Bulfit Privacy Policy

Effective date: 22 September 2026

This policy explains what personal data Bulfit handles, where it goes and what you can do about it. It describes the app and our server as they work on the effective date.

Bulfit is in private testing. In the current test build the app still appears on your phone under its earlier name, “All Health”. Wherever this policy says Bulfit, that app is meant.

Some texts inside the current test build are incomplete or wrong. The iPhone’s Apple Health permission screen names only heart rate, HRV, resting heart rate, sleep, activity and workouts, although the app asks to read all 18 kinds of data listed in section 3.1. Several texts say that health data is processed on the phone, or that nothing from Apple Health leaves it in its original form, without saying that each night’s sleep and each workout are sent with their exact times, together with the names of your devices. The sign-in screen mentions only an internal random identifier, although we also keep the identifier Apple gives us (section 3.3). The AI consent text lists only some of the figures that are sent (section 6) and does not say that questions you type are sent to the AI provider. The Privacy Centre says the AI service knows you by a random identifier, but no identifier for you is sent to it. The text shown when you delete your account does not mention backups. Where they differ, this policy describes what actually happens.

1. Who is responsible

The party responsible for your personal data in Bulfit (the data controller) is the Bulfit Compliance Team.

For any question about this policy or your data, and to use any of your rights, write to hi@bulfit.net.

2. What Bulfit is

Bulfit is an iPhone app. It brings together health and fitness data from Apple Health (including data from an Apple Watch) and, if you connect it, from Fitbit. It builds a summary of each day, learns what is normal for you (your personal “baselines”), calculates a daily recovery score and, if you turn this on, uses an AI service to explain your figures in plain language.

Bulfit is not a medical device and not a medical service. It is not designed to diagnose, treat or prevent any disease or condition, and nothing it shows is medical advice. If you are concerned about your health, speak to a qualified healthcare professional.

3. What we collect and where it comes from

3.1 Apple Health, only with your permission

During setup the app asks for permission to read your Apple Health data. You can skip this step (“Skip for now”). In the current test build the app asks for Apple Health access only during setup, so if you skip it, the app will not appear in your iPhone’s Health settings until you go through setup again (for example the next time you have to sign in, or after reinstalling the app). If you allowed access, you can turn it off, or back on, at any time in your iPhone’s settings (see section 9). Bulfit asks only to read. It never writes to Apple Health, so it never adds or changes anything there.

The app asks to read these 18 kinds of data: heart rate, resting heart rate, heart rate variability (HRV), respiratory rate, blood oxygen, body temperature, steps, walking and running distance, active energy, resting energy, exercise minutes, flights climbed, weight, body fat percentage, lean body mass, VO2 max, sleep and workouts.

Each time it refreshes, the app reads the last 90 days of this data on your phone. For steps, distance, active and resting energy, exercise minutes and flights climbed, it reads hourly totals for each recording device or app. For the other measures, it reads each reading’s value and time, the name of the app or device that recorded it, the device model, whether it was typed in by hand, and Apple Health’s ID for the record. For sleep, it reads the sleep stages and their times. For workouts, it reads the activity type, the start and end time, and the totals and heart-rate figures Apple Health keeps for the workout. The device model, the “typed in by hand” flag and the record ID are used only on the phone (for example, so that the same reading is not counted twice) and are never sent to us.

On your phone the app combines readings from different devices into one figure per measure per day, without adding up the same activity twice, and groups sleep data into nights. It then sends daily summaries to our server: one for every day of the last 90 that has data. Every refresh sends all of these days again, not only new ones. A daily summary contains:

Device names. For data that your own iPhone or Apple Watch records, “the name of the device” is the name you gave that device. By default this contains your first name (for example “Sam’s iPhone”). This name is sent to our server and stored with your daily figures. For data written by another app, it is that app’s name.

Individual readings (such as each separate heart-rate measurement) are not sent. Nor are Apple Health record IDs, your device model or any location.

The app sends these summaries automatically every time you start it or sign in (when the Today screen, which opens first, loads) and whenever you pull down to refresh the Today screen. It reads Apple Health and contacts our server only while it is open; it does no work in the background. There is no separate switch to pause uploads: to stop them, turn off the app’s access to Apple Health or stop using the app.

3.2 Fitbit, through the Google Health API, only if you connect it

Fitbit data reaches Bulfit through Google’s Google Health API. Connecting it is optional. If you choose “Connect Fitbit” under Connected devices, your phone’s browser opens Google’s sign-in page, where you decide whether to grant access. You sign in on Google’s page in your browser, not inside the app.

Bulfit asks Google for four read-only permissions: activity and fitness; health metrics and measurements; sleep; and settings. It does not ask for location or for permission to change anything, so we cannot read your exercise routes (GPS) or write to your Google or Fitbit account.

Our server then reads: daily resting heart rate, daily HRV, daily respiratory rate, daily blood oxygen, skin temperature changes measured during sleep, steps, distance, active energy, active zone minutes, floors climbed, weight, body fat, sleep and exercise sessions. Steps, distance, active energy, active zone minutes and floors are read as daily totals already calculated by Google. The first sync reads up to 90 days of history; later syncs start 3 days before the previous one.

A sync happens only when your app asks for one while it is open: each time you start the app, and after that at most once an hour, when you pull down to refresh the Today screen. Our server does not fetch your Fitbit data on a schedule of its own.

From Google we also store your Google Health user ID (or older Fitbit user ID) and the time zone from your Google Health settings; we ignore the other settings. When you open your list of Fitbit devices, our server fetches each device’s name, type, battery level, last sync time and supported features from Google and shows them to you without storing them.

What we store from Fitbit: one figure per measure per day, with the name of the device or app that recorded it where Google provides one; each night of sleep with its exact start and end time and sleep stages; and each exercise session with its exact start and end time, duration, distance, energy and heart-rate figures, plus Google’s own reference for the session, which we use to avoid duplicates. Exercise session titles are used only to pick a general activity type (such as “running”) and are not stored. Google’s raw responses are held in memory only while they are processed and are never stored.

To keep reading your data, we store the access and refresh tokens that Google issues to us, encrypted (see section 8).

3.3 Your account: Sign in with Apple

Sign in with Apple is the only way to sign in. Bulfit asks Apple only for your email address, not your name. Apple lets you share your real address or a private relay address that forwards to it.

From the sign-in, our server keeps:

Apple’s sign-in token is checked once and then discarded. We also create a random internal account ID, and a second random identifier that is currently not used for anything.

3.4 Records the service creates

3.5 Technical data in server logs

Our server logs every request it receives. These access logs contain your IP address, the time, the address requested (including any parameters in it), the result, size and duration, and information your phone sends automatically, such as the app and system version (the “User-Agent”) and your language settings. The Authorization header, which carries your sign-in credential, is hidden. When you connect Fitbit, the one-time code that Google sends back to our server is part of a logged address.

Visits to this website (bulfit.net) are logged in the same way: your IP address, the time, the page you asked for, and the information your browser sends automatically, such as its type and version, your language settings and the page that linked you here. The website sets no cookies and loads nothing from other companies. These logs are kept as described in section 8.

Our application logs record events such as “session created”. Instead of your account ID they carry a short tag calculated from it; anyone with access to our database could link a tag to an account. They contain no health values, and fields such as email, name, token, question and answer are hidden. They may contain your time zone and short error messages from Google.

Your phone’s language setting is also used to decide whether AI answers are written in English or Turkish.

4. What we do not collect

5. Where your data is processed

On your phone: reading Apple Health, combining readings and building the daily summaries. The phone also calculates its own baselines, recovery score, sleep and training analysis and short automatic insights shown in the app; these local results are not sent to us.

The app does not save health data to disk; health data stays in memory while the app runs. There are two exceptions. Test builds made before a fix on 22 September 2026 may have left copies of our server’s responses, which contain health figures, in the app’s cache; these are removed when you are signed out (after deleting your account, or when your session ends). And, as for any iPhone app, iOS keeps a picture of the last screen you saw for the app switcher. The app stores only your two sign-in tokens (in the iOS Keychain, usable only on that device) and a note that you have finished setup. Deleting the app may leave the tokens in the Keychain; they stop working when your session ends, at most 30 days after you signed in. If you export your data, the file is saved only where you choose. The app also writes technical entries (event names, addresses called, status and timing, but no health values) to the iPhone’s own system log, and does not send them anywhere.

On our server in Türkiye: your account, daily summaries, sleep, workouts and Fitbit data are stored; baselines and recovery scores are calculated; and Fitbit data is fetched from Google. Whenever the app asks for an AI explanation, an AI request is assembled in memory from your stored figures (and any question you typed); it is sent to the AI provider only if you have turned AI on, and is otherwise discarded. Traffic between the app and our server is encrypted (HTTPS). The database cannot be reached from the internet.

Other companies:

To run our server we use infrastructure service providers, who process data only on our behalf and only as needed to provide that service. Apart from them and the companies listed above, we do not send your data to any other company.

6. AI explanations (optional)

Your choice

Provider

AI answers are produced by an external AI service provider that we use for this purpose, through its API. Where the app says an answer was “written by the All Health model”, it means that provider’s model; it is not a model of our own. Requests are sent from our server, not from your phone, so the AI provider does not see your IP address or your device.

When requests are made

The app asks our server for an explanation automatically every time you start it (when the Today screen, which opens first, loads). With AI on, this becomes a request to the AI provider; with AI off, our server refuses it without contacting the AI provider. A request is also made whenever you ask a question or tap a suggested question. A single request may be sent to the AI provider up to four times: again without a formatting option if the AI provider rejects it, and once more if its reply cannot be used, in which case the repeat includes up to 2,000 characters of the model’s previous reply. If the AI provider cannot be reached, the request is not repeated.

What is sent

Our server builds each request from the daily summaries it holds for you, which may come from Apple Health, Fitbit or both. Figures are rounded (for example steps to the nearest 100, heart rate and HRV to whole numbers, sleep to a tenth of an hour). A request can contain:

What is never sent

Apart from whatever you type into a question, our server never puts your name, email address, Apple identifier, account IDs, device or app names, exact dates or times, location, individual readings or day-by-day series into an AI request. An automatic check blocks any request that contains a field outside a fixed list, or, outside your question, a value that looks like an email address, a token, a timestamp, a pair of coordinates or a UUID (a common format for IDs).

Your question is sent as you wrote it, apart from technical clean-up such as removing control characters. It is not checked for personal details, and the automatic check above does not apply to it. Do not type anything you would not want the AI provider to receive, such as names, contact details or information about other people.

What we keep

We do not store your question or the AI’s answer. The answer is shown in the app and kept only in memory.

For each AI request that passes the consent check and the automatic check, we keep a record of the type of request, the provider and model names, the names (not the values) of the fields sent, whether it succeeded, how long it took, any error code and when it happened. This shows that, and when, you asked a free-text question, but not what you asked. These records are kept until you delete your account.

What the AI provider does with the data

How long the AI provider keeps requests and answers, whether it uses them to train models, where it processes them and whether it passes them on to others (for example the developer of the model) depend on the AI provider’s own practices. We cannot see or control them from our systems, and our requests do not include any instruction not to keep the data. If this matters to you, leave AI turned off.

Limits on answers

The model is told that it is not a clinician and must not diagnose, name diseases or conditions, or give advice on medication or treatment. If an answer makes a medical claim, or contains things such as email addresses or internal system details, our server sends it back to the AI provider once for correction. If the corrected answer still fails the check, our server replaces it with an answer from its own rules. The summary of every answer is labelled as written by the model or by the rule engine.

7. Google user data

We intend our use of information received from Google APIs to follow the Google API Services User Data Policy, including the Limited Use requirements. However, when AI is on, rounded figures derived from your Fitbit data are sent to the AI provider, and we do not yet have terms with the AI provider that limit how it keeps or uses them.

In practice:

8. Storage, security and retention

Security

How long we keep data

What we cannot yet confirm

9. Your rights and how to use them

In the app, under Profile › Privacy Centre unless stated otherwise:

By email at hi@bulfit.net you can ask to see, correct or delete your data, receive a copy of it, restrict or object to its processing, withdraw your consent, or ask anything about this policy. We may ask you for information to confirm that the account is yours. We will reply free of charge, as soon as possible and within 30 days at the latest.

If you are not satisfied with our answer, you can complain to Türkiye’s Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) or, if you live in the European Economic Area, to your local data protection authority.

10. No advertising, no selling, no tracking

Bulfit shows no advertising. We do not sell or rent your data, and we do not use it for advertising or marketing. The app contains no analytics, advertising, crash-reporting or tracking code and does not use the advertising identifier, and our server uses no third-party analytics or error-tracking service. We do not track you across other companies’ apps or websites. Your Apple Health data is never used for advertising.

11. Children

Bulfit is not intended for children. The app does not ask for your age. If you believe a child has created an account, write to us and we will delete it.

Health data is a special category of personal data under Türkiye’s Personal Data Protection Law No. 6698 (KVKK) and, where it applies to you, the EU General Data Protection Regulation (GDPR).

Our server is in Türkiye. If you use Bulfit from outside Türkiye, your data is sent to and stored on that server; we have not put in place any additional transfer safeguards for users outside Türkiye, and the app does not ask for separate consent to this. We do not send your health data to Apple or Google. We do not know whether the AI provider processes AI requests outside Türkiye (section 6), and we have no agreement with it about such transfers; if that matters to you, leave AI turned off.

13. Changes to this policy

Bulfit is in private testing and changes often. When this policy changes, we will publish the new version on this page and update the effective date. If a change needs your consent, we will ask for it before the change applies to you.

Effective date: 22 September 2026

Bulfit Gizlilik Politikası

Yürürlük tarihi: 22 Eylül 2026

Bu politika, Bulfit’in hangi kişisel verileri işlediğini, bu verilerin nereye gittiğini ve bu konuda neler yapabileceğinizi açıklar. Uygulamayı ve sunucumuzu yürürlük tarihindeki çalışma biçimleriyle anlatır.

Bulfit kapalı test aşamasındadır. Mevcut test sürümünde uygulama telefonunuzda hâlâ eski adıyla, “All Health” olarak görünür. Bu politikada Bulfit dendiği her yerde bu uygulama kastedilir.

Mevcut test sürümündeki bazı metinler eksik ya da yanlıştır. iPhone’un Apple Health izin ekranı yalnızca nabız, HRV, dinlenme nabzı, uyku, etkinlik ve antrenmanları sayar; oysa uygulama bölüm 3.1’de sayılan 18 veri türünün tamamını okumak için izin ister. Bazı metinler sağlık verilerinin telefonda işlendiğini ya da Apple Health’ten hiçbir şeyin özgün biçimiyle telefondan çıkmadığını söyler, ancak her uyku gecesinin ve her antrenmanın kesin saatleriyle, cihazlarınızın adlarıyla birlikte gönderildiğini belirtmez. Giriş ekranı yalnızca rastgele bir iç tanımlayıcıdan söz eder, oysa Apple’ın verdiği tanımlayıcıyı da saklarız (bölüm 3.3). Yapay zekâ onay metni gönderilen değerlerin yalnızca bir kısmını sayar (bölüm 6) ve yazdığınız soruların yapay zekâ sağlayıcısına gönderildiğini söylemez. Gizlilik Merkezi, yapay zekâ hizmetinin sizi rastgele bir tanımlayıcıyla tanıdığını söyler, ancak ona sizi tanımlayan hiçbir tanımlayıcı gönderilmez. Hesabınızı silerken gösterilen metin yedeklerden söz etmez. Aralarında fark olduğunda gerçekte ne olduğunu bu politika anlatır.

1. Sorumlu kim

Bulfit’te kişisel verilerinizden sorumlu taraf (veri sorumlusu) Bulfit Compliance Team’dir (Bulfit Uyum Ekibi).

Bu politika veya verilerinizle ilgili her soru için ve haklarınızdan herhangi birini kullanmak için hi@bulfit.net adresine yazın.

2. Bulfit nedir

Bulfit bir iPhone uygulamasıdır. Apple Health’teki (Apple Watch verileri dahil) ve bağlamayı seçerseniz Fitbit’teki sağlık ve fitness verilerinizi bir araya getirir. Her günün bir özetini çıkarır, sizin için neyin normal olduğunu (kişisel ortalamalarınızı) öğrenir, günlük bir toparlanma puanı hesaplar ve bu özelliği açarsanız değerlerinizi sade bir dille açıklamak için bir yapay zekâ hizmeti kullanır.

Bulfit bir tıbbi cihaz ya da tıbbi hizmet değildir. Herhangi bir hastalığı veya durumu teşhis etmek, tedavi etmek ya da önlemek için tasarlanmamıştır ve gösterdiği hiçbir şey tıbbi tavsiye değildir. Sağlığınızla ilgili bir endişeniz varsa yetkin bir sağlık profesyoneline danışın.

3. Neleri topluyoruz ve nereden

3.1 Apple Health, yalnızca izninizle

Kurulum sırasında uygulama, Apple Health verilerinizi okumak için izin ister. Bu adımı atlayabilirsiniz (“Şimdilik geç”). Mevcut test sürümünde uygulama Apple Health erişimini yalnızca kurulum sırasında ister; bu nedenle adımı atlarsanız, kurulumu yeniden yapana kadar (örneğin bir sonraki kez giriş yapmanız gerektiğinde ya da uygulamayı yeniden yüklediğinizde) uygulama iPhone’unuzun Sağlık ayarlarında görünmez. Erişime izin verdiyseniz bunu istediğiniz zaman iPhone ayarlarınızdan kapatabilir veya yeniden açabilirsiniz (bkz. bölüm 9). Bulfit yalnızca okuma izni ister. Apple Health’e hiçbir zaman yazmaz; yani orada hiçbir şey eklemez ya da değiştirmez.

Uygulama şu 18 veri türünü okumak için izin ister: nabız, dinlenme nabzı, kalp atış hızı değişkenliği (HRV), solunum hızı, kandaki oksijen, vücut sıcaklığı, adım sayısı, yürüme ve koşu mesafesi, aktif enerji, dinlenme enerjisi, egzersiz dakikaları, çıkılan kat sayısı, kilo, vücut yağ oranı, yağsız vücut kütlesi, VO2 maks, uyku ve antrenmanlar.

Uygulama her yenilemede bu verilerin son 90 gününü telefonunuzda okur. Adım sayısı, mesafe, aktif ve dinlenme enerjisi, egzersiz dakikaları ve çıkılan kat sayısı için, kaydeden her cihaz veya uygulama için ayrı ayrı saatlik toplamları okur. Diğer ölçümler için her ölçümün değerini ve zamanını, ölçümü kaydeden uygulamanın veya cihazın adını, cihaz modelini, elle girilip girilmediğini ve Apple Health’in o kayda verdiği kimliği okur. Uyku için uyku evrelerini ve saatlerini okur. Antrenmanlar için etkinlik türünü, başlangıç ve bitiş saatini ve Apple Health’in o antrenman için tuttuğu toplamları ve nabız değerlerini okur. Cihaz modeli, “elle girildi” bilgisi ve kayıt kimliği yalnızca telefonda kullanılır (örneğin aynı ölçüm iki kez sayılmasın diye) ve bize hiçbir zaman gönderilmez.

Uygulama telefonunuzda farklı cihazlardan gelen ölçümleri, aynı etkinliği iki kez toplamadan, her ölçüm türü için günde tek bir değerde birleştirir ve uyku verilerini gecelere ayırır. Ardından sunucumuza günlük özetler gönderir: son 90 günün veri bulunan her günü için bir özet. Her yenileme yalnızca yeni günleri değil, bu günlerin tamamını yeniden gönderir. Bir günlük özet şunları içerir:

Cihaz adları. Kendi iPhone’unuzun veya Apple Watch’unuzun kaydettiği veriler için “cihazın adı”, o cihaza verdiğiniz addır. Bu ad varsayılan olarak adınızı içerir (örneğin “Ayşe’nin iPhone’u”). Bu ad sunucumuza gönderilir ve günlük değerlerinizle birlikte saklanır. Başka bir uygulamanın yazdığı veriler için bu, o uygulamanın adıdır.

Tek tek ölçümler (örneğin her bir nabız ölçümü) gönderilmez. Apple Health kayıt kimlikleri, cihaz modeliniz ve herhangi bir konum bilgisi de gönderilmez.

Uygulama bu özetleri, onu her başlattığınızda veya giriş yaptığınızda (ilk açılan ekran olan Bugün ekranı yüklendiğinde) ve Bugün ekranını aşağı çekerek her yenilediğinizde otomatik olarak gönderir. Apple Health’i yalnızca açıkken okur ve sunucumuza yalnızca açıkken bağlanır; arka planda hiçbir iş yapmaz. Gönderimleri duraklatmak için ayrı bir düğme yoktur: durdurmak için uygulamanın Apple Health erişimini kapatın veya uygulamayı kullanmayı bırakın.

3.2 Fitbit, Google Health API üzerinden, yalnızca bağlarsanız

Fitbit verileri Bulfit’e Google’ın Google Health API’si üzerinden ulaşır. Bağlamak isteğe bağlıdır. Bağlı cihazlar bölümünde “Fitbit’i bağla”yı seçerseniz telefonunuzun tarayıcısında Google’ın giriş sayfası açılır ve erişim verip vermeyeceğinize orada karar verirsiniz. Girişi uygulamanın içinde değil, tarayıcınızda Google’ın sayfasında yaparsınız.

Bulfit Google’dan dört salt okunur izin ister: etkinlik ve fitness; sağlık metrikleri ve ölçümler; uyku; ve ayarlar. Konum izni veya herhangi bir şeyi değiştirme izni istemez; bu nedenle egzersiz rotalarınızı (GPS) okuyamayız ve Google ya da Fitbit hesabınıza yazamayız.

Sunucumuz ardından şunları okur: günlük dinlenme nabzı, günlük HRV, günlük solunum hızı, günlük kandaki oksijen, uyku sırasında ölçülen cilt sıcaklığı değişimleri, adım sayısı, mesafe, aktif enerji, aktif bölge dakikaları, çıkılan kat sayısı, kilo, vücut yağı, uyku ve egzersiz oturumları. Adım sayısı, mesafe, aktif enerji, aktif bölge dakikaları ve kat sayısı, Google’ın önceden hesapladığı günlük toplamlar olarak okunur. İlk eşitleme en fazla 90 günlük geçmişi okur; sonraki eşitlemeler bir öncekinden 3 gün önceden başlar.

Eşitleme yalnızca uygulamanız açıkken bunu istediğinde yapılır: uygulamayı her başlattığınızda ve ardından, Bugün ekranını aşağı çekerek yenilediğinizde, en fazla saatte bir. Sunucumuz Fitbit verilerinizi kendi belirlediği bir takvimle çekmez.

Google’dan ayrıca Google Health kullanıcı kimliğinizi (veya eski Fitbit kullanıcı kimliğinizi) ve Google Health ayarlarınızdaki saat dilimini saklarız; diğer ayarları dikkate almayız. Fitbit cihaz listenizi açtığınızda sunucumuz her cihazın adını, türünü, pil düzeyini, son eşitleme zamanını ve desteklediği özellikleri Google’dan alır ve bunları saklamadan size gösterir.

Fitbit’ten sakladıklarımız: her ölçüm türü için günde bir değer ve Google sağlıyorsa bunu kaydeden cihazın veya uygulamanın adı; her uyku gecesi, kesin başlangıç ve bitiş saati ve uyku evreleriyle birlikte; ve her egzersiz oturumu, kesin başlangıç ve bitiş saati, süresi, mesafesi, enerjisi ve nabız değerleriyle birlikte, ayrıca Google’ın o oturum için verdiği ve tekrarları önlemek için kullandığımız referans. Egzersiz oturumu başlıkları yalnızca genel bir etkinlik türü (örneğin “koşu”) seçmek için kullanılır ve saklanmaz. Google’ın ham yanıtları yalnızca işlenirken bellekte tutulur ve hiçbir zaman saklanmaz.

Verilerinizi okumaya devam edebilmek için Google’ın bize verdiği erişim ve yenileme anahtarlarını (token) şifreli olarak saklarız (bkz. bölüm 8).

3.3 Hesabınız: Apple ile Giriş Yap

Giriş yapmanın tek yolu Apple ile Giriş Yap’tır. Bulfit Apple’dan adınızı değil, yalnızca e-posta adresinizi ister. Apple, gerçek adresinizi ya da ona yönlendiren özel bir aktarma (private relay) adresini paylaşmanıza izin verir.

Girişten sunucumuz şunları saklar:

Apple’ın giriş anahtarı bir kez doğrulanır ve ardından atılır. Ayrıca rastgele bir iç hesap kimliği ve şu anda hiçbir şey için kullanılmayan ikinci bir rastgele tanımlayıcı oluştururuz.

3.4 Hizmetin oluşturduğu kayıtlar

3.5 Sunucu kayıtlarındaki teknik veriler

Sunucumuz aldığı her isteği kayda geçirir. Bu erişim kayıtları IP adresinizi, zamanı, istenen adresi (içindeki parametreler dahil), sonucu, boyutu ve süreyi, ayrıca telefonunuzun otomatik olarak gönderdiği bilgileri, örneğin uygulama ve sistem sürümünü (“User-Agent”) ve dil ayarlarınızı içerir. Giriş bilginizi taşıyan Authorization başlığı gizlenir. Fitbit’i bağladığınızda Google’ın sunucumuza geri gönderdiği tek kullanımlık kod, kayda geçen bir adresin parçasıdır.

Bu web sitesine (bulfit.net) yapılan ziyaretler de aynı şekilde kayda geçirilir: IP adresiniz, zaman, istediğiniz sayfa ve tarayıcınızın otomatik olarak gönderdiği bilgiler, örneğin tarayıcının türü ve sürümü, dil ayarlarınız ve sizi buraya yönlendiren sayfa. Web sitesi çerez kullanmaz ve başka şirketlerden hiçbir şey yüklemez. Bu kayıtlar bölüm 8’de anlatıldığı gibi tutulur.

Uygulama kayıtlarımız “oturum oluşturuldu” gibi olayları kaydeder. Bu kayıtlar hesap kimliğiniz yerine ondan hesaplanan kısa bir etiket taşır; veritabanımıza erişimi olan biri bir etiketi bir hesapla eşleştirebilir. Sağlık değeri içermezler; e-posta, ad, anahtar (token), soru ve yanıt gibi alanlar gizlenir. Saat diliminizi ve Google’dan gelen kısa hata mesajlarını içerebilirler.

Telefonunuzun dil ayarı, yapay zekâ yanıtlarının İngilizce mi Türkçe mi yazılacağına karar vermek için de kullanılır.

4. Neleri toplamıyoruz

5. Verileriniz nerede işlenir

Telefonunuzda: Apple Health’in okunması, ölçümlerin birleştirilmesi ve günlük özetlerin oluşturulması. Telefon ayrıca uygulamada gösterilen kendi kişisel ortalamalarını, toparlanma puanını, uyku ve antrenman analizini ve kısa otomatik içgörüleri hesaplar; bu yerel sonuçlar bize gönderilmez.

Uygulama sağlık verilerini diske kaydetmez; sağlık verileri uygulama çalışırken bellekte kalır. Bunun iki istisnası vardır. 22 Eylül 2026’daki bir düzeltmeden önce hazırlanan test sürümleri, sunucumuzun sağlık değerleri içeren yanıtlarının kopyalarını uygulamanın önbelleğinde bırakmış olabilir; bunlar oturumunuz kapatıldığında (hesabınızı sildikten sonra ya da oturumunuz sona erdiğinde) silinir. Ayrıca her iPhone uygulamasında olduğu gibi iOS, uygulama değiştirici için gördüğünüz son ekranın bir görüntüsünü saklar. Uygulama yalnızca iki oturum anahtarınızı (iOS Anahtar Zinciri’nde, yalnızca o cihazda kullanılabilir biçimde) ve kurulumu tamamladığınıza dair bir işareti saklar. Uygulamayı silmek bu anahtarları Anahtar Zinciri’nde bırakabilir; anahtarlar oturumunuz sona erdiğinde, yani giriş yaptıktan en geç 30 gün sonra çalışmaz hale gelir. Verilerinizi dışa aktarırsanız dosya yalnızca sizin seçtiğiniz yere kaydedilir. Uygulama ayrıca iPhone’un kendi sistem günlüğüne teknik kayıtlar (olay adları, çağrılan adresler, durum ve süre; sağlık değeri yok) yazar ve bunları hiçbir yere göndermez.

Türkiye’deki sunucumuzda: hesabınız, günlük özetleriniz, uyku, antrenman ve Fitbit verileriniz saklanır; kişisel ortalamalar ve toparlanma puanları hesaplanır; ve Fitbit verileri Google’dan alınır. Uygulama bir yapay zekâ açıklaması istediğinde, saklanan değerlerinizden (ve yazdığınız bir soru varsa ondan) bellekte bir yapay zekâ isteği oluşturulur; bu istek yalnızca yapay zekâyı açtıysanız yapay zekâ sağlayıcısına gönderilir, aksi halde atılır. Uygulama ile sunucumuz arasındaki trafik şifrelidir (HTTPS). Veritabanına internetten erişilemez.

Diğer şirketler:

Sunucumuzu işletmek için, verileri yalnızca bizim adımıza ve yalnızca bu hizmet için gerektiği ölçüde işleyen altyapı hizmet sağlayıcıları kullanırız. Onlar ve yukarıda sayılan şirketler dışında verilerinizi başka hiçbir şirkete göndermeyiz.

6. Yapay zekâ açıklamaları (isteğe bağlı)

Seçiminiz

Sağlayıcı

Yapay zekâ yanıtlarını, bu amaçla kullandığımız dış bir yapay zekâ hizmet sağlayıcısı, kendi API’si üzerinden üretir. Uygulama bir yanıt için “All Health modeli yazdı” dediğinde bu sağlayıcının modeli kastedilir; bu bizim kendi modelimiz değildir. İstekler telefonunuzdan değil sunucumuzdan gönderilir; bu nedenle yapay zekâ sağlayıcısı IP adresinizi veya cihazınızı görmez.

İsteklerin ne zaman yapıldığı

Uygulama, onu her başlattığınızda (ilk açılan ekran olan Bugün ekranı yüklendiğinde) sunucumuzdan otomatik olarak bir açıklama ister. Yapay zekâ açıksa bu, yapay zekâ sağlayıcısına giden bir isteğe dönüşür; kapalıysa sunucumuz isteği sağlayıcıya başvurmadan reddeder. Ayrıca her soru sorduğunuzda veya önerilen bir soruya dokunduğunuzda da istek yapılır. Tek bir istek sağlayıcıya en fazla dört kez gönderilebilir: sağlayıcı isteği reddederse bir biçimlendirme seçeneği olmadan yeniden, yanıtı kullanılamazsa bir kez daha; bu son durumda yeniden gönderilen istek, modelin önceki yanıtından en fazla 2.000 karakter içerir. Sağlayıcıya ulaşılamazsa istek yinelenmez.

Neler gönderilir

Sunucumuz her isteği sizin için tuttuğu günlük özetlerden oluşturur; bunlar Apple Health’ten, Fitbit’ten veya her ikisinden gelebilir. Değerler yuvarlanır (örneğin adım sayısı en yakın 100’e, nabız ve HRV tam sayıya, uyku saatin onda birine). Bir istek şunları içerebilir:

Hiçbir zaman gönderilmeyenler

Yazdığınız bir soru dışında, sunucumuz bir yapay zekâ isteğine hiçbir zaman adınızı, e-posta adresinizi, Apple tanımlayıcınızı, hesap kimliklerinizi, cihaz veya uygulama adlarını, kesin tarih veya saatleri, konumu, tek tek ölçümleri ya da gün gün seriler halindeki verileri koymaz. Otomatik bir kontrol, sabit bir listenin dışında kalan bir alanı ya da sorunuz dışında e-posta adresi, anahtar (token), zaman damgası, koordinat çifti veya UUID (kimlikler için yaygın bir biçim) gibi görünen bir değeri içeren her isteği engeller.

Sorunuz, yazdığınız gibi gönderilir; yalnızca kontrol karakterlerinin kaldırılması gibi teknik temizlik yapılır. Kişisel bilgi içerip içermediği denetlenmez ve yukarıdaki otomatik kontrol ona uygulanmaz. Yapay zekâ sağlayıcısının almasını istemeyeceğiniz hiçbir şeyi, örneğin adları, iletişim bilgilerini veya başka kişilerle ilgili bilgileri yazmayın.

Neleri saklıyoruz

Sorunuzu veya yapay zekânın yanıtını saklamayız. Yanıt uygulamada gösterilir ve yalnızca bellekte tutulur.

Onay kontrolünü ve otomatik kontrolü geçen her yapay zekâ isteği için şunların kaydını tutarız: istek türü, sağlayıcı ve model adları, gönderilen alanların adları (değerleri değil), başarılı olup olmadığı, ne kadar sürdüğü, varsa hata kodu ve ne zaman gerçekleştiği. Bu kayıt serbest metinli bir soru sorduğunuzu ve bunu ne zaman yaptığınızı gösterir, ne sorduğunuzu göstermez. Bu kayıtlar hesabınızı silene kadar saklanır.

Yapay zekâ sağlayıcısının verilerle ne yaptığı

Yapay zekâ sağlayıcısının istekleri ve yanıtları ne kadar süre sakladığı, bunları model eğitmek için kullanıp kullanmadığı, nerede işlediği ve başkalarına (örneğin modelin geliştiricisine) aktarıp aktarmadığı sağlayıcının kendi uygulamalarına bağlıdır. Bunları kendi sistemlerimizden göremez ve denetleyemeyiz; isteklerimiz, verilerin saklanmamasını isteyen bir talimat da içermez. Bu sizin için önemliyse yapay zekâyı kapalı tutun.

Yanıtlara ilişkin sınırlar

Modele, bir hekim olmadığı ve teşhis koymaması, hastalık veya durum adı vermemesi, ilaç ya da tedavi konusunda tavsiyede bulunmaması söylenir. Bir yanıt tıbbi bir iddia içeriyorsa ya da e-posta adresi veya iç sistem ayrıntıları gibi şeyler barındırıyorsa sunucumuz onu düzeltilmesi için bir kez yapay zekâ sağlayıcısına geri gönderir. Düzeltilen yanıt da kontrolden geçemezse sunucumuz onu kendi kurallarından üretilen bir yanıtla değiştirir. Her yanıtın özeti, modelin mi yoksa kural motorunun mu yazdığı belirtilerek etiketlenir.

7. Google kullanıcı verileri

Google API’lerinden alınan bilgileri, Sınırlı Kullanım (Limited Use) gereklilikleri dahil olmak üzere Google API Hizmetleri Kullanıcı Verileri Politikası’na uygun biçimde kullanmayı amaçlıyoruz. Ancak yapay zekâ açıkken Fitbit verilerinizden türetilen yuvarlanmış değerler yapay zekâ sağlayıcısına gönderilir ve sağlayıcı ile bu değerleri nasıl sakladığını veya kullandığını sınırlayan bir sözleşmemiz henüz yoktur.

Uygulamada bu şu anlama gelir:

8. Depolama, güvenlik ve saklama süresi

Güvenlik

Verileri ne kadar süre saklıyoruz

Henüz doğrulayamadıklarımız

9. Haklarınız ve bunları nasıl kullanırsınız

Aksi belirtilmedikçe uygulamada Profil › Gizlilik Merkezi altında:

E-postayla hi@bulfit.net adresine yazarak verilerinizi görmeyi, düzeltilmesini veya silinmesini, bir kopyasını almayı, işlenmesinin kısıtlanmasını veya işlenmesine itiraz etmeyi, onayınızı geri almayı talep edebilir ya da bu politikayla ilgili her şeyi sorabilirsiniz. Hesabın size ait olduğunu doğrulamak için sizden bilgi isteyebiliriz. Başvurunuza en kısa sürede ve en geç 30 gün içinde, ücretsiz olarak yanıt veririz.

Yanıtımızdan memnun kalmazsanız Kişisel Verileri Koruma Kurumu’na veya Avrupa Ekonomik Alanı’nda yaşıyorsanız bulunduğunuz yerdeki veri koruma otoritesine şikâyette bulunabilirsiniz.

10. Reklam yok, satış yok, izleme yok

Bulfit reklam göstermez. Verilerinizi satmayız veya kiralamayız, reklam ya da pazarlama için kullanmayız. Uygulama analiz, reklam, çökme raporlama veya izleme kodu içermez ve reklam tanımlayıcısını kullanmaz; sunucumuz da üçüncü taraf bir analiz veya hata izleme hizmeti kullanmaz. Sizi başka şirketlerin uygulamaları veya web siteleri arasında izlemeyiz. Apple Health verileriniz hiçbir zaman reklam için kullanılmaz.

11. Çocuklar

Bulfit çocuklara yönelik değildir. Uygulama yaşınızı sormaz. Bir çocuğun hesap oluşturduğunu düşünüyorsanız bize yazın; hesabı sileriz.

Sağlık verileri, 6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) ve sizin için geçerli olduğu durumlarda AB Genel Veri Koruma Tüzüğü (GDPR) kapsamında özel nitelikli kişisel veridir.

Sunucumuz Türkiye’dedir. Bulfit’i Türkiye dışından kullanırsanız verileriniz bu sunucuya gönderilir ve orada saklanır; Türkiye dışındaki kullanıcılar için ek bir aktarım güvencesi oluşturmadık ve uygulama bu konuda ayrıca rıza istemez. Sağlık verilerinizi Apple’a veya Google’a göndermeyiz. Yapay zekâ sağlayıcısının istekleri Türkiye dışında işleyip işlemediğini bilmiyoruz (bölüm 6) ve onunla bu tür aktarımlara ilişkin bir sözleşmemiz yoktur; bu sizin için önemliyse yapay zekâyı kapalı tutun.

13. Bu politikadaki değişiklikler

Bulfit kapalı test aşamasındadır ve sık değişir. Bu politika değiştiğinde yeni sürümü bu sayfada yayımlar ve yürürlük tarihini güncelleriz. Bir değişiklik onayınızı gerektiriyorsa, değişiklik sizin için geçerli olmadan önce onayınızı isteriz.

Yürürlük tarihi: 22 Eylül 2026