Last updated: June 14, 2026

Privacy Policy

This policy explains precisely what data we collect, why we collect it, how it is stored and protected, and your rights regarding that data.

1. Who We Are & Scope

sare-ai ("we," "us," "our") operates the AI-powered vector generation platform at sare-ai.com (the "Service"). This Privacy Policy applies to all users of the Service, including visitors, registered users, and beta participants.

This policy complies with the Republic of Turkey's Personal Data Protection Law No. 6698 (Kişisel Verilerin Korunması Kanunu — KVKK) and, where applicable, the European Union's General Data Protection Regulation (GDPR).

2. Data We Collect

We collect the following categories of personal data:

Account & Identity Data

  • Email address — used for authentication, communication, and security verification
  • Username — a display name you provide (optional)
  • Password — stored as a salted SHA-256 hash; we never store your plain-text password
  • Profile avatar — only if you sign in via Google OAuth
  • Account provider — whether you registered via email or Google
  • Beta access code — the invitation code used at registration (stored for audit purposes)

Usage & Activity Data

  • Total and daily generation counts
  • Credit balance and transaction history
  • Subscription plan
  • Text prompts submitted for generation — stored in your personal library (chats subcollection)
  • Generated SVG outputs — stored in your personal library if saved
  • Account creation date and last active date
  • Referral data — if you participate in our referral programme

Security & Technical Data (automatically collected)

  • IP address — logged on every login attempt, account creation, and certain account actions
  • Browser user agent string — device and browser type logged with security events
  • Event type and timestamp — what action occurred and when (e.g., login_success, login_fail, signup)

Brand Kit Data (Browser-Only)

  • Brand colours and font preference — stored exclusively in your browser's localStorage under the key sare_brandkit. This data never leaves your device and is not transmitted to our servers unless explicitly included in a generation prompt.

Communication Data

  • Support ticket content — messages, category, priority, and associated email you submit when opening a ticket
  • Direct email messages — if you contact us via our support email address, the content of your message, your sender address, and the subject line are received and stored securely for the purpose of responding to your enquiry
  • Newsletter subscription status — if you opt in via the website footer
  • Email verification codes — temporary 6-digit codes stored with a 10-minute expiry; deleted immediately after successful verification

3. How We Use Your Data

We process your personal data for the following purposes:

  • Service delivery — authenticating your account, processing generations, managing credits and subscriptions
  • Security & fraud prevention — detecting unauthorised access, suspicious login patterns, and abuse; IP and user agent logs are used exclusively for this purpose
  • Transactional communications — sending email verification codes, account notifications, and support replies via our email provider
  • Service improvement — aggregate, anonymised usage analytics to improve features and performance
  • Legal compliance — retaining records as required by applicable law, including KVKK obligations
  • Newsletter — sending product updates to users who explicitly opted in (opt-out available at any time)

We do not sell your personal data. We do not use your data for behavioural advertising or share it with third parties for their own marketing purposes.

4. Data Storage & Third-Party Processors

To operate the Service, we work with trusted third-party infrastructure and service providers. Each provider acts as a data processor under our instructions and is bound by appropriate data processing agreements. We use the following categories of processors:

  • Cloud Database Provider

    Stores all account data, security logs, support tickets, and generation history on secure cloud infrastructure with industry-standard access controls.

  • Transactional Email Provider

    Handles delivery of all system emails including verification codes, account notifications, and support replies. Your email address and email content are processed solely for delivery purposes.

  • AI Generation API Provider(s)

    Processes the text prompts you submit in order to produce vector graphic outputs. Prompts are transmitted securely and are not used to train models without consent. We work with one or more AI API providers depending on the generation type selected.

  • Hosting & Edge Infrastructure Provider

    Serves the web application and runs serverless functions. Standard request metadata (including IP addresses) may be logged by the hosting provider for operational and security purposes.

The identities of specific sub-processors are available upon request — contact us via a support ticket. Your data may be processed in countries outside Turkey, including within the European Economic Area and the United States, under standard contractual safeguards.

5. Local Storage (Browser)

For performance purposes, we store a subset of your account data (username, email, plan, credit balance, language preference, and a maintenance status cache) in your browser's localStorage. This data is a local copy of what is stored in our database — it is not a substitute for server-side storage.

Additionally, the following data is stored exclusively in your browser and is never sent to our servers:

  • Brand Kit (sare_brandkit) — your chosen brand colours and font preference
  • Recent prompts (recentPrompts) — up to 20 of your most recent generation prompts, used solely for the autocomplete feature in your browser

We do not use tracking cookies or advertising cookies. Session-related data is managed via localStorage, not cookies. You can clear localStorage at any time through your browser's developer tools or privacy settings, though this will log you out and reset locally stored preferences.

6. Data Retention

Data CategoryRetention Period
Account data (email, username, plan)Until account deletion + 30 days
Password hashUntil account deletion
Security logs (IP, user agent)12 months from collection date
Email verification codes10 minutes (auto-deleted on use)
Generation history & promptsUntil account deletion or manual deletion
Support tickets & direct email enquiries3 years from creation date
Newsletter subscriptionsUntil opt-out + 90 days
Billing records7 years (legal / tax obligation)

7. Your Rights (KVKK & GDPR)

Depending on your location, you have the following rights regarding your personal data:

  • Right of access — request a copy of all personal data we hold about you
  • Right to rectification — request correction of inaccurate or incomplete data
  • Right to erasure — request deletion of your data ("right to be forgotten"), subject to legal retention obligations
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing for direct marketing (newsletters) at any time
  • Right to restriction — request that we restrict processing of your data in certain circumstances
  • Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing

To exercise any of these rights, open a support ticket at /ticket or contact us through your account settings. We will respond within 30 days. We may need to verify your identity before fulfilling requests.

If you are located in Turkey and believe your rights under KVKK have been violated, you may lodge a complaint with the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu — KVKK).

8. Children's Privacy

The Service is not directed at children under 13 years of age. We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided personal data to us, please contact us immediately and we will delete such data.

Users between 13 and 18 must have verifiable parental or guardian consent before creating an account or using the Service.

9. Security Measures

We implement the following measures to protect your personal data:

  • Passwords are stored as salted SHA-256 hashes — never in plain text
  • All data in transit is encrypted via HTTPS/TLS
  • Sensitive operations (password reset, email verification) use HMAC-signed, time-limited tokens
  • Security events are logged and monitored for anomalies
  • Access to production systems is restricted to authorised personnel only
  • Firestore security rules limit read/write access to appropriate parties

While we take all reasonable precautions, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security and are not liable for any breach that occurs despite these measures.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via a notice in the Service dashboard or by email at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

Your continued use of the Service after any update constitutes acceptance of the revised policy. If you do not agree with the changes, you must stop using the Service before the effective date.

11. Contact & Data Controller

For any privacy-related requests, questions, or to exercise your rights, please open a support ticket at sare-ai.com/ticket or contact us through your account settings. Please mark your request clearly as a "Privacy/KVKK Request" for faster handling.