Legal

Privacy Policy

What Sim4App collects, why, who else sees it, how long it is kept, and how to get it removed. Written to match what the app and our servers actually do.

Hukuki

Gizlilik Politikası

Sim4App'in neyi topladığı, neden topladığı, başka kimin gördüğü, ne kadar sakladığı ve nasıl sildirebileceğiniz. Uygulamanın ve sunucularımızın gerçekte yaptığı işe göre yazıldı.

Last updated: 9 September 2026 · Effective: 9 September 2026

1. Who we are

Sim4App is a mobile application that lets you receive SMS verification codes on a temporary virtual phone number instead of your own. It is operated by Webmetri ("we", "us"), which is the data controller for the personal data described here.

Reach us about anything in this policy at privacy@sim4.app, or through the Support tab in the app.

2. At a glance

We do not ask for your real phone number. We do not sell personal data, we do not run advertising or ad tracking in the app, and we do not share your data with data brokers.

We do share data with the service providers that make the app function — Google Firebase for sign-in and push, RevenueCat with Apple and Google for purchases, and the telecom partners that own the numbers. Those partners handle the SMS messages sent to a number you rent. Section 6 lists every one of them.

3. What we collect

Account and sign-in

Sign-in is handled by Google Firebase Authentication. Depending on the method you choose we receive and store:

You can also use the app as a guest without giving an email address, and link a permanent sign-in method later. We never receive or store your password — Firebase handles credentials.

Device and technical data

Approximate location (country only)

We work out which country a request comes from so we can hide services that may not lawfully be offered in that jurisdiction. The country is resolved from your IP address using a database installed on our own server, or from a header set by our reverse proxy, or from the region your device reports. Your IP address is not sent to a third-party lookup service for this. We do not collect GPS or precise location at any point.

Purchases

Coins are bought as in-app purchases through the App Store or Google Play. Payment itself happens inside the store: we never see your card number, bank details or billing address. What we store is the record of the transaction — store name, store transaction identifier, product identifier, price and currency as reported by the store, the coin amount and your resulting balance.

Numbers you rent and messages you receive

Please keep in mind that a virtual number is shared infrastructure. Anyone can send an SMS to it while it is allocated to you, and the number is returned to the pool afterwards. Do not use it for banking, government services, or any account you cannot afford to lose access to.

Support conversations

When you open a support ticket we store its subject, category, status and the full message history, including any image you attach (PNG, JPEG, WebP or GIF, up to 10 MB each). Attachments are stored as files on our server. Our team may also record internal notes about a case on your account.

The number-use agreement

Before your first order the app asks you to accept an agreement about lawful use of the numbers, and to type your full name as a signature. To make that acceptance provable we record the name you typed, the time, the language and version of the text you saw, your IP address, user agent, device identifier, platform, operating system version and app version. The same record is created again, more briefly, each time you reaffirm it at purchase.

Notifications

If you allow notifications we store the Firebase Cloud Messaging token for each of your devices, plus which notification categories you have turned on. Tokens that stop working are dropped automatically. We also record when an in-app announcement was delivered to you and whether it was read.

App analytics

The app includes Google's Firebase Analytics SDK, which may record standard app-usage measurements such as app opens, session length, device model, operating system version and coarse region, under an identifier Google generates for the app installation. On Android that SDK also declares the advertising-identifier permission, which is why the Play listing mentions it.

Sim4App shows no advertising. There is no advertising-network SDK in the app, we do not use any identifier to target ads at you, and we do not combine analytics measurements with your email address.

4. What we never collect

5. Why we use it

Purpose Data used Legal basis (GDPR / KVKK)
Creating your account and keeping you signed in Firebase identifier, email, sign-in methods Performance of a contract
Allocating numbers and showing you the codes that arrive Order records, number, message content Performance of a contract
Selling coins, refunding failed orders, keeping the ledger Purchase records, balance, transaction history Contract; legal obligation (accounting)
Answering support tickets Ticket messages, attachments, account context Contract; legitimate interests
Preventing fraud, abuse and multi-account farming Device identifiers, IP, access logs, order patterns Legitimate interests
Hiding services that cannot lawfully be offered in your region Country derived from IP or device region Legal obligation; legitimate interests
Proving that the number-use agreement was accepted Name typed, timestamp, IP, device and app details Legitimate interests; legal obligation
Sending push notifications about codes, replies and announcements Push tokens, notification preferences Consent (withdrawable in Settings or the OS)
Showing the app in your language Language preference, device locale Performance of a contract
Keeping the service secure and investigating incidents Access logs, IP, user agent Legitimate interests; legal obligation

We do not use your data for automated decisions with a legal effect on you, and we do not profile you for advertising.

6. Who else sees it

We share personal data only with the providers below, only for the purpose stated, and only to the extent they need it. None of them is permitted to use it for their own marketing.

Provider What it does for us What it receives
Google (Firebase Authentication) Sign-in with email, Google or Apple, and guest sessions Email address, authentication events, device and IP data
Google (Firebase Cloud Messaging) Delivering push notifications Push token, notification title and body, related order id
Google (Firebase Analytics) Standard app-usage measurement App installation identifier, device and usage events, and on Android the advertising identifier the SDK requests
Apple App Store · Google Play Taking payment for coin purchases Your payment details, which they process as their own controller
RevenueCat Validating store receipts so coins are credited exactly once Your Firebase identifier and the store's purchase data
Telecom number partners (currently SMSPVA and OnlineSim) Owning the numbers and receiving the SMS traffic The country and service code and an order identifier. They do not receive your identity, but as the operators of the number they necessarily handle the messages sent to it.
Google (Gemini API) Translating interface text, and helping our team draft and translate support replies Interface strings; and, when the drafting aid is used on a ticket, the text of that support conversation
Our hosting provider Running the servers and storing the database and attachments Everything described in section 3, as stored data

We will also disclose data where the law requires it — a valid order from a court or a competent authority — or where it is necessary to establish or defend a legal claim, or to protect someone's safety. We will not hand over more than the request covers.

If Sim4App is ever sold or merged, personal data may transfer to the acquirer. You would be told before that happens and this policy would continue to apply until replaced.

7. How long we keep it

Where we have no defined retention period for a category, we keep the data only as long as the purpose in section 5 requires, and review it periodically.

8. Deleting your account

Open Settings → Delete account in the app. The request is scheduled with a 30-day waiting period so that an accidental or pressured request can be reversed; during that time the same screen offers a Cancel button and your account keeps working normally.

When the waiting period elapses, automatically and without further action from you:

What stays, and why, is listed in section 7: the financial ledger, order and message records stripped of their link to you, support history, agreement acceptances and security logs.

If you cannot get into the app, email privacy@sim4.app from the address on the account and we will verify you another way and do it for you.

9. Your rights

Depending on where you live — including under the EU/UK GDPR and Turkey's KVKK — you can ask us to:

Write to privacy@sim4.app. We answer within 30 days. We may need to confirm you are the account holder first — usually by asking you to write from the account's email address — because handing account data to the wrong person is its own privacy breach. Exercising any of these rights costs nothing and will not degrade the service.

If you are not satisfied with our answer you can complain to your local data protection authority. In Turkey that is the Personal Data Protection Authority (KVKK); in the EU it is the authority for the country you live in.

10. Children

Sim4App is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has created an account, tell us at privacy@sim4.app and we will close it and delete the data.

11. Security

Traffic between the app and our servers is encrypted with TLS. Authentication is delegated to Firebase, so no password ever reaches us. Administrative access to user data is limited to the accounts that need it, and every administrative change is written to an append-only audit log. Uploaded images are stored under server-generated filenames and served with a fixed content type so an upload cannot be turned into executable content.

No system is perfectly secure. If a breach ever affects your personal data we will notify you and the competent authority as the law requires.

12. International transfers

Our own servers are operated in the European Union. Several of the providers in section 6 — Google, RevenueCat, Apple and our telecom partners — operate globally, so your data may be processed outside your country, including in the United States. Where that happens we rely on the transfer mechanisms those providers offer, such as the European Commission's standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.

13. Changes to this policy

When this policy changes we update it here and change the date at the top. If a change materially affects how we use your data we will also tell you in the app before it takes effect. Continuing to use Sim4App after that means the updated policy applies to you.

14. Contact

Privacy and data requests: privacy@sim4.app
Everything else: support@sim4.app or the Support tab in the app
Operator: Webmetri, operator of Sim4App

Son güncelleme: 9 Eylül 2026 · Yürürlük: 9 Eylül 2026

1. Kimiz

Sim4App, SMS doğrulama kodlarını kendi numaranız yerine geçici bir sanal telefon numarasında almanızı sağlayan bir mobil uygulamadır. Webmetri ("biz") tarafından işletilir ve burada anlatılan kişisel veriler bakımından veri sorumlusu Webmetri'dir.

Bu politikayla ilgili her konuda privacy@sim4.app adresinden veya uygulamadaki Destek sekmesinden bize ulaşabilirsiniz.

2. Kısaca

Gerçek telefon numaranızı istemiyoruz. Kişisel veri satmıyoruz, uygulamada reklam veya reklam takibi yürütmüyoruz ve verilerinizi veri tacirleriyle paylaşmıyoruz.

Uygulamanın çalışmasını sağlayan hizmet sağlayıcılarla veri paylaşıyoruz: giriş ve bildirim için Google Firebase, satın alma için Apple ve Google ile birlikte RevenueCat, ve numaraların sahibi olan telekom partnerleri. Kiraladığınız numaraya gelen SMS'ler bu partnerlerin elinden geçer. 6. bölümde hepsi tek tek listelidir.

3. Neleri topluyoruz

Hesap ve giriş

Giriş işlemleri Google Firebase Authentication tarafından yürütülür. Seçtiğiniz yönteme göre şunları alır ve saklarız:

Uygulamayı e-posta vermeden misafir olarak da kullanabilir, kalıcı bir giriş yöntemini sonra bağlayabilirsiniz. Şifrenizi hiç almıyor ve saklamıyoruz; kimlik bilgilerini Firebase yönetir.

Cihaz ve teknik veriler

Yaklaşık konum (yalnızca ülke)

Bir isteğin hangi ülkeden geldiğini, o ülkede hukuken sunulamayacak servisleri gizlemek için belirleriz. Ülke; kendi sunucumuzda kurulu bir veritabanıyla IP adresinizden, ters vekil sunucumuzun eklediği bir başlıktan ya da cihazınızın bildirdiği bölgeden çözümlenir. IP adresiniz bu amaçla üçüncü taraf bir sorgulama servisine gönderilmez. GPS veya hassas konum verisini hiçbir aşamada toplamıyoruz.

Satın alımlar

Coin'ler App Store veya Google Play üzerinden uygulama içi satın alma olarak alınır. Ödemenin kendisi mağazanın içinde gerçekleşir; kart numaranızı, banka bilgilerinizi veya fatura adresinizi asla görmeyiz. Sakladığımız şey işlemin kaydıdır: mağaza adı, mağaza işlem kimliği, ürün kimliği, mağazanın bildirdiği fiyat ve para birimi, coin miktarı ve işlem sonrası bakiyeniz.

Kiraladığınız numaralar ve gelen mesajlar

Sanal numaranın paylaşılan bir altyapı olduğunu unutmayın. Numara size ayrıldığı sürece herkes ona SMS gönderebilir ve sonrasında numara havuza döner. Bankacılık, kamu hizmetleri ya da erişimini kaybetmeyi göze alamayacağınız hiçbir hesap için kullanmayın.

Destek görüşmeleri

Destek talebi açtığınızda talebin konusunu, kategorisini, durumunu ve tüm mesaj geçmişini, eklediğiniz görsellerle birlikte saklarız (her biri en fazla 10 MB; PNG, JPEG, WebP veya GIF). Ekler sunucumuzda dosya olarak tutulur. Ekibimiz ayrıca bir vakayla ilgili dahili notlar da tutabilir.

Numara kullanım onayı

İlk siparişinizden önce uygulama, numaraların hukuka uygun kullanımına dair bir metni kabul etmenizi ve imza yerine geçmek üzere ad soyadınızı yazmanızı ister. Bu kabulün kanıtlanabilmesi için yazdığınız adı, zamanı, gördüğünüz metnin dilini ve sürümünü, IP adresinizi, kullanıcı aracınızı, cihaz kimliğinizi, platformu, işletim sistemi sürümünü ve uygulama sürümünü kaydederiz. Satın alma sırasında her yeniden onayda aynı kayıt daha kısa biçimde yeniden oluşturulur.

Bildirimler

Bildirimlere izin verirseniz her cihazınız için Firebase Cloud Messaging jetonunu ve açık bıraktığınız bildirim kategorilerini saklarız. Çalışmayı bırakan jetonlar otomatik olarak listeden düşer. Uygulama içi bir duyurunun size ne zaman iletildiğini ve okunup okunmadığını da kaydederiz.

Uygulama ölçümleri

Uygulama, Google'ın Firebase Analytics SDK'sını içerir; bu SDK uygulama açılışı, oturum süresi, cihaz modeli, işletim sistemi sürümü ve kaba bölge gibi standart kullanım ölçümlerini, Google'ın uygulama kurulumu için ürettiği bir kimlik altında kaydedebilir. Android'de bu SDK reklam kimliği iznini de bildirir; Play sayfasında bundan söz edilmesinin nedeni budur.

Sim4App'te hiçbir reklam gösterilmez. Uygulamada reklam ağı SDK'sı yoktur, hiçbir kimliği size reklam hedeflemek için kullanmıyoruz ve ölçüm verilerini e-posta adresinizle birleştirmiyoruz.

4. Hiç toplamadıklarımız

5. Neden kullanıyoruz

Amaç Kullanılan veri Hukuki dayanak (KVKK / GDPR)
Hesabınızı oluşturmak ve oturumu sürdürmek Firebase kimliği, e-posta, giriş yöntemleri Sözleşmenin ifası
Numara ayırmak ve gelen kodları göstermek Sipariş kayıtları, numara, mesaj içeriği Sözleşmenin ifası
Coin satışı, başarısız siparişlerin iadesi, defterin tutulması Satın alma kayıtları, bakiye, işlem geçmişi Sözleşme; hukuki yükümlülük (muhasebe)
Destek taleplerini yanıtlamak Talep mesajları, ekler, hesap bağlamı Sözleşme; meşru menfaat
Dolandırıcılığı, kötüye kullanımı ve çoklu hesap üretimini önlemek Cihaz kimlikleri, IP, erişim kayıtları, sipariş örüntüleri Meşru menfaat
Bölgenizde hukuken sunulamayan servisleri gizlemek IP veya cihaz bölgesinden türetilen ülke Hukuki yükümlülük; meşru menfaat
Numara kullanım onayının verildiğini kanıtlamak Yazılan ad, zaman, IP, cihaz ve uygulama bilgileri Meşru menfaat; hukuki yükümlülük
Kodlar, yanıtlar ve duyurular için bildirim göndermek Bildirim jetonları, bildirim tercihleri Açık rıza (Ayarlar'dan veya sistemden geri alınabilir)
Uygulamayı kendi dilinizde göstermek Dil tercihi, cihaz yereli Sözleşmenin ifası
Hizmeti güvende tutmak ve olayları incelemek Erişim kayıtları, IP, kullanıcı aracısı Meşru menfaat; hukuki yükümlülük

Verilerinizi hakkınızda hukuki sonuç doğuran otomatik kararlar için kullanmıyoruz ve reklam amaçlı profilleme yapmıyoruz.

6. Başka kim görüyor

Kişisel verileri yalnızca aşağıdaki sağlayıcılarla, yalnızca belirtilen amaçla ve yalnızca ihtiyaç duydukları kadar paylaşıyoruz. Hiçbirinin bu verileri kendi pazarlaması için kullanmasına izin verilmez.

Sağlayıcı Bizim için ne yapıyor Neyi alıyor
Google (Firebase Authentication) E-posta, Google veya Apple ile giriş ve misafir oturumları E-posta adresi, kimlik doğrulama olayları, cihaz ve IP verisi
Google (Firebase Cloud Messaging) Bildirimlerin iletilmesi Bildirim jetonu, bildirim başlığı ve gövdesi, ilgili sipariş kimliği
Google (Firebase Analytics) Standart uygulama kullanım ölçümü Uygulama kurulum kimliği, cihaz ve kullanım olayları; Android'de SDK'nın istediği reklam kimliği
Apple App Store · Google Play Coin satın alımlarında ödemenin alınması Ödeme bilgileriniz; bunları kendi veri sorumlusu olarak işlerler
RevenueCat Mağaza makbuzlarının doğrulanması, coin'in tam bir kez yüklenmesi Firebase kimliğiniz ve mağazanın satın alma verisi
Telekom numara partnerleri (şu an SMSPVA ve OnlineSim) Numaraların sahibi olmaları ve SMS trafiğini almaları Ülke ve servis kodu ile bir sipariş kimliği. Kimliğinizi almazlar; ancak numaranın işletmecisi olduklarından o numaraya gelen mesajlar zorunlu olarak ellerinden geçer.
Google (Gemini API) Arayüz metinlerinin çevirisi; ekibimizin destek yanıtlarını yazması ve çevirmesi Arayüz metinleri; destek yardımcısı bir talepte kullanıldığında o destek görüşmesinin metni
Barındırma sağlayıcımız Sunucuların işletilmesi, veritabanı ve eklerin depolanması 3. bölümde anlatılan her şey, saklanan veri olarak

Hukukun zorunlu kıldığı hallerde — mahkemeden veya yetkili bir makamdan gelen geçerli bir talep — ya da bir hukuki talebin ileri sürülmesi veya savunulması için, ya da birinin güvenliğini korumak için de veri açıklarız. Talebin kapsadığından fazlasını vermeyiz.

Sim4App bir gün satılır veya birleşirse kişisel veriler devralan tarafa geçebilir. Bu gerçekleşmeden önce size bildirilir ve bu politika değiştirilene kadar geçerli olmaya devam eder.

7. Ne kadar saklıyoruz

Bir veri kategorisi için tanımlı bir saklama süresi bulunmadığında, veriyi yalnızca 5. bölümdeki amaç gerektirdiği sürece tutar ve düzenli olarak gözden geçiririz.

8. Hesabınızı silmek

Uygulamada Ayarlar → Hesabı sil yolunu açın. Talep, yanlışlıkla veya baskı altında verilmiş bir isteğin geri alınabilmesi için 30 günlük bekleme süresiyle planlanır; bu süre boyunca aynı ekran İptal düğmesi sunar ve hesabınız normal şekilde çalışmayı sürdürür.

Bekleme süresi dolduğunda, sizden başka bir işlem gerekmeksizin otomatik olarak:

Nelerin kaldığı ve nedeni 7. bölümde listelidir: mali defter, sizinle bağlantısı kesilmiş sipariş ve mesaj kayıtları, destek geçmişi, onay kabulleri ve güvenlik kayıtları.

Uygulamaya giremiyorsanız hesaptaki adresten privacy@sim4.app adresine yazın; kimliğinizi başka bir yolla doğrulayıp işlemi sizin için yapalım.

9. Haklarınız

Yaşadığınız yere göre — KVKK ve AB/BK GDPR kapsamında da — bizden şunları talep edebilirsiniz:

privacy@sim4.app adresine yazın. 30 gün içinde yanıt veriyoruz. Hesap sahibi olduğunuzu önce doğrulamamız gerekebilir — genellikle hesabın e-posta adresinden yazmanızı isteyerek — çünkü hesap verisini yanlış kişiye vermek başlı başına bir gizlilik ihlalidir. Bu hakların kullanılması ücretsizdir ve hizmetinizi hiçbir şekilde kısıtlamaz.

Yanıtımızdan memnun kalmazsanız yerel veri koruma otoritesine şikâyette bulunabilirsiniz. Türkiye'de bu Kişisel Verileri Koruma Kurumu (KVKK), AB'de yaşadığınız ülkenin otoritesidir.

10. Çocuklar

Sim4App 18 yaşından küçükler için tasarlanmamıştır ve çocuklardan bilerek kişisel veri toplamıyoruz. Bir çocuğun hesap açtığını düşünüyorsanız privacy@sim4.app adresine bildirin; hesabı kapatıp verileri silelim.

11. Güvenlik

Uygulama ile sunucularımız arasındaki trafik TLS ile şifrelenir. Kimlik doğrulama Firebase'e devredilmiştir; bu yüzden hiçbir şifre bize ulaşmaz. Kullanıcı verisine yönetsel erişim yalnızca ihtiyacı olan hesaplarla sınırlıdır ve her yönetsel değişiklik yalnızca eklemeye açık bir denetim kaydına yazılır. Yüklenen görseller sunucunun ürettiği dosya adlarıyla saklanır ve sabit bir içerik tipiyle sunulur; böylece bir yükleme çalıştırılabilir içeriğe dönüştürülemez.

Hiçbir sistem kusursuz güvenli değildir. Kişisel verilerinizi etkileyen bir ihlal yaşanırsa hukukun gerektirdiği şekilde size ve yetkili otoriteye bildirimde bulunuruz.

12. Yurt dışına aktarım

Kendi sunucularımız Avrupa Birliği'nde işletilir. 6. bölümdeki sağlayıcıların birçoğu — Google, RevenueCat, Apple ve telekom partnerlerimiz — küresel olarak faaliyet gösterir; bu nedenle verileriniz ülkenizin dışında, Amerika Birleşik Devletleri dahil, işlenebilir. Böyle durumlarda bu sağlayıcıların sunduğu aktarım mekanizmalarına dayanırız: Avrupa Komisyonu'nun standart sözleşme hükümleri ve uygulanabildiği yerde AB–ABD Veri Gizliliği Çerçevesi gibi.

13. Bu politikadaki değişiklikler

Bu politika değiştiğinde burada güncelleriz ve en üstteki tarihi değiştiririz. Bir değişiklik verilerinizi kullanma şeklimizi esaslı biçimde etkiliyorsa yürürlüğe girmeden önce uygulamada da size bildiririz. Bundan sonra Sim4App'i kullanmaya devam etmeniz, güncellenmiş politikanın size uygulanacağı anlamına gelir.

14. İletişim

Gizlilik ve veri talepleri: privacy@sim4.app
Diğer her şey: support@sim4.app veya uygulamadaki Destek sekmesi
İşletmeci: Webmetri, Sim4App işletmecisi