Kısa hali: hesap yok, takip yok, reklam yok, analitik yok.
Mektubun bu uygulamanın sunucularına uğramaz — şifreleme cihazında olur. Tek
istisna: "Edebi öneri al" düğmesine sen basarsan taslağın öneri için aktarıcımız
üzerinden yapay zekâya iletilir (aşağıda ayrıntısı var).
Mektup içeriği
Yazdığın mektup, telefonundan ayrılmadan cihazında şifrelenir (AES-256-GCM) ve yalnız
senin ürettiğin kağıda/PDF'e QR kod olarak yazılır. Düz (şifresiz) mektup metni hiçbir
zaman bize ya da üçüncü bir tarafa gönderilmez, hiçbir yerde saklanmaz, loglanmaz. Şifreli
kapsül sana bir kez gösterilir; kopyasını tutmayız — tutamayız. Mektubuna eklediğin
fotoğraf ve belgeler de aynı şekilde cihazında şifrelenir ve yalnız dijital kapsül
dosyasının içinde yaşar — bize ya da başka bir sunucuya gitmez. Galeri/kamera erişimi
yalnız senin seçtiğin ekleri okumak içindir.
Hesap ve kimlik
Üyelik, kullanıcı adı, parola, profil yoktur. Mühürleme sırasında sahteciliği önlemek için
cihazındaki Apple/Google girişiyle e-posta adresin doğrulanır; bu adres ve doğrulama
zamanı
yalnız şifreli mektubun içine damgalanır. E-posta adresinin kendisi hiçbir
sunucumuza gönderilmez — sadece mektubu günü gelince açan kişi görür. Cihaz başına verilen
bir ücretsiz mektup hakkının uygulamayı silip yeniden kurarak sıfırlanmasını
önlemek için bir sayaç tutulur. Bu sayacın nerede durduğu işletim sistemine göre
değişir:
-
iPhone / iPad: Apple'ın DeviceCheck servisi kullanılır — cihaz başına
tek bir bit (ücretsiz mektubun kullanılıp kullanılmadığı)
Apple'ın sunucusunda tutulur. Uygulama bize tek kullanımlık, içeriği okunamayan
bir jeton gönderir; hangi cihaz olduğunu yalnız Apple bilir.
Bizde hiçbir kayıt oluşmaz.
-
Android: Android'de bunun bir karşılığı yoktur, bu yüzden sayacı
biz tutmak zorundayız. Cihazın kalıcı kimliği cihazın kendisinde geri
döndürülemez biçimde özetlenir (SHA-256); sunucumuza yalnız bu özet ulaşır,
ham kimlik hiçbir zaman bize gelmez. Özet sunucuda ikinci kez gizli bir anahtarla
karıştırılıp saklanır, böylece kayıtlarımız sızsa bile cihaz kimliğine ya da başka bir
servisteki kaydına geri gidilemez. Bu kayıt yalnız kötüye kullanımı önlemek için
kullanılır; e-postanla, adınla ya da mektuplarınla ilişkilendirilmez, kimseyle
paylaşılmaz ve iki yıl kullanılmazsa silinir.
Her iki durumda da bizde ne e-posta, ne e-posta özeti, ne de bir kullanıcı kaydı vardır ve
sayaç hiçbir mektupla ilişkilendirilemez.
Cihazdan dışarı ne çıkar?
-
Mektup parmak izi (hash): mühürleme anında mektubun SHA-256 özeti Polygon
zincirine yazılmak üzere aktarıcımıza gönderilir. Hash tek yönlüdür; içerik, isim ya da
kişisel veri içermez ve içeriğe geri çevrilemez. Aktarıcı mektupla ilgili
hiçbir şey saklamaz — barındırma sağlayıcımız (Vercel) ise her istek için teknik
erişim kayıtları (IP, zaman, yol) tutabilir; buna erişimimiz vardır.
-
Taslağın cihazından çıkmaz — istisnasız. Uygulamanın eski sürümlerinde isteğe
bağlı bir "edebi öneri" özelliği vardı ve o düğmeye basarsan taslağın bir yapay zekâ
servisine iletiliyordu. Bu özellik kaldırıldı. Bugün mektup metnini cihazından
çıkaran hiçbir yol yoktur; şifreleme de zaten cihazında yapılır.
-
Zaman kilidi: mektup açılırken uygulama, herkese açık drand ağından o günün
imzasını indirir. Bu istekte mektupla ilgili hiçbir bilgi gönderilmez.
Kötüye kullanımı önlemek için tuttuklarımız
Mektuplarla ilgisi olmayan, kısa ömürlü ve tek amacı bot/istismar engellemek olan üç kayıt
tutuyoruz. Hiçbiri adınla, e-postanla ya da bir mektupla ilişkilendirilemez:
-
İstek sayacı (IP): aynı bağlantıdan gelen istek sayısını günlük olarak sayarız.
IP adresi düz olarak saklanmaz: yalnız bizde duran gizli bir anahtarla
karıştırılmış hâli anahtar olarak kullanılır ve kayıt 48 saat sonra kendiliğinden
düşer. Sayaçtan IP'ye geri gidilemez.
-
Uygulama doğrulaması (yalnız iPhone/iPad): isteğin gerçekten bizim uygulamamızdan
geldiğini doğrulamak için Apple'ın App Attest servisi kullanılır. Cihazın ürettiği
açık anahtar ve bir sayaç bizde tutulur. Bu anahtar cihazı bize tanıtmaz, başka
hiçbir servisteki kaydınla eşleştirilemez ve mektuplarınla ilişkilendirilmez.
-
Ücretsiz hak defteri (yalnız Android): yukarıda anlatılan, iki kez karıştırılmış
cihaz özeti.
Bunların hiçbiri reklam, ölçümleme ya da profilleme için kullanılmaz; üçüncü taraflara
verilmez.
Cihazında ne kalır?
Yalnız içeriksiz "mühür anıları" (alıcı adı, tarihler, hash), dil/tema tercihlerin ve
açtıysan hatırlatmalar. Bunlar cihazından hiç çıkmaz ve uygulama içinden silinebilir.
Uygulamayı silersen hepsi yok olur.
İki küçük istisna, ikisi de cihazında kalır: (1) "Mühürle"ye bastığın andan işlem
bitene kadar mektubun şifreli bir taslağı tutulur — telefon o sırada uygulamayı
kapatırsa yazdığın kaybolmasın diye. Şifre anahtarı cihazın güvenli deposundadır
(Keychain), taslak işlem biter bitmez silinir ve bir sonraki açılışta "geri yükle" ya da
"sil" diye sorulur. (2) Ücretsiz mektup hakkının kullanılıp kullanılmadığı bilgisi
(tek sayı, mektupla ilgili hiçbir şey içermez) cihazın güvenli deposunda tutulur;
iPhone'da uygulamayı silip yeniden kurmak bunu sıfırlamaz.
Hatırlatmalar yerel bildirimdir: cihazın kendi takviminde planlanır. Uzak push
(APNs/FCM) kullanmıyoruz — bize cihaz jetonu da, açılış tarihin de gelmez. Ayarlar'dan
kapatabilirsin.
Analitik, reklam, çerez
Yoktur. Davranış takibi, reklam kimliği, çökme raporu toplama, çerez kullanılmaz.
Satın almalar
Uygulama içi satın almalar Apple App Store / Google Play tarafından işlenir; ödeme ve kart
bilgilerin bize hiçbir biçimde ulaşmaz.
İletişim
Sorular için: mail@cagricakir.com.tr
Privacy Policy
Last updated: 12 August 2026
In short: no accounts, no tracking, no ads, no analytics.
Your letter never reaches our servers — encryption happens on your device. The one
exception: if you tap "Get a literary suggestion," your draft is sent through our
relay to an AI service (details below).
Letter content
Your letter is encrypted on your device (AES-256-GCM) before it goes anywhere, and it is
written as QR codes only onto the paper/PDF you produce. The plaintext is never sent to us
or to any third party, never stored, never logged. The capsule is shown to you once; we
keep no copy — we cannot. Photos and files you attach are likewise encrypted on your
device and live only inside the digital capsule file — they never reach us or any server.
Gallery/camera access is used only to read the attachments you choose.
Accounts and identity
There are no accounts. At sealing time your e-mail address is verified via your device's
Apple/Google sign-in to prevent impersonation; that address and timestamp are stamped
only inside the encrypted letter. The e-mail address itself is never sent to our
servers — only the person who opens the letter on its date can see it. Solely to stop the
one free letter per device from being reset by reinstalling the app, we keep a
counter. Where that counter lives depends on your operating system:
-
iPhone / iPad: we use Apple's DeviceCheck service —
a single bit per device (whether the free letter was used) is stored
on Apple's servers. The app sends us a single-use, opaque token; only Apple can
tell which device it belongs to.
We store nothing.
-
Android: Android has no equivalent, so
we have to keep the counter ourselves. The device's persistent identifier is
irreversibly digested (SHA-256) on the device itself; only that digest reaches
our server and the raw identifier never reaches us. On the server the digest is
mixed again with a secret key before being stored, so even if our records leaked they
could not be traced back to a device identifier or matched against records held by any
other service. This record is used solely to prevent abuse; it is not linked to
your e-mail, your name or your letters, is never shared, and is
deleted after two years of disuse.
In both cases we hold no e-mail, no e-mail digest and no user record, and the counter
cannot be linked to any letter.
What leaves your device?
-
Letter fingerprint (hash): at sealing, the letter's SHA-256 digest is sent to our
relay to be written to the Polygon chain. A hash is one-way; it contains no content or
personal data and cannot be reversed. The relay stores nothing related to your
letter — but our hosting provider (Vercel) may keep technical access records (IP, time,
path) for each request, and we can access those.
-
Your draft never leaves your device — no exceptions. Earlier versions of the app
had an optional "literary suggestion" feature that sent your draft to an AI service when
you tapped it. That feature has been removed. There is no longer any path that
takes your letter text off your device; the encryption happens there too.
-
Time lock: when opening a letter, the app fetches that day's signature from the
public drand network. That request carries no information about your letter.
What we keep to prevent abuse
We keep three short-lived records that have nothing to do with letters and exist only to
stop bots and abuse. None of them can be linked to your name, your email or any letter:
-
Request counter (IP): we count how many requests come from the same connection
each day. The IP address is not stored in the clear: only a version mixed with a
secret key we hold is used as the counter's name, and the record expires by itself after
48 hours. The counter cannot be turned back into an IP.
-
App verification (iPhone/iPad only): to confirm a request really comes from our
app, Apple's App Attest is used. The public key your device generates, plus a
counter, is kept by us. It does not identify you, cannot be matched with your record at
any other service, and is never linked to your letters.
-
Free-letter ledger (Android only): the twice-hashed device digest described
above.
None of this is used for advertising, measurement or profiling, and none of it is shared
with third parties.
What stays on your device?
Only contentless "seal memories" (recipient name, dates, hash), your language/theme
preferences and any reminders you enabled. They never leave the device and can be deleted
in the app.
Two small exceptions, both of which stay on your device: (1) from the moment you
tap "Seal" until the process finishes, an encrypted draft of your letter is kept,
so that nothing is lost if the phone closes the app in the meantime. The encryption key
lives in the device's secure store (Keychain); the draft is deleted as soon as the process
ends, and on the next launch you are asked to restore or discard it. (2) Whether
your one free letter has been used (a single number, containing nothing about any letter)
is kept in the device's secure store; on iPhone, deleting and reinstalling the app does
not reset it.
Reminders are local notifications: they are scheduled by your own device. We do not
use remote push (APNs/FCM) — no device token and no unlock date ever reaches us. You can
turn them off in Settings.
Analytics, ads, cookies
None. No behavioral tracking, no ad identifiers, no crash reporting, no cookies.
Purchases
In-app purchases are processed by Apple App Store / Google Play; your payment details
never reach us in any form.
Contact
Questions: mail@cagricakir.com.tr