Privacy
Last updated 19 August 2026
Avarta is a record of your working life as a DJ. That means it holds things you would not want loose: where you played, what you were paid, who still owes you. This page says plainly what we hold, why we are allowed to, how long we keep it, and how to get rid of it.
Who is responsible for your data
Avarta is not a company. It is run by Cenk Gören, trading as Avarta in Türkiye, who is the data controller under the GDPR and the veri sorumlusu under Turkish law (KVKK). Reach us at support@avarta.app.
What we collect, and why we are allowed to
Under the GDPR every use of your data needs a lawful basis. Here is ours, item by item.
Your account
An email address and a display name, plus a password hash, or the identifier your provider gives us if you signed in with Apple or Google. We use the address to sign you in, to send the six-digit codes that verify an account or reset a password, and to reach you about your subscription. We do not send marketing email. Basis: performance of a contract — you cannot have an account without it.
What you log
The sessions, gigs, bookings, venues, fees, expenses, gear, tech riders and prep templates you enter, along with any photos, notes and set links you attach. This is the product: it exists to hold this, and it is yours. Basis: performance of a contract.
Sensor readings during a session
- Microphone. While a session is running, Avarta samples the room’s relative sound level and tempo on your device. It does not record audio, does not store raw audio, and does not upload raw audio. Derived numeric results such as tempo and relative room level can sync with your set. If you separately turn on Track ID, Apple’s Shazam service receives a derived audio signature to identify a track; Avarta stores the returned track title, artist and timing, not the signature or raw audio. This is not a calibrated sound-pressure measurement. Basis: your consent, given through the iOS microphone permission.
- Heart rate. Read from Apple Health during a session, only if you grant permission. Avarta never writes anything back to Health. Heart rate is health data — a special category under GDPR Article 9 and özel nitelikli kişisel veri under KVKK Article 6 — so we rely on your explicit consent and nothing else. Withdraw it by revoking Health access in iOS and we stop receiving it immediately.
- Calendar. Only with permission. Avarta writes your bookings to a dedicated calendar and reads those events back so a time you change in Calendar reaches the booking. Calendar sync also requires Pro. Turning sync off or losing Pro stops future calendar work but leaves existing events in place. Signing out or deleting the account removes linked Avarta events from that device. Basis: your consent.
Withdrawing any of these is as easy as giving it: turn the permission off in iOS Settings. Withdrawal does not undo processing that already happened, which is normal and required to be said.
Diagnostics and usage
Usage analytics and crash reporting are two separate optional choices. Both are off by default and neither choice enables the other. If you opt in, the selected category and a pseudonymous account identifier go to Google Firebase: feature interactions for Analytics, or crash and diagnostic details for Crashlytics. Avarta does not track you across other companies’ apps or websites and shares nothing with data brokers or advertising networks. Basis: your explicit consent. You can withdraw either choice immediately in Settings. Withdrawal stops future collection and clears local SDK identity/state where supported; it cannot selectively erase a report already sent to Google.
This website
Separate from the app. See the cookie policy for what the site sets and what it does not.
What other people can see
Your profile, avatar, and the gigs you choose to post are visible to other Avarta users; avatar files are publicly retrievable so they can appear on profiles. A gig photo is visible when its gig is public and becomes hidden when that gig is private. New images remain visible only to their uploader while moderation is pending. Your fees, expenses, payment status, notes, heart rate and private energy score are not included in public profiles, sets or feeds. Notes still sync privately to Avarta. Avarta does not offer comments in this version of the app or API.
Blocks, reports and moderation
A block records the two account identifiers and when the block was created. It is used in both directions to remove follows and prevent discovery, viewing and interaction. Your Blocked accounts screen shows the minimum profile information needed to unblock.
A report records the reporter, the explicit target type and identifier, reason, optional details, status, review timestamps, moderator action and an append-only audit history. It also keeps a bounded snapshot of the target’s public evidence so later review does not depend on the item still being live. That snapshot excludes email, private notes, finance, health data, raw tokens and unrelated account data. New images also create a review item before publication.
The production retention period for moderation records has not been owner-confirmed. Account erasure removes blocks, social rate-limit events, associated provisional-media records, reports made by or targeting the account, and their moderation audit rows.
Money records, purchases and deliberate exports
Fees, expenses and whether a gig was paid are private business records. Avarta does not process those payments. For Pro, we receive and store Apple purchase-history identifiers and entitlement dates so the server can verify access; billing remains with Apple.
Share cards are deliberate exports outside Avarta. The preview shows exactly what will be shared. If the selected card includes heart-rate data, the app displays an additional warning immediately before the iOS share sheet. Once you choose another app or person, their handling and retention apply. Heart-rate cards are wellness context, not medical information or advice.
Who receives it
| Recipient | What and why | Location and retention |
|---|---|---|
| Production hosting, API and database provider | Account and app records needed to run and sync Avarta. | Provider, region and backup/log retention require owner confirmation before release. |
| Object-storage provider | Avatar and gig-photo files. | Production provider, region, versioning and deletion retention require owner confirmation. |
| Resend | Email address and transactional verification, reset and account messages. | Production processing location and retention require owner/provider confirmation. |
| Google sign-in | Sign-in handshake and provider account identifier when you choose Google. | Handled under Google’s terms; production transfer details require owner confirmation. |
| Apple / App Store / Shazam | Apple sign-in, subscription transactions, and derived audio signatures only when Track ID is enabled. | Handled under Apple’s terms; Avarta has not verified a single processing region or retention period for all three services. |
| Google Firebase Analytics | Feature interactions and pseudonymous identifier only after separate analytics opt-in. | Production location and console retention require owner confirmation. |
| Google Firebase Crashlytics | Crash and diagnostic data and pseudonymous identifier only after separate crash-report opt-in. | Production location and console retention require owner confirmation. |
We do not sell your data or share it for advertising. We will also disclose data where the law requires it — a valid court order or lawful request from an authority — and will tell you when we are permitted to.
Where it lives, and transfers abroad
Avarta is local-first: what you log is written to your phone first and synced to our servers when there is a connection. Provider processing regions and international- transfer mechanisms are deployment and contract facts, not facts the source repository can establish. They must be confirmed by the owner before this policy is treated as release-ready; the table above marks every unresolved recipient rather than guessing a country or safeguard.
How long we keep it
- Your gigs, bookings and profile: for as long as your account exists. Asking us to delete it hides them from everyone at once and erases them 7 days later.
- Photos: until replaced, their gig is deleted, or the account is erased; blob deletion is requested after database erasure.
- Apple purchase identifiers: until account erasure. Deletion does not cancel the subscription itself.
- Blocks, reports and moderation evidence: the production retention period requires owner confirmation; they are removed when the associated account is erased as described below.
- Backups and server logs: the production periods are not established by this repository and require owner confirmation before release.
- Firebase records: controlled by the production Analytics and Crashlytics console settings, which require owner confirmation.
Security
Traffic is encrypted in transit. Passwords are stored as bcrypt hashes and are not recoverable, by us or anyone else. Sessions are bearer tokens that can be revoked, and a password reset revokes every existing one. Access to production data is limited to the people who need it to run the service. No system is perfectly secure, and we will tell you and the supervisory authority without undue delay if a breach affects you.
Your rights
Over the data we hold about you, you have the right to:
- ask what we hold and get a copy of it;
- correct anything wrong;
- have it deleted;
- restrict or object to how we use it;
- take it elsewhere, in a machine-readable form;
- withdraw any consent you have given, at any time;
- not be subject to a decision made purely by automation — and we make none, so this one is a formality here.
Most of these you can exercise yourself in the app, immediately: export from Settings, delete your account from Settings, revoke a permission in iOS. For anything else write to support@avarta.app and we will answer within 30 days.
If you think we have handled your data badly, you can complain to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, kvkk.gov.tr), or to the data protection authority where you live if that is elsewhere in the EEA.
Deleting your account
Settings → Account → Delete account. The effect is immediate: your profile and everything on it stop being visible to anyone on Avarta, you are signed out on every device, and the copy held on your phone is wiped in the same step.
The erasure itself waits 7 days. During that window you can change your mind — sign in again and Avarta offers to restore the account, one tap, with nothing lost. That window exists because erasure on a single stolen session would be unanswerable: it is the undo.
After 7 days, Avarta permanently deletes the account and its database rows, including your profile, gigs, bookings, purchase-entitlement record, likes, blocks, reports, moderation audit rows, media-upload records, social rate-limit events and any historical comment rows, then requests deletion of avatar and gig-photo objects. If you signed in with Apple, Avarta also attempts to revoke that authorization. The production backup/versioning retention behavior still requires owner confirmation, so this policy does not claim an unverified backup-erasure deadline. Export first if you want to keep anything.
Deleting your account does not cancel an Avarta Pro subscription. Apple bills it, and only you can stop it — Settings → your name → Subscriptions on your iPhone.
Children
Avarta is not intended for anyone under 16, and we do not knowingly hold their data. If you believe a child has given us data, write to us and we will delete it.
Changes
If this page changes in a way that affects you, we will say so in the app before the change takes effect.
Contact
Cenk Gören — support@avarta.app