Privacy Policy

⚠️ This text is a draft prepared from our actual processing activities. It must be reviewed by legal counsel before it is relied on, and details such as the company's legal name, address, MERSIS number and retention periods must be finalised.

Last updated: August 29, 2026

1. Who we are

MyDefense ("we") operates the digital privacy service at mydefense.io. We are the controller of the personal data described below. We are established in Istanbul, Türkiye and serve users worldwide, so more than one data protection regime can apply to a given account — see section 6.

2. Data we collect

  • Identity and contact data: first name, last name, email address
  • Account data: password (hashed), plan tier, wallet balance, and the record of top-ups and charges against that balance
  • The country or region you declare at sign-up, which decides the law we cite when we file an erasure request on your behalf
  • Access and refresh tokens for the platforms you connect (Instagram, X/Twitter, Facebook, LinkedIn, TikTok, YouTube, Gmail) — stored encrypted
  • Scan results: content detected on connected platforms, risk scores, and deletion status
  • Whether your email address appears in breach databases, for breach monitoring
  • Payment and subscription data (handled by our payment provider; we never store your card details)
  • Your consent to this policy, and the date and time you gave it
  • Technical data: IP address, browser information and session logs, for security and error diagnosis

3. Google API Services

3a. Limited Use

MyDefense's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular: we do not use Google user data for advertising; we do not sell it; we do not transfer it to others except as needed to provide the feature you asked for, for security purposes, or to comply with applicable law; and we do not let humans read it, except with your explicit consent on a support request you raise, where security or the law requires it, or on data that has been aggregated and anonymised.

3b. What each scope is used for

ScopeWhat we do with itWhy a narrower scope will not do
gmail.modifySearch your mailbox for messages that expose sensitive data (passwords, verification codes, identity or bank details) and, when you ask us to, move those specific messages to trash.gmail.readonly cannot delete, and deletion is the point of the product. No narrower scope allows both finding and removing a message.
youtube.readonlyList the videos and comments on your own channel so they can be shown to you as findings.Required to read your own channel content.
youtube.force-sslDelete the videos or comments you select.YouTube offers no narrower write scope for removing your own content.

Google data is read only while a scan you started is running, and written only for a deletion you selected. Message bodies are not stored: a finding records the platform, the kind of content, and the identifier needed to act on it. Signing in with Google uses only your basic profile and email address and grants none of the scopes above. You can disconnect any platform from Settings at any time, which deletes the stored tokens, and you can revoke our access directly at myaccount.google.com/permissions.

4. Other connected platforms

The same principle applies to every platform you connect: we request the narrowest permissions that let us show you what is exposed and remove it when you ask.

PlatformPermissions requested
Meta (Facebook)public_profile, email, user_posts
Meta (Instagram)user_profile, user_media
LinkedInopenid, profile, email, w_member_social
X (Twitter)tweet.read, tweet.write, users.read, offline.access
TikTokuser.info.basic, video.list

5. Legal basis for processing

We process your data to perform the contract you entered into when you created an account (GDPR Art. 6(1)(b); KVKK Art. 5/2-c), to comply with our legal obligations (GDPR Art. 6(1)(c); KVKK Art. 5/2-ç), and, where we ask for it explicitly — such as connecting a platform account — on the basis of your consent (GDPR Art. 6(1)(a); KVKK Art. 5/1). You may withdraw consent at any time; withdrawing it does not affect processing carried out before the withdrawal.

6. Your rights

Which law gives you these rights depends on where you live. You tell us that at sign-up, and you can change it in Settings.

6a. European Union, EEA and United Kingdom

Under the GDPR and UK GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing (Art. 21), including the right not to be subject to a decision based solely on automated processing (Art. 22). You may also lodge a complaint with your national supervisory authority.

6b. Türkiye

6698 sayılı Kişisel Verilerin Korunması Kanunu'nun 11. maddesi uyarınca; kişisel verinizin işlenip işlenmediğini öğrenme, işlenmişse buna ilişkin bilgi talep etme, işlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme, yurt içinde veya yurt dışında aktarıldığı üçüncü kişileri bilme, eksik veya yanlış işlenmişse düzeltilmesini isteme, Kanun'da öngörülen şartlar çerçevesinde silinmesini veya yok edilmesini isteme, yapılan düzeltme ve silme işlemlerinin aktarıldığı üçüncü kişilere bildirilmesini isteme, münhasıran otomatik sistemler vasıtasıyla analiz edilmesi suretiyle aleyhinize bir sonucun ortaya çıkmasına itiraz etme ve kanuna aykırı işlenmesi sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme haklarına sahipsiniz.

6c. California

Under the CCPA (Cal. Civ. Code §1798.100 et seq.) you have the right to know what personal information we collect and why, the right to request deletion (§1798.105), the right to correct inaccurate information (§1798.106), and the right not to be discriminated against for exercising any of them. We do not sell or share personal information as those terms are defined in the CCPA, so there is nothing to opt out of.

6d. Everywhere else

If none of the above applies to you, we will still honour a request to access, correct or delete your data. We would rather answer the request than argue about which law compels it.

To exercise any of these rights, write to privacy@mydefense.io. You can also delete your account yourself from Settings at any time.

7. Retention

We keep your personal data for as long as your account is active, and afterwards only as long as a legal retention obligation requires. When you delete your account, your connected-platform tokens and scan findings are removed from our systems within a reasonable period.

8. Security

Connected-platform access tokens are encrypted with AES-GCM before they are stored. Database access is constrained by row-level security policies. Your password is never stored in plain text, and data is encrypted in transit.

9. International transfers and processors

To provide the service, your data is handled by: Supabase (database and authentication), Cloudflare (hosting and edge network), our payment provider (subscriptions and payments), Have I Been Pwned (breach checks), and the platforms you choose to connect — Google, Meta, X, LinkedIn and TikTok — only to the extent you authorise. These providers operate in several countries, so your data may be processed outside the country you live in, under the safeguards those providers offer. We do not sell or rent your data to anyone, and we do not share it for marketing purposes.

10. Contact

For anything about your personal data, write to privacy@mydefense.io.

11. Changes

We may update this policy to reflect changes to the service or to the law. We will tell you about material changes before they take effect.

Back to registration