SYNOVA — Privacy Policy
- Publisher
- Hakan Timur — a natural person (sole proprietor) trading as Noriloop Studio
- Postal address
- Yenişehir Konakları, 979. Sokak 14G Daire 6, 26000 Tepebaşı, Eskişehir, Türkiye
- Contact email
- [email protected]
- Application
- SYNOVA (application id com.noriloop.synova)
- Effective date
- 6 September 2026
- Last updated
- 6 September 2026
1. Who we are
SYNOVA ("the App") is a cognitive training application published by the Publisher named in the identity block at the top of this document ("we", "us", "our"). Every reference below to the Publisher, to our address and to our contact address means the values given in that block, which is the only place in this document where any of them appears.
The Publisher is an individual — a natural person acting as a sole proprietor, not a company. For the purposes of the EU/UK General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law No. 6698 (KVKK), that individual is the data controller for any personal data described in this policy.
You can reach us at the contact email address given in the identity block above.
2. The short version
SYNOVA does not collect your personal data.
Everything the App records about your training — your scores, your streak, your history, your settings — is stored in a database file on your own device and is never sent to us or to anyone else. We do not operate a server that holds your data, because the App does not send data anywhere. We cannot see your results. There is no account, no sign-up, and no login.
The rest of this policy explains that in detail, and explains what would change if we add features that do involve sending data.
3. No account is required
The App has no account system. You do not create an account, you do not provide an email address or a password, and you do not sign in. You use SYNOVA anonymously.
To keep your own training history consistent on your own device, the App generates two random identifiers the first time you open it:
- a local installation identifier, used to associate your saved sessions with the installation on this device; and
- a public player identifier, reserved for a future feature (such as a leaderboard) in which you might choose to appear to other players.
Both are randomly generated values. They are not derived from your device's hardware, your advertising identifier, your phone number, or any account you hold anywhere. Neither of them is transmitted anywhere today, and the public identifier is not currently displayed to anyone, because the feature that would use it is not enabled.
4. What is stored on your device
The App stores the following on your device, and only on your device:
Training data
- The results of each exercise you play: which exercise, which cognitive category, difficulty, accuracy, correct/incorrect/skipped counts, duration, the score awarded, and when the session started and ended.
- A small set of numeric, per-exercise diagnostic measurements. These are numbers only — the field is technically incapable of holding text — and are limited in size by the App.
- Your daily workout plans and which exercises within them you have completed.
- Your Brain Score, your per-category scores, and a dated history of them.
- The App's estimate of your ability at each exercise, used to set difficulty.
- The calendar days credited to your training streak.
- Achievements you have unlocked and your progress toward challenges.
- Your experience points and level.
Preferences
- Your theme and language preferences.
- Your reminder and notification preferences.
- Which exercises you have marked as favourites.
- A record of whether you have completed onboarding and the baseline calibration.
Technical
- The two random identifiers described in §3.
- The local time-zone offset in force when a session was recorded and when a streak day was credited. This is stored so that a day you played is credited correctly if you travel between time zones. It is a numeric offset from UTC, not a location, and it never leaves your device.
- A cached record of whether you hold a premium subscription. See §6.
What is never collected. SYNOVA does not collect, and has no means of collecting: your name, your email address, your phone number, your postal address, your date of birth, your contacts, your photographs, your files, your precise or approximate location, your device's advertising identifier, your browsing activity, or anything you have typed. The App contains no field in which you can enter personal information.
5. Advertising
5.1 Today
The App currently shows no advertisements and contains no advertising software. No advertising identifier is read, no ad request is made, and no advertising company receives anything from the App.
5.2 If and when we introduce advertising
We intend to offer SYNOVA free of charge, supported by advertising, with an optional subscription that removes ads. When advertising is introduced, this policy will be updated before the change reaches you, and the following will apply:
- Advertisements would be served by Google AdMob (Google Ireland Limited / Google LLC). Once an advertising SDK is present in the App, Google collects data directly from your device, independently of us. That typically includes your device's advertising identifier, your IP address and the approximate location derived from it, your device model and operating system version, your language, and your interactions with the advertisements shown.
- We would not receive your advertising identifier or your personal data from Google. We would receive only aggregate reporting about advertising performance.
- Where the GDPR or KVKK applies, you would be asked for consent through Google's consent interface before any advertisement is requested. If you declined, you would still see advertisements, but they would be non-personalised — selected from the context rather than from a profile of you.
- On iOS, we would ask for permission through Apple's App Tracking Transparency prompt only if we served personalised advertisements. If advertising is non-personalised, no such prompt appears and no tracking occurs.
- Google's own privacy policy would govern its processing: https://policies.google.com/privacy and https://support.google.com/admob/answer/6128543 for AdMob specifically.
Nothing in this subsection describes the App as it exists today.
6. Subscriptions
The App offers, or will offer, an optional premium subscription that removes advertisements and unlocks additional features.
Today, no purchase mechanism is connected. The subscription screen is visible but cannot complete a purchase, and no purchase, receipt, transaction identifier or billing information is collected or stored.
When purchasing is enabled, it will be handled entirely by Google Play Billing on Android and Apple's App Store / StoreKit on iOS. That means:
- Your payment details are given to Google or Apple, never to us. We never see your card number, your billing address, or your store account.
- We store on your device only a cached record of whether a subscription is active, its type, when it expires and when it was last verified. This lets the App work offline without repeatedly locking you out.
- Your subscription is managed, and can be cancelled, through your Google Play or Apple App Store account settings, not through us.
See the Terms of Service for how auto-renewal and cancellation work.
7. Analytics and crash reporting
The App currently sends no analytics and no crash reports.
The App contains the internal structure needed to add analytics and crash reporting later, but no such service is connected. When an error occurs, the details are written to your device's local developer log and go no further.
If we connect an analytics or crash reporting provider in the future, we will update this policy before doing so and will state which provider, what is collected, and on what legal basis. Any such data would be limited to information about how the App is used and how it fails — never the content of your training data, and never information that identifies you personally.
8. Children
Minimum age. SYNOVA is intended for users aged 13 and over.
We do not knowingly collect personal data from children. Because the App collects no personal data from anyone and transmits nothing from the device, there is no personal data belonging to a child for us to hold, access or delete.
If you are a parent or guardian and you believe a child has used the App in a way that concerns you, all of the child's data can be removed instantly by deleting the App from the device (see §9), and you may contact us at the contact email address given in the identity block at the top of this document.
9. How to delete your data
Because your data is stored only on your device, you control it completely and do not need to ask us to delete anything — we hold nothing to delete.
To erase your training history: open Profile → "Reset local progress" and confirm. This permanently deletes every session you have played, your daily workouts, your Brain Score history, your category scores, your measured abilities, your streak days, your achievements, your challenge progress and your experience points.
Please note that this does not remove your app preferences, your favourite exercises, the two random identifiers described in §3, or your cached subscription status. Resetting your progress is deliberately not the same as resetting the App.
To erase everything: uninstall the App. Uninstalling deletes the App's entire database from your device. Nothing survives it, and nothing is retained by us, because we never held a copy. This action is irreversible and cannot be undone by reinstalling.
On Android, your data is also excluded from Google cloud backup and from device-to-device transfer, so uninstalling really does end it: no copy is left in your Google account.
10. Your rights under the GDPR and the KVKK
10.1 GDPR (EU/EEA and UK)
If you are in the European Economic Area or the United Kingdom, you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to data portability. You also have the right to lodge a complaint with your national supervisory authority.
In SYNOVA's case, these rights are satisfied directly and immediately by the design of the App rather than by a request process: your data is on your device, visible to you in the App, and erasable by you at any moment (§9). We hold no copy, so there is nothing for us to disclose, correct, export or erase on your behalf.
Should we introduce advertising, analytics or cloud synchronisation, this section will be updated to describe the legal basis for each (consent, or legitimate interests, as applicable) and how to exercise your rights against those processing activities specifically.
10.2 KVKK (Türkiye)
If you are in Türkiye, Article 11 of Law No. 6698 on the Protection of Personal Data gives you the right to learn whether your personal data is processed, to request information about that processing, to learn its purpose, to know the third parties to whom it is transferred, to request correction or deletion, and to object to results produced solely by automated analysis.
As above, SYNOVA processes no personal data on our systems: no data is transferred from your device to us or to any third party, and no personal data is transferred abroad. If this changes, we will publish an updated policy and, where the law requires it, obtain your explicit consent (açık rıza) before the change takes effect.
You may address any request under Article 11 to the contact email address given in the identity block at the top of this document, and you have the right to complain to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu).
11. Permissions the App requests
None, on either platform.
On Android, the App declares no permissions at all. It does not request internet access, network state, notifications, location, camera, microphone, photo library, contacts, or storage, and it does not request an advertising identifier.
On iOS, the App requests no permissions beyond the platform defaults. It does not request tracking permission, location, camera, microphone, photo library or contacts access.
12. Security
Your data is stored in the App's private storage area, protected by the security model of your operating system, which prevents other applications from reading it. The App adds no encryption of its own beyond that, and relies on your device's own encryption, passcode and biometric protection.
Because no data is transmitted, there is no transmission for an attacker to intercept and no server of ours that can be breached. The practical corollary is that the security of your training data is the security of your device: if you share your unlocked device, you share your data.
13. Governing law
This policy is governed by the laws of Türkiye.
Nothing in this policy limits any right you have under the mandatory consumer protection or data protection law of the country in which you live.
14. Changes to this policy
We may update this policy as the App changes. When a change materially affects how your data is handled — in particular, if the App begins transmitting data that it does not transmit today — we will update the effective date at the top of this document and give notice within the App before the change takes effect.
The current version of this policy is the one published at the privacy policy address shown on the App's store pages and reachable inside the App from Profile → Legal. If you are reading this page on the web, this is that current version.
15. Contact
Questions about this policy, or about your data, should be sent to the contact email address in the identity block at the top of this document. Postal correspondence may be sent to the postal address given there.