PRIVACY POLICY Application: Dat by day Baby Tracker ("the App") Developer / Data Controller: Mobisoft Yazilim ("we", "us", "our") Contact: destek@annelertoplandik.com Effective Date: May 1, 2026 Last Updated: May 1, 2026 This Privacy Policy explains how we collect, use, store, share and protect personal information when you use the App on iOS. By creating an account or using the App, you confirm that you have read and understood this Policy. If you do not agree, please do not use the App. This Policy is designed to comply with the Apple App Store Review Guidelines (Section 5.1 — Privacy), Apple App Tracking Transparency (ATT), the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and the Turkish Personal Data Protection Law No. 6698 (KVKK). ------------------------------------------------------------------------ 1. WHO THIS APP IS FOR ------------------------------------------------------------------------ The App is intended for parents, legal guardians, and caregivers aged 18 or older who want to track the daily care of an infant or young child. The App is not directed to children under the age of 13 and we do not knowingly collect personal information from children. All data entered about a baby is provided voluntarily by an adult user about a child for whom they hold parental responsibility or legal guardianship. If you believe a child has provided us with personal information, please contact us at kksal55@gmail.com and we will delete it promptly. ------------------------------------------------------------------------ 2. INFORMATION WE COLLECT ------------------------------------------------------------------------ 2.1 Information You Provide Directly - Account Information: Email address, display name, profile photo (when you sign in with email/password, Google Sign-In, or Sign in with Apple). - Baby Profile Information: Baby's name (or nickname), date of birth, gender, profile photo, and any caregiver invitations you create. - Tracking Data You Enter: Breastfeeding sessions, sleep periods, bottle feedings, formula amounts, diaper changes, pumping volumes, baths, activities, body temperature, medications, height, weight, head circumference, vaccination dates, notebook entries, calendar events. - Media: Photos you choose to upload from your device's photo library or camera. - Communications: Information you send to us by email or via in-app feedback. 2.2 Information Collected Automatically - Device & Diagnostic Data: Device model, operating system version, app version, language, time zone, anonymized device identifiers, and crash logs (collected via Firebase Crashlytics) used solely to diagnose and fix issues. - Usage Data: Aggregated, non-identifying information about features used to help us improve performance. - Push Notification Token: A device-specific token issued by Apple Push Notification service (APNs), used to deliver local and remote reminder notifications you have enabled. - Advertising Identifier (IDFA): Only if you grant permission via Apple's App Tracking Transparency (ATT) prompt. If you decline, no IDFA is shared and only non-personalized ads are served. 2.3 Information We Do Not Collect We do not collect: precise GPS location, contacts, calendar entries outside the App, microphone audio, biometric data, financial information, or browsing history outside the App. ------------------------------------------------------------------------ 3. SENSITIVE HEALTH INFORMATION ------------------------------------------------------------------------ The tracking data you record (e.g., feedings, sleep, temperature, medication) may be considered special-category / health-related data under GDPR Article 9 and equivalent laws. We process this data only with your explicit consent, granted when you create an account and enter the data. You may withdraw consent at any time by deleting the data or your account (see Section 9). The App is a tracking and journaling tool. It is not a medical device, does not provide medical advice, and is not a substitute for professional pediatric care. ------------------------------------------------------------------------ 4. HOW WE USE YOUR INFORMATION ------------------------------------------------------------------------ We use the information described above to: 1. Create and maintain your account and baby profiles; 2. Sync your tracking data across your devices and authorized caregivers; 3. Generate the charts, statistics, and history views you request; 4. Send notifications you have enabled (feeding/medication reminders); 5. Diagnose crashes and improve performance; 6. Display advertisements via Google AdMob (see Section 5); 7. Respond to your support requests; 8. Comply with legal obligations and enforce our Terms of Use. We do not sell your personal information. We do not use your tracking data to train artificial-intelligence models. ------------------------------------------------------------------------ 5. ADVERTISING AND APP TRACKING TRANSPARENCY (ATT) ------------------------------------------------------------------------ The App displays advertisements served by Google AdMob. On iOS 14.5 and later, before any tracking identifier (IDFA) is accessed, we present Apple's standard ATT prompt asking for your permission. - If you choose "Ask App Not to Track": No IDFA is shared. Ads will still appear but will be non-personalized. - If you choose "Allow": The IDFA may be shared with AdMob and its partners to deliver personalized ads and measure performance, in accordance with Google's privacy policy. You can change this setting at any time in iOS Settings > Privacy & Security > Tracking. Google AdMob's privacy practices: https://policies.google.com/technologies/ads ------------------------------------------------------------------------ 6. THIRD-PARTY SERVICES AND DATA SHARING ------------------------------------------------------------------------ We use the following processors and service providers. Each is bound by their own privacy policy and processes data only as needed to provide their service. Firebase Authentication Purpose: Sign-in & account management Data Processed: Email, user ID, auth token Policy: https://firebase.google.com/support/privacy Cloud Firestore Purpose: Cloud storage of baby profiles & tracking data Data Processed: All data you enter Policy: https://firebase.google.com/support/privacy Firebase Storage Purpose: Storing photos you upload Data Processed: Image files Policy: https://firebase.google.com/support/privacy Firebase Cloud Functions Purpose: Server-side logic (e.g., invites) Data Processed: Account & invite metadata Policy: https://firebase.google.com/support/privacy Firebase Crashlytics Purpose: Crash diagnostics Data Processed: Crash logs, device model, OS version Policy: https://firebase.google.com/support/privacy Google AdMob Purpose: Advertising Data Processed: IDFA (only with ATT consent), device data Policy: https://policies.google.com/privacy Google Sign-In Purpose: Optional sign-in Data Processed: Email, name, profile photo Policy: https://policies.google.com/privacy Sign in with Apple Purpose: Optional sign-in Data Processed: Apple-provided relay email or real email Policy: https://www.apple.com/legal/privacy Apple Push Notification service Purpose: Delivering notifications Data Processed: Push token Policy: https://www.apple.com/legal/privacy We do not disclose your data to any third party other than the above, except (a) with your explicit consent, (b) to comply with a lawful legal request, or (c) to protect the rights, safety, or property of users or the public. ------------------------------------------------------------------------ 7. INTERNATIONAL DATA TRANSFERS ------------------------------------------------------------------------ Firebase services may store and process data on Google servers located in the United States, the European Union, or other countries where Google operates. By using the App, you acknowledge that your data may be transferred to and processed in countries whose data-protection laws may differ from your own. Where required by GDPR, transfers rely on Standard Contractual Clauses approved by the European Commission. ------------------------------------------------------------------------ 8. DATA RETENTION ------------------------------------------------------------------------ - Account data is retained as long as your account remains active. - Tracking data is retained until you delete it or delete your account. - Crash logs are retained for up to 90 days by Firebase Crashlytics. - Backups may persist for up to 30 days after deletion before being permanently purged from cold storage. You can delete individual records at any time within the App. ------------------------------------------------------------------------ 9. YOUR RIGHTS AND CHOICES ------------------------------------------------------------------------ Depending on your jurisdiction, you have the right to: - Access the personal data we hold about you; - Correct inaccurate data; - Delete your data ("right to be forgotten"); - Restrict or object to certain processing; - Portability — receive a copy in a structured, machine-readable format; - Withdraw consent at any time; - Lodge a complaint with your local data-protection authority. How to Exercise Your Rights - Edit data: directly within the App. - Delete account & all data: Open the App > Settings > "Delete Account". This is provided in compliance with Apple Guideline 5.1.1(v) and triggers permanent deletion of your account and all associated tracking data within 30 days. - Request a copy or written response: email kksal55@gmail.com from the address linked to your account. We will respond within 30 days. ------------------------------------------------------------------------ 10. PERMISSIONS USED BY THE APP ------------------------------------------------------------------------ Photo Library Why: Pick a profile photo for you or your baby Required: Optional Camera Why: Capture a profile photo Required: Optional Notifications Why: Deliver feeding/medication reminders you set Required: Optional App Tracking Transparency Why: Personalized ads via AdMob Required: Optional Network access Why: Cloud sync, sign-in, ads Required: Required You can change any permission at any time in iOS Settings > Bebeğim. ------------------------------------------------------------------------ 11. DATA SECURITY ------------------------------------------------------------------------ We implement reasonable technical and organizational measures to protect your data, including: - Encryption in transit (HTTPS/TLS) for all server communication; - Encryption at rest on Google Cloud infrastructure; - Access control through Firebase Authentication and Firestore Security Rules; - Crash and abuse monitoring. No method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security. ------------------------------------------------------------------------ 12. CHILDREN'S PRIVACY ------------------------------------------------------------------------ The App is intended for adults. We do not knowingly collect personal data from children under 13 (or under the relevant age in your jurisdiction). The data entered about a baby is provided by an adult user about a minor for whom they hold parental responsibility. If we learn that a child has created an account, we will delete it. ------------------------------------------------------------------------ 13. CHANGES TO THIS PRIVACY POLICY ------------------------------------------------------------------------ We may update this Policy from time to time. The "Last Updated" date at the top reflects the latest revision. If we make material changes, we will notify you in-App or by email before the changes take effect. Continued use of the App after the effective date constitutes acceptance of the updated Policy. ------------------------------------------------------------------------ 14. ACCOUNT DELETION AND DATA REMOVAL ------------------------------------------------------------------------ Users can request deletion of their data or account at any time by contacting us at HokkabazSoft@gmail.com or by visiting our data deletion page: https://annelertoplandik.com/sozlesmeler/bebekbakimi/BebekVeriSilmeTalep.html ------------------------------------------------------------------------ 15. CONTACT US ------------------------------------------------------------------------ For any privacy-related question, request, or complaint: Mobisoft Yazilim Email: destek@annelertoplandik.com If you are located in the European Economic Area or the United Kingdom and we have not resolved your complaint to your satisfaction, you may contact your local data-protection authority.