Privacy Policy
Effective date: 21 August 2026 · Version: v10
Convenience translation: This English version is provided for convenience only. The Turkish original ("Netlik Gizlilik Politikası") is the governing text; in case of any conflict, the Turkish version prevails.
Netlik (the "App") is a family coordination application operated by Mustafa Uğur Serez, a natural person acting as data controller (the "Data Controller" or "we"). It helps parents (living together, living apart or divorced) and other people responsible for a child's care (invited caregivers such as guardians, grandparents or childminders) manage the child's calendar, handovers, messages, expenses, documents and decision processes in one place, with a reliable record. The App suits joint use by two parents, single-parent or one-sided use, and participation by one or more caregivers with limited access. With the users' explicit authorisation it may also be used with limited permissions by professionals such as lawyers, mediators and psychologists. This policy explains which personal data we process when you use the App, for which purposes and how. For the detailed disclosure required under Turkish data protection law, please also read the "KVKK Privacy Notice".
About our service providers. In this text, providers are identified by function and region. The current legal names, functions and countries of those providers are published on the separately maintained https://www.netlikapp.com/en/sub-processors page. When a provider changes, that page is updated; the substance of this policy does not change.
1. Data we process
Account information. Full name, e-mail, password (encrypted), and phone number if provided.
Family and child information. Family name, member and invitation records; child profile (name, date of birth, school/class, teacher details, school transport details, body measurements, notes). Information about a child is entered only by a parent/guardian; no account is created in a child's name.
Special categories of personal data (if you enter them). Allergy, blood type, regular medication and emergency notes you may add to a child profile, and documents you upload under the health category, may contain special categories of personal data (health data) within the meaning of Article 6 of the KVKK. Filling in these fields is entirely your choice. This data is processed solely on the basis of your explicit consent, to provide the service and enable family coordination. The user entering this information declares that they hold the legal authority required to share and have it processed. Health notes written on the child profile are visible to active members of the family space; documents uploaded under the health and legal categories are marked sensitive and are visible only to the uploader and to fully authorised parents/guardians.
Family structure is declaration-based. The family structure created in the App is based on the users' own declarations. Users accept that they hold the legal authority required for the people they invite to access the family space, and that they are responsible for the access permissions they grant to third parties. The Data Controller is not obliged to verify the accuracy of those declarations. The parent or legal representative is responsible for deciding whom to invite into the family space. The access scope of the caregiver role is fixed by the App and cannot be widened by the person issuing the invitation. For professional invitations (lawyer, mediator, psychologist) the permissions, scope and duration are chosen separately at invitation time and can be withdrawn at any point. Invitees can only act within the scope granted to them.
Coordination records. Calendar and handover events, messages, expense and approval requests, decision requests, dispute records, checklists, personal journal notes, court decisions and other documents you upload, and reports you generate.
Optional AI and OCR content. Only when you initiate the relevant action, the draft text selected for a calm-language suggestion, the receipt selected for expense scanning, or the document selected for protocol or court-document extraction is processed together with the necessary action context. Your full message history or child profile is not sent automatically. The scope of protocol/court-document extraction is explained separately in section 4.
Document bridge data. You can request a document from a third party who is not a Netlik user, such as a school, doctor or lawyer. A single-use, time-limited link is generated for that person; the masked IP address (final segment hidden) and truncated browser information of whoever opens the link are recorded together with the file they upload. Any e-mail or phone number you enter as your own note while preparing the link is also stored. Details are in section 4.
Technical data. Session and security records, a device identifier (token) for notifications, error and transaction logs, and limited product usage events in the production mobile App. Analytics events contain technical information such as feature, screen, result, count and risk category; raw message, document, health-note or child-profile content is not added to analytics events. In transaction logs the IP address is anonymized and device/browser information is truncated. No crash reporting is used.
Subscription data. Plan, purchase and subscription status. So that a subscription can be linked to your account correctly, the randomly generated user number of your Netlik account is transmitted to the subscription verification provider; your name, e-mail address and family data are not.
2. Purposes for which we use data
To provide the service and operate your account; to maintain a shared, reliable and tamper-evident record between parents and caregivers; to deliver notifications; to ensure security and prevent abuse; to comply with legal obligations; upon your request, to carry out data export and account deletion; to produce calm-language suggestions, receipt OCR and protocol or court-document extraction results only for actions you initiate; and to monitor secure and healthy operation through limited analytics records. Your personal data is not used for marketing, advertising or profiling; data relating to the child and the family is never used for commercial communication or advertising under any circumstances. You only receive service notifications (handover, approval, security).
3. Permanence of records
Netlik's purpose is to keep a reliable shared record. Sent messages and completed transaction and response history are permanent. For request-type records such as expenses, decisions and disputes, the requester may update or withdraw their own request before the other party's final action and where the App allows it; the audit trail of updates, withdrawals and counter-party responses is preserved. A requester cannot approve, reject or mark their own request as resolved; those actions can only be taken by the other party.
4. Who we share your data with
We do not sell or rent your data for advertising. Data is shared only with the limited service providers required to run the service, within the functions listed below. The current names and countries of those providers are published at https://www.netlikapp.com/en/sub-processors.
- Cloud infrastructure provider (EU / Germany) — hosting, database, file storage, authentication and server functions. All data in the App is held on this infrastructure. Documents are kept encrypted in a private area; sharing links are short-lived and signed.
- Push notification provider (USA) — delivery of notifications to your device. Notification content carries no sensitive detail; a fixed, privacy-preserving text is shown on the lock screen.
- Product analytics provider (USA) — measurement of limited feature and screen usage events in the production mobile App. Analytics events sent by Netlik do not include raw message, document, health-note or child-profile content.
- AI provider (USA, paid service) — relevant content is transmitted only for calm-language suggestions, selected receipt OCR, and selected protocol or court-document extraction actions that you initiate. Full message history or child profiles are not sent automatically. Under the paid-service terms, prompts, files and responses are not used to improve the provider's products or to train models. The provider may retain prompts, context and outputs for 55 days to prevent abuse and meet legal obligations; suspicious use may be reviewed by authorized personnel.
- Service e-mail provider (USA) — delivery of sign-up verification, family invitation, account-deletion completion and content-report outcome e-mails. The recipient e-mail address and fixed template text are processed for this purpose. For the deletion notice the recipient address is kept briefly in an encrypted notification queue; once delivery completes, the temporary recipient information is cleared.
- App stores and subscription verification provider (USA) — execution and verification of purchases and subscription status. The randomly generated user number of your account is transferred for this purpose. Full payment card details are never received by Netlik.
- Web hosting provider (USA) — hosting of web content at https://www.netlikapp.com and app.netlikapp.com; limited request-level technical records may be processed in this context.
Regular transfers to providers abroad are carried out on the basis of an applicable adequacy decision or appropriate safeguard under KVKK Article 9. Explicit consent is used as an exceptional transfer ground only for occasional transfers that meet the statutory conditions.
4/A. Protocol and court-decision extraction
When you upload your divorce settlement protocol or court decision and start the extraction, the entire document is transmitted to the AI provider. No single section is filtered out and sent on its own; the document is processed as a whole, including the reasoning, the facts and the parties' statements. For that reason we recommend reviewing the document's content before starting an extraction.
The extraction looks for the following fourteen headings used by the App: custody and visitation schedule; child and spousal support; expense sharing; school; school transport (company, plate, driver, times, contact); courses and activities; handover conditions; health-related decisions; emergency contacts and instructions; routine checklists; day-swap rules; people authorised to collect or contact the child (name and relationship); travel and passport consent; the contact schedule between the child and the parent who is not present. Provisions that fall under none of these headings (court fees, appeal deadlines, attorney costs, the divorce ruling itself) are not converted into structured data and are only listed as "out of scope".
Extracted information is shown to you as a summary first and is written into your records and calendar only if you approve it. Extraction can be wrong; the summary is informational and, in case of a dispute, the official or certified text of the document prevails. Netlik presents extracted information neutrally and produces no automatic notification, scoring or flagging accusing one party of a "breach" against the other.
4/B. Document bridge (receiving documents from non-users)
To request a document from a third party such as a school, doctor or lawyer, you can generate a single-use, time-limited link. That person is not a Netlik user, does not create an account and is not a party to the Terms of Use.
- The e-mail address or phone number you enter while preparing the link is optional and is stored only as your own note. Netlik sends nothing to that address; you deliver the link to the person yourself.
- The masked IP address and truncated browser information of whoever opens the link are recorded so that it can be evidenced who uploaded the file and when. This is also disclosed on the upload page.
- The uploaded file goes straight into the Documents section of your family space; documents arriving under the health and legal categories are marked sensitive.
- The link is single-use and stops working once it expires.
4/C. People you authorise
Additionally, at your request: people you invite to your family space and professionals you grant time-limited/scoped access to (lawyer, mediator, psychologist) can see records only within the scope you define. Where legally required, data may be shared with competent authorities to the extent required by law.
Netlik does not verify the family relationship between an invitee and the child, or whether the person sending the invitation is legally authorized to grant that access. It only creates the selected role and access scope technically. When sending an invitation, the user declares that they are legally authorized to grant access to the child's personal data. The user sending the invitation is responsible for granting incorrect or unauthorized access.
Invitation e-mail. Netlik sends the invitation to the e-mail address you enter when creating it. The holder of that address may not be a Netlik user yet; the address is processed solely to deliver the invitation and to track its status, and is not used for marketing. The content of the e-mail is fixed: the invitation link, the invitation code and its validity period. Delivery is made through an e-mail delivery provider, and a daily per-family sending limit is applied to limit abuse. If the invitation is not accepted, the record ceases to function when it expires.
4/D. Reporting inappropriate content
Inside the App you can report a message, a document or a person to us. This processes the identity of the reporting person, the selected reason, any note you write, and the identity and owner of the reported content. The purpose is to carry out the content moderation required by store policies and by law.
- The report goes only to Netlik; no one else in the family sees it.
- During review, only the reported record is read; surrounding correspondence is not scanned.
- After review, the content owner may receive a warning. The name of the reporting person is not disclosed in that warning.
- The outcome is communicated to the reporting person in every case.
- Reported content is not deleted; the integrity of the communication history is preserved.
- Netlik is not an emergency service and does not report to law enforcement on its own initiative; it responds to lawful requests to the extent required by law.
5. Security
Access to family data is restricted with row-level authorization; documents are kept in private, encrypted storage; critical operations are bound to tamper-evident transaction records; reports are sealed with a content verification code. No system is 100% secure; in the event of a breach, the notifications required by law will be made.
6. Retention and deletion
Your data is retained for as long as your account is active. From within the App you can request a data export package and initiate account deletion; if you no longer have access to the App, you can also submit your deletion request via https://www.netlikapp.com/en/account-deletion or by writing to netlikapp@gmail.com. A deletion request is not subject to a 30-day waiting period; it is processed automatically in the first 01:00 Europe/Istanbul run following identity verification, and an authorized administrator may process it earlier with fresh two-factor verification. The 30-day period applicable to data protection applications is a maximum response time, not a waiting period. When the operation completes, an automatic service notification is sent to your registered e-mail address.
Exactly what happens on deletion. Your credentials and directly identifying profile information are deleted: name, e-mail address, phone number, profile image, device notification identifiers and your in-app notifications. Sign-in is permanently disabled and the account cannot be reactivated; your personal journal and your private files are deleted.
What happens to shared records. Coordination records the two parents created together — approvals, handover entries, expense settlements, disputes — are not deleted. They belong not only to you but also to the other parent; deleting them at one party's request would destroy the other parent's own history and the record they may rely on in a legal dispute. Your name in those records is replaced by a fixed label and the records no longer carry identifying information.
We state plainly that this is not anonymisation: the records remain attached to the same participant identifier, and in a two-person family space the other parent continues to know whose record it is. What we perform is what the law calls pseudonymisation.
Retention period for shared records. Records are retained for as long as the family space is active — that is, as long as at least one parent keeps using it — because the purpose of retention continues during that time. When the last remaining full-access parent also deletes their account, the purpose ends and the records are deleted in full 2 years after that date. That two-year tail exists because proceedings may still require the record even after one party has left.
If an active legal hold exists, only the limited data explicitly selected in that decision is preserved for the relevant scope and duration. Deletion evidence is retained for at least three years. Other audit records, data protection application records and records subject to statutory retention obligations may be retained for the applicable periods in accordance with the law. Short-lived technical counters are automatically cleared after 7 days and server transaction logs after 30 days.
7. Children's privacy
The App is not directed at users under 18 and no account can be created in a child's name. "Child mode" is a restricted view on the parent's own device.
Special-category information about a child (health, allergy, blood type, medication notes and the like) can be entered or changed only by users with full parent/guardian authority; other caregivers invited to the family space (grandparents, childminders, handover delegates and so on) can access this information with view-only permission. Documents uploaded under the health and legal categories are additionally marked sensitive and are closed to caregivers. Inviting people who are not parents into the family space and granting them access is done by the decision of the authorised parent or parents. Every user's access within the family space is subject to the family space rules and to the role granted to them.
Scope of caregiver access. Caregivers (grandparents, childminders, handover delegates) can only reach the records needed to care for the child: the calendar and custody plan, the child profile, health and school information, activity and transport details, contact people, the child's needs notes, handover records and documents not marked sensitive. Caregivers cannot create or change any of these records; their access is limited to viewing. They cannot see the parents' messages to each other, expense records, decision requests, dispute records, generated reports or audit logs, and they cannot generate reports or export data.
8. Your rights
For your rights — including access, rectification, deletion, objection to processing and portability — please see the "KVKK Privacy Notice" and write to netlikapp@gmail.com.
9. Changes
We may update this policy. For material changes we will present the new version for your acceptance in the App; the current version is always published at https://www.netlikapp.com/en/privacy. Changes to the service provider list are announced at https://www.netlikapp.com/en/sub-processors.
Contact: Mustafa Uğur Serez · Liman Mahallesi, 23. Sokak, No: 2/5, Konyaaltı/Antalya/Türkiye · netlikapp@gmail.com