Privacy Policy

Bitemark Interactive — bitemarkinteractive.com

Last updated: May 18, 2026


1. About This Policy

This Privacy Policy explains how personal data is processed for visitors and account holders of bitemarkinteractive.com (the "Site"). It is designed to satisfy both the disclosure obligation under Turkey's Personal Data Protection Law No. 6698 ("KVKK") and the information requirements under the EU General Data Protection Regulation ("GDPR"). KVKK- and GDPR-specific points are noted in the relevant sections.

Reading and understanding this Policy does not mean you have given explicit consent to any processing. Disclosure (information) and consent are separate.

2. Data Controller

Data Controller: Bitemark Interactive Ltd.
Contact: [email protected]

[LEGAL NOTE]Whether an EU representative is required under GDPR Art. 27 should be assessed by a lawyer.

3. Nature of the Site and Age Requirement

The Site is the promotional and community site of an independent horror game studio. No products or services are sold, no payments are taken, and the games are free.

The Site promotes a game with mature themes (psychological horror). You must be at least 18 years old to use the Site or create an account. By creating an account, you represent that you are over 18. If we learn that you are under 18, we reserve the right to remove the account and related data.

[LEGAL NOTE]The age threshold of 18 has been confirmed. An age representation checkbox ("I have read and accept; I am 18 or older") is being added to the registration flow.

4. What Data We Process, and How

If you only visit the Site, no data that directly identifies you is collected. The following data is processed when you perform the relevant action:

4.1 Account and Profile Data

Email address, username, display name, profile bio, profile image, cover image, language preference. Collected directly from you during registration and profile actions.

4.2 Authentication and Security Data

Your password is stored encrypted; its plaintext is never visible to us. If you use two-factor authentication (2FA): an encrypted TOTP secret and hashed recovery codes. One-time verification codes are processed only as a hash (HMAC); plaintext is not stored in the database and appears only in the email sent to you.

4.3 Transaction Security and Log Data

For security purposes, certain events (sign-in, password/email change, sign-in from a new device, suspicious activity) record your IP address, browser/device information (user-agent) and country code, retained as an audit log for 90 days. For new-device detection, only the subnet (/24) portion of your IP and your browser family may also be processed. When you initiate account deletion, the initiating IP and browser information are recorded in the request.

For rate limiting (abuse prevention), your IP address is processed very briefly (minutes up to 1 hour) and transiently.

4.4 Content Data

Posts, comments, mentions and reports you create in the community and comment sections.

4.5 Communication and Notification Preference Data

Your email notification preferences. Marketing/announcement emails are sent only if you explicitly opt in; they are off by default.

4.6 Cookieless Usage/Activity Data

A cookieless, non-personal analytics system measures overall Site usage volume. This system does notstore your IP address, user identity, or browser information. It processes only a temporary session key unique to your browser tab (deleted when the tab closes), the page visited, language, and a "visitor/member" distinction. Raw records are kept 90 days; aggregated, non-attributable statistics are kept indefinitely.

5. Purposes of Processing

  • Account creation, authentication, account security (incl. 2FA, suspicious sign-in detection),
  • Providing core Site features (profile, community, comments, devlog),
  • Detecting security incidents, preventing abuse and attacks,
  • Moderating community content and ensuring rule compliance,
  • Sending transactional and security notifications (email),
  • Producing non-attributable aggregate usage statistics,
  • Meeting legal obligations.

6. Legal Bases (KVKK Art. 5 / GDPR Art. 6)

Data / ActivityKVKK BasisGDPR Basis
Account, authentication, core servicePerformance of a contract (Art. 5/2-c)Contract (Art. 6/1-b)
Security logs, IP, abuse preventionLegitimate interest (Art. 5/2-f)Legitimate interest (Art. 6/1-f)
Legal retention/notificationLegal obligation (Art. 5/2-ç)Legal obligation (Art. 6/1-c)
Cookieless, non-attributable analyticsLegitimate interest (Art. 5/2-f)Legitimate interest (Art. 6/1-f)
Marketing/announcement emailsExplicit consent (Art. 5/1)Consent (Art. 6/1-a)

[LEGAL NOTE]A Legitimate Interest Assessment (LIA) is recommended for the legitimate-interest basis under GDPR. This table reflects technical reality; final legal characterization is for a lawyer.

7. Data Sharing and International Transfers (KVKK Art. 8–9 / GDPR Chapter V)

The Site's technical infrastructure runs through the providers below. These transfers are necessary to provide the service. Some providers are in the EU, some are US-based.

7.1 Hosting — Turkey

The application server is located in Istanbul, Turkey (hostingdunyam.com.tr). Server access logs may transiently retain your IP; this is a technical necessity outside our application layer's direct control.

7.2 Database and Authentication — Supabase (EU / Germany)

All account, profile and content data is processed and stored on Supabase, in the Frankfurt, Germany (European Union) region.

7.3 File/Image Storage — Cloudflare R2 (EU / Eastern Europe)

Profile, cover, community and devlog images are stored on Cloudflare R2 in the Eastern Europe (EEUR) region and served publicly.

7.4 Traffic, Security and Bot Protection — Cloudflare (US-based)

All traffic to the Site passes through Cloudflare for DDoS protection, security and performance; Cloudflare is US-based and can technically inspect traffic. During bot/human verification (Turnstile), your IP is sent to Cloudflare.

7.5 Email — Resend (US-based)

Transactional and security emails are sent via Resend(US). The recipient email address, username, and email content (e.g., another user's name or a comment excerpt in a notification) are sent to Resend.

7.6 Content Moderation — OpenAI (US-based)

Community posts and comments are automatically moderated before publication/update. The title and plain-text contentof the post/comment is sent to OpenAI's moderation service (US). Author identity, IP or session is not sent; however, the content itself may contain personal data. This applies only to community content and comments; devlog (studio content) is out of scope.

7.7 Rate Limiting — Upstash (EU / Ireland)

Upstash (Redis) is used for abuse prevention; your IP is processed briefly and transiently. Upstash is in the Dublin, Ireland (European Union) region.

7.8 Error Monitoring — Sentry (EU / Germany)

Sentry is used for technical error detection, configured not to send personal data (IP, headers). Sentry is in the Germany (European Union) region; data is relayed via our server.

7.9 Not Used

The Site does not use Google Analytics, Meta/Facebook, ad networks, social media trackers, or similar tracking/advertising tools. Fonts are served from our own server.

8. Retention Periods

DataPeriod
Account and profile dataWhile the account is active
Security/audit logs (incl. IP, user-agent)90 days
One-time verification (OTP) records5–15 minutes
Cookieless analytics — raw records90 days
Cookieless analytics — aggregate (non-attributable)Indefinite
Account deletion request recordsIndefinite (request status record)
Session cookieUp to 400 days (rotates on refresh)
Language preference cookieBrowser session

9. When You Delete Your Account (Anonymization)

When you delete your account, after a 30-day waiting period it is anonymized. This does not mean total destruction of all data; the anonymization method accepted under KVKK and in practice is applied:

  • Data that directly identifies you — email, password, phone, username, display name, bio — is deleted or made non-identifiable.
  • Your community posts and comments are not deleted; they may remain on the Site under an anonymous identity (e.g., "deleted_…") and can no longer be linked to you.
  • Profile and cover images you uploaded, and images embedded inside your community posts, are deleted from storage. Where images were referenced inside post bodies, the post text remains but the image references no longer resolve.
  • The deletion request record itself is retained as the historical marker of the anonymization, but its IP address and browser information are cleared at completion.

10. Your Rights (KVKK Art. 11 / GDPR Art. 15–22)

Regarding your personal data, you have the right to:

  • Information and access: learn whether your data is processed, obtain related information and a copy (KVKK Art. 11/a-b; GDPR Art. 15),
  • Rectification: have incomplete/incorrect data corrected (KVKK Art. 11/d; GDPR Art. 16),
  • Erasure/Anonymization: request deletion/destruction (in practice, anonymization) when conditions are met (KVKK Art. 11/e, Art. 7; GDPR Art. 17),
  • Restriction and objection: restrict/object to processing under GDPR Art. 18 and 21,
  • Data portability: receive your data in a structured format where technically feasible (GDPR Art. 20),
  • Notification of third parties: request that rectification/erasure be communicated to recipients (KVKK Art. 11/f),
  • Object to automated decisions: object to solely automated processing producing adverse effects (KVKK Art. 11/g; GDPR Art. 22),
  • Withdraw consent: for consent-based processing (e.g., marketing emails), withdraw at any time,
  • Compensation: seek remedy for damage from unlawful processing (KVKK Art. 11/ğ),
  • Complaint: lodge a complaint with the Turkish Data Protection Authority (KVKK) or the relevant EU supervisory authority (GDPR).

You may submit requests to: [email protected]. Your request will be resolved within 30 days (KVKK Art. 13 / GDPR Art. 12).

11. Automated Decisions / Moderation

Community content is automatically moderated (including OpenAI) before publication; this may temporarily hold or block publication. This is a content-moderation decision, not personality profiling. You may object to the outcome via the request channel above.

12. Cookies and Local Storage

The Site uses only two cookies, necessary for functionality:

CookiePurposeClassificationLifetime
Session (authentication) cookieLogged-in user's sessionStrictly necessary (contract)Up to 400 days (rotates)
Language preference cookieSite language (TR/EN)FunctionalBrowser session

No advertising or tracking cookies are used. The analytics system uses no cookies; only a temporary browser session key (sessionStorage) deleted when the tab closes. Additionally, a local-storage entry containing no personal data is used for cross-tab logout synchronization.

Since only strictly-necessary and functional cookies are used, no separate cookie consent banner is presented.

[LEGAL NOTE]With only strictly-necessary + functional cookies and no tracking or advertising technology, a consent banner is not required. The KVKK Cookie Guideline's informative-notice recommendation is satisfied by this Privacy Policy.

13. Data Security

Passwords are encrypted; 2FA secrets and one-time codes are stored encrypted/hashed. Access is limited via authorization and row-level security policies. No technical measure guarantees absolute security.

14. Changes

This Policy may be updated as needed. The current version is always published on this page; the effective date appears at the top. Significant changes will be communicated appropriately.

15. Contact

For requests regarding data processing and your rights: [email protected]

Bitemark Interactive

Independent horror, built one nightmare at a time.

© 2026 Bitemark Interactive. All rights reserved.

Explore

  • Games
  • Devlog
  • Community
  • FAQ

Legal

  • Privacy Policy
  • Terms of Service

Follow

Bitemark Interactive
GamesDevlogCommunityFAQ