Skip to main content
Polyteis
Home500 Open ProgramsModulesAbout PolyteisAccessibilityContact
TREN
Join the beta
Home500 Open ProgramsModulesAbout PolyteisAccessibilityContactTürkçe

Privacy

Privacy Policy and KVKK Transparency Notice

This notice explains what Polyteis processes and why, the difference between local and cloud processing, potential recipients and your rights.

Version 1.0Effective: 31 July 2026Last updated: 31 July 2026

Contents

  1. Controller and scope
  2. Intended users
  3. Data categories
  4. Local and cloud processing
  5. Purposes and legal bases
  6. Children and sensitive data
  7. Device permissions
  8. Artificial intelligence
  9. Sharing and providers
  10. Retention and deletion
  11. Security
  12. Your rights
  13. Website and cookies
  14. Changes
  15. Contact
Before entering child or health data

The Polyteis account holder is an adult. Enter a child’s/student’s name, image, voice, diagnosis, medication, allergy or other sensitive information only if you have lawful authority, have given the required notice and have an appropriate legal basis. Do not record unnecessary data; assess cloud and AI options separately.

1. Controller and scope

For purposes of Türkiye’s Personal Data Protection Law No. 6698 (“KVKK”), the controller is independent developer Nidal Sancak, operating as Polyteis in Türkiye. Privacy requests: polyteisapp@gmail.com.

This notice covers polyteis.com, Polyteis mobile/desktop applications, account and cloud features, education modules, reporting and AI. A third party’s independent processing within its own service is subject to that party’s policy.

2. Intended users

Polyteis is administered by adults such as parents, guardians, educators, therapists and organisations. A child is a supervised beneficiary, not an independent account holder or contracting party. The account holder must have valid authority and a lawful basis for every person whose data they enter.

3. Categories of data we may process

CategoryExamplesSource
Account and contactName, email, phone, user ID, authentication provider/sessionAccount holder and sign-in provider
Child/student profileName, date of birth, gender, school/class, guardian details, photo, strengths, challenges, goals and motivatorsAuthorised adult or organisation
Sensitive/special-category informationDisability/diagnosis, health notes, allergies, medication, critical health, communication and sensory/behavioural needsAuthorised adult or organisation; optional
Educational and usage contentActivity results, scores, session notes, routines, cards, programs, IEP/report drafts, targets and progressUser and in-app interaction
Audio, images and derived measuresMicrophone input, selected photo, camera frame; derived reading, voice, gaze, pose, expression or object-analysis resultsDevice sensors with user permission
AI contentPrompts, selected student context, responses, chat history and quota/usage informationUser and Service
Technical and securityDevice ID, platform/model, OS/app version, IP/time, App Check/integrity and root/jailbreak/hook/ADB risk signalsDevice, app and security providers
DiagnosticsCrash reports, stack traces, performance and product interactionApp and Firebase Crashlytics
CommunicationsEmail, support request, attachments and response historyYou

Polyteis does not sell personal data, build advertising profiles or intend to conduct third-party behavioural advertising tracking. If an app-store disclosure and actual data flow diverge, both this notice and the store disclosure will be corrected.

4. Local versus cloud processing

On-device processing

A substantial part of app data may be kept in encrypted local storage. Supported camera-based face, gaze, pose, expression and object analysis is performed on device where possible; live camera frames are not uploaded to Polyteis servers for that analysis.

Optional cloud backup

If enabled, selected profile, education, session and settings data may be sent to cloud infrastructure linked to your account. Disabling backup stops new backup operations, but previously transferred data may remain until you delete it or your deletion request is processed.

Network processing even when backup is off

Account sign-in, app integrity, security, abuse prevention, crash reporting, licence/store functions and cloud AI you expressly use may still communicate over the internet. These functions are separate from cloud backup.

5. Purposes, collection methods and legal bases

Data is collected automatically or partly automatically through the app, device, website, email, authentication providers and service-provider systems.

PurposePrimary legal basis
Account creation, sign-in, requested features, synchronisation and supportEntering into/performance of a contract; consent where required
Requested education, reporting, local analysis, cloud backup and AIContract performance; for optional features and special-category data, explicit consent or another appropriate KVKK condition where applicable
Security, fraud/abuse prevention, device integrity and debuggingLegitimate interests; establishment/exercise/protection of rights; legal obligation
Legal requests, records and disputesLegal obligation; establishment/exercise/protection of rights
Communications and supportContract performance, your request and legitimate interests
Optional processing based on affirmative permissionExplicit consent, which may be withdrawn

Where explicit consent is required it is requested separately for a specific activity. Withdrawal does not affect prior lawful processing. Refusing data required by one feature may prevent only that feature from functioning.

6. Children’s data and special-category data

Disability, diagnosis, health, medication, allergy and data that may acquire biometric characteristics are highly sensitive. Complete only fields strictly necessary for the purpose. The account holder is responsible for notices to the child/student and guardian, institutional authority and an appropriate legal condition under KVKK Articles 5, 6 and 9.

Polyteis does not use these data for advertising, behavioural marketing, denying children rights through scoring or facial-recognition identity verification. Camera-derived measures are not designed as diagnoses or persistent biometric identity templates.

If you discover unauthorised child data, delete it in the app and contact us.

7. Camera, microphone, photo, speech and notification permissions

  • Camera: used for live gaze/pose/expression, object and interaction modules. Frames are not sent to cloud backup unless you expressly save/upload content.
  • Microphone and speech recognition: used for voice, reading or note features. Depending on device settings, the OS may send audio to a platform provider such as Apple or Google.
  • Photos: used only for content/profile images you select; if cloud backup is on, the selected file or related data may be in backup scope.
  • Notifications: local reminders are shown if you grant permission.

You can withdraw permissions in device settings. The relevant feature may stop working, while basic access will continue where possible.

8. Artificial-intelligence features

On-device Assist and cloud-based Polyteis AI chat have different data flows. On-device functions may generate output without sending input to an external AI provider. When you enable and use cloud AI, your prompt, selected student context and relevant knowledge may be sent to Google’s Gemini infrastructure through Firebase Cloud Functions. That function infrastructure may operate outside Türkiye, currently in a US region.

Specific phone, email and Turkish national-ID patterns may be redacted before transmission, but automated redaction is not perfect. Do not enter unnecessary identity, health or confidential organisational data. AI responses may be retained in chat history and security/quota records.

AI outputs are probabilistic and error-prone, not professional assessments. They must not be the sole basis for diagnosis, treatment, educational rights or another high-impact decision.

9. Disclosures, service providers and international transfers

To the extent needed for a function, recipients/processors may include:

  • Google/Firebase: Authentication, Firestore, Cloud Functions, App Check, Crashlytics, Google Sign-In, Gemini and website hosting;
  • Apple and Google platform services: Apple/Google Sign-In, OS speech/voice functions, app stores and device integrity;
  • Security providers such as Talsec/freeRASP: app/device integrity and threat signals;
  • Email and infrastructure providers: support communications and technical operation;
  • Authorities and advisers: where needed for law, security or establishment, exercise or protection of legal rights.

These providers may operate systems outside Türkiye, so data may be transferred and processed internationally. A transfer relies on a valid mechanism under KVKK Article 9, such as an adequacy decision, appropriate safeguard/standard contract, applicable incidental case or explicit consent where required. An optional feature requiring international transfer may remain disabled if no valid mechanism is available.

Polyteis does not sell or rent personal data. Processors are expected to act only on instructions and for service purposes; a provider’s own policy may separately apply where you use its independent service.

10. Retention, account deletion and anonymisation

  • Local data: may remain until you delete it, reset app data or remove the app/device.
  • Account and cloud data: remains while the account, purpose and legal basis continue, then is deleted, destroyed or anonymised under the request/retention process.
  • AI chats and usage: may remain until you delete them or the service/security purpose ends; abuse/quota records may be held for a necessary limited period.
  • Diagnostic/security logs: retained as needed to investigate faults, prevent attacks and protect legal rights.
  • Legal records: may be held for periods required by applicable law.

You may use in-app “delete all data” and “delete account” tools. Deletion begins in active systems; security records, legally retained data and residual copies in ordinary backup cycles may remain for a limited period without active use. Contact us if you observe a technical issue.

KVKK requests are answered within 30 days at the latest. We may verify identity and clarify scope.

11. Security

Polyteis uses measures such as encrypted local storage, encryption in transit, Firebase security rules, App Check, authentication, device-integrity signals, access restrictions and data minimisation. Security and support capacity is limited by the experimental single-developer structure; no internet or storage method is completely secure.

Use a strong password, current device, screen lock, authorised staff access and secure backups. Promptly report suspected incidents to polyteisapp@gmail.com.

12. Your data-protection rights

Under KVKK Article 11 you may ask whether your data is processed; request information; learn the purpose and whether use is consistent with it; learn domestic/international recipients; request correction and notice to recipients; request deletion/destruction when grounds end and notice to recipients; object to adverse results produced exclusively by automated analysis; and seek compensation for damage caused by unlawful processing. You may also withdraw consent prospectively.

Email “KVKK Request” to polyteisapp@gmail.com with your name, relevant account email, request and sufficient verification information; do not send unnecessary identity documents. Requests are generally free, subject to any official fee schedule. If EEA/UK or other law applies, rights of access, correction, erasure, restriction, portability, objection and complaint to a regulator also remain available.

13. Website, cookies and external resources

polyteis.com is a static marketing site and does not place Polyteis behavioural-advertising or user-analytics cookies. Technical hosting logs may contain IP address, browser/device data, request time and security information. Loading Google Fonts may send your IP and request details to Google; using an email link may route communication through Google’s email infrastructure.

You can manage cookies and external-resource preferences in your browser. If non-essential analytics or marketing tools are introduced, an appropriate notice and consent mechanism will be provided.

14. Changes to this notice

This notice may change as the product, providers or law change. The current version and effective date appear here. Material changes to processing may be communicated in-app or by email and fresh consent will be obtained where required.

15. Contact the controller

Controller: Nidal Sancak — independent developer operating as Polyteis, Türkiye

Privacy/KVKK email: polyteisapp@gmail.com

Contact page: polyteis.com/en/contact

Include the relevant account email and a clear request. Additional verification may be required for security.

Polyteis

A special-education environment used together by families and professionals for disabled and differently learning individuals.

Product

500 Open ProgramsModulesAbout Polyteis

Support & Legal

AccessibilityContactPrivacy PolicyTerms of Use

Language

TürkçeEnglish
© 2026 Polyteis. All rights reserved.Made with care for families.