Your data, clearly.
What we store, how we use it, and how you stay in control. Effective: 26 September 2026.
01. Data controller and scope
Data controller under Turkish Personal Data Protection Law No. 6698 (“KVKK”): WhatOTP, —, bayyazilimcioffical@gmail.com (“WhatOTP”). This notice is provided under Article 10 of the KVKK and the Communiqué on the Obligation to Inform.
This notice covers personal data processed through the website, dashboard, Playground, API, support and account security forms. Processing carried out by providers, Google, GitHub and Cloudflare within their own services is governed by their own privacy policies.
02. Personal data we process
Identity: your name and the user ID given by Google/GitHub when you sign in with them.
Contact: your email address, email verification status and notification preference.
Account and transaction: your role, account status, language preference, registration date, linked social accounts, token quota and usage, packages, activation codes you redeemed, API key names, prefixes, model and expiry restrictions and last-used times, dashboard notifications, and support tickets and correspondence.
Security: your hashed (bcrypt) password, hashed session and API key tokens, browser/device information (user-agent) for your sessions, a keyed hash derived from your IP address's network block, a hash of your random device identifier cookie, bot-check results, abuse flags and administrator audit logs.
API usage records: request ID, model, status code, input and output token counts, estimate flag, duration, timestamp, encrypted API key ID and network block hash.
Account access requests: the email address and message you enter in the public account security form when you cannot access your account.
WhatOTP does not knowingly process special categories of personal data and does not collect data for marketing, advertising or profiling.
03. Inputs and model responses
Messages you send to the API or Playground and model responses are held in memory only to process the request, forwarded through WhatOTP's model gateway to the provider that generates the response, and are not written to WhatOTP's database. To diagnose invalid requests, server logs record only the name of the invalid field and the reason, never content.
Providers may retain inputs and responses under their own terms to monitor abuse or to provide or improve their services; WhatOTP cannot control this. Do not include special categories of data, other people's personal data, passwords, card details or confidential business information in your inputs. If your inputs contain third parties' personal data, you are the data controller for that data.
Responses may be processed automatically before delivery (format conversion, replacing request ID and model name, replacing some infrastructure and provider names with “WhatOTP”). Requests forwarded to providers carry your account's random user ID instead of your identity; your name and email are not sent to providers.
04. How data is collected
Personal data is collected electronically, by partly or fully automated means, through the registration, sign-in, settings, support and account security forms, Google/GitHub sign-in, API requests, the Playground, session and security cookies, and the bot check.
05. Purposes
Opening, verifying and managing your account; authentication and session management; providing the API and Playground; forwarding requests to providers; managing token quotas, packages and activation codes; providing usage reports and notifications; answering support requests.
Ensuring service and information security; preventing bot registrations, multiple accounts, quota abuse, fraud and unauthorised access; enforcing rate and concurrency limits; detecting errors and monitoring performance and outages; backups and disaster recovery.
Complying with legal obligations, responding to requests from competent authorities, and establishing, exercising and defending legal claims.
06. Legal grounds
Your personal data is processed on the following grounds in Article 5 of the KVKK: necessity for the conclusion or performance of a contract (Art. 5/2-c) — account, API, quota, packages, support; compliance with a legal obligation (Art. 5/2-ç); establishing, exercising or defending a right (Art. 5/2-e); and legitimate interest, provided it does not harm your fundamental rights and freedoms (Art. 5/2-f) — security, abuse prevention, service improvement and monitoring.
Processing based solely on explicit consent, such as preference cookies, is not carried out without your consent, which you may withdraw at any time.
07. Recipients
Your personal data may be shared, only as needed for the relevant purpose, with: server and infrastructure hosting providers; Cloudflare (Turnstile) for bot checks; Google and GitHub for social sign-in; an email delivery provider for account and notification emails; AI model providers receiving API inputs (request content and a random user ID only, not your identity); legal advisers and auditors; and legally authorised public authorities and courts.
In a merger, acquisition, restructuring or asset transfer, data may be transferred to the acquiring party with the safeguards in this notice. Your personal data is not sold, rented or shared for advertising.
08. International transfers
Cloudflare, Google, GitHub, the email delivery provider, AI providers and some infrastructure services may use servers outside Türkiye (mainly in the United States and the European Union). These transfers are made in accordance with Article 9 of the KVKK: with appropriate safeguards such as standard contracts where possible, or otherwise as occasional transfers necessary for concluding or performing the contract.
By using the Service you acknowledge that API inputs are forwarded to providers abroad to generate responses; if you do not want this, do not send inputs containing personal data to the API.
09. Abuse prevention and automated processing
To prevent free-quota abuse, keyed hashes are derived from your IP address's network block (/64 for IPv6) and your device identifier cookie at registration and on API requests. Raw IP addresses are not stored in the database. If many accounts are created or used from the same network or device in a short period, new registrations may be rejected automatically, or API access may be stopped and flagged for administrator review. Disposable email domains and domains that cannot receive email are rejected automatically.
For repeat-signup checks, keyed hashes of your normalised signup email and linked Google/GitHub identities are kept even after your account is deleted. They contain no raw email or identity and cannot be reversed.
If you believe an outcome of this processing is against you, you may object under KVKK Art. 11/1-g; your request will be reviewed by an administrator.
10. Retention periods
Account, profile, API key, quota, package, notification, usage record and support data are kept until your account is deleted. When you delete it, they are removed from the database; records of activation codes you used are kept with the link to your account removed.
Sessions last 30 days; email verification, email change and password reset links are valid for 30 minutes; Google/GitHub sign-in state is valid for 10 minutes. Registrations not verified within 24 hours may be deleted. Rate-limit counters are kept as hashes only for their time window. Queued emails are deleted once sent.
Account access requests are kept for a reasonable time after resolution for possible disputes and then deleted. Administrator audit logs are kept separately for security and accountability. Keyed hashes kept for repeat-signup checks are retained as long as the abuse-prevention purpose continues.
Daily database backups are taken and the latest 14 are kept; deleted data leaves the backups within 14 days. Where a statutory retention obligation or an ongoing dispute exists, the relevant data may be kept for that period. Data whose period has expired is deleted in line with the Turkish Regulation on the Deletion, Destruction or Anonymisation of Personal Data.
11. Security measures
The following technical and administrative measures under KVKK Art. 12 protect your data: encrypted communication with HTTPS and HSTS; passwords hashed with bcrypt; sessions, API keys and activation codes stored only as hashes; provider credentials and key IDs in usage records encrypted with AES-GCM; role-based authorisation and administrator audit logs; rate limits and bot checks; integrity-checked daily backups; servers with restricted access.
No method is completely secure. If personal data is obtained unlawfully by others, the data subjects and the Personal Data Protection Board will be notified as soon as possible under KVKK Art. 12/5.
12. Children's data
The Service is not intended for anyone under 18, and we do not knowingly process data of people under 18. If you learn that someone under 18 has opened an account, tell us; the account will be closed and the data deleted.
13. Manage your data
In the dashboard you can update your name, language and notification email preference, change your email with verification, link Google/GitHub accounts, view and end sessions, revoke API keys, export usage records as CSV and delete a standard user account.
14. Your rights under the KVKK
Under Article 11 of the KVKK you have the right to: a) learn whether your personal data is processed, b) request information if it is, c) learn the purpose of processing and whether data is used accordingly, d) know third parties in Türkiye or abroad to whom it is transferred, e) request correction of incomplete or inaccurate data, f) request deletion or destruction under the conditions of KVKK Art. 7, g) request that third parties be notified of actions under (e) and (f), h) object to a result against you arising exclusively from automated analysis, and i) claim compensation for damage caused by unlawful processing.
15. How to apply
To exercise your rights, under the Communiqué on the Procedures and Principles of Application to the Data Controller, you can send your application in writing to the data controller's address, via registered electronic mail (KEP), with a secure electronic or mobile signature, or from the email address registered to your WhatOTP account to bayyazilimcioffical@gmail.com. The application must include your full name, signature for written applications, Turkish ID number (for foreigners, nationality and passport/ID number), address or email for notifications, and your request.
Applications are resolved free of charge within 30 days at the latest; if the action requires additional cost, the fee in the Board's tariff may be charged. If your application is rejected, you find the answer insufficient, or no answer is given in time, you may complain to the Personal Data Protection Board within 30 days of learning the answer and in any case within 60 days of the application date. We may ask for additional information to verify your identity.
16. Users outside Türkiye
The Service is operated from Türkiye. If you are in the European Economic Area or the United Kingdom, in addition to the rights above you may exercise the rights of access, rectification, erasure, restriction, data portability and objection under applicable data protection law using the same method, and complain to your local supervisory authority. Our legal bases are performance of a contract, legal obligation, legitimate interest and, where needed, consent.
17. Changes
This notice may be updated to reflect changes to the Service or the law. The current text is published on this page with its effective date; material changes are announced on the site or by email.
Contact: bayyazilimcioffical@gmail.com · Dashboard support ↗