Martis for iOS
Privacy Policy
Last updated: 15 September 2026 · Effective: 15 September 2026
This Privacy Policy explains how Medya 333 (“we”, “us”) collects, uses, stores and deletes personal data when you use Martis, our iOS application in which you create an account, send questions and receive answers generated by artificial intelligence.
It applies only to the Martis app. Other Medya 333 products and this website are covered by their own notices.
1. Who we are
Martis is operated by Medya 333. For the purposes of the EU and UK General Data Protection Regulation (GDPR), Medya 333 is the data controller for the personal data described in this policy.
You can reach us about any privacy matter at destek@medya333.com . We answer privacy requests from this address and no other.
2. Data we collect
We collect only what the app needs in order to work. Specifically:
Account data
- Email address and, where you choose to set one, a display name. These are used to create your account and to sign you back in.
- Authentication identifiers — a unique user ID issued by Firebase Authentication, together with sign-in metadata such as the time of your last sign-in and the sign-in method used.
- Password — if you sign in with an email and password, the password is handled and stored by Firebase Authentication in hashed form. We never see or store your password ourselves.
Chat content
- The questions and messages you send, and the AI-generated answers you receive. These are transmitted to our backend servers and stored there so that your conversation history is available to you across sessions and devices.
- Conversation metadata — timestamps, message ordering and the conversation a message belongs to.
Please do not send information you would not want stored. Because chat history is saved on our servers, avoid including passwords, payment card numbers, government identification numbers or health information in your messages.
Technical and usage data
- Device and app information — device model, operating system version, app version, language and region, collected through Firebase.
- Usage events — pseudonymous events such as app opens and screen views, collected through Firebase Analytics to help us understand which parts of the app are used.
- Crash and diagnostic reports — collected through Firebase Crashlytics when the app stops unexpectedly, including the state of the app at the moment of the crash.
- IP address, processed by our backend and by our service providers as part of delivering and securing the service.
What we do not collect
- We do not collect your contacts, photos, precise location or health data.
- We do not use your data for advertising, and we do not sell or rent personal data to anyone.
- Martis does not process payments, so we do not receive or store payment card details. Any purchase made through the App Store is handled by Apple under Apple’s privacy policy.
3. How we use your data
- To provide the service — creating and authenticating your account, sending your question to the AI provider, returning the answer, and saving your conversation so you can come back to it.
- To keep the service working and safe — diagnosing crashes, detecting abuse, rate-limiting and preventing fraudulent or automated use.
- To improve the app — understanding, in aggregate, which features are used and where people get stuck.
- To communicate with you — replying to your support or privacy requests, and sending service messages such as password resets.
- To meet legal obligations — where we are required to retain or disclose information by law.
We do not use your chat content to build advertising profiles, and we do not use it to train our own models.
4. Legal bases for processing (GDPR)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under Article 6 GDPR:
- Performance of a contract (Art. 6(1)(b)) — for account creation, authentication, processing your questions and storing your chat history. Without this data the app cannot function.
- Legitimate interests (Art. 6(1)(f)) — for security, abuse prevention, crash diagnostics and keeping the service reliable. Our interest is in operating a functioning, secure service; we balance it against your rights and limit the data to what is necessary.
- Consent (Art. 6(1)(a)) — for analytics where consent is required in your jurisdiction. You can withdraw consent at any time; withdrawal does not affect processing that already took place.
- Legal obligation (Art. 6(1)(c)) — where retention or disclosure is required by applicable law.
5. Third-party services we use
We use the providers below. Each one processes data on our behalf under a data processing agreement, and only for the purpose described.
Firebase Authentication
Google Ireland Ltd. / Google LLC
- What it does
- Creates and verifies your account, and keeps you signed in.
- Data involved
- Email address, hashed password, user ID, sign-in metadata.
Firebase Analytics & Crashlytics
Google Ireland Ltd. / Google LLC
- What it does
- Usage statistics and crash reporting.
- Data involved
- Pseudonymous app instance identifier, device and app information, crash logs.
OpenAI API
OpenAI, L.L.C.
- What it does
- Generates the answers to the questions you send.
- Data involved
- The text of your question and the relevant conversation context.
Medya 333 backend API
Operated by us
- What it does
- Stores your account record and chat history, and routes requests to the AI provider.
- Data involved
- All of the data described in section 2.
OpenAI states that data submitted through its API is not used to train its models. Google processes Firebase data in accordance with its own terms. You can read their notices here: OpenAI Privacy Policy · Firebase Privacy and Security.
We may also disclose data where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims.
6. International data transfers
Our providers process data on servers located outside your country, including in the United States. Where personal data is transferred out of the European Economic Area or the United Kingdom, the transfer takes place on the basis of the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with the additional safeguards those providers apply.
7. How long we keep your data
- Account data — kept for as long as your account exists.
- Chat messages and history — kept until you delete them or delete your account.
- Crash reports — retained by Crashlytics for up to 90 days.
- Analytics events — retained in pseudonymous, aggregated form according to our Firebase retention settings.
- Backups — deleted data may persist in encrypted backups for up to 90 days before those backups expire.
8. Deleting your data
You can have your account and everything associated with it deleted. Email destek@medya333.com from the address registered to your Martis account and tell us what you want deleted — your whole account, or specific conversations.
- We acknowledge the request within 72 hours.
- We delete the data from our live systems within 30 days, and confirm to you in writing once it is done.
- Copies in encrypted backups expire within a further 90 days, after which no copy remains.
- Deleting your account removes your account record, your chat messages and your conversation history. It cannot be undone.
Individual conversations can also be deleted from within the app at any time, without deleting your account.
9. Your rights
Under the GDPR — and under comparable laws elsewhere, including Türkiye’s Law No. 6698 (KVKK) — you have the right to:
- Access the personal data we hold about you, and receive a copy of it.
- Rectify data that is inaccurate or incomplete.
- Erase your data (see section 8).
- Restrict or object to processing carried out on the basis of our legitimate interests.
- Data portability — receive your data in a structured, commonly used, machine-readable format.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, write to destek@medya333.com . We respond within 30 days. We do not charge for this, and we will not treat you differently for asking.
10. How we protect your data
- All traffic between the app, our backend and our providers is encrypted in transit (TLS).
- Data at rest is encrypted by our infrastructure providers.
- Authentication is handled by Firebase Authentication; we never store passwords in readable form.
- Access to production systems is limited to the people who need it to operate the service.
No system is perfectly secure. If a data breach occurs that is likely to present a risk to your rights, we will notify the competent supervisory authority within 72 hours and inform you without undue delay where the law requires it.
11. Children's privacy
Martis is not directed at children. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact destek@medya333.com and we will delete it.
12. Changes to this policy
We may update this policy as the app changes. The date at the top of this page always shows the current version. If a change materially affects how we handle your data, we will tell you in the app or by email before it takes effect.
13. Contact us
For any question about this policy, to exercise your rights, or to request deletion of your data:
Data controller
Medya 333
destek@medya333.comPlease write from the email address registered to your Martis account so we can verify the request. We reply to every privacy request, including to confirm when a deletion has been completed.