Privacy Policy

Last updated: July 13, 2026

Your privacy matters. This policy explains what data we collect, why we collect it, and how you can control it.

For users in Türkiye (KVKK)

If you are in Türkiye, Turkish Law No. 6698 (KVKK) may give you additional rights regarding your personal data. You can exercise those rights via kvkk@gtaup.com or privacy@gtaup.com. We aim to respond within 30 days. You may also complain to the Turkish Personal Data Protection Authority (KVKK Board) if you are not satisfied with our response. This notice does not mean GTAUP is a company incorporated in Türkiye.

1. Introduction

This Privacy Policy ("Policy") explains how GTAUP ("GTAUP," "we," "us," or "our") collects, uses, stores, shares, and protects personal data when you access or use the GTAUP website, applications, APIs, or any related services (collectively, the "Service"). Registered company details will be published here when incorporation is complete.

We are committed to protecting your privacy and handling your personal data transparently and lawfully. Depending on where you live and how the Service is provided, this Policy is intended to align with:

  • GDPR — EU General Data Protection Regulation (Regulation 2016/679), where it applies;
  • UK GDPR and equivalent UK rules, where they apply;
  • KVKK — Turkish Law No. 6698, where it applies to you as a data subject in Türkiye;
  • CCPA / CPRA — California Consumer Privacy Act and California Privacy Rights Act, where they apply;
  • Other applicable data protection laws in the jurisdictions where our users are located.

By using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with our data practices, please do not use the Service.

2. Data Controller

For the purposes of applicable data protection laws, the controller responsible for your personal data is:

GTAUP

Email: privacy@gtaup.com

Company name, registered address, and registration number will be added when the operating company is incorporated.

With respect to files you upload to the Service, GTAUP acts as a data processor (veri işleyen) on your behalf. You, as the account holder, are the data controller for any personal data contained within your uploaded files.

3. Personal Data We Collect

We collect the minimum data necessary to provide, secure, and improve the Service. The categories of personal data we process include:

3.1 Data you provide directly

  • Account data: Email address, username, and password hash when you register an account. If you sign in via a third-party provider (e.g., Google, GitHub), we receive your name, email, and profile picture from that provider.
  • Profile data: Optional avatar, display name, and username you set in your profile.
  • Payment data: When you subscribe to a paid plan, payment is processed by our third-party payment provider (Lemonsqueezy). We receive your subscription status, plan type, and billing email. We do not receive or store your full credit card number or payment credentials.
  • Communications: Content of emails, support requests, or abuse reports you send to us.

3.2 Data generated through your use of the Service

  • Upload metadata: File name, file size, MIME type, SHA-256 hash, upload timestamp, retention period, and download count.
  • Usage data: Pages visited, features used, upload and download activity, and interaction timestamps.
  • GTAUP Mail metadata: Sender address, recipient alias, subject line, and timestamps. Email body content is stored encrypted and processed only to deliver the message.
  • Notes data: Note content you create is stored encrypted on our servers.

3.3 Data collected automatically

  • Device and connection data: IP address, browser type and version, operating system, device type, screen resolution, and language preference.
  • Cookies and similar technologies: We use strictly necessary cookies for authentication and session management. We do not use third-party advertising cookies or tracking pixels. See Section 9 for details.

3.4 Data we do NOT collect

  • We do not scan or access the contents of your uploaded files for advertising or profiling purposes.
  • We do not sell your personal data to third parties.
  • We do not build user profiles for behavioral advertising.

5. How We Use Your Data

We use the personal data we collect to:

  • Provide, maintain, and operate the Service;
  • Process file uploads, storage, sharing, and downloads;
  • Authenticate your identity and manage your account;
  • Process payments and manage subscriptions;
  • Deliver GTAUP Mail messages to your alias;
  • Detect, prevent, and respond to security threats, malware, abuse, and fraud;
  • Comply with applicable legal obligations, including tax and accounting requirements;
  • Respond to your inquiries, support requests, and abuse reports;
  • Analyze aggregated, anonymized usage patterns to improve the Service;
  • Send transactional emails (account confirmations, password resets, subscription notifications).

We will never sell your personal data. We do not use your data for third-party advertising or behavioral profiling.

6. Data Sharing and Third Parties

We share personal data only as necessary to provide and secure the Service, and only with the following categories of recipients:

RecipientPurposeLocation
Cloudflare, Inc.CDN, edge delivery, R2 object storage, DDoS protectionUSA / Global edge
Supabase, Inc.Authentication, database hostingUSA
Lemonsqueezy (Lemon Squeezy, LLC)Payment processing, subscription managementUSA
Vercel, Inc.Application hosting and deploymentUSA / Global edge
abuse.ch (MalwareBazaar)Known-malware hash lookup (hash only; not file contents)EU / remote API
Transactional email providerAbuse receipts, security alerts, account emailPer provider (see current DPA)

Each third-party provider processes data in accordance with their own privacy policies and data processing agreements. We ensure that all providers offer adequate data protection guarantees.

We may also disclose personal data when required by law, court order, or governmental authority, or when necessary to protect our rights, safety, or property, or the rights, safety, or property of others. Law enforcement requests are handled as described on our Law Enforcement page (verify or reject; narrow scope; preserve where required).

7. International Data Transfers

Your data may be transferred to and processed in countries outside your country of residence, including jurisdictions where our infrastructure and service providers operate (for example Cloudflare, Supabase, and Vercel).

When transferring personal data internationally, we rely on appropriate safeguards under applicable law, which may include:

  • EU Standard Contractual Clauses (SCCs) adopted by the European Commission, where GDPR requires them;
  • Equivalent transfer tools under other regimes that apply to you (for example UK IDTA / addendum, or KVKK Article 9 mechanisms where Turkish law applies);
  • Technical measures including encryption in transit (TLS 1.2+) and at rest (AES-256);
  • Data processing agreements with third-party providers that include contractual data protection obligations.

8. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Policy, or as required by law.

Data CategoryRetention Period
Free-tier files7 days default retention
Paid-tier temporary files14–30 days depending on plan
Forever files (paid plans)No expiry while subscribed; removed after subscription ends + grace period (or sooner if you delete them)
Account dataDuration of account + 30 days after deletion
Transaction and billing recordsAs required by applicable tax and accounting law
Server logs (IP, access)90 days
Abuse reports — actioned + evidence snapshotMinimum 1 year after decision, or until any legal hold ends + a short buffer (whichever is longer)
Abuse reports — dismissed90 days after dismissal, then reporter PII scrubbed and/or the row deleted (aggregate reason may be kept)
Abuse reports — open / reviewingRetained until decided; no automatic deletion while open
Evidence tied to legal_hold uploadsNot deleted until the hold is released
Reporter IP / emailAligned with the report path above (90 days if dismissed; ≥1 year if actioned)
Hash denylist entriesDepends on violation type; CSAM / court-related hashes may be kept indefinitely or for the legal minimum

Abuse notice handling is processed by GTAUP as controller for the report metadata (reason, evidence snapshot, reporter contact where provided). For personal data inside uploaded files, you remain the controller and GTAUP acts as processor, except where we must process such data to comply with law or to execute a disable/delete/preserve decision. Evidence snapshots are write-once: they are not edited after the report is created.

File hashes may be checked against MalwareBazaar (abuse.ch) for known malware. We do not send file contents to MalwareBazaar — only hashes as needed for that lookup.

When data is no longer needed, it is permanently deleted or irreversibly anonymized, subject to legal holds and statutory retention (for example tax records).

9. Cookies and Similar Technologies

We use a minimal set of cookies that are strictly necessary for the Service to function:

CookiePurposeDuration
sb-*-auth-tokenSupabase authentication sessionSession / 7 days
themeDark/light mode preference1 year
__cf_bmCloudflare bot management30 minutes

We do not use analytics cookies, advertising cookies, or third-party tracking pixels. Because we only use strictly necessary cookies, a consent banner is not required under the GDPR for those cookies. If other laws that apply to you require additional notice or choice, we will follow them. If we introduce optional cookies in the future, we will implement a consent mechanism before deploying them.

10. Data Security

We implement robust technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

  • Encryption at rest: All files stored on Cloudflare R2 are encrypted with AES-256.
  • Encryption in transit: All connections are secured with TLS 1.2 or higher.
  • Authentication: Passwords are hashed using bcrypt. Session tokens are managed securely via Supabase Auth with HTTP-only cookies.
  • Access control: Strict least-privilege access policies for all internal systems and databases.
  • Malware protection: Uploads are validated via magic-bytes inspection and SHA-256 hash checks against known malware databases (MalwareBazaar). Hash lookups do not upload file contents.
  • Abuse reports: Users can report prohibited content via the in-product Report flow or abuse@gtaup.com. We review reports, may disable or remove files, and retain evidence as described in Section 8. See also our Notice and Takedown policy.
  • Infrastructure: Cloudflare edge network with DDoS protection, rate limiting, and WAF rules.

No system is 100% secure. While we take extensive precautions, we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential and for maintaining backups of important files.

11. Your Rights

Depending on your location, you have the following rights regarding your personal data. We honor these rights regardless of where you reside, to the extent technically feasible.

11.1 Additional rights if you are in Türkiye (KVKK)

Under Turkish Law No. 6698, Article 11, you have the right to:

  • Learn whether your personal data is being processed;
  • Request information about how your data has been processed;
  • Learn the purpose of processing and whether data is used in accordance with its purpose;
  • Know the third parties to whom your data is transferred, domestically or abroad;
  • Request correction of incomplete or inaccurate data;
  • Request deletion or destruction of your data under the conditions set forth in Article 7;
  • Request that corrections, deletions, or destructions be notified to third parties to whom data was transferred;
  • Object to a result that is to your detriment through analysis of processed data exclusively by automated systems;
  • Claim compensation for damages arising from unlawful processing of your data.

KVKK applications must be responded to within 30 days. You may submit requests to kvkk@gtaup.com or via registered mail. If your request is not resolved satisfactorily, you may file a complaint with the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu — KVKK Board).

11.2 Rights under GDPR (EU/EEA and UK)

Under GDPR, you have the right to:

  • Access — Obtain a copy of the personal data we hold about you (Art. 15);
  • Rectification — Correct inaccurate or incomplete personal data (Art. 16);
  • Erasure — Request deletion of your personal data ("right to be forgotten") (Art. 17);
  • Restriction — Request restriction of processing in certain circumstances (Art. 18);
  • Data portability — Receive your data in a structured, commonly used, machine-readable format (Art. 20);
  • Objection — Object to processing based on legitimate interest or for direct marketing (Art. 21);
  • Withdraw consent — Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing (Art. 7(3));
  • Automated decisions — Not be subject to decisions based solely on automated processing that produce legal or significant effects (Art. 22).

You may exercise your rights by contacting privacy@gtaup.com. We will respond within 30 days. If unsatisfied, you may lodge a complaint with your local supervisory authority.

11.3 Rights under CCPA / CPRA (California)

If you are a California resident, you have the right to:

  • Know — Request disclosure of the categories and specific pieces of personal information we collect, use, and disclose;
  • Delete — Request deletion of your personal information, subject to certain exceptions;
  • Opt-out of sale or sharing — We do not sell or share your personal information as defined by CCPA/CPRA;
  • Non-discrimination — Exercise your privacy rights without receiving discriminatory treatment.

To submit a verifiable consumer request, contact privacy@gtaup.com. We will respond within 45 days.

11.4 Rights under other laws

If you reside in a jurisdiction with specific data protection laws (e.g., LGPD in Brazil, POPIA in South Africa, PDPA in Singapore or Thailand, DPDP Act in India), we will honor your applicable rights upon verified request. Contact privacy@gtaup.com with your request and the relevant jurisdiction.

12. Children's Privacy

The Service is not directed to children under 16 years of age (or the higher minimum age required in your jurisdiction). We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate parental consent, we will take steps to delete that data promptly.

If you believe a child has provided us with personal data, please contact us at privacy@gtaup.com.

13. Do Not Track Signals

Some browsers transmit "Do Not Track" (DNT) signals. Because there is no industry-standard interpretation of DNT signals, the Service does not currently respond to DNT signals. However, as stated above, we do not engage in cross-site tracking, behavioral advertising, or data sales.

14. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will:

  • Notify the competent supervisory authority without undue delay and, where GDPR applies, within 72 hours of becoming aware of the breach (GDPR Art. 33), and follow equivalent timelines under other laws that apply (including KVKK where it applies);
  • Notify affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms;
  • Document the breach, our response, and remediation steps.

15. Changes to This Policy

We may update this Policy to reflect changes in our data practices, legal requirements, or operational needs. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page;
  • Notify registered users by email and/or a prominent notice within the Service at least 30 days before the changes take effect.

Where required by applicable law (for example GDPR), we will obtain renewed consent before applying changes that depend on consent as the legal basis. Your continued use of the Service after the effective date of a revised Policy constitutes your acceptance of the changes, except where the law requires a different approach.

16. Contact Us

For any questions, requests, or complaints about this Policy or our data practices, you may reach us at:

We aim to respond to data protection inquiries within 30 days (or sooner if a shorter period is required by law). If you are not satisfied with our response, you may lodge a complaint with the competent data protection authority in your jurisdiction.