Skip to content

Polvio Privacy Policy

Last updated: June 2026

1. Introduction

Polvio ("Polvio", "we", "us", or "our") is a news aggregation and political-engagement application that delivers news, AI-generated summaries, politician information, and a community feed. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, how long we keep it, and the rights you have over your data.

This Policy is intended to comply with the EU General Data Protection Regulation ("GDPR") and the Turkish Personal Data Protection Law No. 6698 ("KVKK"). The data controller is Polvio, reachable at [email protected].

By creating an account and using Polvio, you acknowledge that you have read this Policy. Where we rely on your consent — in particular for political opinion data, as described in Section 6 — that consent is requested separately and explicitly, and you may withdraw it at any time.

2. Data We Collect

2.1 Account and identity data

When you create an account, we collect and store:

  • Email address — obtained either through Google or Apple sign-in (where it is cryptographically verified from the sign-in identity token) or when you register with an email and password.
  • Authentication provider — whether you signed in with Email, Google, or Apple. For email/password accounts, your password is stored only as a salted hash, never in plain text.
  • Username (@handle) — a unique, case-insensitive handle (up to 30 characters).
  • Display name (up to 50 characters) and bio (up to 160 characters) — optional and user-controlled.
  • Timezone (e.g., "Europe/Istanbul"), locale and news-language preference, and your plan and subscription status (Free, Premium, or Enterprise).

2.2 Preferences and personalization data

  • Scope countries — the list of countries you choose to follow news for (defaults to a worldwide scope).
  • Theme preference (stored on your device).
  • Political Compass profile — your answers across three axes (economic, social, and foreign policy), plus selected topics and values. This is special-category / sensitive data and is described in detail in Section 6.

2.3 Community content you create

If you use the community features, we store the content you choose to create:

  • Posts (text up to 1,000 characters), with an optional link to a shared news story.
  • Replies to posts (text up to 1,000 characters).
  • Likes on posts and replies (we store that you liked an item; like counts are shown to others, but we do not expose the identities of individual likers).
  • Follow relationships — who you follow and who follows you, including pending follow requests for private accounts, and the time a follow was created or accepted.
  • Your account privacy setting (public or private) and your follower, following, and post counts.

2.4 Interaction, view, and click data

To operate features such as trending content, ranking, and personalization, we record how you interact with the app:

  • News clicks and opens — the news item, its topic and tags, the source/publisher domain, the screen you came from, the position in the list, and the event type (for example, opening an article or following a source link).
  • A session identifier (supplied by the app, used to de-duplicate events) and a one-way hashed form of your IP address (SHA-256 — we do not store your raw IP address). These are used for anti-spam and rate-limiting, including a trust/validation weight and, where applicable, a rejection reason.
  • Bookmarks (saved news and politicians), followed politicians, comments and likes on news, and the list of news sources you have blocked.
  • Politician profile views and aggregate engagement counters (raw and trusted view counts, unique-user counts) used for ranking and trending. These include both logged-in and anonymous visits.
  • An interest profile derived from your activity (topic, politician, source, and tag scores, with decay over time) used to personalize your feed.

2.5 Device, notification, and mobile data

  • Push notification token(s) — one per device, and you may have more than one device.
  • Device identifier and platform (iOS or Android).
  • Push and email notification preferences (opt-in/opt-out, frequency, digest timing) and an optional alternative email address for notifications.
  • Unsubscribe tokens for one-click email unsubscribe links, and timestamps of the last push/digest sent.
  • On iOS, if you allow it through App Tracking Transparency, an advertising/tracking identifier used to deliver personalized ads (see Section 12).

2.6 Usage analytics data

To understand which parts of the app are used — and to improve them — we collect privacy-first, aggregate usage analytics. These are neutral product-usage signals only: which section you view (for example Latest News, Trending, Community, Politicians, or Political Compass) and the time spent there, and which key actions occur (opening an article, posting, commenting, liking, following, or running a search). Each event is keyed only to your pseudonymous account identifier and carries no other personal data — no IP address and no content.

We never record the substance of what you do: not the text of your posts or comments, not your search terms, and — importantly — never your Political Compass answers or political opinions. Visiting the Political Compass screen is recorded only as a neutral screen view; the opinions themselves are never collected as analytics, and we never turn this usage data into behavioral or political profiling. We rely on our legitimate interest in measuring and improving the product (Article 6(1)(f) GDPR, and the corresponding legitimate-interest basis under KVKK) for this neutral measurement. You can turn it off at any time under Settings → Privacy & Data; when it is off, nothing is recorded or sent. Raw usage events are automatically deleted after 90 days and are removed when you delete your account; only anonymous, aggregate totals — which contain no identifiers — are retained for long-term trends. We use these analytics solely in aggregate, never to monitor an individual.

3. How We Use Your Data

We use the data described above to:

  • Create and operate your account, authenticate you, and maintain your profile.
  • Deliver and personalize your news feed, including filtering by your selected countries and topics, ranking related news, and surfacing trending content.
  • Provide community features — posts, replies, likes, follows, and follow requests — and enforce the privacy of public and private accounts.
  • Calculate politician "match" scores and personalize politician and news recommendations where you have provided a Political Compass profile (see Section 6).
  • Send the notifications you have opted into (for example, replies to your posts, new followers, follow requests, and follow acceptances), and email communications such as data-export links.
  • Detect and prevent spam and abuse, including rate-limiting via hashed IP and session signals.
  • Manage subscriptions and entitlements (see Section 4) and, on the free tier, serve advertising (see Section 12).

Our legal bases are: performance of our contract with you (to provide the service you request); your consent (for political opinion data and, where required, for advertising tracking and notifications); and our legitimate interests (security, abuse prevention, and improving the service), balanced against your rights. The final mapping of purposes to legal bases is to be confirmed with legal counsel.

4. Sharing and Service Providers

We do not sell your personal data. We share data with the service providers (processors) we need in order to run Polvio. The categories of processors we actually use are:

  • Sign-in providers — Google and Apple, which verify your identity and provide your verified email when you use social sign-in.
  • Subscription and in-app purchase management — RevenueCat, together with the Apple App Store and Google Play, which process all payments. Polvio does not receive, store, or process your payment card details; the app stores only subscription status and identifiers returned by these providers (see also Section 4.1).
  • Push notification delivery — Firebase Cloud Messaging (FCM).
  • Email delivery — Resend, used to send data-export links and email notifications.
  • AI summary generation — Google Gemini, used to generate news and agenda summaries (see Section 7).
  • Error reporting and observability — Sentry (optional), used for diagnostic error reporting.
  • Hosting and database — servers located in Europe, where the application and its database run.

The processors we use are: Google (Google Sign-In; the Gemini API for AI summaries; AdMob advertising; Firebase Cloud Messaging for push notifications; Google Play billing), Apple (Sign in with Apple; App Store billing), RevenueCat (subscription management), Resend (transactional email), and Sentry (error reporting) — with the application and database hosted on servers located in Europe. Each processor receives only the data needed for its function and is bound to process it on our instructions.

4.1 Payments

Subscriptions (monthly, yearly, and lifetime) are billed through the Apple App Store or Google Play and managed via RevenueCat. You manage and cancel auto-renewing subscriptions in your App Store or Google Play account settings, not within Polvio. Card data is handled entirely by Apple and Google; our backend receives only transaction and entitlement information.

4.2 Visibility of community content to other users

Content you post in the community is shared with other users according to your account's privacy setting. If your account is public, your profile, posts, replies, and follower/following lists are visible to all signed-in users. If your account is private, those items are visible only to you and to followers you have accepted; non-followers see a locked state. Like counts and reply counts are shown, but individual liker identities are not exposed.

5. Community Features: What We Do and Do Not Offer

You can create a profile, post text and optionally share a news story, reply to posts, like posts and replies, follow other users, accept or reject follow requests, and switch your account between public and private at any time.

Please be aware of the following current limitations of the community features, so you can make informed choices about what you share:

  • User blocking is not currently available. You cannot block another user. (Blocking is available for news sources only.)
  • Reporting of community posts, replies, or user profiles is not currently available in the app. (Reporting exists only for news comments, which is a separate feature.)
  • Moderation of community content is limited to deletion: you can delete your own posts and replies, and administrators can remove any post. Deleted content is soft-deleted (hidden from view) rather than immediately erased from our systems.

We may add reporting, blocking, and broader moderation in the future; this Policy will be updated if and when those features are introduced.

6. Political Compass: Sensitive / Special-Category Data

The Political Compass feature lets you record your political interests. Your answers — your positions on the economic, social, and foreign-policy axes, together with the topics and values you select — reveal your political opinions. Under GDPR Article 9 and the KVKK, this is special-category / sensitive personal data, subject to heightened protection.

6.1 Consent is required and optional

We process your Political Compass data only on the basis of your explicit consent (GDPR Article 9(2)(a); KVKK Article 6). Providing this information is entirely optional. You can skip the Political Compass and use Polvio without sharing any political opinion data. We do not infer your political opinions from your browsing; the only political opinion data we hold is what you choose to enter here.

6.2 How we use it

If you provide a Political Compass profile, we use it solely to personalize your experience: to filter and rank your news feed by your chosen countries and topics, and to calculate "match" scores between you and politicians. These scores influence sorting and recommendations; they do not exclude any content from the catalog, and your political profile is not displayed publicly or shared with other users.

6.3 How to withdraw consent and delete this data

You can withdraw your consent and delete your Political Compass profile at any time, with no effect on the rest of your account:

  • Edit individual fields at any time in Settings → Political Compass; changes are saved automatically.
  • Delete the entire political profile using "Restart from the beginning" in the same settings screen, which permanently removes the stored profile. You can then continue using the app without one.
  • If you delete your account (Section 10), your Political Compass data is deleted along with all other account data.

Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. If you exercise your right to data portability (Section 11), your Political Compass data is included in the export.

7. AI Summaries and Automated Content

Polvio aggregates news from third-party RSS sources and presents AI-generated summaries and automatically clustered "Trending" content. You should understand the following about this content:

  • News articles come from third-party publishers. Their accuracy depends on the original sources, and Polvio is not the author of that content.
  • Summaries are generated by large-language models (for example, Google Gemini and other providers). Although the models are instructed not to add information beyond the source articles, AI-generated summaries can still be incomplete, inaccurate, or misleading, and are not fact-checked. Where a model fails or is truncated, the app may fall back to a plain concatenation of headlines.
  • "Trending" clusters and topic categories are produced automatically by clustering and natural-language-processing systems based on engagement and freshness. They are not editorially curated or reviewed by a human before display, and may misclassify or omit stories.
  • Engagement-based popularity does not necessarily reflect the importance or reliability of a story.

AI summaries and trending content are provided for convenience only and should not be relied upon as a complete or authoritative account of any event.

8. Data Retention

We keep your personal data for as long as your account is active and for up to 90 days thereafter, unless a longer period is required by law. When you delete your account, your account record and dependent data are deleted as described in Section 10.

Certain aggregate, non-identifying engagement counters (for example, total view counts on politicians and articles) and anonymous view records that are not linked to your account persist after deletion. Your individual contributions to those aggregates are removed when your account is deleted. Data-export download files are short-lived: they are single-use and expire within 24 hours (see Section 11).

The specific retention periods for each data category are up to 90 days.

9. Security

We take technical and organizational measures to protect your data. These include: storing passwords only as salted hashes; cryptographically verifying social sign-in tokens; storing only a one-way hash of your IP address rather than the raw value; generating single-use, expiring, token-based links for data exports (and never storing the raw token); and applying rate-limiting and anti-spam controls to interaction data.

No system can be guaranteed completely secure. If we become aware of a personal-data breach affecting you, we will notify you and the competent authorities as required by GDPR and the KVKK.

10. Account Model and Deletion

10.1 Your username is display-only

All of your data is linked to a stable, internal account identifier, not to your username. Changing your username only updates the displayed handle. It does not delete, detach, or anonymize any of your data, and it does not sever your bookmarks, follows, posts, comments, or interaction history. Changing your username is therefore not a way to remove your data.

10.2 Account deletion is the way to remove your data

The only way to remove your account data is to delete your account. You can do this in the app under Settings → Delete Account, where you confirm by typing "Delete Account" (and, for email/password accounts, confirming your password).

Deletion is permanent and immediate (a "hard delete"), not a reversible deactivation. It cannot be undone. When you delete your account, we remove your user record and cascade-delete your dependent data, including your follows, bookmarks, push tokens, notification preferences, blocked-source list, news-click history, Political Compass profile, interest profile, notification records, and your news comments.

As noted in Section 8, anonymous view records and pre-computed aggregate engagement counters that are not tied to your account persist after deletion; where a view record had been linked to your account, that link is removed so the record becomes anonymous.

11. Your Rights

Subject to applicable law, you have the following rights over your personal data under the GDPR and the KVKK:

  • Access — to be informed whether we process your data and to obtain a copy of it.
  • Rectification — to correct inaccurate or incomplete data (for example, by editing your profile).
  • Erasure — to have your data deleted, including by deleting your account (Section 10).
  • Restriction — to ask us to limit processing in certain circumstances.
  • Objection — to object to processing based on our legitimate interests.
  • Data portability — to receive your data in a structured, machine-readable format.
  • Withdrawal of consent — to withdraw consent at any time where processing is based on consent, including for your Political Compass data (Section 6).
  • Complaint — to lodge a complaint with a supervisory authority: in Türkiye, the Personal Data Protection Board (KVKK Kurulu); in the EU/EEA, your local Data Protection Authority.

11.1 Downloading your data

You can exercise your right to data portability directly in the app under Settings → Privacy & Data → "Download data". We prepare your data and email you a secure, single-use download link that expires within 24 hours. Exports include your account, preferences, and Political Compass data, but exclude internal security fields such as password hashes. Export requests are limited to one per hour.

To exercise any other right, or if you have questions, contact us at [email protected]. We may need to verify your identity before responding.

12. Cookies, Local Storage, Mobile Identifiers, and Advertising

Polvio is primarily a mobile app and stores some data on your device, such as your theme preference and session information. The app uses device and push identifiers as described in Section 2.5.

On the free tier, we display advertising through Google AdMob. On iOS, before any tracking identifier is used for personalized ads, we ask for your permission through Apple's App Tracking Transparency prompt. In the EU/EEA, we present a Google-certified consent (UMP) flow for advertising. Premium subscribers do not see ads. If AdMob is unavailable, we may show our own in-app promotional ("house") ads, which do not involve third-party ad tracking.

13. International Data Transfers

Some of our service providers (Section 4) operate outside your country, including outside the EU/EEA and Türkiye. Where your data is transferred internationally, we rely on appropriate safeguards required by the GDPR and the KVKK, such as Standard Contractual Clauses or adequacy decisions, and the KVKK conditions for transfers abroad. The specific processors involved are listed in Section 4.

14. Children

Polvio is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child under 16 has provided us with personal data, please contact us at [email protected] and we will take appropriate steps to delete it.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, where the changes are material, provide a more prominent notice. Your continued use of Polvio after an update means you have reviewed the current Policy.

16. Contact and Governing Law

The data controller is Polvio. For any questions, requests, or complaints about this Policy or your personal data, contact us at [email protected].

This Policy is governed by the laws of Turkey, with the courts of Istanbul having jurisdiction, without prejudice to any mandatory data-protection rights you have under the GDPR, the KVKK, or the laws of your country of residence.