Privacybeleid
Version 1.6.1 · Last updated: 2026-07-08
SUMMARY (NOT LEGALLY BINDING)
• SilaWay ("App") provides border wait times, maps, navigation, a voice assistant, and community chat.
• We collect only the data needed to run the service: account, location, chat, and (if you use the voice assistant) audio.
• Your data is not sold for advertising or marketing.
• You can delete your account from within the app; your data is removed at the moment of deletion (technical copies within 30 days at the latest).
• Questions: [email protected]
The text below is the full and binding policy.
1. DATA CONTROLLER
Data controller: SilaWay (the operator of the App).
Contact: [email protected]
SilaWay is the data controller for the purposes of Turkey's Personal Data Protection Law (KVKK No. 6698) and the EU General Data Protection Regulation 2016/679 (GDPR).
2. PERSONAL DATA WE PROCESS AND LEGAL BASIS
The following categories are processed for the purposes stated, on the legal bases set out in KVKK Art. 5 and GDPR Art. 6:
(a) Identity and Contact Data
• Name, email, profile photo (shared by the provider when you sign in with Google or Apple)
• Purpose: account creation, session continuity
• Legal basis: KVKK Art. 5/2(c) performance of contract · GDPR Art. 6(1)(b) contract
(b) Location Data
• Device GPS coordinates (only while active border tracking is on, processed on your device)
• Purpose: alerts when approaching a border crossing; wait time calculation
• Legal basis: KVKK Art. 5/1 explicit consent · GDPR Art. 6(1)(a) consent
• Background location is only collected when the user enables the "start border tracking" feature.
• **Your raw GPS coordinates are not stored on SilaWay's servers.** Only an anonymous wait-time contribution (which border + how many minutes) is sent to the server; this record cannot be linked back to your location or identity.
• When you use the navigation/maps (SilaAI) feature, your location coordinates are sent in real time to map/routing providers (Mapbox, TomTom — see section 3) to draw the route and display the map; they are not retained by those providers beyond computing the route.
• **While inside a border zone** (geofence), to liven up that crossing's chat we keep a **short-lived "I'm here" marker** (your pseudonymous ID + a timestamp; NOT raw GPS — only which border + direction). Other users are shown only an **anonymous total count** ("N drivers here now"); your identity is never shown to them. This marker is automatically deleted after a few minutes.
• **Mobile radar report (when the feature is enabled):** if you report a mobile camera, your report (approximate location + time) is processed **anonymously** (not linked to your identity) and shown briefly to other drivers as a live alert; old reports are discarded automatically. Fixed-camera data is compiled from a licensed third-party database (SCDB) (your personal data is NOT sent to that provider).
(c) Content Data (Community Chat)
• Messages you write in chat, your nickname, message timestamps
• Purpose: enabling community communication
• Legal basis: GDPR Art. 6(1)(b) contract + Art. 6(1)(f) legitimate interest (content moderation)
• WARNING: Content posted in chat is **public** and visible to other users. Once sent, copies of messages may remain on other users' devices.
(d) Device and Usage Data
• Device identifier (Firebase Installation ID), screen visits, error logs
• These data on their own do not identify you, but they are **not anonymous** — they are pseudonymized (linked to your account where applicable).
• Purpose: service performance, error diagnosis, abuse detection
• Legal basis: GDPR Art. 6(1)(f) legitimate interest
(e) Guest Users
• For guest sessions only an anonymous Firebase UID and device-level usage counters are stored. No personal contact information is collected.
(f) Audio Data (Voice Assistant — SilaAI)
• When you speak to the voice assistant, the short audio clip you record is processed to convert it into text; the assistant's reply text is also converted into speech.
• Purpose: speech-to-text (STT) and text-to-speech (TTS).
• Legal basis: KVKK Art. 5/1 explicit consent · GDPR Art. 6(1)(a) consent (microphone permission; if you decline, only the voice feature is unavailable).
• Your audio clip is transmitted to the relevant provider solely for real-time transcription; it is not retained by us or the provider and is not used to train AI models.
(g) Search Queries (Voice/Text Assistant)
• When you describe a place to the assistant (e.g. "where is the nearest X-brand gas station"), your search query is sent to a web search provider.
• Purpose: to find the described place. No identity or location data is sent with the query.
• Legal basis: GDPR Art. 6(1)(b) performance of contract.
3. THIRD-PARTY SERVICES
The following data processors are used to deliver the service:
• Google Firebase (Google LLC, USA) — authentication, database, notifications
• Google Maps Platform / Google Places (Google LLC, USA) — place/business search and address lookup
• Cloudflare, Inc. (USA) — server infrastructure (API proxy); chat/AI requests are routed through this proxy. To improve the service (response quality, debugging, abuse prevention), the questions you send to the AI assistant and the answers you receive are stored **without being linked to your identity (anonymous — no account/location data)** for at most **30 days**, then automatically deleted
• Open-Meteo (Bremen, EU) — weather; no identifiers sent
• A third-party LLM (AI language model) provider — chat content moderation and the AI assistant (SilaAI); the message/chat text you send is transmitted to and processed by this provider for a safety check and to generate AI replies. The provider's server/data location may be outside Turkey/the EU (including China). It is not used by us for model training; only the text you type is sent (identity data such as your account/location is not sent).
• Groq, Inc. (USA) — speech-to-text for the voice assistant (STT); the only data sent is your audio recording, not retained
• Cartesia, Inc. (USA) — text-to-speech for the voice assistant's reply (TTS); the only data sent is the reply text
• Tavily AI, Inc. (USA) — web search for travel/place information in the assistant; the only data sent is your search query (no identity/location). If this provider is unavailable, Brave Software, Inc. (USA) is used as a fallback for the same purpose
• Mapbox, Inc. (USA) — map display; map tile requests may include your approximate location
• TomTom International B.V. (Netherlands, EU) — route calculation, traffic, and speed limits, plus place/POI search and address lookup; the place name you search and your origin/destination/tapped-point coordinates are sent to this provider
• Geoapify GmbH (Germany, EU) — place/POI and address lookup (via the maps proxy, cached)
• AMSS — Auto-Moto Asocijacija Srbije (Serbia) — European border camera streams delivered to your device
• Apple Inc. (USA) — only if you sign in with Apple, as an identity provider
• Apple Inc. / Google LLC (USA) — if you buy the Season Pack (a one-time purchase), payment is processed by the store (App Store / Google Play); SilaWay does NOT see or store your card/payment details, only your premium status (active/expiry)
• RevenueCat, Inc. (USA) — used to manage/verify your premium status; the data sent is your anonymous user ID (Firebase UID) and the store purchase token (no card/payment data is sent)
Your data is not sold or shared for advertising or marketing.
4. INTERNATIONAL DATA TRANSFERS
Due to providers such as Firebase and Google Maps (USA) and a third-party LLM provider, your data may be transferred **outside Turkey and the EU (including the USA and China)**. When you use chat/AI features, your message text is sent to a third-party LLM provider (whose location may include China). When you use the voice assistant, your audio recording (Groq), reply text (Cartesia), and search query (web search provider) are sent to USA-based providers; when you use navigation, your location coordinates are sent to USA-based (Mapbox) and EU-based (TomTom) providers. These transfers are protected:
• Under KVKK Art. 9, by transfers to countries deemed adequate by the Turkish DPA or by contracts providing sufficient guarantees.
• Under GDPR Art. 46(2)(c), by the EU Standard Contractual Clauses.
For details please see the providers' own privacy policies.
5. RETENTION PERIODS
• Account data: as long as your account is active
• Wait-time contributions: kept as anonymous aggregated data for as long as the service runs (contains no raw GPS coordinates)
• Mobile radar reports: anonymous and short-lived; old reports are deleted automatically (not linked to identity)
• Chat messages: retained while your account is active. You can remove messages from within chat or by deleting your account.
• AI assistant questions and answers: stored **anonymously (not linked to your identity)** for at most **30 days**, then automatically deleted.
• Error logs: typically up to 90 days
• When you delete your account, all personal data linked to it (including messages, profile, images) is removed **at the moment of deletion**; technical copies are cleared **within 30 days at the latest**.
6. YOUR RIGHTS
Under KVKK Art. 11 and GDPR Art. 15-22 you have the right to:
• Access your data
• Request correction or deletion
• Restrict processing
• Object to processing
• Data portability
• Withdraw consent (for future processing)
• Permanently delete your account from within the app ("Settings > Delete Account")
You may send requests in writing to [email protected]. Under KVKK Art. 13, responses are provided **within 30 days at the latest**.
7. RIGHT TO LODGE A COMPLAINT
If you believe processing is unlawful, you may lodge a complaint with:
• Turkey: Personal Data Protection Authority (kvkk.gov.tr)
• EU Member States: the supervisory authority in your country of residence (e.g. Germany BfDI, Netherlands AP, Austria DSB)
8. DATA BREACH NOTIFICATION
If we detect a security breach affecting your personal data, we will notify the competent supervisory authority **within 72 hours** as required by GDPR Art. 33-34 and KVKK Art. 12/5, and we will inform affected users via in-app notification or email.
9. CHILDREN'S PRIVACY
The App is **not designed for users under 18 years of age**. Users under 18 must not use the App. Under KVKK and GDPR, processing the personal data of minors requires additional protection; we do not knowingly collect data from users under 18, and such data is deleted if discovered.
10. SECURITY
Your data is transmitted over HTTPS/TLS and stored on Google Cloud infrastructure. However, no method of transmission over the internet can be guaranteed to be 100% secure.
11. POLICY CHANGES
Significant changes to this policy will be announced via in-app notification or email. The version number (1.6.1) and "Last updated" date are updated with each revision.
12. CONTACT
Data controller: SilaWay
Email: [email protected]