Skip to content
How it worksTrustFAQAbout
EN/TR
Get the app

Legal

Privacy Policy

What data Clidna processes, why, who it is shared with, how long it is kept, and how you exercise your rights.

Last updated: September 4, 2026

On this page

  1. 1. Controller and contact
  2. 2. How we collect your data
  3. 3. What we process
  4. 4. Special category (sensitive) data
  5. 5. Purposes and legal bases
  6. 6. Who we share data with
  7. 7. International transfers
  8. 8. Retention
  9. 9. How to exercise your rights
  10. 10. If you live in California (CCPA / CPRA)
  11. 11. What the export file does not contain
  12. 12. Notifications
  13. 13. The 18+ rule
  14. 14. Security
  15. 15. Cookies
  16. 16. Changes
  17. 17. Contact
On this page
  1. 1. Controller and contact
  2. 2. How we collect your data
  3. 3. What we process
  4. 4. Special category (sensitive) data
  5. 5. Purposes and legal bases
  6. 6. Who we share data with
  7. 7. International transfers
  8. 8. Retention
  9. 9. How to exercise your rights
  10. 10. If you live in California (CCPA / CPRA)
  11. 11. What the export file does not contain
  12. 12. Notifications
  13. 13. The 18+ rule
  14. 14. Security
  15. 15. Cookies
  16. 16. Changes
  17. 17. Contact

This text is a draft awaiting legal review and is not legal advice. A lawyer must review it before it is published. The {{ }} fields below — legal entity and contact address — must be filled in before this page can be entered into any store form. (The product domain was settled on 5 September 2026: clidna.com.) The text must not contradict docs/data-governance.md; if the two disagree, one of them is wrong and is corrected the same day.

This page also serves as the disclosure notice required by Article 10 of the Turkish Personal Data Protection Law No. 6698 (KVKK) and as the information notice required by Articles 13–14 of the GDPR.

#1. Controller and contact

Clidna is operated by {{TUZEL_KISI}}. {{TUZEL_KISI}} is the controller under the GDPR and the data controller under the Turkish KVKK. Address: {{TUZEL_KISI_ADRES}}.

For any request, objection, correction or question: support@clidna.com

If a data protection officer or representative is appointed, they will be named here.

#2. How we collect your data

We obtain your personal data only from what you give us and from what happens as you use the app. Collection is electronic: through the mobile app and the website, partly by automated means. We do not enrich your profile from other sources, data brokers or social networks. We collect no advertising identifier, we do not track you across ad networks, and we do not sell your data.

#3. What we process

Data classContents
Account dataEmail address, an irreversible hash of your password, date of birth, region, language preference, consent version, account status
Companion configurationYour character's personality configuration, portrait references and uniqueness fingerprint
Candidate cardsThe five candidate cards shown to you at the meeting moment. Candidates are not optimised against your profile; the only inputs are language and a seed
Relationship stateThe engine-computed state between you and the character: closeness, climate, conflict and repair state, departure ladder
The character's own life stateThe character's fictional day and story threads. This record carries none of your data; the engine is blind to you
Memory ledgerWhat the character remembers about you, each entry with its provenance and a sensitivity marker
Conversation contentThe messages you write and the character's replies
Scheduled touchesThe text of messages the character will send you later and has not delivered yet
Relationship eventsAn audit record of what happened and when, with its payload redacted
Safety eventsRestricted-access records produced by our safety checks. Records carrying a crisis signal are protected with health-data sensitivity
ReportsWhen you report a message: the message id, the reason you picked, any note you added and the review status. The message text is not copied into the report
ConsentsYour third-party AI consent and your special-category consent: given or not, to which version, when
Device and notification tokenThe device registration needed to deliver notifications: platform, push token, app version, language
Subscription entitlementThe entitlement record verified by the store: store, product id, transaction id, status and expiry
Model call accountingA business record counting how many calls were made. A text column is technically impossible in this record
Deletion requestsThe id of the deletion request and three timestamps. It is compliance evidence
Session and technical recordsA hash of your session token, rate-limit counters (pseudonymous), queue jobs (ids only), application logs (request id, path, status, duration)

Payment details never reach us. Card numbers, billing addresses and payment history stay with Apple and Google; we only receive the answer to "is this account's subscription valid".

#4. Special category (sensitive) data

While talking, you may say something about your health, your mental health, your sex life, your beliefs, your political views or your ethnic origin. Under KVKK Art. 6 this is special category personal data, and under GDPR Art. 9 it is special category data.

  • We do not ask you for this information; the app never poses such a question.
  • When it comes up in conversation, the message itself is processed so the service can work.
  • Writing it into the memory ledger as a lasting entry requires a separate, optional explicit consent from you. Without that consent, such details are not written to the ledger.
  • If you did give consent, those entries are held in the protected section of the ledger and can never be used as leverage in an argument, a reproach or any attempt to persuade you — at any intensity. This is one of the product's unchangeable rules.
  • You can withdraw the consent at any time in Settings.

You see the full consent text during sign-up and in Settings → Consents; the same text will also be published under the heading "Special Category Data Consent".

Crisis-signal records produced by our safety checks are protected with the same health-data sensitivity. They rest on vital interests and legal obligation rather than consent, and access to them is restricted.

#5. Purposes and legal bases

PurposeLegal basis (GDPR)KVKK equivalent
Providing the service (chat, memory, state)Performance of a contract (Art. 6(1)(b))Performance of a contract (Art. 5/2-c)
Account creation and authenticationPerformance of a contract (Art. 6(1)(b))Performance of a contract (Art. 5/2-c)
The 18+ age gateLegal obligation and legitimate interest (Art. 6(1)(c), (f))Legal obligation (Art. 5/2-ç); legitimate interest (5/2-f)
Safety checks and abuse preventionLegitimate interest (Art. 6(1)(f))Legitimate interest (Art. 5/2-f)
Handling a crisis signal and pointing to helpVital interests and substantial public interest (Art. 6(1)(d), 9(2)(c), 9(2)(g))Vital interests where consent is impossible (Art. 5/2-b)
Reviewing reports and moderating contentLegal obligation and legitimate interest (Art. 6(1)(c), (f))Legal obligation (Art. 5/2-ç); legitimate interest (5/2-f)
Subscription and entitlement recordsPerformance of a contract, legal obligation (Art. 6(1)(b), (c))Performance of a contract; legal obligation
Sending notificationsConsent (device permission)Explicit consent (Art. 5/1)
Writing special-category detail into the ledgerExplicit consent (Art. 9(2)(a))Explicit consent (Art. 6/2)
Answering legal requests and compliance dutiesLegal obligation (Art. 6(1)(c))Legal obligation (Art. 5/2-ç)

You can object to processing we base on legitimate interest; writing to support@clidna.com is enough.

Automated decision-making: our relationship engine computes state through deterministic rules. That computation produces no decision about you with legal or similarly significant effects (GDPR Art. 22). We do not profile you for advertising.

#6. Who we share data with

We do not sell your data and we share it with no one for marketing. The processors we use to run the service are listed below.

Read the status column carefully: rows marked "planned" are not live on the day this text was written. No user data goes to that provider today; the row describes what will be true once the service is switched on. When a row goes live, this table is updated the same day.

ProviderWhat forData it receivesRegionStatus
CloudflareEdge network, attack protection, app hosting, portrait object storeAll HTTP traffic, request metadata, IPContainers and object store: EU; edge is globalplanned
Neon (alternative: Supabase)PostgreSQL databaseAll the stored data listed aboveEUplanned
Upstash (alternative: Redis Cloud)Session, queue and counter storeSession hashes, job ids, countersEUplanned
GroqSafety classification (input and output checks)Message text and the safety envelopeUSAplanned
Amazon Web Services (Bedrock)Backup for the same safety classificationMessage text and the safety envelopeEU (Ireland)planned
Mistral AIState and memory proposals; output moderationThe compiled context envelope; the replyEUplanned
OpenAIReply generation and memory search vectorsThe compiled context envelope; memory textUSAplanned
DeepInfraFailover for reply generationThe compiled context envelopeUSAplanned
ExpoNotification deliveryDevice push token and a short notification titleUSAplanned
Apple and GoogleIn-app purchases and entitlement verificationStore transaction id and subscription statusThe provider's own networkplanned

The current, version-numbered list of AI providers is shown on the consent screen inside the app. The list on this page and the list in the app come from the same canonical source and are tied together by an automated test; one cannot change while the other goes stale.

You can withdraw your consent from inside the app. Once withdrawn, no new message can be sent, because reply generation does not work without these providers.

Apart from that, we share your data only when legally compelled — on a valid court order or a request from a competent authority. When such a request arrives we tell you about it, unless we are legally forbidden to.

#7. International transfers

Some of our providers are located outside Türkiye and the European Economic Area.

  • KVKK: transfers are made by signing a standard contract under the 2024 regime of Article 9 of Law No. 6698 and notifying the Turkish Data Protection Authority. No provider row goes live before that contract is signed.
  • GDPR: transfers outside the European Economic Area rely on the European Commission's standard contractual clauses (SCCs) plus supplementary technical measures where needed.
  • We do not work with an AI provider without a written record that our inputs will not be used to train models.

If you want to know which mechanism covers which provider, write to support@clidna.com.

#8. Retention

WhatHow long
Your account and everything on itFor as long as your account is open
Your character and the relationshipFor as long as the character lives. Deletion is permanent; there is no archive
The memory ledgerNever deleted; it decays — old, unrepeated entries lose visibility
Sessions, counters and queue jobsShort-lived; removed when they expire or when the job finishes
The deletion request recordSurvives the permanent deletion; carries no personal data, it is evidence
Model call accountingKept indefinitely; de-identified during the permanent deletion

When you delete your account, the permanent deletion runs after a 7-day waiting period. Once it has run, only two things remain: the deletion request record kept as compliance evidence, and de-identified model call accounting. No row tied to you remains in any other table.

#9. How to exercise your rights

Under Article 11 of the KVKK and Articles 15–22 of the GDPR you have the right to: learn whether your personal data is being processed and obtain information about it, learn the purpose of the processing and whether the data is used in line with that purpose, know the third parties inside and outside the country to whom your data has been transferred, have incomplete or incorrect data corrected, request erasure or destruction, require that corrections and erasures be notified to those third parties, object to a result reached solely through automated analysis that works against you, and claim compensation for damage caused by unlawful processing. On top of that, the GDPR gives you the rights of portability, restriction of processing and withdrawal of consent.

Here is how:

  • Get a copy (access and portability): Settings → Your data → "Download my data". Your whole account comes down in a single machine-readable file; there is no pagination and nothing is silently truncated.
  • Delete: Settings → Your data → "Delete account", or https://clidna.com/account/delete. Even if you have uninstalled the app you can sign in there and file the request. You can change your mind within 7 days.
  • Correct: you can fix an entry from the screen that shows what the character remembers; the correction is stored together with its source.
  • Close a subject: saying "don't bring this up again" in the conversation suppresses that subject — the entry stays, but the character never raises it on its own.
  • Withdraw a consent: Settings → Consents.
  • Objections, restriction and everything else: support@clidna.com

We answer requests within 30 days at the latest. Using these rights costs you nothing in the product: your price does not change and your character does not reproach you for it.

Your right to complain: in Türkiye to the Personal Data Protection Authority, and in the European Economic Area to the data protection authority of the country you are in.

#10. If you live in California (CCPA / CPRA)

Categories of personal information we have collected in the last twelve months: identifiers (email address, account id, device push token, IP address), commercial information (subscription status), internet activity (in-app technical logs) and sensitive personal information (the content of the messages you write and the entries in the memory ledger, which may touch on subjects such as health or sex life).

  • We do not sell this information and we do not share it in the behavioural-advertising sense. We did not in the last twelve months either.
  • We use sensitive personal information only to provide the service, keep it safe and meet our legal duties; we do not use it to draw inferences and sort you into categories.
  • You can use your rights to know, delete, correct and limit the use of sensitive information through the routes in section 9 above or by writing to support@clidna.com.
  • We will not discriminate against you for using these rights.
  • You may also act through an authorised agent; we verify the agent's authority.

#11. What the export file does not contain

The file does not contain your password hash (an authentication secret), search vectors derived from your content, or restricted-access safety records. Each of these omissions is declared as a code inside the file itself — the gap is counted, not hidden.

This is not a refusal of your rights but a difference of channel. Showing safety records self-service would open a feedback channel to anyone trying to defeat our safety checks. If you ask for those records, we provide them through an operator once we have verified your identity: support@clidna.com.

#12. Notifications

A notification on your phone never shows the message text; it only tells you that something new has happened. Content carrying negative emotion never enters the notification channel. You can turn notification permission off at any time in your device settings; the app keeps working with notifications off.

Quiet hours are the window you choose. Nothing writes to you on its own during it.

#13. The 18+ rule

The app is for adults aged 18 and over only. A date of birth is required at sign-up and cannot be changed later. Sign-ups identified as under 18 are refused, and we do not knowingly collect data from those people. In the United States store we also read the age-range signal reported by the device; if that signal says "under 18", the sign-up is refused even when it contradicts what was typed.

If you notice that a child has given us data, write to support@clidna.com and we will delete the record.

#14. Security

  • Passwords are stored irreversibly (argon2id); a plain-text password is kept nowhere.
  • All traffic is encrypted in transit.
  • Every query touching user data is scoped to one account; another user's data cannot technically enter the same query, and automated leak tests check this continuously.
  • Sensitive fields are redacted in application logs; raw prompt logging is off by default.
  • Safety records are restricted-access.
  • Even so, no system is flawless. If a breach affects your personal data, we notify the competent authorities and you where the law requires it.

#15. Cookies

The mobile app uses no cookies. The website uses only two technical cookies; both are strictly necessary and need no consent:

  • Session cookie (asena_session): remembers that you are signed in. Its contents are an opaque token that cannot be read in the browser.
  • Language cookie (asena_locale): remembers the interface language. It lasts a year and carries no identity data.

We use no analytics cookies, no advertising cookies and no third-party trackers. That is why you never see a cookie banner here.

#16. Changes

Whenever this page changes, the "last updated" date at the top is refreshed. We also announce material changes inside the app, and if the list of AI providers changes we ask for your consent again.

#17. Contact

Questions, requests and objections: support@clidna.com

Related pages: Terms of Use · Crisis Protocol · Support

Related pages

  • Terms of Use›
  • Support›
  • Safety›
  • Delete account›

An AI character with a life of her own.

Clidna

  • How it works
  • Download
  • FAQ

Company

  • About
  • Press
  • Support

Trust

  • Trust & Safety
  • Crisis protocol
  • Privacy
  • Terms
  • Delete account

Clidnas are AI characters, not real people. 18+.

This site uses no cookies or trackers.

© 2026 Clidna

EN/TR