Privacy policy
Last updated: 14 August 2026 · Version 2026-08-14 · Türkçe
This is a translation. The Turkish text at mombridge.app/gizlilik is the original and is the one that governs; where the two differ, the Turkish is what applies.
This page says what is processed when you use MomBridge, where it sits, who can see it and how long it stays. We write down what the product actually does: every clause below is the behaviour of the app and the server today. When something changes, this page and the date above it change.
In short: no advertising, no sale of data, no analytics software of our own built into the product. The servers are in the European Union. The document sent for motherhood verification is deleted the moment the decision is made.
1. Who is responsible
Merve Nur KÖSE — the individual who runs MomBridge. There is no company behind it: the person who decides what happens to the data and the person who answers for it are the same person.
One address for everything: destek@mombridge.app. If you live in Türkiye, the KVKK disclosure notice sets out your rights under Law No. 6698 and how to exercise them.
2. What is processed
Only what the product needs to work. No field is collected because it "might be useful later".
2.1 What you give
- Account: email address, username, display name, an irreversible digest of your password (bcrypt), language preference.
- Profile: profile photograph, short introduction, Instagram username if you write one.
- Approximate location: country, city, district and, if you want, neighbourhood — as much as you type. No street address is asked for and no GPS location is read. The "show my city" switch is in Settings › Privacy and notifications and can be turned off at any time.
- About your child: your child's date of birth and, if you write it, sex; or the week of your pregnancy. Age-appropriate suggestions and matching with mothers at the same stage are built on this. You do not have to write your child's name — you can leave it blank. If you write it, it appears on your profile and members who look at your profile can read it.
- Motherhood verification: the document you upload (a selfie or a photograph of a document) and your note if you write one. See section 5: this document is treated differently from everything else.
- Content: posts, comments, messages, photographs, voice messages, stories, polls, meet-ups, rooms and listings — and your reactions to them.
- Reports and appeals: the content you report, the reason you choose and the explanation you write.
2.2 What use produces
- Session and device: the random identifier the device gives itself, session tokens, app version, operating system.
- Connection logs: IP address, the time of a request and its result. Kept for security and abuse review.
- State inside the product: last seen, read receipts, which rooms you are in, level and badges.
- Browser notification permission: the address your browser issues when you turn notifications on, and two encryption keys. They can only be used to send a notification to your browser.
2.3 What is not collected
- Advertising identifiers, cookie-based tracking, analytics software of our own. The sign-in providers' own development kits are present in the app and can take their own measurements; we do not read those.
- Your contacts, your call history, your photo library (only the file you choose).
- Precise (GPS) location. The product asks for a location permission nowhere.
- Payment card details. If you ever buy something, the store (Apple/Google) handles the payment; card details never reach us.
3. Why it is processed
| Purpose | Legal basis |
|---|---|
| Opening an account, keeping a session, providing the core features | Formation and performance of a contract |
| Motherhood verification — deciding who the community is open to | Explicit consent (the document may contain special-category data) |
| Safety: countering abuse, fake accounts, harassment and fraud | Legitimate interest — the safety of members |
| Resolving reports and appeals | Legitimate interest and legal obligation |
| Suggesting mothers, rooms and meet-ups near you | Performance of a contract (this is the product itself) |
| Translating messages and posts into the language you read | Performance of a contract |
| Sending notifications | Explicit consent (browser / operating system permission) |
| Statutory retention and answering official requests | Legal obligation |
4. Who can see it
- Other members: your profile, your posts, your comments and your messages in the rooms you have joined. What you write in a room is visible to everybody in that room.
- Direct messages: only the person you are writing to. They sit on an encrypted disk on the server; there is no end-to-end encryption — technically, the server can read them. We write this down because there are products that imply otherwise.
- The moderation team: only when needed — reported content, a verification application, an appeal. Who can touch what depends on their permissions, and every action is written to an audit log.
- Somebody with no account: a person who installs the app
and taps "Browse as a guest", or who opens a shared link, can see the
following. This is deliberate: a woman cannot decide whether sending a
verification photograph is worth it without seeing what is inside.
- The text of posts and comments, and the like and comment counts. She cannot see who wrote them: no name, username, photograph, city or district is sent; the author appears as "Anonymous mom" and the profile cannot be opened. The badge saying the writing came from a verified mother stays, because it identifies nobody.
- Photographs on posts are not sent. Neither are the people tagged in a photograph or mentioned in a comment.
- She cannot ask for a particular person's posting history or the photographs she is tagged in; those require an account.
- A shared meet-up link opens the meet-up itself: its name, description, place and time. The organiser's identity and the photographs in the album are not sent. The list of meet-ups is closed entirely to somebody with no account — who met where this week is not something to hand to whoever types the address.
- A shared profile link opens a narrow profile: display name, username, profile photograph, the "about" text and level. City, district, information about children and posts are not sent. A link has to open onto something; it does not have to open onto a city, a district and a child's age.
5. The motherhood verification document
This is the most sensitive data in the product and it is treated as such:
- The document is written to a separate directory the media server never looks at; even somebody who knows the address cannot open it.
- Only a moderator with the verification permission can open it, with a verified session.
- It is deleted the moment the decision is made — approved or refused alike. What remains is the decision, its date and who made it.
- It does not survive a decision never being made either: where more information is asked for and no new document is sent, or an application is forgotten in review, the document is deleted automatically after 90 days at the latest. Your account stays where it is; if you want to apply again, a new photograph is asked for.
- It is transferred nowhere and is not used to train any model.
6. Who it is shared with
We do not sell data and we share it with nobody for advertising. These are the services the product uses to work:
| Service | What for | Where |
|---|---|---|
| Hostinger International | Server and database hosting | Lithuania (EU) |
| Google (Gemini API) | Where people in a conversation read different languages, the text to be translated is sent | EU/US |
| Klipy | GIF and sticker search; the images load directly from their servers, so they see your IP address | EU/US |
| Mozilla · Google (browser notifications) | Carrying the notification. In a browser the content is encrypted with your browser's own key; the carrier cannot read it | Global |
| Apple (iPhone notifications) | Carrying the notification. There is no such encryption here: the title and the line of the notification go to Apple in the clear, which means a message's preview can be read by Apple. Turn notifications off and this stops too | Global |
| Apple · Google (optional sign-in) | Authentication, if you use "Sign in with Apple" or "Sign in with Google" | Global |
Beyond these, sharing happens in two cases only: a properly made request under applicable law, and a threat to somebody's life.
7. Transfers abroad
The servers are in the EU (Lithuania); the controller is in Türkiye. Some of the services above can take data outside the EU. Those transfers are made under standard contractual clauses and the providers' own undertakings; for transfers from Türkiye, the conditions in Article 9 of the KVKK are observed.
8. How long it is kept
| Data | Period |
|---|---|
| Verification document | Until the decision; deleted with it |
| Account and profile | As long as the account is open |
| Posts, comments, messages | Until you delete them or close your account |
| Stories | Become invisible automatically after 24 hours |
| Connection and security logs | Up to 90 days |
| Moderation decisions and the audit log | 3 years |
| Records subject to statutory retention | The period the relevant legislation requires |
9. Deleting your account
You can delete your account from inside the app: Settings › Account › Delete my account. You do not have to write to us, fill in a form or wait for an approval — it starts the moment you type your username and confirm.
- Your profile and your content become invisible in the app at once, your open sessions end and the account cannot be signed in to.
- If you sign in again within 30 days your account comes back as it was. That period exists only so you can change your mind.
- When the thirty days are up the account is deleted automatically and permanently. Your row is removed from the database; your posts, your meet-ups and the rooms you opened go with it. The photographs you uploaded are deleted from disk. You do not have to ask for any of this separately.
- What remains is only what there is a statutory obligation to keep: moderation decisions and the audit log, in a form that cannot be associated with your identity, for the period in the table above.
If something goes wrong, or you want it deleted sooner, you can write to destek@mombridge.app. That is not a requirement, only another way.
10. Your rights
You have the right to access, correct, delete, restrict the processing of, object to and port your personal data. For processing based on explicit consent you may withdraw that consent at any time — for the verification document, that means your account returns to being unverified.
One address for applications: destek@mombridge.app. We answer within 30 days at the latest. For the detailed procedure in Türkiye, see the KVKK disclosure notice.
11. Children
MomBridge is not open to anybody under 18. The product processes only the date of birth and, if it is written, the sex of members' children; the mother enters this herself and it is used for nothing but age-appropriate suggestions. Whether to share a photograph of your child is entirely your decision — we suggest thinking twice before you do.
12. Security
- All traffic is encrypted with TLS. Passwords are stored with bcrypt and are held in plain text nowhere.
- Session tokens live in the device's secure store (iOS Keychain, Android Keystore); in a browser, in the browser's own store.
- Verification documents are in a separate directory that is not served.
- Access to the administration screens depends on role and permission; every action is written to an audit log.
No system is flawless. If you notice a security problem, write to destek@mombridge.app; thank you, and we will come back to you quickly.
13. Cookies and similar technologies
This website uses no cookies; there is no script here for advertising or tracking. When you use the app from a browser, your session and your language preference are kept in the browser's own store (localStorage) — that is required for the product to work and can be cleared from the browser's settings.
14. Changes
When this text changes, the date and the version number are updated; for a material change we also say so inside the app and, where it is needed, ask for consent again.