Privacy Policy
1. Introduction
This Privacy Policy explains how Moa Bilgisayar Yazılım İnşaat Sanayi ve Ticaret Limited Şirketi (“Moa Bilgisayar”, “we”, “us”, or “our”) collects, uses, stores, and protects personal information when you use VooMoa — including the website at https://voomoa.com and our companion mobile applications (together, the “Service”).
By using the Service, you acknowledge that you have read this Privacy Policy. If you do not agree, please do not use the Service.
2. Data controller
The data controller responsible for your personal data is:
Moa Bilgisayar Yazılım İnşaat Sanayi ve Ticaret Limited ŞirketiHacıakif Mah. Bağlar Cad. No:27A/2
Beyşehir, Konya, Türkiye
MERSİS: 0622223957200001
Trade registry no.: 2957
Tax office / no.: Beyşehir / 6222239572
Phone: 0332 225 40 01
KEP: moa.bilgisayaryazilim@hs01.kep.tr
Authorized representative: Hasan Dedeoğlu
Email: privacy@voomoa.com
3. Information we collect
3.1 Information you provide
- Language preferences — the source and target languages you select to play.
- Email account (optional) — if you register or sign in with email and password, we process your email address, username (if provided), password hash, and email-verification / password-reset codes sent by email.
- Google Sign-In (optional) — if you sign in with Google, we receive information from Google such as your email address, display name, profile photo URL (when available), and a unique account identifier, as permitted by your Google account settings and our sign-in flow.
- Passkey (optional) — if you register or sign in with a passkey, we store a public credential identifier and related WebAuthn metadata needed to verify future sign-ins. Your device may use biometrics or a screen lock to authorise passkey use locally; we do not receive or store your biometric templates.
- Leaderboard display name (optional) — if you join weekly leagues, you may set a public nickname shown on leaderboards, or we may assign an automatic pseudonym.
- Support messages — if you contact us (for example at support@voomoa.com), we process the content of your message and contact details you include.
3.2 Information collected automatically
- Guest / device identifier — if you play without signing in, we assign a pseudonymous device identifier (cookie on web; local storage on mobile where applicable) so we can maintain a guest session and game progress on that device.
- Game and learning data — progress through chapters and subcategories, answers, scores, retention features (such as streaks and daily goals), weekly league XP and rankings, in-game economy (e.g. hearts, coins, hints), and related gameplay metadata necessary to operate the adaptive learning experience.
- Gameplay integrity data — answer timing, session tokens, and related signals used to detect abuse, replay attacks, and automated or excessively fast submissions.
- Device attestation (mobile) — on supported platforms we may receive integrity signals from Google Play Integrity (Android) and/or Apple App Attest (iOS) to confirm that requests come from a genuine app build and to reduce abuse.
- Session and security data — access and refresh tokens, session identifiers, and anti-abuse signals (see Section 6).
- Purchase and ad-reward data (mobile) — if you buy in-app products or watch rewarded ads, we process purchase/receipt verification data and ad server-side verification callbacks needed to credit your account safely. Purchase records may be retained in anonymised form for accounting after account deletion.
- Diagnostics and analytics (mobile) — crash reports, performance diagnostics, and basic usage analytics (such as app opens) collected via Firebase Crashlytics and Firebase Analytics on supported platforms (currently Android). These may include device model, OS version, app version, and crash stack traces.
- Advertising identifiers (mobile) — when ads are shown, advertising platforms may process an advertising ID and related device signals subject to your device settings and platform rules.
- Technical data — browser or app type, general device information, IP address (processed by us and our service providers for security and fraud prevention), and approximate usage patterns.
3.3 Information we do not intentionally collect
We do not require your real name, postal address, or phone number to use the core Service. We do not knowingly collect sensitive categories of personal data (such as health data) through VooMoa. Passkey biometrics, when used, remain on your device and are not transmitted to us.
4. How we use your information
We use personal information to:
- Provide, operate, and improve the Service and your learning experience on web and mobile;
- Save and sync your progress when you use an account or guest session;
- Authenticate you (email/password, Google, or passkey) and link an identity to an existing guest profile when you choose;
- Send transactional emails such as email verification and password reset;
- Operate retention features, weekly leagues/leaderboards, and the in-game economy;
- Deliver and measure advertisements and reward you for completed rewarded-ad offers where available;
- Verify in-app purchases and deliver purchased virtual items;
- Diagnose crashes and improve reliability (Crashlytics / Analytics);
- Protect the Service against abuse, cheating, and automated attacks;
- Process account-deletion requests (including a grace period before permanent deletion);
- Comply with legal obligations and enforce our terms.
5. Legal bases (EEA, UK, and similar jurisdictions)
Where applicable law requires a legal basis, we rely on:
- Contract — to provide the Service you request;
- Legitimate interests — security, fraud prevention, service improvement, and diagnostics, balanced against your rights;
- Consent — where required for optional sign-in methods, certain analytics, or advertising identifiers;
- Legal obligation — where we must retain or disclose data by law (including limited purchase records).
6. Third-party services
We use trusted third parties that may process personal data on our behalf or as independent controllers:
- Google Sign-In — optional authentication. See Google’s Privacy Policy.
- WebAuthn / passkeys — optional passwordless sign-in supported by your browser and operating system. We do not receive your device passcode or biometric data.
- Cloudflare Turnstile — bot and abuse protection on certain web flows. See Cloudflare’s Privacy Policy.
- Firebase (Google) — Analytics and Crashlytics on supported mobile builds. See Firebase Privacy and Security and Google’s Privacy Policy.
- Google AdMob — banner, interstitial, and rewarded ads in the mobile apps where enabled. See Google Advertising and AdMob / Google privacy terms. You can limit ad personalisation via your device advertising settings where available.
- App stores / billing — Google Play Billing (and Apple In-App Purchase when offered) process payments. We receive verification data needed to unlock purchases; card details are handled by the store, not by us.
- Email delivery (SMTP) — transactional messages such as verification and password-reset emails.
- Content processors — text-to-speech and related providers may process learning content we publish (for example pronunciation audio generation). This is primarily content operations, not your private messages.
- Hosting and infrastructure providers — to run our API, website, databases, and CDN securely.
Links to third-party sites or services are not covered by this Privacy Policy. We encourage you to review their policies.
7. Cookies and similar technologies
On the website we use cookies and similar storage mechanisms to:
- Keep you signed in and maintain guest sessions (including access and refresh tokens stored in httpOnly cookies);
- Remember your selected language pair;
- Store a pseudonymous device identifier for guest play;
- Support security verification (Turnstile).
The web client uses a backend-for-frontend pattern: your browser talks to our web server, which calls our API using server-side session cookies. API tokens are not exposed to client-side JavaScript.
On mobile apps we use local storage (and secure storage where appropriate) for session tokens, preferences, and similar operational data. Essential storage is necessary for the Service to function.
You can control non-essential cookies through your browser settings; blocking essential cookies may limit gameplay or sign-in. On mobile, you can manage advertising identifiers and app permissions in your device settings.
8. Retention and account deletion
This section explains how long VooMoa keeps personal data and how you can delete your VooMoa account (operated by Moa Bilgisayar Yazılım İnşaat Sanayi ve Ticaret Limited Şirketi).
8.1 How long we keep data (retention)
- Active accounts and guest sessions — we keep the data needed to run the Service (profile, progress, economy, leagues, sessions) for as long as you use VooMoa and the account or guest profile remains active.
- After account deletion — once the grace period ends and deletion completes, account and learning data are permanently removed from our production systems, except the limited categories in Section 8.4.
- Inactivity — guest or account data may be deleted or anonymised after prolonged inactivity, subject to backups and legal retention rules.
- Legal / security holds — we may retain specific records longer when required by law, accounting rules, dispute resolution, fraud prevention, or security investigations.
8.2 How to request account deletion
You can request deletion from within the Service:
- Website (voomoa.com) — sign in, open your profile / account menu, choose Delete account, read the warning, confirm your identity (password, Google, and/or passkey as offered), and confirm the request.
- Mobile app (Android / iOS) — sign in, open your profile, choose Delete account, follow the on-screen warnings, confirm your identity, and confirm the request.
- Help by email — if you cannot use in-product deletion, contact support@voomoa.com or privacy@voomoa.com from the email associated with your account and ask for account deletion. We may verify your identity first.
8.3 14-day waiting period (grace period)
After you confirm deletion, the request enters a 14-day grace period before permanent deletion. During those 14 days you may cancel the request by signing in again and choosing to cancel deletion (where the Service shows that option). When the grace period ends, deletion is processed automatically and cannot be undone.
8.4 What is deleted vs kept
- Deleted — account credentials and linked sign-in identifiers, profile and display name, learning progress, scores, streaks/goals, coin/heart balances, premium entitlements tied to the account, and related gameplay/session data used only to operate your account.
- May be retained in limited form — anonymised or aggregated purchase/accounting audit records, security/abuse logs needed for fraud prevention, and records we must keep by law. These are not kept to continue providing you a playable account.
9. Your rights
Depending on your location, you may have the right to:
- Access, correct, or delete your personal data;
- Restrict or object to certain processing;
- Data portability;
- Withdraw consent where processing is consent-based;
- Lodge a complaint with a supervisory authority.
To exercise these rights, email privacy@voomoa.com or contact us via KEP at moa.bilgisayaryazilim@hs01.kep.tr. Product support questions may be sent to support@voomoa.com. We may need to verify your identity before responding.
9.1 Türkiye (KVKK)
If you are in Türkiye, your personal data is processed under the Law on Protection of Personal Data (Kişisel Verilerin Korunması Kanunu — KVKK, Law No. 6698). Our Turkish KVKK Aydınlatma Metni provides detailed information in Turkish as required for data subjects in Türkiye, including processing purposes, legal bases, transfers, and your rights under Article 11. You may apply to us using the contact details in Section 2 or lodge a complaint with the Personal Data Protection Authority (KVKK Kurumu — kvkk.gov.tr).
10. Children
The Service is intended for a general audience learning languages. We do not knowingly collect personal information from children under 13 (or the minimum age required in your country) without appropriate parental consent. If you believe a child has provided us personal data, contact us and we will take steps to delete it.
11. International transfers
We and our service providers may process data in Türkiye and other countries (including where Google, Cloudflare, Firebase, AdMob, or hosting providers operate). Where required, we implement appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) for cross-border transfers.
12. Security
We use technical and organisational measures appropriate to the nature of the data, including encrypted connections (HTTPS), httpOnly session cookies for web authentication tokens, password hashing, device attestation on supported mobile platforms, and access controls on our systems. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
13. Changes to this policy
We may update this Privacy Policy from time to time. The “Effective date” at the top will reflect the latest version. Material changes may be communicated through the Service where appropriate. Continued use after changes constitutes acceptance of the updated policy.
14. Contact
Questions about this Privacy Policy or our data practices:
Moa Bilgisayar Yazılım İnşaat Sanayi ve Ticaret Limited ŞirketiHacıakif Mah. Bağlar Cad. No:27A/2
Beyşehir, Konya, Türkiye
MERSİS: 0622223957200001
Trade registry no.: 2957
Tax office / no.: Beyşehir / 6222239572
Phone: 0332 225 40 01
KEP: moa.bilgisayaryazilim@hs01.kep.tr
Authorized representative: Hasan Dedeoğlu
Email: privacy@voomoa.com
Web: https://voomoa.com
Privacy: privacy@voomoa.com
Support: support@voomoa.com
KEP: moa.bilgisayaryazilim@hs01.kep.tr
Terms of Service · KVKK Aydınlatma Metni (Türkiye)