Privacy Policy

How BeforeTomorrow collects, uses, and protects your personal data under GDPR, KVKK, and CCPA/CPRA.

Version 1.0Effective 2026-07-10Last reviewed 2026-07-10

1. Who is responsible for your data

Ideasets Teknoloji Yapay Zeka Ticaret Anonim Şirketi (trading as BeforeTomorrow), a company registered in Üsküdar, İstanbul, Türkiye (Tax Office: Üsküdar Vergi Dairesi, Tax No: 4651615036; MERSİS No: 0465161503600001; Trade Registry No: 1113512), is the data controller under Regulation (EU) 2016/679 ("GDPR") and the data responsible party ("veri sorumlusu") under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") for the personal data described in this Privacy Policy.

Not required to register with VERBİS (Data Controllers' Registry) under KVKK Kurulu Decision 2018/68 — the company employs fewer than 50 people and has an annual balance-sheet total under 100 million TRY, and does not process special-category personal data as its main field of activity.

For any question, request, or complaint about this Policy or your personal data, contact us at contact@beforetomorrow.io. We do not currently have a legal obligation to appoint a Data Protection Officer under GDPR Art. 37 or a KVKK-registered representative, given our size and processing activities; this contact address receives and answers all data-protection requests directly.

2. Scope and who this applies to

This Policy applies to everyone who visits https://www.beforetomorrow.io, creates an account, or uses any BeforeTomorrow studio or API — whether you are in the European Economic Area, the United Kingdom, Turkey, the United States, or elsewhere. We apply one global standard rather than a different policy per region: our default is opt-in consent for anything not strictly necessary (the GDPR/KVKK standard), which is a strict superset of what opt-out regimes like the CCPA/CPRA require. This means every visitor, everywhere, gets the same strongest-applicable protection.

3. What personal data we collect

We collect the following categories of personal data:

  • Account data: name, email address, password (hashed by AWS Cognito — we never see or store your plaintext password), profile photo, and any optional profile fields you fill in (bio, company, website, social links).
  • Authentication data: if you sign in with Google, Amazon, or another identity provider, we receive your name, email, and profile photo from that provider as permitted by the scopes you approve.
  • Content you create: prompts, briefs, uploaded files/images, and the generated output (presentations, documents, images, etc.) you produce using our studios.
  • Billing data: credit balance, transaction history, and — if you purchase credits — payment data processed by our payment processor (we do not store full card numbers on our own servers).
  • Usage data: pages visited, studios opened, features used, generation timestamps, error events, and approximate performance metrics, collected only if you consent to Analytics cookies (see §8, Cookies).
  • Device/technical data: browser type and version, operating system, and User-Agent string — collected for security (fraud/abuse detection, rate limiting) and, if consented, analytics.
  • Consent records: your cookie/tracking preferences and the timestamp, category choices, and policy version you agreed to — kept as proof of consent (see §9).
  • Communications: content of any message you send us via email or support channels.

What we do NOT collect: we do not collect precise geolocation, biometric identifiers, government ID numbers, or health data, and we do not knowingly collect data from anyone under 16 (see §12).

5. How long we keep your data

  • Account data: retained while your account is active, plus 30 days after deletion to allow recovery from accidental deletion, then permanently erased.
  • Generated content: retained while your account is active, or until you delete it; you can delete individual generations at any time from your library.
  • Billing/transaction records: retained for 10 years after the transaction to comply with Turkish tax law (Vergi Usul Kanunu) and equivalent accounting obligations.
  • Consent records: retained for the duration of the consent plus 3 years afterward, as evidence of compliance in case of a regulatory inquiry.
  • Security/technical logs: retained for a maximum of 90 days, then automatically purged.

6. Who we share your data with

We do not sell your personal data. We share data only with the following categories of recipients, each acting as our processor/sub-processor under a data processing agreement (GDPR Art. 28) or equivalent contractual safeguard:

  • Amazon Web Services (AWS) — cloud infrastructure, database (DynamoDB), storage (S3), and AI inference (Bedrock). Primary processing region: eu-central-1 (Frankfurt, Germany, EU). AWS processes data under the AWS GDPR Data Processing Addendum.
  • Google (Analytics, Ads) — only if you consent to Analytics or Advertising cookies (see §8). Google Consent Mode v2 ensures no Google tag collects personal data before you consent.
  • Payment processors — to process credit purchases; they receive only the data necessary to complete the transaction.
  • Legal/regulatory authorities — only when required by law, court order, or to protect our legal rights.

We never share your account data, prompts, or generated content with other users, except content you explicitly choose to publish to a public gallery.

7. International data transfers

Our primary infrastructure runs in AWS eu-central-1 (Frankfurt, EU), so most personal data never leaves the European Economic Area. Where a transfer outside the EEA/UK/Turkey is necessary (for example, a global CDN edge node or a US-based sub-processor), we rely on the European Commission's Standard Contractual Clauses (2021/914/EU), the UK International Data Transfer Addendum, or an equivalent safeguard recognized under KVKK Art. 9, and we verify the recipient provides an adequate level of protection before any transfer occurs.

8. Cookies and tracking

We use cookies and similar technologies in four categories, controllable individually via the consent banner shown on your first visit or anytime through "Cookie settings" in the footer:

  • Strictly necessary (always on)Required for the site to function: authentication (AWS Cognito session), security (CSRF/rate-limit tokens), load balancing, and remembering this consent choice itself. These cannot be switched off because the service cannot operate without them.
  • Analytics (opt-in)Helps us understand how the product is used (pages visited, features used, errors hit) so we can improve it. Data is aggregated; we do not sell it.
  • Advertising (opt-in)Used to measure the performance of our own ad campaigns (Google Ads) and, if enabled, to personalize ads you see elsewhere. Disabling this stops ad measurement and personalization cookies, not the ads you see (those are controlled by the sites you visit).
  • Functionality (opt-in)Remembers preferences like language, theme, and recently used studios to make the product nicer to use across visits. Not required for core functionality.

Full technical detail on every cookie we set is in our Cookie Policy.

9. Your rights

Depending on where you live, you have some or all of the following rights over your personal data. We honor the strongest applicable version of each right, for every user, regardless of location:

  • Access — request a copy of the personal data we hold about you (GDPR Art. 15 / KVKK Art. 11(1)(a-ç) / CCPA §1798.100).
  • Rectification — correct inaccurate or incomplete data (GDPR Art. 16 / KVKK Art. 11(1)(d)).
  • Erasure ("right to be forgotten") — request deletion of your data, subject to our legal retention obligations (GDPR Art. 17 / KVKK Art. 11(1)(e) / CCPA §1798.105).
  • Restriction — request we limit processing while a dispute is resolved (GDPR Art. 18).
  • Portability — receive your data in a structured, machine-readable format (GDPR Art. 20).
  • Objection — object to processing based on legitimate interest, including profiling for marketing (GDPR Art. 21).
  • Withdraw consent — at any time, with no effect on the lawfulness of processing before withdrawal (GDPR Art. 7(3) / KVKK Art. 11(1)(ç)) — use "Cookie settings" in the footer or contact us.
  • Opt out of sale/sharing — we do not sell personal data, and honor the Global Privacy Control (GPC) signal as an automatic opt-out of any data sharing for cross-context advertising (CCPA/CPRA, 11 CCR §7025).
  • Non-discrimination — we will never degrade your service or pricing because you exercised a privacy right (CCPA §1798.125).

To exercise any of these rights, email contact@beforetomorrow.io. We verify your identity before acting on a request and respond within 30 days (KVKK Art. 13(2)) or one month, extendable by two further months for complex requests (GDPR Art. 12(3)). If you are in Turkey and unsatisfied with our response, or receive no response within the statutory period, you may complain to the Kişisel Verileri Koruma Kurumu (KVK Kurumu) within 30 days of our response or 60 days of the request if we do not respond. If you are in the EEA/UK, you may complain to your local supervisory authority.

10. How we protect your data

  • Encryption in transit (TLS 1.2+) for every connection to our servers, and encryption at rest for all databases and object storage.
  • Least-privilege IAM roles — application servers hold only the specific AWS permissions each function needs, never broad account access.
  • Cryptographic authentication — passwords are never stored in plaintext; sessions are verified via signed JWTs issued by AWS Cognito.
  • Rate limiting and abuse detection on every state-changing endpoint to prevent credential stuffing and denial-of-service.
  • Input validation and output encoding on every API boundary (OWASP Top 10 controls) to prevent injection attacks.
  • Regular dependency and infrastructure review to close known vulnerabilities promptly.
  • Data minimization by design — we intentionally never log or store your IP address in our consent-proof records.

11. Automated decision-making and AI processing

The core of our service is AI-assisted content generation: your prompts and briefs are sent to large language models (run on AWS Bedrock, within the EU where residency requires it) to produce the presentations, documents, and other artifacts you request. This is a service you directly request and control — it is not automated decision-making that produces legal or similarly significant effects about you (GDPR Art. 22), since you review and choose whether to use every output. We do not use your data to train third-party foundation models, and your prompts/content are not used to profile you for purposes unrelated to delivering the service you asked for.

12. Children's privacy

BeforeTomorrow is not directed at, and we do not knowingly collect personal data from, anyone under 16 years of age (the GDPR's default age of digital consent, which we apply globally as the stricter standard even where local law sets a lower age, e.g. 13 under CCPA/COPPA). If we learn that a user under 16 has provided us with personal data, we will delete it promptly. Parents or guardians who believe their child has provided us data should contact contact@beforetomorrow.io.

13. Changes to this Policy

We will update this Policy as our processing activities evolve. Material changes will be communicated by email or a prominent in-product notice, and — where the change affects the scope of your consent (e.g. a new tracking category) — we will ask for fresh consent before the change takes effect. The version number and "Effective" date at the top of this page always reflect the current, binding version.

14. Contact us

For any privacy question, request, or complaint:
Ideasets Teknoloji Yapay Zeka Ticaret Anonim Şirketi
Üsküdar, İstanbul, Türkiye
Email: contact@beforetomorrow.io