Yesterday Privacy Policy
Last updated: 9 September 2026
1. Who We Are
Yesterday is operated by Flapp Bilisim A.S., located in Beyoglu, Istanbul, Türkiye. We are responsible for the personal data we process in connection with the Yesterday iOS app and related support communications.
For support, privacy questions or data-rights requests, contact yesterday@flapp.ist.
2. Information We Process
Your journal: Entries, questions, answers, dates, drafts and attached photos are stored locally on your device. Normal app operation does not upload journal text or photos to our Firebase services. Signing in does not automatically back up or synchronize your journal to another device.
Account information: When you sign in using Apple, Google or email, we and our authentication provider process your account identifier, email address, name where provided, sign-in provider information and authentication records. Apple may provide a private relay email address if you choose Hide My Email. Email/password authentication is handled by Firebase Authentication; passwords are not stored in the journal database.
Account-linked app information: We store settings and metadata such as reminder preferences, theme, entry and photo counts, streak counts, premium-access status, subscription type, renewal information where available, account timestamps and whether certain upgrade prompts have been shown. These records do not contain your journal text or photo files.
Technical information: Services used to operate and secure the app may process IP addresses, app or installation identifiers, device and operating-system information, request timestamps and security logs. Necessary authentication and service operations are separate from optional analytics and diagnostics.
Support information: If you contact us, we process your email address, messages and any attachments you choose to provide. Please avoid sending passwords, private keys or sensitive journal content unless necessary for your request.
3. How and Why We Use Information
We obtain information through your app interactions, sign-in providers, app service providers and communications with us. We use it to provide and secure accounts, operate journaling and reminders, manage settings, verify premium access, process backup/import/export requests, respond to support requests, prevent misuse and meet applicable legal obligations.
Depending on the purpose and applicable law, processing is based on providing the service you request or performing our contract with you, complying with legal obligations, establishing or protecting legal rights, or legitimate interests in operating and securing the service where these do not override your rights. Optional analytics and diagnostics are based on your consent. This policy is an explanation of processing, not a request for blanket consent.
4. Optional Analytics and Diagnostics
Usage analytics and crash diagnostics are off by default and can be enabled or disabled separately in Settings. You can use the app without opting in.
If enabled, Firebase Analytics receives information about feature use, such as opening the app, sealing an entry, viewing memories, exporting a backup or interacting with premium features. Analytics may use pseudonymous app or installation identifiers; it is not necessarily anonymous. Our custom analytics events do not include journal text, photos, email addresses, names or account IDs.
If enabled, Firebase Crashlytics receives technical crash and diagnostic information, which may include device and app details, installation identifiers and crash traces. We do not deliberately include journal content in diagnostic reports. Disabling these options stops future app collection under that option; it does not automatically erase information already received by a provider. Provider processing and retention are described in Firebase’s privacy information.
We do not sell your personal data, use journal content for AI training, or use the app for targeted advertising or cross-app advertising tracking.
5. Permissions, Backups and Purchases
The app may request access needed to attach a photo and permission to send reminders. You control these permissions through iOS Settings. Reminders are scheduled locally on your device.
When you export or share a backup, text file or PDF, the file may contain your journal and photos. These exports are not password-protected or encrypted by Yesterday. They are sent to the destination you choose and are subject to that destination’s handling. Device backups, including iCloud backups, may also contain app data depending on your Apple settings. Protect exported files and backups carefully.
Apple processes App Store purchases and subscriptions. We receive purchase or entitlement information needed to provide premium features, but we do not receive or store your payment-card number. Apple handles payment information under its own terms and privacy policy.
6. Sharing and International Processing
We use Google/Firebase services for authentication, account metadata, backend functions, app configuration, security and optional analytics and diagnostics. Apple and Google also process information when you use their sign-in services; Apple processes App Store purchases. Their own privacy terms apply to their independent processing. See Google’s Privacy Policy and Apple’s Privacy Policy.
Information may also be disclosed where legally required or necessary to protect legal rights, prevent fraud or address security incidents. Journal files are shared when you choose to export them or provide them to support, rather than through normal journal synchronization.
Our providers operate internationally, so account, technical and optional analytics or diagnostic information may be processed outside Türkiye, including in the United States. Cross-border processing is subject to applicable data-protection requirements. Contact yesterday@flapp.ist for information about the processing locations and transfer arrangements applicable to your data. Using the app does not itself constitute blanket consent to international transfers.
7. Retention, Deletion and Security
We retain personal data for as long as needed for the purposes described in this policy, considering account status, support needs, legal obligations, security requirements and applicable provider retention settings. Different categories may have different retention periods. Contact us for information about retention applicable to your request.
You can initiate account deletion from Settings or request assistance at yesterday@flapp.ist. Identity verification or reauthentication may be required. Account deletion and local journal deletion are distinct from deleting copies in device backups, shared exports, recipients’ systems or Apple’s purchase records. Some records may remain where retention is legally required or necessary to handle legal claims or security matters. Turning off analytics is not a request to delete your account.
Uninstalling Yesterday does not by itself delete your server-held account. Deleting your account does not cancel an App Store subscription; manage or cancel subscriptions through Apple separately.
We use technical and organizational safeguards to protect information, but no system is completely secure. An unlocked device, its backups or an exported file may expose journal content. Signing in with a different account does not automatically isolate or remove the journal already stored on that device. Yesterday does not promise end-to-end encryption of backups or exports.
8. Your Rights
Depending on applicable law, including Türkiye’s Personal Data Protection Law No. 6698 (KVKK), you may request information about whether and how your personal data is processed, its purposes and recipients, access or correction, deletion where applicable, and notification of corrections or deletion to relevant recipients. You may also have rights to object to certain processing or adverse results from exclusively automated analysis, seek compensation for unlawful processing, and complain to the competent data-protection authority. Other applicable laws may provide portability or restriction rights.
You may withdraw optional consent in Settings without affecting the lawfulness of earlier consent-based processing. Send rights requests to yesterday@flapp.ist. We may request information reasonably needed to verify your identity and will handle requests within applicable legal time limits. Information about KVKK rights is available from the Turkish Personal Data Protection Authority.
9. Children and Policy Updates
Minors should use Yesterday only where permitted by applicable law and with parental or guardian involvement where required. If you believe a child has provided personal data without legally required authorization, contact us so we can assess and address the request.
We may update this policy as the app or legal requirements change. The updated version will be published on this page with a revised date. Where required, we will provide additional notice or request fresh consent before new consent-based processing.
Contact: Flapp Bilisim A.S., Beyoglu, Istanbul, Türkiye.
Email: yesterday@flapp.ist