Bulfit Privacy Policy
This policy explains what personal data Bulfit handles, where it goes and what you can do about it. It describes the app and our server as they work on the effective date.
Bulfit is in private testing. In the current test build the app still appears on your phone under its earlier name, “All Health”. Wherever this policy says Bulfit, that app is meant.
Some texts inside the current test build are incomplete or wrong. The iPhone’s Apple Health permission screen names only heart rate, HRV, resting heart rate, sleep, activity and workouts, although the app asks to read all 18 kinds of data listed in section 3.1. Several texts say that health data is processed on the phone, or that nothing from Apple Health leaves it in its original form, without saying that each night’s sleep and each workout are sent with their exact times, together with the names of your devices. The sign-in screen mentions only an internal random identifier, although we also keep the identifier Apple gives us (section 3.3). The AI consent text lists only some of the figures that are sent (section 6) and does not say that questions you type are sent to the AI provider. The Privacy Centre says the AI service knows you by a random identifier, but no identifier for you is sent to it. The text shown when you delete your account does not mention backups. Where they differ, this policy describes what actually happens.
1. Who is responsible
The party responsible for your personal data in Bulfit (the data controller) is the Bulfit Compliance Team.
For any question about this policy or your data, and to use any of your rights, write to hi@bulfit.net.
2. What Bulfit is
Bulfit is an iPhone app. It brings together health and fitness data from Apple Health (including data from an Apple Watch) and, if you connect it, from Fitbit. It builds a summary of each day, learns what is normal for you (your personal “baselines”), calculates a daily recovery score and, if you turn this on, uses an AI service to explain your figures in plain language.
Bulfit is not a medical device and not a medical service. It is not designed to diagnose, treat or prevent any disease or condition, and nothing it shows is medical advice. If you are concerned about your health, speak to a qualified healthcare professional.
3. What we collect and where it comes from
3.1 Apple Health, only with your permission
During setup the app asks for permission to read your Apple Health data. You can skip this step (“Skip for now”). In the current test build the app asks for Apple Health access only during setup, so if you skip it, the app will not appear in your iPhone’s Health settings until you go through setup again (for example the next time you have to sign in, or after reinstalling the app). If you allowed access, you can turn it off, or back on, at any time in your iPhone’s settings (see section 9). Bulfit asks only to read. It never writes to Apple Health, so it never adds or changes anything there.
The app asks to read these 18 kinds of data: heart rate, resting heart rate, heart rate variability (HRV), respiratory rate, blood oxygen, body temperature, steps, walking and running distance, active energy, resting energy, exercise minutes, flights climbed, weight, body fat percentage, lean body mass, VO2 max, sleep and workouts.
Each time it refreshes, the app reads the last 90 days of this data on your phone. For steps, distance, active and resting energy, exercise minutes and flights climbed, it reads hourly totals for each recording device or app. For the other measures, it reads each reading’s value and time, the name of the app or device that recorded it, the device model, whether it was typed in by hand, and Apple Health’s ID for the record. For sleep, it reads the sleep stages and their times. For workouts, it reads the activity type, the start and end time, and the totals and heart-rate figures Apple Health keeps for the workout. The device model, the “typed in by hand” flag and the record ID are used only on the phone (for example, so that the same reading is not counted twice) and are never sent to us.
On your phone the app combines readings from different devices into one figure per measure per day, without adding up the same activity twice, and groups sleep data into nights. It then sends daily summaries to our server: one for every day of the last 90 that has data. Every refresh sends all of these days again, not only new ones. A daily summary contains:
- the date (the calendar day in your phone’s time zone);
- for each measure: the day’s value and unit, how it was combined, a confidence level, the fact that it came from Apple Health, the name of the device or app that recorded the chosen value, the values that other devices or apps in Apple Health reported that day (without their names), and the number of readings it is based on;
- for sleep: the night’s exact start and end time (to the second); the time spent asleep, in bed, awake, and in deep, REM and core sleep; the number of times you woke up; and its source and a confidence level;
- for each workout: the type of activity, its exact start and end time, duration, distance, active energy, average and maximum heart rate, and its source and a confidence level;
- which sources contributed that day and which measures were missing.
Device names. For data that your own iPhone or Apple Watch records, “the name of the device” is the name you gave that device. By default this contains your first name (for example “Sam’s iPhone”). This name is sent to our server and stored with your daily figures. For data written by another app, it is that app’s name.
Individual readings (such as each separate heart-rate measurement) are not sent. Nor are Apple Health record IDs, your device model or any location.
The app sends these summaries automatically every time you start it or sign in (when the Today screen, which opens first, loads) and whenever you pull down to refresh the Today screen. It reads Apple Health and contacts our server only while it is open; it does no work in the background. There is no separate switch to pause uploads: to stop them, turn off the app’s access to Apple Health or stop using the app.
3.2 Fitbit, through the Google Health API, only if you connect it
Fitbit data reaches Bulfit through Google’s Google Health API. Connecting it is optional. If you choose “Connect Fitbit” under Connected devices, your phone’s browser opens Google’s sign-in page, where you decide whether to grant access. You sign in on Google’s page in your browser, not inside the app.
Bulfit asks Google for four read-only permissions: activity and fitness; health metrics and measurements; sleep; and settings. It does not ask for location or for permission to change anything, so we cannot read your exercise routes (GPS) or write to your Google or Fitbit account.
Our server then reads: daily resting heart rate, daily HRV, daily respiratory rate, daily blood oxygen, skin temperature changes measured during sleep, steps, distance, active energy, active zone minutes, floors climbed, weight, body fat, sleep and exercise sessions. Steps, distance, active energy, active zone minutes and floors are read as daily totals already calculated by Google. The first sync reads up to 90 days of history; later syncs start 3 days before the previous one.
A sync happens only when your app asks for one while it is open: each time you start the app, and after that at most once an hour, when you pull down to refresh the Today screen. Our server does not fetch your Fitbit data on a schedule of its own.
From Google we also store your Google Health user ID (or older Fitbit user ID) and the time zone from your Google Health settings; we ignore the other settings. When you open your list of Fitbit devices, our server fetches each device’s name, type, battery level, last sync time and supported features from Google and shows them to you without storing them.
What we store from Fitbit: one figure per measure per day, with the name of the device or app that recorded it where Google provides one; each night of sleep with its exact start and end time and sleep stages; and each exercise session with its exact start and end time, duration, distance, energy and heart-rate figures, plus Google’s own reference for the session, which we use to avoid duplicates. Exercise session titles are used only to pick a general activity type (such as “running”) and are not stored. Google’s raw responses are held in memory only while they are processed and are never stored.
To keep reading your data, we store the access and refresh tokens that Google issues to us, encrypted (see section 8).
3.3 Your account: Sign in with Apple
Sign in with Apple is the only way to sign in. Bulfit asks Apple only for your email address, not your name. Apple lets you share your real address or a private relay address that forwards to it.
From the sign-in, our server keeps:
- the user identifier that Apple creates for your account with our app (a code that does not change);
- the email address Apple gives us, which is your real address or, if you chose “Hide My Email”, a private relay address that forwards to it, and whether it is a relay address. We do not currently use it for anything; it is kept with your account and included in your data export.
Apple’s sign-in token is checked once and then discarded. We also create a random internal account ID, and a second random identifier that is currently not used for anything.
3.4 Records the service creates
- Baselines and daily recovery scores that our server calculates from your summaries.
- Sign-in sessions: when each began, when it expires or was ended, and the label “iOS”. These records contain no IP address and no device identifier.
- Your AI consent decisions, each with its date. Each also carries a version field, which is currently always “1” and does not record which text you were shown.
- A log of privacy-related actions, for example: account created, AI consent given or withdrawn, Fitbit connected or disconnected, data export requested, AI history deleted.
- If you connected Fitbit: the connection’s status, the permissions granted, the last sync time and the last error code.
- A record of each AI request (see section 6).
3.5 Technical data in server logs
Our server logs every request it receives. These access logs contain your IP address, the time, the address requested (including any parameters in it), the result, size and duration, and information your phone sends automatically, such as the app and system version (the “User-Agent”) and your language settings. The Authorization header, which carries your sign-in credential, is hidden. When you connect Fitbit, the one-time code that Google sends back to our server is part of a logged address.
Visits to this website (bulfit.net) are logged in the same way: your IP address, the time, the page you asked for, and the information your browser sends automatically, such as its type and version, your language settings and the page that linked you here. The website sets no cookies and loads nothing from other companies. These logs are kept as described in section 8.
Our application logs record events such as “session created”. Instead of your account ID they carry a short tag calculated from it; anyone with access to our database could link a tag to an account. They contain no health values, and fields such as email, name, token, question and answer are hidden. They may contain your time zone and short error messages from Google.
Your phone’s language setting is also used to decide whether AI answers are written in English or Turkish.
4. What we do not collect
- We never write to Apple Health.
- From Apple Health we do not request blood pressure, blood glucose, height, date of birth, sex, blood type, clinical (medical) records or workout routes.
- We do not collect your precise location: the app does not ask for location permission, and we do not ask Google for location data. Your IP address in our server logs (section 3.5) and your time zone can show roughly where you are.
- The app does not ask for access to your contacts, photos, camera, microphone, motion data or Bluetooth, or for permission to send notifications.
- We do not ask for your name. Your name can still reach us through a device name (section 3.1), an email address, or something you type into a question (section 6).
- We do not use the advertising identifier or Apple’s identifier for vendors (identifierForVendor). We do receive the names of your devices, as described in section 3.1. The app includes no third-party software libraries: no analytics, advertising, crash-reporting or tracking tools.
- Individual readings from Apple Health and raw responses from Google are not stored on our server.
5. Where your data is processed
On your phone: reading Apple Health, combining readings and building the daily summaries. The phone also calculates its own baselines, recovery score, sleep and training analysis and short automatic insights shown in the app; these local results are not sent to us.
The app does not save health data to disk; health data stays in memory while the app runs. There are two exceptions. Test builds made before a fix on 22 September 2026 may have left copies of our server’s responses, which contain health figures, in the app’s cache; these are removed when you are signed out (after deleting your account, or when your session ends). And, as for any iPhone app, iOS keeps a picture of the last screen you saw for the app switcher. The app stores only your two sign-in tokens (in the iOS Keychain, usable only on that device) and a note that you have finished setup. Deleting the app may leave the tokens in the Keychain; they stop working when your session ends, at most 30 days after you signed in. If you export your data, the file is saved only where you choose. The app also writes technical entries (event names, addresses called, status and timing, but no health values) to the iPhone’s own system log, and does not send them anywhere.
On our server in Türkiye: your account, daily summaries, sleep, workouts and Fitbit data are stored; baselines and recovery scores are calculated; and Fitbit data is fetched from Google. Whenever the app asks for an AI explanation, an AI request is assembled in memory from your stored figures (and any question you typed); it is sent to the AI provider only if you have turned AI on, and is otherwise discarded. Traffic between the app and our server is encrypted (HTTPS). The database cannot be reached from the internet.
Other companies:
- Apple provides Sign in with Apple and Apple Health on your phone under Apple’s own terms. Our server contacts Apple only to download Apple’s public keys for checking sign-ins; this request contains no data about you.
- Google holds your Fitbit data under Google’s own terms. Our server sends Google only what it needs to connect and read your data: the one-time sign-in code and our app credentials when you connect, our tokens when renewing or revoking access, and, for each read, the access token with the type of data, the date range and paging details. It never sends health data to Google.
- An external AI service provider receives the AI requests described in section 6, and only if you have turned AI on.
To run our server we use infrastructure service providers, who process data only on our behalf and only as needed to provide that service. Apart from them and the companies listed above, we do not send your data to any other company.
6. AI explanations (optional)
Your choice
- AI is off by default. A new account starts with AI turned off.
- During setup the app asks you separately: “Turn on AI insights” or “Not now”. You can change your choice at any time in Privacy Centre with “Allow cloud AI processing”.
- If your choice cannot be recorded (for example because you are offline), the previous setting stays in effect (for a new account, that means off), and the current app does not show an error.
- If you turn AI off, this applies from the next request. Your earlier decisions stay in your consent history.
- Our server checks your consent on every AI request. Without consent, nothing is sent to the AI provider and no AI request record is created. The current app shows the question box even when AI is off; a question you type then still reaches our server, which refuses it without passing it on or storing it.
Provider
AI answers are produced by an external AI service provider that we use for this purpose, through its API. Where the app says an answer was “written by the All Health model”, it means that provider’s model; it is not a model of our own. Requests are sent from our server, not from your phone, so the AI provider does not see your IP address or your device.
When requests are made
The app asks our server for an explanation automatically every time you start it (when the Today screen, which opens first, loads). With AI on, this becomes a request to the AI provider; with AI off, our server refuses it without contacting the AI provider. A request is also made whenever you ask a question or tap a suggested question. A single request may be sent to the AI provider up to four times: again without a formatting option if the AI provider rejects it, and once more if its reply cannot be used, in which case the repeat includes up to 2,000 characters of the model’s previous reply. If the AI provider cannot be reached, the request is not repeated.
What is sent
Our server builds each request from the daily summaries it holds for you, which may come from Apple Health, Fitbit or both. Figures are rounded (for example steps to the nearest 100, heart rate and HRV to whole numbers, sleep to a tenth of an hour). A request can contain:
- your recovery score, its state and confidence, its parts and its main factors;
- sleep: the latest night’s duration, your usual duration and the difference, a classification, sleep efficiency, and whether sleep stages are available;
- HRV, resting heart rate and respiratory rate, each with your baseline for comparison;
- steps and active energy, each with your baseline for comparison;
- training load as a band (such as “moderate”) and a load ratio;
- for HRV (measured in up to two ways), resting heart rate, sleep duration and steps: the direction, percentage and confidence of the change over the last 30 days;
- which measures are missing, and an overall data confidence;
- technical fields: the type of request, a relative period such as “today”, the answer language (English or Turkish) and a random request number that is new each time and that we do not keep;
- the question you typed or the suggested question you tapped, up to 1,000 characters.
What is never sent
Apart from whatever you type into a question, our server never puts your name, email address, Apple identifier, account IDs, device or app names, exact dates or times, location, individual readings or day-by-day series into an AI request. An automatic check blocks any request that contains a field outside a fixed list, or, outside your question, a value that looks like an email address, a token, a timestamp, a pair of coordinates or a UUID (a common format for IDs).
Your question is sent as you wrote it, apart from technical clean-up such as removing control characters. It is not checked for personal details, and the automatic check above does not apply to it. Do not type anything you would not want the AI provider to receive, such as names, contact details or information about other people.
What we keep
We do not store your question or the AI’s answer. The answer is shown in the app and kept only in memory.
For each AI request that passes the consent check and the automatic check, we keep a record of the type of request, the provider and model names, the names (not the values) of the fields sent, whether it succeeded, how long it took, any error code and when it happened. This shows that, and when, you asked a free-text question, but not what you asked. These records are kept until you delete your account.
What the AI provider does with the data
How long the AI provider keeps requests and answers, whether it uses them to train models, where it processes them and whether it passes them on to others (for example the developer of the model) depend on the AI provider’s own practices. We cannot see or control them from our systems, and our requests do not include any instruction not to keep the data. If this matters to you, leave AI turned off.
Limits on answers
The model is told that it is not a clinician and must not diagnose, name diseases or conditions, or give advice on medication or treatment. If an answer makes a medical claim, or contains things such as email addresses or internal system details, our server sends it back to the AI provider once for correction. If the corrected answer still fails the check, our server replaces it with an answer from its own rules. The summary of every answer is labelled as written by the model or by the rule engine.
7. Google user data
We intend our use of information received from Google APIs to follow the Google API Services User Data Policy, including the Limited Use requirements. However, when AI is on, rounded figures derived from your Fitbit data are sent to the AI provider, and we do not yet have terms with the AI provider that limit how it keeps or uses them.
In practice:
- We ask Google only for the four read-only permissions listed in section 3.2, and not for location.
- We use data received from Google only to show you your own figures, baselines, recovery score, sleep and training information in the app, to produce AI explanations for you if you have turned AI on, and to run the service. For example, the time zone from your Google Health settings decides where your days begin and end, and Google data is included in our backups (section 8). When AI is on, rounded figures based partly on your Fitbit data are sent to the AI provider as described in section 6; what the AI provider does with them is outside our control.
- We do not use Google user data for advertising, we do not sell it, and we do not use it to develop or train AI models.
- Bulfit has no screen or tool that shows your data to other users or to administrators. The people who run our server can technically access the database and its backups. They do not look at an individual user’s data, including data received from Google, unless that user agrees, it is needed for security, or the law requires it.
- When you disconnect Fitbit, we ask Google to revoke our access and we delete the tokens we hold. We do not currently check Google’s reply, so please confirm in your Google Account’s list of third-party connections that the app no longer has access. Data already synced from Fitbit, and the time zone taken from your Google Health settings, are not deleted when you disconnect: they stay until you delete your account. Until then the data is still shown in the app and, if AI is on, still used in AI requests to the AI provider. To have only that data deleted, write to hi@bulfit.net.
- Deleting your Bulfit account deletes the Google tokens we hold but does not ask Google to revoke access. Disconnect Fitbit first, or remove access in your Google Account.
8. Storage, security and retention
Security
- All traffic between the app and our server is encrypted with HTTPS.
- Google access and refresh tokens are encrypted in the database with AES-256-GCM. The key is kept outside the database, in a protected configuration file on the same server, and in the development environment on the computer used to build Bulfit.
- Everything else, including your health figures, sleep and workout times, email address and device names, is stored in the database without additional encryption by the application. We have not been able to confirm whether the server’s disks are encrypted.
- The database and a short-term cache run on an internal network that cannot be reached from the internet. The cache holds only a link between a Fitbit connection attempt and your account, for at most 10 minutes; it is deleted when used and never written to disk.
- Each request to our server is tied to your own sign-in and can reach only your own data. Your sign-in session ends at most 30 days after you sign in with Apple; after that you sign in again. The current test build has no separate sign-out button, so apart from deleting your account, a session ends only when it expires.
How long we keep data
- There is currently no automatic deletion. Your daily summaries, sleep, workouts, baselines, recovery scores, AI request records, consent history, privacy log and sign-in session records are kept until you delete your account. The Fitbit connection and its tokens are kept until you disconnect Fitbit or delete your account.
- The Privacy Centre in the current test build shows “Retention” as 90 days. That limit is not yet enforced: data older than 90 days is not currently deleted automatically.
- Turning off Apple Health access or disconnecting Fitbit stops new data from arriving but does not delete data already stored, which is still used for your figures and, if AI is on, for AI requests.
- If you delete or change a record in Apple Health, our copy is not always updated. A changed daily value is replaced at the next refresh only if the day is within the last 90 days and that measure still has data that day. A deleted workout or night of sleep, or a measure with no data left that day, stays on our server until you delete your account or ask us by email to remove it.
- Backups: every night a full copy of the database is made and kept on the same server, normally for about 15 to 16 days. Older copies are deleted by the next nightly backup that succeeds, so if backups fail for a while, older copies are kept longer. The copies are not encrypted by the application, and the backup process does not copy them anywhere else; see “What we cannot yet confirm” for copies made while the service was being set up. Data you delete, including a deleted account, remains in copies made before the deletion until they expire. If an older copy were ever restored, accounts deleted since it was made would come back; there is no automatic step to delete them again.
- Server logs of the API and the web server are limited by size (about 50 MB per service), not by time, and are also removed whenever the service is updated. How many days they cover depends on traffic. The database’s own log is kept under the same size limit but, unlike the other server logs, is not cleared when the service is updated.
- After an account is deleted, one record remains that is not linked to the account: the time of the deletion and how many items of each kind were deleted.
What we cannot yet confirm
- how the AI provider handles AI requests (section 6);
- whether the server’s disks are encrypted;
- what the database’s own log records, which we have not configured, and how long the operating system’s journal on the server is kept;
- whether all copies of data made while the service was being set up (a test restore on the server and data moved from a development environment) have been removed.
9. Your rights and how to use them
In the app, under Profile › Privacy Centre unless stated otherwise:
- Get a copy of your data: “Export my data” creates a JSON file that you save wherever you choose (suggested name “all-health-export”). It contains your account email, Fitbit connection, consent history, daily summaries (including the values other sources reported and, where recorded, the name of the device or app behind them), sleep durations, workouts, baselines, recovery scores and privacy log. It does not yet contain everything we hold: for example it leaves out your time zone, sign-in session records, AI request records, your Apple identifier, your Google Health user ID, the device or app name chosen for each daily figure, the exact start and end times of sleep and the end times of workouts. You can ask us by email for the rest.
- Withdraw AI consent: turn off “Allow cloud AI processing”.
- Delete AI history: “Delete AI history” deletes stored AI answers. Because we do not store AI answers, there is currently nothing for it to delete, and it does not delete the AI request records described in section 6. Those are deleted with your account, or you can ask us by email to delete them.
- Delete your account: “Delete account and all data” immediately deletes your account and everything linked to it on our server: sign-in sessions, Fitbit connection and tokens, daily summaries, sleep, workouts, baselines, recovery scores, AI request records, consent history and privacy log. The exceptions are the backups and server logs described in section 8, the one unlinked record with counts, any copies listed under “What we cannot yet confirm”, and anything the AI provider may have kept from earlier AI requests (section 6), which deleting your account cannot reach. Deleting your account does not revoke Google’s access (disconnect Fitbit first), does not remove the app’s permission to read Apple Health, and does not remove Bulfit from Sign in with Apple in your Apple Account settings. The current app signs you out afterwards even if the deletion failed, without showing an error; if you want to be sure, ask us by email to confirm.
- Disconnect Fitbit: under Profile › Connected devices, choose “Disconnect”. It takes effect at once, without a confirmation step; if Fitbit is still listed afterwards, the request did not go through and you should try again. See section 7 for what this does and does not delete.
- Stop Apple Health access: in the iPhone’s Settings › Privacy & Security › Health, choose the app and turn off the categories you no longer want it to read. This stops future reads; summaries already sent to us stay until you delete your account and are still used for your figures and, if AI is on, for AI requests.
- Stop using Sign in with Apple for Bulfit: in your Apple Account settings, under Sign in with Apple. This does not delete your Bulfit account or any data on our server, and the app stays signed in until its current session ends (at most 30 days after you signed in). To delete your data, use “Delete account and all data” first.
- Deleting the app: deleting the app from your iPhone does not delete your account or any data on our server, and your sign-in tokens may remain in the iPhone’s Keychain. To delete your data, use “Delete account and all data” before you remove the app, or write to us.
By email at hi@bulfit.net you can ask to see, correct or delete your data, receive a copy of it, restrict or object to its processing, withdraw your consent, or ask anything about this policy. We may ask you for information to confirm that the account is yours. We will reply free of charge, as soon as possible and within 30 days at the latest.
If you are not satisfied with our answer, you can complain to Türkiye’s Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) or, if you live in the European Economic Area, to your local data protection authority.
10. No advertising, no selling, no tracking
Bulfit shows no advertising. We do not sell or rent your data, and we do not use it for advertising or marketing. The app contains no analytics, advertising, crash-reporting or tracking code and does not use the advertising identifier, and our server uses no third-party analytics or error-tracking service. We do not track you across other companies’ apps or websites. Your Apple Health data is never used for advertising.
11. Children
Bulfit is not intended for children. The app does not ask for your age. If you believe a child has created an account, write to us and we will delete it.
12. Legal basis
Health data is a special category of personal data under Türkiye’s Personal Data Protection Law No. 6698 (KVKK) and, where it applies to you, the EU General Data Protection Regulation (GDPR).
- Health data from Apple Health and Fitbit: we rely on your explicit consent. For Apple Health, the current test build does not yet ask for this consent in a separate step. It relies on the permission you give on your iPhone, and the text on that permission screen says that data is processed on the phone and does not describe the upload to our server (see the note at the top of this policy). For Fitbit, you give your consent by connecting Fitbit; the connection screens do not say that the data is stored on our server in Türkiye. If you did not expect your data to be sent to our server, write to hi@bulfit.net and we will delete it, or delete your account yourself (section 9). You can withdraw your consent at any time as described in section 9. Withdrawing stops new data from arriving. Data already stored is kept, and still used for your figures and, if AI is on, for AI requests, until you delete your account or ask us by email to delete it.
- AI processing: a separate explicit consent, which stays off until you turn it on. The consent text in the current test build lists only some of the figures described in section 6 and does not say that questions you type are sent. Section 6 is the complete description, and you can turn AI off at any time.
- Account and sign-in records and server logs: needed to provide the service you signed up for and to keep it secure.
- Backups also contain your health data. They are kept for about 15 to 16 days to protect against data loss, and for the health data in them we rely on the same explicit consent as for the health data itself.
- AI request records, consent history and the privacy log are kept until you delete your account, so that we can show which choices you made and that we respected them.
Our server is in Türkiye. If you use Bulfit from outside Türkiye, your data is sent to and stored on that server; we have not put in place any additional transfer safeguards for users outside Türkiye, and the app does not ask for separate consent to this. We do not send your health data to Apple or Google. We do not know whether the AI provider processes AI requests outside Türkiye (section 6), and we have no agreement with it about such transfers; if that matters to you, leave AI turned off.
13. Changes to this policy
Bulfit is in private testing and changes often. When this policy changes, we will publish the new version on this page and update the effective date. If a change needs your consent, we will ask for it before the change applies to you.
Bulfit Gizlilik Politikası
Bu politika, Bulfit’in hangi kişisel verileri işlediğini, bu verilerin nereye gittiğini ve bu konuda neler yapabileceğinizi açıklar. Uygulamayı ve sunucumuzu yürürlük tarihindeki çalışma biçimleriyle anlatır.
Bulfit kapalı test aşamasındadır. Mevcut test sürümünde uygulama telefonunuzda hâlâ eski adıyla, “All Health” olarak görünür. Bu politikada Bulfit dendiği her yerde bu uygulama kastedilir.
Mevcut test sürümündeki bazı metinler eksik ya da yanlıştır. iPhone’un Apple Health izin ekranı yalnızca nabız, HRV, dinlenme nabzı, uyku, etkinlik ve antrenmanları sayar; oysa uygulama bölüm 3.1’de sayılan 18 veri türünün tamamını okumak için izin ister. Bazı metinler sağlık verilerinin telefonda işlendiğini ya da Apple Health’ten hiçbir şeyin özgün biçimiyle telefondan çıkmadığını söyler, ancak her uyku gecesinin ve her antrenmanın kesin saatleriyle, cihazlarınızın adlarıyla birlikte gönderildiğini belirtmez. Giriş ekranı yalnızca rastgele bir iç tanımlayıcıdan söz eder, oysa Apple’ın verdiği tanımlayıcıyı da saklarız (bölüm 3.3). Yapay zekâ onay metni gönderilen değerlerin yalnızca bir kısmını sayar (bölüm 6) ve yazdığınız soruların yapay zekâ sağlayıcısına gönderildiğini söylemez. Gizlilik Merkezi, yapay zekâ hizmetinin sizi rastgele bir tanımlayıcıyla tanıdığını söyler, ancak ona sizi tanımlayan hiçbir tanımlayıcı gönderilmez. Hesabınızı silerken gösterilen metin yedeklerden söz etmez. Aralarında fark olduğunda gerçekte ne olduğunu bu politika anlatır.
1. Sorumlu kim
Bulfit’te kişisel verilerinizden sorumlu taraf (veri sorumlusu) Bulfit Compliance Team’dir (Bulfit Uyum Ekibi).
Bu politika veya verilerinizle ilgili her soru için ve haklarınızdan herhangi birini kullanmak için hi@bulfit.net adresine yazın.
2. Bulfit nedir
Bulfit bir iPhone uygulamasıdır. Apple Health’teki (Apple Watch verileri dahil) ve bağlamayı seçerseniz Fitbit’teki sağlık ve fitness verilerinizi bir araya getirir. Her günün bir özetini çıkarır, sizin için neyin normal olduğunu (kişisel ortalamalarınızı) öğrenir, günlük bir toparlanma puanı hesaplar ve bu özelliği açarsanız değerlerinizi sade bir dille açıklamak için bir yapay zekâ hizmeti kullanır.
Bulfit bir tıbbi cihaz ya da tıbbi hizmet değildir. Herhangi bir hastalığı veya durumu teşhis etmek, tedavi etmek ya da önlemek için tasarlanmamıştır ve gösterdiği hiçbir şey tıbbi tavsiye değildir. Sağlığınızla ilgili bir endişeniz varsa yetkin bir sağlık profesyoneline danışın.
3. Neleri topluyoruz ve nereden
3.1 Apple Health, yalnızca izninizle
Kurulum sırasında uygulama, Apple Health verilerinizi okumak için izin ister. Bu adımı atlayabilirsiniz (“Şimdilik geç”). Mevcut test sürümünde uygulama Apple Health erişimini yalnızca kurulum sırasında ister; bu nedenle adımı atlarsanız, kurulumu yeniden yapana kadar (örneğin bir sonraki kez giriş yapmanız gerektiğinde ya da uygulamayı yeniden yüklediğinizde) uygulama iPhone’unuzun Sağlık ayarlarında görünmez. Erişime izin verdiyseniz bunu istediğiniz zaman iPhone ayarlarınızdan kapatabilir veya yeniden açabilirsiniz (bkz. bölüm 9). Bulfit yalnızca okuma izni ister. Apple Health’e hiçbir zaman yazmaz; yani orada hiçbir şey eklemez ya da değiştirmez.
Uygulama şu 18 veri türünü okumak için izin ister: nabız, dinlenme nabzı, kalp atış hızı değişkenliği (HRV), solunum hızı, kandaki oksijen, vücut sıcaklığı, adım sayısı, yürüme ve koşu mesafesi, aktif enerji, dinlenme enerjisi, egzersiz dakikaları, çıkılan kat sayısı, kilo, vücut yağ oranı, yağsız vücut kütlesi, VO2 maks, uyku ve antrenmanlar.
Uygulama her yenilemede bu verilerin son 90 gününü telefonunuzda okur. Adım sayısı, mesafe, aktif ve dinlenme enerjisi, egzersiz dakikaları ve çıkılan kat sayısı için, kaydeden her cihaz veya uygulama için ayrı ayrı saatlik toplamları okur. Diğer ölçümler için her ölçümün değerini ve zamanını, ölçümü kaydeden uygulamanın veya cihazın adını, cihaz modelini, elle girilip girilmediğini ve Apple Health’in o kayda verdiği kimliği okur. Uyku için uyku evrelerini ve saatlerini okur. Antrenmanlar için etkinlik türünü, başlangıç ve bitiş saatini ve Apple Health’in o antrenman için tuttuğu toplamları ve nabız değerlerini okur. Cihaz modeli, “elle girildi” bilgisi ve kayıt kimliği yalnızca telefonda kullanılır (örneğin aynı ölçüm iki kez sayılmasın diye) ve bize hiçbir zaman gönderilmez.
Uygulama telefonunuzda farklı cihazlardan gelen ölçümleri, aynı etkinliği iki kez toplamadan, her ölçüm türü için günde tek bir değerde birleştirir ve uyku verilerini gecelere ayırır. Ardından sunucumuza günlük özetler gönderir: son 90 günün veri bulunan her günü için bir özet. Her yenileme yalnızca yeni günleri değil, bu günlerin tamamını yeniden gönderir. Bir günlük özet şunları içerir:
- tarih (telefonunuzun saat dilimine göre takvim günü);
- her ölçüm türü için: günün değeri ve birimi, nasıl birleştirildiği, bir güven düzeyi, Apple Health’ten geldiği bilgisi, seçilen değeri kaydeden cihazın veya uygulamanın adı, Apple Health’teki diğer cihazların veya uygulamaların o gün bildirdiği değerler (adları olmadan) ve değerin dayandığı ölçüm sayısı;
- uyku için: gecenin saniyesine kadar kesin başlangıç ve bitiş saati; uykuda, yatakta, uyanık ve derin, REM ve çekirdek (core) uykuda geçen süre; kaç kez uyandığınız; ayrıca kaynağı ve bir güven düzeyi;
- her antrenman için: etkinlik türü, kesin başlangıç ve bitiş saati, süresi, mesafe, aktif enerji, ortalama ve en yüksek nabız; ayrıca kaynağı ve bir güven düzeyi;
- o gün hangi kaynakların veri sağladığı ve hangi ölçümlerin eksik olduğu.
Cihaz adları. Kendi iPhone’unuzun veya Apple Watch’unuzun kaydettiği veriler için “cihazın adı”, o cihaza verdiğiniz addır. Bu ad varsayılan olarak adınızı içerir (örneğin “Ayşe’nin iPhone’u”). Bu ad sunucumuza gönderilir ve günlük değerlerinizle birlikte saklanır. Başka bir uygulamanın yazdığı veriler için bu, o uygulamanın adıdır.
Tek tek ölçümler (örneğin her bir nabız ölçümü) gönderilmez. Apple Health kayıt kimlikleri, cihaz modeliniz ve herhangi bir konum bilgisi de gönderilmez.
Uygulama bu özetleri, onu her başlattığınızda veya giriş yaptığınızda (ilk açılan ekran olan Bugün ekranı yüklendiğinde) ve Bugün ekranını aşağı çekerek her yenilediğinizde otomatik olarak gönderir. Apple Health’i yalnızca açıkken okur ve sunucumuza yalnızca açıkken bağlanır; arka planda hiçbir iş yapmaz. Gönderimleri duraklatmak için ayrı bir düğme yoktur: durdurmak için uygulamanın Apple Health erişimini kapatın veya uygulamayı kullanmayı bırakın.
3.2 Fitbit, Google Health API üzerinden, yalnızca bağlarsanız
Fitbit verileri Bulfit’e Google’ın Google Health API’si üzerinden ulaşır. Bağlamak isteğe bağlıdır. Bağlı cihazlar bölümünde “Fitbit’i bağla”yı seçerseniz telefonunuzun tarayıcısında Google’ın giriş sayfası açılır ve erişim verip vermeyeceğinize orada karar verirsiniz. Girişi uygulamanın içinde değil, tarayıcınızda Google’ın sayfasında yaparsınız.
Bulfit Google’dan dört salt okunur izin ister: etkinlik ve fitness; sağlık metrikleri ve ölçümler; uyku; ve ayarlar. Konum izni veya herhangi bir şeyi değiştirme izni istemez; bu nedenle egzersiz rotalarınızı (GPS) okuyamayız ve Google ya da Fitbit hesabınıza yazamayız.
Sunucumuz ardından şunları okur: günlük dinlenme nabzı, günlük HRV, günlük solunum hızı, günlük kandaki oksijen, uyku sırasında ölçülen cilt sıcaklığı değişimleri, adım sayısı, mesafe, aktif enerji, aktif bölge dakikaları, çıkılan kat sayısı, kilo, vücut yağı, uyku ve egzersiz oturumları. Adım sayısı, mesafe, aktif enerji, aktif bölge dakikaları ve kat sayısı, Google’ın önceden hesapladığı günlük toplamlar olarak okunur. İlk eşitleme en fazla 90 günlük geçmişi okur; sonraki eşitlemeler bir öncekinden 3 gün önceden başlar.
Eşitleme yalnızca uygulamanız açıkken bunu istediğinde yapılır: uygulamayı her başlattığınızda ve ardından, Bugün ekranını aşağı çekerek yenilediğinizde, en fazla saatte bir. Sunucumuz Fitbit verilerinizi kendi belirlediği bir takvimle çekmez.
Google’dan ayrıca Google Health kullanıcı kimliğinizi (veya eski Fitbit kullanıcı kimliğinizi) ve Google Health ayarlarınızdaki saat dilimini saklarız; diğer ayarları dikkate almayız. Fitbit cihaz listenizi açtığınızda sunucumuz her cihazın adını, türünü, pil düzeyini, son eşitleme zamanını ve desteklediği özellikleri Google’dan alır ve bunları saklamadan size gösterir.
Fitbit’ten sakladıklarımız: her ölçüm türü için günde bir değer ve Google sağlıyorsa bunu kaydeden cihazın veya uygulamanın adı; her uyku gecesi, kesin başlangıç ve bitiş saati ve uyku evreleriyle birlikte; ve her egzersiz oturumu, kesin başlangıç ve bitiş saati, süresi, mesafesi, enerjisi ve nabız değerleriyle birlikte, ayrıca Google’ın o oturum için verdiği ve tekrarları önlemek için kullandığımız referans. Egzersiz oturumu başlıkları yalnızca genel bir etkinlik türü (örneğin “koşu”) seçmek için kullanılır ve saklanmaz. Google’ın ham yanıtları yalnızca işlenirken bellekte tutulur ve hiçbir zaman saklanmaz.
Verilerinizi okumaya devam edebilmek için Google’ın bize verdiği erişim ve yenileme anahtarlarını (token) şifreli olarak saklarız (bkz. bölüm 8).
3.3 Hesabınız: Apple ile Giriş Yap
Giriş yapmanın tek yolu Apple ile Giriş Yap’tır. Bulfit Apple’dan adınızı değil, yalnızca e-posta adresinizi ister. Apple, gerçek adresinizi ya da ona yönlendiren özel bir aktarma (private relay) adresini paylaşmanıza izin verir.
Girişten sunucumuz şunları saklar:
- Apple’ın uygulamamızdaki hesabınız için oluşturduğu kullanıcı tanımlayıcısı (değişmeyen bir kod);
- Apple’ın bize verdiği e-posta adresi: gerçek adresiniz ya da “E-postamı Gizle”yi seçtiyseniz ona yönlendiren özel bir aktarma adresi; ayrıca bunun bir aktarma adresi olup olmadığı. Bu adresi şu anda hiçbir şey için kullanmıyoruz; hesabınızla birlikte saklanır ve veri dışa aktarımınıza dahil edilir.
Apple’ın giriş anahtarı bir kez doğrulanır ve ardından atılır. Ayrıca rastgele bir iç hesap kimliği ve şu anda hiçbir şey için kullanılmayan ikinci bir rastgele tanımlayıcı oluştururuz.
3.4 Hizmetin oluşturduğu kayıtlar
- Sunucumuzun özetlerinizden hesapladığı kişisel ortalamalar ve günlük toparlanma puanları.
- Oturumlar: her birinin ne zaman başladığı, ne zaman sona ereceği veya sonlandırıldığı ve “iOS” etiketi. Bu kayıtlar IP adresi veya cihaz tanımlayıcısı içermez.
- Yapay zekâ onayına ilişkin kararlarınız; her biri tarihiyle birlikte. Her birinde ayrıca bir sürüm alanı bulunur; bu alan şu anda her zaman “1”dir ve size hangi metnin gösterildiğini kaydetmez.
- Gizlilikle ilgili işlemlerin kaydı, örneğin: hesap oluşturuldu, yapay zekâ onayı verildi veya geri alındı, Fitbit bağlandı veya bağlantısı kesildi, veri dışa aktarımı istendi, yapay zekâ geçmişi silindi.
- Fitbit bağladıysanız: bağlantının durumu, verilen izinler, son eşitleme zamanı ve son hata kodu.
- Her yapay zekâ isteğinin kaydı (bkz. bölüm 6).
3.5 Sunucu kayıtlarındaki teknik veriler
Sunucumuz aldığı her isteği kayda geçirir. Bu erişim kayıtları IP adresinizi, zamanı, istenen adresi (içindeki parametreler dahil), sonucu, boyutu ve süreyi, ayrıca telefonunuzun otomatik olarak gönderdiği bilgileri, örneğin uygulama ve sistem sürümünü (“User-Agent”) ve dil ayarlarınızı içerir. Giriş bilginizi taşıyan Authorization başlığı gizlenir. Fitbit’i bağladığınızda Google’ın sunucumuza geri gönderdiği tek kullanımlık kod, kayda geçen bir adresin parçasıdır.
Bu web sitesine (bulfit.net) yapılan ziyaretler de aynı şekilde kayda geçirilir: IP adresiniz, zaman, istediğiniz sayfa ve tarayıcınızın otomatik olarak gönderdiği bilgiler, örneğin tarayıcının türü ve sürümü, dil ayarlarınız ve sizi buraya yönlendiren sayfa. Web sitesi çerez kullanmaz ve başka şirketlerden hiçbir şey yüklemez. Bu kayıtlar bölüm 8’de anlatıldığı gibi tutulur.
Uygulama kayıtlarımız “oturum oluşturuldu” gibi olayları kaydeder. Bu kayıtlar hesap kimliğiniz yerine ondan hesaplanan kısa bir etiket taşır; veritabanımıza erişimi olan biri bir etiketi bir hesapla eşleştirebilir. Sağlık değeri içermezler; e-posta, ad, anahtar (token), soru ve yanıt gibi alanlar gizlenir. Saat diliminizi ve Google’dan gelen kısa hata mesajlarını içerebilirler.
Telefonunuzun dil ayarı, yapay zekâ yanıtlarının İngilizce mi Türkçe mi yazılacağına karar vermek için de kullanılır.
4. Neleri toplamıyoruz
- Apple Health’e hiçbir zaman yazmayız.
- Apple Health’ten kan basıncı, kan şekeri, boy, doğum tarihi, cinsiyet, kan grubu, klinik (tıbbi) kayıtlar veya antrenman rotaları istemeyiz.
- Kesin konumunuzu toplamayız: uygulama konum izni istemez ve Google’dan konum verisi istemeyiz. Sunucu kayıtlarımızdaki IP adresiniz (bölüm 3.5) ve saat diliminiz, kabaca nerede olduğunuzu gösterebilir.
- Uygulama rehberinize, fotoğraflarınıza, kameranıza, mikrofonunuza, hareket verilerinize veya Bluetooth’a erişim ya da bildirim gönderme izni istemez.
- Adınızı istemeyiz. Adınız yine de bir cihaz adı (bölüm 3.1), bir e-posta adresi ya da bir soruya yazdığınız bir şey (bölüm 6) yoluyla bize ulaşabilir.
- Reklam tanımlayıcısını veya Apple’ın satıcıya özgü tanımlayıcısını (identifierForVendor) kullanmayız. Cihazlarınızın adlarını ise bölüm 3.1’de anlatıldığı gibi alırız. Uygulama hiçbir üçüncü taraf yazılım kitaplığı içermez: analiz, reklam, çökme raporlama veya izleme aracı yoktur.
- Apple Health’teki tek tek ölçümler ve Google’ın ham yanıtları sunucumuzda saklanmaz.
5. Verileriniz nerede işlenir
Telefonunuzda: Apple Health’in okunması, ölçümlerin birleştirilmesi ve günlük özetlerin oluşturulması. Telefon ayrıca uygulamada gösterilen kendi kişisel ortalamalarını, toparlanma puanını, uyku ve antrenman analizini ve kısa otomatik içgörüleri hesaplar; bu yerel sonuçlar bize gönderilmez.
Uygulama sağlık verilerini diske kaydetmez; sağlık verileri uygulama çalışırken bellekte kalır. Bunun iki istisnası vardır. 22 Eylül 2026’daki bir düzeltmeden önce hazırlanan test sürümleri, sunucumuzun sağlık değerleri içeren yanıtlarının kopyalarını uygulamanın önbelleğinde bırakmış olabilir; bunlar oturumunuz kapatıldığında (hesabınızı sildikten sonra ya da oturumunuz sona erdiğinde) silinir. Ayrıca her iPhone uygulamasında olduğu gibi iOS, uygulama değiştirici için gördüğünüz son ekranın bir görüntüsünü saklar. Uygulama yalnızca iki oturum anahtarınızı (iOS Anahtar Zinciri’nde, yalnızca o cihazda kullanılabilir biçimde) ve kurulumu tamamladığınıza dair bir işareti saklar. Uygulamayı silmek bu anahtarları Anahtar Zinciri’nde bırakabilir; anahtarlar oturumunuz sona erdiğinde, yani giriş yaptıktan en geç 30 gün sonra çalışmaz hale gelir. Verilerinizi dışa aktarırsanız dosya yalnızca sizin seçtiğiniz yere kaydedilir. Uygulama ayrıca iPhone’un kendi sistem günlüğüne teknik kayıtlar (olay adları, çağrılan adresler, durum ve süre; sağlık değeri yok) yazar ve bunları hiçbir yere göndermez.
Türkiye’deki sunucumuzda: hesabınız, günlük özetleriniz, uyku, antrenman ve Fitbit verileriniz saklanır; kişisel ortalamalar ve toparlanma puanları hesaplanır; ve Fitbit verileri Google’dan alınır. Uygulama bir yapay zekâ açıklaması istediğinde, saklanan değerlerinizden (ve yazdığınız bir soru varsa ondan) bellekte bir yapay zekâ isteği oluşturulur; bu istek yalnızca yapay zekâyı açtıysanız yapay zekâ sağlayıcısına gönderilir, aksi halde atılır. Uygulama ile sunucumuz arasındaki trafik şifrelidir (HTTPS). Veritabanına internetten erişilemez.
Diğer şirketler:
- Apple, Apple ile Giriş Yap’ı ve telefonunuzdaki Apple Health’i kendi koşulları altında sağlar. Sunucumuz Apple’a yalnızca girişleri doğrulamak için Apple’ın açık anahtarlarını indirmek üzere bağlanır; bu istek sizinle ilgili hiçbir veri içermez.
- Google, Fitbit verilerinizi kendi koşulları altında tutar. Sunucumuz Google’a yalnızca bağlanmak ve verilerinizi okumak için gerekenleri gönderir: bağlanırken tek kullanımlık giriş kodunu ve uygulamamızın kimlik bilgilerini, erişimi yenilerken veya iptal ederken anahtarlarımızı ve her okumada erişim anahtarını, veri türünü, tarih aralığını ve sayfalama bilgilerini. Google’a hiçbir zaman sağlık verisi göndermez.
- Dış bir yapay zekâ hizmet sağlayıcısı, yalnızca yapay zekâyı açtıysanız, bölüm 6’da anlatılan yapay zekâ isteklerini alır.
Sunucumuzu işletmek için, verileri yalnızca bizim adımıza ve yalnızca bu hizmet için gerektiği ölçüde işleyen altyapı hizmet sağlayıcıları kullanırız. Onlar ve yukarıda sayılan şirketler dışında verilerinizi başka hiçbir şirkete göndermeyiz.
6. Yapay zekâ açıklamaları (isteğe bağlı)
Seçiminiz
- Yapay zekâ varsayılan olarak kapalıdır. Yeni bir hesap yapay zekâ kapalı olarak başlar.
- Kurulum sırasında uygulama bunu ayrıca sorar: “Yapay zekâ içgörülerini aç” veya “Şimdi değil”. Seçiminizi istediğiniz zaman Gizlilik Merkezi’nde “Bulut yapay zekâ işlemeye izin ver” ile değiştirebilirsiniz.
- Seçiminiz kaydedilemezse (örneğin çevrimdışıysanız) önceki ayar geçerli kalır (yeni bir hesapta bu, kapalı demektir) ve mevcut uygulama bir hata göstermez.
- Yapay zekâyı kapatırsanız bu, bir sonraki istekten itibaren geçerli olur. Önceki kararlarınız onay geçmişinizde kalır.
- Sunucumuz onayınızı her yapay zekâ isteğinde kontrol eder. Onay yoksa yapay zekâ sağlayıcısına hiçbir şey gönderilmez ve yapay zekâ isteği kaydı oluşturulmaz. Mevcut uygulama, yapay zekâ kapalıyken de soru kutusunu gösterir; bu durumda yazdığınız bir soru yine sunucumuza ulaşır, sunucumuz da onu reddeder, başka bir yere iletmez ve saklamaz.
Sağlayıcı
Yapay zekâ yanıtlarını, bu amaçla kullandığımız dış bir yapay zekâ hizmet sağlayıcısı, kendi API’si üzerinden üretir. Uygulama bir yanıt için “All Health modeli yazdı” dediğinde bu sağlayıcının modeli kastedilir; bu bizim kendi modelimiz değildir. İstekler telefonunuzdan değil sunucumuzdan gönderilir; bu nedenle yapay zekâ sağlayıcısı IP adresinizi veya cihazınızı görmez.
İsteklerin ne zaman yapıldığı
Uygulama, onu her başlattığınızda (ilk açılan ekran olan Bugün ekranı yüklendiğinde) sunucumuzdan otomatik olarak bir açıklama ister. Yapay zekâ açıksa bu, yapay zekâ sağlayıcısına giden bir isteğe dönüşür; kapalıysa sunucumuz isteği sağlayıcıya başvurmadan reddeder. Ayrıca her soru sorduğunuzda veya önerilen bir soruya dokunduğunuzda da istek yapılır. Tek bir istek sağlayıcıya en fazla dört kez gönderilebilir: sağlayıcı isteği reddederse bir biçimlendirme seçeneği olmadan yeniden, yanıtı kullanılamazsa bir kez daha; bu son durumda yeniden gönderilen istek, modelin önceki yanıtından en fazla 2.000 karakter içerir. Sağlayıcıya ulaşılamazsa istek yinelenmez.
Neler gönderilir
Sunucumuz her isteği sizin için tuttuğu günlük özetlerden oluşturur; bunlar Apple Health’ten, Fitbit’ten veya her ikisinden gelebilir. Değerler yuvarlanır (örneğin adım sayısı en yakın 100’e, nabız ve HRV tam sayıya, uyku saatin onda birine). Bir istek şunları içerebilir:
- toparlanma puanınız, durumu ve güven düzeyi, bileşenleri ve başlıca etkenleri;
- uyku: son gecenin süresi, olağan süreniz ve aradaki fark, bir sınıflandırma, uyku verimliliği ve uyku evrelerinin mevcut olup olmadığı;
- HRV, dinlenme nabzı ve solunum hızı; her biri karşılaştırma için kişisel ortalamanızla birlikte;
- adım sayısı ve aktif enerji; her biri karşılaştırma için kişisel ortalamanızla birlikte;
- bir bant olarak antrenman yükü (örneğin “orta”) ve bir yük oranı;
- HRV (en fazla iki ölçüm yöntemiyle), dinlenme nabzı, uyku süresi ve adım sayısı için son 30 gündeki değişimin yönü, yüzdesi ve güven düzeyi;
- hangi ölçümlerin eksik olduğu ve genel bir veri güven düzeyi;
- teknik alanlar: istek türü, “bugün” gibi göreli bir dönem, yanıt dili (İngilizce veya Türkçe) ve her seferinde yeniden üretilen, bizim saklamadığımız rastgele bir istek numarası;
- yazdığınız soru veya dokunduğunuz önerilen soru; en fazla 1.000 karakter.
Hiçbir zaman gönderilmeyenler
Yazdığınız bir soru dışında, sunucumuz bir yapay zekâ isteğine hiçbir zaman adınızı, e-posta adresinizi, Apple tanımlayıcınızı, hesap kimliklerinizi, cihaz veya uygulama adlarını, kesin tarih veya saatleri, konumu, tek tek ölçümleri ya da gün gün seriler halindeki verileri koymaz. Otomatik bir kontrol, sabit bir listenin dışında kalan bir alanı ya da sorunuz dışında e-posta adresi, anahtar (token), zaman damgası, koordinat çifti veya UUID (kimlikler için yaygın bir biçim) gibi görünen bir değeri içeren her isteği engeller.
Sorunuz, yazdığınız gibi gönderilir; yalnızca kontrol karakterlerinin kaldırılması gibi teknik temizlik yapılır. Kişisel bilgi içerip içermediği denetlenmez ve yukarıdaki otomatik kontrol ona uygulanmaz. Yapay zekâ sağlayıcısının almasını istemeyeceğiniz hiçbir şeyi, örneğin adları, iletişim bilgilerini veya başka kişilerle ilgili bilgileri yazmayın.
Neleri saklıyoruz
Sorunuzu veya yapay zekânın yanıtını saklamayız. Yanıt uygulamada gösterilir ve yalnızca bellekte tutulur.
Onay kontrolünü ve otomatik kontrolü geçen her yapay zekâ isteği için şunların kaydını tutarız: istek türü, sağlayıcı ve model adları, gönderilen alanların adları (değerleri değil), başarılı olup olmadığı, ne kadar sürdüğü, varsa hata kodu ve ne zaman gerçekleştiği. Bu kayıt serbest metinli bir soru sorduğunuzu ve bunu ne zaman yaptığınızı gösterir, ne sorduğunuzu göstermez. Bu kayıtlar hesabınızı silene kadar saklanır.
Yapay zekâ sağlayıcısının verilerle ne yaptığı
Yapay zekâ sağlayıcısının istekleri ve yanıtları ne kadar süre sakladığı, bunları model eğitmek için kullanıp kullanmadığı, nerede işlediği ve başkalarına (örneğin modelin geliştiricisine) aktarıp aktarmadığı sağlayıcının kendi uygulamalarına bağlıdır. Bunları kendi sistemlerimizden göremez ve denetleyemeyiz; isteklerimiz, verilerin saklanmamasını isteyen bir talimat da içermez. Bu sizin için önemliyse yapay zekâyı kapalı tutun.
Yanıtlara ilişkin sınırlar
Modele, bir hekim olmadığı ve teşhis koymaması, hastalık veya durum adı vermemesi, ilaç ya da tedavi konusunda tavsiyede bulunmaması söylenir. Bir yanıt tıbbi bir iddia içeriyorsa ya da e-posta adresi veya iç sistem ayrıntıları gibi şeyler barındırıyorsa sunucumuz onu düzeltilmesi için bir kez yapay zekâ sağlayıcısına geri gönderir. Düzeltilen yanıt da kontrolden geçemezse sunucumuz onu kendi kurallarından üretilen bir yanıtla değiştirir. Her yanıtın özeti, modelin mi yoksa kural motorunun mu yazdığı belirtilerek etiketlenir.
7. Google kullanıcı verileri
Google API’lerinden alınan bilgileri, Sınırlı Kullanım (Limited Use) gereklilikleri dahil olmak üzere Google API Hizmetleri Kullanıcı Verileri Politikası’na uygun biçimde kullanmayı amaçlıyoruz. Ancak yapay zekâ açıkken Fitbit verilerinizden türetilen yuvarlanmış değerler yapay zekâ sağlayıcısına gönderilir ve sağlayıcı ile bu değerleri nasıl sakladığını veya kullandığını sınırlayan bir sözleşmemiz henüz yoktur.
Uygulamada bu şu anlama gelir:
- Google’dan yalnızca bölüm 3.2’de sayılan dört salt okunur izni isteriz; konum izni istemeyiz.
- Google’dan alınan verileri yalnızca size uygulamada kendi değerlerinizi, kişisel ortalamalarınızı, toparlanma puanınızı, uyku ve antrenman bilgilerinizi göstermek, yapay zekâyı açtıysanız size yapay zekâ açıklamaları üretmek ve hizmeti işletmek için kullanırız. Örneğin Google Health ayarlarınızdaki saat dilimi günlerinizin nerede başlayıp bittiğini belirler ve Google verileri yedeklerimizde yer alır (bölüm 8). Yapay zekâ açıkken kısmen Fitbit verilerinize dayanan yuvarlanmış değerler bölüm 6’da anlatıldığı gibi yapay zekâ sağlayıcısına gönderilir; sağlayıcının bunlarla ne yaptığı bizim denetimimizde değildir.
- Google kullanıcı verilerini reklam için kullanmayız, satmayız ve yapay zekâ modelleri geliştirmek ya da eğitmek için kullanmayız.
- Bulfit’te verilerinizi başka kullanıcılara veya yöneticilere gösteren bir ekran ya da araç yoktur. Sunucumuzu işleten kişiler teknik olarak veritabanına ve yedeklerine erişebilir. Bu kişiler, Google’dan alınan veriler dahil tek bir kullanıcının verilerine, o kullanıcı kabul etmedikçe, güvenlik için gerekmedikçe veya yasa gerektirmedikçe bakmazlar.
- Fitbit bağlantısını kestiğinizde Google’dan erişimimizi iptal etmesini isteriz ve elimizdeki anahtarları sileriz. Google’ın yanıtını şu anda kontrol etmiyoruz; bu nedenle lütfen Google Hesabınızdaki üçüncü taraf bağlantıları listesinden uygulamanın artık erişimi olmadığını doğrulayın. Fitbit’ten daha önce eşitlenmiş veriler ve Google Health ayarlarınızdan alınan saat dilimi, bağlantıyı kestiğinizde silinmez; hesabınızı silene kadar kalır. O zamana kadar bu veriler uygulamada gösterilmeye ve yapay zekâ açıksa sağlayıcıya giden yapay zekâ isteklerinde kullanılmaya devam eder. Yalnızca bu verilerin silinmesini istiyorsanız hi@bulfit.net adresine yazın.
- Bulfit hesabınızı silmek elimizdeki Google anahtarlarını siler, ancak Google’dan erişimi iptal etmesini istemez. Önce Fitbit bağlantısını kesin veya erişimi Google Hesabınızdan kaldırın.
8. Depolama, güvenlik ve saklama süresi
Güvenlik
- Uygulama ile sunucumuz arasındaki tüm trafik HTTPS ile şifrelenir.
- Google erişim ve yenileme anahtarları veritabanında AES-256-GCM ile şifrelenir. Şifreleme anahtarı veritabanının dışında, aynı sunucudaki korumalı bir yapılandırma dosyasında ve Bulfit’in geliştirildiği bilgisayardaki geliştirme ortamında tutulur.
- Sağlık değerleriniz, uyku ve antrenman saatleri, e-posta adresiniz ve cihaz adları dahil diğer her şey, veritabanında uygulama tarafından ek bir şifreleme yapılmadan saklanır. Sunucunun disklerinin şifreli olup olmadığını doğrulayamadık.
- Veritabanı ve kısa süreli bir önbellek, internetten erişilemeyen bir iç ağda çalışır. Önbellek yalnızca bir Fitbit bağlantı denemesi ile hesabınız arasındaki bağı en fazla 10 dakika tutar; kullanıldığında silinir ve hiçbir zaman diske yazılmaz.
- Sunucumuza yapılan her istek sizin oturumunuza bağlıdır ve yalnızca sizin verilerinize ulaşabilir. Oturumunuz, Apple ile giriş yaptıktan en geç 30 gün sonra sona erer; ardından yeniden giriş yaparsınız. Mevcut test sürümünde ayrı bir oturumu kapatma düğmesi yoktur; bu nedenle hesabınızı silmediğiniz sürece bir oturum yalnızca süresi dolduğunda sona erer.
Verileri ne kadar süre saklıyoruz
- Şu anda otomatik silme yoktur. Günlük özetleriniz, uyku, antrenman, kişisel ortalamalar, toparlanma puanları, yapay zekâ isteği kayıtları, onay geçmişi, gizlilik kaydı ve oturum kayıtları hesabınızı silene kadar saklanır. Fitbit bağlantısı ve anahtarları, Fitbit bağlantısını kesene veya hesabınızı silene kadar saklanır.
- Mevcut test sürümündeki Gizlilik Merkezi “Saklama süresi” olarak 90 gün gösterir. Bu sınır henüz uygulanmamaktadır: 90 günden eski veriler şu anda otomatik olarak silinmez.
- Apple Health erişimini kapatmak veya Fitbit bağlantısını kesmek yeni veri gelmesini durdurur, ancak saklanmış verileri silmez; bu veriler değerleriniz için ve yapay zekâ açıksa yapay zekâ istekleri için kullanılmaya devam eder.
- Apple Health’te bir kaydı silerseniz veya değiştirirseniz bizdeki kopya her zaman güncellenmez. Değişen bir günlük değer bir sonraki yenilemede yalnızca gün son 90 gün içindeyse ve o ölçüm türünün o gün hâlâ verisi varsa değiştirilir. Silinen bir antrenman veya uyku gecesi ya da o gün hiç verisi kalmayan bir ölçüm, hesabınızı silene veya bizden e-postayla kaldırılmasını isteyene kadar sunucumuzda kalır.
- Yedekler: her gece veritabanının tam bir kopyası alınır ve aynı sunucuda normalde yaklaşık 15–16 gün tutulur. Eski kopyalar, başarıyla tamamlanan bir sonraki gece yedeklemesiyle silinir; bu nedenle yedekleme bir süre başarısız olursa eski kopyalar daha uzun tutulur. Kopyalar uygulama tarafından şifrelenmez ve yedekleme işlemi onları başka bir yere kopyalamaz; hizmet kurulurken oluşturulan kopyalar için “Henüz doğrulayamadıklarımız” bölümüne bakın. Sildiğiniz veriler, silinmiş bir hesap dahil, silme işleminden önce alınan kopyalarda bu kopyaların süresi dolana kadar kalır. Daha eski bir kopya bir gün geri yüklenirse, o kopyadan sonra silinen hesaplar geri gelir; bunları yeniden silen otomatik bir adım yoktur.
- API’nin ve web sunucusunun sunucu kayıtları zamana göre değil boyuta göre sınırlanır (hizmet başına yaklaşık 50 MB) ve hizmet her güncellendiğinde de silinir. Kaç günü kapsadıkları trafiğe bağlıdır. Veritabanının kendi kaydı da aynı boyut sınırıyla tutulur, ancak diğer sunucu kayıtlarından farklı olarak hizmet güncellendiğinde silinmez.
- Bir hesap silindikten sonra hesapla bağlantılı olmayan tek bir kayıt kalır: silme zamanı ve her türden kaç öğenin silindiği.
Henüz doğrulayamadıklarımız
- Yapay zekâ sağlayıcısının istekleri nasıl işlediği (bölüm 6);
- sunucunun disklerinin şifreli olup olmadığı;
- veritabanının kendi kaydına neler yazıldığı (bunun ayarlarını biz yapmadık) ve sunucudaki işletim sistemi günlüğünün ne kadar süre tutulduğu;
- hizmet kurulurken oluşturulan veri kopyalarının (sunucuda yapılan bir test geri yüklemesi ve bir geliştirme ortamından taşınan veriler) tamamının silinip silinmediği.
9. Haklarınız ve bunları nasıl kullanırsınız
Aksi belirtilmedikçe uygulamada Profil › Gizlilik Merkezi altında:
- Verilerinizin bir kopyasını alın: “Verilerimi dışa aktar”, istediğiniz yere kaydedeceğiniz bir JSON dosyası oluşturur (önerilen ad “all-health-export”). Dosya hesap e-postanızı, Fitbit bağlantınızı, onay geçmişinizi, günlük özetlerinizi (diğer kaynakların bildirdiği değerler ve kaydedilmişse bunların arkasındaki cihazın veya uygulamanın adı dahil), uyku sürelerini, antrenmanları, kişisel ortalamaları, toparlanma puanlarını ve gizlilik kaydınızı içerir. Henüz tuttuğumuz her şeyi içermez: örneğin saat diliminiz, oturum kayıtlarınız, yapay zekâ isteği kayıtları, Apple tanımlayıcınız, Google Health kullanıcı kimliğiniz, her günlük değer için seçilen cihaz veya uygulama adı, uykunun kesin başlangıç ve bitiş saatleri ve antrenmanların bitiş saatleri dosyada yer almaz. Geri kalanını bizden e-postayla isteyebilirsiniz.
- Yapay zekâ onayını geri alın: “Bulut yapay zekâ işlemeye izin ver” seçeneğini kapatın.
- Yapay zekâ geçmişini silin: “Yapay zekâ geçmişini sil”, saklanan yapay zekâ yanıtlarını siler. Yapay zekâ yanıtlarını saklamadığımız için şu anda silinecek bir şey yoktur; bölüm 6’da anlatılan yapay zekâ isteği kayıtlarını da silmez. Bu kayıtlar hesabınızla birlikte silinir veya silinmelerini bizden e-postayla isteyebilirsiniz.
- Hesabınızı silin: “Hesabı ve tüm verileri sil”, hesabınızı ve sunucumuzda ona bağlı her şeyi hemen siler: oturumlar, Fitbit bağlantısı ve anahtarları, günlük özetler, uyku, antrenmanlar, kişisel ortalamalar, toparlanma puanları, yapay zekâ isteği kayıtları, onay geçmişi ve gizlilik kaydı. İstisnalar şunlardır: bölüm 8’de anlatılan yedekler ve sunucu kayıtları, sayıları içeren ve hesapla bağlantısız tek kayıt, “Henüz doğrulayamadıklarımız” altında sayılan kopyalar ve yapay zekâ sağlayıcısının önceki isteklerden saklamış olabileceği her şey (bölüm 6); hesabınızı silmek bunlara ulaşamaz. Hesabınızı silmek Google’ın erişimini iptal etmez (önce Fitbit bağlantısını kesin), uygulamanın Apple Health okuma iznini kaldırmaz ve Bulfit’i Apple Hesabı ayarlarınızdaki Apple ile Giriş Yap listesinden çıkarmaz. Mevcut uygulama, silme işlemi başarısız olsa bile hata göstermeden oturumunuzu kapatır; emin olmak istiyorsanız bizden e-postayla doğrulama isteyin.
- Fitbit bağlantısını kesin: Profil › Bağlı cihazlar altında “Bağlantıyı kes”i seçin. İşlem bir onay adımı olmadan hemen gerçekleşir; ardından Fitbit hâlâ listeleniyorsa istek iletilmemiştir ve yeniden denemelisiniz. Bunun neyi silip neyi silmediği için bölüm 7’ye bakın.
- Apple Health erişimini durdurun: iPhone’da Ayarlar › Gizlilik ve Güvenlik › Sağlık bölümünde uygulamayı seçin ve artık okumasını istemediğiniz kategorileri kapatın. Bu, gelecekteki okumaları durdurur; bize daha önce gönderilmiş özetler hesabınızı silene kadar kalır ve değerleriniz için ve yapay zekâ açıksa yapay zekâ istekleri için kullanılmaya devam eder.
- Bulfit için Apple ile Giriş Yap kullanımını sonlandırın: Apple Hesabı ayarlarınızda, Apple ile Giriş Yap bölümünden. Bu, Bulfit hesabınızı veya sunucumuzdaki hiçbir veriyi silmez ve uygulama, mevcut oturumu sona erene kadar (giriş yaptıktan en geç 30 gün sonra) oturumu açık tutar. Verilerinizi silmek için önce “Hesabı ve tüm verileri sil”i kullanın.
- Uygulamayı silmek: uygulamayı iPhone’unuzdan silmek hesabınızı veya sunucumuzdaki hiçbir veriyi silmez ve oturum anahtarlarınız iPhone’un Anahtar Zinciri’nde kalabilir. Verilerinizi silmek için uygulamayı kaldırmadan önce “Hesabı ve tüm verileri sil”i kullanın veya bize yazın.
E-postayla hi@bulfit.net adresine yazarak verilerinizi görmeyi, düzeltilmesini veya silinmesini, bir kopyasını almayı, işlenmesinin kısıtlanmasını veya işlenmesine itiraz etmeyi, onayınızı geri almayı talep edebilir ya da bu politikayla ilgili her şeyi sorabilirsiniz. Hesabın size ait olduğunu doğrulamak için sizden bilgi isteyebiliriz. Başvurunuza en kısa sürede ve en geç 30 gün içinde, ücretsiz olarak yanıt veririz.
Yanıtımızdan memnun kalmazsanız Kişisel Verileri Koruma Kurumu’na veya Avrupa Ekonomik Alanı’nda yaşıyorsanız bulunduğunuz yerdeki veri koruma otoritesine şikâyette bulunabilirsiniz.
10. Reklam yok, satış yok, izleme yok
Bulfit reklam göstermez. Verilerinizi satmayız veya kiralamayız, reklam ya da pazarlama için kullanmayız. Uygulama analiz, reklam, çökme raporlama veya izleme kodu içermez ve reklam tanımlayıcısını kullanmaz; sunucumuz da üçüncü taraf bir analiz veya hata izleme hizmeti kullanmaz. Sizi başka şirketlerin uygulamaları veya web siteleri arasında izlemeyiz. Apple Health verileriniz hiçbir zaman reklam için kullanılmaz.
11. Çocuklar
Bulfit çocuklara yönelik değildir. Uygulama yaşınızı sormaz. Bir çocuğun hesap oluşturduğunu düşünüyorsanız bize yazın; hesabı sileriz.
12. Hukuki dayanak
Sağlık verileri, 6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) ve sizin için geçerli olduğu durumlarda AB Genel Veri Koruma Tüzüğü (GDPR) kapsamında özel nitelikli kişisel veridir.
- Apple Health ve Fitbit’ten gelen sağlık verileri: açık rızanıza dayanırız. Apple Health için mevcut test sürümü bu rızayı henüz ayrı bir adımda istemez. iPhone’unuzda verdiğiniz izne dayanır; bu izin ekranındaki metin verilerin telefonda işlendiğini söyler ve sunucumuza yapılan gönderimi anlatmaz (bu politikanın başındaki nota bakın). Fitbit için rızanızı Fitbit’i bağlayarak verirsiniz; bağlantı ekranları verilerin Türkiye’deki sunucumuzda saklandığını söylemez. Verilerinizin sunucumuza gönderilmesini beklemiyorduysanız hi@bulfit.net adresine yazın, verilerinizi sileriz; ya da hesabınızı kendiniz silin (bölüm 9). Rızanızı bölüm 9’da anlatıldığı gibi istediğiniz zaman geri alabilirsiniz. Geri almak yeni veri gelmesini durdurur. Daha önce saklanan veriler ise hesabınızı silene veya bizden e-postayla silinmesini isteyene kadar tutulur ve değerleriniz için ve yapay zekâ açıksa yapay zekâ istekleri için kullanılmaya devam eder.
- Yapay zekâ işleme: siz açana kadar kapalı kalan ayrı bir açık rıza. Mevcut test sürümündeki onay metni bölüm 6’da anlatılan değerlerin yalnızca bir kısmını sayar ve yazdığınız soruların gönderildiğini söylemez. Eksiksiz açıklama bölüm 6’dadır ve yapay zekâyı istediğiniz zaman kapatabilirsiniz.
- Hesap ve oturum kayıtları ile sunucu kayıtları: kaydolduğunuz hizmeti sunmak ve güvenliğini sağlamak için gereklidir.
- Yedekler sağlık verilerinizi de içerir. Veri kaybına karşı yaklaşık 15–16 gün tutulurlar ve içlerindeki sağlık verileri için, sağlık verilerinin kendisi için verdiğiniz açık rızaya dayanırız.
- Yapay zekâ isteği kayıtları, onay geçmişi ve gizlilik kaydı, hangi seçimleri yaptığınızı ve bunlara uyduğumuzu gösterebilmek için hesabınızı silene kadar tutulur.
Sunucumuz Türkiye’dedir. Bulfit’i Türkiye dışından kullanırsanız verileriniz bu sunucuya gönderilir ve orada saklanır; Türkiye dışındaki kullanıcılar için ek bir aktarım güvencesi oluşturmadık ve uygulama bu konuda ayrıca rıza istemez. Sağlık verilerinizi Apple’a veya Google’a göndermeyiz. Yapay zekâ sağlayıcısının istekleri Türkiye dışında işleyip işlemediğini bilmiyoruz (bölüm 6) ve onunla bu tür aktarımlara ilişkin bir sözleşmemiz yoktur; bu sizin için önemliyse yapay zekâyı kapalı tutun.
13. Bu politikadaki değişiklikler
Bulfit kapalı test aşamasındadır ve sık değişir. Bu politika değiştiğinde yeni sürümü bu sayfada yayımlar ve yürürlük tarihini güncelleriz. Bir değişiklik onayınızı gerektiriyorsa, değişiklik sizin için geçerli olmadan önce onayınızı isteriz.