📅 Last Updated: August 21, 2026 ⚡ Effective Date: August 21, 2026 🏷️ Version: 1.0

ANKORA — PRIVACY POLICY AND TERMS OF USE

This document contains the Privacy Policy, the Personal Data Protection and Processing Disclosure Statement (KVKK / GDPR / CCPA), and the Terms of Use and Conditions of Service (Terms of Service / EULA) governing the use of the Ankora mobile application (“Application”, “Ankora”, “We”, or “Service”).

By downloading, creating an account on, or using Ankora, you declare that you have read, understood, and agreed to all terms and data processing principles set forth in this agreement.

SECTION 1: PRIVACY POLICY AND KVKK / GDPR DISCLOSURE TEXT

1. Data Controller and General Information

Pursuant to the Law on the Protection of Personal Data No. 6698 (“KVKK”) and the European Union General Data Protection Regulation (“GDPR”), your personal data is processed by the Ankora Development Team in the capacity of data controller within the scope described below.

  • Application: Ankora — Medical Flashcard and Spaced Repetition Platform
  • Data Controller: Ankora Team (MedXLab)
  • Contact & Privacy Email: ancoracards@gmail.com
  • Website: https://ankoracards.com
  • Platform: Android (Google Play Store)

Definitions

  • Service: The Ankora mobile application and associated cloud infrastructure.
  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Data Processor: Third-party service providers offering technical infrastructure on behalf of the data controller (Supabase, Google Cloud, n8n infrastructure, etc.).
  • User: The natural person who uses the Service and whose personal data is processed.

2. Collected Personal Data and Data Categories

Ankora collects the following data categories in order to provide you with an advanced spaced repetition algorithm and artificial intelligence-assisted deck generation experience:

3. Purposes and Legal Grounds for Processing Personal Data

Your personal data is processed based on the legal grounds specified in Articles 5 and 6 of the KVKK and Article 6 of the GDPR for the following purposes:

  1. Service Provision and Performance of Contract (KVKK Art. 5/2-c, GDPR Art. 6/1-b):
    • Creating user accounts and managing secure authentication processes,
    • Executing the personalized spaced repetition algorithm and presenting cards at the most optimal time,
    • Automatically synchronizing local data with the cloud across devices and after offline study sessions,
    • Defining Ankora Pro subscription rights and tracking usage quotas.
  2. AI-Powered Deck Generation (Explicit Consent and Performance of Service):
    • Scanning your uploaded academic study documents to automatically convert them into flashcard sets with questions, answers, and hints.
  3. Sending Personalized Notifications (Legitimate Interest and Consent):
    • Delivering instant notifications including morning briefings at your chosen study hours, evening reminders to preserve your streak, and deck generation status updates.
  4. Improving User Experience and Performance (KVKK Art. 5/2-f, GDPR Art. 6/1-f):
    • Calculating study statistics, success projections, and learning graphs,
    • Identifying in-app issues and implementing performance improvements.
  5. Fulfillment of Legal Obligations (KVKK Art. 5/2-ç, GDPR Art. 6/1-c):
    • Responding to lawful requests from authorized institutions and organizations, and ensuring compliance with consumer regulations.

Important Principle: Your data is strictly never used for advertisement display or ad targeting; it is never sold or rented to third parties.

4. Artificial Intelligence (AI) and Secure Infrastructure Integrations

Ankora works with industry-standard, trusted infrastructure providers to deliver an uninterrupted and high-performance service:

A. Google Gemini Artificial Intelligence Infrastructure

  • Processed Information: Course documents and texts uploaded to generate decks with artificial intelligence.
  • Purpose of Use: Extracting medical/academic concepts from uploaded materials to generate question-answer cards.
  • Privacy Guarantee: Uploaded documents are processed under Google Cloud enterprise data privacy standards. Your documents and personal data are NEVER used for the general training of any AI model. The processing session is terminated once the card generation process is completed.

B. Cloud Database and Secure Storage (Supabase)

  • Processed Information: User account information, profile details, encrypted authentication records, deck/card database, study logs, and uploaded documents.
  • Security Standard: Hosted on servers with international security standards (SOC 2). Database communications are protected by TLS 1.3 in transit and AES-256 encryption at rest on the server. Thanks to Row Level Security (RLS) architecture, each user can only access their own data.

C. Secure Card Generation Automation

  • Processed Information: Deck creation requests and file transfers.
  • Security Standard: Server communication is protected with secret tokens and SSL encryption.

D. Google Play Services

  • Processed Information: Basic profile information provided upon Google Sign-In (name, email, profile picture); Google Play verification tokens during Pro subscription transactions.

5. Sensitive Health Data and Patient Privacy Warning

🔒 PATIENT PRIVACY AND SPECIAL CATEGORY DATA WARNING

Ankora is designed for personal study and academic exam preparation. Users are strictly requested not to share real patient identifying information, patient clinical photographs, personal medical records, or third-party special category personal data in the cards they create or lecture notes they upload. Any liability arising from the upload of such data belongs to the user who uploaded it.

6. Application Permissions and Device Access

Ankora may request the following permissions from your device to perform its functions:

  1. Internet Access: Required for data synchronization, account login, and AI deck generation.
  2. Notification Permission: Used to send study reminders, streak recovery alerts, and deck-ready notifications based on user preference.
  3. Exact Alarm / Reminder Permission: Used to deliver punctual notifications at user-scheduled times (e.g., morning briefing or evening streak alert).
  4. File Picker Access: Used solely to allow the user to select and upload their own chosen study document or profile image. Other files on your device are never accessed.

*Note: Sensitive hardware permissions such as location, contacts, call logs, camera, or microphone are not requested by Ankora.*

7. Data Security, Retention, and International Transfer

  • Security Measures: All data communications take place encrypted over the SSL/TLS protocol. Passwords are cryptographically hashed and stored; they are never kept in plain text. Data isolation is ensured with Row Level Security (RLS).
  • Retention Period: Your personal data is stored as long as your account is active. Inactive accounts with no activity or login for 1 (one) year may be warned and deleted for security reasons.
  • International Transfer: Due to the servers of our cloud infrastructure (Supabase / Google Cloud), your data may be processed in secure global data centers. These transfers are carried out in full compliance with standard contractual clauses and international data protection standards.

8. Right to Data Deletion and Account Closure (Right to be Forgotten)

Ankora grants users full control over their data:

  1. In-App (Instant Deletion):
    By following the steps Profile > Settings > Delete My Account within the application, you can instantly and permanently delete your account, all flashcard decks, uploaded documents, and study history.
  2. Via Email (Within 48 Hours at the Latest):
    Users who have deleted the application from their device can request the deletion of their data by sending an email titled “Account and Data Deletion Request” from their registered email address to ancoracards@gmail.com. Requests are fulfilled completely within 48 hours at the latest.

Scope of Deletion: When an account is deleted, all your personal data, uploaded documents, and study records are completely and irreversibly destroyed from our active systems.

9. Children's Privacy

Ankora is designed for medical faculty students, healthcare professionals, and adult exam candidates. We do not knowingly collect personal data from individuals under 13 years of age (or the legal minimum age in the country of residence). If it is determined that data belonging to an individual under 13 has been uploaded to the system, such data will be deleted immediately.

10. Data Subject Rights (KVKK / GDPR / CCPA)

As a data subject, you have the right at any time to:

  • Learn whether your data is processed and request a copy of it (Data Portability),
  • Request rectification of inaccurate or incomplete information,
  • Request the complete erasure of your account and data,
  • Object to automated analysis and profiling results.

You may submit your requests to ancoracards@gmail.com.

© 2026 Ankora. All Rights Reserved.