bindlestory
Terms Privacy KVKK

Privacy Policy

Last updated: July 2, 2026

This Privacy Policy describes what we collect, how we use it, and the choices you have. It applies to the Bindlestory mobile application and related services (together, the "Service").

1. Information We Collect

Account information. When you sign up we collect your email address, display name, chosen sign-in method (email/password, Sign in with Apple, or Google Sign-In), and preferred language.

Voice recordings (biometric data). To clone your voice, we collect short audio samples you record in-app. We also collect a per-language consent recording in which you read a scripted phrase. Voice recordings are biometric data under applicable privacy laws. From these recordings we also derive a mathematical voiceprint (a numerical embedding) that we use to check that the person giving consent is the same person whose voice is being cloned — a safeguard against someone cloning another person's voice without permission. This voiceprint is biometric data too, and like your recordings it is generated and processed only inside the European Economic Area.

Content you create. Text you paste or upload for narration, extracted text from documents you upload (PDF, EPUB, DOCX, ODT, plain text), generated audiobooks, cover art, bookmarks, and playback positions.

Content fingerprints. For every piece of text we process, we compute and store a SHA-256 fingerprint of the normalised text. The fingerprint is used to deduplicate identical uploads and — where we have actioned a DMCA notice against a specific piece of content — to prevent re-uploads of the same material. See Section 9 (DMCA) for how the fingerprint interacts with takedown notices.

Payment information. We do not see your full payment details. In-app purchases are processed by your device's app store, and a subscription-management partner records your subscription state on our behalf. We receive a customer identifier, the product you bought, and its status (active, cancelled, expired, trial).

Friends and sharing data. If you use the Sharing with Friends feature, we collect and store:

  • your mutual friend relationships, including who sent the original request and when;
  • a pseudonymous 8-character "friend code" we generate for you, which you can share with others to let them send you friend requests;
  • the email address of anyone you invite by email (retained only until they accept or the invite expires);
  • the audiobooks you explicitly share with specific friends, including an acknowledgement timestamp and the Terms version under which you acknowledged your redistribution rights;
  • your list of blocked users, if any.

Shared content access logs. When a friend plays an audiobook you have shared with them, we log the authorisation event for audit purposes. Aggregate access counts may be shown to the audiobook's owner; individual play events are not surfaced to the owner.

Device and usage data. IP address, device model, operating system and version, app version, locale, timezone, and diagnostic logs. We use this to detect abuse, debug issues, and measure feature usage.

Website visits and launch waitlist. When you visit our website, Cloudflare — our content-delivery network — processes your IP address to deliver the site and protect it from abuse, derives an approximate country from it, and gives us a cookieless count of page views. That count is how we know how many people visit and roughly where from. We do not run advertising trackers, the website sets no cookies, and nothing on it follows you to other sites. Our webfonts are served from our own servers rather than embedded from a third party, so visiting our site does not disclose your IP address to a font provider. If you join the launch waitlist, we additionally store your email address and that approximate country, so we can send you a single launch notification when we open in your region and count how many prospective users are in each jurisdiction for our data-protection compliance. We use waitlist data only for that one launch email — never for marketing — and remove it on request.

2. How We Use Your Information

We use your information to:

  • run and secure the Service (authentication, abuse detection, moderation);
  • parse, chunk, and process your uploaded text through our automated text-to-speech pipeline to generate audiobooks, as described in the Terms of Service;
  • train a personalized voice model scoped to your account;
  • verify, using speaker-recognition technology, that your per-language consent recording matches the voice in your voice samples, so that the Service cannot be used to clone another person's voice without their consent;
  • generate audiobooks you request;
  • operate the Sharing with Friends feature — resolving friend codes, delivering friend requests, routing shares to the right recipients, and controlling recipients' access to shared audiobooks;
  • protect rights-holders and comply with our Digital Millennium Copyright Act ("DMCA") obligations, including maintaining a content-fingerprint blocklist seeded by notices we have actioned;
  • process payments and maintain subscription state;
  • communicate with you about your account, important changes to the Service, and support requests;
  • send you optional product updates and tips by email — only if you ticked the "Send me product updates and tips" box during sign-up or later in Profile → Preferences. We record the timestamp of your opt-in as proof of consent (GDPR Art. 7(1)) and the source of the opt-in (sign-up or settings). Every marketing email includes an unsubscribe link, and you can withdraw consent at any time from your profile or by contacting [email protected]. Withdrawing marketing consent does not affect transactional emails (account, billing, important Service changes), which we send regardless of marketing opt-in status;
  • determine which data-protection laws apply to you (for example EU or UK GDPR, or Turkish KVKK) from the approximate country derived from your IP address, so we can meet the corresponding legal obligations;
  • comply with legal obligations.

We do not sell your personal information or Your Content. We do not use Your Content to train generative models for anyone other than you.

3. Legal Basis for Processing (GDPR & KVKK)

We process your personal information on the following legal bases:

  • Contract. Providing the Service you asked for, including the friends and sharing features you opt into.
  • Consent. For voice biometric data, marketing communications, and any optional data we collect beyond what's necessary to operate the Service. You can withdraw consent at any time.
  • Legitimate interest. Security, fraud prevention, rights-holder protection, service improvement.
  • Legal obligation. Tax, accounting, responding to lawful requests, and DMCA §512 record-keeping.

Because Bindlestory is established in Türkiye, the Turkish Personal Data Protection Law No. 6698 ("KVKK") applies alongside GDPR. The bases above correspond to the processing conditions in KVKK Article 5. Your voice recordings are special-category (biometric) data under KVKK Article 6 as well as GDPR Article 9, and we process them only with your explicit consent (açık rıza), collected per language before any voice processing begins.

You can reach us at [email protected] at any time to exercise these rights or to ask a question about how we process your data.

4. Who We Share With

We share information with third parties only as needed to operate the Service, and only to the minimum extent required for each purpose:

  • Cloud infrastructure to host our databases, cache, and object storage.
  • Text-to-speech processing to turn your text and voice reference into narrated audio.
  • Transcription to verify that voice-consent recordings match the expected language and phrase.
  • Content moderation to screen story text for prohibited content (toxicity and self-harm) before an audiobook is generated.
  • Payments and subscription management to operate in-app purchases and record your subscription state.
  • Email delivery to send friend invites, DMCA correspondence, and transactional messages.
  • Observability to collect crash reports and diagnostic logs.
  • Legal or safety. If required to comply with law, to respond to a DMCA notice or counter-notification, to enforce the Terms, or to protect users, we may disclose information to authorities, to rights-holders, or to the complaining party.

Each processor is bound by a data-processing agreement that restricts them to using information only for the purposes we specify. Your biometric voice data — your voice recordings and their transcription — is processed only inside the European Economic Area, and is never sent to any of the United States-based processors listed below. Some non-voice data (such as story text for cleanup and moderation, subscription state, and sign-in identifiers) is processed by providers located in the United States. For those transfers we rely on the European Commission's Standard Contractual Clauses ("SCCs").

The processors we currently use are:

Processor What they do for us Data location Transfer safeguard
Scaleway Object storage (generated audio, cover art) EEA (France) Within EEA
Hetzner Servers hosting our API, database, self-hosted voice transcription, and self-hosted crash reporting (disabled during child listening sessions) EEA (Germany) Within EEA
RunPod GPU compute for voice generation and voice-model training EEA regions only Within EEA
NVIDIA AI cover-image generation US SCCs
Together AI LLM text cleanup of story text US SCCs
OpenAI Text moderation (self-harm screening of story text only; never voice) US SCCs
RevenueCat Subscription and billing management US SCCs
Apple In-App Purchase and Sign in with Apple US SCCs
Google Google Sign-In; automated text moderation of story text (Perspective API) US SCCs
Resend Transactional and invite email delivery (email addresses only) US SCCs
Cloudflare Website delivery and protection, cookieless visitor statistics, launch-waitlist form (website only — never the app or your content) Global edge SCCs

To be explicit: your voice recordings and their transcription are not sent to any of the United States-based processors above (NVIDIA, Together AI, OpenAI, RevenueCat, Apple, Google, Resend, or Cloudflare). Voice generation, voice-model training, storage, and transcription all take place inside the European Economic Area. The specific vendors above may change over time; when they do, we will update this list and, where the change is material, notify you under Section 12.

We do not share your data with other Bindlestory users beyond what the features themselves require. Specifically, when you accept a friend request or receive a shared audiobook, the counter-party sees your display name, avatar, and — for shares — the metadata of the audiobook being shared with you (title, duration, cover). Your email address is never exposed to another user through the friends feature; email is only used to deliver an invite and is stored on the invite row until it is accepted or expires.

5. International Transfers

Bindlestory's infrastructure is located inside the European Economic Area, and all biometric voice data is processed exclusively within the European Economic Area. Because Bindlestory is established in Türkiye, personal data is transferred from Türkiye to that EEA infrastructure and to the processors listed in Section 4; these transfers abroad are carried out under the mechanisms provided by KVKK Article 9, including your explicit consent where required. When non-voice information is transferred outside the European Economic Area — for example to the United States-based processors listed in Section 4 — we rely on approved transfer mechanisms such as the Standard Contractual Clauses.

6. Data Retention

  • Account data. Kept while your account is active. On deletion, we remove it within 30 days except where law requires longer retention.
  • Voice recordings. Stored as long as the related voice profile exists. When you delete a voice profile, the underlying audio and derived model adapters are deleted within 30 days.
  • Welcome demo recordings. The short voice sample from the optional welcome demo is kept for up to 24 hours so you can replay your demo clip or save that voice as a voice profile, then deleted automatically. Dismissing the demo or signing out deletes it immediately; a failed demo deletes it right away. If you save the voice, the sample becomes a voice recording (previous bullet). The generated demo clip follows the same 24-hour lifetime.
  • Consent recordings. Retained for up to 7 years after account deletion, retained for legal defense of the consent you gave. This is one of the categories kept after account deletion; it is stored encrypted and accessed only on a lawful-access basis.
  • Uploaded content and generated audiobooks. Retained while your account is active. On account deletion they are removed within 30 days.
  • Content fingerprints. Retained for the life of the related upload. Fingerprints that have been added to the DMCA blocklist under Section 9 are retained for the duration of the blocklist entry regardless of whether the original uploading account still exists.
  • Friend relationships, blocks, shares. Retained while both parties' accounts are active. Deletion of either account cascades to the friendship and to any shares between the pair. Shares are also revoked when an audiobook is deleted or flagged.
  • Content-encryption-key material. When a friend caches a shared audiobook for offline playback, the per-share key is stored server-side in sealed form and on the recipient's device inside the platform keystore (iOS Keychain, Android Keystore). When a share is revoked, rotated, or the recipient signs out, the server stops issuing the key and the device deletes its local copy on the next sync. Orphaned keys are purged within the account-deletion window.
  • DMCA audit logs. Copyright-relevant audit entries (upload acknowledgement, share acknowledgement, DMCA strikes, takedown actions, admin flags) are retained for up to 7 years regardless of account status, as required for DMCA record-keeping.
  • Payment records. 7 years, as required by tax law.
  • Diagnostic logs. 90 days.

7. Your Rights

Depending on where you live, you may have rights under GDPR, KVKK (Article 11), CCPA, or similar laws to:

  • access the personal information we hold about you;
  • correct inaccurate information;
  • delete your information ("right to erasure");
  • export your data in a portable format, including your friend list and share history;
  • object to certain processing or withdraw consent;
  • lodge a complaint with your local data protection authority in the European Economic Area, or with the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) if you are in Türkiye.

You can export your data and request account deletion from the app's Settings screen. For other requests, email [email protected].

8. Children

Bindlestory is intended for adults (16+). Users under 16 are not permitted to sign up for Bindlestory, record a voice sample, or otherwise use the Service on their own behalf. Adults may add children as listener-only sub-profiles under their family account. We do not knowingly collect data from children beyond the minimum needed to operate playback (a display name; no email, no standalone account, no voice recording, no friends activity, no sharing).

Child sub-profiles may not use the Sharing with Friends feature in any form: they cannot send or receive friend requests, cannot hold a friend code, cannot appear in another user's friend list, and cannot be the recipient of a shared audiobook. This is enforced both in the app and at the server level.

The adult account holder who adds a child sub-profile is the legal guardian of that profile on the platform, is responsible for the child's use of the Service, and is responsible for compliance with our Terms of Service and community rules on that child's behalf. Parents and guardians should review both the Privacy Policy and the Terms of Service before adding a child, and should supervise the child's listening sessions to stay informed about what's playing back.

Because under-16s cannot hold a Bindlestory account, a child sub-profile doesn't have its own privacy settings; the parent profile's settings apply, and any data-subject request (access, deletion, export) is initiated by the parent on behalf of the child profile. If you believe we have collected information from a child outside this flow, contact [email protected] and we will delete it.

9. DMCA, Abuse Reports, and Rights-Holder Correspondence

If a rights-holder submits a DMCA takedown notice targeting content you have uploaded or shared, we will:

  • disable access to the identified content and pause or revoke any active shares of that content;
  • record a strike against your account under the repeat-offender policy described in our Terms of Service;
  • notify you, with enough information for you to submit a counter-notification if you believe the notice was incorrect.

When we correspond with the complaining rights-holder, we disclose only the information necessary to process the notice. We do not disclose the identity of the complaining party to you beyond what is required by law or required to enable a valid counter-notification under 17 U.S.C. § 512(g)(3).

Non-copyright abuse reports — including unauthorised voice cloning, deepfake misuse, impersonation, non-consensual intimate audio, and harassment — are handled under Section 11 of the Terms of Service and are routed to [email protected]. When we correspond with the reporter, with authorities, or with a data protection authority about an abuse report, we disclose only the information necessary to process it. Where AI-generated audio is the subject of a report, we may use the inaudible perceptual watermark described in Section 11 of this Policy to confirm that the audio originated from our Service.

Our designated agent for DMCA notices is:

  • Agent: Haydar Öztürk
  • Registration number (United States Copyright Office): DMCA-1071796
  • Email: [email protected]

10. Security and Safeguards Against Misuse

We use industry-standard safeguards including encryption in transit and at rest, hashed passwords, scoped access tokens with rotation, and access logging. No system is perfectly secure, so we encourage you to use a strong, unique password and to enable biometric unlock if your device supports it.

Protecting voices, rights-holders, and other people. Because the Service creates voice clones and audiobooks, we operate a layered set of measures to deter and detect misuse — voice impersonation, deepfakes, and copyright infringement. Without disclosing details that would help someone evade them, these include:

  • Consent voice-matching. Before a voice can be used, we check with speaker-recognition technology that the person recording the consent phrase is the same person whose voice is being cloned (see Sections 1 and 2). A mismatch blocks the voice and can trigger review.
  • Human review of consent. Consent recordings can be reviewed by our team; a lifetime total of three rejected consents freezes the account pending appeal.
  • Automated content moderation. Uploaded text is screened by automated moderation for prohibited content before an audiobook is generated, as described in our Terms of Service.
  • Copyright re-upload prevention. When we action a copyright takedown, we record a content fingerprint of the material so the same content cannot simply be re-uploaded (Section 9).
  • AI-provenance watermarking. Every audiobook we generate carries an inaudible watermark that lets us and third parties confirm the audio came from our Service (Section 11).
  • Abuse reporting and enforcement. Anyone — user or not — can report a voice or audiobook, and we operate a three-strike enforcement policy that can suspend sharing, freeze accounts, and, in serious cases, terminate them and preserve evidence for lawful-access requests (Terms of Service Sections 10–12).

We describe these here in good faith so you understand the protections in place. We deliberately do not publish the thresholds, models, or internal signals behind them, because doing so would help bad actors circumvent them.

For the Sharing with Friends feature, we apply additional technical protections:

  • Each shared audiobook is protected by a per-share content-encryption key ("CEK"). The CEK is generated server-side, sealed with a server-held master key, and persisted to the database sealed;
  • When a recipient caches a shared audiobook for offline playback, the plaintext CEK is returned over TLS to the recipient's device and stored in the platform keystore (iOS Keychain / Android Keystore) with a "when unlocked, this device only" access policy;
  • On-device ciphertext is written to the app's sandboxed document storage using AES-256-GCM. The app decrypts into a short-lived temporary plaintext file in its cache directory only for the duration of an active playback session, and purges that temporary file on unload, sign-out, and subsequent app launch;
  • When a share is revoked, rotated, or the recipient signs out, the app deletes the local ciphertext and keystore entry. The Service refuses to issue new CEKs for revoked or paused shares.

These measures raise the effort required to extract or redistribute shared audiobook audio. They do not guarantee technical impossibility on rooted or jailbroken devices, and the limited licence granted to recipients under the Terms of Service prohibits any attempt to circumvent them.

When you add a child sub-profile, the platform requires you to set a 6-digit PIN on your parent profile. This PIN is what stops the child from switching back to your creator context — keep it private from the child as part of the supervision responsibility described in Section 8.

11. AI Transparency

Audiobook audio generated by the Service carries an inaudible perceptual watermark that identifies it as AI-generated and lets Bindlestory, rights-holders, platforms, and law enforcement verify that a given audio file originated from our pipeline. The watermark carries no personal information about you — it identifies the Service, not the user. We generate the watermark as part of the text-to-speech pipeline described in Section 2; no additional personal data is collected to produce it. See Terms of Service Section 5 for the related use terms, and Section 9 of this Policy for how the watermark is used when we action an abuse report.

12. Changes to This Policy

When we make material changes to this policy we will notify you in-app and require you to re-accept before continuing to use the Service. Minor clarifications that do not change your rights will be noted with a revised "Last updated" date above.

13. Contact

Our data controller (veri sorumlusu under KVKK) is Haydar Öztürk (operating as Bindlestory), Esentepe Mah. Zincirlidere Cad. No: 86, Şişli, İstanbul, Türkiye, reachable at [email protected].

Our representative in the EU/EEA, the United Kingdom, and Switzerland. Bindlestory is established in Türkiye and has no establishment inside the EU/EEA, the United Kingdom, or Switzerland, so we have appointed Data Protection Representative Limited (trading as "DataRep") as our data protection representative under Article 27 of the EU GDPR, Article 27 of the UK GDPR, and Article 14 of the Swiss FADP. If you are in one of those places, you can raise anything about our processing of your personal data with DataRep instead of, or as well as, with us:

  • Online: www.datarep.com/data-request
  • By post: DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland; in the United Kingdom, DataRep, 107-111 Fleet Street, London, EC4A 2AB; in Switzerland, DataRep, Leutschenbachstrasse 95, Zurich, 8050. Address postal correspondence to "DataRep" — not to Bindlestory — or it may not reach them, and mention Bindlestory in the letter so DataRep can match it to us.

DataRep is our representative for data-protection matters only. For anything about the Service itself — your account, a subscription, an audiobook — write to [email protected]. To make a privacy request directly to us, use [email protected]; both routes reach the same controller. DMCA notices and counter-notifications should be sent to [email protected] per Section 9. Non-copyright abuse reports should be sent to [email protected] per Section 9. We aim to respond to GDPR and KVKK requests within 7 days; in cases where the request requires significant review or involves a large volume of data, our response may take up to 30 days, as permitted under GDPR and under KVKK Article 13.

bindlestory

Need help or have feedback? Email [email protected].

For copyright concerns, see the DMCA notice in our Terms of Service.

© 2026 Bindlestory · Crafted for the quiet hours.

Support Report content Guidelines Privacy Terms KVKK