Privacy Policy
This Privacy Policy explains how FABERA YAZILIM HİZMETLERİ ANONİM ŞİRKETİ (“Fabera”, “we”, “us”, or “our”) collects, uses, discloses, retains, and protects personal data when you use the FinCamp mobile application, websites, subscriptions, virtual portfolio, AI Research features, and related services (collectively, the “Service”).
Fabera is the data controller for the processing described in this Policy. Our registered address is UTKU MAH, ÇİMENTEPE_1 CAD, NO:49/18, 45000 ŞEHZADELER/MANİSA, Türkiye. You may contact us at support@fabera.ai.
1. Scope and your choices
This Policy applies to information processed through the Service and support communications. It does not control independent processing by Apple or other third parties under their own policies. This Policy is a privacy notice, not a contract or a request for consent. Where consent is legally required, we request it separately, and refusing that consent does not amount to rejecting this notice.
Some processing is necessary to provide subscriptions, restore purchases, secure the Service, and remember your progress. Other processing, such as access to the advertising identifier or cross-company tracking, is subject to your choices and applicable consent requirements.
2. Categories of data we process
2.1 Pseudonymous service identifiers
FinCamp does not create a single account identifier before you sign in to a future account feature. RevenueCat, PostHog, and AppsFlyer instead generate and maintain their own pseudonymous identifiers for subscription access, product analytics, and attribution. These identifiers do not directly contain your name or email address, but they distinguish an app installation or provider record and may be linked through limited secondary fields where needed to measure subscription outcomes. We therefore treat them as personal data. On an installation upgraded from an earlier pre-launch build, RevenueCat or PostHog may continue using an identifier value already stored in that provider's local SDK cache, including a value originally generated by FinCamp.
2.2 Subscription and transaction information
When you view or purchase a subscription, we and our providers may process the product identifier, offering, price and currency, subscription status, trial or introductory-offer status, purchase and renewal dates, store, transaction and receipt identifiers, cancellation, expiration, refund, tax, commission, and related entitlement information. Apple processes your payment. We do not receive or store your full payment-card number or Apple Account password.
2.3 Device, network, and technical information
We and our providers may process IP address, device and operating-system type or version, app version, language, locale, time zone, country or approximate location inferred from IP, request timestamps, network and server logs, crash or diagnostic information, Apple’s Identifier for Vendor (IDFV), an attribution-provider identifier, and similar technical identifiers.
Apple’s App Tracking Transparency (“ATT”) permission controls access to the Identifier for Advertisers (“IDFA”). ATT does not by itself authorise all processing described in this Policy. If you deny ATT permission, we do not access the IDFA. We may still process limited IDFA-less information, such as pseudonymous service identifiers, IDFV, IP address, install, session, fraud-prevention, and attribution information, where we have another valid legal basis. This can include aggregated advertising measurement as described in Sections 4 and 6. If a jurisdiction or use case requires separate consent, we request it before the covered processing.
2.4 Usage, learning, and interaction data
The current iOS release sends AppsFlyer limited attribution milestones such as completion of the onboarding funnel, a paywall view, subscription acceptance, and repeatable lesson completion, together with install, session, device, and campaign information processed by its SDK. It also sends PostHog product-usage events used to understand onboarding, feature use, learning progress, quiz selections, paywall interaction, and app reliability. These are pseudonymous product analytics used to operate, understand, and improve FinCamp; they are not directly associated with your name, email address, or phone number. They continue regardless of your ATT choice because ATT controls advertising tracking, not ordinary product analytics. PostHog may receive pseudonymous service identifiers and limited device, app, and usage context. We do not provide PostHog with IDFA, advertising campaign fields, email addresses, or phone numbers.
Your detailed learning and simulation state is stored locally on your device, including lesson progress, quiz answers, onboarding preferences, virtual trades and positions, fictional rewards, activity days, bookmarks, AI Research view timestamps, and app settings. Local data can be lost if the app or its data is deleted, the device fails, or storage is corrupted. Unless technically excluded, local app data may also be included in Apple device backups under Apple’s rules and your backup settings.
2.5 AI Research and market requests
When you request a company, chart, market screen, content pack, narration file, or AI Research report, the Service may send the requested ticker or symbol, data range, app language, manifest, lesson-related content or audio path, and ordinary HTTP request metadata such as IP address, user agent, and timestamp to our cloud infrastructure. These requests do not transmit your full lesson progress. The current AI Research workflow does not send your virtual portfolio, quiz answers, pseudonymous service identifiers, personal financial circumstances, or a free-text prompt to the AI model.
2.6 Support and communications
If you contact us, we process the information you provide, such as your email address, message, attachments, support history, device or subscription details, and any other information you choose to include. Our email infrastructure provider, currently Google Workspace, may process these communications. Please do not send passwords, payment-card numbers, brokerage credentials, or other unnecessary sensitive data.
2.7 Data we do not currently request
FinCamp does not currently require your legal name, postal address, phone number, brokerage login, bank credentials, government identifier, precise GPS location, contacts, photos, camera, microphone, or health information to provide its core iOS Service. If a future feature changes this, we will update this Policy and request any permission required before collection.
We do not intentionally request special-category or sensitive personal data through FinCamp. Please do not include such data in support messages.
3. Why we process data and our legal bases
Depending on applicable law, we process data for the following purposes and legal bases:
- Provide and perform the Service: maintain pseudonymous service identifiers, deliver lessons and market content, remember local progress, provide virtual trading, unlock subscription features, restore purchases, and respond to support requests. The basis is performance of our contract with you or steps taken at your request, including KVKK Article 5(2)(c) where applicable.
- Subscriptions and records: process entitlements, trials, renewals, refunds, and transaction records. The basis is contract performance and compliance with legal, tax, accounting, and consumer-protection obligations, including KVKK Articles 5(2)(c) and 5(2)(ç) where applicable.
- Security, fraud prevention, and enforcement: authenticate entitlement state, detect misuse, investigate incidents, protect users and systems, enforce our Terms, and establish, exercise, or defend legal claims. The basis is legal obligations, the establishment, exercise, or protection of a right, and our legitimate interests where they do not override your fundamental rights, including KVKK Articles 5(2)(ç), 5(2)(e), and 5(2)(f) where applicable.
- Service operation and improvement: understand feature use, diagnose failures, measure onboarding and paywall performance, test improvements, and maintain the Service. The basis is our legitimate interest in operating and improving FinCamp where it does not override your fundamental rights, including KVKK Article 5(2)(f) where applicable.
- Attribution and campaign measurement: understand which advertising campaign led to an install or subscription, prevent attribution fraud, and measure effectiveness. For strictly limited, IDFA-less measurement, the basis is our legitimate interest where that interest does not override your rights. IDFA access occurs only with ATT permission. Where we rely on consent for a particular advertising or measurement activity, that consent may be obtained through Apple and/or within the Service.
- Legal compliance and corporate transactions: respond to lawful requests, comply with regulation, and manage a merger, financing, restructuring, acquisition, or asset transfer. The basis is legal obligation, protection of legal rights, or legitimate interests, including KVKK Articles 5(2)(ç), 5(2)(e), and 5(2)(f) where applicable.
We collect data automatically through the app, device, SDKs, and server requests; from Apple and service providers; and directly from you when you contact us. We do not treat this notice or ATT permission as blanket consent. The legal basis described above applies to the specific purpose and data involved; consent for one purpose does not authorise an unrelated purpose.
4. When and with whom we share data
We do not sell personal data for money. We disclose only information reasonably necessary for the purposes described above, subject to contracts and safeguards where required.
4.1 Service providers and platforms
- Apple: App Store distribution, subscriptions and payments, receipt and entitlement information, refund handling, device services, App Tracking Transparency, and operating-system functionality.
- RevenueCat: subscription offerings, purchase processing support, entitlement status, trial and renewal lifecycle, and subscription analytics. RevenueCat generates its own pseudonymous App User ID and may receive device and attribution identifiers and campaign fields such as media source, campaign, ad group, ad, keyword, or creative as permitted. When the RevenueCat–AppsFlyer integration is enabled, RevenueCat may send subscription-lifecycle and revenue events to AppsFlyer for attribution and campaign measurement.
- PostHog: pseudonymous product analytics, feature flags, crash diagnostics, and related service improvement. PostHog may process pseudonymous service identifiers, device and app information, and permitted product-usage and diagnostic events.
- AppsFlyer: install attribution, limited conversion events, campaign measurement, and related analytics. AppsFlyer may process its own identifier, device identifiers, IP address, approximate location inferred from IP, user agent, campaign information, and permitted event data. If ATT permission is granted, this may include IDFA.
- Meta Platforms: advertising delivery, attribution, aggregated event measurement, campaign reporting, and optimisation. Meta receives qualifying information through FinCamp’s AppsFlyer integration. Depending on ATT status and the applicable measurement method, this may include installs, app opens, selected in-app and subscription events, event values, IP address, IDFV, pseudonymous advertising or attribution identifiers, user agent, and IDFA when available. FinCamp does not provide Meta with email addresses or phone numbers for advertising matching.
- Cloudflare: API delivery, cloud hosting, storage, security, server logs, cached market content, pre-generated AI reports, and a subscription-event audit ledger. The current ledger may include event and transaction identifiers, timestamps, product, trial, renewal, price, currency, commission, tax, a pseudonymous RevenueCat customer ID, and a provider-generated event payload after RevenueCat subscriber attributes are removed.
- AI, model-routing, inference, and search providers: OpenRouter and the model, inference-hosting, or search providers selected through it, currently including the DeepSeek model and Exa search, process company symbols, market inputs, report instructions, and report text to generate or translate AI Research. OpenRouter may dynamically select an infrastructure provider. Under the current workflow, we do not intentionally send them your pseudonymous service identifiers, virtual portfolio, quiz answers, contact information, or personal financial profile.
- Market-data and content providers: providers such as Twelve Data supply market and company information to our server infrastructure. We generally obtain this data server-side without providing those providers with your FinCamp identity.
- Communications providers: Google Workspace processes support email and related metadata when you contact an address hosted for Fabera.
Provider roles depend on the activity. Contracted processors or service providers generally process personal data for the services they provide to Fabera, subject to applicable contracts and legal obligations. Apple and any other provider that independently determines the purposes and means of a particular processing activity may act as a separate controller for that activity. Their independent services and websites are governed by their own privacy notices.
4.2 Legal, safety, and business transfers
We may disclose information if reasonably necessary to comply with law, court orders, lawful government requests, or regulatory obligations; protect rights, property, safety, or security; investigate fraud or misuse; enforce agreements; or establish, exercise, or defend legal claims.
If Fabera is involved in a merger, acquisition, financing, restructuring, insolvency, or transfer of all or part of its business or assets, information may be disclosed to advisers and transaction parties and transferred as part of that transaction, subject to applicable law.
5. AI Research data flow
AI Research reports are generated on our server infrastructure from company identifiers, third-party market data, derived market statistics, report instructions, and search results. Reports may then be translated automatically. The app retrieves an already-generated report for the ticker and language you request.
This architecture is designed to avoid sending an individual user’s identity or personal financial profile to the AI model. However, our cloud infrastructure necessarily receives ordinary network information when your device requests a report. AI providers may retain or process report inputs and outputs according to the applicable provider arrangements and policies. No processing system can be guaranteed risk-free.
FinCamp does not use AI Research or attribution data to make decisions about you that produce legal or similarly significant effects. AI Research consists of pre-generated educational content and does not make a personalised investment decision for you.
6. Tracking, attribution, and your choices
FinCamp uses attribution technology to measure advertising effectiveness and subscription outcomes. Apple may classify some identifier use as “tracking” when data is linked across apps or websites owned by different companies for advertising measurement.
Where Apple requires permission, FinCamp presents the ATT prompt before accessing the IDFA. You can deny permission or later change it in iOS Settings under Privacy & Security → Tracking. Denying permission does not block core educational features. It prevents FinCamp from accessing IDFA for advertising tracking, but does not stop PostHog product analytics and does not necessarily stop limited install, session, subscription, security, fraud-prevention, or IDFA-less attribution processing carried out under another valid legal basis.
Through the AppsFlyer integration, qualifying conversion events may be made available to Meta for aggregated advertising measurement even when IDFA is unavailable. Such data may include IP address, IDFV, pseudonymous advertising or attribution identifiers, user agent, installs, app opens, and selected in-app or subscription events. FinCamp does not receive an identified Meta user profile from this process and does not provide email addresses or phone numbers for advertising matching.
Although we do not sell data for money, certain advertising-attribution disclosures could be considered “sharing,” “targeted advertising,” or a “sale” under some US state privacy laws. Where such a law applies, you may request the legally available opt-out by contacting us. The current iOS app does not use browser-based Global Privacy Control signals. We will provide any additional privacy choice required for a jurisdiction before using data there in the covered manner.
7. International data transfers
Fabera is established in Türkiye. Our providers may process information in Türkiye, the United States, the European Economic Area, and other countries where they or their subprocessors operate. These countries may have privacy laws different from those where you live.
Where required, we use a lawful cross-border transfer mechanism appropriate to the provider and jurisdiction. This may include an adequacy decision, the EU Standard Contractual Clauses and supplementary measures, the UK Addendum or IDTA, or an appropriate safeguard under KVKK Article 9. We also use data minimisation, access controls, and contractual restrictions. This notice is not consent to an international transfer.
8. Data retention
We retain personal data only for as long as necessary for the stated purpose and any applicable legal, tax, accounting, security, dispute, or recordkeeping period. We determine retention by the data category, purpose, sensitivity, legal requirements, and the time reasonably required to investigate or defend a claim.
- Detailed learning, virtual-portfolio, reward, bookmark, and research-view state stored locally remains until it is deleted through app or device operations.
- Pseudonymous provider identifiers and related records are retained according to the provider's storage behavior, our configuration, operational need, and applicable legal obligations. App deletion may reset some device-side identifiers but does not itself erase provider records.
- An earlier pre-launch build stored a FinCamp-generated pseudonymous identifier in Apple Keychain. Upgraded installations may retain that dormant item, which can survive app deletion or an encrypted Apple backup. The current app no longer reads or writes that Keychain item, and leaves it untouched to avoid a destructive migration. RevenueCat and PostHog may separately retain and continue processing a cached provider copy of the same historical value on an upgraded installation.
- Subscription and transaction records, including the current Cloudflare subscription-event ledger, may be retained for contractual, accounting, fraud-prevention, dispute, and legal limitation purposes.
- Attribution, analytics, security logs, and support correspondence are retained according to operational need, provider settings, legal obligations, and applicable limitation periods.
We may retain aggregated or irreversibly de-identified information that can no longer reasonably identify you. A deletion request may not require deletion of information that we must retain by law or need to establish, exercise, or defend legal claims.
9. Security
We use reasonable technical and organisational safeguards designed to protect information, including access controls, data minimisation, secure transport, restricted production access, provider controls, separation of secrets from the app, and separation between subscription, product-analytics, and attribution identifiers.
No method of transmission, storage, software, cloud service, or third-party system is completely secure. We cannot guarantee absolute security, availability, or protection against every incident. You are responsible for securing your device, Apple Account, network, and operating system.
10. Your privacy rights
Your rights depend on where you live and may be subject to legal conditions and exceptions. We may need to verify your request before acting.
10.1 Türkiye and KVKK
Under Article 11 of Türkiye’s Law No. 6698 on the Protection of Personal Data (“KVKK”), you may have the right to learn whether your personal data is processed, request information about processing, learn the purpose and whether data is used accordingly, learn the recipients in Türkiye or abroad, request correction, request deletion or destruction where conditions are met, request notice of correction or deletion to recipients, object to an adverse result arising solely from automated analysis, and claim compensation where you suffer damage because of unlawful processing.
10.2 EEA, United Kingdom, and Switzerland
Where the GDPR, UK GDPR, or equivalent law applies, you may have rights of access, rectification, erasure, restriction, objection, and data portability; the right to withdraw consent without affecting earlier lawful processing; and the right not to be subject to certain solely automated decisions with legal or similarly significant effects. You may complain to the competent data protection authority where you live, work, or believe an infringement occurred.
We generally respond to valid GDPR or UK GDPR requests within one month. Where the law permits an extension because a request is complex or numerous, we may extend that period by up to two further months and will explain the extension within the initial period. You may also request information about an applicable international-transfer safeguard. An authorised representative may submit a request where applicable law permits it, subject to verification of the authority and request.
10.3 United States and other jurisdictions
Depending on your state or country, you may have rights to know, access, correct, delete, or obtain a portable copy of personal data; opt out of sale, sharing, targeted advertising, or certain profiling; and appeal a denied request. We will not discriminate against you for exercising a legal privacy right.
10.4 How to exercise a right
General privacy questions may be sent to support@fabera.ai. A formal KVKK application may be submitted by signed written application to our registered address or by another method permitted under the applicable Data Controller Application Procedures and Principles Communiqué. Describe the right, relevant device or purchase, and enough information to locate the record without sending passwords or payment-card details. Because the current app does not display its pseudonymous provider identifiers, we will work with you on proportionate verification but may be unable to link an email address to a pseudonymous record without additional evidence.
We respond to a valid KVKK application as soon as possible and no later than 30 days. Applications are generally handled free of charge, subject to any tariff or fee permitted by law. Other requests are answered within the period required by the applicable law. Where legally required and technically applicable, we will act on records under our control and instruct the relevant processor to delete, correct, restrict, or provide the covered record. A remote request cannot itself erase data stored only in your device or cancel an Apple subscription.
11. Children
FinCamp is not intended for anyone under 16 years old, and we do not knowingly collect personal data from anyone under 16. Users aged 16 or 17 may use FinCamp only with the permission of a parent or legal guardian.
If you believe a person under 16 has provided personal data through FinCamp, contact us so we can investigate and take appropriate action, including deletion where appropriate.
12. Changes to this Policy
We may update this Policy to reflect changes in the Service, providers, law, or processing practices. The “Last updated” date identifies the current version. Where required, we will provide notice of material changes through the Service or another reasonable channel. We will request new consent if applicable law requires it.
FinCamp reminders are currently scheduled locally on your device. Fabera does not currently collect a remote push-notification token for these reminders. Third-party links are governed by the destination’s own terms and privacy notice. Before the FinCamp website adds non-essential cookies or analytics, this Policy and any required consent controls must be updated.
13. Contact
Questions, complaints, and privacy requests may be sent to:
FABERA YAZILIM HİZMETLERİ ANONİM ŞİRKETİ
Data Controller
UTKU MAH, ÇİMENTEPE_1 CAD, NO:49/18
45000 ŞEHZADELER/MANİSA, Türkiye
support@fabera.ai