Privacy Policy
Last updated: August 23, 2026 · 🇹🇷 Türkçe oku
At Fabulery ("we", "our app") we take our users' privacy seriously. This Privacy Policy explains how your personal data is collected, used, stored and protected. It covers both the mobile app and the fabulery.com website.
1. Data We Collect
1.1 Automatically Created Guest Identity
The first time you open the app, an anonymous account (guest session) is created automatically, without any action from you. This is so your progress can be saved from the very start and so story and audio content can be downloaded from our servers. This anonymous account is nothing more than a random identifier (UID) assigned to you; it contains no name, e-mail address or device identifier. If you later sign in with Google or e-mail, you can choose to transfer your progress to that permanent account.
1.2 Account Information
When you sign in with Google or with e-mail/password, we receive:
- E-mail address
- Name / display name (taken from your Google profile when signing in with Google; optionally provided by you when registering with e-mail/password)
- Profile photo URL (Google sign-in only; displayed on the website only)
- Account identifier (UID)
If you register with e-mail/password, your password is handled securely (hashed) directly by Firebase Authentication; our app never sees or stores it.
1.3 Learning and Gameplay Data
As you use the app, the following data is created and saved to your account:
- Level, experience points and overall progress
- In-game virtual items (gold, gems, feathers, hints, axes, etc.)
- Completed stories, scenes and word game (FabuWords) chapters
- Progress in Lessons, Exercises, Daily Puzzle, TilkoLand and Quests
- Word-level learning history: learned / to-learn / confused words; each record contains the word, its translation, the language pair, the story where you encountered it, a word score, an error count and a timestamp
- Daily login streak, wheel/reward and season progress
- Unlocked stickers, collections and backgrounds
- Shop purchases (made with in-game virtual currency only — see Section 9)
- Your friends list (the identifiers of users you have added)
- Native / target language, font size and app preferences
- Activity timestamps and your time zone offset (stored server-side so daily rewards are granted on the correct day)
- If you submit them: your translation feedback messages (free text you write)
1.4 Microphone and Speech Recognition
The "Speak" exercise in Lessons uses the microphone to evaluate your pronunciation. Using this feature is optional; if you decline the microphone permission the exercise is disabled and the rest of the app works normally.
- We do not record, store or upload your voice to our own servers. The audio is used only momentarily, to convert the word you said into text, and is discarded from memory as soon as the operation finishes.
- The conversion itself is performed by your device's operating-system speech recognition service (on Android this is, on most devices, Google's speech recognition service).
- On Android 12 (API 31) and above, if the relevant language pack is installed on the device, recognition may run on-device. We request this as a preference, but we cannot guarantee it: on older Android versions, or when the language pack is missing, the audio leaves your device and is sent to the operating system's recognition provider for processing.
- In that case the processing of your voice is governed by the privacy policy of that speech recognition service (e.g. Google). Only the recognised text is returned to us.
1.5 Technical Data
- FCM (Firebase Cloud Messaging) token — for push notifications (if you granted notification permission)
- Device information (operating system and version)
- Firebase App Check — an abuse-prevention mechanism used to verify that requests come from a genuine copy of the app. It is not used to track your identity. Note: App Check is not currently in enforce mode; the infrastructure is in place and will be enabled gradually.
1.6 Analytics and Crash Reports (optional — off by default)
We may use Google Firebase Analytics and Firebase Crashlytics to improve the app experience. These tools are enabled only if you give explicit consent inside the app; they are off by default and you can withdraw your consent at any time from Settings.
If you consent, the following may be collected:
- Anonymous usage events (which screens/features are used)
- Crash and error reports (technical state at the moment of failure)
- Device model, operating system version and app version
This data is never used for advertising or profiling; it is used only to fix bugs and improve the app. If you withdraw consent no further data is sent; crash reports already submitted may remain in Google's systems for their retention period (typically 90 days for Crashlytics).
2. Data Visible to Other Users
Because of the app's social features (Feather League and Friends), some of your information is visible to other people using the app. It is important that you use these features knowingly:
- Your display name — shown on the league table and in friend search. If you signed in with Google, this name is usually your real name from your Google account.
- Your short ID — the 8-character code used to add friends; it is searchable.
- Your league standing — your weekly feather score and rank appear on the league table.
- Your level and login streak — shown on your public profile card.
Your e-mail address, word history, lesson progress and other learning data are not visible to any user. If you prefer your name not to be shown, you can change your display name in the app's profile settings.
3. How We Use Data
- Creating your account and authenticating you
- Saving your learning progress and syncing it across devices
- Providing a personalised learning experience (including which words you need to review)
- Social features: league standings and the friends system
- Sending notifications (if you granted permission)
- Preventing cheating and abuse (server-side validation of rewards)
- Improving performance and fixing bugs (only if you consented)
Legal basis (GDPR/KVKK): processing related to your account, progress and social features is based on performance of a contract; abuse prevention on legitimate interest; analytics, crash reports, notifications and microphone use are based on your explicit consent.
4. Data Storage and Retention
Your data is stored on Google Firebase infrastructure (Firestore database and Firebase Storage). All transfers are encrypted with HTTPS/TLS and data is held encrypted at rest on Google's infrastructure.
- International transfers: Firebase is operated by Google LLC and your data may be processed in Google data centres, including in the United States. Our server-side functions (Cloud Functions) run in the
us-central1 (USA) region.
- Access control: Firestore security rules ensure that only you can access your learning data and account information. The exception is the fields listed in Section 2, which are deliberately public for the social features.
- On your device: your progress is also kept in an encrypted file on your device so it works offline. In addition, your preferences and (only if you selected "remember me") your e-mail address are stored in the device's local preference store.
- Retention: your data is retained for as long as your account exists. When you delete your account the data is removed immediately and permanently (see Section 7). We do not apply an automatic time limit; deletion is under your control.
5. Data Sharing
We do not sell, rent, or share your personal data for advertising. Your data is processed only by the following services, which are required for the service to function:
- Firebase Authentication — authentication
- Firebase Firestore — data storage
- Firebase Storage — serving content (stories, audio, images)
- Firebase Cloud Functions — secure server-side execution of rewards and account deletion
- Firebase Cloud Messaging — notifications (if you granted permission)
- Firebase App Check — abuse prevention
- Firebase Analytics and Crashlytics — only if you consented (see Section 1.6)
Within these services the data is processed by Google LLC acting as a data processor. For details see the Firebase Privacy and Security page.
In addition: when you use the "Speak" exercise, your audio may be transmitted to your device's operating-system speech recognition service for processing (see Section 1.4). That is a device service outside our control.
Where legally required (e.g. a court order) we may have to share data with the competent authorities.
6. Children's Privacy
Fabulery is a language learning app and its content (Aesop's fables) is suitable for all ages. However, the app is not designed for children and its target audience is users aged 13 and over.
- We do not knowingly collect personal data from users under 13.
- The league and friends features require a display name to be shown to other users (see Section 2). For this reason we recommend that children use the app only under parental supervision.
- If you believe your child has provided us with personal data, contact us at destek@fabulery.com and we will delete the account and the data.
- Parents may request access to, correction of, or deletion of the data in their child's account.
7. Account Deletion
You can permanently delete your account and its associated data. Deletion is irreversible.
For the list of deleted data and a detailed explanation, see the Account Deletion page.
8. Your Rights
Under KVKK and GDPR you have the following rights:
- Access: you can view your data in the app, and you may write to us to request a copy.
- Rectification: you can update your display name and preferences in the app.
- Erasure: you can delete your account from the app or the website (Section 7).
- Portability: you may request a machine-readable copy of your data.
- Objection and withdrawal of consent: you can turn off analytics/crash-report consent and notification permission at any time in Settings.
To exercise these rights, write to destek@fabulery.com. We respond to requests within 30 days at the latest.
9. Payments and Advertising
The app contains no advertising; no data is sent to any ad network and no Advertising ID is collected.
Purchases in the shop are made with in-game virtual currency only (gold/gems). There are currently no real-money purchases. If they are added in future, this policy will be updated.
10. Cookies and Local Storage (website)
The fabulery.com website uses no advertising or tracking cookies. Only technical storage required for the service is used:
- Browser storage used by Firebase Authentication to keep you signed in
- Preference and cache keys: menu state, sign-out preference and the story catalogue cache
This data stays in your browser and is not sent to third-party trackers. You can clear it by deleting site data in your browser settings.
11. Changes
We may update this privacy policy from time to time. The current version is always available on this page, together with the "Last updated" date at the top. We will inform you through the app or the website about significant changes.
12. Data Controller and Contact
Data controller: Fabulery is operated by Süleyman GÜNDÜZOĞLU, a natural person established in Türkiye. You may submit your requests under KVKK and GDPR through the channel below; we respond within 30 days at the latest.