Hanko
Privacy Policy
Last updated 9 September 2026
Hanko is built so that the person who makes it cannot read what you write. This page explains exactly what that means, where the limits are, and every outside company that receives anything at all.
Who is responsible
Hanko is made by Halil Akgündüz, an individual developer based in Türkiye — the data controller (veri sorumlusu) for the purposes of the Turkish Personal Data Protection Law (KVKK, Law No. 6698) and, for users in the UK and EU, the GDPR.
Contact: privacy@hankoaffirmations.app
The short version
- Your entries never leave your device. They are stored in a database on your phone. There is no sync, and no copy of them on any server.
- An account is optional. The app works completely without one, and you are never asked to sign in to write anything.
- If you do create an account, all it currently holds is your identity — an email address, or the fact that you signed in with Google. It does not hold your entries.
- Payments are handled by the App Store and Google Play. We never see your card.
- We do use a small number of third-party services for subscriptions, the paywall, and usage analytics. Every one of them is named below, with what it receives.
What stays on your device, and only there
Everything that makes the app work is stored locally, in an SQLite database on your phone: your entries, the topics you keep in rotation, feeling tags, any photos you attach, your practice-ring progress, markers, and your reminder settings.
None of it is uploaded. Not when you sign in, not in the background, not ever — there is currently no code in Hanko that sends an entry anywhere.
The consequence is worth being blunt about: if you lose your phone and have not exported a backup, your entries are gone. We cannot recover them, because we never had them. See Backups.
Accounts (optional)
Hanko can create an account for you through Supabase, our authentication provider. You can sign up with an email address and password, or with Google.
What Supabase stores: your email address, an internal user ID, sign-in timestamps, and — if you use Google — the identity Google returns to confirm it is you. If email confirmation is enabled, Supabase sends you a confirmation email.
What it does not store: anything you write in Hanko.
Your login session is kept in your device's secure hardware store — the iOS Keychain or the Android Keystore — not in ordinary app storage.
Right now, having an account does not unlock anything. It exists so that features like cross-device sync can be added later. If we ever add sync, that will be an opt-in choice with its own explanation, and this page will be updated before it ships.
Backups
Backup is manual. Profile → Export backup writes a file containing your entries and hands it to your phone's share sheet, so you choose where it goes — Files, iCloud Drive, Google Drive, email to yourself, anywhere. Restore from backup reads that file back on a new device.
The file goes straight from your device to wherever you send it. It does not pass through us. Once it is in another company's storage, that company's terms apply to it, not ours.
Photos
If you attach a photo to an entry, Hanko asks your operating system for permission to your photo library or camera, then stores a copy alongside the entry, on your device. Photos are never uploaded, and are only included in a backup file you create yourself.
Notifications
If you allow reminders, they are scheduled locally by your device. Hanko does not use a push service, so no server needs to know when — or whether — to message you.
The third parties that receive something
These are all the outside services in the app. All of them process data outside Türkiye.
RevenueCat — subscriptions
Handles your subscription status. It receives the purchase receipt from Apple or Google and tells the app whether you are entitled to the paid features. It generates its own anonymous identifier for your install; we do not link it to your Hanko account, so your purchases and your identity are not connected to each other on our side.
Superwall — the paywall
Decides which paywall to show and when. It receives your device and app details, plus two numbers from your usage: how many days are left in your trial, and how many days of practice you have logged in total. It never receives the content of an entry, the topics you chose, or your feeling tags.
Mixpanel — product analytics
Tells us how the app is used in aggregate — which screens people reach, where they get stuck, whether a feature is being found at all. It receives events describing actions taken, device and app version information, and a generated identifier for your install.
It never receives the text of your entries, your attached photos, or your feeling tags. We use it to make the app better, not to build a picture of you.
Supabase — accounts
Described under Accounts above. Only used if you choose to sign in.
Netlify — this website
Hosts hankoaffirmations.app. Like any web host it processes standard request logs, including IP addresses, to serve pages and resist abuse. This website carries no analytics, no advertising trackers, and no cookies. Its fonts are served from this domain rather than from Google, so visiting it does not tell any third party that you were here.
Transfers outside Türkiye
Supabase, RevenueCat, Superwall, Mixpanel and Netlify all store and process data on servers outside Türkiye, generally in the United States and the European Union. Under KVKK Article 9 this is a cross-border transfer, and by creating an account or using the app you are informed of and consent to it. Where those providers offer standard contractual clauses or equivalent safeguards, we rely on them.
What we never do
- We do not sell or rent your data.
- We do not show ads, and there are no advertising SDKs in the app.
- We do not rank, score, or publish your entries. Hanko has no social features and no feed.
- We do not read your entries. We cannot — they are not on our servers.
- We do not use your entries to train machine-learning models.
How long things are kept
Entries stay on your device until you delete them or delete the app. Account records stay with Supabase until you ask us to delete them. Analytics events are retained under Mixpanel's standard retention for our plan.
Your rights
Under KVKK Article 11 — and, for users in the UK and EU, under the GDPR — you may ask whether we hold data about you, ask what it is and why, ask for it to be corrected or deleted, and object to how it is processed.
For your entries, you do not need to ask us at all: they are on your device, so you can read, edit, delete or export any of them yourself, immediately, in the app. That is the whole file.
For an account, or for analytics data, write to privacy@hankoaffirmations.app and we will act on it. We aim to respond within 30 days.
If you are in Türkiye and are unhappy with our response, you may complain to the Personal Data Protection Authority (KVKK Kurumu). In the UK or EU, you may complain to your national supervisory authority.
Children
Hanko is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has created an account, write to us and we will remove it.
Changes
If this policy changes in a way that affects how your data is handled — in particular if entry sync is ever added — we will update the date at the top, note it in the app's release notes, and tell you in the app before the change takes effect.
Contact
Halil Akgündüz
privacy@hankoaffirmations.app