01Overview
Ekstre Analiz ("we", "the app") is a personal finance application that helps users manage their credit card statements, expenses, subscriptions, and income/expenses. This Privacy Policy is prepared in accordance with the Turkish Personal Data Protection Law (KVKK), the EU General Data Protection Regulation (GDPR), and the privacy requirements of the Apple App Store and Google Play Store.
Please read this policy carefully before downloading, creating an account, or using the app. By using the app, you consent to the data practices described herein.
02Data We Collect
We collect your data purposefully and minimally. Categories of data we collect:
2.1 Account Information
To personalize your account.
Account verification, password reset, notifications.
Hashed irreversibly with bcrypt.
Language, currency, notification settings.
2.2 Financial Data (Stored On-Device)
Only last 4 digits and bank name. Full card numbers are never requested or stored.
Parsed on device, raw PDF not retained.
Date, description, amount, category.
Platform name, amount, renewal date.
Manual financial entries you add.
Entered manually from your card issuer's app.
2.3 Usage & Technical Data
For compatibility and debugging.
To understand which version errors occurred in.
Apple/Google standard crash reporter; contains no personal data.
Subscription state via RevenueCat (only "Pro active/inactive", not content).
2.4 Communication Data
When you contact our support team, we retain the email content, screenshots, and issue details you share. These are used solely to assist you.
03How We Use Your Data
We process your data only for the following purposes:
- Service delivery: Creating your account, analyzing your statements, providing financial visualizations.
- Personalization: Applying your preferred language, currency, and notification settings.
- Notifications: Payment reminders, subscription renewal alerts (as local notifications).
- Customer support: Answering your questions and resolving issues.
- Service improvement: Improving the app via anonymous crash reports and aggregate usage statistics.
- Legal obligations: Compliance with lawful requests from judicial and administrative authorities.
We do not share your data with third parties for marketing purposes, do not sell to ad networks, and do not perform profiling.
04On-Device Processing (Privacy-First)
Ekstre Analiz's most distinctive feature is that your financial data is processed entirely on your device. This is radically different from most other finance apps in the industry.
PDF Parsing
When you upload a bank statement PDF, the file never leaves your device. On iOS we use Apple PDFKit + Vision Framework; on Android, PdfRenderer + Google ML Kit. All text extraction, bank detection, and transaction parsing work even without an internet connection.
AI Categorization
The app uses an on-device open-source Qwen models (Qwen 2.5 1.5B on the small tier, Qwen3-4B and Qwen3-8B on the larger tiers) to automatically categorize transactions. The model file is downloaded once, and all subsequent AI operations run fully offline. Your transactions, descriptions, and amounts are never sent to any AI provider's servers.
05Cloud Sync (Optional)
For users who want multi-device access or backup, we offer an optional "Cloud Sync" in-app purchase. This feature is fully opt-in — if you don't purchase it, your transaction data is not transmitted to our servers. (Email forwarding is a separate optional feature; see section 06.)
When Cloud Sync Is Active
- Transactions, subscriptions, cards, and income/expense entries are written to our Turkey-hosted servers over an encrypted (TLS 1.3) connection.
- Our servers run on Hostinger infrastructure (EU data center) and are KVKK + GDPR compliant.
- Sensitive fields (e.g., card aliases) are encrypted at the database layer.
- No one, including our server team, can access your raw PDF content — cloud data is only structured transaction data.
You can cancel Cloud Sync anytime from Settings → Cloud Sync; all server data is deleted within 30 days of cancellation.
06Email Statement Forwarding (Optional)
If you would rather email your statements than share them by hand, the app gives you a dedicated email address. This feature is opt-in; until you enable it, no email is processed.
When This Feature Is Enabled
- PDF statements you send to that address do reach our servers. Unlike PDFs you add from inside the app, these files are received on the server rather than on your device.
- Once the statement is parsed, the raw PDF is permanently deleted within 24 hours. Only the parsed transaction records remain in your account.
- Transfer is encrypted with TLS 1.3, and the PDF is stored encrypted while it waits to be processed.
- You can turn the feature off at any time under Settings → Email Forwarding. Once off, the address is deactivated and incoming mail is rejected unprocessed.
This is a deliberate exception to the app’s on-device principle and it applies only when you switch it on. If you want the file to stay on your device, add the PDF from inside the app with “Share” instead.
07Third-Party Sharing
We share your data only with trusted service providers necessary for the app's operation, listed below. No data is shared, sold, or rented for marketing or advertising purposes.
- Apple Inc. & Google LLC. In-app purchase transactions (App Store, Google Play) transmit only subscription state. Apple's and Google's own privacy policies apply.
- RevenueCat, Inc. Subscription management platform. Only anonymous user ID and subscription state are shared; no content is shared.
- Hostinger International Ltd. Our server infrastructure provider. Offers GDPR-compliant infrastructure in EU data centers (Germany/Netherlands).
- Firebase (Google LLC.) Used only for push notification delivery. Message contents are not sent to Firebase — only "deliver notification to this device" triggers.
- Judicial and administrative authorities. In case of legal obligation (court order etc.), we may be required to share necessary data. We will notify you in advance whenever possible.
08Data Retention
- On-device data: As long as the app is installed. Deleting the app removes all local data.
- Account information: While your account is active. Removed within 30 days of account deletion (except legal requirements).
- Cloud data: While Cloud Sync is active. Deleted within 30 days of cancellation.
- Crash and log records: Maximum 90 days, then anonymized or deleted.
- Legal retention obligations: For the duration required by law in cases such as tax legislation or court requests.
09Security Measures
We apply industry-standard measures to protect your data:
- Encryption in transit: All server communication over TLS 1.3.
- Encryption at rest: Merchant names, transaction descriptions, your notes, your card's last four digits and your card alias are encrypted with AES-256 at the application layer on the server. Amounts, dates, currency and category names are stored unencrypted; export and totalling depend on them. Because the key is managed server-side, this is not end-to-end (zero-knowledge) encryption.
- Password protection: Bcrypt hash, irreversible.
- Biometric lock: On-device Face ID / Touch ID / fingerprint support.
- Strict access control: Server access restricted to authorized technical personnel via IP-restricted SSH.
- Regular backups: Encrypted, automated daily backups.
- Security audits: Automated dependency scanning; critical vulnerabilities patched within 48 hours.
No system is 100% secure; however, in case of a data breach, we will notify within 72 hours as required by KVKK Article 12 and GDPR Article 33.
10Children's Privacy
The app is not intended for children under 13. We do not knowingly collect personal data from users under 13. If we become aware of such an account, we will promptly delete it along with related data.
In the European Union, parental consent may be required for users under 16 per GDPR Article 8. If you have concerns about your child using this app, please contact us.
11Your Rights
Under KVKK Article 11 and GDPR Articles 15-22, you have the following rights:
- Right of access: Learn what data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): Request permanent deletion of your account and data.
- Right to restriction: Request that processing be limited to certain purposes.
- Right to data portability: Receive your data in a structured, machine-readable format (JSON/CSV).
- Right to object: Object to specific processing activities.
- Protection from automated decision-making: The app does not perform automated decision-making or profiling.
- Right to complain: Lodge a complaint with the Turkish Data Protection Authority (kvkk.gov.tr) or your local EU data protection authority.
To exercise your rights, email destek@ekstreanaliz.com or send a direct deletion request via Settings → Delete Account. We respond to requests within 30 days.
12Policy Changes
This policy may change over time due to legal updates or service changes. We notify you of material changes by in-app notification, email to your registered address, and by updating the "Last updated" date at the top of this page. Continued use of the app after changes constitutes acceptance of the new policy.
13Contact
Have questions?
For any questions, requests, or complaints regarding our privacy policy:
E-posta: destek@ekstreanaliz.com
Web: ekstreanaliz.com