Kulis — Privacy Policy
Version: 0.1 (draft) · Effective date: [[YURURLUK_TARIHI]] · Last updated: [[YURURLUK_TARIHI]]
This is a draft and not legal advice. It must be reviewed by a licensed attorney before publication. Fields in double brackets ([[...]]) must be filled in first. Language and governing law. This is a faithful translation of the Turkish original (privacy.tr.md). Kulis is established in Türkiye; Turkish law governs, and the Turkish text prevails in case of any discrepancy.
1. Who is the data controller
Kulis (kulis.ai) is an event announcement and content distribution system for independent venues. The controller for the processing described here is:
| Legal name | [[VERI_SORUMLUSU_UNVAN]] |
| Address | [[ADRES]] |
| MERSIS no. | [[MERSIS]] |
| Registered e-mail (KEP) | [[KEP]] |
| [[ILETISIM_EPOSTA]] | |
| Web | https://kulis.ai |
Kulis is established in Türkiye. Personal data is processed under Turkish Personal Data Protection Law no. 6698 ("KVKK").
2. What data we process
Account data. Your e-mail address, an irreversible hash of your password, your workspace (venue) name, your role, and account creation/update timestamps. Kulis is currently invite-only; public sign-up is disabled.
Connected platform accounts. You connect your own YouTube, Instagram, Facebook, TikTok and Telegram accounts. What we receive: account/channel ID, display name, profile image, the list of permissions (scopes) you granted, and access/refresh tokens. Tokens are stored encrypted with AES-256-GCM, are never sent to your browser, and are decrypted only by the background process that performs publishing.
Videos and images you upload. The files you upload for distribution and their re-encoded copies made to satisfy platform rules. If the file is a recording of a show, it may contain the image and voice of performers and of the audience.
Transcripts. Speech-to-text output and its time-stamped segments, produced per post when you turn it on. Transcription is off by default; you start it separately for each post. If speaker separation is enabled, labels are anonymous ("Speaker 1", "Speaker 2").
AI inputs and outputs. Prompts sent for generating titles, descriptions, hashtags, thumbnails, subtitles and voice-overs; the generated files; and for each generation which provider and model produced it, with estimated and actual cost.
Telegram identifiers. If you use the Telegram "inbox" bot: the ID of the chat/channel you allowed, and the content you send from it.
Operational and error logs. Publishing attempts, error messages returned by platforms, queue states, server access logs and IP address.
Early-access form. If you join the list: venue name, Instagram username, number of shows per week, WhatsApp number, language preference, and the source of the entry.
Cookies. Only three functional cookie families are used: session cookies (to keep you signed in), a 10-minute security cookie used while connecting an account (oauth_nonce, anti-forgery), and a language preference cookie (NEXT_LOCALE). No advertising, tracking or profiling cookies are used.
3. Why we process it, and our legal basis (KVKK art. 5)
| Data | Purpose | Legal basis |
|---|---|---|
| Account data | Create your account, authenticate you, manage your workspace | art. 5/2-c — necessary for the conclusion/performance of a contract |
| Platform tokens and account profile | Publish on your behalf, with your approval | art. 5/2-c |
| Uploaded video and images | Distribution and re-encoding to meet platform rules | art. 5/2-c |
| Image/voice of performers and audience | Allowing the venue to announce its own event | art. 5/2-f — legitimate interest (with a written balancing test); for performers, separate written consent is obtained |
| Transcripts | Producing subtitles, descriptions and promotional copy | art. 5/2-c and art. 5/2-f |
| AI prompts and outputs | Text, image and audio generation; cost tracking | art. 5/2-c |
| Operational and error logs | Verifying the service works, preventing abuse, troubleshooting | art. 5/2-f — legitimate interest |
| Invoices and financial records (if charging begins) | Statutory bookkeeping and record retention | art. 5/2-ç — legal obligation |
| Early-access form | Contacting you when your turn comes | art. 5/2-f — legitimate interest (at your own request) |
Important: We do not send commercial electronic messages to the early-access list. You will only be contacted individually about your own request. If we ever start sending commercial messages, we will first obtain separate explicit consent and register it with the Turkish Message Management System (İYS).
4. How long we keep it
| Data | Retention |
|---|---|
| Uploaded video and its normalized copies | Deleted 30 days after publication completes |
| Transcripts and their segments | Deleted 90 days after publication completes |
| Generated titles/descriptions/images/audio | Until you delete the post or the workspace |
| Platform tokens | Until you disconnect the account or revoke access at the platform; deleted within 30 days at the latest |
| Account data | While the account is open; deleted within 30 days of a closure request |
| Operational, publishing and error logs | 12 months |
| Early-access entry | 24 months, or earlier on your deletion request |
| Financial records (if charging begins) | The period required by tax law (10 years) |
Your deletion request does not cover records we are legally required to keep; those are retained, access-restricted, until their statutory period expires and are used only for that legal obligation.
5. Who we share it with
The platforms you publish to. When you approve a post, the content is sent to the relevant platform (YouTube, Instagram, Facebook, TikTok, Telegram) through the account you connected. Those platforms process the data under their own privacy policies.
Our service providers (sub-processors). The current list, with each provider's country, purpose and data accessed: docs/legal/subprocessors.md (published at https://kulis.ai/subprocessors). In brief: Supabase (database and authentication, Frankfurt/EU), Cloudflare R2 (media storage), Vercel (web hosting), Hetzner (Germany, background server), Anthropic (text generation), ElevenLabs / OpenAI / Deepgram (transcription and voice), fal.ai (image and video generation), Telegram (bot).
Public authorities. Only where legislation expressly requires it, and after we review the lawfulness of the request.
We do not sell your personal data and do not transfer it to third parties for advertising.
6. International transfers (KVKK art. 9)
Some of the providers above are located outside Türkiye (USA, Germany, EU), so data is transferred abroad. Transfers are made on the basis of standard contracts under KVKK art. 9; each signed standard contract is notified to the Turkish Data Protection Authority within 5 business days of signature. Where an adequacy decision exists for a country, the transfer relies on art. 9/1.
If you enable transcription, your audio is sent to the provider you selected (ElevenLabs, OpenAI or Deepgram). These providers are outside Türkiye. Please make that decision knowingly.
7. Security
Tokens are encrypted with AES-256-GCM and decrypted only server-side; row level security is enabled in the database and each workspace sees only its own data; authorization flows are protected with a signed state parameter and a single-use cookie; administrative access is limited to the minimum number of people.
To be straight with you: the media you upload is kept reachable through an unguessable address (cdn.kulis.media) so that Instagram and TikTok can fetch the video. Anyone who knows that address can reach the file; it is not exposed to search engines, and files are deleted at the end of the retention periods above.
8. Your rights (KVKK art. 11)
You have the right to: learn whether your personal data is processed; request information about it; learn the purpose of processing and whether it is used accordingly; know the third parties to whom it is transferred in Türkiye or abroad; request correction if it is incomplete or inaccurate; request erasure or destruction; request that correction/erasure be notified to third parties to whom the data was transferred; object to a result produced against you solely through automated analysis; and claim compensation for damage.
How to apply: write to [[ILETISIM_EPOSTA]] or to our registered e-mail address [[KEP]], including information that lets us verify your identity. We will conclude your request within 30 days at the latest. If our response does not satisfy you, you may lodge a complaint with the Turkish Data Protection Board.
Step-by-step instructions to delete your account and data: https://kulis.ai/data-deletion.
9. Google / YouTube data
Kulis uses YouTube API Services. When you connect your YouTube account, the data accessed through YouTube API Services is: channel ID, channel name, profile image, the scopes you granted, and the ID, URL and upload status of videos you upload through Kulis.
- What it is used for: only to upload the video you approved to your own channel, show its upload status, and prevent the same video from being uploaded twice. It is not used for advertising, profiling or training AI models, and is never sold.
- How long it is kept: authorization tokens for as long as the account stays connected. Other YouTube data is deleted within 30 calendar days of you disconnecting the account or revoking access through Google.
- How to delete / revoke: disconnect from the Accounts screen inside Kulis, or revoke access directly at the Google security settings page: https://security.google.com/settings/security/permissions
- Kulis's use of information received from YouTube API Services complies with the Google API Services User Data Policy, including the Limited Use requirements.
- By using Kulis you also agree to the YouTube Terms of Service: https://www.youtube.com/t/terms
- Google Privacy Policy: https://policies.google.com/privacy
10. Meta (Instagram and Facebook) data
When you connect an Instagram business account or a Facebook page, we access: account/page ID, name, profile image, the permissions granted, and an access token. Permissions used: instagram_business_basic, instagram_business_content_publish, pages_show_list, pages_manage_posts, pages_read_engagement, publish_video.
- What it is used for: only to publish the content you approved to your own account and to show its status.
- How long it is kept: until you disconnect; deleted within 30 days after that at the latest.
- How to delete: disconnect inside Kulis, or remove Kulis from Settings → Apps and Websites on Facebook/Instagram. When you remove the app there, Meta sends us an automatic deletion callback; we record the request, delete the connected account data, and return a confirmation code and a status page URL. Details:
https://kulis.ai/data-deletion.
11. TikTok data
When you connect your TikTok account, we access: open user ID (open_id), display name, profile image and an access token. Scopes used: user.info.basic, video.upload, video.publish.
- What it is used for: only to send the video you approved to your own account and show its status. The video file is pulled by TikTok from
cdn.kulis.media. - How long it is kept: until you disconnect; deleted within 30 days after that at the latest.
- How to delete: disconnect inside Kulis, or remove Kulis's access from Settings → Security and permissions → Apps permissions in the TikTok app.
- Until our TikTok audit is complete, videos you send remain visible only to you (
SELF_ONLY) or stay as drafts on TikTok's side. This is TikTok's rule.
12. Children
Kulis is not directed at anyone under 18 and does not knowingly collect data from children. If we learn we have, we delete it.
13. Changes
If we update this policy we change the effective date and record it in the version history below. For material changes we notify registered users by e-mail in advance.
| Version | Date | Change |
|---|---|---|
| 0.1 | [[YURURLUK_TARIHI]] | Initial publication. |
Contact: [[ILETISIM_EPOSTA]] · [[KEP]]