Privacy and personal data protection
Last updated: 7 October 2026
This notice fulfils the duty to inform under Article 10 of the Turkish Personal Data Protection Law No. 6698 (KVKK). It explains which personal data is processed when you use wide.tr, why, and for how long it is kept.
Data controller and contact
Data controller: [email protected]
For any question or request about your personal data, write to: [email protected]
What data we process
- Account details: email address, username, display name, short bio and profile picture. Your password is stored only as an irreversible hash.
- Content you create: your graphs, their nodes and relations, and images you upload; visibility follows the access level you set on each graph (public, members-only, link, private).
- Edit history: when you create, change (add, edit or delete nodes/relations; settings, translations, views), import into, reset or delete a graph — who you are, the time and a summary of the change (counts and examples of changed node names); so that a change can be undone, the previous state of the changed records is kept too. People who can edit that graph (the owner, admin and editor members) and site administrators can see it.
- Activity records while you are logged in: which graphs and nodes you open, time spent on a graph (while the page is visible), your exports and PNG downloads, and your last login time. Site administrators can see these records.
- Visitor counters are anonymous: for visitors who are not logged in we keep only daily totals (how many times a graph or node was viewed). No IP address, cookie, fingerprint or other identifier is stored for these counters; search engines and other bots are not counted. A graph's owner can see these anonymous daily totals for their own graph (member views included, without who looked).
- Cookies and browser storage: the session cookie set when you log in (strictly necessary) and the NEXT_LOCALE cookie that remembers your language (necessary/preference) are used; Cloudflare may set its own security cookie. No advertising or tracking cookies are used. Interface preferences (e.g. dismissed tips, editing options) are kept only in your browser's local storage (localStorage) and are not sent to the server. Your email address is used for verification, password reset and invitation messages.
- Server access logs: for security (spotting attacks and abuse) the web server keeps a technical record of each request (IP address, time, requested address, browser information) for a limited period. These logs are separate from the visitor counters and are not used for activity records.
- Login records: on every login to your account (also when you sign up or reset your password) the IP address, browser, operating system, device type and time are recorded (details below).
Purpose and legal basis
We process your data to manage your account, serve and share your graphs, send messages, and keep the site secure and useful. Legal bases (KVKK Art. 5):
- Performance of a contract (Art. 5/2-c): the account, your content and email messages are needed to provide the service.
- Legitimate interest (Art. 5/2-f): activity records help us understand which content is used, spot abuse and improve the site; they are kept limited so as not to harm your fundamental rights and freedoms.
- Legal obligation (Art. 5/2-ç): login records are kept for obligations under Turkish Law No. 5651 and lawful requests from competent authorities.
Retention periods
- Detailed activity records of members (graphs and nodes opened, time spent, exports, PNG downloads) are kept for 90 days and then deleted automatically.
- Your last login time is part of your account details: it is not subject to the 90-day limit, is kept while your account is open and is updated on each login.
- Login records (IP address, browser, operating system, device type, time) are kept for 1 year and then deleted automatically.
- Edit history is kept as long as the graph exists; even when a graph is deleted, the deletion record (the graph's name, who deleted it and when) remains. If you delete your account, your identity is removed from history rows (shown as “deleted account”).
- Anonymous daily totals cannot be linked to a person, so they are not personal data and may be kept indefinitely.
- Server access logs are kept for a limited period and deleted regularly.
- Your account details and content are kept while your account is open. You can delete your account yourself with the “Delete my account” button on the Settings page: your account, the graphs you own and your activity records are deleted immediately. You can also send a deletion request to the data controller; it is carried out unless a legal retention duty applies.
Login records (IP and device)
A login record is kept for every successful login to your account, and when you sign up or log in by resetting your password. Failed login attempts are not written to this record.
- What is recorded: IP address, browser and version, operating system, device type (desktop, phone, tablet), the identification string your browser sends (user agent) and the time.
- Purpose: the security of your account (spotting logins you don't recognise), preventing abuse and meeting legal obligations under Turkish Law No. 5651.
- Legal basis: KVKK Art. 5/2-ç (legal obligation of the data controller) and Art. 5/2-f (legitimate interest).
- Retention: 1 year; expired records are deleted automatically every day. If you delete your account, your login records are deleted immediately too.
- Who has access: site administrators only; competent authorities when legally required. You can see your own recent logins on the Settings page.
Transfers
Your data is not sold or shared for advertising. It is passed on only as far as needed to run the service: to our hosting provider and to Cloudflare, which we use as a content delivery network (CDN). Cloudflare sits in front of the site's traffic and processes your IP address while doing so, so data may be transferred abroad. Data may be shared with competent public authorities when legally required.
Only strictly necessary and preference cookies are used (session, language preference, Cloudflare security cookie); since there are no advertising or tracking cookies, no cookie consent banner is shown.
Your rights and how to apply
Under KVKK Art. 11 you may apply to the data controller to:
- find out whether your personal data is processed,
- request information if it has been processed,
- learn the purpose of processing and whether it is used accordingly,
- know the third parties it is transferred to, in Turkey or abroad,
- request correction if it is incomplete or inaccurate,
- request deletion or destruction under KVKK Art. 7,
- request that corrections and deletions be notified to third parties the data was transferred to,
- object to a result against you that arises solely from automated analysis of the data,
- claim compensation if you suffer damage from unlawful processing.
Send your request from the email address registered on your account to the contact address above; we may ask for extra information to verify your identity.
Your request is answered within 30 days at the latest, depending on its nature. If you find the answer insufficient, you keep the right to complain to the Personal Data Protection Board.