Privacy Policy
Privacy Policy — Duet
Last updated: 28 August 2026
This Privacy Policy describes how Morrowline Apps (trading as Seyfi Can Zeyrek) (“we”, “us”) handles information in the Duet mobile application on Android and iOS.
Related documents: Terms of Use. Turkish KVKK notice: KVKK aydınlatma.
1. Introduction
Duet is a couple home-screen widget app. Two adults can pair, sync widgets (timer, countdown, notes, drawings, distance, and related types), send pings, and optionally subscribe to Couple Pro. This policy covers Duet version 1.0 and later on Android and iOS.
2. Data controller
Controller: Morrowline Apps (trading as Seyfi Can Zeyrek)
Address: Esenyali Mahallesi 52/75 Sk. Izmir/Türkiye
Country: Türkiye
Privacy email: sczgamesinfo@gmail.com
Support email: sczgamesinfo@gmail.com
Data-protection inquiries: sczgamesinfo@gmail.com
Phone: not published; use email.
EU Digital Services Act (trader): In the European Union we act as a trader. The same legal name, postal address, and email above are our trader contact details.
3. Scope
This policy applies to Duet on Android (com.morrowline.duet) and iOS (com.morrowline.duet), including the iOS widget extension (com.morrowline.duet.DuetHomeWidget), invite pages on https://duet.morrowline.app/, and our Firebase backend for project duet-172cf. It does not apply to Apple, Google, or RevenueCat’s own consumer accounts.
4. Data we collect
| Category | Examples | Purpose | Location | Retention | Shared with |
|---|---|---|---|---|---|
| Account identifiers | Firebase anonymous UID; optional Apple or Google identity; display name | Run Duet, pair partners, restore purchases | Firebase Auth / Firestore users/{uid}; RevenueCat app user id |
Until account deletion | Google; Apple or Google if you link; RevenueCat |
| Couple content | Widget settings, names, notes, drawings metadata, pings, pet/care, check-ins, activity, events | Provide the paired service | Firestore couples/{id} |
Until unpair or overwrite; the couple document cannot be deleted by the client | Your paired partner; Google |
| Photos and drawings | Timer portraits, custom backgrounds, drawing PNGs | Show on widgets and to your partner | Firebase Storage under couples/{id}/… |
Until overwritten; account deletion currently does not delete these Storage objects | Your paired partner (download URLs); Google |
| Precise location | Latitude, longitude, timestamp | Straight-line distance | Firestore couples/{id}/locations/{uid}; live/state.distanceKm |
Until you stop sharing, overwrite, or leave | Your paired partner; Google; Cloud Functions |
| Device / push identifiers | FCM registration tokens | Partner alerts and silent widget refresh | users/{uid}.fcmTokens; Google FCM |
Until rotation or account deletion | |
| Settings | Onboarding completed, notification preferences, pinned widget ids | App operation | On device | Until uninstall | Not uploaded as a bulk settings file |
| Widget cache | Names, notes, photo URLs, distance | Home-screen widgets | On device (App Group / widget prefs) | Until widget removed or uninstall | Anyone who can see the device |
| Analytics | Events such as pair_complete, note_sent, ping_sent, pet_care, streak_check_in, account_linked, account_deleted; Analytics userId = Firebase UID | Improve the product | Google Analytics for Firebase | Google default | |
| Crash diagnostics | Stack traces, device/OS, Crashlytics user id | Fix crashes | Firebase Crashlytics | Google default | |
| Purchases | Duet Premium entitlement, weekly/annual packages, store transaction metadata | Couple Pro and couple billing overlay | RevenueCat; admin billing fields | Vendor and legal retention | RevenueCat; Apple or Google; our webhook |
| Invites | 6-digit code, couple id, expiry | Pairing | Firestore invites/{code}; URL path /join/{code} |
About 7 days | Anyone with the link may try to join |
| Security | App Check attestation | Abuse prevention | Short-lived | ||
| Fonts | IP on font fetch | Load fonts | Google Fonts | Google default |
We do not collect advertising IDs, contacts, microphone audio, HealthKit data, or a public social graph.
5. How we collect
- Automatically: Firebase Auth anonymous sign-in, App Check, analytics and crash SDKs, FCM token, app version (
package_info_plus). - You provide: display name, notes, drawings, photos you pick, invite sharing via
share_plus. - Permissions: location when in use, photo library, notifications (see §8).
- Partner: content they save to the couple space, including their location if they enable it.
- Stores / RevenueCat: purchase status after you buy or restore.
6. Why we use data
To operate pairing and widgets, show distance, deliver operational notifications, process Couple Pro, keep the service secure, understand product usage, and fix bugs. We do not use your photos or location for advertising.
7. Legal bases
| Purpose | GDPR / UK GDPR | KVKK |
|---|---|---|
| Provide Duet, pairing, widgets, notes | Contract | Sözleşmenin ifası |
| Location and photo library | Consent (you can refuse) | Açık rıza |
| Operational notifications | Contract | Sözleşmenin ifası |
| Analytics and crash reporting | Legitimate interests | Meşru menfaat |
| App Check / fraud | Legitimate interests | Meşru menfaat |
| Subscriptions | Contract | Sözleşmenin ifası |
| Legal compliance | Legal obligation | Kanuni yükümlülük |
EEA/UK details: GDPR notes below. Türkiye: see the KVKK aydınlatma.
8. Sensitive permissions
Photos
FOR: pictures you select for the timer widget and Couple Pro custom backgrounds. NOT FOR: bulk camera-roll upload or selling images. Selected files are stored locally, then uploaded to Firebase Storage if you save the widget. Person-shaped cutouts run on the device (Apple Vision / Google ML Kit) before upload.
Location
FOR: when-in-use location to compute straight-line distance with your paired partner. We store precise coordinates, not a city name. NOT FOR: background tracking, advertising, or sharing with anyone except your partner and our processors.
Notifications
FOR: partner pings, notes, pairing events, and silent widget updates. NOT FOR: reading other apps’ notifications. Marketing tray campaigns are not in the current visible send set.
Camera (iOS string only)
iOS includes a camera usage description. Current app code picks from the photo library, not the live camera. We do not use the camera for hidden recording.
Accessibility, usage access, overlay, VPN
Not used.
You may revoke permissions in the operating system settings. Features that need that permission will stop working.
9. Sharing and processors
We share couple data with your paired partner. We use these third parties (each is named because it is in the app):
| Name | Role | Data |
|---|---|---|
| Google — firebase_core, firebase_auth, cloud_firestore, firebase_storage, cloud_functions, firebase_app_check | Hosting, auth, database, files, callables, attestation | Account, couple docs, media, App Check |
| Google — firebase_analytics | Analytics | Events, device info, userId |
| Google — firebase_crashlytics | Crash reporting | Stacks, device, user id |
| Google — firebase_messaging | Push | FCM tokens, payloads |
| Google — google_sign_in | Optional account link | Google identity |
| Google — google_fonts | Fonts | IP on fetch |
| Google — Play Billing | Android IAP | Purchase tokens |
| Google — ML Kit subject segmentation | On-device cutout; may download a model | Image frames on device |
| Apple — sign_in_with_apple | Optional account link | Apple identity |
| Apple / Google stores | Payments and distribution | Store account, receipts |
| RevenueCat — purchases_flutter | Subscriptions | Firebase UID as app user id, entitlements |
| geolocator | On-device GPS | Coordinates before Firestore write |
| image_picker | System photo picker | Selected images on device |
| share_plus | System share sheet | Invite text/URL |
| home_widget | Home-screen widgets | Widget payload on device |
| permission_handler | Permission prompts | Permission status |
| flutter_local_notifications | Local notification channel | Channel config |
| url_launcher | Open Play Store listing | Store URL |
| package_info_plus | App version | Version string |
| shared_preferences | Local flags | Keys listed in §4 |
| uuid | Random ids | On device |
| image | Local image bytes | On device |
| video_player | Bundled mascot clips only | No personal data |
We do not sell personal information. We do not use AdMob or other ad networks.
10. International transfers
Firebase, Analytics, Crashlytics, FCM, Fonts, Play, and RevenueCat process data in the United States and other countries. Cloud Functions for this project run in us-central1. Transfers from the EEA/UK use Standard Contractual Clauses or other lawful mechanisms in those vendors’ terms.
11. Retention
- On-device settings: until uninstall.
- User document and Auth user: until you delete your account.
- Couple documents: may remain for the remaining partner (
allow delete: if falseon the couple document). - Storage photos/drawings/backgrounds: until overwritten; account deletion currently does not remove
couples/…/{uid}/objects. - Invite codes: about 7 days.
- Analytics/crash: Google defaults.
- Purchases: as required by store and tax rules.
12. Your rights
EEA. You may access, rectify, erase, restrict, port, and object; withdraw consent; complain to your supervisory authority. Contact sczgamesinfo@gmail.com.
United Kingdom. The same rights under UK GDPR; you may complain to the ICO.
Türkiye. Rights under KVKK Article 11; see the Turkish aydınlatma. VERBİS status: not registered.
California. We do not sell or share personal information for cross-context behavioral advertising. You may request to know, delete, or correct by emailing sczgamesinfo@gmail.com. Precise location and photos you upload are used only to provide Duet features you choose. We do not use a separate “Do Not Sell or Share” link because we do not sell or share for ads.
You can turn off location, photos, and notifications in the OS. You can unlink Apple/Google in Account settings.
13. Account and deletion
Duet creates a Firebase anonymous identifier when you open the app. That is an account identifier, not “no account.” You may link Apple (iOS) or Google.
Delete your account from Us → Account. This calls our deleteAccount function, which deletes your users/{uid} document and the Auth user, and tries to rewrite couple seats for a remaining partner. It does not currently delete Storage files under couples/{coupleId}/photos|drawings|widgetBackgrounds/{uid}/. Shared couple space may stay for your partner. Analytics, RevenueCat, Apple, and Google may retain records under their rules. Home-screen widgets on the device remain until you remove them.
14. Children
Duet is for people 18 years or older. We do not target children. It is not a parental-control product. If you believe a minor used Duet, contact sczgamesinfo@gmail.com.
15. Security
We use HTTPS, Firebase security rules, Storage rules, and App Check (Play Integrity / App Attest in release). On-device stores are not encrypted with a separate app PIN. No method is perfectly secure.
16. Automated decisions
Person segmentation is an on-device cosmetic cutout. We do not make solely automated decisions that produce legal or similarly significant effects.
17. Changes
We will update this policy and the date above. Material changes will be signaled in the app or on https://duet.morrowline.app/en/privacy/ when that page is live.
18. Contact
Morrowline Apps (trading as Seyfi Can Zeyrek)
Esenyali Mahallesi 52/75 Sk. Izmir/Türkiye
sczgamesinfo@gmail.com
Website: https://duet.morrowline.app/

