Bitemark Interactive — bitemarkinteractive.com
Last updated: May 18, 2026
This Privacy Policy explains how personal data is processed for visitors and account holders of bitemarkinteractive.com (the "Site"). It is designed to satisfy both the disclosure obligation under Turkey's Personal Data Protection Law No. 6698 ("KVKK") and the information requirements under the EU General Data Protection Regulation ("GDPR"). KVKK- and GDPR-specific points are noted in the relevant sections.
Reading and understanding this Policy does not mean you have given explicit consent to any processing. Disclosure (information) and consent are separate.
Data Controller: Bitemark Interactive Ltd.
Contact: [email protected]
The Site is the promotional and community site of an independent horror game studio. No products or services are sold, no payments are taken, and the games are free.
The Site promotes a game with mature themes (psychological horror). You must be at least 18 years old to use the Site or create an account. By creating an account, you represent that you are over 18. If we learn that you are under 18, we reserve the right to remove the account and related data.
If you only visit the Site, no data that directly identifies you is collected. The following data is processed when you perform the relevant action:
Email address, username, display name, profile bio, profile image, cover image, language preference. Collected directly from you during registration and profile actions.
Your password is stored encrypted; its plaintext is never visible to us. If you use two-factor authentication (2FA): an encrypted TOTP secret and hashed recovery codes. One-time verification codes are processed only as a hash (HMAC); plaintext is not stored in the database and appears only in the email sent to you.
For security purposes, certain events (sign-in, password/email change, sign-in from a new device, suspicious activity) record your IP address, browser/device information (user-agent) and country code, retained as an audit log for 90 days. For new-device detection, only the subnet (/24) portion of your IP and your browser family may also be processed. When you initiate account deletion, the initiating IP and browser information are recorded in the request.
For rate limiting (abuse prevention), your IP address is processed very briefly (minutes up to 1 hour) and transiently.
Posts, comments, mentions and reports you create in the community and comment sections.
Your email notification preferences. Marketing/announcement emails are sent only if you explicitly opt in; they are off by default.
A cookieless, non-personal analytics system measures overall Site usage volume. This system does notstore your IP address, user identity, or browser information. It processes only a temporary session key unique to your browser tab (deleted when the tab closes), the page visited, language, and a "visitor/member" distinction. Raw records are kept 90 days; aggregated, non-attributable statistics are kept indefinitely.
| Data / Activity | KVKK Basis | GDPR Basis |
|---|---|---|
| Account, authentication, core service | Performance of a contract (Art. 5/2-c) | Contract (Art. 6/1-b) |
| Security logs, IP, abuse prevention | Legitimate interest (Art. 5/2-f) | Legitimate interest (Art. 6/1-f) |
| Legal retention/notification | Legal obligation (Art. 5/2-ç) | Legal obligation (Art. 6/1-c) |
| Cookieless, non-attributable analytics | Legitimate interest (Art. 5/2-f) | Legitimate interest (Art. 6/1-f) |
| Marketing/announcement emails | Explicit consent (Art. 5/1) | Consent (Art. 6/1-a) |
The Site's technical infrastructure runs through the providers below. These transfers are necessary to provide the service. Some providers are in the EU, some are US-based.
The application server is located in Istanbul, Turkey (hostingdunyam.com.tr). Server access logs may transiently retain your IP; this is a technical necessity outside our application layer's direct control.
All account, profile and content data is processed and stored on Supabase, in the Frankfurt, Germany (European Union) region.
Profile, cover, community and devlog images are stored on Cloudflare R2 in the Eastern Europe (EEUR) region and served publicly.
All traffic to the Site passes through Cloudflare for DDoS protection, security and performance; Cloudflare is US-based and can technically inspect traffic. During bot/human verification (Turnstile), your IP is sent to Cloudflare.
Transactional and security emails are sent via Resend(US). The recipient email address, username, and email content (e.g., another user's name or a comment excerpt in a notification) are sent to Resend.
Community posts and comments are automatically moderated before publication/update. The title and plain-text contentof the post/comment is sent to OpenAI's moderation service (US). Author identity, IP or session is not sent; however, the content itself may contain personal data. This applies only to community content and comments; devlog (studio content) is out of scope.
Upstash (Redis) is used for abuse prevention; your IP is processed briefly and transiently. Upstash is in the Dublin, Ireland (European Union) region.
Sentry is used for technical error detection, configured not to send personal data (IP, headers). Sentry is in the Germany (European Union) region; data is relayed via our server.
The Site does not use Google Analytics, Meta/Facebook, ad networks, social media trackers, or similar tracking/advertising tools. Fonts are served from our own server.
| Data | Period |
|---|---|
| Account and profile data | While the account is active |
| Security/audit logs (incl. IP, user-agent) | 90 days |
| One-time verification (OTP) records | 5–15 minutes |
| Cookieless analytics — raw records | 90 days |
| Cookieless analytics — aggregate (non-attributable) | Indefinite |
| Account deletion request records | Indefinite (request status record) |
| Session cookie | Up to 400 days (rotates on refresh) |
| Language preference cookie | Browser session |
When you delete your account, after a 30-day waiting period it is anonymized. This does not mean total destruction of all data; the anonymization method accepted under KVKK and in practice is applied:
Regarding your personal data, you have the right to:
You may submit requests to: [email protected]. Your request will be resolved within 30 days (KVKK Art. 13 / GDPR Art. 12).
Community content is automatically moderated (including OpenAI) before publication; this may temporarily hold or block publication. This is a content-moderation decision, not personality profiling. You may object to the outcome via the request channel above.
The Site uses only two cookies, necessary for functionality:
| Cookie | Purpose | Classification | Lifetime |
|---|---|---|---|
| Session (authentication) cookie | Logged-in user's session | Strictly necessary (contract) | Up to 400 days (rotates) |
| Language preference cookie | Site language (TR/EN) | Functional | Browser session |
No advertising or tracking cookies are used. The analytics system uses no cookies; only a temporary browser session key (sessionStorage) deleted when the tab closes. Additionally, a local-storage entry containing no personal data is used for cross-tab logout synchronization.
Since only strictly-necessary and functional cookies are used, no separate cookie consent banner is presented.
Passwords are encrypted; 2FA secrets and one-time codes are stored encrypted/hashed. Access is limited via authorization and row-level security policies. No technical measure guarantees absolute security.
This Policy may be updated as needed. The current version is always published on this page; the effective date appears at the top. Significant changes will be communicated appropriately.
For requests regarding data processing and your rights: [email protected]