Privacy Policy
This policy explains what personal data is processed when you use the SayMatik mobile app for iPhone and Android, the website saymatik.com with its web wallet, and the saymatik.com servers the app talks to (together, “SayMatik”): what we process, why, on what legal basis, who receives it, how long we keep it and what your rights are. If you are in Türkiye, the same information is given in Turkish in our KVKK Aydınlatma Metni.
In short
Self-custody: your recovery phrase, private keys and app password stay on your device, and the app never sends them to us or anyone else. We cannot see or recover them.
You do not need an account. We do not ask for your name, e-mail address or phone number to use SayMatik.
What our servers keep is linked to public wallet addresses: Buy SCI purchases, swaps on the SCI exchange, token listing requests, referrals, transfers you make from the web wallet and documents stored with DeCerta in older versions of the app.
ChitChat messages are public and permanent: they are written to the blockchain unencrypted and can never be deleted. Do not put personal data in them.
Wallet addresses and transactions are public on the blockchain, and nobody, including us, can delete them there.
The app contains no analytics, advertising, crash-reporting or tracking tools.
1. Who is responsible
The controller of your personal data (the “veri sorumlusu” under Turkish Law No. 6698, KVKK) is ZİNCİRX BİLİŞİM TEKNOLOJİ VE DANIŞMANLIK A.Ş. (“ZincirX A.Ş.”), the company in Türkiye that provides SayMatik (“we”, “us”), for users in every country:
- Company
- ZİNCİRX BİLİŞİM TEKNOLOJİ VE DANIŞMANLIK A.Ş.
- Registered office
- Gülbahçe Mah. Gülbahçe Cad. İYTE Sitesi No: 1/40 İç Kapı No: 51, 35430 Urla/İzmir, Türkiye
- MERSİS No
- 0999144137300001
- Tax office and number
- Urla Tax Office, 9991441373
- E-mail (privacy requests and questions)
- info@zincirx.com
2. Self-custody: what we never receive
- When you create or import a wallet in the app, your recovery phrase, private key and app password are stored on your device, in encrypted storage (the iOS Keychain or Android’s encrypted storage). The app never sends them anywhere: it uses the key on the device to sign transactions, and only the signed transaction is sent to the blockchain.
- The app does not back up your recovery phrase to any cloud service, and we cannot recover your wallet. On iPhone, your device’s own encrypted backups may include the app’s encrypted storage, depending on your settings. Keep your recovery phrase offline and private.
- If you use the copy buttons for your recovery phrase or private key, they are placed on your device’s clipboard, where other apps may be able to read them. Avoid copying them.
- The web wallet on saymatik.com works with a browser wallet such as MetaMask. Your keys stay in that browser wallet; the website only learns the address you connect.
- We will never ask for your recovery phrase, private key or password.
3. What we process, why and on what basis
The legal bases below are those of the EU and UK General Data Protection Regulation (GDPR, Art. 6(1)) and, for people in Türkiye, KVKK Art. 5. The KVKK notice sets out the Turkish bases in detail.
| When | Data | Why | Legal basis |
|---|---|---|---|
| Every visit to saymatik.com and every request from the app to our servers | IP address, date and time, requested address (which can contain a wallet address), referring page, browser or app identification (user agent), response status | Delivering the website and the app’s data, security, preventing abuse, fixing errors | Legitimate interests (GDPR Art. 6(1)(f)); KVKK Art. 5(2)(f) |
| Buy SCI: after you send a stablecoin payment from the app | Payment transaction hash, network, paying wallet address, stablecoin, amount, SCI amount and price, the time, and the IP address and app identification (user agent) of the request | Checking the payment on the blockchain, sending you the SCI, preventing double claims and fraud, showing your purchase history, keeping commercial records | Contract (GDPR Art. 6(1)(b)); legitimate interests in fraud prevention and in complying with Turkish commercial and tax law (Art. 6(1)(f)); KVKK Art. 5(2)(c), (ç) and (f) |
| Region check: when a Buy SCI payment notification arrives, and when versions of the app that include the check ask which features are offered where you are (below) | The IP address of the request, used only to look up its country and not kept for this check; for a Buy SCI payment notification refused because the IP address is registered in Türkiye, its country, network and transaction hash | Not offering Eppay QR payments and Buy SCI in Türkiye; tracing a refused payment | Legitimate interests in complying with Turkish law (GDPR Art. 6(1)(f)); KVKK Art. 5(2)(ç) and (f) |
| Swaps and liquidity on the SCI exchange in the app | Wallet address, token, buy/sell/add-liquidity, amount, price, value, transaction hash, contract address, time, gas and block details | Price charts and trading statistics for SCI tokens | Legitimate interests (Art. 6(1)(f)): providing market data for the exchange; KVKK Art. 5(2)(f) |
| Token listing requests | Wallet address, payment transaction hash, network, amount paid; the token’s name, symbol, contract address, decimals, supply, description and logo | Checking the listing payment, reviewing the request and showing the token in SayMatik | Contract (Art. 6(1)(b)); KVKK Art. 5(2)(c) |
| Activating swap, locker or peer-to-peer tools for a token you manage | Token address, contract addresses, transaction hash, network (no wallet address) | Connecting the token to its trading and locking contracts in SayMatik | Contract (Art. 6(1)(b)); KVKK Art. 5(2)(c) |
| Referrals: when you set who referred you | Your wallet address, the referrer’s wallet address, a signature from your wallet proving the request is yours, the time | Sending the referrer their share of transfer fees | Contract (Art. 6(1)(b)); KVKK Art. 5(2)(c) |
| Sending tokens from the web wallet on saymatik.com | Wallet address, recipient, token, amount, transaction hash, status, gas, time, a short description | Showing your transaction history on the website | Contract (Art. 6(1)(b)); KVKK Art. 5(2)(c) |
| DeCerta document storage (older versions of the app; see below) | Wallet address, document name, description, file type, the contents of the file (stored unencrypted), the hashes of its parts, upload time | Storing your document and giving it back to you | Contract (Art. 6(1)(b)); KVKK Art. 5(2)(c) |
| When you e-mail us | Your e-mail address, name if you give it, the content of your message and anything you attach, such as a wallet address or transaction hash | Answering you and handling your request | Legitimate interests (Art. 6(1)(f)) or contract (Art. 6(1)(b)); KVKK Art. 5(2)(c) and (f) |
| Legal requests and disputes | The data relevant to the request or dispute | Answering authorities where the law requires, establishing or defending legal claims | Legitimate interests (Art. 6(1)(f)); KVKK Art. 5(2)(ç) and (e) |
| Only if you accept analytics in the cookie banner on saymatik.com | Pages visited (without wallet addresses or transaction hashes), browser, device, approximate location (see Google Analytics) | Understanding how the website is used | Consent (Art. 6(1)(a)); explicit consent, KVKK Art. 5(1) |
We do not ask for or collect identity documents (no KYC), and we do not process special categories of data such as health or biometric data. We do not sell personal data, use it for advertising or make decisions about you based solely on automated processing. Where we rely on legitimate interests, you can object (section 10).
The sign-up and sign-in forms on saymatik.com do not create accounts: what you type into them is not sent to our servers.
Eppay QR payments (paying an Eppay QR code and making “Get paid” codes) and Buy SCI are not offered in Türkiye. To apply this:
- Versions of the app that include this check look at your device’s region, language and time-zone settings on the device, without sending them to us, and ask saymatik.com, which looks up the country that the IP address of the request belongs to. The app keeps saymatik.com’s last answer (which features are not offered) on the device, replaces it at each check, and relies on it for up to 7 days when it cannot reach saymatik.com.
- For every Buy SCI payment notification, from any version of the app, saymatik.com looks up the same country and refuses notifications from IP addresses registered in Türkiye (these can include some networks used outside Türkiye). No SCI is sent for a refused payment, and the application log keeps its country, network and transaction hash, but not the IP address, so that the payment can be traced (section 9).
Legal basis for these checks: GDPR Art. 6(1)(f), our legitimate interest in complying with Turkish law; KVKK Art. 5(2)(ç), legal obligation, and Art. 5(2)(f), legitimate interest.
saymatik.com does not keep the IP address for these checks. As with every request to our servers, the IP address still appears in the web server’s access log (section 9), and every Buy SCI payment notification, refused or not, also creates or updates the short-lived session record described in section 11 and, to limit how often notifications can be sent, leaves a hashed form of the IP address, which expires after about a minute and is deleted within the following hour (section 9). These server records rest on our legitimate interest in running the service securely (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f); section 3).
DeCerta documents
Older versions of the SayMatik app offered DeCerta, a feature for storing documents. The current version no longer does, but the documents uploaded with it are still kept on our server:
- What is stored: the wallet address that uploaded the document, the document’s name, description and file type, the file itself split into parts (stored unencrypted), the hashes of those parts, the upload time and, if one was set, an expiry date. Any personal data inside a document is stored with it.
- Where: in our database on our server in Vilnius, Lithuania (Hostinger).
- Who can see it: through the API, only the wallet that uploaded a document can retrieve or delete it, by signing the request. Our administrators can access the server.
- On the blockchain: when a document was uploaded, its name, description, file type, the hashes of its parts and the first few small parts of the file were also written to the SCI blockchain, where they are public and cannot be deleted.
- How long: until you delete the document or ask us to delete it.
- Deletion: e-mail info@zincirx.com with the wallet address and, if you have it, the document name. We will ask you to sign a message with that wallet to prove the document is yours, then delete the document from our server.
4. Data that stays on your device
The app keeps the following on your device only. We have no access to it.
- In encrypted storage: your wallet (address, recovery phrase, private key, password, nickname), your address book and failed-unlock counters.
- In the app’s local storage: your transaction history, your chat contacts and recent chats, the referrer address you set, tokens you created or added, cached event and certificate data (which can include the name and e-mail address on your certificates), your language and theme, and cached token lists and settings.
- Versions of the app that include the region check also keep saymatik.com’s last answer on which features are not offered where you are (no IP address), replace it at each check and rely on it for up to 7 days when they cannot reach saymatik.com; they read your device’s region, language and time-zone settings without sending them (section 3).
- The camera is used only to scan QR codes, such as wallet addresses. Images are processed on the device and are not saved or sent.
- The photo library is used only if you choose a photo for a property listing; the photo is shown in the app and is not uploaded.
- The app does not use your device’s location services (GPS), contacts, microphone, biometrics or advertising identifier, and it does not send push notifications.
5. Public blockchains
Every transaction you sign is sent to a public blockchain. Your wallet address, the addresses you deal with, amounts, tokens and any data contained in the transaction become public and permanent: anyone can see them, others may link your address to you, and neither we nor anyone else can change or delete them. Before you write data to a blockchain, keep in mind in particular that:
- ChitChat messages: a message you send with ChitChat is written to the SCI blockchain unencrypted, together with your wallet address and the recipient’s. It is public, so anyone can read it, and permanent, so it can never be edited or deleted, by you or by us. Do not put personal data, yours or anyone else’s, or anything confidential in a ChitChat message.
- Event registrations: when you register for an event in the Event Certificates feature, the name, e-mail address and organisation you enter are written permanently to a public smart contract, where the event organiser and anyone else can read them. Do not register if you do not want this.
- Events and property listings you create: event names, venues, location text and dates, and property details such as location, parcel number, type and price, are written to the blockchain.
- Tokens you create: a token’s name, symbol, supply and owner address are public.
- DeCerta documents: the on-chain part of documents uploaded with older app versions (see above).
Apart from DeCerta documents (see above), these on-chain records are not stored by us on our servers, and the rights described in section 10 cannot remove them from a blockchain.
6. Services your device connects to directly
To work, the app and the website connect directly to services we do not operate. They receive your IP address and the request itself, and process them under their own privacy policies:
- Blockchain nodes (RPC providers). To show balances and send transactions, your device sends your wallet address and signed transactions to the network you use: the SCI network’s node (rpc.scimatic.net, run by SciMatic) and public nodes for the other networks, such as those of Binance (BNB Chain), dRPC, LlamaNodes, Ankr, PublicNode, 1RPC, Avalanche, Polygon, Fantom, Arbitrum, Optimism, Base, Linea, Gnosis and Celo.
- Property listings. The real-estate section loads listings from imlakchain.com and, when you buy property tokens, reports the property and the token amount there (no wallet address).
- Eppay QR payments. As soon as you scan an Eppay QR code, the app checks your balance on the network node named in the code, so that node learns your wallet address even if you then cancel; if you pay, the payment is sent through the same node. After the payment, the app sends your wallet address, the amount, token, transaction hash and product ID to the web address in the code. That address is normally the merchant’s, and the merchant uses the data under its own terms. The purpose is completing the payment you asked for, and the legal basis is the contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)). If the merchant is outside Türkiye, the transfer is also subject to Article 9 of the KVKK. For codes made with SayMatik’s own “Get paid” screen, the address is saymatik.com. Since 10 October 2026, its application log keeps only the transaction hash and the time of such a notification; notifications received before then were logged with the IP address too (section 9). Like every request to our servers, the notification also appears, with your IP address, in the web server’s access log; it can also create or update a short-lived session record with your IP address and app identification (section 11), and, to limit how often notifications can be sent, a hashed form of your IP address is kept, which expires after about a minute and is deleted within the following hour (section 9). These server records rest on our legitimate interest in running the service securely (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f); section 3).
- Token logos and metadata. Token and NFT logos and metadata are loaded from wherever their creators host them (for example CoinMarketCap, CoinGecko or Etherscan image servers, or a token creator’s own server).
- Website resources. Pages of saymatik.com other than these legal pages load fonts from Google Fonts (Google), icons from cdnjs (Cloudflare) and, on the web wallet pages, code libraries from jsDelivr. Your browser connects to them when a page loads.
- App stores. Apple and Google process data when you download and update the app, under their own policies. They may give the app’s publisher statistics such as install numbers and, if you chose to share them with developers in your device settings, crash reports.
- Links you open. Block explorers and other websites you open from SayMatik.
7. Who receives data
- Hostinger International Ltd. hosts our servers (data centre in Vilnius, Lithuania, EU) and our e-mail (EU), as our processor. Outgoing e-mails are relayed by MailChannels (Canada; servers in North America).
- Google Ireland Limited and Google LLC receive website usage data only if you accept analytics (section 11).
- Our legal and tax advisers, where needed, under a duty of confidentiality.
- Courts and public authorities, only where the law requires it.
The services in section 6 receive data from your device directly, not from us.
8. Transfers outside Türkiye and the EEA
Our servers are in the EU (Lithuania), so data about users in Türkiye is transferred abroad. Some of the services above are in the USA or other countries that may not protect personal data to the same standard as Türkiye or the EU. For people in Türkiye, transfers abroad other than the transfer to Google for analytics are subject to Article 9 of the KVKK, and we do not rely on your explicit consent for them; you can ask for details of these transfers at info@zincirx.com. The transfer to Google for analytics relies on your consent (section 11).
9. How long we keep data
| Data | Kept for |
|---|---|
| Web server access logs | Up to 15 days |
| Application logs (errors and payment checks, including the IP address and transaction hash of Buy SCI payment notifications; the country, network and transaction hash of Buy SCI payment notifications refused because the IP address is registered in Türkiye; and the transaction hash of “Get paid” payment notifications, with the IP address for those received before 10 October 2026) | As long as needed for security, fraud prevention, troubleshooting and handling refused payments |
| Buy SCI purchase records | As long as Turkish commercial and tax law requires commercial records to be kept: up to 10 years (Turkish Commercial Code Art. 82: 10 years; Tax Procedure Law Art. 253: 5 years) |
| Token listing requests | While the listing is shown or under review; payment records as for purchases |
| Swap records, web wallet transaction history, referrals and token contract links | While SayMatik offers the feature they serve, unless you ask us to delete them earlier and we have no legal reason to keep them |
| DeCerta documents on our server | Until you delete them or ask us to delete them |
| E-mails with us | As long as needed to handle your request and any follow-up, and longer only where a legal claim is possible |
| Session and security cookies, and the session record on our server (IP address, browser or app identification, and the address of the last page or request, which can contain a wallet address) | 2 hours; expired session records are deleted automatically some time after they expire |
| Rate-limit entries for payment notifications (a hashed form of the IP address) | They expire after about a minute and are deleted within the following hour |
| Google Analytics | _ga cookies up to 2 years; Google keeps the analytics data for 14 months |
| Data on public blockchains | Permanently; it cannot be deleted |
When a period ends, we delete or anonymise the data.
10. Your rights
Depending on the law that applies to you, you have the right to:
- know whether we process your data and get a copy of it (access);
- have inaccurate data corrected;
- have data deleted, or its use restricted, where the conditions in the law are met;
- receive data you gave us in a machine-readable format (portability);
- object to processing based on our legitimate interests;
- withdraw consent at any time, without affecting what happened before;
- for people in Türkiye, the rights in KVKK Art. 11, listed in the KVKK notice;
- complain to a data protection authority: in Türkiye, the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu), after first applying to us; in the EU, the authority where you live or work.
To use these rights, e-mail info@zincirx.com. Because most data we hold is linked only to a wallet address, we may ask you to sign a message with that wallet to show it is yours. We answer within 30 days, free of charge. People in Türkiye can also apply in the ways set out in the KVKK notice.
11. Cookies and browser storage
The website and our servers use only what they need to work, and nothing for tracking or advertising:
saymatik_web3_wallet_session(session) andXSRF-TOKEN(protection against cross-site request forgery): strictly necessary cookies, set on website visits and on the app’s requests to our servers, that expire after 2 hours. The session has a record on our server holding your IP address, your browser or app identification and the address of the last page or request, which can contain a wallet address; it is deleted automatically some time after the session expires.walletConnectedandwalletAddressin your browser’s local storage, set when you connect a browser wallet on the home page, so the page can show your address on your next visit. They stay in your browser until you disconnect or clear your browser data.zx_consentin your browser’s local storage: your cookie choice (accept or reject) and its date; you are asked again after 6 months.
Strictly necessary cookies need no consent and rely on our legitimate interest in providing a secure website.
Google Analytics
The only optional tool on the website is Google Analytics 4, provided by Google Ireland Limited (for visitors in the EEA and Switzerland) and Google LLC (USA). It runs only on the home page and the sign-in and sign-up pages, and only if you choose “Accept all”, or turn on Analytics under “Preferences”, in the cookie banner; until then no request is sent to Google and no analytics cookie is set. It never runs in the app or on the wallet, exchange, transactions or admin pages.
It measures the pages you visit, page titles, the page you came from, when and how long you visit,
interactions such as scrolling and outbound clicks, your browser, device and language, and an approximate
location (country, city) derived from your IP address; Google Analytics 4 does not log or store IP addresses.
Before anything is sent, wallet addresses and transaction hashes are removed from page addresses and the query
string is dropped (except campaign utm_ tags); a page whose address carries other parameters is
not measured, and measurement stops on a page as soon as it shows a connected wallet address. No name,
e-mail address, wallet address, account or user ID is sent to Google, and Google signals and ad
personalisation are switched off. It sets the _ga and _ga_<ID> cookies,
which stay in your browser for up to 2 years; Google keeps the analytics data for 14 months, then deletes it.
Legal basis: your consent (GDPR Art. 6(1)(a) and ePrivacy Art. 5(3); for visitors in Türkiye, explicit consent under KVKK Art. 5(1)). The data is processed by Google, including on servers in the USA. Google LLC is certified under the EU-U.S. Data Privacy Framework; for visitors in Türkiye the transfer abroad relies on your explicit consent under KVKK Art. 9(6)(a), given knowing that the USA may not offer the same level of protection as Türkiye and that US authorities may be able to access the data.
You can change your choice or withdraw consent at any time with the “Cookie settings” link at the bottom of
the home page or under the sign-in and sign-up forms. Withdrawing stops Google Analytics and deletes the
_ga cookies the site can delete. Rejecting does not affect your use of the site.
12. Security
The website and our servers use encrypted connections (HTTPS), access to our servers is restricted, and the app keeps your keys in your device’s encrypted storage. No system is completely secure, so protect your device, keep your recovery phrase offline and be wary of anyone asking for it.
13. Children
SayMatik is not intended for anyone under 18, and we do not knowingly process children’s personal data. If you believe a child has sent us personal data, contact us and we will delete it.
14. Changes to this policy
We update this policy when SayMatik or the law changes. The date at the top shows the current version; for significant changes we will also tell you in the app or on the website.
15. Contact
For questions or requests about your personal data, write to info@zincirx.com.