Coeffy Privacy Notice (KVKK)

Last updated: 25 September 2026

This notice explains what personal data Coeffy processes, why, who receives it and what your rights are. It is our disclosure under Article 10 of the Turkish Personal Data Protection Law No. 6698 (KVKK), and it also covers the GDPR where that applies.

1. Data controller

MavenWright, Istanbul, Türkiye, is the data controller for the personal data described here. Contact: [email protected].

2. What stays on your computer

Your data files and their rows never leave your computer. Coeffy reads your SPSS variable list and result tables locally. The log of what was sent to the AI is also kept only on your computer.

3. Google Forms

If you have a Coeffy plan, you can connect a Google Form to Coeffy. The app on your computer then signs in to your Google account and asks for one permission only: access to the files you choose in Google's file picker ("drive.file"). Coeffy cannot see your other Google Drive files.

The chosen form's questions and responses go from Google straight to your computer. They never pass through our servers and we never store them. The Google access key is kept encrypted on your computer (the macOS Keychain or Windows data protection). Coeffy uses this data only to show how many responses a form has, to turn the responses into an SPSS dataset on your computer and, when you ask, to open or close the form for new responses. On your computer Coeffy keeps only the list of your connected forms and your coding choices; responses stay in memory while you work with them.

Because the responses never reach us, we do not process your respondents' data; as the researcher, you remain responsible for it.

You can disconnect in the app at any time. Coeffy then withdraws its access at Google and deletes the form list and your choices from your computer. You can also remove Coeffy's access at myaccount.google.com/permissions. Your form and its responses stay in your Google account.

Coeffy's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. We do not use this data for advertising, do not sell it and do not let anyone at MavenWright read it.

4. What is sent to the AI

To answer you, Coeffy sends the following through our server to OpenAI, L.L.C. (USA):

  • the messages you type;
  • the variable list of your open dataset (names, labels, value labels and measurement levels), leaving out locked variables; in strict mode, names are replaced with codes such as V1 and V2;
  • result tables from your SPSS output, after counts under 5 have been hidden (you can raise this threshold, not lower it) and after tables that could reveal individuals have been withheld.

5. How the AI provider handles it

We call OpenAI with conversation storage turned off, and our server does not store the content of your messages or tables. Under OpenAI's API terms, data sent through the API is not used to train its models and may be kept for up to 30 days to detect abuse. We do not send your name or email address to OpenAI.

6. Account and service data

When you use Coeffy we process:

  • account data: email address, password (stored only as a one-way hash), language and sign-up date;
  • if you sign in with Google or Apple: the account identifier the provider gives us and the email address it shares (with Apple this may be a private relay address);
  • your consent to launch and product emails, with its date and where you gave it;
  • a device identifier, stored only as a keyed hash, so that the free trial is given once per computer;
  • credit balance, purchases, credit use and, for each AI request, the number of tokens, the model and the response time;
  • IP address and country, to protect the service from abuse, to limit request rates and to show prices for your country;
  • error reports from the app with dataset content removed (Sentry);
  • a recording of how you move through the app's screens: clicks, scrolling, layout, and the app's own menu, button and heading text; variable names, labels, results and chat content are masked and never enter it (Microsoft Clarity).

7. The Coeffy pages on this website

After you sign up or sign in, the website sets a necessary cookie named cf_ready for one day. It holds your email address and whether it is verified, so the download page can show the right step. We do not store sign-in tokens in your browser.

The website also uses analytics and advertising tools: Google Analytics and Google Ads, the Meta Pixel, Microsoft Clarity (which masks what you type into forms) and Plausible. They show us which pages and ads work, for example whether an ad led to a sign-up. Wherever you are visiting from, these tools start when a page opens; we do not show a cookie banner first. You can turn analytics and marketing off, separately, at any time with “Cookie preferences” at the bottom of every page; your choice is kept for 180 days in a cookie named mw_consent. You can also block these tools with your browser's settings or a content blocker, and you can write to us at the address in section 15 to object.

When you arrive from a Google ad, the link carries a click identifier (gclid, gbraid or wbraid). The website keeps it for 90 days in a cookie named cf_click; if you turned marketing off, it does not, and it no longer uses one it kept before. When you buy on the website, a cookie named cf_buy holds a random one-time code for one day, so that only the browser that started the purchase can see its status and set the new account's password. If you sign up or buy, the click identifier is kept with your account or order for 90 days.

8. Payments

Purchases are handled by Polar Software, Inc. (USA), our merchant of record. Polar collects your payment details and billing address and processes them under its own privacy policy. We receive the order details (product, amount, currency, country, email address and order number), never your full card number.

When an order is a first payment (not a renewal), we tell Google Ads about it so we can see which ads lead to purchases: we send the click identifier if there is one, the order amount and currency, the time of the order and a SHA-256 hash of your email address, never the address itself or your payment details.

9. Who receives data

We share personal data only with the service providers we need to run Coeffy:

  • OpenAI, L.L.C. (USA): AI answers;
  • Polar Software, Inc. (USA): payments, receipts and tax;
  • Cloudflare, Inc. (USA): network security and content delivery;
  • Hostinger: hosting of our servers and database;
  • Google LLC and Apple Inc. (USA): sign-in, if you choose it; Google also for website analytics and ads;
  • Meta Platforms, Inc. (USA) and Microsoft Corporation (USA): website ad measurement and analytics; Microsoft also for usage recordings in the app with your data masked (Clarity);
  • Plausible Insights OÜ (Estonia): website visit statistics;
  • Functional Software, Inc. (Sentry, USA): app error reports;
  • our email delivery provider: account emails and, with your consent, launch emails.

10. Transfers abroad

Several of these providers are outside Türkiye. We transfer personal data to them under Article 9 of the KVKK, on the basis of standard contracts notified to the Personal Data Protection Authority or, where the law requires it, your explicit consent.

11. Why we process data (legal bases)

  • to create and run your account and credits and to provide the service you asked for: performance of a contract (KVKK Art. 5(2)(c));
  • to keep billing and tax records: legal obligation (Art. 5(2)(ç));
  • to protect the service, prevent trial abuse, fix errors and understand how the app is used: our legitimate interest (Art. 5(2)(f));
  • to measure whether our Google ads lead to sign-ups and purchases (click identifier, order amount, hashed email address): our legitimate interest (Art. 5(2)(f));
  • to send launch and product emails and, where needed, to transfer data abroad: your explicit consent (Art. 5(1)), which you can withdraw at any time.

12. How long we keep data

We keep account data while your account is open. When you close it, we remove your email address, password, sign-in sessions, any unused verification and password-reset tokens, Google or Apple links and your consent record straight away. Purchase and billing records are kept for as long as commercial and tax law requires (up to 10 years). Three things stay after closure, because they carry no contact details and we need them to keep counting fairly: your credit ledger entries, your free-question counts, and a keyed hash of the computer that used the free trial — so that closing an account and opening a new one does not give a second trial. Security logs with IP addresses are kept for a short time, normally no more than 30 days. While your account is open, we keep your consent record for as long as the consent is valid and for as long as we may need to prove it.

13. Launch and product emails

We send these emails only if you tick the box when you sign up. You can withdraw at any time with the link in each email or by writing to [email protected]. Emails about your account (verification, password reset, receipts) are part of the service and do not need this consent.

14. Your rights

Under Article 11 of the KVKK you have the right to:

  • learn whether your personal data is processed and, if so, request information about it;
  • learn the purpose of processing and whether data is used for that purpose;
  • know the third parties in Türkiye or abroad to whom data is transferred;
  • ask for incomplete or incorrect data to be corrected;
  • ask for data to be erased or destroyed under the conditions of Article 7;
  • ask for a correction or erasure to be passed on to the third parties who received the data;
  • object to a result against you that arises solely from automated analysis of your data;
  • claim compensation if you suffer damage from unlawful processing.

15. How to apply

Write to [email protected] from the email address on your account. We answer within 30 days at the latest and free of charge, unless the law allows a fee. If you are not satisfied with our answer, you can complain to the Personal Data Protection Authority (KVKK).

16. Children

Coeffy is intended for people aged 18 and over. If you think a child has given us personal data, write to us and we will delete it.

17. Changes

We update this notice when our processing changes and show the date at the top. If a change matters to you, we will tell you in the app or by email.