Privacy Policy
Adventure Istanbul
Effective date: 16 July 2026
Document version: aligns with in-app CURRENT_LEGAL_VERSION (currently 3)
1. Who we are
Adventure Istanbul is published under the Rasegame indie publishing brand by Mehmet Rauf Oğuz and Selin Özdem, acting jointly as individuals (no company).
The joint data controllers for personal data processed by Adventure Istanbul are:
- Mehmet Rauf Oğuz (individual)
- Selin Özdem (individual)
Email: [email protected]
Website: https://rasegame.com/games/adventure-istanbul
The app may be offered in all App Store territories. Turkish law (KVKK, Law No. 6698) applies because the controllers are in Turkey. Where the GDPR or UK GDPR applies to you (for example if you are in the EEA/UK), those rights are described below as well. Other regions may grant additional rights (for example California); contact us to exercise them.
2. How we use your data (design intent)
We use account and game data to run the game: sign-in, sync idle progress, restore your save, keep sessions secure, and record that you accepted these terms.
- We do not sell your personal data.
- We do not use your name or email ourselves for third-party advertising profiles.
- Optional features (ads, push notifications, subscriptions, certain emails) may involve third-party processors when those features are enabled in a given build. Those processors are listed in Section 5.
Apple's App Privacy labels and this policy disclose collection by us and by SDKs in the app, even when our first-party purpose is only gameplay.
3. Data we collect
3.1 Account and profile
| Data | When |
|---|---|
| User ID | Always (guest or registered) |
| Email, password (hashed) | When you register or convert from guest |
| Display name | When set / on sign-up |
| Anonymous / guest flag | Guest play |
| Legal acceptance version | When you accept this policy |
3.2 Gameplay
Progress needed to run Adventure Istanbul, including balance, products, managers, cooldowns, offline claims, levels, XP, and tasks. Stored on our servers and linked to your user ID so you can continue on the same account.
3.3 Session and security
Session records may include IP address and user agent for authentication, security, and abuse prevention.
3.4 Notification preferences
Settings such as email and push opt-in/out, so we can honor your choices when those channels are enabled.
3.5 Communications (when enabled)
If the build enables them: one-time passwords, magic-link emails, and/or offline-earnings reminder emails via email providers (for example Resend and/or Amazon SES).
4. Soft launch vs full features
Some builds (for example early TestFlight) disable ads, in-app purchases, push, and certain emails using environment flags. In those builds we still collect account and gameplay data needed for the game, but we do not load AdMob, OneSignal, or RevenueCat unless the corresponding feature is on.
When a later build enables those features, collection described in Section 5 applies.
5. Third-party services
Depending on the build:
| Service | Role | Typical data |
|---|---|---|
| Google AdMob | Ads (banner, interstitial, rewarded) | Advertising identifiers / device data; may involve tracking under Apple's definition. We request App Tracking Transparency permission on iOS where required. For EEA/UK users, ad-personalization consent is managed via Google's User Messaging Platform (UMP) |
| RevenueCat / Apple IAP | Remove-ads subscription | Purchase / entitlement data linked to your user ID |
| OneSignal | Push notifications | Device push token; we may tag level for messaging |
| Resend / Amazon SES | Transactional email | Email address and message content |
| Hosting / database providers | Run API and storage | Account and game data as processed under our instructions |
We do not operate a separate consumer analytics SDK (for example Crashlytics) in the current app; if that changes, this policy and App Privacy labels will be updated.
6. Legal bases (KVKK / GDPR)
Where required, we process data based on:
- Contract / service delivery: providing the game and account
- Legitimate interests: security, anti-cheat, improving stability (balanced against your rights)
- Consent: where required (for example ATT for tracking; marketing messages if we send them)
- Legal obligation: when the law requires retention or disclosure
7. International transfers
Servers and processors may be located outside Turkey and/or outside your country (including the EEA). Where required, we use appropriate safeguards (for example contractual clauses with processors). Contact us for more detail about your situation.
8. Retention
We keep account and game data while your account exists and as needed to provide the service. Session and security logs are kept for a limited period. After account deletion we remove personal data we are not legally required to retain (for example limited financial records if subscriptions were used).
9. Security
We use industry-standard measures appropriate for an indie game backend (HTTPS, hashed passwords via our auth stack, access controls). No method of transmission or storage is 100% secure.
10. Your rights
KVKK (Turkey)
You may have rights to learn whether your data is processed, request information, correction, deletion/destruction, objection, and other rights under KVKK. Contact [email protected].
GDPR / UK GDPR (where applicable)
You may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. Contact us at the email above.
Apple App Store / in-app deletion
You can permanently delete your guest or registered account in the app: Profile → Delete Account (registered accounts confirm with password). This uses better-auth's native delete APIs and removes your account and associated game progress from our systems. You may also contact [email protected] for help.
11. Children
Adventure Istanbul is not directed at children under 13 (or the higher digital-consent age in your country, such as 16 in parts of the EU). We do not offer the app in Apple's Kids Category. If you believe a child provided data, contact us to delete it.
12. Do Not Track / ATT
On iOS, if a build uses personalized advertising, we use the App Tracking Transparency prompt before tracking as defined by Apple. You can also reset advertising identifiers in system Settings.
13. Changes
We may update this policy. Material changes will be reflected here and, when appropriate, by requiring re-acceptance in the app (CURRENT_LEGAL_VERSION). Continued use after notice means you accept the updated policy, except where the law requires otherwise.
14. Contact
Mehmet Rauf Oğuz and Selin Özdem (joint data controllers)
[email protected]
https://rasegame.com/games/adventure-istanbul
Related: Terms of Service · Support