Privacy Policy
Last updated: July 13, 2026
Your privacy matters. This policy explains what data we collect, why we collect it, and how you can control it.
For users in Türkiye (KVKK)
If you are in Türkiye, Turkish Law No. 6698 (KVKK) may give you additional rights regarding your personal data. You can exercise those rights via kvkk@gtaup.com or privacy@gtaup.com. We aim to respond within 30 days. You may also complain to the Turkish Personal Data Protection Authority (KVKK Board) if you are not satisfied with our response. This notice does not mean GTAUP is a company incorporated in Türkiye.
Table of Contents
- 1. Introduction
- 2. Data Controller
- 3. Personal Data We Collect
- 4. Legal Basis for Processing
- 5. How We Use Your Data
- 6. Data Sharing and Third Parties
- 7. International Data Transfers
- 8. Data Retention
- 9. Cookies and Similar Technologies
- 10. Data Security
- 11. Your Rights
- 12. Children's Privacy
- 13. Do Not Track Signals
- 14. Data Breach Notification
- 15. Changes to This Policy
- 16. Contact Us
1. Introduction
This Privacy Policy ("Policy") explains how GTAUP ("GTAUP," "we," "us," or "our") collects, uses, stores, shares, and protects personal data when you access or use the GTAUP website, applications, APIs, or any related services (collectively, the "Service"). Registered company details will be published here when incorporation is complete.
We are committed to protecting your privacy and handling your personal data transparently and lawfully. Depending on where you live and how the Service is provided, this Policy is intended to align with:
- GDPR — EU General Data Protection Regulation (Regulation 2016/679), where it applies;
- UK GDPR and equivalent UK rules, where they apply;
- KVKK — Turkish Law No. 6698, where it applies to you as a data subject in Türkiye;
- CCPA / CPRA — California Consumer Privacy Act and California Privacy Rights Act, where they apply;
- Other applicable data protection laws in the jurisdictions where our users are located.
By using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with our data practices, please do not use the Service.
2. Data Controller
For the purposes of applicable data protection laws, the controller responsible for your personal data is:
GTAUP
Email: privacy@gtaup.com
Company name, registered address, and registration number will be added when the operating company is incorporated.
With respect to files you upload to the Service, GTAUP acts as a data processor (veri işleyen) on your behalf. You, as the account holder, are the data controller for any personal data contained within your uploaded files.
3. Personal Data We Collect
We collect the minimum data necessary to provide, secure, and improve the Service. The categories of personal data we process include:
3.1 Data you provide directly
- Account data: Email address, username, and password hash when you register an account. If you sign in via a third-party provider (e.g., Google, GitHub), we receive your name, email, and profile picture from that provider.
- Profile data: Optional avatar, display name, and username you set in your profile.
- Payment data: When you subscribe to a paid plan, payment is processed by our third-party payment provider (Lemonsqueezy). We receive your subscription status, plan type, and billing email. We do not receive or store your full credit card number or payment credentials.
- Communications: Content of emails, support requests, or abuse reports you send to us.
3.2 Data generated through your use of the Service
- Upload metadata: File name, file size, MIME type, SHA-256 hash, upload timestamp, retention period, and download count.
- Usage data: Pages visited, features used, upload and download activity, and interaction timestamps.
- GTAUP Mail metadata: Sender address, recipient alias, subject line, and timestamps. Email body content is stored encrypted and processed only to deliver the message.
- Notes data: Note content you create is stored encrypted on our servers.
3.3 Data collected automatically
- Device and connection data: IP address, browser type and version, operating system, device type, screen resolution, and language preference.
- Cookies and similar technologies: We use strictly necessary cookies for authentication and session management. We do not use third-party advertising cookies or tracking pixels. See Section 9 for details.
3.4 Data we do NOT collect
- We do not scan or access the contents of your uploaded files for advertising or profiling purposes.
- We do not sell your personal data to third parties.
- We do not build user profiles for behavioral advertising.
4. Legal Basis for Processing
We process your personal data on the following legal bases, as applicable under the GDPR and equivalent rules under other laws (including KVKK where it applies):
| Purpose | Legal Basis | Reference (GDPR; local equivalents may apply) |
|---|---|---|
| Providing the Service (upload, storage, sharing) | Performance of contract | GDPR Art. 6(1)(b) |
| Account creation and authentication | Performance of contract | GDPR Art. 6(1)(b) |
| Payment processing | Performance of contract | GDPR Art. 6(1)(b) |
| Security measures (malware scanning, abuse prevention) | Legitimate interest | GDPR Art. 6(1)(f) |
| Legal compliance (tax records, law enforcement requests) | Legal obligation | GDPR Art. 6(1)(c) |
| Service improvement and analytics | Legitimate interest | GDPR Art. 6(1)(f) |
| Marketing communications (if opted in) | Explicit consent | GDPR Art. 6(1)(a) |
Where we rely on legitimate interest, we have conducted a balancing test to ensure that our interests do not override your fundamental rights and freedoms.
5. How We Use Your Data
We use the personal data we collect to:
- Provide, maintain, and operate the Service;
- Process file uploads, storage, sharing, and downloads;
- Authenticate your identity and manage your account;
- Process payments and manage subscriptions;
- Deliver GTAUP Mail messages to your alias;
- Detect, prevent, and respond to security threats, malware, abuse, and fraud;
- Comply with applicable legal obligations, including tax and accounting requirements;
- Respond to your inquiries, support requests, and abuse reports;
- Analyze aggregated, anonymized usage patterns to improve the Service;
- Send transactional emails (account confirmations, password resets, subscription notifications).
We will never sell your personal data. We do not use your data for third-party advertising or behavioral profiling.
6. Data Sharing and Third Parties
We share personal data only as necessary to provide and secure the Service, and only with the following categories of recipients:
| Recipient | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | CDN, edge delivery, R2 object storage, DDoS protection | USA / Global edge |
| Supabase, Inc. | Authentication, database hosting | USA |
| Lemonsqueezy (Lemon Squeezy, LLC) | Payment processing, subscription management | USA |
| Vercel, Inc. | Application hosting and deployment | USA / Global edge |
| abuse.ch (MalwareBazaar) | Known-malware hash lookup (hash only; not file contents) | EU / remote API |
| Transactional email provider | Abuse receipts, security alerts, account email | Per provider (see current DPA) |
Each third-party provider processes data in accordance with their own privacy policies and data processing agreements. We ensure that all providers offer adequate data protection guarantees.
We may also disclose personal data when required by law, court order, or governmental authority, or when necessary to protect our rights, safety, or property, or the rights, safety, or property of others. Law enforcement requests are handled as described on our Law Enforcement page (verify or reject; narrow scope; preserve where required).
7. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including jurisdictions where our infrastructure and service providers operate (for example Cloudflare, Supabase, and Vercel).
When transferring personal data internationally, we rely on appropriate safeguards under applicable law, which may include:
- EU Standard Contractual Clauses (SCCs) adopted by the European Commission, where GDPR requires them;
- Equivalent transfer tools under other regimes that apply to you (for example UK IDTA / addendum, or KVKK Article 9 mechanisms where Turkish law applies);
- Technical measures including encryption in transit (TLS 1.2+) and at rest (AES-256);
- Data processing agreements with third-party providers that include contractual data protection obligations.
8. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this Policy, or as required by law.
| Data Category | Retention Period |
|---|---|
| Free-tier files | 7 days default retention |
| Paid-tier temporary files | 14–30 days depending on plan |
| Forever files (paid plans) | No expiry while subscribed; removed after subscription ends + grace period (or sooner if you delete them) |
| Account data | Duration of account + 30 days after deletion |
| Transaction and billing records | As required by applicable tax and accounting law |
| Server logs (IP, access) | 90 days |
| Abuse reports — actioned + evidence snapshot | Minimum 1 year after decision, or until any legal hold ends + a short buffer (whichever is longer) |
| Abuse reports — dismissed | 90 days after dismissal, then reporter PII scrubbed and/or the row deleted (aggregate reason may be kept) |
| Abuse reports — open / reviewing | Retained until decided; no automatic deletion while open |
| Evidence tied to legal_hold uploads | Not deleted until the hold is released |
| Reporter IP / email | Aligned with the report path above (90 days if dismissed; ≥1 year if actioned) |
| Hash denylist entries | Depends on violation type; CSAM / court-related hashes may be kept indefinitely or for the legal minimum |
Abuse notice handling is processed by GTAUP as controller for the report metadata (reason, evidence snapshot, reporter contact where provided). For personal data inside uploaded files, you remain the controller and GTAUP acts as processor, except where we must process such data to comply with law or to execute a disable/delete/preserve decision. Evidence snapshots are write-once: they are not edited after the report is created.
File hashes may be checked against MalwareBazaar (abuse.ch) for known malware. We do not send file contents to MalwareBazaar — only hashes as needed for that lookup.
When data is no longer needed, it is permanently deleted or irreversibly anonymized, subject to legal holds and statutory retention (for example tax records).
10. Data Security
We implement robust technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
- Encryption at rest: All files stored on Cloudflare R2 are encrypted with AES-256.
- Encryption in transit: All connections are secured with TLS 1.2 or higher.
- Authentication: Passwords are hashed using bcrypt. Session tokens are managed securely via Supabase Auth with HTTP-only cookies.
- Access control: Strict least-privilege access policies for all internal systems and databases.
- Malware protection: Uploads are validated via magic-bytes inspection and SHA-256 hash checks against known malware databases (MalwareBazaar). Hash lookups do not upload file contents.
- Abuse reports: Users can report prohibited content via the in-product Report flow or abuse@gtaup.com. We review reports, may disable or remove files, and retain evidence as described in Section 8. See also our Notice and Takedown policy.
- Infrastructure: Cloudflare edge network with DDoS protection, rate limiting, and WAF rules.
No system is 100% secure. While we take extensive precautions, we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential and for maintaining backups of important files.
11. Your Rights
Depending on your location, you have the following rights regarding your personal data. We honor these rights regardless of where you reside, to the extent technically feasible.
11.1 Additional rights if you are in Türkiye (KVKK)
Under Turkish Law No. 6698, Article 11, you have the right to:
- Learn whether your personal data is being processed;
- Request information about how your data has been processed;
- Learn the purpose of processing and whether data is used in accordance with its purpose;
- Know the third parties to whom your data is transferred, domestically or abroad;
- Request correction of incomplete or inaccurate data;
- Request deletion or destruction of your data under the conditions set forth in Article 7;
- Request that corrections, deletions, or destructions be notified to third parties to whom data was transferred;
- Object to a result that is to your detriment through analysis of processed data exclusively by automated systems;
- Claim compensation for damages arising from unlawful processing of your data.
KVKK applications must be responded to within 30 days. You may submit requests to kvkk@gtaup.com or via registered mail. If your request is not resolved satisfactorily, you may file a complaint with the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu — KVKK Board).
11.2 Rights under GDPR (EU/EEA and UK)
Under GDPR, you have the right to:
- Access — Obtain a copy of the personal data we hold about you (Art. 15);
- Rectification — Correct inaccurate or incomplete personal data (Art. 16);
- Erasure — Request deletion of your personal data ("right to be forgotten") (Art. 17);
- Restriction — Request restriction of processing in certain circumstances (Art. 18);
- Data portability — Receive your data in a structured, commonly used, machine-readable format (Art. 20);
- Objection — Object to processing based on legitimate interest or for direct marketing (Art. 21);
- Withdraw consent — Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing (Art. 7(3));
- Automated decisions — Not be subject to decisions based solely on automated processing that produce legal or significant effects (Art. 22).
You may exercise your rights by contacting privacy@gtaup.com. We will respond within 30 days. If unsatisfied, you may lodge a complaint with your local supervisory authority.
11.3 Rights under CCPA / CPRA (California)
If you are a California resident, you have the right to:
- Know — Request disclosure of the categories and specific pieces of personal information we collect, use, and disclose;
- Delete — Request deletion of your personal information, subject to certain exceptions;
- Opt-out of sale or sharing — We do not sell or share your personal information as defined by CCPA/CPRA;
- Non-discrimination — Exercise your privacy rights without receiving discriminatory treatment.
To submit a verifiable consumer request, contact privacy@gtaup.com. We will respond within 45 days.
11.4 Rights under other laws
If you reside in a jurisdiction with specific data protection laws (e.g., LGPD in Brazil, POPIA in South Africa, PDPA in Singapore or Thailand, DPDP Act in India), we will honor your applicable rights upon verified request. Contact privacy@gtaup.com with your request and the relevant jurisdiction.
12. Children's Privacy
The Service is not directed to children under 16 years of age (or the higher minimum age required in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete that data promptly.
If you believe a child has provided us with personal data, please contact us at privacy@gtaup.com.
13. Do Not Track Signals
Some browsers transmit "Do Not Track" (DNT) signals. Because there is no industry-standard interpretation of DNT signals, the Service does not currently respond to DNT signals. However, as stated above, we do not engage in cross-site tracking, behavioral advertising, or data sales.
14. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the competent supervisory authority without undue delay and, where GDPR applies, within 72 hours of becoming aware of the breach (GDPR Art. 33), and follow equivalent timelines under other laws that apply (including KVKK where it applies);
- Notify affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms;
- Document the breach, our response, and remediation steps.
15. Changes to This Policy
We may update this Policy to reflect changes in our data practices, legal requirements, or operational needs. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page;
- Notify registered users by email and/or a prominent notice within the Service at least 30 days before the changes take effect.
Where required by applicable law (for example GDPR), we will obtain renewed consent before applying changes that depend on consent as the legal basis. Your continued use of the Service after the effective date of a revised Policy constitutes your acceptance of the changes, except where the law requires a different approach.
16. Contact Us
For any questions, requests, or complaints about this Policy or our data practices, you may reach us at:
- Privacy: privacy@gtaup.com
- If you are in Türkiye (KVKK requests): kvkk@gtaup.com
- Abuse reports: abuse@gtaup.com
- Legal: legal@gtaup.com
We aim to respond to data protection inquiries within 30 days (or sooner if a shorter period is required by law). If you are not satisfied with our response, you may lodge a complaint with the competent data protection authority in your jurisdiction.