TDS

Legal

RemindMate Privacy Policy

Last updated: July 30, 2026

RemindMate("App", "Service", "we", "us", "our") values your privacy. This Privacy Policy and KVKK Disclosure Notice ("Policy") explains, under Law No. 6698 on the Protection of Personal Data ("KVKK") and — for European Economic Area / United Kingdom users — the General Data Protection Regulation ("GDPR"), what personal data we process when you use the RemindMate app, for what purposes, on what legal bases, with whom it may be shared, how long it is retained, and what rights you have.

Except where processing is based on explicit consent (see §9), this Policy is not a standalone consent statement; it fulfills our disclosure obligation under KVKK Art. 10.

1. Identity of the Data Controller

FieldInformation
Legal / business nameRemindMate
App package identifiersiOS: com.thedynamicstudios.remindmate · Android: com.thedynamicstudios.remindmate
Contact (including KVKK/GDPR requests)support.thedynamicstudios@gmail.com
Websitehttps://www.thedynamicstudios.com/en/apps/remindmate

RemindMate acts as the data controller for personal data processed under this Policy.

2. Personal Data We Collect and Categories

2.1 Identity and Contact Data (Account Information)

When you create an account, we collect:

  • Email address
  • Password (stored only in a secure, one-way hashed form; we can never view your plain-text password)
  • Display name and optional profile information you provide

Authentication is provided through Supabase Auth (PKCE-based email/password sign-in, password reset, and session management).

2.2 Reminder and App Content Data

  • Reminder titles, descriptions, categories (medication, finance, shopping, daily tasks)
  • Schedule times, recurrence rules, completion/missed status
  • Notes and labels you attach to reminders
  • In-app preference settings (language, theme, notification options)

This data is stored on Supabase (PostgreSQL) and associated with your account. A local cache on your device supports offline access and syncs when connectivity returns.

2.3 Family Watch (Caregiver Mode) Data

When you use Family Watch, additional data is processed to link caregivers and monitored persons:

  • Invite codes and QR-based pairing tokens
  • Linked account relationships (caregiver ↔ monitored person)
  • Medication schedules and dose completion/missed status visible to authorized caregivers
  • Caregiver alert preferences for missed doses or critical events

Authorized caregivers can view only the data permitted by the app's Family Watch permission model. You are responsible for whom you invite and link.

2.4 Notification and Communication Data

If you opt in, we use local notifications and — where enabled — OneSignal (with Firebase Cloud Messaging on Android) for reminder alerts, missed-dose notifications to caregivers, and service-related messages. Push delivery requires a device push token and subscriber record. You can disable notifications in device settings or within the app.

2.5 Analytics and Crash Data — Production Builds Only

Only in production app builds (not development/test builds), we use Firebase Analytics and Firebase Crashlytics:

  • Feature usage statistics (e.g. creating reminders, completing doses, Family Watch pairing)
  • Device model, OS version, app version, anonymous crash logs (stack traces)

This data is not used for personalized advertising and does not include reminder content such as medication names or health notes.

2.6 On-Device Local Storage

The app uses on-device local storage for caching reminders, preferences, and offline sync queues. This data is cleared at the device level when you uninstall the app or delete your account.

2.7 Support and Communication Records

When you contact us by email, we retain your message and contact details for a reasonable period to respond and improve service quality.

2.8 Automatically Collected Technical Data

The app and our infrastructure providers (Supabase, Firebase) may automatically process technical data such as IP address, device/OS information, app version, and session timestamps for security, debugging, and service continuity.

3. Purposes of Processing Personal Data

Your personal data is processed for the following purposes:

  1. Creating, verifying, and managing your account
  2. Storing and synchronizing reminders across devices
  3. Delivering scheduled and local reminder notifications
  4. Enabling Family Watch linking, monitoring, and caregiver alerts
  5. Measuring app performance, diagnosing and fixing errors (production only)
  6. Monitoring compliance with terms of service, detecting and preventing abuse
  7. Fulfilling legal obligations, responding to legal requests, and protecting our rights
  8. Responding to support requests

We do not sell your personal data. We do not use your reminder or health-related content for third-party advertising.

4. Legal Bases for Processing

4.1 Türkiye (KVKK Art. 5)

  • Performance of a contract (Art. 5/2-c): account creation, reminder sync, Family Watch features
  • Legal obligation (Art. 5/2-ç): legal request processes
  • Legitimate interest (Art. 5/2-f): security, abuse prevention, analytics, and product development (subject to balancing test)
  • Explicit consent (Art. 5/1): push notification permission (see §9)

4.2 EEA/UK Users (GDPR)

  • Contract (Art. 6/1-b): providing the Service
  • Legitimate interest (Art. 6/1-f): security, analytics, product improvement
  • Consent (Art. 6/1-a): notifications where required

5. Recipients of Personal Data and Transfer Purposes

To provide the Service, your data may be shared with the following service providers (data processors), limited to the stated purposes:

ProviderRoleDataLocation
SupabaseAuthentication, database, Realtime, Edge FunctionsAccount, profile, reminders, Family Watch linkage dataEU/US (per provider infrastructure)
Firebase (Google)Analytics and crash reporting (production only)Device/app identifiers, usage events, crash logsUS/Global
OneSignalPush notification deliveryDevice token, subscriber ID, notification preferencesUnited States
Apple / GooglePush delivery infrastructure (FCM/APNs)Device tokens per their policiesUS / Global

Each provider processes your data on behalf of RemindMate and in accordance with our instructions, under their own privacy and security commitments. Where international transfers occur, appropriate safeguards under KVKK Art. 9 and GDPR (e.g. Standard Contractual Clauses) apply.

Except where legally required, your personal data is not sold or rented to third parties for marketing purposes.

6. Methods of Collection

Your data is collected electronically through in-app forms (registration, profile, creating reminders), device permissions (notifications), automatic technical logging (via SDKs), Family Watch invite/QR flows, and — where applicable — support emails.

7. Retention Periods

Data categoryRetention period
Account and reminder dataWhile your account is active
After account deletionSettings → Account → Delete Account triggers server-side deletion; auth record and related profile/reminder/Family Watch data are removed from Supabase. Disaster recovery backups may be retained for up to 30 days.
Analytics / crash logsPer Firebase default/configured retention (typically 14–26 months, in aggregated and anonymized form)
Support correspondenceA reasonable period after resolution, up to 2 years maximum

When the retention period ends or the processing purpose ceases, data is deleted, destroyed, or anonymized.

8. Data Subject Rights

8.1 Your Rights Under KVKK Art. 11

Under KVKK Art. 11, you may apply to us to:

  • Learn whether your personal data is being processed
  • Request information if it has been processed
  • Learn the purpose of processing and whether it is used in accordance with that purpose
  • Know third parties to whom data is transferred domestically or abroad
  • Request correction if data is incomplete or inaccurate
  • Request deletion/destruction when conditions under KVKK Art. 7 are met
  • Request notification of correction/deletion to third parties to whom data was transferred
  • Object to a result arising solely from automated processing that is adverse to you
  • Claim compensation for damage arising from unlawful processing

8.2 Additional Rights Under GDPR (EEA/UK Users)

Access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection, and withdrawal of consent are also available under GDPR. You retain the right to lodge a complaint with the relevant supervisory authority.

8.3 How to Exercise Your Rights

To exercise your rights, submit a written request to support.thedynamicstudios@gmail.com. We may ask you to verify your identity. Requests are processed free of charge within 30 days under KVKK Art. 13.

In-app actions: edit profile (Settings), delete account (Settings → Account → Delete Account), disable notification preferences (device settings / in-app), revoke Family Watch links (Settings → Family Watch).

9. Processing Requiring Explicit Consent

For the following activities, your explicit consent is obtained separately from this disclosure, at the time of the action (via permission prompt / consent screen):

  • Push notification permission (iOS/Android system permission prompt)

You may withdraw these permissions at any time in device settings; withdrawal may limit reminder and caregiver alerts but does not affect your account.

10. Children's Privacy

RemindMate is not directed at children under 13 (or 16 where applicable in the EEA) and does not knowingly collect personal data from this age group. If you believe a child has provided data to us, please contact support.thedynamicstudios@gmail.com; we will delete it promptly.

11. Data Security

We apply the following technical and organizational measures to protect your personal data:

  • TLS encryption in transit
  • Supabase Row Level Security (RLS) for database access control — each user can access only their own data and authorized Family Watch relationships
  • Hardened authorization for server-side (service-role) operations (JWT verification) — e.g. account deletion and Family Watch pairing endpoints
  • No hardcoded secrets in production app binaries; keys injected at build time
  • R8/ProGuard obfuscation on Android; Dart code obfuscation (--obfuscate) on production iOS builds

No transmission or storage method is 100% secure; absolute security cannot be guaranteed. If a security breach affecting personal data is detected, notification will be made to data subjects and/or competent authorities within the time and manner required by applicable law (KVKK, GDPR).

12. International Data Transfers

Our service providers (Supabase, Firebase, OneSignal, Apple, Google) may process your data outside Türkiye (primarily in the United States). These transfers rely on appropriate safeguards under KVKK Art. 9 and GDPR equivalent tools such as Standard Contractual Clauses (SCCs).

13. Policy Changes

This Policy may be updated from time to time. The current version is always published at https://www.thedynamicstudios.com/en/apps/remindmate/privacywith an updated "Last Updated" date. Material changes may also be communicated via in-app notification or email. Continued use of the Service after an update means you accept the updated Policy.

14. Contact

RemindMate
Email: support.thedynamicstudios@gmail.com
Website: https://www.thedynamicstudios.com/en/apps/remindmate

Terms: Terms of Service