TEBHOSTEBHOS⬇Download
PremiumPartnersBlogHelp
🌐TR·EN
Sign inOpen TEBHOS
DownloadPremiumPartnersBlogHelpSign inTürkçeOpen TEBHOS

Privacy Policy

How TEBHOS handles personal data, what we do not do with it, and the controls and rights you have.

Last updated: August 14, 2026

On this page

  • 1. Data controller
  • 2. What we collect — and what we don't
  • 3. How we use your data — and how we don't
  • 4. KVKK: legal bases, your rights and how to apply
  • 5. Who we share your data with — and who we don't
  • 6. Where your data lives: the truth about international transfers
  • 7. Automated content safety
  • 8. Retention periods
  • 9. Security
  • 10. Your controls
  • 11. Children's privacy
  • 12. Cookies and similar technologies
  • 13. Third-party services and links
  • 14. Official requests
  • 15. Changes to this policy
  • 16. Contact

Note: The Turkish version of this document is legally binding; this English translation is provided for convenience only. If the two versions conflict, the Turkish text prevails.

The short version: TEBHOS is a chat service developed in Türkiye, and this policy explains how we handle your data. It is part of our Terms of Service, so you can hold us to it.

  • We do not sell, rent, or license your personal data. We have no advertising partners and no dealings with data brokers. Our revenue comes from TEBHOS Pro, our optional premium subscription.
  • AI does not read what you share on TEBHOS. We run no AI or LLM inference over your messages, files, or voice and video calls, and none of your content is used to train or fine-tune AI models. The only automated content check is a local image classifier on our own servers that helps respect explicit-content preferences.
  • We do not track you around the web: no tracking cookies, no analytics SDKs, no browser fingerprinting.
  • You can request a copy of your data, delete your messages, and close your account whenever you like.
  • Your data lives primarily on servers in Germany (Frankfurt); Section 6 explains honestly what that means.

1. Data controller

The TEBHOS team operating TEBHOS is the data controller of your personal data under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"): we decide which data is processed and for what purpose, and this policy also fulfils our duty to inform under Article 10 of the KVKK.

  • Data controller: TEBHOS
  • Contact (all requests, including privacy and data protection): [email protected]

2. What we collect — and what we don't

2.1 What you give us

Account data. Creating an account requires an email address, username, password and date of birth (for the age check). Everything else, such as your avatar and about-me text, is optional. Your password is stored as an Argon2 hash — no one, including us, can read your plain-text password.

Content. What you do on TEBHOS: messages, files, images, voice/video calls and stage-room participation, server data, reactions and your profile details. All of it belongs to you (see the Terms of Service, Section 4).

Support correspondence. When you email us, the content of your message and any attachments are processed to resolve your request.

Payments. Payments are processed not by us but by Polar as merchant of record. When you buy TEBHOS Pro or another paid product, we receive only what is needed to record and manage the purchase: transaction status, product and timing information. Your card number never reaches us and is never stored by us.

We do not ask you for special categories of personal data such as health, religion, ethnic origin or sexual orientation. If you choose to share such information in a message or on your profile, it is not used for profiling, targeting or different treatment.

2.2 What is collected automatically

Technical data: the IP address you connect from, browser type and version, operating system, device type and similar details.

Security and operational logs: sign-in attempts and authentication events, account-setting changes, rate-limit triggers, API and system errors, and spam/abuse signals.

Approximate location from IP: approximate country/region information is derived from your IP address using a local geo database running on our own servers; no request is sent to any third party for this lookup. This is used for security and regional functionality (such as local currency on the payment page).

TEBHOS has no ad trackers, third-party analytics SDKs, browser fingerprinting or cross-site tracking pixels. We do not build behavioural profiles and we do not track which sites you visit before or after TEBHOS.

2.3 What comes from other sources

Other users generate data about your account when they interact with you: someone mentioning you or messaging you involves your username, the content of the interaction and timing information.

Service providers send limited operational information: our email infrastructure reports delivery status, and Polar reports payment status.

3. How we use your data — and how we don't

What we use it for

  • Operating TEBHOS: managing your account, delivering your messages to the right recipients, making features work end to end.
  • Security and abuse prevention: preventing unauthorised access; investigating abuse, fraud and spam; enforcing the Terms of Service and the Community Guidelines.
  • Service communication: security alerts, service updates and the administrative emails your account needs to function.
  • Payments: recording purchases and managing your subscription when you buy a paid service.
  • Maintenance and improvement: aggregate metrics such as error rates and feature-usage counts — without reading message or file content.
  • Legal obligations: meeting legal requirements, responding to valid official requests, and protecting the safety and rights of our users, the public and TEBHOS.

What we never use it for

Your messages, files, calls and everything else you create on TEBHOS are never used for:

  • advertising — targeted or otherwise
  • training, fine-tuning or evaluating AI or machine-learning models
  • profiling for advertising, marketing or behavioural analysis
  • sale, rental or licensing to any third party for their own purposes
  • mining or aggregation for commercial gain beyond operating the service

4. KVKK: legal bases, your rights and how to apply

4.1 Processing grounds (KVKK Art. 5)

Your personal data is processed on the following legal grounds under Article 5 of the KVKK:

  • Formation and performance of a contract (Art. 5/2-c): opening your account, delivering your messages, providing the services you purchase, and giving support.
  • Legitimate interest (Art. 5/2-f): service security, preventing fraud and abuse, and the reliability and performance of the service — provided your fundamental rights and freedoms are not harmed.
  • Legal obligation (Art. 5/2-ç): obligations arising from tax and other legislation, and responses to valid requests from competent authorities.
  • Explicit consent (Art. 5/1): relied on only in limited cases not covered above (e.g. optional marketing messages); you can withdraw your consent at any time.

4.2 Your rights (KVKK Art. 11)

Under Article 11 of the KVKK you have the right to:

  • learn whether your personal data is processed
  • request information if it has been processed
  • learn the purpose of processing and whether the data is used in line with it
  • know the third parties to whom your data is transferred, in Türkiye or abroad
  • request correction if it is incomplete or inaccurate
  • request deletion or destruction under the conditions in Article 7 of the KVKK
  • request that corrections and deletions be notified to third parties who received the data
  • object to a result that is to your detriment arising exclusively from automated analysis of your data
  • claim compensation if you suffer damage due to unlawful processing

4.3 How to apply

To exercise these rights, write to [email protected] from the email address registered to your account so we can verify your identity. Applications are concluded free of charge within 30 days at the latest, under Article 13 of the KVKK; if the process involves an additional cost, the fee in the Personal Data Protection Board's tariff may be requested.

If your application is rejected, the response is insufficient, or no response is given in time, you retain the right to lodge a complaint with the Personal Data Protection Board (kvkk.gov.tr).

5. Who we share your data with — and who we don't

Your personal data is never sold, rented or traded to any third party. Sharing is limited to the situations below.

5.1 Sharing you initiate

Your messages go to their recipients, your server posts are visible to members, and your profile is visible to the extent you choose. Shared content can be saved or re-shared outside TEBHOS by other users; as with any chat app, be mindful of what you share and with whom.

5.2 Our service providers (data processors)

A small number of selected providers process data on our behalf so the service can run:

Provider Role Data processed
Vultr Server hosting (Frankfurt, Germany) All service data stored on our servers
Cloudflare Domain/DNS, CDN and security layer; R2 object storage Site traffic (as security layer), uploaded media files and encrypted backups (R2)
Polar Payments (merchant of record) Payment and invoice details; transaction status is returned to us
Resend Transactional email (verification, password reset, etc.) Your email address and the content of the message sent
hCaptcha Bot protection at sign-up/sign-in Browser/interaction signals during verification (also subject to its own policy)

Our voice and video infrastructure (LiveKit software) runs on our own servers — your audio/video traffic does not go to a third-party service. GIF search queries are proxied through our servers; our error-tracking and metrics infrastructure also runs on servers under our own control, and no data is sent to a third-party tracking service.

hCaptcha may also process data on its own behalf while you interact directly with its verification screen; in those interactions hCaptcha's privacy policy applies alongside ours. If this list changes, this page is updated and important changes are recorded in the Changelog.

5.3 When law or safety requires it

Disclosure outside TEBHOS happens only to: comply with a valid legal obligation or a request from a competent authority; enforce the Terms of Service; protect the safety, rights or property of users, the public or TEBHOS; and detect and prevent fraud, security or technical issues. Where legally possible and where it creates no safety risk, we try to inform the affected user before disclosing data due to a request.

6. Where your data lives: the truth about international transfers

Our main servers are in Vultr's Frankfurt (Germany) data centre: your account details, messages and server data are stored there. Uploaded media files and encrypted database backups are kept in Cloudflare R2 object storage; site traffic passes through Cloudflare's global network. Payments are processed on Polar's infrastructure and transactional emails on Resend's.

What this plainly means: your personal data is hosted abroad (mostly in the European Union), and using TEBHOS technically requires this transfer. Article 9 of the KVKK provides specific mechanisms for transfers abroad (adequacy decisions, appropriate safeguards or explicit consent); our work towards full compliance with these mechanisms continues alongside our incorporation process. In the meantime our honest commitment is this: we keep data to a minimum, we do not move it beyond the providers listed here, and we encrypt it in transit and at rest. If our hosting setup changes, this section is updated.

7. Automated content safety

We do not run AI or large language models over your messages; no model is trained on your content. The limited automated safety measures we do run are:

An explicit-content classifier. We score the likelihood that uploaded images and video frames contain explicit content using a small, open-source image classifier (OpenNSFW2) running on our own servers. It is not generative AI: all it does is return a probability value; it cannot read text, keeps no memory and does not learn from what it sees. No media is sent to any third party for this purpose, and the results are used only for age-restricted content flagging.

Other automated measures. Narrow systems working on patterns such as message frequency, link structure, account age and IP reputation block spam, phishing links and coordinated abuse. They do not read message content and feed no advertising or profiling.

Human review. Authorised staff may look at specific content only when needed to review a user report, enforce the rules or respond to a serious safety situation; access is logged.

8. Retention periods

Your personal data is kept only as long as needed for the purposes in this policy, legal obligations and the resolution of disputes.

Data Retention
Account details For as long as your account is active
Your messages and content Unless you delete them, for as long as your account is active
Deleted account 14-day grace period; then removed from active systems
Deleted messages and records Removed from active systems quickly; at most 30 days in encrypted backups
Deleted media attachments Removed from active storage; not included in database backups
Database backups Taken daily, encrypted end to end (keys held only by us), kept for 30 days
Security and operational logs Limited period; deleted on a regular cycle, kept longer only during an active security investigation or legal obligation
Purchase records For the period required by applicable legislation (including tax); card details are never stored

9. Security

We apply technical and administrative measures to protect your personal data against loss, alteration, disclosure and unauthorised access:

  • standard encryption in transit (TLS)
  • encryption at rest on servers and in backups; backups are encrypted with keys held only by us
  • password hashing with Argon2 (no plain-text passwords stored)
  • security updates, patch management and infrastructure hardening
  • rate limiting and abuse/attack protections
  • access to user data limited to authorised people with a demonstrated need

An honest note about encryption. Nothing on TEBHOS is currently end-to-end encrypted. Your data is encrypted between your device and our servers and on our servers; but because the service needs server-side processing to work, message content is technically accessible to our systems while being processed. Put plainly: you are trusting TEBHOS to protect this traffic.

Responsible disclosure. If you find a security vulnerability, please follow the process on our Security page.

9.1 Data breaches

In the event of a personal data breach we investigate and take the necessary corrective steps. In line with the KVKK and the decisions of the Personal Data Protection Board, breaches are reported to the Board as soon as possible and within 72 hours at the latest of becoming known, and affected individuals are informed within the shortest reasonable time. Notifications explain what happened, which data may have been affected and what you can do to protect yourself.

10. Your controls

Account deletion. You can delete your account from inside the app (User Settings → account section); if you sign in within the 14-day grace period, the deletion is cancelled. Details are in the Terms of Service, Section 9.

Message deletion. You can delete individual messages from inside the app; deleting a message also deletes its attachments.

Requests by email. To have specific data deleted or corrected rather than deleting everything, write to [email protected] from the email address registered to your account and state clearly what you want us to do. You can also request a copy of your personal data (under KVKK Art. 11) the same way.

11. Children's privacy

You must be at least 13 to use TEBHOS; a date-of-birth declaration is taken at registration. We do not knowingly collect personal data from children under 13; if we identify such an account we delete it. If you believe a child in your care is using TEBHOS without permission, write to [email protected] to request deletion of the account and its data. Since no one on TEBHOS is ad-profiled, children are not either.

12. Cookies and similar technologies

The short version: TEBHOS does not use cookies for your session, and there are no advertising or analytics cookies at all. The only third parties involved are hCaptcha for bot protection and Cloudflare in the infrastructure.

12.1 Our approach

Advertising and tracking cookies are used nowhere on TEBHOS. Operational logs are server-side and are not used for advertising or cross-site profiling.

12.2 The app does not use cookies

The TEBHOS app does not use cookies for authentication: your session keys are kept in the browser's local storage and sent with requests in an authorisation header. Preferences such as theme and volume also stay in local storage on your device. Our marketing site (including this page) sets no cookies of its own and runs no analytics scripts. The only exception is a single functional cookie named locale, set only if you explicitly switch the site language, which stores your language choice for up to one year; it identifies no one and tracks nothing.

12.3 Third-party cookies

  • hCaptcha: during bot-protection verification at sign-up and sign-in, it may use its own cookies for bot detection; that use is subject to hCaptcha's privacy policy.
  • Cloudflare: as the infrastructure layer protecting the site, it may use technical cookies for security purposes.

12.4 Managing cookies

You can manage cookies in your browser settings. Because the third-party cookies we use are tied to security functions, blocking them may affect the sign-up/sign-in flow. If a non-essential cookie is ever added, this section will be updated and your prior consent obtained where required.

13. Third-party services and links

When rich previews are generated for links shared in messages, the target page is fetched by our servers; external media is served through our signed media proxy. GIF searches are proxied server-side — your IP address and device details do not go to the GIF provider. When you click an external link in a message, the destination site's own privacy policy applies.

14. Official requests

Every official request for user data is reviewed carefully; the privacy and safety of those affected is the first priority. Requests should be sent to [email protected] and must state the requesting authority, the legal basis and the scope of the data sought. Overly broad or legally invalid requests may be narrowed or rejected. Where legally possible, we try to inform the affected user before disclosure.

15. Changes to this policy

This policy may be updated to reflect changes in our practices, services or legal obligations. Important changes are announced at least 30 days in advance by email, in-app notice or an announcement on our website, and the update date at the top of the page is refreshed. Records are kept in the Changelog. If you do not accept the updated policy, you can always delete your messages and your account.

16. Contact

Privacy, data protection and general support: [email protected]

For requests about your account, write from the email address registered to your account where possible, so we can verify your identity.

Related policies

Terms of ServiceThe agreement between you and TEBHOS, written to explain your rights and responsibilities clearly.Community GuidelinesClear standards for using TEBHOS, protecting others, and keeping communities safe.SecurityHow to report security issues, what is in scope, and how safe harbor works.Company InformationLegal details for TEBHOS, including how we make money and how to contact us.ChangelogA record of significant changes to our Terms of Service, Privacy Policy, and Community Guidelines.
TEBHOSTEBHOS

TEBHOS is a free instant messaging and VoIP chat app built for friends, groups, and communities.

✉ [email protected]

Product

  • Download
  • Premium
  • Discovery
  • Partners

Resources

  • Blog
  • Help center
  • Changelog
  • Security

Legal

  • Terms of Service
  • Privacy Policy
  • Community Guidelines
  • Company Information

© TEBHOS

🌐Türkçe·English

Made in Türkiye 🇹🇷

English translations are provided for convenience; for legal documents the Turkish version is binding.