1. Scope and status of this Policy
This Privacy Policy applies to personal information processed through the TRP AI application, related services, support, purchases, security controls, and public account functions. TRP AI is a digital service operated by Ahmetcan Korkmaz. For the purposes of applicable data protection law, Ahmetcan Korkmaz is the operator and data controller of TRP AI. Read this Policy with the Terms of Use and AI Notice.
Your rights and our obligations vary depending on where you live and the circumstances. This Policy does not create rights beyond Applicable Law, constitute blanket consent, or amount to an admission of fault or unlawful processing. Consent is used only where specifically required or requested.
2. Information processed
We process Google Sign-In information such as display name and email; an authenticated account identifier; account status and Pill balance; immutable ledger entries; Google Play purchase and verification records; Stripe web-payment status and transaction records; recorded refund, reversal, dispute, chargeback, or Google Play consumption status; chat messages; stored conversation history and metadata; short-lived chat-operation records; and necessary security and operational metadata.
We may also process device- or installation-derived anti-abuse identifiers, provider-derived welcome-credit claim identifiers, security and incident records, administrative audit records, support information where supplied, account-deletion records, and the minimal pseudonymous legal-acceptance record described below. We do not need your contacts, precise location, microphone, or camera for the documented Service behavior.
3. Sources of information
Information comes directly from you when you sign in, send messages, manage conversations, contact support, or request deletion; from Google Sign-In and Firebase Authentication; from Google Play for Android purchases and Stripe for web payments; from the app installation or device for anti-abuse controls; from service providers operating the infrastructure; and from automated security, fraud-prevention, support, and administrative activity as applicable.
4. Purposes and applicable processing grounds
We use information to authenticate users; initialize and manage Accounts; generate chat Outputs; store and retrieve conversations; administer Pills and immutable ledgers; verify and reconcile purchases, refunds, reversals, and chargebacks; prevent fraud, repeated welcome-credit claims, automated abuse, and unauthorized access; protect security; investigate incidents; provide support; comply with legal obligations; resolve disputes and legal claims; delete accounts; and administer current legal-document acceptance.
Subject to Applicable Law, Account creation, authentication, chat, conversation services, Pill administration, and requested purchases support performance of the service agreement or steps you request. Fraud prevention, welcome-credit abuse controls, Account security, transaction integrity, Service protection, and incident investigation support performance and protection of the Service, recognized legitimate operational and security interests, and applicable legal obligations. Purchase, refund, chargeback, accounting, audit, dispute, and legally required records support transaction administration, compliance, fraud prevention, and the establishment, exercise, or defense of legal claims. Optional processing relies on consent only where consent is specifically requested and legally required. The applicable ground may differ by jurisdiction and circumstance. Acknowledgment of this Policy is not blanket consent to all processing.
5. DeepSeek and AI processing
DeepSeek is the external large-language-model provider used to generate Outputs. The Service sends a server-controlled system instruction and validated message content. For a request without conversation context, the content is the current validated user message. For a conversation request, selected prior user and assistant messages may also be included within server-controlled context limits. Stored conversation history may therefore be broader than the context transmitted for a particular request.
DeepSeek returns model-generated text, which is delivered as the Output and may be stored with the conversation. Any additional handling by DeepSeek is governed by the applicable provider terms, privacy documentation, account configuration, contractual arrangements, and applicable law; Ahmetcan Korkmaz does not control all independent provider processing. Do not submit unnecessary sensitive, confidential, privileged, intimate, authentication, payment, or third-party information.
6. Other service providers
Google Sign-In and Firebase Authentication establish authenticated identity. Firebase and Google Cloud support account, conversation, ledger, purchase, anti-abuse, deletion, and operational data functions. Google Play processes Android purchases and supplies purchase-verification information. Stripe processes web payments and supplies the payment status and transaction information required for fulfillment, reconciliation, refunds, disputes, and fraud prevention. Render hosts application services. DeepSeek processes model requests. These providers act as independent platforms, service providers, or processors as appropriate to their role and Applicable Law.
7. Disclosures, advertising, and sale of data
TRP AI does not sell personal information or use personal information for targeted advertising. The application does not use advertising identifiers for advertising or display third-party advertising. Optional Google Analytics on trpai.app and app.trpai.app runs only after analytics consent. Legal definitions differ, so users may exercise any legally defined opt-out right that applies to actual processing.
With your optional consent, Google Analytics measures visits, traffic sources and interactions such as opening the web application, starting Google Sign-In and sending a prompt. This may involve analytics cookies, pseudonymous identifiers, browser, device and referral information processed by Google. We do not intentionally send chat-message contents to Google Analytics. You can refuse without losing access and change or withdraw your choice using Cookie settings. The consent-preference cookie trp_analytics_consent is configured to last 180 days. Analytics cookies and data retention depend on our Google Analytics settings. See how Google processes site and app data.
Information is disclosed to service providers only for the operational, security, payment, support, compliance, and AI-response purposes described in this Policy; to authorities or other recipients when lawfully required; and where reasonably necessary to investigate fraud or security incidents, protect users or third parties, resolve disputes, enforce agreements, or establish, exercise, or defend legal rights. We seek to limit disclosure to what is reasonably necessary.
8. Security and international processing
Network communications use encrypted connections as applicable. We use reasonable technical and organizational safeguards and access controls appropriate to the Service, but no internet transmission, storage system, provider, or authentication method is absolutely secure. You are responsible for securing your Google account, device, and access credentials and for reporting suspected compromise.
Providers may process information outside your country. Where Applicable Law requires safeguards for international processing or transfer, legally required safeguards are used as applicable. We do not promise a particular data residency, name an unsupported transfer mechanism, or claim a certification that does not apply.
9. Retention
Account and conversation data may remain until deletion or while operationally necessary. Chat-operation records have a seven-day retention target when the configured cleanup process operates; this is not a promise that every record is automatically removed at an exact time. Conversation history remains available until deleted through available controls or account deletion, subject to exceptions below.
Ledger, purchase, refund, reversal, chargeback, fraud, anti-abuse, security, administrative audit, deletion, legal-acceptance, dispute, and legal-claim records may be retained longer or anonymized where reasonably necessary and legally permitted. Backups and pseudonymous or anonymized records may persist until safely overwritten or no longer needed. Retention considers operational integrity, accounting, fraud prevention, transaction replay protection, security, legal duties, disputes, and limitation periods.
10. Account deletion
You can request account deletion from Control Center → Account or use the separate Account Deletion page. Uninstalling the app does not delete the Account. The current deletion process removes the Firebase Authentication user, Account record, conversations and messages, chat-operation records, remaining balance, and ordinary identifying account data.
Purchase, financial, refund, fraud, anti-abuse, security, accounting, administrative, compliance, dispute, and legal-claim records may be retained in anonymized or pseudonymous form where necessary. The acceptance record is deleted so a deleted and later re-registered Account must accept current documents again. Retained records are not used by normal flows to recreate the deleted Account.
11. Privacy rights and requests
Subject to Applicable Law and depending on where you live, you may have rights to confirmation, access, correction, deletion, restriction, objection, portability, withdrawal of consent, appeal, complaint to a competent authority, or legally defined opt-outs. Not every right applies to every user or every processing activity, and this Policy does not guarantee eligibility for every requested remedy.
We may need to verify identity and authority and may request reasonable verification details without requesting passwords or payment-card data. Requests may be delayed, restricted, or refused where permitted because of fraud, security, accounting, purchases, disputes, third-party rights, technical feasibility, legal claims, or other legal conditions and exceptions. Anonymized information and lawfully retained records may not be subject to deletion. Repetitive, excessive, abusive, or fraudulent requests may be handled as Applicable Law permits. Contact trpai@proton.me.
12. Legal-acceptance records
When current documents are accepted, TRP AI stores only an opaque pseudonymous acceptance identifier, the three required document versions, an acceptance timestamp, and a validated app version or locale if supplied. The record supports access control, proof of the version presented, document updates, compliance administration, and disputes.
A raw account identifier, email, display name, provider subject, IP address, user-agent text, raw device identifier, chat content, payment information, and arbitrary application metadata are not stored solely for legal acceptance. The application cannot choose or override required document versions.
13. Age, updates, and contact
The Service is intended for people aged 16 or older. Users under 18 require parent or legal-guardian permission. Age verification may not be perfect. We may update this Policy prospectively as the Service, providers, risks, or law change and may request renewed acknowledgment for material changes.
Version 2026-07-26.1 took effect on 2026-07-26; this Privacy Policy was last updated 2026-09-22. Contact Ahmetcan Korkmaz at trpai@proton.me. Also review the Terms, AI Notice, and Account Deletion page.