Privacy Policy
Last updated: 30 July 2026
Short version: we take your email address, use it to tell you when we launch, share it with nobody, and delete it whenever you ask. Everything below is the long, binding version of that sentence.
1. Who is responsible
The controller — under Art. 4(7) GDPR and under Turkey's Personal Data Protection Law No. 6698 (KVKK) — is Murathan Bakti.
- Email: contact@wordmi.com
- Place of establishment: Türkiye
Wordmi is run by Murathan Bakti as an individual, not by a company. We have not appointed a Data Protection Officer, because none of the conditions in Art. 37(1) GDPR apply: our core activity is not large-scale monitoring, and we process no special categories of data.
2. When this policy applies
It applies when you visit this site and when you join the early-access list. Joining is entirely optional — you can read every page without giving us anything.
3. What we process, why, and on what legal basis
Everything is collected directly from you, either from the form you fill in or from the technical information your browser sends with the request. We do not buy data, enrich your record from brokers, or look you up on social networks.
| Data | Why | Legal basis | Retention |
|---|---|---|---|
| Email address | To tell you when we launch and when your invite is ready; to stop the same person being added twice | Your consent — Art. 6(1)(a) GDPR · KVKK Art. 5/1 | At most 6 months after launch and your invite; immediately if you withdraw |
Language preference (e.g. en-US) | So we know which language to write to you in | Legitimate interests — Art. 6(1)(f) GDPR · KVKK Art. 5/2-f | Same as the email address |
Which form you used (hero or the closing section) | To understand which part of the page actually works | Legitimate interests — Art. 6(1)(f) GDPR · KVKK Art. 5/2-f | Same as the email address |
| Invite codes — yours, plus the code of whoever invited you, if any | To count invites and credit the right person | Legitimate interests — Art. 6(1)(f) GDPR · KVKK Art. 5/2-f | Same as the email address |
| Sign-up timestamp | To fix your place in the queue and to evidence when you opted in | Legal obligation and proof of consent — Art. 6(1)(c) and Art. 7(1) GDPR | Same as the email address |
| IP address | Rate limiting, so the form cannot be flooded by scripts | Legitimate interests — Art. 6(1)(f) GDPR · KVKK Art. 5/2-f | Held in server memory for at most 60 seconds. Never written to the database |
| Server logs (IP, user agent, request time) | Security, error and abuse records kept by the hosting provider | Legitimate interests — Art. 6(1)(f) GDPR · KVKK Art. 5/2-f | Per the hosting provider's own short log retention |
Your invite code is derived from your email address — it is the first six characters of a hash of it. The code cannot be turned back into your address, but it is a stable pseudonym tied to it, and the invite link you share contains it.
There is no analytics, advertising or tracking on this site. No Google Analytics, no pixels, no fingerprinting, no heatmaps, no third-party advertising cookies. The page's Content Security Policy blocks outbound connections at a technical level, so this is enforced rather than merely promised.
4. Data that never leaves your browser
The words you click in the subtitle demo, and the word tray they collect into, live only in that tab's memory. They are never sent to a server, never stored, and disappear when you close the tab. That data never reaches us at all.
5. Cookies
There is exactly one cookie: NEXT_LOCALE, which remembers your language. It is written only when you use the language switcher, lasts a year, and contains nothing but a language code such as tr or ja. It is strictly necessary to provide a service you explicitly requested, so it is exempt from consent under Art. 5(3) of the ePrivacy Directive 2002/58/EC (and §25(2) TDDDG in Germany). See the Cookie Policy for detail.
6. Who we share it with
We do not sell, rent or share the list for advertising. The only third parties with access are the technical providers that keep the site running. They act as processors under Art. 28 GDPR, on our instructions and nothing more.
| Recipient | Purpose | Location |
|---|---|---|
| Supabase Inc. | The PostgreSQL database that holds the sign-ups | US-based; data sits on AWS infrastructure in the project's configured region |
| Vercel Inc. | Hosting and serving the site; server logs | US-based; global edge network |
Beyond that we disclose data only where legally compelled — a court order or an explicit statutory requirement. If we receive such a request we will tell you, unless we are prohibited from doing so.
7. International transfers
Because those providers sit outside Türkiye and outside the EEA, your data is transferred internationally. The transfers rest on:
- Art. 46(2)(c) GDPR: the European Commission's Standard Contractual Clauses, together with supplementary measures — a transfer impact assessment and encryption in transit and at rest.
- Art. 9 KVKK, as amended with effect from 1 June 2024: since the Turkish Data Protection Board has issued no adequacy decision, transfers rely on the standard contract safeguard. Executed standard contracts are notified to the Turkish Data Protection Authority within five business days of signature.
The data set being transferred is one email address and a handful of technical fields attached to it. No special categories of data are transferred.
8. Retention and deletion
We keep your record until the purpose is spent: the product launches, your invite goes out, and at most six months later the record is deleted. Ask us sooner and one email is enough — we delete it and write back to confirm.
After deletion we do not keep a copy of your address on a suppression list. Your record is gone entirely, which also means that if you re-join later, it is a fresh sign-up.
9. Your rights
Wherever you live, you can ask us to act on any of the following. If you are in the EEA, the UK or Switzerland these are your rights under Arts. 15–22 GDPR; if you are in Türkiye they are your rights under Art. 11 KVKK. In practice we apply the same standard to everyone.
- Access — confirmation of whether we process your data, and a copy of it (Art. 15).
- Rectification — correction of anything inaccurate or incomplete (Art. 16).
- Erasure — deletion of your record, the “right to be forgotten” (Art. 17).
- Restriction — freezing processing while a dispute is resolved (Art. 18).
- Portability — your data in a machine-readable format (Art. 20).
- Objection — to processing based on legitimate interests (Art. 21). Where you object to direct marketing, we stop unconditionally.
- Withdrawal of consent — at any time (Art. 7(3)). Withdrawal does not affect the lawfulness of processing carried out before it.
- Not to be subject to automated decisions producing legal or similarly significant effects (Art. 22).
Turkish law adds two further rights under Art. 11 KVKK: to learn the third parties your data has been transferred to at home or abroad, and to claim compensation for damage caused by unlawful processing.
10. How to exercise them
Write to contact@wordmi.com. To unsubscribe you can also use the link at the bottom of any email we send you.
- EEA / UK / Switzerland: we answer within one month. If the request is complex we may extend by a further two months, telling you why. There is no charge.
- Türkiye: applications should follow the Communiqué on Application Procedures to the Data Controller and include information identifying you. We conclude the request within 30 days. Applications are free of charge, save for the tariff set by the Board where the response entails an additional cost.
We may ask for extra information to confirm your identity. We do that only to avoid disclosing someone else's data to the wrong person.
11. Complaining to a regulator
- EEA / UK / Switzerland: under Art. 77 GDPR you may complain to the supervisory authority in your country of residence, work, or where the alleged infringement occurred. In Germany that is the data protection authority of your federal state.
- Türkiye: you may complain to the Personal Data Protection Board within 30 days of receiving our reply, and in any case within 60 days of your application (Art. 14 KVKK).
You do not have to come to us first, though we can usually fix things the same day.
12. How we protect it
- All traffic is encrypted with HTTPS, and HSTS refuses unencrypted connections outright.
- The waitlist table has row-level security enabled with no read policy defined. The public key the site uses can neither read nor write the table — it can only call two narrow functions that insert a row and return a count.
- Server-side secrets live in environment variables and are never shipped to the browser.
- A Content Security Policy technically prevents the page from leaking data to third parties.
- The form is rate limited per IP and in aggregate, with hard caps on body size and email length.
No system is perfectly secure. If a breach affects your personal data we will notify the competent supervisory authority within 72 hours under Arts. 33–34 GDPR, notify the Turkish Board within 72 hours under Art. 12/5 KVKK, and tell you directly where the risk to you is high.
13. Children
The early-access list is not for anyone under 16, and we do not knowingly process the data of under-16s. We use 16 because that is the threshold Germany applies under Art. 8 GDPR, and applying the strictest figure everywhere is simpler than tracking each country. If we learn that an under-16 has signed up we delete the record without delay — tell us at contact@wordmi.com if you spot one.
14. Automated decisions and profiling
We make no decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR). We do not profile you. Your place in the queue depends only on when you signed up and how many people you invited.
15. Changes
If we update this policy we change the “last updated” date above. If a change materially expands what we process or why, we email everyone on the list as well. Where the expansion relies on consent, we ask you again rather than assume.
16. Contact
Any privacy question, request or complaint: contact@wordmi.com. Data protection requests are answered by Murathan Bakti personally.