VERSION 3 · 3 October 2026
Privacy and personal data
Developer and contact
Flower My Day is developed by Doğukan Yılmazel. For anything about your personal data, write to [email protected].
What we use
Account and sign-in: your Sign in with Apple identifier or email address, and any name and email Apple shares.
Profile: the name you use in the app, your time zone and language.
Your daily entries: the flower (mood) you pick each day, and optionally a note you write and a single photo you add. These entries make up your garden and are shown only to you.
Notifications: your notification preferences and time, your device push token, and whether in-app notifications were read.
Subscription: store transaction and subscription status. Your card number never reaches our servers.
Home Screen widget
To show your recent flowers, the widget keeps that information in the app's storage on your phone. Notes and photos are not passed to the widget.
What we don't do
We don't use your entries for advertising, profiling or sale, and we use no third-party advertising or analytics tools. We don't ask for your location.
Purposes and legal bases
Creating your account, signing you in, storing and showing your daily entries, sending reminders and managing subscription access are carried out as needed to perform the service agreement (Turkish KVKK Art. 5/2-c). Service security and abuse prevention rely on legitimate interest, provided your fundamental rights are not harmed (Art. 5/2-f). Processing needed to meet a legal obligation or to establish, exercise or defend a right relies on those grounds (Art. 5/2-ç and e).
Service providers
Email sign-in codes go through Postmark; subscription access through Apple and RevenueCat; notifications through Firebase Cloud Messaging and Apple Push Notification service; photo storage through Cloudflare R2. The API and MongoDB database run on server infrastructure. Cloudflare carries and protects website/API traffic. Messages to our support address are routed through Cloudflare Email Routing to our support inbox and processed only to answer you. Open and click tracking is off in sign-in emails. These providers may process data on infrastructure outside Türkiye.
Retention and deletion
Your account, profile, daily entries, photos and notification history are kept while your account is open. Sign-in codes are valid for five minutes and only their hashes are stored. Sessions last 30 days. Technical records of subscription events are cleaned up automatically 90 days after processing. Automatic clean-up may not happen at the exact second a period ends.
When you request deletion from Profile → Delete my account, access is closed and clean-up is targeted within seven days. It covers photo storage, account data, the Sign in with Apple link and the RevenueCat customer record. It does not delete Apple's own purchase records or cancel your subscription. See the Account deletion page for details.
Photos and sensitive information
Photos are re-processed on the server and embedded location and device metadata is removed. Please don't write identity documents, card details or other people's sensitive information in your notes; the service does not ask for them.
Website
The website uses no advertising or analytics cookies. The network and security infrastructure serving the site may process your IP address and request details to establish and protect the connection.
Your rights
Under KVKK you may learn whether your data is processed, request information, learn the purpose and whether it is used accordingly, know domestic/foreign recipients, request correction of incomplete or inaccurate data, request erasure or destruction under legal conditions and notification of these to recipients, object to a result against you arising solely from automated analysis, and claim compensation for unlawful processing. Send requests to [email protected]; we may ask for information to confirm the request belongs to your account. Never send a password or sign-in code.
