Privacy Policy
This policy describes the privacy practices of the SignalLock app and the signallock.app website. It is prepared in compliance with the EU General Data Protection Regulation (GDPR) and the Republic of Türkiye’s Personal Data Protection Law No. 6698 (KVKK).
1. Data Controller
Acting as data controller within the meaning of GDPR Article 4(7) and KVKK:
- Name: Muhammet Şafak
- Email: info@muhammetsafak.com.tr
- Country: Türkiye
2. Data We Collect (and Don’t Collect)
2.1 SignalLock Desktop Application
The SignalLock desktop app collects, stores, and transmits no personal data to any server. It runs entirely locally:
- Bluetooth Low Energy (BLE) scanning is processed only in your device’s local memory.
- Your selected trusted device’s identifier and the app’s settings are stored only in your device’s local user files (macOS:
UserDefaults; Windows:%APPDATA%\SignalLock; Linux:~/.config/SignalLock). - Location services are not used.
- The app does not require an internet connection to function and never communicates with any remote server.
- No telemetry, analytics, or crash report data is sent.
2.2 Website (signallock.app)
The website is entirely static files. There is no server-side application, database, form, or session management. The limited data that may be processed for normal technical operation is:
a) Server access logs
When you visit the site, our hosting infrastructure automatically records information such as IP address, user agent (browser identification), requested URL, and timestamp. This information is used only for security, error diagnosis, and statistical measurement; it is never shared with third parties. Retention period: up to 30 days, then automatically deleted.
b) Cloudflare Pages (hosting and content delivery network)
The site is hosted on Cloudflare Pages. Cloudflare temporarily processes your connection details, including IP address, for service security and performance. Cloudflare is subject to its own privacy policy: cloudflare.com/privacypolicy.
c) Third-party requests — none
The site issues no requests to third-party CDNs, font services, analytics tools, or ad networks. The “Inter” typeface is served from our own origin; your browser never connects to any external domain, Google Fonts included. The Content Security Policy enforces this at the browser level too.
d) Browser storage — none
The site uses no cookies and stores nothing in localStorage or sessionStorage. Language selection works through separate addresses (signallock.app/ for Turkish, signallock.app/en/ for English), so there is no preference to remember. See the Cookie Policy for details.
3. Legal Basis for Processing
Under GDPR Article 6(1)(f) and KVKK Article 5(2)(f), we process data on the basis of legitimate interest in the secure and technical operation of the website. We do not process data for marketing, profiling, or analytics purposes, so no processing requires explicit consent.
4. Data Sharing
We do not share your data with third parties for marketing or other commercial purposes. Apart from the hosting provider (Cloudflare) identified in Section 2.2, we use no third-party services. We will not disclose your data to any party, including government agencies, except where legally required.
5. International Data Transfers
Because Cloudflare is a global infrastructure, your visit data may be processed outside Türkiye or the EU. Such transfers are protected by Standard Contractual Clauses pursuant to GDPR Article 46 and by Cloudflare’s published Data Processing Addendum.
6. Data Subject Rights
Pursuant to KVKK Article 11 and GDPR Articles 15-22, you have the following rights:
- To learn what personal data is processed about you
- To request rectification or erasure
- To object to data processing
- To data portability in a structured format
- To request restriction of processing
- To object to automated decision-making
- To withdraw consent for processing you previously agreed to
- To file a complaint with a Data Protection Authority (KVKK Authority in Türkiye; your local supervisory authority in the EU)
To exercise these rights, write to info@muhammetsafak.com.tr. Your request will be answered within 30 days as required by KVKK Article 13 and GDPR Article 12.
7. Children’s Privacy
SignalLock is not intended for users under 13 years of age. We do not knowingly collect personal data from users under 13. If you believe your child has provided us data, contact us and the relevant data will be deleted promptly.
8. Data Security
Web traffic is end-to-end encrypted with TLS 1.2 / 1.3. Server access logs are accessible only to authorized personnel. Local data produced by the desktop app is protected by the operating system’s standard user-isolation mechanisms.
9. Policy Changes
We may update this policy from time to time. Changes are published on this page and reflected in a new “Last updated” date. We recommend reviewing this page periodically for material changes.
10. Contact
For questions, requests, or complaints regarding our data processing practices: info@muhammetsafak.com.tr