Gizlilik Politikası
Son güncelleme: 12 Temmuz 2026
Bu politika, Kangru iOS uygulamasının ("Kangru", "uygulama") kişisel verileri nasıl işlediğini açıklar. Kısa özet: Kangru’nun kendi sunucusu yoktur ve verilerini biz göremeyiz. Verilerin büyük kısmı yalnızca cihazında saklanır. İsteğe bağlı acil yardım bildirimi kullandığında bazı bilgiler geçici olarak Apple’ın CloudKit altyapısına yazılır (aşağıda ayrıntılı).
Kangru bilgilendirme amaçlı bir uygulamadır; tıbbi cihaz veya tıbbi tavsiye kaynağı değildir. Kan nakli ve bağış kararları yalnızca sağlık profesyonelleri tarafından, laboratuvar doğrulamasıyla verilir.
Hangi verileri işleriz?
- Profil bilgin: Görünen adın, kan grubun ve (istersen) telefon numaran. Telefon, hedefli acil bildirimleri alabilmen için yerelde tutulur.
- Tanıdık listen: Eklediğin kişilerin adı, yakınlık derecesi, kan grubu ve (istersen) telefon numarası.
- Kimlik: Apple ile Giriş’ten gelen anonim kullanıcı kimliği. Bu kimlik cihazının güvenli Keychain alanında saklanır.
- Uygulama ayarları: Dil tercihi, otomatik yedekleme sıklığı, isteğe bağlı Face ID / Touch ID uygulama kilidi gibi yerel tercihler.
Bu verilerin ana kopyası cihazında (Apple SwiftData veritabanı, Keychain ve uygulama ayarları) tutulur. Kangru’nun kendi sunucusu yoktur; hiçbir veri Kangru’ya gönderilmez.
Widget ve uygulama grubu
Ana ekran veya kilit ekranı widget’ları kullanırsan, görünen adın, kan grubun ve tanıdık sayısı gibi özet bilgiler cihazındaki uygulama grubu (App Group) alanında widget ile paylaşılır. Bu veri cihazda kalır; Kangru sunucusuna gitmez.
Yedekleme
İstersen tanıdık listenin yedeğini alabilirsin veya otomatik yedeklemeyi açabilirsin. Yedek dosyaları:
- Cihazında, uygulamanın kendi Belgeler klasöründe tutulur;
- AES-GCM ile, hesabına (Apple kullanıcı kimliğine) bağlı bir anahtarla şifrelenir;
- iOS tam dosya koruması ile saklanır (cihaz kilitliyken dosyalara erişilemez).
Cihazının iCloud / bilgisayar yedeğine dahil olup olmayacağı senin iOS yedekleme ayarlarına bağlıdır; bu Apple’ın standart cihaz yedeklemesidir ve Apple’ın gizlilik koşullarına tabidir. Uygulamadan çıkış veya profil sıfırlama, mevcut yedek dosyalarını otomatik silmez; istersen dosyaları kendin silebilirsin.
Acil yardım bildirimleri (isteğe bağlı)
Acil yardım bildirimi göndermeyi seçersen bu özellik Apple’ın iCloud (CloudKit) Public Database altyapısını kullanır. Bu, verinin cihaz dışına çıktığı ana durumdur ve şu şekilde çalışır:
- Bildirim yalnızca sen başlattığında gönderilir; arka planda otomatik gönderim yoktur.
- Özellik için cihazda iCloud hesabı gerekir.
- CloudKit kaydına yazılanlar: gönderen adı, kan grubu, konum / hastane metni (senin girdiğin veya seçtiğin), isteğe bağlı harita bağlantısı, bildirim metni ve alıcı telefon numaralarının SHA-256 ile geri döndürülemez hash’leri. Açık telefon numarası iletilmez.
- Kayıtlar yaklaşık 24 saat sonra geçersiz sayılır; gönderen cihaz süresi dolan kayıtları temizlemeye çalışır.
- Push bildiriminin kilit ekranı metni ad, kan grubu ve konum bilgisini içerebilir.
- Veri yalnızca Apple’ın altyapısından geçer; Apple dışında üçüncü tarafla paylaşılmaz.
- Bu özelliği hiç kullanmazsan CloudKit’e acil kaydı yazılmaz.
Hastane veya konum araması Apple MapKit ile yapılır; seçtiğin yer metni / bağlantısı mesaja ve (bildirim gönderirsen) CloudKit kaydına girer. Kangru sürekli GPS konumunu takip etmez ve konum geçmişi tutmaz.
Paylaşım özellikleri
- Mesaj / paylaşım sayfası: Liste veya acil mesaj paylaşımı, iOS paylaşım ekranıyla ve yalnızca senin onayınla gerçekleşir.
- QR kod: QR kodlar cihazında üretilir; içeriği (adlar, kan grupları ve isteğe bağlı telefonlar) yalnızca kodu taratan kişi görür.
- Yakındaki cihazla takas: İki Kangru kullanıcısı arasındaki kartvizit takası Bluetooth ve eşler arası Wi‑Fi üzerinden, internet olmadan, şifreli bağlantıyla yapılır. Kartta ad, kan grubu ve isteğe bağlı telefon olabilir. Her iki taraf da takası açıkça onaylar.
Rehber erişimi
- Tanıdık ekleme: iOS kişi seçiciyi kullanabilirsin. Uygulama yalnızca senin seçtiğin kişinin adını ve telefonunu alır.
- Acil bildirim alıcıları: Alıcı seçmek için rehber izni isteyebiliriz. İzin verirsen uygulama, seçim listesini göstermek üzere rehberindeki ad ve telefon numaralarını geçici olarak cihaz belleğinde okur. Bu liste Kangru sunucusuna yüklenmez, dosya olarak kopyalanmaz veya kalıcı olarak saklanmaz. Bildirim gönderirken yalnızca seçtiğin numaraların hash’leri CloudKit’e gider.
Face ID / Touch ID kilidi
İsteğe bağlı uygulama kilidi, biyometrik doğrulamayı yalnızca cihazda Apple’ın LocalAuthentication çerçevesiyle yapar. Biyometrik şablonlar Kangru’ya veya başka bir sunucuya gönderilmez.
Toplamadıklarımız
- Analitik veya kullanım verisi toplamayız.
- Reklam göstermeyiz; reklam ağlarıyla çalışmayız.
- Üçüncü taraf izleyici veya SDK kullanmayız.
- Kangru’nun kendi arka uç sunucusu yoktur; veriler Kangru’ya iletilmez.
Uygulama içi satın alma
“Vişne suyu ısmarla” desteği tamamen isteğe bağlıdır ve ödeme Apple’ın App Store (StoreKit) altyapısıyla gerçekleşir. Ödeme veya kart bilgini görmeyiz.
Verilerin ve hesabın silinmesi
- Tanıdıklarını tek tek silebilirsin.
- Profil → çıkış akışından verilerini silip çıkabilirsin; bu, cihazındaki ilgili profil ve tanıdık kayıtlarını ve Keychain’deki oturum kimliğini kaldırır.
- Uygulamayı cihazdan silmek, cihazda kalan uygulama verilerini de siler.
- Daha önce gönderilmiş CloudKit acil kayıtları ve push abonelikleri, çıkış sırasında otomatik olarak her zaman temizlenmeyebilir; süre dolunca geçersizleşirler. Yardım için [email protected] adresine yazabilirsin.
Çocukların gizliliği
Kangru çocuklara özel bir uygulama değildir ve yaş doğrulaması yapmaz. Kangru’ya (kendi sunucumuza) kişisel veri göndermeyiz. Aile listesine eklenen kayıtlar — çocuklara ait kayıtlar dahil — yalnızca cihaz sahibinin kontrolündedir. 13 yaşından küçüklerin kullanımı ebeveyn / vasi sorumluluğundadır.
Değişiklikler
Bu politika değişirse güncel sürüm bu sayfada yayımlanır ve tarih güncellenir.
İletişim
Sorular için: [email protected]
Privacy Policy
Last updated: July 12, 2026
This policy explains how the Kangru iOS app ("Kangru", "the app") handles personal data. The short version: Kangru runs no servers of its own and cannot see your data. Most data stays only on your device. If you use optional emergency alerts, some information is written temporarily to Apple’s CloudKit infrastructure (details below).
Kangru is an informational app; it is not a medical device or a source of medical advice. Transfusion and donation decisions are made only by healthcare professionals with laboratory verification.
What data do we process?
- Your profile: Display name, blood type, and (optionally) your phone number. The phone number is stored locally so you can receive targeted emergency alerts.
- Your relatives list: Names, relation, blood type, and (optionally) phone numbers of people you add.
- Identity: The anonymous user identifier from Sign in with Apple, stored in your device’s secure Keychain.
- App settings: Local preferences such as language, automatic backup frequency, and an optional Face ID / Touch ID app lock.
The primary copy of this data lives on your device (Apple SwiftData, Keychain, and app settings). Kangru operates no servers of its own; nothing is ever sent to Kangru.
Widgets and App Group
If you use home-screen or lock-screen widgets, summary data such as your display name, blood type, and contact counts is shared with the widget through an on-device App Group container. This data stays on the device; it is not sent to a Kangru server.
Backups
You can create backups of your relatives list manually or enable automatic backups. Backup files are:
- Kept on your device, in the app’s own Documents folder;
- Encrypted with AES-GCM using a key derived for your account (Apple user ID);
- Stored with iOS complete file protection (inaccessible while the device is locked).
Whether they are included in your iCloud / computer device backup depends on your own iOS backup settings; that is Apple’s standard device backup, governed by Apple’s privacy terms. Signing out or resetting your profile does not automatically delete existing backup files; you can remove those files yourself.
Emergency alerts (optional)
If you choose to send an emergency alert, this feature uses Apple’s iCloud (CloudKit) Public Database. This is the main case where data leaves your device, and it works like this:
- Alerts are sent only when you initiate them; there is no automatic background sending.
- An iCloud account on the device is required for this feature.
- Written to the CloudKit record: sender name, blood type, location / hospital text (as you enter or select it), optional maps link, alert text, and SHA-256 irreversible hashes of recipient phone numbers. Plain phone numbers are never transmitted.
- Records are treated as expired after about 24 hours; the sending device attempts to prune expired records.
- The lock-screen push text may include name, blood type, and location.
- Data passes only through Apple’s infrastructure; it is not shared with any third party besides Apple.
- If you never use this feature, no emergency record is written to CloudKit.
Hospital or place search uses Apple MapKit; the place text / link you choose goes into the message and (if you send an alert) the CloudKit record. Kangru does not continuously track GPS location and does not keep a location history.
Sharing features
- Messages / share sheet: Sharing your list or an emergency message happens through the iOS share sheet and only with your confirmation.
- QR codes: QR codes are generated on your device; their content (names, blood types, and optional phones) is visible only to the person who scans the code.
- Nearby exchange: Card exchange between two Kangru users happens over Bluetooth and peer-to-peer Wi‑Fi, without internet, through an encrypted connection. A card may include name, blood type, and optional phone. Both sides explicitly confirm the exchange.
Contacts access
- Adding a relative: You may use the iOS contact picker. The app receives only the name and phone number of the person you select.
- Emergency alert recipients: We may ask for contacts permission so you can pick recipients. If you grant it, the app temporarily reads names and phone numbers from your address book into device memory to show a selection list. That list is not uploaded to a Kangru server, not copied as a file, and not kept permanently. When an alert is sent, only hashes of the numbers you selected go to CloudKit.
Face ID / Touch ID lock
The optional app lock uses biometric authentication only on-device through Apple’s LocalAuthentication framework. Biometric templates are never sent to Kangru or any other server.
What we don’t collect
- No analytics or usage data.
- No ads; no ad networks.
- No third-party trackers or SDKs.
- No Kangru backend of our own; data is not transmitted to Kangru.
In-app purchases
The “buy us a sour cherry juice” tip is entirely optional and processed by Apple’s App Store (StoreKit). We never see your payment or card details.
Deleting your data and account
- You can delete individual relatives.
- From Profile → sign-out, you can delete your data and sign out; this removes the related profile and relative records on the device and the Keychain session identity.
- Deleting the app from the device also removes remaining on-device app data.
- Previously sent CloudKit emergency records and push subscriptions may not always be cleared automatically on sign-out; they expire after their lifetime. Contact [email protected] if you need help.
Children’s privacy
Kangru is not directed at children and does not verify age. We do not send personal data to Kangru (we have no server of our own). Records added to the family list — including records about children — are solely under the device owner’s control. Use by children under 13 is the responsibility of a parent or guardian.
Changes
If this policy changes, the current version will be published on this page with an updated date.
Contact
Questions: [email protected]