Kısa hali: hesap yok, takip yok, reklam yok, analitik yok.
Mektubun bu uygulamanın sunucularına uğramaz — şifreleme cihazında olur. Tek
istisna: "Edebi öneri al" düğmesine sen basarsan taslağın öneri için aktarıcımız
üzerinden yapay zekâya iletilir (aşağıda ayrıntısı var).
Mektup içeriği
Yazdığın mektup, telefonundan ayrılmadan cihazında şifrelenir (AES-256-GCM) ve yalnız
senin ürettiğin kağıda/PDF'e QR kod olarak yazılır. Düz (şifresiz) mektup metni hiçbir
zaman bize ya da üçüncü bir tarafa gönderilmez, hiçbir yerde saklanmaz, loglanmaz. Şifreli
kapsül sana bir kez gösterilir; kopyasını tutmayız — tutamayız. Mektubuna eklediğin
fotoğraf ve belgeler de aynı şekilde cihazında şifrelenir ve yalnız dijital kapsül
dosyasının içinde yaşar — bize ya da başka bir sunucuya gitmez. Galeri/kamera erişimi
yalnız senin seçtiğin ekleri okumak içindir.
Hesap ve kimlik
Üyelik, kullanıcı adı, parola, profil yoktur. Mühürleme sırasında sahteciliği önlemek için
cihazındaki Apple/Google girişiyle e-posta adresin doğrulanır; bu adres ve doğrulama
zamanı
yalnız şifreli mektubun içine damgalanır. E-posta adresinin kendisi hiçbir
sunucumuza gönderilmez — sadece mektubu günü gelince açan kişi görür. Cihaz başına verilen
bir ücretsiz mektup hakkının uygulamayı silip yeniden kurarak sıfırlanmasını
önlemek için bir sayaç tutulur. Bu sayacın nerede durduğu işletim sistemine göre
değişir:
-
iPhone / iPad: Apple'ın DeviceCheck servisi kullanılır — cihaz başına
tek bir bit (ücretsiz mektubun kullanılıp kullanılmadığı) Apple'ın
sunucusunda tutulur.
Uygulama bize tek kullanımlık, içeriği okunamayan bir jeton gönderir; hangi cihaz
olduğunu yalnız Apple bilir. Bizde hiçbir kayıt oluşmaz.
-
Android: Android'de bunun bir karşılığı yoktur, bu yüzden sayacı
biz tutmak zorundayız. Cihazın kalıcı kimliği cihazın kendisinde geri
döndürülemez biçimde özetlenir (SHA-256); sunucumuza yalnız bu özet ulaşır,
ham kimlik hiçbir zaman bize gelmez. Özet sunucuda ikinci kez gizli bir anahtarla
karıştırılıp saklanır, böylece kayıtlarımız sızsa bile cihaz kimliğine ya da başka bir
servisteki kaydına geri gidilemez. Bu kayıt yalnız kötüye kullanımı önlemek için
kullanılır; e-postanla, adınla ya da mektuplarınla ilişkilendirilmez, kimseyle
paylaşılmaz ve iki yıl kullanılmazsa silinir.
Her iki durumda da bizde ne e-posta, ne e-posta özeti, ne de bir kullanıcı kaydı vardır ve
sayaç hiçbir mektupla ilişkilendirilemez.
Cihazdan dışarı ne çıkar?
-
Mektup parmak izi (hash): mühürleme anında mektubun SHA-256 özeti Polygon
zincirine yazılmak üzere aktarıcımıza gönderilir. Hash tek yönlüdür; içerik, isim ya da
kişisel veri içermez ve içeriğe geri çevrilemez. Aktarıcı durumsuzdur: kodumuz
hiçbir şey saklamaz ve loglamaz — barındırma sağlayıcımız (Vercel) ise her istek için
teknik erişim kayıtları (IP, zaman, yol) tutabilir; buna erişimimiz vardır.
-
Edebi öneri (isteğe bağlı): yalnız sen "Edebi öneri al" düğmesine basarsan,
taslağın öneri üretilmesi için önce aktarıcımıza, oradan yapay zekâ servisine (Anthropic
Claude) iletilir. Biz saklamayız; sağlayıcının kötüye-kullanım denetimi kapsamında kısa
süre saklaması mümkündür — bunu tek taraflı garanti edemeyiz. Bu düğmeye basmazsan
taslağın cihazdan çıkmaz.
-
Zaman kilidi: mektup açılırken uygulama, herkese açık drand ağından o günün
imzasını indirir. Bu istekte mektupla ilgili hiçbir bilgi gönderilmez.
Cihazında ne kalır?
Yalnız içeriksiz "mühür anıları" (alıcı adı, tarihler, hash), dil/tema tercihlerin ve
açtıysan hatırlatmalar. Bunlar cihazından hiç çıkmaz ve uygulama içinden silinebilir.
Uygulamayı silersen hepsi yok olur.
Hatırlatmalar yerel bildirimdir: cihazın kendi takviminde planlanır. Uzak push
(APNs/FCM) kullanmıyoruz — bize cihaz jetonu da, açılış tarihin de gelmez. Ayarlar'dan
kapatabilirsin.
Analitik, reklam, çerez
Yoktur. Davranış takibi, reklam kimliği, çökme raporu toplama, çerez kullanılmaz.
Satın almalar
Uygulama içi satın almalar Apple App Store / Google Play tarafından işlenir; ödeme ve kart
bilgilerin bize hiçbir biçimde ulaşmaz.
İletişim
Sorular için: mail@cagricakir.com.tr
Privacy Policy
Last updated: July 27, 2026
In short: no accounts, no tracking, no ads, no analytics.
Your letter never reaches our servers — technically it cannot.
Letter content
Your letter is encrypted on your device (AES-256-GCM) before it goes anywhere, and it is
written as QR codes only onto the paper/PDF you produce. The plaintext is never sent to us
or to any third party, never stored, never logged. The capsule is shown to you once; we
keep no copy — we cannot. Photos and files you attach are likewise encrypted on your
device and live only inside the digital capsule file — they never reach us or any server.
Gallery/camera access is used only to read the attachments you choose.
Accounts and identity
There are no accounts. At sealing time your e-mail address is verified via your device's
Apple/Google sign-in to prevent impersonation; that address and timestamp are stamped
only inside the encrypted letter. The e-mail address itself is never sent to our
servers — only the person who opens the letter on its date can see it. Solely to stop the
one free letter per device from being reset by reinstalling the app, we keep a
counter. Where that counter lives depends on your operating system:
-
iPhone / iPad: we use Apple's DeviceCheck service — a single bit
per device (whether the free letter was used) is stored on Apple's servers. The app
sends us a single-use, opaque token; only Apple can tell which device it belongs to.
We store nothing.
-
Android: Android has no equivalent, so
we have to keep the counter ourselves. The device's persistent identifier is
irreversibly digested (SHA-256) on the device itself; only that digest reaches
our server and the raw identifier never reaches us. On the server the digest is
mixed again with a secret key before being stored, so even if our records leaked they
could not be traced back to a device identifier or matched against records held by any
other service. This record is used solely to prevent abuse; it is not linked to
your e-mail, your name or your letters, is never shared, and is
deleted after two years of disuse.
In both cases we hold no e-mail, no e-mail digest and no user record, and the counter
cannot be linked to any letter.
What leaves your device?
-
Letter fingerprint (hash): at sealing, the letter's SHA-256 digest is sent to our
stateless relay to be written to the Polygon chain. A hash is one-way; it contains no
content or personal data and cannot be reversed. The relay is stateless: our code
stores and logs nothing — but our hosting provider (Vercel) may keep technical access
records (IP, time, path) for each request, and we can access those.
-
Literary suggestion (optional): only if you tap "Get a literary suggestion," your
draft is sent first to our relay and from there to an AI service (Anthropic Claude) to
produce the suggestion. We do not store it; the provider may retain it briefly for abuse
monitoring — we cannot unilaterally guarantee otherwise. It is not stored. If you never
tap it, your draft never leaves the device.
-
Time lock: when opening a letter, the app fetches that day's signature from the
public drand network. That request carries no information about your letter.
What stays on your device?
Only contentless "seal memories" (recipient name, dates, hash), your language/theme
preferences and any reminders you enabled. They never leave the device and can be deleted
in the app.
Reminders are local notifications: they are scheduled by your own device. We do not
use remote push (APNs/FCM) — no device token and no unlock date ever reaches us. You can
turn them off in Settings.
Analytics, ads, cookies
None. No behavioral tracking, no ad identifiers, no crash reporting, no cookies.
Purchases
In-app purchases are processed by Apple App Store / Google Play; your payment details
never reach us in any form.
Contact
Questions: mail@cagricakir.com.tr