Birikko is a personal finance app built for families to track income and expenses together. Financial data is sensitive, so this policy explains in plain language what we collect, why we collect it, and what rights you have over it.
Summary
The short version:
- We don't connect to your bank. Every transaction in Birikko is entered manually by you or another member of your ledger. We never ask for or store your banking credentials.
- We never see your card details. Subscription payments are handled by the App Store and Google Play; your payment information stays with them.
- We don't sell your data. We do not sell or rent your personal data to third parties for advertising.
- A shared ledger means shared data. When you add someone to a ledger, they can see its transactions, budgets, and goals according to their role.
- You can delete your data at any time. You can permanently delete your account and ledgers from within the app.
1. Data Controller
Under Turkish Personal Data Protection Law No. 6698 ("KVKK") and, where applicable, the EU General Data Protection Regulation ("GDPR"), the data controller is:
| Entity | SLY TEKNOLOJİ VE YAZILIM HİZMETLERİ LİMİTED ŞİRKETİ |
| privacy@slyteknoloji.com | |
| Web | https://birikko.com |
2. Personal Data We Process
2.1 Account and identity data
Data received from Google or Apple when you sign in: name, email address, profile photo (if any), and the unique user ID issued by the provider. If you use Sign in with Apple and choose to hide your email, we only receive Apple's private relay address.
2.2 Financial content
Records you enter into the app: transaction amount and currency, date, category, description or note, tags, recurring payment (subscription) definitions, budget limits, and savings goals. This is content you create — it is never imported automatically from a bank or financial institution.
2.3 Ledger and sharing data
Ledger name, base currency, time zone, budget period start day, membership roles (Owner, Admin, Member, Viewer), invitation codes, and invitation status.
2.4 Subscription data
Your premium subscription status, plan type (monthly/annual), start and renewal dates, trial or billing status, and the anonymous transaction identifier issued by the platform. Card numbers, expiry dates, and CVV codes are never transmitted to or stored by us.
2.5 Device and usage data
Device model and OS version, app version, language and region settings, pseudonymous device identifiers, crash reports, error logs, and basic usage statistics.
2.6 Notification data
Your device's push notification token and your notification preferences, used to deliver reminders and alerts.
2.7 Support correspondence
Messages and attachments you send us by email or through the app.
What we do not process: banking credentials, card data, national ID numbers, location data, contacts, or photo library access (unless you explicitly upload an image), and special categories of personal data. We recommend not entering sensitive information such as health, religious, or political details into free-text fields like transaction notes or category names.
3. Purposes and Legal Bases
| Purpose | Data used | Legal basis |
|---|---|---|
| Account creation and authentication | Account and identity data | Performance of a contract |
| Income/expense tracking, budgets, goals | Financial content, ledger data | Performance of a contract |
| Sharing a ledger with family members | Ledger and sharing data | Performance of a contract |
| Subscription management and billing | Subscription data | Contract; legal obligation |
| Reminders and renewal notifications | Notification data, financial content | Consent |
| Personalized insights and analysis | Financial content | Consent |
| App stability, debugging, security | Device and usage data | Legitimate interest |
| Fraud and abuse prevention | Account and device data | Legitimate interest |
| Responding to support requests | Support correspondence | Legitimate interest |
| Statutory retention and tax obligations | Subscription data | Legal obligation |
You can withdraw consent for notifications and personalized insights at any time in the app's settings. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
4. Visibility in Shared Ledgers
Birikko's core feature is letting a household share one ledger. When you join or invite someone to a ledger, the following visibility applies:
| Role | Can see | Can do |
|---|---|---|
| Owner | All transactions, budgets, goals, members | Everything; can delete the ledger and transfer ownership |
| Admin | All content | Add, edit, and delete transactions, budgets, goals; invite members |
| Member | All content | Add transactions and edit their own records |
| Viewer | All content | View only; cannot make any changes |
Important: Every transaction you add to a ledger is visible to its other members, along with an indication of who created it. If you want to keep personal spending separate, create a separate ledger. When you leave a ledger, records you previously added remain in it — they are part of the ledger's shared financial history.
5. Automated Analysis and Insights
Birikko analyzes the transaction data you enter to generate insights that summarize your spending patterns (for example, flagging a recurring subscription or a rise in a spending category). These insights:
- Operate only on data within your own ledger,
- Are informational and do not constitute investment, credit, or financial advice,
- Do not produce automated decisions that have legal effects or similarly significantly affect you,
- Can be turned off in settings.
If a third-party AI provider is used to generate insights, only the minimum data necessary — anonymized wherever possible — is transmitted, and the provider is contractually prohibited from using it to train their own models.
6. Who We Share Data With
We do not sell your data. We share it on a limited basis with the following service providers acting as processors:
| Provider | Purpose | Data shared |
|---|---|---|
| Google (Firebase Authentication) | Authentication | Account and identity data |
| Google (Firebase Cloud Messaging) | Push notifications | Notification token |
| Apple | Sign in with Apple, in-app purchases | Identity, subscription data |
| Google Play Billing | In-app purchases | Subscription data |
| Hetzner Online GmbH | Server and database hosting | All application data |
| Google (Firebase Crashlytics / Analytics) | Error tracking and stability | Device and usage data |
We may also disclose data where required by law, a court order, or a valid request from a competent public authority, limited to what the law requires.
7. International Transfers
Some of the providers listed above host data outside Türkiye. In those cases, personal data is transferred under KVKK Art. 9 on the basis of your explicit consent or appropriate safeguards such as standard contractual clauses. We have agreements in place with each provider restricting the use of your data to the purposes described in this policy.
8. Retention Periods
| Data type | Retention |
|---|---|
| Account and profile data | While the account is active |
| Financial content and ledger data | Until the ledger is deleted |
| Deleted records (undo window) | 30 days, then permanently deleted |
| Deleted account | Permanently erased within 30 days of the request |
| Subscription and billing records | 10 years, as required by tax law |
| Crash and error logs | 90 days |
| Support correspondence | 2 years |
Once the period expires, data is deleted, destroyed, or irreversibly anonymized.
9. Security
Technical and organizational measures we apply:
- TLS encryption for all data in transit
- Database-level access control and encrypted storage
- We store no passwords; authentication is handled by Google and Apple
- Ledger-scoped authorization — every query is constrained by the user's membership
- Staff access limited on a least-privilege basis
- Regular backups and log monitoring
No system is completely secure. If a breach affecting your personal data occurs, we will notify the supervisory authority (within 72 hours, per KVKK Art. 12/5) and inform affected users without undue delay.
10. Your Rights
Under KVKK Art. 11 — and, where the GDPR applies, Articles 15–22 — you have the right to:
- Learn whether your personal data is being processed
- Request information about that processing
- Learn the purpose of processing and whether it is used accordingly
- Know the third parties, domestic or abroad, to whom your data is transferred
- Request correction of incomplete or inaccurate data
- Request erasure or destruction of your data
- Request that corrections and erasures be communicated to third parties
- Object to a result produced against you solely by automated analysis
- Claim compensation for damages arising from unlawful processing
- Where the GDPR applies: request portability of your data and lodge a complaint with your local supervisory authority
Send requests to privacy@slyteknoloji.com. We respond free of charge within 30 days. If you are unsatisfied with the outcome, you may file a complaint with the Turkish Personal Data Protection Authority (KVKK) or your local data protection authority.
11. Deleting Your Account and Data
- In the app: Settings → Profile → Delete account
- By email: Send a request from your account's email address to privacy@slyteknoloji.com
Before you delete: if you own a ledger with other members, deleting it removes their access too. Alternatively, transfer ownership to another member and leave the ledger. Deletion is irreversible.
To cancel a subscription, use your App Store or Google Play subscription settings — deleting your account does not automatically cancel billing.
12. Children's Privacy
Birikko is not directed at anyone under 18, and we do not knowingly collect data from users under 18. If we learn that a child has provided us with data, we will delete it. If you believe a child in your care has entered data into Birikko, please contact us.
13. Cookies and Similar Technologies
The mobile app does not use cookies. Our website (birikko.com) uses only strictly necessary cookies for session handling and core site functionality, plus — subject to your consent where required — anonymous analytics cookies. You can manage your preferences through your browser settings or the site's cookie preference panel.
14. Changes to This Policy
We may update this policy from time to time. For material changes, we will notify you by in-app message or email before the change takes effect. The effective date appears at the top of this page, and previous versions are available on request.
15. Contact
For any privacy question or request:
Email: privacy@slyteknoloji.com Support: support@slyteknoloji.com
This policy is published in Turkish and English. In case of any conflict, the Turkish version prevails.