Instagram / Meta veri silme: adım adım talimat 5. bölümde — okumak için giriş gerekmez.
Privacy Policy
Last updated: August 22, 2026
HAWK AI ("HAWK", "we") respects your privacy. This policy explains what personal data we collect, why and how we process it, and your rights under KVKK (Law No. 6698) and the GDPR. It also serves as our App Store / Google Play data disclosure.
1. Data we collect
- Account: email address, name, and password (stored only as a hash — never in plain text). If you use "Continue with Google/Apple", we receive your email and name from that provider.
- Chat & content: the messages you send to HAWK, files and images you upload, and voice input (converted to text). This content is processed to generate AI responses.
- Voice/audio: when you use voice typing or voice chat, audio is sent to our server, transcribed to text, and then deleted (not stored as audio).
- Location (optional): only if you grant permission — used for weather and location-based answers. It is used at the moment of the request and is not stored. If you deny it, that feature simply doesn't run.
- Identifiers & usage: an account/user identifier, language preference, and functional usage counters (e.g. quota). We do not collect the advertising identifier (IDFA) or a device advertising ID.
- Purchases: your subscription/purchase status. In-app purchases are processed by Apple App Store (iOS) or Google Play (Android); on the web by our payment provider (Lemon Squeezy). We do not store your card details.
2. How we use your data
- To generate AI answers, analyze files/images, and provide voice chat.
- To manage your account, keep the service secure, and prevent abuse.
- To operate and improve the service and meet legal obligations.
- We do not sell your data. We use no third‑party advertising or cross‑app/website tracking.
3. Third‑party AI processors & your explicit consent
We ask for your explicit in‑app permission before any of your content is sent to a third‑party AI provider. If you do not grant permission, no request is sent to the providers below and the features that depend on them will not work. Features that run on HAWK's own servers (speech‑to‑text with Whisper, text‑to‑speech with Piper, text extraction from PDF/DOCX/XLSX, your account and privacy settings) remain available. You can grant or withdraw permission at any time at Settings › Privacy & Data Permissions.
Your chat messages are answered by HAWK's own language model — we do not send your chat to another company's AI model. That model runs on third‑party GPU infrastructure, so the infrastructure provider is listed below as a data processor.
| Provider | Purpose | Data that may be sent |
|---|---|---|
| RunPod, Inc. | GPU infrastructure running HAWK's own model (Qwen2.5‑32B) | text prompts, conversation history, images, text extracted from files |
| OpenAI, L.L.C. | Live voice conversation (Realtime API); speech‑to‑text if local processing fails; image generation if our GPU and the free provider are unavailable | your voice audio and its transcript during a live call; image prompts |
| Microsoft Corporation (Edge TTS) | Text‑to‑speech when the local voice engine is unavailable | the assistant's reply text |
| Brave Software, Inc. | Web search | your search query only |
| Pollinations.AI | Image generation when our own GPU is busy | your image prompt only |
| Supabase, Inc. | Cloud backup of persistent memory records | memory facts you asked HAWK to remember |
Payments are handled by Apple, Google or Lemon Squeezy. Files may be stored in our object storage (Cloudflare R2). We use no analytics, crash‑reporting or advertising SDKs, and we do not sell your data. If we ever add a new AI provider, this list changes and you will be asked for permission again — data is never sent silently to a new company.
4. Instagram / Meta integration (optional)
HAWK can connect to an Instagram professional (Business / Creator) account so that the owner of that account can read and answer the comments and direct messages arriving on their own account from inside HAWK. The integration is optional — HAWK works without it — and it is active only while an account owner has explicitly connected an account.
4.1 What we receive from Instagram / Meta
- Account identity: the connected Instagram account's ID and username, and the ID of the Facebook Page linked to it.
- Comments on that account's own posts: the comment ID, the commenter's Instagram ID/username, the comment text and its timestamp.
- Direct messages sent to that account: the message ID, the sender and recipient IDs, the message text and its timestamp.
- Account insights (e.g. reach, view counts): requested from Meta's API at the moment they are shown. We store only whether the insights permission works — not the metric values.
- Access token: the long‑lived access token Meta issues for the connected account.
4.2 Why we process it
Solely so that the account owner can see and answer the comments and messages that arrive on their own account. Replies are written or approved by the account owner and sent back to Instagram through Meta's API. This data is not used for advertising, profiling, audience building or resale, and it is not used to train any AI model.
4.3 Where and how it is stored
- It stays in our own server database. Every record is scoped to the account owner and every query is filtered by that scope, so one owner cannot reach another owner's data.
- The access token is stored only in encrypted form (AES‑256‑GCM). If the encryption key is unavailable, the connection is refused rather than falling back to storing the token in plain text.
- The token never appears in any screen, API response, log file or browser storage. Interfaces show only a non‑reversible 12‑character fingerprint (a SHA‑256 prefix), which is enough to recognise a connection without revealing the token.
- Comments and direct messages delivered by Meta's webhook are stored so the owner can read them and reply. Incoming webhook calls are signature‑verified; unsigned events are quarantined and pruned.
- When a token is replaced, up to five previous tokens are kept — still encrypted — so a mistaken re‑connection can be rolled back.
4.4 How long we keep it
Until the account owner removes the connection or asks us to delete the data (see section 5). Comment and message records remain available in the owner's inbox until they are deleted that way; we do not apply an automatic expiry to them.
4.5 Sharing
Instagram / Meta data is not sold and not transferred to third parties, is not used for advertising or profiling, and is not used for AI model training. The only outbound transfer is back to Meta itself, when the account owner sends a reply to a comment or a message.
5. How to delete your Instagram / Meta data
Option A — remove the connection inside HAWK (effective immediately)
- Sign in at https://www.hawk-operasyon.com with the account that created the connection.
- Open the Instagram panel at /admin/instagram.
- Press "Delete Token" and confirm the dialog.
- The stored access token is deleted at once and the integration's automation switch is forced off. From that moment HAWK can no longer read anything from, or write anything to, the Instagram account.
Option B — ask us to erase everything by email (no login needed)
- Send an email to ***KISISEL-VERI-TEMIZLENDI*** with the subject "Instagram data deletion".
- State the Instagram username that was connected, so that we can locate the records.
- We erase every item listed below and confirm by reply. Requests are completed within 30 days — in practice usually within a few business days.
Option C — remove HAWK from Instagram / Facebook
In the Instagram or Facebook app open Settings › Apps and websites (or Business integrations) and remove HAWK. Meta then invalidates the access token, so HAWK loses access immediately. To also erase the records already stored on our side, use Option A or Option B.
What the deletion covers
- the encrypted access token of the connected account, and the encrypted backups of previous tokens;
- the account identity record: Instagram account ID, username, linked Page ID, measured capabilities and the automation flag;
- the stored comment and direct‑message records of that account: comment/message IDs, sender and recipient IDs, message text and the raw event payloads;
- the webhook delivery and diagnostic records belonging to that connection.
What each option actually reaches: Option A deletes the live access token immediately and ends all access, but the comment/message records already received and the encrypted backups of previous tokens are removed through Option B. If you want everything gone, send the email described in Option B — a single request covers all four items above.
Deleting your whole HAWK account (Settings › Account) removes your HAWK account data as described in section 6; the Instagram integration records are covered by Option A / Option B above.
6. Retention, deletion & withdrawing consent
You can permanently delete your account from inside the app — no email or support request is required: Settings › Account › Permanently Delete My Account. You will be asked to re‑authenticate and to confirm explicitly. Deletion is immediate and irreversible.
What is deleted: profile and account details, chat history, uploaded files and images, audio recordings and voice sessions, personal memory records, device pairings, session and refresh tokens, Workspace projects and tasks, notification subscriptions, usage and quota records. If you signed in with Apple, your Apple token is revoked.
What is retained, and why: financial records (amount and date) are kept where required by law, but the link to your identity is removed. Abuse‑prevention blocks are kept as a one‑way hash so you cannot be identified from them while the block remains effective.
Retention while your account is active: chat history and memory records are kept until you delete them or delete your account. Security and audit logs are kept up to 90 days. Temporary AI provider transfers are not stored by us beyond what is needed to return the answer.
Withdrawing consent: go to Settings › Privacy & Data Permissions and choose "Don't Allow". New transfers to the providers above stop immediately.
7. Your KVKK & GDPR rights
You have the right to access, correct, delete, restrict processing of, port, and object to the processing of your data. Contact us to exercise these rights. Under the GDPR you may also lodge a complaint with your supervisory authority.
8. Security
Passwords are hashed, traffic is encrypted with TLS, access is protected by authorization (JWT), and user data is isolated between accounts.
9. Children's privacy
HAWK is not directed to children under 13, and we do not knowingly collect data from them.
10. Changes & contact
We may update this policy and will notify you of material changes. Questions: ***KISISEL-VERI-TEMIZLENDI***
Gizlilik Politikası
Son güncelleme: 22 Ağustos 2026
HAWK AI ("HAWK", "biz") olarak gizliliğine önem veriyoruz. Bu politika hangi kişisel verileri topladığımızı, neden ve nasıl işlediğimizi ve KVKK (6698) ile GDPR kapsamındaki haklarını açıklar. Aynı zamanda App Store / Google Play veri açıklamamızdır.
1. Topladığımız veriler
- Hesap: e‑posta, ad, şifre (yalnızca hash — düz metin saklanmaz). "Google/Apple ile devam et" kullanırsan e‑posta ve adını sağlayıcıdan alırız.
- Sohbet & içerik: HAWK'a yazdığın mesajlar, yüklediğin dosya/görseller, sesli girdi (metne çevrilir). Bu içerik yapay zeka yanıtı üretmek için işlenir.
- Ses: sesli yazma/sohbet kullandığında ses sunucumuza gönderilir, metne çevrilir ve silinir (ses olarak saklanmaz).
- Konum (opsiyonel): yalnızca izin verirsen — hava durumu ve konum tabanlı yanıtlar için. İstek anında kullanılır, saklanmaz. İzin vermezsen bu özellik çalışmaz.
- Tanımlayıcı & kullanım: hesap/kullanıcı kimliği, dil tercihi, işlevsel kullanım sayaçları (ör. kota). Reklam kimliğini (IDFA) veya reklam amaçlı cihaz kimliğini toplamayız.
- Satın alma: abonelik/satın alma durumun. Uygulama içi satın almalar Apple App Store (iOS) veya Google Play (Android); web'de ödeme sağlayıcımız (Lemon Squeezy) üzerinden işlenir. Kart bilgin bizde saklanmaz.
2. Verileri nasıl kullanıyoruz
- Yapay zeka yanıtları üretmek, dosya/görsel analiz etmek, sesli sohbet sağlamak.
- Hesabını yönetmek, güvenliği sağlamak, kötüye kullanımı önlemek.
- Hizmeti işletmek, iyileştirmek ve yasal yükümlülükleri yerine getirmek.
- Verilerini satmayız. Üçüncü taraf reklam veya uygulamalar/siteler arası izleme kullanmayız.
3. Üçüncü taraf yapay zekâ sağlayıcıları ve açık rızan
İçeriğin herhangi bir üçüncü taraf yapay zekâ sağlayıcısına gönderilmeden önce uygulama içinde açık iznini isteriz. İzin vermezsen aşağıdaki sağlayıcılara hiçbir istek gönderilmez ve onlara bağlı özellikler çalışmaz. HAWK'ın kendi sunucusunda çalışan özellikler (Whisper ile ses→metin, Piper ile metin→ses, PDF/DOCX/XLSX'ten metin çıkarma, hesap ve gizlilik ayarların) kullanılabilir olmaya devam eder. İzni dilediğin zaman Ayarlar › Gizlilik ve Veri İzinleri bölümünden verebilir veya geri çekebilirsin.
Sohbet mesajların HAWK'ın KENDİ dil modeliyle cevaplanır — sohbetini başka bir şirketin yapay zekâ modeline göndermeyiz. O model üçüncü taraf GPU altyapısında çalıştığı için altyapı sağlayıcısı aşağıda veri işleyen taraf olarak listelenmiştir.
| Sağlayıcı | Amaç | Gönderilebilecek veri |
|---|---|---|
| RunPod, Inc. | HAWK'ın kendi modelini (Qwen2.5‑32B) çalıştıran GPU altyapısı | yazdığın metinler, sohbet geçmişin, görseller, dosyalardan çıkarılan metin |
| OpenAI, L.L.C. | Canlı sesli görüşme (Realtime API); yerel ses çözümü başarısız olursa ses→metin; kendi GPU'muz ve ücretsiz sağlayıcı çalışmıyorsa görsel üretme | canlı görüşme sırasındaki sesin ve konuşma metni; görsel tarifin |
| Microsoft Corporation (Edge TTS) | Yerel ses motoru kullanılamadığında metin→ses seslendirme | HAWK'ın cevap metni |
| Brave Software, Inc. | Web araması | yalnız arama sorgun |
| Pollinations.AI | Kendi GPU'muz meşgulken görsel üretme | yalnız görsel tarifin |
| Supabase, Inc. | Kalıcı hafıza kayıtlarının bulut yedeği | HAWK'tan hatırlamasını istediğin bilgiler |
Ödemeler Apple, Google veya Lemon Squeezy tarafından işlenir. Dosyalar nesne depomuzda (Cloudflare R2) tutulabilir. Analytics, crash‑raporlama veya reklam SDK'sı kullanmayız ve verilerini satmayız. İleride yeni bir yapay zekâ sağlayıcısı eklersek bu liste değişir ve iznin yeniden istenir — yeni bir şirkete sessizce veri gönderilmez.
4. Instagram / Meta entegrasyonu (opsiyonel)
HAWK bir Instagram profesyonel (Business / Creator) hesabına bağlanabilir; böylece hesap sahibi kendi hesabına gelen yorumları ve doğrudan mesajları HAWK içinden okuyup yanıtlayabilir. Bu entegrasyon opsiyoneldir — HAWK onsuz da çalışır — ve yalnızca bir hesap sahibi açıkça bağlantı kurduğu sürece etkindir.
4.1 Instagram / Meta'dan aldığımız veriler
- Hesap kimliği: bağlanan Instagram hesabının kimliği (ID) ve kullanıcı adı, hesaba bağlı Facebook sayfasının kimliği.
- Hesabın kendi gönderilerine gelen yorumlar: yorum kimliği, yorumu yazan kişinin Instagram kimliği/kullanıcı adı, yorum metni ve zamanı.
- Hesaba gelen doğrudan mesajlar: mesaj kimliği, gönderen ve alıcı kimlikleri, mesaj metni ve zamanı.
- Hesap içgörüleri (ör. erişim, görüntülenme sayıları): gösterildiği anda Meta API'sinden istenir. Biz yalnızca içgörü izninin çalışıp çalışmadığını saklarız — metrik değerlerini değil.
- Erişim jetonu: Meta'nın bağlanan hesap için verdiği uzun ömürlü erişim jetonu.
4.2 Niçin işliyoruz
Yalnızca hesap sahibinin kendi hesabına gelen yorum ve mesajları görüp yanıtlayabilmesi için. Yanıtlar hesap sahibi tarafından yazılır veya onaylanır ve Meta API'si üzerinden Instagram'a geri gönderilir. Bu veriler reklam, profilleme, kitle oluşturma veya satış için kullanılmaz ve hiçbir yapay zekâ modelinin eğitiminde kullanılmaz.
4.3 Nerede ve nasıl saklanıyor
- Veriler kendi sunucu veritabanımızda kalır. Her kayıt hesap sahibine bağlı bir kapsamla tutulur ve her sorgu bu kapsama göre süzülür; bir sahip başka bir sahibin verisine erişemez.
- Erişim jetonu yalnızca şifreli olarak (AES‑256‑GCM) saklanır. Şifreleme anahtarı yoksa bağlantı reddedilir; jeton düz metin olarak saklanmaya ASLA düşülmez.
- Jeton hiçbir arayüzde, hiçbir API cevabında, günlük dosyasında veya tarayıcı deposunda görünmez. Arayüzler yalnızca geri döndürülemez 12 karakterlik bir parmak izi (SHA‑256 ön eki) gösterir; bu, jetonu açığa çıkarmadan bağlantıyı tanımaya yeter.
- Meta webhook'u ile gelen yorum ve mesajlar, sahibi okuyup yanıtlayabilsin diye kaydedilir. Gelen webhook çağrıları imza doğrulamasından geçer; imzasız olaylar karantinaya alınır ve budanır.
- Jeton değiştirildiğinde önceki en fazla beş jeton — yine şifreli olarak — saklanır; yanlış bir yeniden bağlanma geri alınabilsin diye.
4.4 Ne kadar süre saklanıyor
Hesap sahibi bağlantıyı kaldırana ya da verinin silinmesini talep edene kadar (bkz. 5. bölüm). Yorum ve mesaj kayıtları, bu yolla silinene kadar sahibin gelen kutusunda kalır; bunlara otomatik bir süre sonu uygulamıyoruz.
4.5 Paylaşım
Instagram / Meta verisi satılmaz ve üçüncü taraflara aktarılmaz, reklam veya profilleme için kullanılmaz, yapay zekâ modeli eğitiminde kullanılmaz. Tek dışa aktarım, hesap sahibi bir yoruma veya mesaja yanıt gönderdiğinde bu yanıtın Meta'ya geri iletilmesidir.
5. Instagram / Meta verini nasıl sildirirsin
A yolu — bağlantıyı HAWK içinden kaldır (anında etkili)
- https://www.hawk-operasyon.com adresine, bağlantıyı kuran hesapla giriş yap.
- /admin/instagram adresindeki Instagram panelini aç.
- "Jetonu Sil" düğmesine bas ve onay penceresini onayla.
- Kayıtlı erişim jetonu anında silinir ve entegrasyonun otomasyon anahtarı zorla kapatılır. O andan itibaren HAWK Instagram hesabından hiçbir şey okuyamaz ve hesaba hiçbir şey yazamaz.
B yolu — e‑posta ile tamamının silinmesini iste (giriş gerekmez)
- ***KISISEL-VERI-TEMIZLENDI*** adresine "Instagram veri silme" konusuyla e‑posta gönder.
- Kayıtları bulabilmemiz için bağlanmış olan Instagram kullanıcı adını yaz.
- Aşağıda sayılan her kaydı sileriz ve cevaben teyit ederiz. Talepler en geç 30 gün içinde tamamlanır; uygulamada genellikle birkaç iş günü sürer.
C yolu — HAWK'ı Instagram / Facebook tarafından kaldır
Instagram veya Facebook uygulamasında Ayarlar › Uygulamalar ve web siteleri (ya da İşletme entegrasyonları) bölümünden HAWK'ı kaldır. Meta bu durumda erişim jetonunu geçersiz kılar; HAWK erişimini anında kaybeder. Bizde hâlihazırda kayıtlı verilerin de silinmesi için A veya B yolunu kullan.
Silme neleri kapsar
- bağlanan hesabın şifreli erişim jetonu ve önceki jetonların şifreli yedekleri;
- hesap kimlik kaydı: Instagram hesap kimliği, kullanıcı adı, bağlı sayfa kimliği, ölçülen yetenekler ve otomasyon bayrağı;
- o hesaba ait kayıtlı yorum ve doğrudan mesaj kayıtları: yorum/mesaj kimlikleri, gönderen ve alıcı kimlikleri, mesaj metni ve ham olay yükleri;
- o bağlantıya ait webhook teslimat ve teşhis kayıtları.
Hangi yol neye ulaşır (olduğu gibi): A yolu canlı erişim jetonunu anında siler ve tüm erişimi bitirir; ancak daha önce alınmış yorum/mesaj kayıtları ile önceki jetonların şifreli yedekleri B yolu ile silinir. Her şeyin silinmesini istiyorsan B yolundaki e‑postayı gönder — tek talep yukarıdaki dört kalemin tamamını kapsar.
HAWK hesabının tamamını silmek (Ayarlar › Hesap) HAWK hesap verilerini 6. bölümde anlatıldığı gibi kaldırır; Instagram entegrasyonu kayıtları yukarıdaki A / B yolu ile silinir.
6. Saklama, silme ve izni geri çekme
Hesabını uygulama içinden kalıcı olarak silebilirsin — e‑posta yazmak veya destek talebi açmak GEREKMEZ: Ayarlar › Hesap › Hesabımı Kalıcı Olarak Sil. Kimliğini yeniden doğrulaman ve açıkça onaylaman istenir. Silme anında gerçekleşir ve geri alınamaz.
Silinenler: profil ve hesap bilgilerin, sohbet geçmişin, yüklediğin dosyalar ve görseller, ses kayıtların ve ses oturumların, kişisel hafıza kayıtların, cihaz eşleştirmelerin, oturum ve yenileme token'ların, Workspace projelerin ve görevlerin, bildirim aboneliklerin, kullanım ve kota kayıtların. Apple ile giriş yaptıysan Apple token'ın iptal edilir.
Saklananlar ve gerekçesi: mali kayıtlar (tutar ve tarih) yasal zorunluluk gereği kalır ancak kimliğinle bağı koparılır. Kötüye kullanım engelleri tek yönlü hash olarak kalır; bu kayıtlardan kimliğin belirlenemez ama engel etkili olmaya devam eder.
Hesabın aktifken saklama: sohbet geçmişin ve hafıza kayıtların sen silene ya da hesabını silene kadar saklanır. Güvenlik ve denetim kayıtları en fazla 90 gün tutulur. Yapay zekâ sağlayıcılarına yapılan geçici aktarımlar, cevabı döndürmek için gerekenin ötesinde bizde saklanmaz.
İzni geri çekme: Ayarlar › Gizlilik ve Veri İzinleri bölümünden "İzin Verme" seçeneğini işaretle. Yukarıdaki sağlayıcılara yeni aktarım anında durur.
7. KVKK & GDPR hakların
Verilerine erişme, düzeltme, silme, işlemeyi kısıtlama, taşınabilirlik ve itiraz hakkına sahipsin. Bu hakları kullanmak için bizimle iletişime geç. GDPR kapsamında ilgili denetim otoritesine şikâyet hakkın saklıdır.
8. Güvenlik
Şifreler hash'lenir, iletişim TLS ile şifrelenir, erişim yetkilendirme (JWT) ile korunur, kullanıcı verileri birbirinden izole edilir.
9. Çocukların gizliliği
HAWK 13 yaş altı çocuklara yönelik değildir; bilerek bu yaş grubundan veri toplamayız.
10. Değişiklikler & iletişim
Bu politikayı güncelleyebiliriz; önemli değişiklikleri bildiririz. Sorular için: ***KISISEL-VERI-TEMIZLENDI***
This document is provided for general information / Bu metin genel bilgilendirme amaçlıdır.