1. Introduction and Scope
This notice explains how personal data is processed in the Birikko mobile application and its related website (the "App"). It is issued in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Turkish Personal Data Protection Law No. 6698 ("KVKK").
Birikko is a personal and household finance application that lets you track income and expenses, set budgets and savings goals, and view analyses of your spending habits. The App does not connect to your bank or any financial institution. It does not collect bank statements, card numbers or banking credentials. All financial records in the App are entered manually by you or by the people you share your ledger with.
By using the App you acknowledge that you have read this notice.
2. Data Controller
| Controller | SLY TEKNOLOJİ VE YAZILIM HİZMETLERİ LİMİTED ŞİRKETİ |
| privacy@slyteknoloji.com | |
| Website | https://birikko.com |
In this notice "we", "us" and "Birikko" refer to the controller above; "you" and "user" refer to users of the App.
3. Personal Data We Process
3.1 Identity and contact data
- Name, surname or display name
- Email address
- Profile picture (if provided by your Google or Apple account)
- Unique account identifier (user ID)
3.2 Account and authentication data
- Authentication tokens received from Google or Apple during sign-in
- Session information and last sign-in date
- Account creation date and account status
Birikko does not store your password. Authentication is handled entirely by Google and Apple.
3.3 Financial records you enter
- Income and expense transactions: amount, currency, date, category, description/notes, tags
- Exchange rate frozen at the time of each transaction
- Ledger (household) name, base currency, budget period, time zone
- Category budgets and limits
- Savings goals and contribution records
- Recurring payments / subscription records and renewal dates
- Ledger memberships and roles (Owner / Admin / Member / Viewer)
- Invitation codes and invitation status
3.4 Subscription and purchase data
- Premium subscription status, plan type (monthly/annual), start and renewal dates
- Purchase verification data (receipt/token) provided by the App Store or Google Play
We do not process your payment details. Card and payment method data are collected and stored directly by Apple or Google. We only receive confirmation of whether a subscription is valid.
3.5 Security and technical data
- IP address
- Device information: model, operating system and version, app version, language and region
- Device/installation identifier and push notification token
- Server and access logs, error and crash reports
3.6 Usage and analytics data
- Screen views, feature usage frequency, session duration
- Crash and performance diagnostics
- Notification permission status and preferences
3.7 Support data
- Content of your support messages, attachments and contact details
- Feedback and complaint records
3.8 Data we do not seek
Birikko does not intend to collect special categories of personal data (Art. 9 GDPR — health, religion, biometric data, etc.). Please avoid entering such information in free-text fields (transaction notes, descriptions, tags). You remain responsible for the content you enter into these fields.
4. Purposes of Processing
We process personal data in order to:
- Create accounts and authenticate users
- Provide the service — create, store and synchronise transactions, budgets, goals and subscription records across your devices
- Operate shared ledgers — invite household members, manage roles, provide access to shared data
- Generate analyses and insights — produce summaries, charts and advisory suggestions about your spending
- Send functional notifications — budget overruns, upcoming subscription renewals, goal progress
- Manage subscriptions and billing — verify premium entitlement and subscription status
- Provide user support — respond to questions, requests and complaints
- Ensure security and prevent abuse — detect unauthorised access, fraud and misuse; protect system integrity
- Improve the service — diagnose errors, measure performance, develop features based on usage statistics
- Comply with legal obligations — retention, disclosure and responses to competent authorities
5. Legal Bases for Processing
| Legal basis | Processing activity |
|---|---|
| Art. 6(1)(b) GDPR — performance of a contract (KVKK Art. 5/2-c) | Account creation, delivery of the service, data synchronisation, shared ledger features, subscription management |
| Art. 6(1)(c) GDPR — legal obligation (KVKK Art. 5/2-ç) | Retention of logs and financial records, responses to lawful requests from authorities |
| Art. 6(1)(f) GDPR — legitimate interests (KVKK Art. 5/2-e, 5/2-f) | Security, fraud prevention, error diagnostics, service improvement, establishment or defence of legal claims |
| Art. 6(1)(a) GDPR — consent (KVKK Art. 5/1) | Non-essential cookies, marketing communications, optional analytics, personalised insights, and international transfers where consent is the applicable safeguard |
Where processing relies on legitimate interests, we balance those interests against your rights and freedoms; you may object at any time (see Section 13).
Where processing relies on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
6. How We Collect Data
Personal data is collected through automated and partially automated electronic means, specifically:
- Information you enter directly in the App (transactions, budgets, goals, notes)
- Information received automatically from Google or Apple when you sign in
- Records generated automatically by the App and our servers (logs, device data, usage data)
- Information provided by users who invite you to a ledger or whom you invite
- Messages you send to our support channels
7. Sharing and Transfers
7.1 Recipients
We share personal data only to the extent necessary for the purposes described above, with the following categories of recipients:
| Recipient category | Purpose | Example providers |
|---|---|---|
| Cloud infrastructure and hosting | Data storage and backup | Hetzner Online GmbH, Google Cloud Platform |
| Authentication providers | Sign-in | Google (Firebase Authentication), Apple (Sign in with Apple) |
| Push notification infrastructure | Delivering notifications | Firebase Cloud Messaging, Apple Push Notification Service |
| Error and performance monitoring | Crash diagnostics, stability | Firebase Crashlytics, Google Analytics for Firebase |
| App stores | Subscription purchase and validation | Apple App Store, Google Play |
| Exchange rate service | Rates for multi-currency transactions | CurrencyBeacon |
| Support and communication tools | Handling user requests | Google Workspace |
| Competent public authorities | Statutory information requests | Courts, prosecutors, regulators |
We do not sell or rent your personal data to third parties for marketing purposes.
7.2 Sharing within a household ledger
When you share a ledger, the transactions, budgets, goals, subscriptions and notes you add become visible to the other members of that ledger, together with your display name and profile picture.
- Owner / Admin roles can edit and delete records, and invite or remove members.
- Member role can add records and edit their own.
- Viewer role has read-only access.
Before joining or sharing a ledger, please consider that you are granting those members access to your financial records. If you leave a ledger, records you added before leaving remain in the ledger, as they form part of that household's shared data.
7.3 International transfers
Some of our cloud, authentication and notification providers operate servers outside the EEA and outside Türkiye. Where personal data is transferred internationally, we rely on one of the following safeguards:
- Transfer to a country covered by an adequacy decision (Art. 45 GDPR / a decision of the Turkish Data Protection Board);
- Standard Contractual Clauses, binding corporate rules or equivalent appropriate safeguards (Art. 46 GDPR / KVKK Art. 9), supported by a transfer impact assessment where required;
- Where no such safeguard applies and no statutory derogation is available, your explicit consent (Art. 49 GDPR / KVKK Art. 9).
You may request a copy of the relevant safeguards by contacting us.
8. Retention Periods
| Data category | Retention period |
|---|---|
| Account, profile and financial records | For as long as your account is active |
| Data after account deletion | Permanently deleted or anonymised within 30 days of the deletion request |
| Records added to a shared ledger | Until the ledger is deleted (under the ledger owner's control) |
| Server and access logs | 2 years (statutory retention requirements) |
| Subscription and payment verification records | 10 years (commercial and tax law requirements) |
| Support requests and correspondence | 3 years from closure of the request |
| Consent-based processing | Until consent is withdrawn |
| Data relevant to a dispute | Until the end of the applicable limitation period |
Data whose retention period has expired is deleted, destroyed or anonymised during our periodic destruction cycles.
9. Security Measures
Technical measures
- TLS encryption for all data in transit
- Encryption of data at rest
- Role-based access control and least-privilege principle
- Regular, encrypted backups
- Vulnerability scanning and dependency updates
- Access and activity logging with anomaly monitoring
- Authentication delegated to trusted providers (Google, Apple)
Organisational measures
- Confidentiality undertakings with staff and suppliers
- Data processing agreements with all processors
- Periodic review of access rights
- Staff awareness training
- Documented data breach response procedure
In the event of a personal data breach, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
10. Automated Analysis and Insights
Birikko automatically analyses the financial records you enter to produce spending summaries, budget alerts and savings suggestions ("insights") — for example, flagging a subscription you appear not to use, or a rise in spending within a category.
These insights:
- are advisory only and do not constitute automated decision-making producing legal effects or similarly significantly affecting you within the meaning of Art. 22 GDPR;
- are not used for credit scoring, risk rating or comparable profiling;
- operate only on your own data (or that of your ledger);
- can be partly or fully disabled in Settings > Notifications.
The accuracy of insights depends on the accuracy of the data you enter. Birikko does not provide financial, investment or tax advice.
11. Cookies and Similar Technologies
Our website and in-app web views may use the following cookies:
| Type | Purpose | Legal basis |
|---|---|---|
| Strictly necessary | Session management, security, language preference | Necessary for the service / legitimate interests |
| Functional | Remembering preferences (theme, currency) | Consent |
| Analytics | Aggregated usage statistics | Consent |
Non-essential cookies are set only with your consent. You can change your choices at any time via the cookie preferences panel or your browser settings.
12. Children's Data
Birikko is not directed at persons under the age of 18 and we do not knowingly collect personal data from them. If we learn that we have processed data belonging to a person under 18, we will delete the account and associated data without undue delay. Please contact privacy@slyteknoloji.com if you believe this has occurred.
Where you add someone to a shared household ledger, it is your responsibility to inform them and, where required, to obtain parental consent.
13. Your Rights
Under the GDPR (Arts. 15–22) and KVKK (Art. 11) you have the right to:
- Access — obtain confirmation of whether we process your data and receive a copy of it
- Rectification — have inaccurate or incomplete data corrected
- Erasure — request deletion of your data ("right to be forgotten")
- Restriction — request that processing be limited in certain circumstances
- Data portability — receive your data in a structured, commonly used, machine-readable format and transmit it to another controller
- Object — object to processing based on legitimate interests, and to direct marketing at any time
- Withdraw consent — at any time, without affecting prior lawful processing
- Not be subject to solely automated decisions producing legal or similarly significant effects
- Be informed of the third parties to whom your data has been disclosed, including recipients abroad
- Compensation — claim damages if you suffer loss due to unlawful processing
- Lodge a complaint with a supervisory authority (see Section 14)
You can also exercise several of these rights directly in the App:
- Settings > Profile — update your information
- Settings > Export my data — download your records in a machine-readable format
- Settings > Delete my account — request deletion of your account and data
14. How to Exercise Your Rights
Send your request to privacy@slyteknoloji.com from the email address registered in our system.
Please include your name, contact details and a clear description of your request. We may ask for additional information to verify your identity.
- GDPR: we will respond within one month of receipt, extendable by two further months for complex requests, in which case we will inform you within the first month. Requests are handled free of charge; manifestly unfounded or excessive requests may incur a reasonable fee or be refused.
- KVKK: we will respond within 30 days. Where the request requires additional cost, a fee set by the Turkish Data Protection Board may apply.
Complaints
If you are not satisfied with our response, you may lodge a complaint with:
- Your local EU/EEA supervisory authority — in the Member State of your habitual residence, place of work, or the place of the alleged infringement. A list is available at edpb.europa.eu.
- The UK Information Commissioner's Office (ICO) — if you are in the United Kingdom: ico.org.uk.
- The Turkish Personal Data Protection Authority (KVKK) — kvkk.gov.tr. A complaint may be filed within 30 days of receiving our response and in any case within 60 days of your original application.
15. Changes to This Notice
We may revise this notice to reflect changes in law or in our services. Material changes will be announced through an in-app notice or by email before they take effect. The current version is always published at https://birikko.com/en/kvkk.
16. Contact
Email: privacy@slyteknoloji.com