Skip to content

Privacy Policy

Effective 5 August 2026 · Last updated 5 August 2026

This policy explains what the Chatbot PGG iOS app does with your data. It is written against what the app and our servers actually do, not against a template.

The controller is Applus Mobil Hizmetler Limited Şirketi, Etiler Mah. Evliya Çelebi Cad. No:23 Kat:1/106, Muratpaşa / Antalya, Türkiye — [email protected].

The short version. There is no account and we never ask for your name, email or phone number. Your conversations are stored on your device, not on our servers. To answer you, your messages are sent through our server to an AI provider — we do not log or store the content of your prompts or the replies. Voice audio goes from your device straight to OpenAI, not through us.

1. No account, no sign-up

Chatbot PGG has no registration, no login and no profile. We do not collect your name, email address, phone number, postal address, date of birth, contacts, or precise location. We have no way to identify you as a person.

2. What is stored on your device

Your chat history — conversation titles, every message, generated images and voice transcripts — is stored locally on your iPhone in the app’s private container. It is not uploaded to us, and it is not synced between your devices.

Private Chat threads are never written to storage at all. They exist only in memory and disappear when the conversation ends. Note that a private chat is private on your device: the message is still transmitted to an AI provider in order to be answered, exactly as a normal chat is.

The app also keeps a small number of local preferences: your chosen voice, whether onboarding has been seen, a cached subscription flag, a cached copy of the remote configuration, and a daily message counter. None of these contain personal content.

3. What leaves your device, and to whom

Text chat

When you send a message, the app transmits the conversation thread — your messages and the previous replies in it, as plain text — to our server at api.chatbotpgg.com. Our server adds instructions about response language and formatting and forwards the request to OpenRouter, which routes it to the provider that serves the model you selected (OpenAI, Anthropic, Google, xAI or DeepSeek). The reply is streamed back to your device.

If you enable web search, your query is additionally processed by OpenRouter’s search integration.

Image generation

Your image prompt is sent to our server and forwarded to OpenAI. The generated image is returned to your device. Neither the prompt nor the image is stored by us.

Voice conversations

Voice works differently, and we want to be explicit about it:

Dictation

The microphone button in the composer uses Apple’s speech recognition. Where your device supports on-device recognition for your language, audio stays on the device. Where it does not, Apple processes the audio on its servers under Apple’s privacy policy. This is a system feature and we receive nothing from it.

Photos, camera and files

The app cannot upload your photos or documents. There is no image or file field in the request format it sends.

4. What our servers store

Our backend is a Cloudflare Worker acting as a streaming proxy. It does not write your prompts, your messages, the replies, your image prompts or the generated images to any database, log or file. Content passes through memory and is gone.

The only per-user records we keep are the counters needed to enforce subscription limits, all keyed to an anonymous identifier (see below):

RecordContentsRetention
Subscription status cacheWhether the identifier is a subscriber, which plan, expiry1 hour
Image credit ledgerCredits remaining, period end, planUntil 1 day after the period ends
Daily message counterA number48 hours

Cloudflare, as our hosting provider, processes standard request metadata (IP address, timestamp, path, status code, user agent) to route and protect traffic. Request and response bodies are not recorded.

5. Identifiers we handle

IdentifierWhat it isWhy
App user ID An anonymous, randomly generated ID created by RevenueCat. Not linked to your Apple ID, name or email. To apply your subscription and usage limits
Analytics instance ID An anonymous ID created by Google Analytics for Firebase To measure how the subscription screen performs
IP address Seen transiently by Cloudflare, by the AI providers, and by Google’s STUN server during voice calls Network routing and abuse prevention

We do not use the Advertising Identifier (IDFA). The app contains no advertising SDK, does no cross-app or cross-site tracking, and never presents an App Tracking Transparency prompt. We do not sell or share personal information, and we do not build advertising profiles.

6. Analytics

The app uses Google Analytics for Firebase, limited to the subscription screen. The events recorded are: the paywall being shown, a plan being selected, a purchase starting, succeeding, being cancelled or failing, a restore attempt, the screen being dismissed, and a locked feature being tapped. Their parameters are the plan and product identifier, price and currency, and error codes. A property records whether the device currently has an active subscription.

Firebase additionally collects a standard set of automatic measurements — first open, session start, app version, device model, operating-system version, and coarse country inferred from IP.

Your chat content is never sent to analytics. No message, prompt, reply, transcript or image is included in any event.

The app also fetches remote configuration from Firebase to control pricing copy and feature gating. That is a download; it sends no personal data.

7. Purchases

Subscriptions are sold by Apple through in-app purchase. We never see your payment card, billing address or Apple ID. We use RevenueCat to verify entitlements: it receives the App Store transaction data and the anonymous app user ID, and tells our server whether that ID is currently a subscriber.

To link purchase measurement with product analytics, the app sends the Firebase analytics instance ID to RevenueCat. It contains no personal information.

8. Device permissions

PermissionUsed for
MicrophoneVoice conversations and dictation. Only while you are actively using them.
Speech recognitionConverting your dictation into text in the composer.
Photo library (add only)Saving a generated image. This is add-only — the app cannot read your library.
CameraRequested by the attachment menu. Captured photos are currently discarded and never leave the device.

Every permission is optional. Declining one disables that feature and nothing else.

9. Sub-processors

ProviderPurposePolicy
CloudflareHosting our API and this websitePolicy
OpenRouterRouting text requests to model providersPolicy
OpenAIVoice conversations, image generation, some text modelsPolicy
AnthropicClaude modelsPolicy
GoogleGemini models; Firebase analytics and remote config; WebRTC STUNPolicy
xAIGrok modelsPolicy
DeepSeekDeepSeek modelsPolicy
RevenueCatSubscription verificationPolicy
AppleApp distribution, payments, speech recognitionPolicy

Providers may retain content briefly for abuse monitoring under their own terms. We do not control their retention. This list may change as models are added or removed; this page is updated when it does.

10. Retention

Chat history stays on your device until you delete it or remove the app. On our side, the only records are the counters in section 4, which expire automatically on the schedules listed there. We keep no long-term profile of you.

11. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. Under Turkish law (KVKK Art. 11) you have equivalent rights. Under the GDPR our legal bases are: performance of a contract for delivering the service and enforcing subscription limits; legitimate interests for abuse prevention and product measurement; and consent where you grant a device permission.

Because we hold no name, email or account, we usually cannot connect a request to a specific person. If you want us to act on the server-side counters, include the app user ID from the app — but understand that sending it to us links that identifier to your email address, which is otherwise not something we hold.

If you are in the EU/EEA or the UK you may complain to your supervisory authority. In Türkiye you may apply to the Personal Data Protection Authority (KVKK).

California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not knowingly process the personal information of anyone under 16 for such purposes.

12. Deleting your data

13. Children

The app is not directed to children under 13 and we do not knowingly collect their personal data. If you believe a child has provided personal data through the app, contact us and we will act on it.

14. International transfers

We operate from Türkiye. Our providers process data in the United States, the European Union and elsewhere. Transfers out of the EEA/UK rely on the transfer mechanisms our providers put in place, typically the European Commission’s Standard Contractual Clauses.

15. Changes

We will update this policy when the app changes what it does. The “Last updated” date at the top always reflects the current version. Material changes will be signalled in the app before they take effect.

16. Contact

Applus Mobil Hizmetler Limited Şirketi
Etiler Mah. Evliya Çelebi Cad. No:23 Kat:1/106
Muratpaşa / Antalya, Türkiye
[email protected]