications, your device's notification key and the content of the notification pass through this service. Expo uses Google Firebase Cloud Messaging on Android and the Apple Push Notification service on iOS to reach your device. If you turn notifications off, this transfer does not happen.
(g) Sentry (error monitoring) — when an error occurs, the error record and your account identifier.
(h) Apple and Google (app stores) — these companies process purchases and are the sellers of record.
(i) Apple and Google (speech to text) — if you use dictation, your speech is converted to text by your device's operating system: Apple on iOS, Google on Android. Your audio may reach that company's infrastructure during this and never passes through our servers; we receive only the resulting text. If you do not use the feature, no such transfer occurs.
(j) Meta (advertising measurement) — so we can tell whether our Instagram and Facebook campaigns work, your device's advertising identifier, your install and open events and your purchase events (amount and currency) are sent to Meta. Your name, birth details, photographs, readings and chats are not sent. You can reset the advertising identifier or turn off personalised advertising in your device settings (Android: Settings, then Google, then Ads; iOS: Settings, then Privacy and Security, then Tracking).
8.3. We may also disclose data to competent public authorities where their request has a lawful basis.
9. International Transfers
9.1. We are established in Türkiye, and the providers listed in section 8 are established outside the European Economic Area or process data outside it. Your data is therefore transferred outside the EEA and the United Kingdom.
9.2. The transferred data is not anonymous; it can be linked to your account.
9.3. The European Commission has not adopted an adequacy decision for Türkiye. Where our providers offer standard contractual clauses or operate under an approved transfer mechanism, we rely on those. Where such a mechanism is not available to an individual developer, the transfer rests on the safeguards described in 9.4 rather than on a formal Article 46 instrument. We state this plainly rather than imply a protection we cannot evidence.
9.4. The measures we do apply:
(a) We choose providers whose enterprise terms commit them not to use your data for their own purposes.
(b) We send each provider only the data it needs. The analytics provider never receives reading or chat content.
(c) Free text and reading texts are stored encrypted, with a separate key for each user.
(d) Where a provider offers an EU region, we use it. Our database and our analytics both run in the European Union.
9.5. You can ask us for more detail about a specific transfer by writing to appfalmira@gmail.com.
10. Security
10.1. What you write in free text fields — your questions, your dreams, your chat messages — and the reading texts produced for you are stored encrypted on our servers.
10.2. The encryption key is separate for every user. One user's data cannot be opened with another user's key.
10.3. When you delete your account the key is destroyed. Without the key the content cannot be recovered.
10.4. Your photographs are held in a private storage area reachable only through your own account.
10.5. No system can offer absolute security. We take appropriate technical and organisational measures, and if a personal data breach occurs we will make the notifications required of us, including notifying the competent supervisory authority within 72 hours where the breach is likely to result in a risk to your rights and freedoms.
11. How Long We Keep It
11.1. Your account data, profile, readings and chats are kept for as long as your account exists.
11.2. Daily horoscope texts are deleted automatically after 21 days.
11.3. When you delete your account your data is deleted, except records we are legally required to retain.
11.4. Records relating to purchases may be kept for the period required by tax and accounting law.
12. When You Delete Your Account
12.1. You can delete your account from within the app, or by writing to appfalmira@gmail.com.
12.2. Deletion removes your photographs first, then your account and every record attached to it: profile, readings, chats, token records and notification records.
12.3. Your encryption key is destroyed as well, which is why deletion cannot be undone.
12.4. Deleting your account does not cancel a subscription you started through an app store. To stop being billed you must also cancel it in your Apple App Store or Google Play account.
13. Your Rights
13.1. Under the GDPR you have the right to:
(a) ask whether we process your personal data and obtain a copy of it (Article 15),
(b) have inaccurate or incomplete data corrected (Article 16),
(c) have your data erased (Article 17),
(d) ask us to restrict processing (Article 18),
(e) receive the data you gave us in a structured, commonly used, machine-readable format and have it transmitted to another controller where technically feasible (Article 20),
(f) object to processing based on our legitimate interests (Article 21),
(g) withdraw consent where processing is based on consent, without affecting processing already carried out (Article 7(3)),
(h) not be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you (Article 22).
13.2. To exercise any of these rights, write to appfalmira@gmail.com. We will respond within one month, and will tell you if we need to extend that period as Article 12(3) allows.
13.3. You can update your profile data yourself inside the app at any time; you do not need to make a request for that.
13.4. Exercising these rights is free of charge unless a request is manifestly unfounded or excessive.
13.5. You also have the right to lodge a complaint with a supervisory authority, in particular in the country where you live, where you work, or where the alleged infringement took place. In the United Kingdom this is the Information Commissioner's Office.
14. Children
14.1. Falmira is for people aged 18 and over; an age check is applied when you create an account.
14.2. In the birth chart section a chart can be produced for another person, and no age limit is applied there. If you enter a child's birth details, you confirm that you do so as their parent or guardian.
14.3. If we learn that an account belongs to someone under 18, we close it and delete the data.
15. Changes to This Policy
15.1. We may update this policy when the law or the way the app works changes.
15.2. If we make a substantial change we will tell you inside the app.
15.3. The current text is always published inside the app and at falmira.app.
