ReyportTürkçe

Privacy Policy

Last updated:

This policy explains what personal data Reyport collects, why, who else receives it, where it is stored, how long it is kept, and what rights you have. It describes the system as it actually works on the date above, including the parts that are less convenient to describe.

The Turkish version of this page is also Reyport's information notice (aydınlatma metni) under Turkish Personal Data Protection Law No. 6698 (KVKK). Both versions describe the same practices; if they ever differ, the version that is more protective of you applies.

1. Who is responsible

Data controller: Reyport — Emir Zanyar Kaya. Reyport is a brand name and is not yet operated through an incorporated company, so the natural person named here operates reyport.com and app.reyport.com and is personally responsible, as data controller, for the personal data described in this policy. "Reyport", "we" and "us" in this policy refer to that person. If a company is incorporated, this policy will be updated to name it as controller and account holders will be notified as described in section 14.

For any question about this policy or to exercise any of your rights, write to info@reyport.com.

2. What Reyport does

Reyport is a business-to-business tool for exporters. A user describes, in their own words, the kind of buyer they are looking for in a country. Reyport then searches public map listings and the public web for matching companies, uses AI to judge whether each one could plausibly buy, collects the business contact details those companies publish, drafts an outreach email per company with AI, and sends it from the user's own mailbox only after a person on the user's team approves it. Replies are read back from the user's mailbox so they can be matched to the email that caused them.

Accounts are created by us for business customers; there is no public sign-up.

3. Data we process about our users, and why

3.1 Account data

  • Your login email address and password. Authentication is handled by Supabase Auth, which stores the password as a one-way hash; we never see it in plain text. Supabase Auth also keeps technical sign-in records, which can include the time and IP address of a sign-in.
  • The link between your login and your company account. Everyone who is a member of a company account sees that company's data.

Why: to let you sign in and to keep each company's data separate from every other company's.

3.2 Company profile and knowledge base

  • Company name, website, location, sector and sub-sectors, a free-text description, strategic notes, email templates and their instructions.
  • Files you upload, with the file name and any note you attach. Uploaded files are kept in Supabase Storage at a link that is hard to guess but public: anyone who has the exact link can open the file. Deleting a file in Reyport removes it from your account, but does not currently delete the stored file itself; write to us and we will delete it.

Why: the AI reads your profile to decide which discovered companies count as potential buyers and to write emails that describe your business accurately. Only include personal data in these fields if it is needed for that.

3.3 Mailbox connection

  • For each mailbox you add: the email address, a label, the SMTP and IMAP server settings, the username and the password. The password is encrypted with AES-256-GCM before it is stored and is never sent back to your browser.
  • Adding a mailbox always requires these server credentials (for Gmail, typically an app password). Reyport uses them to read the inbox over IMAP, and to send over SMTP where the hosting network allows it.
  • Sending limits and counters, a warm-up schedule start date, bounce-rate holds, connection status, and your email signature.
  • If you also authorise Google for sending, the data described in section 5.

3.4 Email content

  • Drafts: recipient address, company name, subject, body, status, send time, the message's Message-ID, Gmail's thread ID when sent through the Gmail API, any error message, and whether it bounced.
  • Sent emails: a copy of each email sent through Reyport is stored with its sender, To, Cc and Bcc addresses, subject and plain-text and HTML body. The same message is also placed in your mailbox's Sent folder.
  • Inbox: every two minutes Reyport connects to your mailbox's INBOX folder over IMAP and stores the messages that arrived since the last check (on the first connection, the last 30 days). This is every message in the inbox, not only replies to emails sent through Reyport. For each message it stores the sender's name and address, the To and Cc addresses, subject, plain-text and HTML body, date, read status, Message-ID, In-Reply-To and References headers, Gmail's thread ID where the server provides it, and whether it is a reply, a bounce or an automatic reply. Attachments on incoming messages are not stored. Folders other than INBOX are not read.
  • Attachments you add to emails you write in Reyport are stored in Supabase Storage at a hard-to-guess public link, like uploaded files (3.2).
  • Unsent emails you are writing in the mail composer are saved automatically so they survive a page reload.

Why: to send the emails you approve, to show you your inbox inside Reyport, to link each reply to the email that caused it, and to detect bounced addresses so they are never emailed again.

3.5 Customer records and activity

Companies you move from discovery into your customer list, with their status, your notes, follow-up dates and AI-written summaries; a history of changes to them; and a log of actions in your account (discovery runs, drafts generated, emails sent) with their cost. Why: so you can manage your sales pipeline and see what was done.

3.6 AI assistant conversations

Messages you type to the Reyport AI assistant. Your conversation history is stored only in your browser (localStorage), not on our servers, and is removed from the browser when you log out. Each message you send is processed by OpenAI together with your company context (see section 6). If you use the assistant on the Mail page while a message is open, that message's sender name and address, subject, and the first 500 characters of its body are included.

3.7 Technical data

Server logs kept by our hosting provider. They contain company and mailbox identifiers, error messages, and in some cases email addresses (for example, the sender of a reply that could not be matched to a sent email) and the message and thread IDs Gmail returns after a send. Why: to operate, debug and secure the service.

3.8 Legal bases

Under KVKK Article 5(2) and GDPR Article 6(1), we rely on: performance of our contract with your company (KVKK 5(2)(c), GDPR 6(1)(b)) for providing the service; compliance with legal obligations (KVKK 5(2)(ç), GDPR 6(1)(c)); and our legitimate interests in operating, securing and improving the service (KVKK 5(2)(f), GDPR 6(1)(f)). We do not intentionally process special categories of personal data.

4. Personal data of people who are not our users: discovered business contacts

Reyport's core function collects information about companies that our users may want to contact, and about people who work at them. If you work at such a company, this section is for you. It is also how we meet the duty to inform people whose data we did not obtain from them directly (KVKK Article 10, GDPR Article 14).

Where it comes from

  • Public business listings on Google Maps and public web search results, obtained through the search provider Serper.dev, including public LinkedIn company pages and Facebook and Instagram pages that appear in those results.
  • The company's own public website: Reyport reads up to six pages of the company's own domain.

What is collected

  • Company details: name, website, phone number, address, business category.
  • Email addresses published on those pages, the page they were found on, and the text around them.
  • Names and job titles of people that appear next to those addresses or on pages such as a team page.
  • Short excerpts of the company's homepage and of search results, and an AI-written relevance score and reason.
  • Inferred addresses. If a company's site publishes one person's address (for example a.yilmaz@example.com) and also names another person with a job title but no address, Reyport may generate one likely address for that second person using the same pattern. This is a guess, and it is recorded as inferred rather than found.
  • Technical checks: whether the address's domain accepts email (a DNS lookup).

What is done with it

  • The text around each found address, together with the address, is sent to OpenAI to classify it (for example, a general company inbox or a named person's address).
  • Company data is sent to OpenAI to judge relevance and to write a draft email.
  • The results are shown only to the company account that ran the search.
  • An email is sent only if a person at that company approves it. It is sent from that company's own mailbox, under that company's name, and every email includes an unsubscribe link and a List-Unsubscribe header.

Why, and on what legal basis

To let businesses find and make first contact with other businesses that may buy their products. We rely on legitimate interests in business-to-business commercial contact (KVKK 5(2)(f), GDPR 6(1)(f)) and, for contact details a person or company has published for business contact, on the data having been made public by the person concerned (KVKK 5(2)(d)). Only information that is publicly available is collected. The Reyport user who decides to contact you is responsible for having a lawful basis to email you in your country (see our Terms of Service); Reyport is responsible for how the discovery system collects and stores the data.

How long it is kept

Discovery results are kept with the search run's records and are not deleted automatically. Some derived search statistics expire after 90 days, and the memory of companies a search rejected expires after 30 days.

Your options

  • Use the unsubscribe link in any email you received. After you confirm, your address is added to that sending company's do-not-send list, and Reyport refuses every later send to it from that company.
  • Write to info@reyport.com to ask what we hold about you, to have it deleted, or to object. We will delete your data from discovery results and customer records, and, so that you are not found and contacted again, add your address to the do-not-send list of each Reyport customer account. That list keeps only your address and the reason.

5. Google user data

Connecting Google is optional. It exists only so that Reyport can send the emails you approve from your Gmail address through the Gmail API. This section describes exactly which Google permissions Reyport requests and what happens to the data they give access to.

5.1 Permissions (OAuth scopes) requested

ScopeWhat Google calls itWhat Reyport does with it
https://www.googleapis.com/auth/gmail.sendSend email on your behalfSends each email you approve in Reyport from your Gmail account, through the Gmail API's messages.send method. Nothing else. This permission cannot read, list, search, change or delete any message in your mailbox.
openidAssociate you with your personal info on GoogleRequested together with email because Google's user-info endpoint does not accept a token that only has gmail.send. Reyport does not store your Google account ID.
email (https://www.googleapis.com/auth/userinfo.email)See your primary Google Account email addressRead once, immediately after you connect, to record which Google account was authorised and to warn you if it is not the same address as the mailbox you connected it to.

Reyport requests no other Google permissions. It does not request read access to Gmail through Google's APIs. Reading your inbox (section 3.4) happens over IMAP with the server credentials you entered when adding the mailbox, not through the Google authorisation.

5.2 What Reyport stores from Google

  • The OAuth refresh token and access token Google issues, and the access token's expiry time. Both tokens are encrypted with AES-256-GCM before they are stored and are never sent to your browser.
  • The email address of the Google account you authorised.
  • For each email sent through the Gmail API, the Gmail thread ID, used only to link replies to the email that caused them. The message ID, thread ID and label IDs Google returns are also written to server logs.
  • If Google reports that the authorisation has been revoked or has expired, the time and the error message, so Reyport can show you why sending stopped.

The content of the emails sent through Gmail is written in Reyport before it is sent; Reyport does not receive email content from Google. That content is stored as described in section 3.4. All of the above is held in our database (Supabase, Switzerland) and passes through our application servers (Railway, United States).

5.3 How Google user data is used, and the limits on that use

Reyport's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google user data is not used to train any artificial intelligence or machine learning model, and it is not sold or shared for advertising.

  • Google user data is used only to provide the Gmail sending feature you see in Reyport.
  • It is not sent to OpenAI or any other AI provider, and it is not transferred to anyone else except the hosting providers that store and run Reyport, or where required by law.
  • It is not used for advertising, for credit or lending decisions, or to build profiles of you.
  • No person at Reyport reads it, except with your explicit permission, when necessary for security (for example, investigating abuse), or to comply with the law.

5.4 Retention and deletion of Google user data

  • Kept for as long as Google stays connected to the mailbox in Reyport.
  • When you disconnect Google in Reyport (Company page, email accounts), the refresh token, access token, expiry time and Google account email address are deleted from our database immediately, and the mailbox goes back to sending over SMTP.
  • If Google reports the authorisation revoked, Reyport deletes the stored access token immediately and stops sending through Gmail. The encrypted refresh token stays stored until you disconnect Google or delete the mailbox in Reyport.
  • When you delete the mailbox in Reyport, all of its tokens and all of its stored messages are deleted permanently. Drafts created for that mailbox, including their Gmail thread IDs, remain in your account until you ask us to delete them or your company account is deleted.
  • Server logs are kept for the log retention period of our hosting provider.

5.5 How to revoke Google access

  • In Reyport: open the Company page and choose to disconnect Google on the mailbox. This deletes the tokens Reyport holds.
  • At Google: go to https://myaccount.google.com/permissions, select Reyport and remove its access. Disconnecting in Reyport does not by itself revoke the grant at Google, so do both if you want the authorisation gone on both sides.
  • After revocation, Reyport can no longer send from your Gmail address. Reading your inbox over IMAP continues until you disconnect or delete the mailbox in Reyport, because it uses separate credentials.

6. Service providers and what each receives

We do not sell personal data. The following providers process personal data on our behalf to run Reyport:

ProviderWhat it doesWhat it receivesLocation
SupabaseDatabase, sign-in, file storageEverything stored by Reyport and described in sections 3 to 5: account and company data, mailbox credentials and Google tokens (encrypted), drafts, sent and received emails, customer records, discovery results. Login email and password hash. Uploaded files and outgoing attachments.Switzerland (AWS eu-central-2, Zurich)
RailwayHosting of the application, the background worker and the Redis working storeAll data passes through its servers while being processed. Redis holds working data for discovery searches, including discovered companies and contacts, and usage counters. Server logs (section 3.7).United States
OpenAIAI models: understanding your search goal, scoring companies, classifying found addresses, writing and translating drafts, customer summaries, the AI assistantYour search goals; your company profile, notes, file names and file notes, template instructions; the email addresses of mailboxes you connected (as assistant context); discovered company data, page excerpts and search snippets; found email addresses with the text around them; draft subjects and bodies; your messages to the assistant; on the Mail page, the open message's sender, subject and first 500 characters. It does not receive mailbox passwords, Google tokens, your Google account email address or Gmail thread IDs.United States
Serper.devWeb and map searchSearch queries built from your goal: product and category terms, city and country names, and company names and websites when looking up a company's site. No account data or email content.Outside Türkiye
GoogleGmail API, only if you connect GoogleThe emails you send through the Gmail API, and the authorisation described in section 5.Google's global infrastructure
OpenStreetMap NominatimConverting city names to map coordinatesCity and country names only. No personal data.Outside Türkiye
Your email providerYour own mail serversYour mailbox credentials when Reyport connects, and the emails sent and read.Chosen by you

Reyport's crawler also requests pages from the websites of discovered companies and looks up their domains in DNS; those sites and DNS servers see a request from our hosting provider, but no user data is sent to them.

OpenAI requests are made with OpenAI's default setting, which lets OpenAI keep the request and response content. Under OpenAI's API data policies this content is retained for up to 30 days and is not used to train OpenAI's models. We do not use the data sent to OpenAI to train any model.

Reyport's code can also check email addresses with an email verification provider (MyEmailVerifier, or ZeroBounce). This is not enabled as of the date above. If it is enabled, this policy will be updated before it is, to say so.

7. International transfers

Reyport's database is in Switzerland and its application servers are in the United States, and OpenAI processes data in the United States. Personal data is therefore transferred outside Türkiye and, for people in the European Economic Area, outside the EEA.

These transfers are made under Article 9 of KVKK and Chapter V of the GDPR, relying on the standard contractual clauses in these providers' data processing terms. You can ask us at info@reyport.com for information about the safeguards used for a particular provider.

8. How long data is kept

DataRetention
Account and company dataAs long as the company account exists. There is no self-service account deletion; write to us and we will delete the company account and all data attached to it.
Mailbox credentialsUntil you delete the mailbox in Reyport.
Google tokens and Google account emailUntil you disconnect Google or delete the mailbox (details in 5.4).
Sent and received emailsNot deleted automatically. Deleting a message in Reyport's mail view hides it but keeps it in the database. Deleting the mailbox in Reyport permanently deletes all of its stored messages. Drafts remain after the mailbox is deleted.
Uploaded files and outgoing attachmentsDeleting a file in Reyport removes its record; the stored file remains until we delete it at your request.
Customer records and activity historyAs long as the company account exists.
Discovery results, including discovered business contactsNot deleted automatically (section 4). Derived search statistics expire after 90 days; the list of rejected companies after 30 days.
Do-not-send listAs long as the company account exists, so that an opt-out keeps working.
Email verification resultsKept; a result is re-checked when it is older than 30 days.
AI assistant historyIn your browser only, until you log out or clear it.
Server logsFor our hosting provider's log retention period.
Data sent to OpenAIUp to 30 days at OpenAI (section 6).

When data is deleted from the database, copies in the database provider's backups can persist until those backups expire.

9. Security

Connections to Reyport use HTTPS. Mailbox passwords and Google tokens are encrypted with AES-256-GCM using a key held only by the application server; the background worker holds neither that key nor any access to the database. Every company's data is kept separate from every other company's, and automated tests check that separation. Uploaded files and attachments are the exception described in 3.2: they are reachable by anyone who has their exact link. No system is completely secure; if a breach affects your personal data, we will notify you and the authorities as the law requires.

10. Your rights and how to use them

Under Article 11 of KVKK you have the right to learn whether your personal data is processed; to request information about it; to learn the purpose of processing and whether it is used for that purpose; to know the third parties it is transferred to in Türkiye or abroad; to request correction of incomplete or inaccurate data; to request its deletion or destruction; to request that third parties it was transferred to are notified of a correction or deletion; to object to a result against you arising exclusively from automated analysis; and to claim compensation for damage caused by unlawful processing.

Under the GDPR (Articles 15 to 22), people in the EEA have the rights of access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests, including at any time to direct marketing.

To exercise any of these rights, email info@reyport.com from the address concerned, or tell us how we can confirm that the data is yours. We may ask for information to verify your identity. We answer free of charge within 30 days (KVKK) and within one month (GDPR), unless the law allows a fee or an extension for a particular request.

If you are not satisfied with our answer, you can complain to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, https://www.kvkk.gov.tr) or, in the EEA, to the data protection authority of your country.

11. Cookies and browser storage

  • Sign-in cookies set by Supabase Auth (names starting with sb-): keep you signed in. Strictly necessary.
  • NEXT_LOCALE: remembers the language you chose for the app, for one year. Set only when you switch language.
  • Browser localStorage: your AI assistant conversation history, per company, removed when you log out.

Reyport uses no analytics, advertising or third-party tracking cookies. Fonts are served from Reyport's own domain. Because only strictly necessary storage is used, there is no cookie consent banner.

12. Automated decisions

AI scores decide which companies are shown as potential buyers and which are set aside. These scores concern businesses, not individuals, and do not produce legal effects for anyone. Users can restore a company the AI set aside, and no email is sent without a person approving it.

13. Children

Reyport is a service for businesses and is not intended for anyone under 18.

14. Changes to this policy

When this policy changes, the date at the top of this page changes. For a material change, such as a new category of data, a new purpose, or a new provider receiving personal data, we will email account holders at least 30 days before the change takes effect. A change required by law or needed to protect security can take effect sooner, and we will explain why.