Yasal
Privacy Policy
Effective date: August 25, 2026
This Privacy Policy applies to the Daily News: Highlight Bar macOS application and related services operated by Habip Ertuğrul Dağdemir (the “Service Provider”).
1. Data controller and contact
Habip Ertuğrul Dağdemir is the data controller for personal data processed through the App.
- Name: Habip Ertuğrul Dağdemir
- Email: habipertugruldagdemir@gmail.com
2. Information we process
The App does not require a named account and does not collect your name, email address, age, gender, contacts, precise location or advertising identifier. It does process the following information:
- Pseudonymous Firebase user ID: a random UID created for authentication, access control and synchronising your data. It is not your name or email address, but it is linked to the data stored for your App account.
- Installation and device integrity data: a random installation secret kept in the macOS Keychain and its one-way server-side HMAC digest; Firebase App Check and Apple DeviceCheck signals used for trial eligibility and abuse prevention. Raw DeviceCheck tokens are not stored.
- Preferences and saved articles: selected source/output languages, categories, and bookmarked article headlines and links.
- Subscription and purchase information: product identifier, purchase and expiry details, subscription status and receipt-validation data. Apple processes payment; RevenueCat synchronises entitlement status.
- Analytics and crash data: Firebase Analytics receives limited launch/interaction events and associated technical or app-instance information, and Firebase Crashlytics receives crash reports and diagnostic breadcrumbs. These are used for reliability and product operation, not advertising or cross-app tracking.
- AI processing: article text and metadata may be sent to our configured AI provider (currently OpenRouter and/or Vercel AI Gateway) to generate summaries. We do not intentionally send your name or email in these requests.
- Security and rate limiting: the backend may temporarily read an IP address to enforce abuse-prevention limits. The App’s own database and application logs do not store IP addresses; infrastructure or proxy providers may maintain their own technical logs.
3. How we use information and legal bases
- Provide news, summaries, preferences, saved articles and account deletion (contract performance).
- Validate purchases and manage subscriptions (contract performance and legal obligations).
- Secure the service, prevent fraud and enforce trial limits (legitimate interests).
- Measure reliability and diagnose crashes through Firebase Analytics and Crashlytics (legitimate interests; where consent is legally required, consent).
- Generate summaries using AI providers (contract performance).
We do not sell personal information, use it for advertising, send marketing communications, or track you across other apps and websites. Where we rely on consent, you give it by opting in to the relevant feature and may withdraw it at any time.
4. Cookies and similar technologies
The macOS App does not use advertising cookies or cross-site tracking pixels. Our website may use essential browser storage for its theme preference. Firebase, RevenueCat and AI providers may use their own technical identifiers as described in their policies.
5. Service providers and disclosures
- Apple Inc. — payment processing, receipts, subscriptions and DeviceCheck. See Apple’s privacy policy.
- Google LLC (Firebase) — anonymous authentication, App Check, Analytics and Crashlytics. See Firebase’s privacy information, including Crashlytics information.
- RevenueCat, Inc. — subscription validation and entitlement synchronisation. See RevenueCat’s privacy policy.
- OpenRouter and/or Vercel AI Gateway — AI model gateway used to generate summaries. Their current privacy terms are available at OpenRouter and Vercel.
- GDELT Project and news publishers — public article metadata and links.
We may disclose data to service providers acting on our instructions, when required by law, or when necessary to protect users, security or our rights. Where required by GDPR Article 28, we use appropriate data-processing agreements.
6. International transfers
Our providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, approved Standard Contractual Clauses, or another lawful GDPR Chapter V safeguard.
7. Retention and deletion
Account, preference, saved-article and subscription records are retained while needed to operate the service. Summary archives follow the configured retention period (currently 30 days by default). Application technical logs are retained for up to 30 days; billing webhook audit records may be retained up to 180 days. AI providers may retain request data according to their own terms.
You can use Settings → Privacy → Delete account and all data to delete your profile, preferences, summaries, saved articles and anonymous Firebase account. Billing audit records are pseudonymised where necessary for transaction integrity. You may also email habipertugruldagdemir@gmail.com. Apple DeviceCheck bits are not reset by account deletion, and subscriptions must be cancelled through Apple.
8. Your choices and GDPR rights
You may uninstall the App, restore purchases, and manage or cancel subscriptions through your Apple account. Where the GDPR applies, you may:
- request access to the personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request erasure (“right to be forgotten”), subject to lawful exceptions;
- request restriction of processing;
- request a copy in a structured, commonly used and machine-readable format (data portability);
- object to processing based on legitimate interests, and object at any time to direct marketing (we do not send direct marketing);
- withdraw consent where processing is based on consent; and
- request information about, or human review of, a decision covered by GDPR Article 22.
We respond within one month where GDPR timelines apply; this may be extended by up to two further months for complex or numerous requests. To exercise a right, email habipertugruldagdemir@gmail.com. You may also complain to your local data-protection authority; European authority contacts are listed by the European Data Protection Board.
9. AI and automated decision-making
AI is used to summarise news and personalise the feed according to your selected preferences. The App does not use automated decision-making that produces legal or similarly significant effects about you. If that changes, we will provide the information and safeguards required by law.
10. California privacy rights
If you are a California resident, applicable law may give you the right to know the categories and specific pieces of personal information collected, request deletion or correction, opt out of sale or sharing for cross-context behavioural advertising, limit certain sensitive-data uses, and receive equal service. We do not sell personal information or share it for cross-context behavioural advertising. To exercise applicable rights, contact habipertugruldagdemir@gmail.com. We may verify requests using information you provide, and you may use an authorised agent where permitted by law.
11. Children
The App is not directed to children under 16. We do not knowingly collect children’s personal data in violation of applicable law. Contact us if you believe a child has provided personal data.
12. Security and breaches
We use access controls, HTTPS, limited data collection and other reasonable technical and organisational safeguards. No system is completely secure. Where GDPR requires it, we notify the supervisory authority within 72 hours of becoming aware of a reportable breach and notify affected individuals without undue delay when the risk is high.
13. Changes
We may update this Policy. Material changes will be posted with a new effective date.
14. Contact
Privacy questions, rights requests and deletion requests: habipertugruldagdemir@gmail.com.