FinCamp

Privacy Policy

Effective date: 28 July 2026 · Last updated: 28 August 2026

This Privacy Policy explains how FABERA YAZILIM HİZMETLERİ ANONİM ŞİRKETİ (“Fabera”, “we”, “us”, or “our”) collects, uses, discloses, retains, and protects personal data when you use the FinCamp mobile application, websites, subscriptions, virtual portfolio, AI Research features, and related services (collectively, the “Service”).

Fabera is the data controller for the processing described in this Policy. Our registered address is UTKU MAH, ÇİMENTEPE_1 CAD, NO:49/18, 45000 ŞEHZADELER/MANİSA, Türkiye. You may contact us at support@fabera.ai.

FinCamp does not require a brokerage account and does not receive your brokerage password, bank credentials, or real investment portfolio. The current AI Research feature uses pre-generated company reports. You do not submit a personal prompt or personal financial profile to the AI model through this feature. AI Research may be inaccurate and is not financial or investment advice; see our Terms of Use for the complete risk disclosures.

1. Scope and your choices

This Policy applies to information processed through the Service and support communications. It does not control independent processing by Apple or other third parties under their own policies. This Policy is a privacy notice, not a contract or a request for consent. Where consent is legally required, we request it separately, and refusing that consent does not amount to rejecting this notice.

Some processing is necessary to provide subscriptions, restore purchases, secure the Service, and remember your progress. Other processing, such as access to the advertising identifier or cross-company tracking, is subject to your choices and applicable consent requirements.

2. Categories of data we process

2.1 Pseudonymous service identifiers

FinCamp does not create a single account identifier before you sign in to a future account feature. RevenueCat, PostHog, and AppsFlyer instead generate and maintain their own pseudonymous identifiers for subscription access, product analytics, and attribution. These identifiers do not directly contain your name or email address, but they distinguish an app installation or provider record and may be linked through limited secondary fields where needed to measure subscription outcomes. We therefore treat them as personal data. On an installation upgraded from an earlier pre-launch build, RevenueCat or PostHog may continue using an identifier value already stored in that provider's local SDK cache, including a value originally generated by FinCamp.

2.2 Subscription and transaction information

When you view or purchase a subscription, we and our providers may process the product identifier, offering, price and currency, subscription status, trial or introductory-offer status, purchase and renewal dates, store, transaction and receipt identifiers, cancellation, expiration, refund, tax, commission, and related entitlement information. Apple processes your payment. We do not receive or store your full payment-card number or Apple Account password.

2.3 Device, network, and technical information

We and our providers may process IP address, device and operating-system type or version, app version, language, locale, time zone, country or approximate location inferred from IP, request timestamps, network and server logs, crash or diagnostic information, Apple’s Identifier for Vendor (IDFV), an attribution-provider identifier, and similar technical identifiers.

Apple’s App Tracking Transparency (“ATT”) permission controls access to the Identifier for Advertisers (“IDFA”). ATT does not by itself authorise all processing described in this Policy. If you deny ATT permission, we do not access the IDFA. We may still process limited IDFA-less information, such as pseudonymous service identifiers, IDFV, IP address, install, session, fraud-prevention, and attribution information, where we have another valid legal basis. This can include aggregated advertising measurement as described in Sections 4 and 6. If a jurisdiction or use case requires separate consent, we request it before the covered processing.

2.4 Usage, learning, and interaction data

The current iOS release sends AppsFlyer limited attribution milestones such as completion of the onboarding funnel, a paywall view, subscription acceptance, and repeatable lesson completion, together with install, session, device, and campaign information processed by its SDK. It also sends PostHog product-usage events used to understand onboarding, feature use, learning progress, quiz selections, paywall interaction, and app reliability. These are pseudonymous product analytics used to operate, understand, and improve FinCamp; they are not directly associated with your name, email address, or phone number. They continue regardless of your ATT choice because ATT controls advertising tracking, not ordinary product analytics. PostHog may receive pseudonymous service identifiers and limited device, app, and usage context. We do not provide PostHog with IDFA, advertising campaign fields, email addresses, or phone numbers.

Your detailed learning and simulation state is stored locally on your device, including lesson progress, quiz answers, onboarding preferences, virtual trades and positions, fictional rewards, activity days, bookmarks, AI Research view timestamps, and app settings. Local data can be lost if the app or its data is deleted, the device fails, or storage is corrupted. Unless technically excluded, local app data may also be included in Apple device backups under Apple’s rules and your backup settings.

2.5 AI Research and market requests

When you request a company, chart, market screen, content pack, narration file, or AI Research report, the Service may send the requested ticker or symbol, data range, app language, manifest, lesson-related content or audio path, and ordinary HTTP request metadata such as IP address, user agent, and timestamp to our cloud infrastructure. These requests do not transmit your full lesson progress. The current AI Research workflow does not send your virtual portfolio, quiz answers, pseudonymous service identifiers, personal financial circumstances, or a free-text prompt to the AI model.

2.6 Support and communications

If you contact us, we process the information you provide, such as your email address, message, attachments, support history, device or subscription details, and any other information you choose to include. Our email infrastructure provider, currently Google Workspace, may process these communications. Please do not send passwords, payment-card numbers, brokerage credentials, or other unnecessary sensitive data.

2.7 Data we do not currently request

FinCamp does not currently require your legal name, postal address, phone number, brokerage login, bank credentials, government identifier, precise GPS location, contacts, photos, camera, microphone, or health information to provide its core iOS Service. If a future feature changes this, we will update this Policy and request any permission required before collection.

We do not intentionally request special-category or sensitive personal data through FinCamp. Please do not include such data in support messages.

3. Why we process data and our legal bases

Depending on applicable law, we process data for the following purposes and legal bases:

We collect data automatically through the app, device, SDKs, and server requests; from Apple and service providers; and directly from you when you contact us. We do not treat this notice or ATT permission as blanket consent. The legal basis described above applies to the specific purpose and data involved; consent for one purpose does not authorise an unrelated purpose.

4. When and with whom we share data

We do not sell personal data for money. We disclose only information reasonably necessary for the purposes described above, subject to contracts and safeguards where required.

4.1 Service providers and platforms

Provider roles depend on the activity. Contracted processors or service providers generally process personal data for the services they provide to Fabera, subject to applicable contracts and legal obligations. Apple and any other provider that independently determines the purposes and means of a particular processing activity may act as a separate controller for that activity. Their independent services and websites are governed by their own privacy notices.

4.2 Legal, safety, and business transfers

We may disclose information if reasonably necessary to comply with law, court orders, lawful government requests, or regulatory obligations; protect rights, property, safety, or security; investigate fraud or misuse; enforce agreements; or establish, exercise, or defend legal claims.

If Fabera is involved in a merger, acquisition, financing, restructuring, insolvency, or transfer of all or part of its business or assets, information may be disclosed to advisers and transaction parties and transferred as part of that transaction, subject to applicable law.

5. AI Research data flow

AI Research reports are generated on our server infrastructure from company identifiers, third-party market data, derived market statistics, report instructions, and search results. Reports may then be translated automatically. The app retrieves an already-generated report for the ticker and language you request.

This architecture is designed to avoid sending an individual user’s identity or personal financial profile to the AI model. However, our cloud infrastructure necessarily receives ordinary network information when your device requests a report. AI providers may retain or process report inputs and outputs according to the applicable provider arrangements and policies. No processing system can be guaranteed risk-free.

FinCamp does not use AI Research or attribution data to make decisions about you that produce legal or similarly significant effects. AI Research consists of pre-generated educational content and does not make a personalised investment decision for you.

6. Tracking, attribution, and your choices

FinCamp uses attribution technology to measure advertising effectiveness and subscription outcomes. Apple may classify some identifier use as “tracking” when data is linked across apps or websites owned by different companies for advertising measurement.

Where Apple requires permission, FinCamp presents the ATT prompt before accessing the IDFA. You can deny permission or later change it in iOS Settings under Privacy & Security → Tracking. Denying permission does not block core educational features. It prevents FinCamp from accessing IDFA for advertising tracking, but does not stop PostHog product analytics and does not necessarily stop limited install, session, subscription, security, fraud-prevention, or IDFA-less attribution processing carried out under another valid legal basis.

Through the AppsFlyer integration, qualifying conversion events may be made available to Meta for aggregated advertising measurement even when IDFA is unavailable. Such data may include IP address, IDFV, pseudonymous advertising or attribution identifiers, user agent, installs, app opens, and selected in-app or subscription events. FinCamp does not receive an identified Meta user profile from this process and does not provide email addresses or phone numbers for advertising matching.

Although we do not sell data for money, certain advertising-attribution disclosures could be considered “sharing,” “targeted advertising,” or a “sale” under some US state privacy laws. Where such a law applies, you may request the legally available opt-out by contacting us. The current iOS app does not use browser-based Global Privacy Control signals. We will provide any additional privacy choice required for a jurisdiction before using data there in the covered manner.

7. International data transfers

Fabera is established in Türkiye. Our providers may process information in Türkiye, the United States, the European Economic Area, and other countries where they or their subprocessors operate. These countries may have privacy laws different from those where you live.

Where required, we use a lawful cross-border transfer mechanism appropriate to the provider and jurisdiction. This may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures, the UK Addendum or IDTA, or an appropriate safeguard under KVKK Article 9. We also use data minimisation, access controls, and contractual restrictions. This notice is not consent to an international transfer.

8. Data retention

We retain personal data only for as long as necessary for the stated purpose and any applicable legal, tax, accounting, security, dispute, or recordkeeping period. We determine retention by the data category, purpose, sensitivity, legal requirements, and the time reasonably required to investigate or defend a claim.

We may retain aggregated or irreversibly de-identified information that can no longer reasonably identify you. A deletion request may not require deletion of information that we must retain by law or need to establish, exercise, or defend legal claims.

9. Security

We use reasonable technical and organisational safeguards designed to protect information, including access controls, data minimisation, secure transport, restricted production access, provider controls, separation of secrets from the app, and separation between subscription, product-analytics, and attribution identifiers.

No method of transmission, storage, software, cloud service, or third-party system is completely secure. We cannot guarantee absolute security, availability, or protection against every incident. You are responsible for securing your device, Apple Account, network, and operating system.

10. Your privacy rights

Your rights depend on where you live and may be subject to legal conditions and exceptions. We may need to verify your request before acting.

10.1 Türkiye and KVKK

Under Article 11 of Türkiye’s Law No. 6698 on the Protection of Personal Data (“KVKK”), you may have the right to learn whether your personal data is processed, request information about processing, learn the purpose and whether data is used accordingly, learn the recipients in Türkiye or abroad, request correction, request deletion or destruction where conditions are met, request notice of correction or deletion to recipients, object to an adverse result arising solely from automated analysis, and claim compensation where you suffer damage because of unlawful processing.

10.2 EEA, United Kingdom, and Switzerland

Where the GDPR, UK GDPR, or equivalent law applies, you may have rights of access, rectification, erasure, restriction, objection, and data portability; the right to withdraw consent without affecting earlier lawful processing; and the right not to be subject to certain solely automated decisions with legal or similarly significant effects. You may complain to the competent data protection authority where you live, work, or believe an infringement occurred.

We generally respond to valid GDPR or UK GDPR requests within one month. Where the law permits an extension because a request is complex or numerous, we may extend that period by up to two further months and will explain the extension within the initial period. You may also request information about an applicable international-transfer safeguard. An authorised representative may submit a request where applicable law permits it, subject to verification of the authority and request.

10.3 United States and other jurisdictions

Depending on your state or country, you may have rights to know, access, correct, delete, or obtain a portable copy of personal data; opt out of sale, sharing, targeted advertising, or certain profiling; and appeal a denied request. We will not discriminate against you for exercising a legal privacy right.

10.4 How to exercise a right

General privacy questions may be sent to support@fabera.ai. A formal KVKK application may be submitted by signed written application to our registered address or by another method permitted under the applicable Data Controller Application Procedures and Principles Communiqué. Describe the right, relevant device or purchase, and enough information to locate the record without sending passwords or payment-card details. Because the current app does not display its pseudonymous provider identifiers, we will work with you on proportionate verification but may be unable to link an email address to a pseudonymous record without additional evidence.

We respond to a valid KVKK application as soon as possible and no later than 30 days. Applications are generally handled free of charge, subject to any tariff or fee permitted by law. Other requests are answered within the period required by the applicable law. Where legally required and technically applicable, we will act on records under our control and instruct the relevant processor to delete, correct, restrict, or provide the covered record. A remote request cannot itself erase data stored only in your device or cancel an Apple subscription.

11. Children

FinCamp is not intended for anyone under 16 years old, and we do not knowingly collect personal data from anyone under 16. Users aged 16 or 17 may use FinCamp only with the permission of a parent or legal guardian.

If you believe a person under 16 has provided personal data through FinCamp, contact us so we can investigate and take appropriate action, including deletion where appropriate.

12. Changes to this Policy

We may update this Policy to reflect changes in the Service, providers, law, or processing practices. The “Last updated” date identifies the current version. Where required, we will provide notice of material changes through the Service or another reasonable channel. We will request new consent if applicable law requires it.

FinCamp reminders are currently scheduled locally on your device. Fabera does not currently collect a remote push-notification token for these reminders. Third-party links are governed by the destination’s own terms and privacy notice. Before the FinCamp website adds non-essential cookies or analytics, this Policy and any required consent controls must be updated.

13. Contact

Questions, complaints, and privacy requests may be sent to:

FABERA YAZILIM HİZMETLERİ ANONİM ŞİRKETİ
Data Controller
UTKU MAH, ÇİMENTEPE_1 CAD, NO:49/18
45000 ŞEHZADELER/MANİSA, Türkiye
support@fabera.ai