Son güncelleme: 31 Temmuz 2026 · Sürüm 2.0 (uygulama sürümü 1.2.0)
Kısaca: MedReminder varsayılan olarak çevrimdışı çalışır. İlaçlarınız, programlarınız ve doz geçmişiniz yalnızca cihazınızdaki veritabanında durur; hiçbir sunucuya gönderilmez. Yalnızca bir "Aile" kurmayı veya bir aileye katılmayı seçerseniz veri iletilmeye başlar — ve o veri cihazınızda uçtan uca şifrelenir: aile üyeleriniz okuyabilir, biz okuyamayız. Ancak sunucumuz şifrelenmemiş bazı yönlendirme bilgilerini görür; aşağıda hepsini tek tek yazdık.
MedReminder, Appouse Teknoloji Limited Şirketi tarafından geliştirilir ve işletilir.
Aile özelliğinin sunucusu Türkiye'de barındırılmaktadır
(family.medreminder.appouse.com).
Uygulamanın çekirdeği tamamen çevrimdışıdır. Şunlar cihazınızdaki SQLite veritabanında saklanır ve hiçbir koşulda kendiliğinden bir yere gönderilmez:
Uygulama otomatik bulut yedeklemesini kapatır: bu veritabanı Google Drive'a veya iCloud'a yedeklenmez, cihazdan cihaza aktarıma dahil edilmez. Verinizin kopyasını istiyorsanız Ayarlar → Dışa Aktarma'dan JSON veya CSV olarak kendiniz alabilir, dilediğinizde geri yükleyebilirsiniz. Uygulamayı kaldırmanız cihazdaki bu veritabanını siler.
Bir aile kurduğunuzda veya bir aileye katıldığınızda, sunucumuzda takma ad niteliğinde bir hesap oluşturulur. Bu hesap e-posta, telefon veya isim istemez; rastgele bir kimlikten ibarettir.
Aşağıdakiler cihazınızda AES-256-GCM ile şifrelenir. Şifre çözme anahtarı ailenin kurucusunun cihazında üretilir ve yeni üyelere yalnızca o üyenin açabileceği biçimde (X25519) sarmalanarak iletilir. Anahtarın açık hâli sunucumuza hiç ulaşmaz:
İlaç adlarının paylaşılıp paylaşılmayacağına yalnızca siz karar verirsiniz ve varsayılan gizlidir: aile kurucusu bunu sizin adınıza değiştiremez.
Uçtan uca şifreleme içeriği korur, yönlendirme bilgisini koruyamaz. Sunucumuz şunları düz olarak görür ve saklar:
| Veri | Neden gerekli | Saklama süresi |
|---|---|---|
| Takma ad hesap kimliği ve cihazınızın açık anahtarı | İstekleri doğrulamak, aile anahtarını size sarmalamak | Hesabı silene kadar |
| Oturum jetonunuzun karması (SHA-256) | Kimlik doğrulama | Hesabı silene kadar |
| Hesap oluşturma ve son görülme zamanı | İşletim ve kötüye kullanım tespiti | Hesabı silene kadar |
| Kimin hangi ailede olduğu, rolü ve katılma tarihi | Bildirimlerin doğru kişilere gitmesi | Aileden ayrılana veya hesabı silene kadar |
| Paylaşım tercihiniz ("yalnızca durum" / "ilaç adlarıyla") | Cihazınıza ne göndereceğini bilmek | Aileden ayrılana kadar |
| Davet kodları, kodu üreten kişi ve son kullanma zamanı | Davetin geçerliliğini denetlemek | 24 saat sonra geçersiz, ardından silinir |
| Bir bildirimin var olduğu bilgisi: hangi ailede, kimden, hangi saatte | Bildirimi iletmek | 7 gün |
| Bir bildirimi kimin okuduğu | Aynı uyarıyı tekrar göstermemek | 7 gün |
| Cihazınızın bildirim jetonu (APNs / FCM) ve platformu | Bildirimi cihazınıza ulaştırmak | Hesabı silene kadar |
| Sunucu erişim kayıtlarındaki IP adresiniz ve istek zamanları | Güvenlik, hata ayıklama, kötüye kullanım | En fazla 30 gün |
Bunu açıkça söylemek isteriz: bir bildirimin varlığı tek başına bir bilgi taşır. Sunucuya yalnızca kaçırılan dozlar için kayıt düşüldüğünden, biz hangi ilacın söz konusu olduğunu göremesek de "bu hesap şu saatte bir dozu kaçırmış" bilgisini teknik olarak görebiliriz. Bu kayıtlar 7 gün sonra otomatik silinir.
Bir aileye katılmak istediğinizde yazdığınız ad, o anda düz metin olarak iletilir — çünkü henüz o ailenin şifreleme anahtarına sahip değilsinizdir ve kurucunun isteği değerlendirebilmesi için adı okuması gerekir. Bu ad, isteğiniz onaylandığında veya reddedildiğinde sunucudan silinir; hiç yanıtlanmayan istekler de belirli bir süre sonra otomatik temizlenir. Gerçek adınızı yazmak zorunda değilsiniz.
Bir aile üyesi sizden güncel bir uyum özeti isteyebilir. Bu durumda cihazınıza sessiz bir bildirim gider ve cihazınız yeni bir şifreli özet yükler. Bu işlem size sorulmaz; ancak yüklenen özet yine yalnızca aile üyelerinizin okuyabileceği biçimdedir. Aynı sessiz bildirim yöntemi, bir katılma isteğini kurucuya duyurmak ve onaylanan üyeye anahtarını almasını söylemek için de kullanılır.
İlaç hatırlatmalarınız tamamen cihazınızda üretilir ve hiçbir sunucudan geçmez. Yalnızca aile bildirimleri uzaktan gelir: bunlar Apple (APNs) ve Google (FCM) üzerinden iletilir. İletilen paketin içinde okunabilir metin yoktur — yalnızca şifreli veri taşınır ve okunabilir hâle cihazınızda getirilir. Dolayısıyla Apple ve Google bir ilaç adını veya kimin ne kaçırdığını göremez; yalnızca cihazınıza bir bildirim gittiğini ve zamanını bilirler.
Uygulamada Google AdMob banner reklamları gösterilir. Google Mobile Ads SDK'sı Google'a şunları iletir: reklam kimliğiniz, cihaz ve işletim sistemi bilgileri, IP adresiniz (bundan yaklaşık konum çıkarılabilir), reklam etkileşimleri ile SDK'nın kendi tanılama ve performans verileri. Bu veriler Google'ın veri sorumlusu/işleyeni olarak kendi politikalarına tabidir.
Uygulamada ayrı bir analitik veya çökme raporlama SDK'sı bulunmaz; yukarıda sayılan tanılama verisi reklam SDK'sının kendi işleyişinden kaynaklanır.
Avrupa Birliği, Birleşik Krallık ve İsviçre'deki kullanıcılara Google'ın onay çerçevesi (UMP) üzerinden bir onay ekranı gösterilir. Reklamları tek seferlik satın alma ile kaldırabilirsiniz; bu durumda banner'lar kapanır. Sağlık verilerinizle hedeflenmiş reklam gösterilmez ve doz verileriniz reklam amacıyla kullanılmaz.
"Reklamları kaldır" satın alması App Store veya Google Play üzerinden gerçekleşir. Ödeme bilgileriniz bize hiç ulaşmaz; yalnızca satın almanın yapılıp yapılmadığı bilgisini mağazadan alırız.
Verinizi satmıyoruz. Yalnızca hizmetin çalışması için gereken şu taraflar devrededir:
| Taraf | Rolü | Ne alıyor | Nerede |
|---|---|---|---|
| Apple | Bildirim iletimi (APNs), mağaza ve ödeme | Cihaz bildirim jetonu, şifreli bildirim içeriği | ABD |
| Bildirim iletimi (FCM), reklam (AdMob), mağaza | Cihaz bildirim jetonu, şifreli bildirim içeriği; ayrıca reklam kimliği ve cihaz bilgileri | ABD | |
| Barındırma sağlayıcımız | Sunucu altyapısı (veri işleyen) | Bölüm 3.2'deki tüm veriler, teknik olarak sunucuda bulunduğu ölçüde | Türkiye |
Ayrıca yasal bir yükümlülük doğması hâlinde yetkili makamlarla paylaşım gerekebilir. Böyle bir durumda dahi uçtan uca şifreli içeriği çözebilecek bir anahtara sahip olmadığımızı belirtiriz.
Aile özelliği için verdiğiniz rızayı dilediğiniz an geri çekebilirsiniz: aileden ayrılmak yeni bildirim gönderilmesini durdurur, hesabınızı silmek ise sunucudaki kaydınızı tamamen kaldırır (bölüm 10).
Sunucumuz Türkiye'dedir. Bildirim iletimi ve reklamlar nedeniyle sınırlı veri Apple ve Google'a (ABD) aktarılır. Türkiye dışındaki kullanıcılar için bu aktarım, aile özelliğini açarken verdiğiniz açık rızaya dayanır. Avrupa Ekonomik Alanı'ndaki kullanıcılar açısından Türkiye bir yeterlilik kararına sahip olmadığından, bu aktarım GDPR m.49(1)(a) kapsamında açık rızanıza dayanmaktadır ve rızanızı geri çekene kadar geçerlidir.
Saklama süreleri bölüm 3.2'deki tabloda kalem kalem yazılıdır. Özetle: kaçırılan doz kayıtları 7 gün, davet kodları 24 saat, sunucu erişim kayıtları en fazla 30 gün sonra silinir. Geri kalan her şey hesabınızı silene kadar durur.
Uygulama içinden silme: Ayarlar → Aile → "Aile hesabımı sil". Bu işlem sunucudaki hesabınızı, tüm aile üyeliklerinizi, bildirim jetonlarınızı ve yayımlanmış uyum özetlerinizi kalıcı olarak siler. Cihazınızdaki ilaç verileriniz silinmez; onlar sizde kalır.
Aileden ayrılmak ile hesabı silmek aynı şey değildir: ayrılmak yalnızca o aileyle bağınızı ve o ailede yayımlanmış özetinizi kaldırır, hesabınız durur.
Uygulama dışından silme: mustafa.ulukaya@appouse.com adresine yazabilirsiniz. Hesabınızı bulabilmemiz için uygulamadaki Aile ekranında gösterilen hesap kimliğini iletmeniz gerekir — başka hiçbir tanımlayıcı bilgimiz yoktur. Taleplere en geç 30 gün içinde yanıt veririz. Ayrıntılı yönerge: medreminder.appouse.com/delete-data
KVKK m.11 ve GDPR m.15–22 uyarınca; verilerinize erişme, düzeltilmesini, silinmesini veya işlenmesinin kısıtlanmasını isteme, işlemeye itiraz etme, verilerinizi taşınabilir biçimde alma ve rızanızı geri çekme haklarına sahipsiniz. Taşınabilirlik için ilaç verilerinizi zaten uygulama içinden JSON/CSV olarak dışa aktarabilirsiniz.
Talepleriniz için mustafa.ulukaya@appouse.com. Yanıt süremiz en fazla 30 gündür. Sonuçtan memnun kalmazsanız Türkiye'de Kişisel Verileri Koruma Kurumu'na, AB'de ise bulunduğunuz ülkenin denetim makamına şikâyette bulunabilirsiniz.
Sunucuyla tüm iletişim HTTPS üzerinden yapılır. Oturum jetonlarınız sunucuda düz olarak değil, karması alınarak saklanır. Aile içeriği cihazınızda şifrelenir ve anahtarı sunucuya hiç gitmez. Yine de bir veri ihlali yaşanırsa, ilgili mevzuatın öngördüğü süreler içinde (KVKK kapsamında Kurul'a en kısa sürede, GDPR kapsamında yetkili makama 72 saat içinde) bildirimde bulunur ve sizi bilgilendiririz.
MedReminder 13 yaşın altındaki çocuklara yönelik değildir ve bilerek onlara ait veri toplamayız. Bir ebeveyn veya bakıcı, çocuğunun ilaç takibini kendi cihazından yapabilir; bu durumda veriler ebeveynin hesabı altında işlenir. Bir çocuğa ait veriyi rızanız dışında işlediğimizi düşünüyorsanız bize yazın, silelim.
MedReminder bir tıbbi cihaz değildir; teşhis, tedavi veya acil durum izleme aracı olarak kullanılamaz. Bildirimlerin zamanında ulaşacağı garanti edilemez — işletim sistemi kısıtları, pil optimizasyonu, ağ kesintileri veya bildirim izinlerinin kapatılması bildirimleri geciktirebilir ya da engelleyebilir. İlaç kullanımınıza ilişkin kararları hekiminizle birlikte alın.
Bu politikayı güncellersek üstteki tarihi değiştiririz. Aile özelliğini etkileyen esaslı bir değişiklik olursa uygulama içinde onayınızı yeniden isteriz.
Last updated: 31 July 2026 · Version 2.0 (app version 1.2.0)
In short: MedReminder works offline by default. Your medications, schedules and dose history stay in a database on your device and are never sent to a server. Data leaves your phone only if you choose to create or join a "Family" — and that data is end-to-end encrypted on your device: your family members can read it, we cannot. Our server does see some unencrypted routing information, and we list every item of it below.
MedReminder is built and operated by Appouse Teknoloji Limited Şirketi.
The server behind the family feature is hosted in Türkiye
(family.medreminder.appouse.com).
The core of the app is entirely offline. The following live in a SQLite database on your phone and are never sent anywhere on their own:
The app disables automatic cloud backup: this database is not backed up to Google Drive or iCloud and is excluded from device-to-device transfer. If you want a copy, export it yourself as JSON or CSV from Settings → Export, and import it back whenever you like. Uninstalling the app deletes this database from your device.
When you create or join a family, a pseudonymous account is created on our server. It asks for no email, no phone number and no real name — it is a random identifier.
The following are encrypted on your device with AES-256-GCM. The decryption key is generated on the family founder's device and handed to new members wrapped so that only that member can open it (X25519). The key itself never reaches our server:
You alone decide whether medication names are shared, and the default is private: the family founder cannot change this on your behalf.
End-to-end encryption protects content, not routing. Our server sees and stores the following in the clear:
| Data | Why it is needed | Retention |
|---|---|---|
| Pseudonymous account id and your device's public key | Authenticating requests, wrapping the family key for you | Until you delete the account |
| A SHA-256 hash of your session token | Authentication | Until you delete the account |
| Account creation time and last-seen time | Operations and abuse detection | Until you delete the account |
| Who is in which family, their role and join date | Sending alerts to the right people | Until you leave or delete the account |
| Your sharing preference ("status only" / "with medication names") | Knowing what your device should send | Until you leave the family |
| Invite codes, who issued them and when they expire | Validating invitations | Invalid after 24 hours, then deleted |
| The fact that an alert exists: which family, from whom, at what time | Delivering the alert | 7 days |
| Who has read an alert | Not showing the same alert twice | 7 days |
| Your device's push token (APNs / FCM) and platform | Getting the alert to your device | Until you delete the account |
| Your IP address and request times in server access logs | Security, debugging, abuse prevention | At most 30 days |
We want to be explicit about one thing: the existence of an alert is itself information. Because a record is only ever written for a missed dose, even though we cannot see which medication is involved, we can technically see that "this account missed a dose at this time". These records are deleted automatically after 7 days.
The name you type when asking to join a family is transmitted in plain text at that moment — you do not yet hold that family's encryption key, and the founder has to be able to read the name to decide. That name is deleted from the server as soon as your request is approved or rejected, and requests that are never answered are cleaned up automatically after a period. You are not required to use your real name.
A family member can ask you for an up-to-date adherence summary. Your device receives a silent notification and uploads a fresh encrypted summary. You are not prompted when this happens; the uploaded summary is still readable only by your family members. The same silent-notification mechanism tells a founder about a join request and tells an approved member to collect their key.
Your medication reminders are generated entirely on your device and pass through no server. Only family alerts arrive remotely, via Apple (APNs) and Google (FCM). The delivered payload contains no readable text — only ciphertext, which is turned into words on your device. Apple and Google therefore cannot see a medication name or who missed what; they know only that a notification was sent to your device, and when.
The app shows Google AdMob banner ads. The Google Mobile Ads SDK sends Google your advertising identifier, device and OS information, your IP address (from which an approximate location can be derived), ad interactions, and the SDK's own diagnostic and performance data. That data is governed by Google's own policies, in its role as controller/processor.
The app ships no separate analytics or crash-reporting SDK; the diagnostic data described above originates from the ads SDK itself.
Users in the EU, UK and Switzerland are shown a consent screen through Google's consent framework (UMP). You can remove the ads with a one-time purchase, which turns the banners off. No advertising is targeted using health data, and your dose data is never used for advertising.
The "remove ads" purchase is handled by the App Store or Google Play. Your payment details never reach us; we only learn from the store whether the purchase was made.
We do not sell your data. Only the parties required to make the service work are involved:
| Party | Role | What it receives | Where |
|---|---|---|---|
| Apple | Notification delivery (APNs), store and payments | Device push token, encrypted alert payload | USA |
| Notification delivery (FCM), advertising (AdMob), store | Device push token, encrypted alert payload; plus advertising identifier and device information | USA | |
| Our hosting provider | Server infrastructure (processor) | Everything in section 3.2, to the extent it is technically present on the server | Türkiye |
We may also have to share data with authorities where a legal obligation arises. Even then, we hold no key capable of decrypting end-to-end encrypted content.
You can withdraw your consent to the family feature at any time: leaving a family stops new alerts, and deleting your account removes your record from the server entirely (section 10).
Our server is in Türkiye. Limited data is transferred to Apple and Google (USA) for notification delivery and advertising. For users outside Türkiye, this transfer relies on the explicit consent you give when enabling the family feature. For users in the European Economic Area, Türkiye is not covered by an adequacy decision, so this transfer relies on your explicit consent under GDPR Art 49(1)(a) and remains valid until you withdraw it.
Retention periods are listed item by item in the table in section 3.2. In summary: missed-dose records are deleted after 7 days, invite codes after 24 hours, and server access logs after at most 30 days. Everything else remains until you delete your account.
Deleting from inside the app: Settings → Family → "Delete my family account". This permanently removes your server-side account, all of your family memberships, your push tokens and any adherence summaries you published. Your medication data on the device is not deleted; that stays with you.
Leaving a family and deleting your account are different: leaving removes only your link to that family and the summary you published there, while your account remains.
Deleting from outside the app: write to mustafa.ulukaya@appouse.com. So that we can find your account, you must include the account id shown on the app's Family screen — we hold no other identifying information about you. We respond to requests within 30 days at the latest. Detailed instructions: medreminder.appouse.com/delete-data
Under GDPR Art 15–22 and KVKK Art 11 you have the right to access your data, to have it corrected, erased or its processing restricted, to object to processing, to receive your data in a portable form, and to withdraw your consent. For portability, you can already export your medication data as JSON or CSV from inside the app.
Send requests to mustafa.ulukaya@appouse.com. We respond within 30 days at the latest. If you are not satisfied with the outcome, you may complain to the Turkish Personal Data Protection Authority (KVKK) or, in the EU, to your national supervisory authority.
All communication with the server uses HTTPS. Session tokens are stored on the server as hashes, not in the clear. Family content is encrypted on your device and its key never reaches the server. Should a data breach nonetheless occur, we will notify the relevant authority within the periods required by law (without undue delay under KVKK; within 72 hours under GDPR) and inform you.
MedReminder is not directed at children under 13 and we do not knowingly collect their data. A parent or carer may track a child's medication from their own device, in which case the data is processed under the parent's account. If you believe we hold a child's data without your consent, write to us and we will delete it.
MedReminder is not a medical device and must not be used for diagnosis, treatment or emergency monitoring. Timely delivery of notifications cannot be guaranteed — operating system restrictions, battery optimisation, network outages or revoked notification permissions can delay or prevent them. Make decisions about your medication together with your doctor.
If we update this policy we will change the date at the top. If a change materially affects the family feature, we will ask for your consent again inside the app.