Privacy Policy
Privacy Policy — Menty: CBT for Anxiety Relief
Last updated: 16 July 2026
1. Introduction
This Privacy Policy explains how Seyfi Can Zeyrek (trading as Morrowline Apps) (“we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data when you use the mobile application Menty: CBT for Anxiety Relief (“Menty,” the “App,” or the “Service”) on Android and iOS, and related pages on https://menty.morrowline.app/.
Menty provides digital wellness and self-help content inspired by approaches such as CBT, mindfulness, and self-compassion. It is not a medical device, does not diagnose, treat, or cure anxiety or any medical or mental-health condition, and is not a substitute for professional medical or mental-health care. AI-generated check-ins and advice are automated suggestions with limitations; they are not professional, clinical, or emergency advice.
By using the App, you acknowledge this Privacy Policy. Our Terms of Use are available at https://menty.morrowline.app/en/terms/. Turkish users should also read our KVKK disclosure notice (aydınlatma metni): https://menty.morrowline.app/en/kvkk/ (also available as https://menty.morrowline.app/en/kvkk/). Explicit consent under KVKK, where required, is obtained separately and is not merged into this Privacy Policy.
2. Data controller
| Field | Details |
|---|---|
| Controller | Seyfi Can Zeyrek (trading as Morrowline Apps) |
| Address | Esenyali Mahallesi 52/75 Sk. Izmir/Türkiye |
| Country | Republic of Türkiye |
| Phone | +90 555 027 76 81 |
| Privacy / support email | sczgamesinfo@gmail.com |
The controller is an individual developer (natural person). “Morrowline Apps” is a brand name only and is not a separate registered company or legal entity.
We have not appointed a Data Protection Officer (DPO). For all privacy requests, contact us at sczgamesinfo@gmail.com.
3. Scope
This Policy applies to:
- The Menty App on Android and iOS (current store versions, including Android version name 2.0 / version code 7 as published)
- Personal data processing described in our product inventory for Firebase, OpenAI, store billing, local storage, and local notifications
- Visitors who open this Policy or related legal pages on https://menty.morrowline.app/
This Policy does not cover third-party websites, app stores, or services that we do not control (for example Apple, Google Play, or OpenAI’s own consumer products), except to describe how we use their APIs as processors or platforms for features you request.
Markets in scope for this Policy and its annexes: Türkiye (TR), European Union / EEA (EU), United Kingdom (UK), and United States (US).
4. Data we collect
Core usage data (for example moments, local AI advice cache, and journey progress) stays on your device in the on-device database. Limited cloud processing occurs for anonymous authentication, subscription/premium status and usage counters, optional feedback and AI like/report uploads, remote configuration (including OpenAI API key fetch), crash/analytics telemetry, App Check attestation, and AI chat completions via OpenAI, using Firebase (Auth, Firestore, Analytics, Crashlytics, App Check) and OpenAI.
The App uses Firebase Anonymous Authentication (an anonymous identifier) and may use a device identifier (Android ID / identifierForVendor) as the Firestore document key for user-related cloud records. This is not the absence of an account or identity.
Onboarding and personalization answers may be processed on-device and, where implemented, sent as analytics event parameters (including age band, gender, neurodivergence flag, past support, goals, and quiz answers) via Firebase Analytics. They are not treated as completely confidential relative to the analytics and cloud processors named in this Policy.
4.1 Data stored on your device
| Category | Examples | Purpose | Location | Retention | Shared with |
|---|---|---|---|---|---|
| Health / wellness journal content | Situation, emotion, thought, behavior, body sensations; AI check-in free text; AI request/response JSON; moments; journey progress; favorite techniques; app-open history | Journaling, CBT-inspired journeys, on-device AI advice cache, progress tracking | On device (SQLDelight); not SQLCipher-encrypted in the current build | Until you uninstall the App or clear App storage | Not shared from this store unless you trigger cloud features below |
| App preferences / settings | notifications_enabled; feedback_count; has_rated_app; reported/liked advice ids; selected_content_category; discount_dismissal_count; has_purchased; app_open_count | Reminders, rating prompts, content category, purchase flags | On device (multiplatform Settings / SharedPreferences / NSUserDefaults) | Until uninstall | Not uploaded as a bulk prefs dump |
| Language preference | selected_language | Locale / language | On device | Until uninstall | Not shared |
| Device identifier (local copy) | Android Settings.Secure.ANDROID_ID; iOS UIDevice.identifierForVendor | Key related cloud records; associate anonymous session | On device, and used as Firestore document key | Until uninstall (local); cloud key may persist after uninstall | Google Firebase (Firestore path keyed by device id) |
4.2 Data processed in the cloud (via Firebase)
| Category | Examples | Purpose | Location | Retention | Shared with |
|---|---|---|---|---|---|
| Device / account identifiers | Device id as Firestore doc id; Firebase Anonymous Auth UID; premium flag; subscription_end_date; techniques_started_count; ai_checkin_count; moments_logged_count | Anonymous identity, premium entitlement sync, usage counters | Google Cloud / Firebase Firestore (koru_users/{deviceId}) |
Operated retention (not auto-deleted on uninstall) | Google Firebase |
| User feedback | Free-text feedback | Product feedback | Firestore koru_feedback/{deviceId} |
Operated retention | Google Firebase |
| AI analysis uploads (optional) | analysisJson (may include emotional content) | Improve moderation and product quality for reported/liked AI output | Firestore koru_ai_reports/{deviceId}, koru_ai_liked/{deviceId} |
Operated retention | Google Firebase |
| Remote configuration (operational) | App version gates; OpenAI API key fetch for App use | Feature configuration; AI feature enablement | Firestore koru_configs/api, koru_configs/app |
Operated retention | Google Firebase (API key is not your personal data) |
4.3 Data sent to third-party processors
| Category | Examples | Purpose | Location | Retention | Shared with |
|---|---|---|---|---|---|
| Wellness / journal text for AI | user_situation_text, emotion, thoughts, behaviors, body_sensations, system prompt context | Generate AI wellness suggestions via OpenAI Chat Completions | Processed by OpenAI (api.openai.com, US); responses may be cached on device | Per OpenAI practices; on-device cache until uninstall | OpenAI, LLC (HTTPS via Ktor client) |
| Analytics events | Event names; device/app info; app_instance_id; onboarding parameters (age, gender, neurodivergence flag, past_support, goal, quiz_answers) | Product analytics and improvement | Google Firebase Analytics | Per Google / Firebase retention | Google (Firebase Analytics) |
| Crash diagnostics | Crash reports, device info, stack traces | Stability and crash diagnosis | Google Firebase Crashlytics | Per Google Crashlytics retention | Google (Crashlytics) |
| App integrity attestations | App Check / Play Integrity / App Attest tokens | Protect backend and reduce abuse | Google Firebase App Check | Short-lived / per Google App Check | |
| Purchase / subscription data | Product ids, purchase tokens, subscription status, transactions | Provide Premium; restore purchases | Google Play Billing / Apple StoreKit; premium flags also in Firestore | Per store policies; entitlement flags as operated | Google Play; Apple; Firebase for entitlement sync |
4.4 Data we do not collect (current inventory)
Based on the current codebase inventory, we do not collect or request:
- Precise or coarse location
- Contacts or address book
- Camera images, video, or microphone audio
- Accessibility service content (passwords, messages, keystrokes)
- Package usage statistics / screen-time of other apps
- Advertising IDs for personalized advertising (no ads SDK)
- FCM / remote push notification tokens (local reminders only)
- RevenueCat or similar third-party subscription SDKs (native Play Billing and StoreKit only)
5. How we collect data
We collect personal data through:
| Method | Examples |
|---|---|
| You provide it | Journal entries, AI check-in text, optional feedback, onboarding answers, like/report of AI output |
| Automatic / device | Device identifiers, anonymous Auth UID, analytics and crash events, App Check attestations, preference flags, local notification schedules |
| Feature use you initiate | OpenAI Chat Completions when you request advice; Firestore uploads when you submit feedback or like/report AI analysis |
| App stores | Subscription product ids, purchase tokens, and entitlement signals via Google Play Billing and Apple StoreKit |
| Local scheduling | Daily reminder notifications via Android WorkManager and iOS UNUserNotificationCenter (on-device; not FCM) |
Network access is used for HTTPS calls to Firebase, OpenAI, and store billing. See Section 8 for permissions detail.
6. Why we use data
We use personal data to:
- Provide CBT-inspired wellness journeys, techniques, moment journaling, and AI check-ins / advice
- Authenticate you anonymously and sync premium status and usage counters
- Process optional feedback and AI like/report uploads
- Operate analytics and crash diagnostics to improve stability and features
- Protect the Service with App Check
- Process subscriptions via Google Play and the App Store
- Schedule local daily reminder notifications (not FCM push tokens in App code)
- Respond to privacy and support requests you send to us
We do not currently use an advertising SDK or sell personal information for money.
7. Legal bases
Where the EU GDPR, UK GDPR, or similar laws apply, we rely on the following bases (see also Annex A and Annex B):
| Purpose | Typical legal basis |
|---|---|
| Provide the App (local journaling, journeys, techniques, settings) | Contract (Art. 6(1)(b)) |
| Anonymous authentication and cloud Premium / usage status | Contract (Art. 6(1)(b)) |
| Process subscriptions via Apple / Google | Contract (Art. 6(1)(b)); legal obligation for tax/accounting where applicable |
| Optional AI check-in / advice (OpenAI) | Contract when you request the feature; consent (Art. 6(1)(a)) where required for special-category or optional processing |
| Optional feedback, AI like/report uploads | Contract / consent as applicable |
| Product analytics (Firebase Analytics), including onboarding personalization parameters | Legitimate interests (Art. 6(1)(f)) and/or consent where required under ePrivacy / national law |
| Crash diagnostics (Firebase Crashlytics) | Legitimate interests (Art. 6(1)(f)) |
| Security / App Check attestation | Legitimate interests (Art. 6(1)(f)) |
| Remote configuration fetch (including OpenAI API key from Firestore) | Legitimate interests / contract as needed to operate features |
| Local daily reminder notifications | Contract for operational reminders you enable; consent if marketing notifications are later offered |
Legitimate interests. Where we rely on legitimate interests, our interests are operating a secure, reliable wellness App, understanding aggregate usage, preventing abuse, and improving features. You may object as described under Section 12.
Special categories. Emotional check-in and related wellness text may reveal information about health or mental state. Where Article 9 (or UK/KVKK equivalents) applies, we process such data only as necessary for the service you request (for example local storage; transmission to OpenAI when you request AI advice) and on an appropriate condition (including explicit consent where required). KVKK explicit consent, where used, is obtained through a separate interface and is not part of this Policy text.
For California residents, see Annex C (CCPA / CPRA notice at collection and consumer rights).
8. Sensitive permissions and device capabilities
Menty requests only the permissions required for network features, optional local reminders, and store billing. The App does not use Accessibility Services, Usage Access, display-over-other-apps overlay, camera, microphone, contacts, or location APIs in the current inventory.
| Permission / capability | Platform | FOR | NOT FOR |
|---|---|---|---|
INTERNET |
Android | Connect to Firebase, OpenAI, and Google Play Billing | Unrelated background scraping of unrelated apps |
POST_NOTIFICATIONS |
Android 13+ | Local daily reminder notifications | Required for core journaling; marketing push; FCM token collection |
com.android.vending.BILLING |
Android | Google Play subscriptions | Ads or unrelated billing |
ios.user_notifications |
iOS | Local daily reminder notifications (alert, sound) | Required for core use; remote FCM push |
Internet access (android.permission.INTERNET)
| Why we request it | Enable HTTPS network calls for Firebase (Auth, Firestore, Analytics, Crashlytics, App Check), OpenAI Chat Completions, and Google Play Billing validation |
| What we do NOT access | Other apps’ private data; local files unrelated to Menty |
| You can revoke it | Airplane Mode, restricting background data, or uninstalling the App |
Notifications — Android (POST_NOTIFICATIONS) and iOS (UNUserNotificationCenter)
| Why we request it | Schedule local daily reminder notifications (Android WorkManager / iOS UNUserNotificationCenter) |
| What we do NOT access | Notification content of other apps; FCM / remote push tokens (not used in App code) |
| You can revoke it | Android Settings → Apps → Menty → Notifications; iOS Settings → Notifications → Menty |
Billing (com.android.vending.BILLING / StoreKit)
| Why we request it | Offer and restore Premium subscriptions through Google Play Billing and Apple StoreKit |
| What we do NOT access | Your full payment card details (handled by Google Play / Apple) |
| You can revoke it | Manage or cancel subscriptions in your store account; uninstalling does not cancel the store subscription |
9. Sharing and processors
We share personal data with the following processors and platforms as needed to operate the Service. We do not sell personal data for money and do not operate an advertising SDK.
| Processor | Vendor | Purpose | Data shared | Regions |
|---|---|---|---|---|
| Firebase Analytics | Analytics events and device/app telemetry | Events, device info, app_instance_id, onboarding profile parameters | US, EU | |
| Firebase Authentication | Anonymous authentication | Anonymous UID | US, EU | |
| Cloud Firestore | User docs, counters, feedback, AI like/report, remote config | Device-keyed user docs, feedback text, analysis JSON, config | US, EU | |
| Firebase Crashlytics | Crash reporting | Crash reports, device info, stack traces | US, EU | |
| Firebase App Check (+ Play Integrity) | App attestation / abuse prevention | Attestation / integrity tokens | US, EU | |
| Firebase Remote Config | Linked in dependencies; no FirebaseRemoteConfig API usage found in App source (config loaded from Firestore instead) | Config fetches / device info if SDK activates | US, EU | |
| OpenAI API | OpenAI | AI chat completions for wellness guidance | Emotional / journal text fields and prompt context | US |
| Google Play Billing | Android subscriptions | Product ids, purchase tokens, subscription status | US, EU | |
| Apple StoreKit | Apple | iOS subscriptions | Product ids, transactions, subscription status | US, EU |
| Ktor HTTP client | JetBrains (library) | HTTPS transport to OpenAI | Request bodies to OpenAI | N/A (client library) |
| SQLDelight | Cash App (library) | On-device database | Local DB only | On device |
| multiplatform-settings | russhwolf (library) | On-device preferences | Local prefs only | On device |
| AndroidX WorkManager | Google (library) | Schedule local reminder work | Scheduled work metadata | On device |
| AndroidX Media3 ExoPlayer | Google (library) | Local media playback in the App | Media handled on device; not used as a cloud personal-data processor | On device |
Processor relationships are governed by the applicable Google / Firebase, OpenAI, Apple, and Google Play terms and data processing terms (including DPAs and Standard Contractual Clauses or equivalent transfer tools where offered).
We may also disclose data if required by law, to protect rights and safety, or in connection with a business transfer, to the extent permitted by applicable law.
10. International transfers
Personal data may be transferred to and processed in countries outside your country of residence, including the United States, where Google Firebase and OpenAI operate.
| Destination / host | Purpose | Data types |
|---|---|---|
| api.openai.com | AI chat completions | Journal / emotion / thought / behavior / sensation text; prompt context |
| firestore.googleapis.com | Cloud storage for user, feedback, AI reports, config | Device id, auth_uid, premium status, counters, feedback, AI analysis JSON, operational config |
| firebaseappcheck.googleapis.com | App attestation | Integrity attestations |
| Google Analytics / Firebase Analytics collectors | Analytics | Events, device info, app_instance_id, onboarding demographics |
| play.google.com / Google Play Billing | Subscriptions | Product ids, purchase tokens |
| apps.apple.com / App Store / StoreKit | Subscriptions | Product ids, transactions |
For users in the EEA, the United Kingdom, and Türkiye, we rely on appropriate safeguards offered by our processors (including Standard Contractual Clauses, UK IDTA/Addendum, or equivalent mechanisms in the processor’s terms) and on contractual necessity to provide the Service you request. Additional KVKK transfer rules may apply for Türkiye-based users; see the Turkish KVKK notice.
11. Retention
| Layer | Retention |
|---|---|
| On-device SQLDelight database and preferences | Until App uninstall or clear App storage |
| Firestore user, feedback, and AI report/like documents | Until deleted through our support process (not automatically deleted on uninstall) |
| OpenAI processing | Per OpenAI’s practices for API requests you initiate |
| Analytics / Crashlytics | Per Google Firebase product retention |
| Store purchase records | Per Google Play / Apple policies; we retain entitlement signals needed for Premium |
Exact cloud retention for some Firestore collections is operated as configured and may be refined; contact us for the current practice applicable to your request.
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or port personal data, to object to certain processing, to withdraw consent where processing is consent-based, and to lodge a complaint with a supervisory authority.
How to exercise rights. Email sczgamesinfo@gmail.com with a description of your request and enough information to identify your App instance (for example platform, approximate install period, and any device/account identifiers you can provide). We may need to verify your request. There is no self-serve export UI in the current App; you may request information about personal data we hold by contacting the same email.
- EEA / EU: See Annex A (GDPR rights, legal bases, transfers, complaints).
- United Kingdom: See Annex B (UK GDPR; ICO complaints).
- California / US: See Annex C (CCPA / CPRA rights, including know, delete, correct, opt-out of sale/share, and limit sensitive PI).
- Türkiye: Also read the KVKK aydınlatma metni at https://menty.morrowline.app/en/kvkk/. KVKK rights requests may be sent to sczgamesinfo@gmail.com.
13. Account and deletion
The App uses Firebase Anonymous Authentication and may key Firestore documents by device identifier. This creates an account-like identity for operating the Service.
In-App deletion. Settings includes Delete my data. When you confirm, the App:
- Deletes Firestore documents associated with your device identifier in the user profile, feedback, AI report, and AI like collections (including both historical like collection names where applicable);
- Deletes your Firebase Anonymous Auth user (and signs out if deletion cannot complete);
- Clears on-device SQLDelight user data (moments, AI advice / check-ins, journey progress, favorites, app-open history, and the local user row) and local preferences (including legal acceptance flags).
After a successful wipe, the App restarts through the splash / onboarding flow so you can begin again. You will be asked to accept the Terms of Use and Privacy Policy again.
Uninstalling the App without using Delete my data removes on-device data but does not by itself delete Firebase Auth, Firestore, Analytics, Crashlytics, or OpenAI processing history.
You may also request deletion of cloud-associated data by emailing sczgamesinfo@gmail.com with enough information for us to locate your records (for example platform and approximate install period). We will respond as required under applicable law (including GDPR / UK GDPR / KVKK / CCPA timelines where they apply).
Manage or cancel store subscriptions separately in Google Play or the App Store; deleting in-App data or uninstalling the App does not cancel a subscription.
14. Children
The Service is for users 18 years of age or older (consistent with our store age targets of 18+). It is not directed to children under 13, and it is not intended for users under 18. We do not knowingly collect personal data from children under 13 or from users under 18. If you believe we have collected data from someone under 18, contact sczgamesinfo@gmail.com and we will take appropriate steps to delete it.
15. Security
We implement technical and organizational measures appropriate to the nature of the Service, including HTTPS/TLS for network traffic, Firebase App Check for abuse reduction, and store-managed payment processing.
The on-device database may store situation, emotion, thought, behavior, and free-text check-in content, plus AI request/response JSON. Local storage is not SQLCipher-encrypted in the current build. When you request AI advice, related text fields are transmitted to OpenAI. Optional like/report actions may upload analysis JSON to Firestore.
No method of transmission or storage is completely secure. We do not guarantee absolute security of personal data.
16. Automated decisions
The App uses automated AI suggestions when you request check-in advice (OpenAI Chat Completions). These outputs are informational wellness suggestions and are not decisions that produce legal effects or similarly significant effects solely by automated means (GDPR Article 22 style). Limited analytics and onboarding parameters may be used to understand and improve the product; they are not used for automated credit, employment, insurance, or similar decisions.
Do not rely on the App in a crisis; contact emergency services or a qualified professional.
17. Changes
We may update this Privacy Policy from time to time. The “Last updated” date and the version in the document header will change when we do. Material changes will be indicated by updating this Policy at https://menty.morrowline.app/ and, where appropriate, by in-App notice or updated legal links in Settings / paywall. Continued use of the App after the updated Policy takes effect constitutes acceptance of the revised Policy to the extent permitted by law.
18. Contact
| Controller | Seyfi Can Zeyrek (trading as Morrowline Apps) |
| Address | Esenyali Mahallesi 52/75 Sk. Izmir/Türkiye |
| Phone | +90 555 027 76 81 |
| Privacy email | sczgamesinfo@gmail.com |
| Support email | sczgamesinfo@gmail.com |
| Website | https://menty.morrowline.app/ |
| Terms of Use | https://menty.morrowline.app/en/terms/ |
| KVKK notice (TR) | https://menty.morrowline.app/en/kvkk/ |
Annex A — Information for users in the European Economic Area (EEA) and EU
This annex supplements the Privacy Policy when the EU General Data Protection Regulation (GDPR) applies.
A.1 Controller
| Field | Details |
|---|---|
| Controller | Seyfi Can Zeyrek (trading as Morrowline Apps) |
| Address | Esenyali Mahallesi 52/75 Sk. Izmir/Türkiye |
| Phone | +90 555 027 76 81 |
| Privacy contact | sczgamesinfo@gmail.com |
We have not appointed a Data Protection Officer (DPO). For privacy requests, contact the controller at sczgamesinfo@gmail.com.
A.2 Purposes and legal bases (GDPR Article 6)
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide the App (local journaling, journeys, techniques, settings) | On-device moments, progress, preferences | Art. 6(1)(b) — contract / requested service |
| Anonymous authentication and cloud Premium / usage status | Firebase Anonymous Auth UID; device ID as Firestore document key; Premium flags and counters | Art. 6(1)(b) — contract |
| Process subscriptions via Apple / Google | Purchase/entitlement signals | Art. 6(1)(b) — contract |
| Optional AI check-in / advice (OpenAI) | Text fields and related AI request/response content you submit | Art. 6(1)(b) when you request the feature; Art. 6(1)(a) where consent is required for special-category or optional processing |
| Optional feedback, AI like/report uploads | Feedback text; analysis JSON you choose to send | Art. 6(1)(b) / Art. 6(1)(a) as applicable |
| Product analytics (Firebase Analytics), including onboarding personalization parameters | Event data; parameters such as age band, gender, neurodivergence flag, past support, goals, quiz answers where implemented | Art. 6(1)(f) legitimate interests and/or Art. 6(1)(a) consent where required under ePrivacy / national law |
| Crash diagnostics (Firebase Crashlytics) | Crash and diagnostic data | Art. 6(1)(f) — integrity and improvement of the App |
| Security / App Check attestation | Attestation signals | Art. 6(1)(f) — security and abuse prevention |
| Remote configuration fetch (including OpenAI API key from Firestore config) | Non-user config; may enable cloud AI features | Art. 6(1)(f) / Art. 6(1)(b) as needed to operate features |
| Local daily reminder notifications | Local notification schedules (no FCM push token in App code) | Art. 6(1)(b) for operational reminders you enable; Art. 6(1)(a) if marketing notifications are later offered |
Legitimate interests. Where we rely on Art. 6(1)(f), our interests are operating a secure, reliable wellness App, understanding aggregate usage, preventing abuse, and improving features. You may object as described under “Your rights.”
Special categories. Emotional check-in and related wellness text may reveal information about health or mental state. Where Article 9 applies, we process such data only as necessary for the service you request and on an appropriate Art. 9 condition (including explicit consent where required).
A.3 Recipients and processors
| Recipient / processor | Role | Purpose |
|---|---|---|
| Google LLC / Google Ireland Limited (Firebase: Auth, Firestore, Analytics, Crashlytics, App Check) | Processor | Auth, cloud user/docs, analytics, crash reports, attestation |
| OpenAI, L.L.C. (api.openai.com) | Processor / independent provider of AI completions | AI chat completions when you request advice |
| Google Play Billing | Payment platform | Android subscription payment and entitlement |
| Apple Inc. (StoreKit / App Store) | Payment platform | iOS subscription payment and entitlement |
We do not operate an advertising SDK. Firebase Remote Config is linked in dependencies but not used for Remote Config API calls in App source; configuration is loaded from Firestore.
A.4 International transfers
Controllers and processors may process data in the United States and other countries outside the EEA. Where GDPR Chapter V applies, transfers rely on:
- An adequacy decision where available; and/or
- Standard Contractual Clauses (SCCs) or other lawful transfer tools in the vendor’s data processing terms; and/or
- Other safeguards permitted by GDPR.
You may request further information via sczgamesinfo@gmail.com.
A.5 Retention
| Data | Retention criterion |
|---|---|
| On-device database and local preferences | Until you uninstall the App or clear App storage |
| Cloud Firestore / Auth records | Retained while the App operates the relevant collections, or until we complete a verified deletion request; uninstall alone does not automatically delete cloud records |
| Analytics / Crashlytics | Per Google Firebase retention settings for the project |
| OpenAI processing | Per OpenAI’s retention and API policies for content sent when you request AI features |
| Store purchase records | Held by Apple / Google under their policies; we retain entitlement signals needed for Premium |
A.6 Your rights (GDPR)
Subject to conditions and exceptions in GDPR, you may:
- Access your personal data
- Rectify inaccurate data
- Erase data (“right to be forgotten”)
- Restrict processing
- Data portability (where applicable)
- Object to processing based on legitimate interests
- Withdraw consent at any time where processing is based on consent (withdrawal does not affect prior lawful processing)
- Lodge a complaint with a supervisory authority
How to exercise rights. Email sczgamesinfo@gmail.com. An in-App one-tap account deletion flow is not currently implemented. Deletion of cloud data requires a request to the privacy contact above.
A.7 Withdraw consent and notification permission
- Withdraw consent for consent-based processing by contacting us or using in-App / OS controls where provided.
- Revoke notification permission in system settings to stop local reminders.
- Manage store subscriptions separately via Apple or Google (see Terms of Use).
A.8 Automated decision-making and profiling
The App uses automated AI suggestions when you request check-in advice. These outputs are informational wellness suggestions and are not decisions that produce legal effects or similarly significant effects under GDPR Article 22. Limited analytics and onboarding parameters may be used to understand and improve the product; they are not used for automated credit, employment, or similar decisions.
A.9 Complaints
You may lodge a complaint with your local EEA supervisory authority. A list of authorities is published by the European Data Protection Board. You may also contact us first at sczgamesinfo@gmail.com.
A.10 Children
The App is for users 18 years of age or older and is not directed to children.
Annex B — Information for users in the United Kingdom
This annex supplements the Privacy Policy and Annex A when the UK GDPR and the Data Protection Act 2018 apply to your use of Menty.
B.1 Controller and contact
| Field | Details |
|---|---|
| Controller | Seyfi Can Zeyrek (trading as Morrowline Apps) |
| Address | Esenyali Mahallesi 52/75 Sk. Izmir/Türkiye |
| Phone | +90 555 027 76 81 |
| Privacy contact | sczgamesinfo@gmail.com |
No Data Protection Officer has been appointed. Use sczgamesinfo@gmail.com for UK data protection requests.
B.2 Alignment with the EEA/EU annex
Unless this UK annex states otherwise, the descriptions of purposes, legal bases, recipients/processors, international transfers, retention, automated decision-making, children, and how to exercise rights in Annex A apply to UK users, read with references to the UK GDPR (and ICO guidance) instead of the EU GDPR where required.
Legal bases map to UK GDPR Article 6 (and Article 9 where special-category data applies) in the same pattern as the EEA/EU table: contract, legitimate interests, and consent where required.
B.3 International transfers from the UK
Where personal data is transferred from the UK to the United States or other third countries (including via Google Firebase, OpenAI, Apple, or Google Play), we rely on UK adequacy regulations where available and/or the vendor’s UK International Data Transfer Agreement / Addendum or other transfer tools permitted under UK GDPR, as set out in the applicable vendor terms.
B.4 Your UK rights
You have the rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent (where processing is consent-based), subject to UK GDPR conditions and exemptions. Submit requests to sczgamesinfo@gmail.com. In-App one-tap deletion of cloud data is not currently available; see Section 13.
B.5 Complaints — ICO
You may lodge a complaint with the Information Commissioner’s Office (ICO):
- Website: https://ico.org.uk/
- Helpline and complaint channels are published on the ICO website
You may contact us first at sczgamesinfo@gmail.com.
B.6 Consumer digital content
UK consumer rights for digital content and services (including fairness and, where applicable, cancellation/withdrawal rules for distance contracts) are addressed in the Terms of Use. Store subscription cancellation remains via the App Store or Google Play.
Annex C — Notice for California residents (CCPA / CPRA)
This California notice supplements the Privacy Policy and applies to personal information subject to the California Consumer Privacy Act as amended by the CPRA (“CCPA”).
C.1 Notice at collection
We collect the categories of personal information described below for the business and commercial purposes stated. Collection occurs when you install and use the App, complete onboarding, use journaling / AI features, enable notifications, purchase a subscription, or contact us.
A link to this Privacy Policy (including this California notice) is available from the App’s Settings (and paywall legal links) and from https://menty.morrowline.app/. You may print or save this page for your records. We review and update this notice at least annually when material practices change.
C.2 Categories collected (prior 12 months)
| CCPA category | Examples in Menty | Sources | Business / commercial purpose |
|---|---|---|---|
| Identifiers | Firebase Anonymous Auth UID; Android ID / iOS identifierForVendor used as cloud document key; IP/device signals via Firebase/Google | You; device; service providers | Provide App; auth; sync Premium/status; security (App Check) |
| Customer records / account-like data | Premium status; subscription end; usage counters; optional feedback | You; Apple/Google purchase signals | Provide Premium; support; operate service |
| Commercial information | Subscription purchase/entitlement events | Apple App Store; Google Play | Process purchases; restore entitlement |
| Internet or electronic activity | Firebase Analytics events (including onboarding and feature use); Crashlytics diagnostics | Device; analytics/crash SDKs | Analytics; debug; improve App |
| Sensory / free-form content | Situation, emotion, thought, behavior, check-in text; AI request/response JSON (on device; sent to OpenAI when you request advice); optional like/report JSON to Firestore | You | Core journaling; AI advice; optional quality signals |
| Inferences / personalization inputs | Onboarding parameters such as age band, gender, neurodivergence flag, past support, goals, quiz answers (as analytics parameters where implemented) | You | Personalize experience; product analytics |
| Sensitive personal information (as applicable) | Wellness/emotional journal content; certain onboarding demographic or neurodivergence flags | You | Provide requested wellness features; analytics as implemented |
We do not collect precise geolocation, government ID numbers, financial account numbers (card data is handled by Apple/Google), or biometric identifiers for unlocking the device.
C.3 Categories of third parties / service providers
| Party | Role |
|---|---|
| Google (Firebase Auth, Firestore, Analytics, Crashlytics, App Check) | Service provider / contractor |
| OpenAI | Service provider for AI completions you request |
| Apple / Google (billing) | Independent platforms for payments |
We do not use an advertising SDK. No sale of personal information for monetary consideration is conducted by us.
C.4 Sell / Share / targeted advertising
Under CCPA:
- Sale: We do not sell personal information for money.
- Share (cross-context behavioral advertising): We do not share personal information for cross-context behavioral advertising. We do not operate AdMob or similar ad networks, and iOS App Tracking Transparency for ad tracking is not enabled in the current build.
- Service providers: We disclose personal information to the processors named above to operate the App.
If our practices change, we will update this notice and provide a “Do Not Sell or Share My Personal Information” link or equivalent mechanism where required.
Do Not Sell or Share requests. Even though we do not sell or share as described above, California residents may submit a request confirming opt-out of sale/share by emailing sczgamesinfo@gmail.com with the subject line “California Do Not Sell or Share.”
C.5 Right to Limit Use of Sensitive Personal Information
Where we use sensitive personal information (for example emotional journal content or certain demographic/neurodivergence onboarding flags) beyond what is necessary to perform the services reasonably expected by an average consumer, you may request that we limit such use to permitted purposes by emailing sczgamesinfo@gmail.com with the subject “Limit Sensitive PI.”
Operational use necessary to provide journaling, AI advice you request, and core App functions continues as needed to deliver the service.
C.6 Your California consumer rights
Subject to CCPA verification and exceptions, you may request:
| Right | Description |
|---|---|
| Know / Access | Categories and specific pieces of personal information collected, sources, purposes, and categories of third parties |
| Delete | Deletion of personal information, subject to exceptions |
| Correct | Correction of inaccurate personal information |
| Opt-out of sale/share | As described above |
| Limit sensitive PI | As described above |
| Non-discrimination | We will not discriminate against you for exercising CCPA rights |
How to submit. Email sczgamesinfo@gmail.com. Describe the right you wish to exercise and provide information reasonably needed to verify you control the relevant App instance. Authorized agents may submit requests with proof of authorization as required by CCPA.
Response timing. We aim to respond within the periods required by CCPA (generally 45 days, extendable as permitted).
Deletion note. An in-App one-tap deletion flow is not currently implemented. Cloud deletion is handled via verified email requests. Uninstall removes on-device data but does not by itself delete all cloud records.
C.7 Contact
Privacy requests: sczgamesinfo@gmail.com
Controller: Seyfi Can Zeyrek (trading as Morrowline Apps), Esenyali Mahallesi 52/75 Sk. Izmir/Türkiye, +90 555 027 76 81

