Privacy Policy

FABLESO YAZILIM VE MÜHENDİSLİK ANONİM ŞİRKETİ

Last updated: 18 September 2026

Introduction

FABLESO YAZILIM VE MÜHENDİSLİK ANONİM ŞİRKETİ ("Fableso," "we," "our," or "us") built Apps (the "App" or "Service") as a freemium application. This Service is provided by Fableso at no cost for basic features (with optional premium paid features) and is intended for use as-is.

This page informs visitors and users of our policies regarding the collection, use, and disclosure of Personal Information when using the Service. By using the Service, you agree to the collection and use of information in accordance with this Policy. Capitalized terms used in this Policy have the same meanings as in our Terms of Use unless otherwise defined here.

Information Collection and Use

To provide a better experience, we may ask you to provide certain personally identifiable information, including but not limited to device identifiers (e.g., IDFA/GAID), usernames, and contact details you choose to share (such as an email address for customer support).

We also collect the information you submit or upload to use the core features of PastPeek, which includes:

  • Images of antiques, vintage items, and collectibles that you scan.
  • Optional texts or notes you provide.

The information we request is retained by us and used as described in this Policy to provide and improve the Service. This includes debugging, security, analytics, customer messaging, and—in ad-supported free tiers—ad delivery and measurement.

We do not sell your Personal Information. We may "share" certain technical identifiers with advertising and analytics partners to support app functionality and measure ad performance where applicable.

Use of Third-Party AI Models

To operate PastPeek's core identification and valuation features, we may send your inputs and related data to third-party Artificial Intelligence (AI) model providers such as Google and OpenAI.

  • What may be shared: The photo of the item you upload, any texts that you enter, and minimal technical metadata needed for the scan (e.g., image resolution, format, and scan parameters).
  • Purpose & scope: We share only what is strictly necessary to maintain functionality (e.g., to identify the antique, pull historical context, estimate value, or suggest a condition grade). Some third-party providers may retain logs to ensure reliability and prevent abuse.
  • Your choice: The core identification features of PastPeek rely on this technology and will not work if you do not want content sent to third-party AI providers. If you prefer not to share this data, please do not use the scanning features.
  • Model improvement: We may use your uploaded images and generated content to train and improve our models and Service quality (for example, using de-identified or anonymized image samples for testing).

Third-Party Services

Apps use third-party services that may collect information used to identify you or your device. Examples of these providers include:

  • Google Play Services
  • AdMob
  • Google Analytics for Firebase
  • Firebase Crashlytics
  • Unity
  • GameAnalytics
  • OneSignal
  • AppLovin
  • Adjust
  • RevenueCat
  • Third-Party AI model providers (e.g., OpenAI, Google, etc.)

These providers assist us with analytics, crash reporting, push notifications, marketing attribution, ad mediation/serving, processing subscriptions, and AI inference.

Log Data

When you use the Service and an error or crash occurs, we collect Log Data (often via third-party SDKs) to help us diagnose the issue. This may include your device's IP address, device name, operating system version, app configuration at the time of the crash, timestamps, and usage events.

Cookies and Similar Technologies

Third-party SDKs integrated into the Apps may use mobile identifiers and SDK-level storage for analytics, attribution, and advertising purposes. You can control ad personalization or reset your advertising identifier directly within your mobile device's settings. Refusing certain identifiers may affect ad-supported functionality.

Service Providers

We may employ third-party companies and individuals to:

  • Facilitate our Service;
  • Provide the Service on our behalf;
  • Perform Service-related maintenance; or
  • Assist us in analyzing how our Service is used.

These third parties have access to your Personal Information strictly to perform these tasks on our behalf and are legally obligated not to disclose or use it for any other purpose.

Security

We value your trust in providing us with your Personal Information and utilize commercially reasonable means to protect it. However, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

User Inputs and Outputs

User inputs (scanned photos) and generated outputs (historical reports and pricing data) may be accessed and processed solely as necessary to operate, maintain, secure, and improve the Service. This includes diagnosing technical issues and enhancing the AI's accuracy.

Access to this content is limited to authorized personnel and systems, subject to confidentiality obligations, and handled in accordance with applicable data protection laws. We do not sell your user content to third parties.

Children's Privacy

The Services are not intended for anyone under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If you are a parent or guardian and you believe your child has provided us with Personal Information, please contact us immediately so we can delete the data from our servers.

Additional Information for PastPeek: Antique Identifier

PastPeek: Antique Identifier
  • Data used for features: Images of antiques/collectibles you upload, related prompts/notes, and technical metadata required for scanning.
  • AI processing: As described above, PastPeek sends your uploads and metadata to third-party AI model providers as needed to maintain core functionality (identification, reference pricing, historical context, and grading).

Ownership and Licensing

  • Premium (Paid) Subscribers retain the rights to use the AI-generated textual reports and descriptions created during their subscription for Commercial Use (e.g., online auction listings).
  • Free Users are granted a license for Personal, non-commercial use of the generated reports and must provide attribution (e.g., "Identified by PastPeek AI") if sharing publicly.
  • Users are solely responsible for ensuring that scanning specific items or uploading certain images does not infringe upon third-party copyrights.
  • Note: The ownership and licensing points above are a summary. If there is any inconsistency between this Privacy Policy and the Terms of Use, the Terms of Use shall control.

Additional Information for AI Music Video Generator: Yuna

AI Music Video Generator: Yuna

This section governs the privacy policy for AI Music Video Generator: Yuna ("Yuna"), and in the case of a conflict between the rest of the privacy policy and this section, this section takes precedence for Yuna.

1. Data Storage and Protection

At Yuna, we prioritize the security of your personal content. We implement industry-standard encryption and security measures to ensure that your photos and generated videos are protected from unauthorized access.

2. Purpose of Uploads

Users upload 2D images to AI Music Video Generator: Yuna solely to generate AI-powered music videos, artistic portraits, or similar visual effects.

  • No Biometrics: The app does not employ facial recognition technology for user identification, authentication, or biometric verification.
  • Creative Use Only: Your photos are used as a visual reference for the AI to create your personalized music clip.

3. Use of Face Data

Any face data (2D images containing faces) uploaded to Yuna is used exclusively to:

  • Generate AI-modified visuals, including music video previews and personalized video content.
  • Process the uploaded images through third-party AI generation services to create personalized video content based on the user's request.
  • Display and return the processed music video results to the user within the app interface.
  • Visual Attribute Analysis: To provide more accurate video results and improve the AI's creative output, our system may analyze the uploaded 2D image to generate internal descriptive metadata. This includes general visual attributes such as clothing, hair color, setting, and estimated demographic characteristics (e.g., age range, gender, or ethnic appearance) to ensure the generated content matches the user’s appearance in the final video.

4. Restrictions on Face Data Usage

Yuna follows a strict "No Misuse" policy:

  • No Identification: Collected face data is never used for biometric analysis, surveillance, or user identification.

5. Third-Party Processing

To provide high-quality AI generation, uploaded 2D images may be temporarily shared with secure third-party service providers (e.g., cloud-based AI processors). These providers have their own privacy policies and your data may be used according to their privacy policies.

6. Data Storage Location

Data is stored for as long as necessary to provide our services and for a reasonable timeframe on secure servers managed by Yuna and trusted cloud providers in compliant regions (e.g., EU or US).

7. Data Retention and User Control

  • User Control: You have full control over your content. Both original photos and generated videos remain available in the app gallery for your viewing until you manually delete them.
  • Manual Deletion: If you delete a photo or video via the Yuna interface, it is permanently removed from our servers and third-party systems within a reasonable timeframe.
  • Incomplete Sessions: Temporary files from incomplete or failed video generation sessions are automatically deleted as soon as reasonably possible.

8. No Biometric or Identification Use

The technologies implemented in AI Music Video Generator: Yuna do not allow unique identification or authentication of a user. We do not collect "biometric identifiers" as defined under laws like GDPR or CCPA.

9. Metadata and Internal Logs

When you process an 2D image, AI Music Video Generator: Yuna generates temporary text-based descriptions (metadata) to help the AI understand the scene (e.g., "person sitting on a bed," "short hair"). These summaries are used to guide the video generation engine and are handled with the same security standards as your original photos.

Additional Information for Rec Me Duo - Two Lenses

Rec Me Duo - Two Lenses

This section governs the privacy practices for Rec Me Duo. In the case of a conflict between the rest of the general privacy policy and this section, this section takes precedence for Rec Me Duo - Two Lenses.

1. On-Device Storage and Protection

Rec Me Duo - Two Lenses, we prioritize the security of your content. Unlike cloud-based apps, all video recording and processing happen locally on your device. We do not upload your raw footage to our servers. Your videos are stored directly in your system Photos library, protected by phone native encryption.

2. Purpose of Camera and Microphone Access

Users grant access to the camera and microphone solely to:

  • Capture simultaneous video feeds (e.g., front and back cameras or dual rear lenses).
  • Record synced audio for your video content.
  • Provide real-time previews for portrait (9:16) and landscape (16:9) framing.

3. No Biometrics or Facial Recognition

  • No Identification: The app does not employ facial recognition, facial modeling, or any biometric technology to identify or authenticate users.
  • Creative Use Only: If a face is visible in the frame, it is processed only as part of the standard video signal for recording purposes (focus, exposure). No face data is extracted, collected, or stored separately.

4. Data Processing and Third-Parties

  • Local Processing: All video merging, syncing, and stabilization are performed by your device's internal processor (ISP).
  • No Third-Party Sharing: Since processing is local, your video and audio data are never shared with or sold to third-party AI services, advertisers, or cloud processors.

5. Use of Metadata

Rec Me Duo - Two Lenses may analyze technical metadata (such as resolution, frame rate, ISO, and device compatibility) to ensure the app functions correctly. This metadata is used for session performance only and is not linked to your personal identity.

6. Data Retention and User Control

  • User Control: You have 100% control over your content. Rec Me Duo - Two Lenses does not maintain a separate cloud gallery.
  • Deletion: When you delete a video from your Photos library, it is removed according to your settings. Our app does not keep "shadow copies" or hidden backups.
  • Zero Accounts: We do not require account creation, meaning we do not link your footage to an email address or personal profile.

7. Compliance

The technologies implemented in Rec Me Duo - Two Lenses do not collect "biometric identifiers" or "biometric information."

Additional Information for Color Dictionary: Sanzo

Color Dictionary: Sanzo

This section governs the privacy practices for Color Dictionary: Sanzo. In the case of a conflict between the rest of the general privacy policy and this section, this section takes precedence for Color Dictionary: Sanzo.

Overview

Fableso Yazılım ve Mühendislik Anonim Şirketi ("Fableso," "we," "us," or "our") operates this mobile application (the "App"), a color reference tool built around a curated color combination library and a Color Scanner. This Privacy Policy explains what information we collect, how we use it, and the choices you have.

1. Information We Collect

  • Purchase and Subscription Data: We use RevenueCat to manage subscriptions. It assigns your device an app-specific user ID and records your subscription status and purchase history, linked to you, to manage entitlements and for internal analytics.
  • Device and Advertising Identifiers: We use Adjust as our attribution partner to measure marketing performance across Meta and Apple Search Ads. On iOS, this only occurs if you grant permission via the App Tracking Transparency ("ATT") prompt.
  • Usage and Analytics Data: We use Firebase Analytics to understand how the App is used and which advertisements led to installs.
  • Account Information: The App does not require an account. We do not collect your name or email unless you voluntarily contact us.

2. Color Scanner & Camera Data

  • On-Device Processing Only: All Color Scanner processing happens entirely on your device. No photo, camera frame, or image data is transmitted to, stored on, or accessible by our servers or any third party.
  • Accuracy Limitation: Because scan results depend on your device's camera, ambient lighting, and screen calibration, the colors and matches shown may not exactly reflect the true color of a physical object, printed material, or paint sample.

3. Third-Party Services

We share data with the following providers, each under its own privacy policy: RevenueCat (subscriptions), Adjust (attribution), Meta (advertising measurement), Apple Search Ads (attribution), and Firebase (analytics).

4. App Tracking Transparency (iOS)

On first launch, the App may request tracking permission under Apple's ATT framework, used solely to measure advertising performance via Adjust. Declining this permission does not affect App functionality.

5. Data Security

We use commercially reasonable technical and organizational measures to protect the data described above. No method of transmission or storage is 100% secure.

Additional Information for TCG Scan & Grade Cards: DexPal

TCG Scan & Grade Cards: DexPal

This section governs the privacy practices for TCG Scan & Grade Cards: DexPal ("DexPal"). In the case of a conflict between the rest of the general privacy policy and this section, this section takes precedence for DexPal.

1. Data Used for Features

  • Card Images: Photographs of trading cards you scan, together with any optional notes or prompts you provide.
  • Technical Metadata: Minimal information required to run the scan, such as image resolution, file format, capture parameters, and timestamps.
  • Collection Data: Where you save scanned cards to an in-app collection or wishlist, we retain those records and their associated results so the feature can function across sessions.

2. AI Processing and Third-Party Model Providers

To deliver DexPal's core identification, valuation, and grading features, we send your uploads and related data to third-party AI model providers such as Google and OpenAI.

  • What may be shared: The card image you upload, any text you enter, and the minimal technical metadata needed for the scan.
  • Purpose and scope: We share only what is strictly necessary to maintain functionality — identifying the card and its set, printing, rarity, and edition, retrieving reference pricing, and suggesting a condition grade. Some providers may retain logs to ensure reliability and prevent abuse, subject to their own policies.
  • Your choice: DexPal's scanning features depend on this technology and will not work if you prefer that your content not be sent to third-party AI providers. If you would rather not share this data, please do not use the scanning features. Other parts of the App that do not require analysis remain available.

3. Model Improvement and Training

We may use your uploaded images and the outputs generated from them to develop, train, test, and improve our models and overall Service quality, including through de-identified, anonymized, or redacted samples used for testing, demonstration, or evaluation. We will not sell or publicly distribute your raw, original, unredacted images outside the uses described in this Policy and the Terms of Use without your explicit consent.

4. Reference Pricing and Third-Party Market Data

DexPal displays pricing and catalog information drawn from marketplaces, pricing aggregators, and registry services operated by third parties. Requests made to retrieve this data may transmit technical information such as your IP address to those providers, whose own privacy policies then apply. We do not control that data and are not responsible for it.

5. Affiliate and Marketplace Links

DexPal may contain referral or affiliate links to other third-party marketplaces. Following such a link takes you outside the App, and the destination site's own privacy practices and tracking technologies apply from that point onward. Affiliate networks may set identifiers to attribute a resulting purchase. We do not receive your payment details, order contents, or account information from these marketplaces.

6. Purchase, Subscription, and Analytics Data

We use RevenueCat to manage subscriptions and scan entitlements, which records an app-specific user identifier, your subscription status, purchase history, and remaining scan allowance. Analytics and attribution providers listed in the Third-Party Services section above may also collect device and usage data. On iOS, tracking for advertising measurement occurs only where you grant permission through Apple's App Tracking Transparency prompt.

7. What Not to Include in Your Scans

Please photograph only the card itself. Images may incidentally capture surroundings, documents, screens, or other people, and anything visible in the frame is transmitted for analysis and may be retained as described above. Avoid including anything you would not wish to share.

8. Data Retention and User Control

  • Retention: We retain images and derived data for as long as is reasonably necessary to operate DexPal, support reproducibility of past results, improve our models, and comply with legal obligations.
  • Deletion: You may delete individual scans and saved cards through the App. Deletion removes the item from your collection and from our active systems within a reasonable timeframe, though anonymized or aggregated data that no longer identifies you or your card may be retained.
  • Failed sessions: Temporary files from incomplete or failed scans are deleted as soon as reasonably possible.

9. No Biometric Use

DexPal analyzes images of trading cards. It does not employ facial recognition, facial modeling, or any biometric technology, and it does not collect "biometric identifiers" or "biometric information" as those terms are defined under laws such as GDPR, KVKK, or CCPA.

10. Ownership and Licensing

You retain ownership of your images and of whatever rights you hold in the card itself. Your use of DexPal's identifications, valuations, grades, and generated reports is governed by the Terms of Use.

Note: The ownership and licensing points above are a summary. If there is any inconsistency between this Privacy Policy and the Terms of Use, the Terms of Use shall control.

Additional Information for Playable AI Story - Loreveil

Playable AI Story - Loreveil

Effective date: September 18, 2026
Last updated: September 18, 2026

This Privacy Policy explains what personal data FABLESO YAZILIM VE MÜHENDİSLİK ANONİM ŞİRKETİ, a company registered in Türkiye with its registered office at ÜNIVERSITELER MAH. 1597 CADDE KÜME EVLER NO:43 İÇ KAPI NO: 36 ÇANKAYA / ANKARA ("Loreveil", "we", "us", or "our"), collects when you use Playable AI Story - Loreveil and the services we provide through it (the "Platform"), why we collect it, who we share it with, how long we keep it, and what you can do about it.

Our processing of personal data is primarily governed by applicable Turkish data protection laws, including the Law on the Protection of Personal Data No. 6698 ("KVKK"). Where another data protection law applies to you because of where you live or use the Platform, we will comply with the applicable requirements of that law to the extent required.

Terms written in bold have the meaning given in our Terms of Use.

The short version

  • We collect what the Platform needs to work: your account details, your stories and creations, your chats and prompts, your purchases, and technical data from your device.
  • Your chats and prompts are part of the product. They are stored against your account so you can continue a story, and they may be processed by AI providers to generate the next reply, image, or other content.
  • We do not sell your personal data.
  • We do not permit third-party AI providers to use your content to train their own models, subject to the terms and limitations described in Section 8.
  • You can request access, correction, deletion, or other applicable rights regarding your personal data through the process described in Section 11 and Section 12.
  • The Platform is not intended for children under 13. Mature content, where available, requires users to be 18 or older.
  • Questions or privacy requests: info@fableso.com.

What is in this Policy

  • 1 — What we collect and why — Sections: 1–6; Contents: Data you give us, data your use creates, automatic data, data from other sources, our purposes and legal bases, and what we do not collect
  • 2 — Who sees it — Sections: 7–10; Contents: Service providers, AI model providers, other disclosures, and what we do not do
  • 3 — Your choices and rights — Sections: 11–15; Contents: In-product controls, your rights, regional rights, making requests, and appeals
  • 4 — How we look after your data — Sections: 16–20; Contents: Retention, security, international transfers, children and age assurance, and automated processing
  • 5 — Practical matters — Sections: 21–24; Contents: Cookies, third-party links, changes, and how to contact us

Part 1 — What we collect and why

1. Data you give us

1.1 Account data. An email address and a password, or the identifier supplied by a third-party sign-in provider where you use one, typically your email address, name, and provider user ID. We never receive your password for a third-party sign-in provider.

1.2 Profile data. Your display name, avatar, and any profile text you choose to provide. Depending on the Platform features you use, information you make public may be visible to other users.

1.3 Optional details for personalisation. Where the Platform asks for information such as age range, date of birth, or content preferences, you may choose whether to provide it where optional. We may use this information to apply age-related rules and personalise your experience.

1.4 Purchase data. Records of purchases you make through the Platform, including the amount, currency, date, product, and transaction identifier provided by our payment processor. We do not receive or store your full card number, CVC, or bank credentials when these are processed directly by a payment provider.

1.5 Support and legal correspondence. What you write to us, including support requests, bug reports, moderation appeals, copyright notices, privacy requests, and other legal correspondence, together with attachments and the email address from which you contact us.

1.6 Reports about other users. When you report content or another user, we collect the information you provide and associate it with the report. Reports may be handled confidentially, but we may need to describe the substance of a report to the person concerned where necessary.

2. Data your stories and creations produce

2.1 Conversation and prompt data. The text you send, the choices you make in stories, prompts you write, and images or other files you upload as context. Collectively, these are "Inputs."

2.2 Generated content. Narrative text, dialogue, images, interactive story content, and other content generated by the Platform in response to your Inputs ("Outputs"), together with metadata needed to reconstruct a session, such as the story, character configuration, and model configuration used.

2.3 Why we store it. We store this information so that a story can be resumed rather than restarted; so that you can review, export, or delete your history where those features are available; so that we can enforce our Terms of Use and investigate reports; so that we can diagnose faults; and so that we can comply with legal obligations.

2.4 Progress and game state. Save points, statistics, relationship states, endings reached, progress information, and credits or other in-app resources consumed during use of the Platform.

2.5 Creations you publish. A story, character, or other creation that you choose to publish, together with its title, description, tags, cover image, prompts where displayed by the Platform, and related metrics. Published Creations may be public.

2.6 Community activity. Comments, likes, follows, shares, ratings, reports, and other community interactions, together with information about accounts or content you interact with.

2.7 Please do not put personal data into Inputs. Inputs are not a suitable place for your real identity information, address, health information, financial information, another person's private information, or anything you would not want stored on our systems or processed by a provider described in Section 8. Our Terms of Use prohibit uploading other people's private or intimate material where prohibited by those Terms.

3. Data we collect automatically

3.1 Device and connection data. IP address, approximate location derived from the IP address, browser type and version where applicable, operating system, language, screen and viewport size, time zone, and device type.

3.2 Usage data. Stories and pages viewed, features used, buttons and links clicked, searches performed within the Platform, session start and end times, referring URL where applicable, and error and crash information.

3.3 Identifiers. Cookie and local-storage identifiers, session identifiers, and account identifiers.

3.4 Security and abuse signals. Login attempts and their outcomes, password reset events, rate-limit and filter triggers, and signals used to detect automation, multiple-account abuse, payment fraud, security incidents, and attempts to circumvent safety systems.

3.5 Inferences. Interests and content preferences that we may infer from your use of the Platform in order to rank recommendations and search results. These are behavioural inferences and are not intended to constitute conclusions about your identity, health, beliefs, or other sensitive characteristics.

4. Data from other sources

4.1 Sign-in providers. If you sign in using a third-party account, that provider may provide us with your email address, provider user ID, and, where permitted by your settings, your name and profile picture. The information shared by the provider is governed by your settings with that provider.

4.2 Payment processors. Our payment processor may provide information such as whether a payment succeeded, limited payment instrument information, billing country, and chargeback or fraud signals. We use this information for receipts, refunds, payment management, and fraud prevention.

4.3 Infrastructure and security providers. Our hosting, CDN, analytics, and anti-abuse providers may provide technical signals about traffic, including whether a request appears automated or originates from a known abusive source.

4.4 Rights holders and authorities. Where someone sends us a copyright notice, legal request, safety report, or other lawful communication, we may receive the information contained in that communication.

5. Why we use personal data

We may use personal data for the following purposes:

  • Create and operate your account; authenticate you — Data used: Account, profile, and identifiers; Legal basis where required: Performance of a contract and/or applicable legal basis
  • Deliver the Platform, including interactive stories and generated content — Data used: Inputs, Outputs, progress, and technical data; Legal basis where required: Performance of a contract
  • Process purchases, receipts, refunds, and account balances — Data used: Purchase and payment data; Legal basis where required: Performance of a contract; legal obligations
  • Publish content you choose to publish and operate community features — Data used: Profile and creation data; community activity; Legal basis where required: Performance of a contract
  • Recommend content and rank search results — Data used: Usage, progress, community, and inferred preference data; Legal basis where required: Legitimate interests and/or consent where required
  • Moderate content, enforce our Terms of Use, and handle reports and appeals — Data used: Support, Inputs, Outputs, reports, and security data; Legal basis where required: Legitimate interests; legal obligations
  • Protect against fraud, abuse, automation, and security incidents — Data used: Technical, purchase, and security data; Legal basis where required: Legitimate interests; legal obligations
  • Protect children and enforce age-related restrictions — Data used: Age-related and technical information; Legal basis where required: Legal obligations and other applicable legal bases
  • Provide customer support — Data used: Support correspondence and account information; Legal basis where required: Performance of a contract; legitimate interests
  • Diagnose faults, measure performance, and improve the Platform — Data used: Technical, usage, Input, Output, and performance data; Legal basis where required: Legitimate interests and/or consent where required
  • Improve model behaviour and safety systems — Data used: De-identified or aggregated Inputs and Outputs where appropriate; Legal basis where required: Legitimate interests, subject to applicable rights and choices
  • Send service communications — Data used: Account information; Legal basis where required: Performance of a contract; legal obligations
  • Send optional marketing communications — Data used: Contact information; Legal basis where required: Consent where required
  • Comply with law and establish, exercise, or defend legal claims — Data used: Data reasonably necessary for the purpose; Legal basis where required: Legal obligation; legitimate interests

5.2 New purposes. If we want to use your data for a materially different purpose, we will update this Privacy Policy and, where required by applicable law, obtain your consent.

5.3 Legitimate interests. Where we rely on legitimate interests as a legal basis, we consider the relevant interests against your rights and freedoms and provide applicable objection rights.

5.4 Aggregated and de-identified data. We may produce statistics and de-identified datasets, such as usage statistics, safety-filter statistics, and performance measurements. Where information is genuinely aggregated or de-identified so that it can no longer reasonably identify you, we may use it for legitimate business purposes without treating it as personal data.

5.5 Human review. A limited number of authorised employees and contractors may access Inputs and Outputs where necessary to investigate a report, respond to a support request, debug a fault, enforce our Terms of Use, or verify that safety systems are operating properly. Access is limited to people who need it and is subject to confidentiality and security obligations.

5.6 Improving the Platform with your content. We may use Inputs and Outputs to improve the Platform, including prompts, safety filters, evaluation systems, and quality measurements. Where reasonably possible, we use de-identified or aggregated material for these purposes. You may contact us at info@fableso.com regarding applicable choices or requests concerning the use of your content for improvement. This does not affect processing required to operate the Platform, maintain security, prevent abuse, or comply with law.

Separately, we do not permit third-party AI providers to use your submitted content to train or fine-tune their own models, subject to the terms and limitations described in Section 8.

6. Sensitive data and what we do not collect

6.1 We do not intentionally request sensitive personal data. We do not intentionally request information such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health information, or information concerning sex life or sexual orientation unless required for a specific lawful purpose.

6.2 But you might provide it. Because you can write freely within the Platform, an Input may contain sensitive information. Where this occurs, we process it only as necessary to provide the feature you requested, maintain safety and security, comply with legal obligations, or for another lawful purpose.

6.3 Account credentials. Login credentials are used for authentication and security. Passwords are stored using appropriate security measures and are not stored in plain text.

6.4 Precise location. We do not intentionally collect GPS-level location through the Platform unless a specific feature clearly requires it and applicable permission is obtained. Where we need to determine your general country or region, we may derive approximate location from your IP address.

6.5 We do not collect government identity documents, biometric identifiers, contact lists, microphone or camera streams, or the contents of your device outside information you voluntarily upload or provide through the Platform.

Part 2 — Who sees your data

7. Service providers

7.1 We use third-party service providers to operate the Platform. They may process personal data only as necessary to provide services to us, subject to applicable contractual, confidentiality, privacy, and security obligations.

7.2 Categories of service providers may include:

  • Hosting, storage, databases, CDN — Data they process: Platform data, at rest and in transit; Provider: Cloud infrastructure providers
  • Generative AI — text and dialogue — Data they process: Inputs and Outputs; Provider: AI model providers
  • Generative AI — images and other generated content — Data they process: Uploaded images, prompts, generated content; Provider: AI model providers
  • Content safety classification — Data they process: Inputs and Outputs as necessary; Provider: AI and safety providers
  • Payment processing — Data they process: Purchase and payment information; Provider: Payment processor selected at checkout
  • Product analytics — Data they process: Technical, usage, and identifier data; Provider: Analytics providers
  • Error and performance monitoring — Data they process: Technical logs and performance data; Provider: Monitoring providers
  • Transactional email — Data they process: Email address and message content; Provider: Email delivery providers
  • Customer support — Data they process: Support correspondence; Provider: Support tooling providers
  • Fraud and abuse prevention — Data they process: Security and technical data; Provider: Security and anti-abuse providers
  • Professional advisers — Data they process: Data necessary for a particular matter; Provider: Lawyers, accountants, auditors, and other advisers

7.3 Changes to providers. We may change or add service providers as necessary to operate and improve the Platform. Where required by applicable law, we will provide information about relevant providers and update this Privacy Policy where the change materially affects how personal data is processed.

8. AI model providers

8.1 What is sent. To generate story content, character responses, images, or other AI-generated content, we may send the relevant Inputs, including the current conversation, story configuration, character configuration, prompts, and images you provide for that request, to the AI provider serving the relevant feature. We may also send technical parameters required to process the request.

We do not intentionally send your password, full payment credentials, or other unrelated account information to an AI provider solely for the purpose of generating content.

8.2 Pseudonymisation. Where technically appropriate, requests to AI providers may be associated with an opaque identifier rather than your direct account details.

8.3 What providers may do. AI providers may process submitted information to provide the requested service and may retain certain information for limited periods for security, abuse prevention, service reliability, or as otherwise permitted under their applicable terms. We seek to use providers whose applicable commercial/API terms do not permit submitted content to be used to train or fine-tune their general-purpose models, where such contractual protections are available.

8.4 What we cannot promise. We select service providers based on their capabilities, contractual terms, security practices, and applicable privacy commitments. However, third-party providers operate systems that we do not directly control. Their own privacy policies and terms may also apply to their processing where they act as independent controllers.

8.5 Self-hosted models. Where we operate an AI model on infrastructure under our control, no separate third-party AI model provider is involved for that processing, although infrastructure providers may still process data as necessary to host the service.

9. Other disclosures

9.1 Legal requests and compliance. We may disclose personal data where legally required or where reasonably necessary to comply with applicable law, a court order, regulatory requirement, or lawful request from a competent authority.

9.2 Safety, rights, and fraud. We may disclose personal data where reasonably necessary to investigate or prevent illegal activity, fraud, security incidents, serious harm, violations of our Terms of Use, or threats to the safety of users or others, or to establish, exercise, or defend legal claims.

9.3 Corporate transactions. If we are involved in a merger, acquisition, financing, reorganisation, insolvency, or sale of assets, personal data may be disclosed to relevant counterparties and advisers under appropriate confidentiality obligations and may transfer as part of the transaction.

9.4 What you make public yourself. Content and information you choose to publish publicly may be visible to other users and, depending on the Platform's configuration, people who are not signed in. Other users may screenshot, copy, or archive public content. Removing content from the Platform does not necessarily remove copies that others may have retained.

9.5 Affiliates. Where we have affiliated companies under common control, we may share personal data with them for the purposes described in this Privacy Policy, subject to applicable law.

10. What we do not do

10.1 We do not sell your personal data.

10.2 We do not intentionally share your personal data for cross-context behavioural advertising except where our practices change and applicable law requires us to provide an appropriate notice and choice mechanism.

10.3 We do not permit third-party AI providers to train their own models on your content except where you have separately and knowingly agreed to such processing or applicable law otherwise requires or permits it.

10.4 We do not knowingly use children's data for targeted advertising.

10.5 We do not read your conversations for marketing purposes. Human access is limited to the purposes described in this Privacy Policy.

10.6 We do not use your data to make decisions about your credit, employment, insurance, or housing, and we do not knowingly supply it to entities for those purposes.

Part 3 — Your choices and your rights

11. Controls inside the Platform

Where these controls are available in your version of the Platform:

  • See and change your account details — Where: Account Settings
  • Change your display name, avatar, or profile — Where: Profile Settings
  • Review, export, or delete story history — Where: Data or Account Settings
  • Manage privacy-related choices — Where: Privacy Settings
  • Manage cookie and analytics preferences — Where: Cookie settings, where available
  • Unsubscribe from marketing email — Where: Unsubscribe link or notification settings
  • Unpublish or delete a Creation — Where: The Creation's settings
  • Delete your account and associated data — Where: Account Settings

If a control listed above is not available in your version of the Platform, you may contact us at info@fableso.com with the subject line "Privacy Request", and we will process the request according to applicable law.

12. Your rights

Depending on the applicable law, you may have rights including:

12.1 Access. Request information about the personal data we process about you and, where applicable, receive a copy.

12.2 Portability. Where required by applicable law, receive certain personal data in a structured, commonly used, and machine-readable format.

12.3 Correction. Request correction of inaccurate or incomplete personal data.

12.4 Deletion. Request deletion of your personal data, subject to legal exceptions and legitimate retention requirements.

12.5 Restriction. Request restriction of processing where applicable law provides this right.

12.6 Objection. Object to certain processing based on legitimate interests or other applicable legal grounds.

12.7 Withdraw consent. Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

12.8 Complaint. You may have the right to lodge a complaint with the competent data protection authority.

12.9 Not absolute. These rights are subject to limitations under applicable law. We may refuse or partially refuse a request where legally permitted or required, where responding would adversely affect another person's rights, or where we cannot reasonably verify the requester's identity.

13. Rights that depend on where you are

13.1 Türkiye. If the KVKK applies to you, you may have the rights provided under applicable provisions of the KVKK, including rights relating to learning whether personal data is processed, requesting information about processing, learning the purpose of processing and whether it is used consistently with that purpose, knowing the third parties to whom personal data is transferred domestically or abroad, requesting correction, requesting deletion or destruction where the legal requirements are met, requesting notification of correction or deletion to relevant third parties, objecting to adverse results arising from analysis of processed data exclusively by automated systems where applicable, and requesting compensation for damages arising from unlawful processing where applicable.

13.2 European Economic Area and United Kingdom. Where the GDPR or UK GDPR applies to you, you may have the rights provided by those laws, including access, correction, deletion, restriction, objection, portability, withdrawal of consent, and rights relating to certain automated decision-making. You may also have the right to lodge a complaint with your relevant supervisory authority.

13.3 United States. Depending on the state in which you reside, you may have additional privacy rights, including rights to know, access, delete, correct, obtain a portable copy of certain personal data, and opt out of certain types of processing where applicable.

13.4 Canada and elsewhere. Where another privacy or data protection law applies to you, we will honour the rights provided by that law to the extent required.

13.5 Authorised agents and representatives. Where permitted by applicable law, an authorised representative may submit a request on your behalf. We may require reasonable evidence of that authority and may still verify your identity as required.

14. Making a privacy request

14.1 How. Contact info@fableso.com with the subject line "Privacy Request" and tell us which right you are exercising and, where necessary, the email address associated with your account.

14.2 Verification. We may verify your identity in proportion to the nature and sensitivity of your request. We will generally use information already associated with your account for verification and will not request unnecessary identity documents.

14.3 Timing. We will acknowledge and respond to requests within the period required by applicable law. Where an extension is legally permitted and necessary, we will inform you accordingly.

14.4 Cost. Requests are generally handled without charge unless applicable law permits a reasonable fee or permits us to refuse a manifestly unfounded, excessive, or repetitive request.

14.5 What deletion actually does. Where a deletion request is valid, we will delete or de-identify personal data from our active systems, subject to information that we are legally required or otherwise legitimately permitted to retain. Backups may retain information temporarily until they are overwritten in accordance with our normal backup cycles.

15. Appeals

15.1 If we refuse a privacy request or you disagree with how we handled it, you may contact info@fableso.com with the subject line "Privacy Appeal". We will review the matter and respond within the period required by applicable law.

15.2 If you remain dissatisfied, you may contact the relevant data protection or consumer protection authority available to you under applicable law.

Part 4 — How we look after your data

16. How long we keep it

16.1 We keep personal data only for as long as reasonably necessary for the purposes described in Section 5, unless a longer retention period is required or permitted by law.

16.2 Retention periods may vary by category. Account and profile information may be retained while your account is active and for a reasonable period after closure where necessary. Conversations, prompts, Outputs, and progress may be retained until you delete them, delete your account, or until they are no longer needed for the purposes described in this Policy, subject to legal requirements. Purchase and tax records may be retained for periods required by applicable accounting, tax, and financial laws. Support, moderation, security, and fraud records may be retained for as long as reasonably necessary to resolve the relevant matter, enforce our Terms of Use, prevent repeat abuse, or comply with legal obligations.

16.3 Legal holds. Where information is relevant to a legal claim, regulatory matter, investigation, or legal preservation obligation, we may retain it for as long as necessary to satisfy that obligation.

17. Security

17.1 What we do. We use reasonable technical and organisational measures designed to protect personal data, which may include encryption in transit and at rest, access controls, password protection, separation of environments, security monitoring, patching, and contractual security requirements for relevant service providers.

17.2 What we cannot do. No method of transmission or storage over the internet is completely secure. We take reasonable measures to protect your information but cannot guarantee absolute security.

17.3 Your part. Choose a strong password, do not reuse your password on other services, keep your credentials confidential, and contact us at info@fableso.com if you suspect unauthorised access to your account.

17.4 If something happens. If a security incident affects your personal data and applicable law requires notification, we will notify affected users and/or authorities as required by law.

18. International transfers

18.1 Where processing happens. FABLESO YAZILIM VE MÜHENDİSLİK ANONİM ŞİRKETİ is established in Türkiye. Depending on the service providers we use, personal data may be processed in Türkiye, the European Economic Area, the United States, or other countries.

18.2 Safeguards for international transfers. Where personal data is transferred internationally, we will use the transfer mechanisms and safeguards required by applicable data protection law, including the KVKK and, where applicable, GDPR or other relevant legislation.

18.3 What this means in practice. A transfer may mean that your personal data is processed in a country whose data protection laws differ from those in your country of residence. We take reasonable steps to ensure appropriate contractual, technical, and organisational safeguards are used where required.

18.4 Information about safeguards. You may contact us at info@fableso.com if you would like additional information about applicable international transfer safeguards, subject to legitimate confidentiality restrictions.

19. Children and age assurance

19.1 Minimum age. The Platform is not directed to children under 13, and users under 13 may not use the Platform. Where applicable law establishes a higher minimum age or additional consent requirements, those requirements apply.

19.2 If it happens anyway. If we learn that an account belongs to a child below the applicable minimum age, we may close the account and delete the associated personal data, subject to applicable legal requirements.

19.3 Parents and guardians. A parent or legal guardian may contact us at info@fableso.com regarding a child's personal data where permitted by applicable law. We may take reasonable steps to verify the requester's authority.

19.4 Age assurance for mature content. Access to mature-labelled content, where available, requires that the user is 18 or older. We may use self-declaration, age-related information provided by the user, or other lawful signals to enforce age restrictions. We may introduce stronger age-assurance measures where required by applicable law, an app store, or a payment provider.

19.5 Content involving minors. Our Terms of Use prohibit content that sexualises minors, including fictional or AI-generated depictions. Where we detect or receive a report concerning potentially illegal child sexual abuse material, we may preserve relevant records and make disclosures to law enforcement or appropriate authorities where required or permitted by law.

19.6 Under-18 data and advertising. We do not knowingly use the personal data of users under 18 for targeted advertising where prohibited by applicable law.

20. Automated processing and AI decisions

20.1 Where automation is involved. Parts of the Platform may operate automatically, including generation of AI Outputs, recommendation and search ranking, content classification, and safety or abuse detection.

20.2 Consequences. Automated safety systems may label, hide, restrict, or block content, limit features, or flag accounts for review. Where required by applicable law, users may have rights to request human review or challenge certain decisions.

20.3 Your rights over these decisions. Where applicable law provides rights concerning solely automated decisions that have legal or similarly significant effects, you may exercise those rights through the complaint and privacy-request processes described in this Policy.

20.4 AI transparency. The Platform uses artificial intelligence to generate certain content and interactions. We may identify AI-generated content or AI interactions where required by applicable law.

20.5 No sensitive profiling. We do not intentionally profile users based on sensitive characteristics such as race, ethnicity, religion, health, sexual orientation, political opinion, or trade union membership for advertising or similar purposes.

Part 5 — Practical matters

21. Cookies and similar technologies

21.1 What we use. Depending on how you access the Platform, we may use cookies, local storage, and similar technologies for:

  • Strictly necessary — What it does: Sign you in, maintain your session, remember consent choices, protect against fraud and abuse, and maintain service functionality; Can you refuse?: Generally no
  • Functional — What it does: Remember preferences such as language, theme, filters, and other settings; Can you refuse?: Where available, yes
  • Analytics — What it does: Help us understand feature usage and performance; Can you refuse?: Where available, yes

21.2 Advertising cookies. We do not intentionally use third-party advertising or cross-site tracking cookies unless our practices change and appropriate notices and choices are provided where required by law.

21.3 Your controls. Where cookie settings are available, you may use them to manage optional cookies. Your browser may also allow you to block or delete cookies, although blocking necessary cookies may affect Platform functionality.

21.4 Global Privacy Control. Where required by applicable law, we may recognise applicable Global Privacy Control or similar legally recognised privacy signals as an opt-out request.

21.5 Lifetime. Cookies and similar identifiers have limited lifetimes appropriate to their purposes, and analytics identifiers may be rotated or deleted periodically.

22. Other sites and services

22.1 The Platform may contain links to third-party websites or services that we do not control. Their privacy practices are governed by their own privacy policies, and this Privacy Policy does not cover their processing.

22.2 Where you sign in through a third-party provider or pay through a third-party payment processor, that provider's own privacy policy may apply to its processing of your personal data as an independent controller.

23. Changes to this Policy

23.1 We may update this Privacy Policy when our practices change, when we add new service providers or processing purposes, or when required by law.

23.2 If a change materially affects your rights or materially changes how we use personal data, we will provide reasonable notice through the Platform, by email, or through another appropriate communication method where required by applicable law.

23.3 Previous versions of this Privacy Policy may be retained for record-keeping purposes. You may contact us at info@fableso.com to request information about previous versions where appropriate.

24. How to contact us

Everything relating to this Privacy Policy — including privacy questions, rights requests, appeals, security reports, legal notices, and general privacy-related support — can be directed to:

FABLESO YAZILIM VE MÜHENDİSLİK ANONİM ŞİRKETİ

Email: info@fableso.com

Registered address:
ÜNIVERSITELER MAH. 1597 CADDE KÜME EVLER NO:43 İÇ KAPI NO: 36
ÇANKAYA / ANKARA
TÜRKİYE

Data Controller:
FABLESO YAZILIM VE MÜHENDİSLİK ANONİM ŞİRKETİ

Privacy Contact:
info@fableso.com

Relevant Data Protection Authority in Türkiye:
Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu — KVKK)

Where the GDPR, UK GDPR, or another data protection law applies to you, you may also have the right to contact the supervisory authority applicable to your jurisdiction.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top. Your continued use of the Apps constitute your continued consent to the Terms of Use and the Privacy Policy. Changes take effect immediately when posted unless otherwise stated.

Contact Us

FABLESO YAZILIM VE MÜHENDİSLİK ANONİM ŞİRKETİ

Email: info@fableso.com

Address: ÜNIVERSITELER MAH. 1597 CADDE KÜME EVLER NO:43 İÇ KAPI NO: 36
ÇANKAYA / ANKARA