Privacy
2026-10-02
Privacy and personal data
PiriMola is published and controlled by Sait Karalar, Türkiye. Contact [email protected].
We process email and password hashes for accounts; optional profile information and selected photos for profiles; answers, learning progress and group participation for learning; credit and entitlement records for balances and access; and app-generated device keys, session IP/client information and support messages for security and operations. A birth date is required for new registrations and is self-reported, not verified age. Processing supports the account/service contract, proportionate security interests and applicable legal obligations.
Public profiles and content follow your visibility settings. Group owners can view their groups’ member learning results. Profile photos and group covers require administrator approval. Private profiles limit profile access and new follows, but do not remove historical credit transfer names/amounts.
Main hosting is provided by Sanalhost in Türkiye. Transactional email is sent from the publisher’s self-managed mail server in Türkiye. Cloudflare handles traffic protection/distribution using international infrastructure and may process connection/IP information. Email providers process recipients and transactional message content. Relevant providers and lawful authorities may receive data as needed. Ask support for provider/transfer details. This Android closed-test build has no enabled advertising, third-party analytics, social-login or store-payment SDK. Camera access supports QR scanning; only photos you select are uploaded.
Use Profile → Close account with a six-digit email PIN and balance confirmation, or our deletion request page. Identity/profile/photos, device keys, personal learning history, follows, favorites, inbox and personal learning requests are erased. Owned groups are closed and transferred to an archive account; other members’ results and shared content remain. Financial/gift and legal acceptance records, including historical names/amounts and a non-public identifier, may be retained with restricted access for obligations and disputes. This is not a retained public profile. An email digest is retained to prevent repeated welcome/referral bonus claims. Sessions lose access immediately; temporary caches expire. PiriMola database backups are retained for at most 30 days; new application security/operational logs for at most 90 days. Provider records follow the provider’s applicable obligations. Financial and commercial documents follow their statutory periods by document type (generally 5 years for tax documents and 10 years for commercial books/documents). Necessary legal or dispute records are restricted and separate; these periods do not apply to all profile and learning data. Previously downloaded data cannot be remotely wiped from a disconnected device.
This release is intended for adults aged 18 and older. No birth date is requested for browsing without an account. During registration we request your birth date to check the minimum age of 18; it is sent to the server over HTTPS and stored in your private account profile. Your birth date is not shown on your public profile. This declaration is not identity or adulthood verification. Optional occupation information is visible only in your own profile editor, even when your profile is public. You may leave it blank or clear it. It does not automatically grant content-audience membership.
Learning profiles within an account store a profile name, birth date, optional gender and separate learning history. Birth date and gender are excluded from profile-picker cards and exact member-number invitation lookup. Extra profiles do not have separate email accounts, balances or subscriptions. Group participation and learning history are profile-specific.
Returning from an extra profile to the main profile is verified against the main profile PIN on the server; its PIN verifier is not kept on the device. Optional profile-entry PINs are independent for each profile and are verified through the API over HTTPS; the server stores stretched verifiers and attempt/lock metadata, not plaintext PINs. These controls do not establish verified age, adulthood or legal guardianship. Account deletion also removes its owned learning profiles and their personal learning history.
You may ask about processing, recipients, correction, deletion and applicable objections/remedies through support. Ownership is verified; never email a password or verification PIN.
Reports and blocks
We store report reasons, details, reporting account, target content/user and moderation decisions for safety operations. Reporter identity is not disclosed to the reported user. Blocks apply to your account and its learning profiles. Closing your account removes block records and clears the account link and free-text details from your reports; targets and moderation decisions may remain for safety auditing. Do not include passwords or unnecessary personal information in reports. The main profile PIN is stored as a one-way verifier on the server and works across devices.