Privacy Policy and Data Protection Notice
The short version: if you don't have an account, the texts you write never leave your device. If you do, your progress and your writing are stored with your account only so we can give them back to you — they are never shown to anyone and never enter the measurement pipeline. We use a cookieless Google Analytics setup for measurement; there are no advertising or tracking cookies. We don't keep raw IP addresses in our application database. The full list of what we collect and don't collect is below.
About this translation
This is an English translation of the Turkish original, provided for convenience. The Turkish text is the binding version; if the two ever differ, the Turkish text prevails. This translation corresponds to version 1.5 of the Turkish text, in force since 2026-09-27.
1. Data controller
This notice is prepared to fulfil the duty to inform under Turkey's Law No. 6698 on the Protection of Personal Data (KVKK). The operator of Senaryo Okulu and the data controller is PARTHENİA MEDYA.
For any question, request or application, use the form on the Contact page (the page is in Turkish).
2. What data do we collect?
The list below is complete; we do not collect any data that isn't written here.
- Account details (only if you signed up): email address, your name, the name shown in the community (generated from the name you entered at sign-up; you can change it on your profile until your first post), and the time of sign-up and last login. Your password is not stored as plain text; only a cryptographic digest produced with the scrypt algorithm and a salt unique to your account is kept.
- If you signed in with Google: Google passes us only your email address, your name and the fact that your email is verified. Your Google password never reaches us. If you had already signed up with the same email address, no new account is created; you are connected to your existing account.
- Profile details (only if you fill them in): role, short bio, city, interests and profile photo.
- Your work (only if you signed up): your lesson progress, exercise answers, Film Lab notes and the project texts in Senaryum. These are stored with your account so you can continue where you left off on another device. Only you can read them: they are never shown to anyone, never made searchable, never enter the measurement pipeline and are never used to train AI. If you don't have an account, none of this leaves your device.
- Community content: your posts, comments, likes, connection requests, team listings and the private messages you send. Private messages are stored on the server as plain text; they are not end-to-end encrypted.
- Community records: the list of members you have blocked, the community notifications you receive (comments, likes, connection requests and the like) and the contribution record kept to calculate your community level (which post or comment counted as a contribution).
- Acceptance record: which version of the Terms of Use you accepted when you signed up, and when.
- Password reset: when you ask for a link, we store only a cryptographic digest of the link and its expiry — not the link itself.
- Live lesson and class records (only if you enrolled in a lesson or class): which session or programme you are enrolled in, the status of your enrolment, when you joined the lessons and the projects you chose to share with the class (which the instructor can then see, read-only).
- Notification subscription (only if you allowed notifications): the notification address of your device or browser, the subscription type (web or mobile app) and when the last notification was sent. This record is not linked to your name, email address or account.
- Email list (only if you joined): your email address, the page you joined from, a link to your account if you have one, a pseudonymous identifier derived from your IP address, and whether you are still on the list.
- Contact form: name, email address, topic, message text, the page you filled the form on and a pseudonymous identifier derived from your IP address.
- Usage measurement: a pseudonymous participant code, a two-letter country code, device type (phone/tablet/desktop), the surface you use (website, Android or iPhone app), interface language, version information and event counters (such as which lesson was opened or which button was pressed).
- Library search queries: the searched word (at most 50 characters). These records hold no participant code — nobody knows who searched.
3. What data do we not collect?
This is the most important part of the policy, because it is where most platforms stay silent.
- None of your writing is sent to the measurement pipeline. Your loglines, scenes and screenplay never go there; only a number like 'how many characters were written' does. (If you have an account, the same texts are stored as described above, only to be given back to you — that is a separate, closed channel.)
- Raw IP addresses are not kept in our application database. Measurement keeps only a two-letter country code; not even the city. In the contact form, a pseudonymous identifier generated with our server secret is stored instead of the address itself.
- No free text, name or email address goes to the usage measurement pipeline. A two-layer allow-list runs on the server: any field not on the list is dropped without being saved.
- We don't use advertising or marketing trackers: there is no Meta Pixel, Google Tag Manager, Google Ads conversion tag, Hotjar or anything similar on the site. The only third-party measurement tool we use is the cookieless Google Analytics setup described in section 5.
- We don't use advertising or tracking cookies.
- We don't use the texts our users write to train AI models.
4. Measurement is pseudonymous, not anonymous
We state this distinction openly because calling it 'anonymous' would be wrong. A random participant code is written to your browser once. This code is not linked to your name, email address or account; but because it links visits from the same browser to each other, the data is pseudonymous, not anonymous.
The code has no expiry: it stays until you clear your browser data or reset your progress in the app.
The only exception is library search queries — those records never hold a participant code and are genuinely anonymous.
5. Cookies and browser storage
The site uses a single cookie: the session cookie (so_oturum). It is created only when you log in, keeps you logged in and expires after 30 days.
This cookie is HttpOnly (JavaScript on the page can't read it), protected with SameSite=Lax, sent only over a secure connection in production, and its content is signed — if it is altered it becomes invalid.
We use Google Analytics for visitor measurement, but the setup is COOKIELESS: Google's own _ga cookie is never created. Instead, two random numbers are kept in the browser's local storage (one visitor number, one session number). These numbers are not linked to your name, email address or account. Advertising signals are denied from the start: the data is not passed to Google Ads and is not used for ad personalisation.
Your progress, projects and preferences are also kept in the browser's local storage, not in cookies. This data is not carried to the server by cookies; it goes there only through the account sync described in section 2, and only if you have an account.
That is why no cookie consent banner is shown at the moment: there are no advertising or tracking cookies on the site, and the only cookie used is the essential one that keeps the session alive. If an optional cookie is added in the future, this will be reconsidered.
6. For what purpose and on what legal basis do we process data?
- Account and profile details — to run your membership, let you log in and identify you in the community. Legal basis: the establishment and performance of a contract (KVKK art. 5/2-c).
- Your work (lesson progress and the texts you write) — so you can continue where you left off on another device. Legal basis: performance of a contract (KVKK art. 5/2-c).
- Community content — to run the community, moderate it and prevent abuse. Legal basis: performance of a contract and legitimate interest (KVKK art. 5/2-c and 5/2-f).
- Live lesson and class records — so the lesson or class you enrolled in can run. Legal basis: performance of a contract (KVKK art. 5/2-c).
- Acceptance record — to be able to show which terms you accepted when needed. Legal basis: the establishment, exercise or protection of a right (KVKK art. 5/2-e).
- Notification subscription and email list — only to send the reminders and announcements you turned on. You can turn both off at any time.
- Contact form — to answer your request. Legal basis: legitimate interest and processing on request (KVKK art. 5/2-f).
- Usage measurement — to understand which lessons work and improve the product. This data is not associated with your identity.
- Spam and abuse prevention — for the security of the service. Legal basis: legitimate interest (KVKK art. 5/2-f).
7. Who do we share it with?
We don't sell your personal data and don't transfer it to third parties for marketing. Only the infrastructure providers needed for the service to work are used, and their servers may be located outside Turkey:
- Vercel — hosting the site.
- Supabase — database and profile photo storage.
- ImprovMX — forwarding emails sent to our organisational address.
- Resend — delivering the emails the platform sends: contact form notifications and replies, password reset links and notices about your account.
- Daily — video and audio in live lessons. Only if you join a live lesson are your camera and microphone passed to the other participants through this service. Lessons are not recorded.
- Google (Analytics) — visitor and page measurement. The setup is cookieless; advertising signals are denied from the start and data is not passed to Google Ads. Measurement runs only on senaryookulu.com.
- Google (sign-in) — if you use 'Continue with Google', Google verifies your identity. If you don't use this option, no such exchange with Google takes place.
- TMDB — film posters in the Agenda section are loaded from this service's servers.
- Google (Firebase Cloud Messaging) — sending reminder notifications in the mobile app. If you allow notifications, your device's notification address (token) is passed to Google. The notification text comes from a fixed list; which lesson you stopped at, what you wrote or your name never goes into a notification. If you don't allow notifications, no such exchange takes place.
- Apple (Push Notification service) — in the iPhone app, notifications are delivered to the device through Apple's own service.
8. Technical logs of infrastructure providers
We wrote above that we don't keep raw IP addresses in our application database. Nevertheless, the infrastructure providers that run the site (Vercel, Supabase) and the email providers (ImprovMX, Resend) may keep IP addresses in their own technical logs for a period.
We don't access these logs for product purposes; they are subject to the providers' own security and operating processes. We state this openly so you can see the full picture.
9. How long do we keep it?
- Account and profile details: as long as your account stays open. They are deleted the moment you delete your account.
- Your work tied to your account (lesson progress and the texts you write): as long as your account stays open. When your account is deleted, these are deleted too. This data is kept only to give it back to you and isn't tied to a retention period — it is there so you don't lose your own work.
- Community posts and comments: until you delete them or moderation removes them.
- Contact form messages: 24 months. They are deleted from the database automatically when the period ends.
- Usage measurement records and search queries: 24 months. They are deleted automatically when the period ends.
- Spam protection records: 30 days. Deleted automatically.
- Password reset records: the link is valid for 60 minutes; the record is deleted automatically after 7 days.
- Live lesson and class records: as long as your account stays open. When your account is deleted, these are deleted too.
- Notification subscription: until you withdraw your permission, turn notifications off in the app, or the device stops receiving notifications.
- Email list: until you leave the list. When you leave, your address stays marked as 'left' so that you are never written to again; this record is deleted automatically after 24 months. If you delete your account, you are removed from the list immediately.
- Acceptance record: kept as proof of acceptance even if you delete your account. This record contains not your email address but a digest derived from it, the version of the document and the date of acceptance.
10. Your rights (KVKK art. 11)
Under Article 11 of the KVKK, you have the right to learn whether your personal data is processed; to request information about it if it is; to learn the purpose of processing; to know the third parties in Turkey or abroad to whom it is transferred; to ask for it to be corrected if it is incomplete or inaccurate; to ask for it to be deleted or destroyed; to ask that these actions be notified to the third parties to whom the data was transferred; to object to an outcome against you arising from analysis by automated systems; and to claim compensation if you suffer damage.
Fill in the form on the Contact page (senaryookulu.com/en/contact) with the topic "Personal data request".
Applications are concluded within 30 days at the latest.
You can turn measurement and notifications off yourself: in the mobile app, the “Usage measurement” and “Reminder notification” rows on the Me tab are two-way switches. When you turn measurement off, no new records are written, the records gathered on the device are deleted and your participant code is dropped. When you turn notifications off, your device's notification address is deleted from our records.
You don't need to apply to delete your account: the “Delete my account” button at the bottom of your Community profile page (on the Me tab in the mobile app) removes your account and the data tied to it the moment you confirm. Before deleting, the screen lists exactly what will go, and the action can't be undone.
11. Security
- Passwords are not stored as plain text; they are digested with the scrypt algorithm using a salt unique to each account.
- Session information is carried in a signed, HttpOnly cookie; JavaScript on the page can't access it.
- Row-level security is on for every table in the database; no table can be accessed directly from the browser, and data is read and written only through server-side endpoints.
- Profile photo file names are random; they are not derived from your email address, so no identity can be inferred from the file name. Location and other EXIF data in an uploaded photo is dropped during resizing.
- The contact form doesn't store the IP address directly; it keeps a pseudonymous identifier generated with a key tied to the server secret. This value can't be reversed without the secret, but it is treated as personal data and protected as such.
12. Age limit
The platform is not designed for users under 13. If you are under 18, you should act with the knowledge of a parent or guardian before opening an account.
13. Changes
The version of this notice in force is 1.5, in force since 2026-09-27. The text is updated as the product changes; for significant changes the version number is increased and an announcement is also made.
Frequently asked questions
If you don't have an account, your texts never leave your device. If you do, they are stored with your account so you can continue on another device — not so we can read them, but so we can give them back to you. They are never shown to anyone, never made searchable, never enter the measurement pipeline and are never used to train AI. If you don't want to show us your text, you can work without an account; then nothing leaves your device.
Google knows you signed in to Senaryo Okulu — it is the one verifying your identity. What it passes to us is only your email address, your name and the fact that your email is verified. Your Google password never reaches us. What you read or write on the site doesn't reach Google this way. You never have to use this option: signing up with email and password is always available.
We don't keep raw IP addresses in our application database: measurement keeps only a two-letter country code, and the contact form stores a pseudonymous identifier instead of the address itself. However, our hosting providers may keep IP addresses in their own technical logs for a period.
No, it's pseudonymous. The participant code written to your browser isn't linked to your name or account, but it links visits from the same browser, so calling it 'anonymous' would be wrong. The only truly anonymous record type is library search queries; they hold no participant code at all.
There are no advertising or tracking cookies on the site. We use Google Analytics for visitor measurement, but the setup is cookieless: Google's _ga cookie is never created and advertising signals are denied from the start. The only cookie left is the essential session cookie that keeps you logged in. If an optional cookie is added in the future, this will be reconsidered.
The fastest way is in your own hands: the “Delete my account” button on your Community profile page deletes your account and the data tied to it the moment you confirm — no waiting. If you only want a copy of your data or want something corrected, use the application route. Fill in the form on the Contact page (senaryookulu.com/en/contact) with the topic "Personal data request". Applications are concluded within 30 days at the latest.
Related reading
Last updated: September 27, 2026