The Polyteis account holder is an adult. Enter a child’s/student’s name, image, voice, diagnosis, medication, allergy or other sensitive information only if you have lawful authority, have given the required notice and have an appropriate legal basis. Do not record unnecessary data; assess cloud and AI options separately.
1. Controller and scope
For purposes of Türkiye’s Personal Data Protection Law No. 6698 (“KVKK”), the controller is independent developer Nidal Sancak, operating as Polyteis in Türkiye. Privacy requests: polyteisapp@gmail.com.
This notice covers polyteis.com, Polyteis mobile/desktop applications, account and cloud features, education modules, reporting and AI. A third party’s independent processing within its own service is subject to that party’s policy.
2. Intended users
Polyteis is administered by adults such as parents, guardians, educators, therapists and organisations. A child is a supervised beneficiary, not an independent account holder or contracting party. The account holder must have valid authority and a lawful basis for every person whose data they enter.
3. Categories of data we may process
| Category | Examples | Source |
|---|---|---|
| Account and contact | Name, email, phone, user ID, authentication provider/session | Account holder and sign-in provider |
| Child/student profile | Name, date of birth, gender, school/class, guardian details, photo, strengths, challenges, goals and motivators | Authorised adult or organisation |
| Sensitive/special-category information | Disability/diagnosis, health notes, allergies, medication, critical health, communication and sensory/behavioural needs | Authorised adult or organisation; optional |
| Educational and usage content | Activity results, scores, session notes, routines, cards, programs, IEP/report drafts, targets and progress | User and in-app interaction |
| Audio, images and derived measures | Microphone input, selected photo, camera frame; derived reading, voice, gaze, pose, expression or object-analysis results | Device sensors with user permission |
| AI content | Prompts, selected student context, responses, chat history and quota/usage information | User and Service |
| Technical and security | Device ID, platform/model, OS/app version, IP/time, App Check/integrity and root/jailbreak/hook/ADB risk signals | Device, app and security providers |
| Diagnostics | Crash reports, stack traces, performance and product interaction | App and Firebase Crashlytics |
| Communications | Email, support request, attachments and response history | You |
Polyteis does not sell personal data, build advertising profiles or intend to conduct third-party behavioural advertising tracking. If an app-store disclosure and actual data flow diverge, both this notice and the store disclosure will be corrected.
4. Local versus cloud processing
On-device processing
A substantial part of app data may be kept in encrypted local storage. Supported camera-based face, gaze, pose, expression and object analysis is performed on device where possible; live camera frames are not uploaded to Polyteis servers for that analysis.
Optional cloud backup
If enabled, selected profile, education, session and settings data may be sent to cloud infrastructure linked to your account. Disabling backup stops new backup operations, but previously transferred data may remain until you delete it or your deletion request is processed.
Network processing even when backup is off
Account sign-in, app integrity, security, abuse prevention, crash reporting, licence/store functions and cloud AI you expressly use may still communicate over the internet. These functions are separate from cloud backup.
5. Purposes, collection methods and legal bases
Data is collected automatically or partly automatically through the app, device, website, email, authentication providers and service-provider systems.
| Purpose | Primary legal basis |
|---|---|
| Account creation, sign-in, requested features, synchronisation and support | Entering into/performance of a contract; consent where required |
| Requested education, reporting, local analysis, cloud backup and AI | Contract performance; for optional features and special-category data, explicit consent or another appropriate KVKK condition where applicable |
| Security, fraud/abuse prevention, device integrity and debugging | Legitimate interests; establishment/exercise/protection of rights; legal obligation |
| Legal requests, records and disputes | Legal obligation; establishment/exercise/protection of rights |
| Communications and support | Contract performance, your request and legitimate interests |
| Optional processing based on affirmative permission | Explicit consent, which may be withdrawn |
Where explicit consent is required it is requested separately for a specific activity. Withdrawal does not affect prior lawful processing. Refusing data required by one feature may prevent only that feature from functioning.
6. Children’s data and special-category data
Disability, diagnosis, health, medication, allergy and data that may acquire biometric characteristics are highly sensitive. Complete only fields strictly necessary for the purpose. The account holder is responsible for notices to the child/student and guardian, institutional authority and an appropriate legal condition under KVKK Articles 5, 6 and 9.
Polyteis does not use these data for advertising, behavioural marketing, denying children rights through scoring or facial-recognition identity verification. Camera-derived measures are not designed as diagnoses or persistent biometric identity templates.
If you discover unauthorised child data, delete it in the app and contact us.
7. Camera, microphone, photo, speech and notification permissions
- Camera: used for live gaze/pose/expression, object and interaction modules. Frames are not sent to cloud backup unless you expressly save/upload content.
- Microphone and speech recognition: used for voice, reading or note features. Depending on device settings, the OS may send audio to a platform provider such as Apple or Google.
- Photos: used only for content/profile images you select; if cloud backup is on, the selected file or related data may be in backup scope.
- Notifications: local reminders are shown if you grant permission.
You can withdraw permissions in device settings. The relevant feature may stop working, while basic access will continue where possible.
8. Artificial-intelligence features
On-device Assist and cloud-based Polyteis AI chat have different data flows. On-device functions may generate output without sending input to an external AI provider. When you enable and use cloud AI, your prompt, selected student context and relevant knowledge may be sent to Google’s Gemini infrastructure through Firebase Cloud Functions. That function infrastructure may operate outside Türkiye, currently in a US region.
Specific phone, email and Turkish national-ID patterns may be redacted before transmission, but automated redaction is not perfect. Do not enter unnecessary identity, health or confidential organisational data. AI responses may be retained in chat history and security/quota records.
AI outputs are probabilistic and error-prone, not professional assessments. They must not be the sole basis for diagnosis, treatment, educational rights or another high-impact decision.
10. Retention, account deletion and anonymisation
- Local data: may remain until you delete it, reset app data or remove the app/device.
- Account and cloud data: remains while the account, purpose and legal basis continue, then is deleted, destroyed or anonymised under the request/retention process.
- AI chats and usage: may remain until you delete them or the service/security purpose ends; abuse/quota records may be held for a necessary limited period.
- Diagnostic/security logs: retained as needed to investigate faults, prevent attacks and protect legal rights.
- Legal records: may be held for periods required by applicable law.
You may use in-app “delete all data” and “delete account” tools. Deletion begins in active systems; security records, legally retained data and residual copies in ordinary backup cycles may remain for a limited period without active use. Contact us if you observe a technical issue.
KVKK requests are answered within 30 days at the latest. We may verify identity and clarify scope.
11. Security
Polyteis uses measures such as encrypted local storage, encryption in transit, Firebase security rules, App Check, authentication, device-integrity signals, access restrictions and data minimisation. Security and support capacity is limited by the experimental single-developer structure; no internet or storage method is completely secure.
Use a strong password, current device, screen lock, authorised staff access and secure backups. Promptly report suspected incidents to polyteisapp@gmail.com.
12. Your data-protection rights
Under KVKK Article 11 you may ask whether your data is processed; request information; learn the purpose and whether use is consistent with it; learn domestic/international recipients; request correction and notice to recipients; request deletion/destruction when grounds end and notice to recipients; object to adverse results produced exclusively by automated analysis; and seek compensation for damage caused by unlawful processing. You may also withdraw consent prospectively.
Email “KVKK Request” to polyteisapp@gmail.com with your name, relevant account email, request and sufficient verification information; do not send unnecessary identity documents. Requests are generally free, subject to any official fee schedule. If EEA/UK or other law applies, rights of access, correction, erasure, restriction, portability, objection and complaint to a regulator also remain available.
13. Website, cookies and external resources
polyteis.com is a static marketing site and does not place Polyteis behavioural-advertising or user-analytics cookies. Technical hosting logs may contain IP address, browser/device data, request time and security information. Loading Google Fonts may send your IP and request details to Google; using an email link may route communication through Google’s email infrastructure.
You can manage cookies and external-resource preferences in your browser. If non-essential analytics or marketing tools are introduced, an appropriate notice and consent mechanism will be provided.
14. Changes to this notice
This notice may change as the product, providers or law change. The current version and effective date appear here. Material changes to processing may be communicated in-app or by email and fresh consent will be obtained where required.
15. Contact the controller
Controller: Nidal Sancak — independent developer operating as Polyteis, Türkiye
Privacy/KVKK email: polyteisapp@gmail.com
Contact page: polyteis.com/en/contact
Include the relevant account email and a clear request. Additional verification may be required for security.