top of page

Privacy Policy

Effective Date: 02.10.2025

Last Updated: 01.07.2026

1. Who We Are
LazyLiz is provided by Ege Ferhat Kıymaz, established in Türkiye, acting as the data controller under GDPR and Türkiye’s KVKK.


2. What We Collect

  • Account Info: name, email (from Apple/Google sign‑in); optional profile fields.

  • User Content: documents, images, notes you upload (processed to generate summaries/quizzes).

  • Usage & Analytics: feature interactions, session metrics, quiz/game stats (via Firebase Analytics and/or Mixpanel, only if analytics is enabled).

  • Diagnostics: crash and performance data (e.g., Crashlytics/ANR).

  • Identifiers: user ID, device/instance IDs.

  • Push Notification Data: device push token, notification delivery and engagement status (e.g., delivered, opened) — processed via OneSignal.

  • Purchase Metadata: subscription/product status (no card data).

  • Onboarding Preferences: age range, study motivation, subject interests, 

  • and learning goals.

  • Device Settings: time zone (used to schedule streak resets and notifications).

  • We do not collect precise location, contacts, health, or browsing history.

Payments are processed by Apple App Store / Google Play. We do not process or store your card details.


3. Legal Bases (GDPR/KVKK)

  • Contract: account creation, content processing, quiz/summary features.

  • Legitimate Interests: security, fraud prevention, essential analytics/performance.

  • Legal Obligation: tax/financial records, responding to lawful requests.

  • Consent (where required): optional notifications or experimental features.

4. How We Use Data

  • Provide and operate the App (account, content processing, subscriptions).

  • Improve performance, fix errors, ensure security.

  • Comply with legal obligations.

  • Respond to user inquiries and provide customer support, including processing communications sent via email (e.g. support requests, error reports, screenshots, and technical files).

  • Diagnose and resolve technical issues and improve app stability based on user-initiated communications, with such communications retained only for as long as necessary for these purposes.

  • Send push notifications related to study reminders, streak alerts, and service updates (with your consent, granted via system-level permission during onboarding).

  • We do not sell personal data and do not use User Content to train our foundation models.

5. Sub‑processors (Data Processors)

  • Google Firebase (Auth, Firestore, Storage, Crashlytics/Analytics optional)

  • RevenueCat (subscription management)

  • Google Cloud Vertex AI (Gemini) (transforming User Content to generate outputs)

  • Apple App Store / Google Play (billing)

  • Mixpanel (product analytics)

  • OneSignal (push notification delivery)

These providers act as processors under DPAs and appropriate safeguards.


6. International Transfers

Data may be processed in the EU/EEA, US, and other regions by the above providers. We rely on Standard Contractual Clauses (SCCs) and apply technical/organizational safeguards (e.g., encryption in transit/at rest).


7. Retention

  • Account Data: scheduled to be deleted or anonymized from our active systems following the 30-day grace period, in accordance with our standard data-processing cycles, except where we must retain limited information for legal compliance, security, fraud prevention, or dispute resolution

  • Backup copies maintained by our service providers (e.g., Google Firebase) may persist for a limited time in accordance with their backup-cycle policies before being automatically removed.

  • User Content: scheduled for removal from our active systems within a reasonable timeframe when you delete specific content. Upon account deletion, content is marked for removal following the 30-day grace period.  

  • Backup & Residual Data: residual copies may remain temporarily in backups and technical logs, and will be removed in accordance with our service providers' (e.g., Google Firebase) standard backup-cycle and disaster recovery policies.

  • Usage / Diagnostics: retained for up to 14 months (may be aggregated or anonymized where feasible).

  • Purchase Records: retained only for legally required periods (e.g., tax or billing records).

8. Your Rights (GDPR/KVKK)
You may request access, correction, deletion, restriction/objection, portability, and withdraw consent where applicable.

You may manage or disable push notifications at any time through your device settings. Contact info@lazyliz.app. We respond within 30 days after verifying your identity. You may also lodge a complaint with KVKK (Türkiye) or your EU Supervisory Authority.


9. Children

The App is not directed to children under 13. Users aged 13–17 may receive push notifications (study reminders, streak alerts) via system-level permission granted during onboarding; a parent or guardian may disable these at any time through device settings. We do not perform cross‑app tracking or request ATT permissions.


10. Security & Breach
We implement appropriate technical and organizational measures (access controls, encryption, logging). In case of a personal data breach, we will notify users and authorities without undue delay as required by law.


11. Changes
We may update this Policy; material changes will be highlighted in‑App or on our website. Continued use after the "Last Updated" date signifies acceptance.


12. Contact
Ege Ferhat Kıymaz — Data Controller
Email: info@lazyliz.app
Address: Ankara, Turkey

bottom of page