Privacy Policy
Sivas Cumhuriyet University — CU Mobile and CU Alumni mobile apps
Effective date: 22 September 2026
This policy explains how the CU Mobile (edu.cumhuriyet.app) and
CU Alumni (edu.cumhuriyet.graduate) mobile apps published by Sivas Cumhuriyet
University, and the university server they connect to (cumobile.cumhuriyet.edu.tr), process
personal data. The data controller is Sivas Cumhuriyet University. If the two versions differ, the
Turkish version prevails.
1. Data the apps send to the university server
| Data | Purpose |
|---|---|
| CU Mobile sign-in: username (student number, staff registry number, national ID number or institutional e-mail) and password | Authentication. The password is sent only with the sign-in request and is passed to the university's identity system for verification; it is stored neither on the phone nor on the server. |
| CU Alumni sign-in: national ID number and date of birth; with ID card sign-in, the card's chip data (see section 3) | Authentication. No password is requested. |
| Device information: a device identifier generated by the app, platform, device model, operating system and app version, whether notifications are allowed, notification token (FCM) | Binding the session to the device, sending notifications, fixing device- or version-specific problems |
| The moment a notification reaches your phone and is opened | Measuring whether notifications are delivered |
| Your survey answers | Taking part in the survey. Who gave the answer is stored encrypted, so the same survey cannot be answered twice. |
| Your requests, suggestions and complaints: the unit you choose, the request type and your message, together with your name | Forwarding the message to the relevant unit and answering it |
| With every request: IP address, time and the operation performed | Security, abuse prevention, error diagnosis |
2. Other processing on the server and retention
- The information you see in the app (such as name, surname, faculty, department or unit, title, grades, timetable, leave records and announcements) is retrieved from the university's own information systems under your identity and passed to the app. So that notifications reach the right person, your name, user type and the faculty, programme or unit you belong to are kept with your device registration.
- Grade notifications (CU Mobile, students): for students signed in on at least one device, grades are checked periodically in the student information system and a notification is sent when a new grade is published. The grade itself is not stored; only a keyed digest sufficient to detect a change is kept, together with the course code and term. The notification contains the course name and exam type, not the grade. Grade notification records are deleted after 120 days.
- Security and diagnostic records are deleted automatically: request logs after 30 days, sign-in attempts (the username tried, the result, IP address and device) after 180 days, error records after one year, and expired session tokens 30 days after they expire.
- Other records (device registrations, notifications sent, grade digests, survey answers, requests) are kept according to the university's Personal Data Retention and Destruction Policy (see section 8).
3. Signing in with a Turkish ID card (CU Alumni)
ID card sign-in is optional. The machine-readable zone on the back of the card is decoded with the camera on your phone, offline; it is used only to open a secure channel with the card's chip. The card image and the text of this zone never leave your phone and are not stored.
Only the identity data group (DG1: national ID number, name, surname, date of birth, sex, nationality, document number and expiry date) and the security data that prove the card is genuine (SOD and DG15) are read from the chip; the card also signs a one-time value sent by the server. Your photograph (DG2) and other personal details (DG11) are not read.
This data is sent to the university server to verify that the card is a genuine, unaltered Turkish ID card. The server checks the signatures and completes the sign-in with your national ID number and date of birth; it does not store the chip data or the signature.
4. Data that stays on your phone
- Session tokens are kept in the operating system's secure keystore (iOS Keychain / Android Keystore) and are presented only to the university server, to prove your identity.
- The notification inbox and information cached for offline use are kept in an encrypted local database whose key is in the secure store. This content is not sent back to the server.
- CU Mobile: the Student Information System (OBS) portal username and password, if you choose to save them, are kept in the secure store. They are used only to fill in the sign-in form of the OBS portal opened inside the app and go from there directly to OBS; they are never sent to the CU Mobile server or any third party. You can turn this off and delete them from inside the app.
- CU Alumni: the notification channels you have muted.
5. Third parties
Google Firebase (both apps)
Cloud Messaging (notification delivery), Crashlytics (crash reports), Analytics (usage analytics), Performance Monitoring, Remote Config (remote settings), App Check (verifying the app is genuine) and In-App Messaging. Data sent to Firebase:
- the notification title and text and the notification token (to deliver the notification to your phone),
- a pseudonymous user id (a salted hash of your user key; your name, number or e-mail is not sent), user type and faculty id,
- device information such as manufacturer, model, operating system version and whether notifications are allowed,
- in-app interaction events (such as screen views, sign-in, sign-out, opening a notification), crash logs, network request timings and the Firebase installation id.
Google acts as a processor on behalf of the university for the Firebase services.
Google ML Kit (CU Alumni only)
The text recognition component that reads the card's machine-readable zone runs on the phone; camera images are not sent to Google. When the component is used, usage information such as device and app information, a per-installation identifier and performance metrics goes to Google, which uses it to diagnose and improve ML Kit.
Talsec freeRASP (CU Mobile only)
A component that checks the security of the phone and the app: root access or jailbreak, debuggers, tampering and whether the app is a modified copy. It sends the check results, the security state of the app and device, and anonymous app and device identifiers to Talsec; Talsec may derive an approximate location (country, region, city) and the network operator from the IP address of this request. Your name, number and the information in the app are not sent to Talsec. Talsec uses this data for security reporting, abuse detection and improving its own product.
Under the Firebase, ML Kit and Talsec services, this data may be processed on servers outside Türkiye. The apps show no advertising and do not collect the advertising id; data is not used for advertising and is not sold. University web pages opened inside the app (such as the OBS portal) connect directly to the university system concerned.
6. Security
- All traffic between the app and the server is encrypted with TLS; the university server's certificate is pinned in the app.
- Every request to the server is signed with HMAC-SHA256.
- Your password is stored neither on the phone nor on the server; sessions use time-limited tokens that change on every refresh.
- Data on the phone is encrypted, with the key held in the operating system's secure store.
- Optional app lock (fingerprint, face or device passcode).
- Screenshot protection on sensitive screens; root, debugger and tampering detection.
7. Permissions
- Notifications: to show announcements and notifications meant for you (for example, that a grade has been published). If you decline, the app still works; you simply receive no notifications.
- Biometric authentication: for the optional app lock. Fingerprint and face data never reach the app; the operating system performs the check.
- Camera and NFC (CU Alumni only): only during ID card sign-in; the camera reads the back of the card and NFC reads its chip. Camera images are not stored or transmitted. This sign-in method is optional.
Location, microphone, contacts, calendar, photos and file access are never requested.
8. Your rights
The apps do not create a separate account; you sign in with your existing university record. At any time, from inside the app, you can:
- remove this device's registration (notifications to that device stop); signing out also removes the device's registration,
- sign out of every device,
- delete the saved portal credentials in CU Mobile.
To exercise your rights under Article 11 of the Turkish Personal Data Protection Law No. 6698 (KVKK), such as learning whether your data is processed or asking for it to be corrected or deleted, use the application form on the university's Personal Data Protection page or write to bidb@cumhuriyet.edu.tr. The university's data protection policy and its Retention and Destruction Policy are also published on that page.
The deletion steps and how to request deletion are described in detail on the Account and Data Deletion page.
9. Children's data
The apps are intended for university students, staff and alumni. They are not directed at children and do not knowingly collect data from children.
10. Changes
When this policy is updated, the new version is published on this page and the effective date is revised.
11. Contact
Sivas Cumhuriyet University — Department of Information Technologies
Daire Başkanlıkları Binası A Blok, 58050 Yenişehir / Sivas, Türkiye
bidb@cumhuriyet.edu.tr