Privacy Policy
BeMatrx ("App", "we", "us", "our") takes your privacy seriously. This Privacy Policy explains what personal data we collect when you use the BeMatrx mobile application, how we use it, with whom we share it, and your rights regarding your data.
By using BeMatrx, you agree to the practices described in this Privacy Policy.
PAI — Privacy with Artificial Intelligence: where a feature in BeMatrx uses artificial intelligence (for example, to generate your avatar, to detect a face in a photo you upload, or to write Bema's replies to you), it processes only what that feature needs, and only to build the result that feature is meant to deliver. The providers who perform this processing act solely on our instructions, as described in section 5.1 — never to build an advertising profile, and never to read your private conversations with other users, other than the messages included in a report about that conversation.
1. Data Controller
Data Controller: BeMatrx Labs
Address: Antalya, Türkiye
Email: privacy@bematrx.com
Website: bematrx.com
2. About Our Service
BeMatrx is a Living World app where you live a chosen life: create characters, pursue virtual careers, engage in social interaction, and participate in a virtual economy.
Minimum Age: BeMatrx is intended for users aged 17 and above. Individuals under 17 are prohibited from using the App.
Real-world interactions: Through BeLocal, users may arrange practical help in the physical world. BeMatrx only introduces users to each other and is not a party to what they arrange. See section 5 of the Terms of Service.
3. Data We Collect
3.1. Information You Provide Directly
When creating an account and using the App, you provide us with:
- Account Information: Email address, password (encrypted), BeMatrx ID (auto-assigned)
- Profile Information: Display name, profile photo or generated avatar, character appearance, date of birth, gender, biography, name style preference, career preference, city of residence, social media links (optional), phone number (optional)
- Content: Photos and videos you share, text posts (Moments, Flashes), captions, comments, likes, ratings, private messages, audition links
- Location Information: Your chosen city and — if you grant location permission — your device's location while the App is open, to work out which city you are in, show nearby venues, check in, and add a place to a Flash. When you share a Moment in Alchemy by taking a photo on the spot, your approximate location is also used to look up the current weather (see 5.1). The App does not collect your location while it is closed or running in the background
- BeLocal Information: Your BeLocal listing (introduction text and the kinds of help you offer), help requests you send or receive, and references you write or receive
- Communications: Messages you send us for support or feedback
- Invitations: The e-mail address of a person you invite by e-mail, used to send the invitation and to match it when the invitation is used
3.2. Information Collected Automatically
- Device Information: Device type (iOS/Android), operating system version, app version, unique device identifiers
- Usage Data: How you use the App (which screens you visit, time spent, features used). You can switch this off at any time in Settings; when you do, the App stops sending it straight away. Crash reports and technical performance measurements are separate from this setting and continue to be sent
- Log Data: IP address, access time, session information
- Notification Data: Device token for push notifications
- Error Reports: Technical data when the App crashes or encounters errors (through our error-reporting provider)
- Screenshot and Screen-Recording Signals: In Whisper conversations the App detects when a screenshot or screen recording is taken and informs the other participant. We record only that the event happened, when, and in which conversation — never the image or the recording itself
- Bluetooth Proximity Data: When you open the nearby-people screen and grant Bluetooth permission, the App broadcasts a randomly generated, temporary session code over Bluetooth and scans for the codes broadcast by nearby devices. The broadcast carries no name, photo, or account details; each scan lasts about 10 seconds and then stops on its own; and the session code is short-lived: it is deleted from our servers when you leave the screen, and if the App is closed unexpectedly it expires within minutes and is removed by an hourly clean-up. While the screen is open, other people who have it open too and whose device detects your code see your name, photo, career and level in their nearby-people list. Bluetooth is not used at any other time
- Invitation Matching Data: To credit the person who invited you, the App looks once after installation for an invitation code — on iPhone it reads the clipboard one time and keeps only text in the BeMatrx invitation-code format (nothing else from the clipboard is kept or sent); on Android it reads the store's install-referrer information
3.3. Information from Third Parties
If you sign in with Apple ID or Google Account, we may receive basic account information such as email address and name from those providers.
4. How We Use Your Data
We use the collected data for the following purposes:
- Creating and managing your account
- Providing the App's core features (character creation, messaging, social interactions)
- Matching users with each other (followers, messaging, city-based interactions)
- Sending push notifications (messages, interactions, alerts)
- Detecting and resolving technical issues
- Improving the App and developing new features
- Preventing fraud, spam, harassment, and other abuse
- Fulfilling our legal obligations
- Responding to your support requests
- Enforcing our Terms of Service
- Operating BeLocal — showing listings, delivering help requests, and publishing references
- Protecting private conversations, including notifying participants of screenshots and screen recordings in Whisper
- Automatically checking the photos and videos you upload for sexual content before they are published
5. Data Sharing and Third Parties
We do not share your personal data with third parties except in the following cases:
5.1. Service Providers
BeMatrx uses the following third-party services:
- Database, authentication and file storage (USA/EU): Your account, your content, and the real-time connection the App uses
- App build and delivery (USA): Building the App, distributing its updates, and delivering push notifications. The text of a notification passes through this provider and through Apple's and Google's notification channels; if you turn off message previews in Settings, the sender's name and the message text are left out
- Error reporting (USA): Technical details when the App crashes or hits an error, so that we can fix it
- App stores and platform services (USA): Distribution on iOS and Android, store payments where applicable, Apple's and Google's push channels, and signing in with an Apple ID or a Google Account if you choose to
- AI image services (USA) — PAI: Generating your AI profile photo (your name and career are used in the instructions given to the image service), checking that a photo you upload contains a clear human face, and reading the ticket or venue-proof photo you attach to a Moment in order to make a share image from it (Alchemy). When you check in at a venue with Alchemy, the profile avatars of other users who checked in at the same venue within the last two hours may be sent along as references, so that they can appear as other patrons in your image — and your own profile avatar may likewise be used for theirs. Only the generated avatar is used, never the photo a person originally uploaded. Private accounts can appear only in the images of people who follow them; accounts in Ghost Mode, and blocked or suspended accounts, never appear. If the first provider fails to produce an image, the selfie you uploaded is sent to a second image-editing service so that your career avatar can still be created. Before a photo or video you share is published (a Moment, a Flash, or the selfie you upload for your avatar), it is sent to this service to be checked for sexual content; for a long video, still frames taken from it are sent instead of the file itself
- AI text services (USA) — PAI: Writing Bema's replies (the messages you write to Bema, your recent conversation with Bema, a few profile details such as your name, level, career and language and — for the letters Bema writes you — your city, job and in-app finances are sent), writing the short in-app "inner voice" texts (details of your in-app character and activity — such as your name, level, career, city, the venue you are at, and your in-app job and finances — are sent), checking election candidate statements before they are published, and assessing reports (the reported content is sent; for a reported conversation, its most recent messages are sent). Ordinary conversations between users are not sent to these services except through a report
- Places data (USA): Finding venues near you, completing the place names you type, turning a location into a place or city name, and verifying that a venue is a real place. For this, the location you share with the feature (only while the App is open) and the text you type are sent to the provider
- Weather: When you share a Moment in Alchemy by taking a photo on the spot, and you have already granted location permission, your location is rounded to about 1 km and sent through our servers, without your identity, to a weather service. It is used only to find out the current weather and is not stored on our servers. This approximate location is not sent to the AI services; from this feature they receive only weather details such as temperature and precipitation
- Map images (USA): The map pictures shown on Moments, saved items and place pages are downloaded directly from a map provider, which receives the coordinates of the place shown and your device's IP address
- Video and film images (USA): Film posters, and video thumbnails and players shown in the App (such as YouTube videos), are loaded directly from the provider that hosts them; that provider receives your device's IP address and the item you open, and a video player may use its own cookies or similar technologies
- Website measurement (USA): The tag container, web analytics and the advertising conversion count described in the Cookie Policy — all loaded only after you allow it
- Usage analytics (European Union): Usage analytics in the App; usage analytics and session recording on the bematrx.com website, where text you type into input fields is masked while you're typing it. On the website these requests reach the provider through bematrx.com/ingest, an address on our own domain
- E-mail delivery (USA): The e-mails we send you — sign-up confirmation, security alerts, invitations, waiting-list messages, moderation decisions and your founder certificate. The provider receives your e-mail address and the content of the message, and tells us whether it was delivered. If you invite someone by e-mail, the address you enter is sent to the provider in the same way
- SMS delivery: The one-time code we text you to verify your phone number or to recover your account. The provider receives your phone number and the message
- Website hosting (USA): Hosting the bematrx.com website and measuring page loading speed
These service providers process your data only on behalf of BeMatrx and according to our instructions. The exceptions are the map-image and the video and film-image providers: your device connects to them directly, and they handle that connection under their own privacy policies.
5.2. Legal Requirements
We may share your data when required by law, court order, or legitimate requests from authorized legal authorities.
5.3. Other Users
Parts of your profile information (display name, BeMatrx ID, profile photo, character, city, posts) are visible to other users. You can manage these preferences in your account settings. Other information may be visible as well, such as your level, career, follower counts, badges, biography, social links, the city and venue you are in right now, and when you were last active; you can hide your location and online status with Ghost Mode and the other privacy options in Settings.
References you write or receive through BeLocal are public and permanent: they stay visible on the BeLocal profile to any user who can see it.
5.4. Business Transfers
In the event that BeMatrx Labs is sold to, merged with, or has its assets transferred to another company, your personal data may be transferred to the relevant third party. In such cases, we will inform you in advance with reasonable notice.
6. Data Retention
We keep your account data only as long as your account is active. When you delete your account, the account is closed immediately and your profile and content stop being visible to other users. If you sign in again within 30 days, the deletion is canceled and your account is restored. Your personal data is then permanently erased within 30 days: the photos and videos you uploaded, your Moments and Flashes, the comments you wrote, and your biography, links, date of birth, phone number and email address. Conversations with other users are an exception: so that the other person’s own correspondence stays intact, the messages you sent and your name remain in that person’s chat, shown as “deleted their account”, until that person deletes the conversation on their side or permanently closes their own account. Outside those conversations, your name does not appear anywhere in the App. Records connected to the account may be retained afterwards for as long as necessary to meet our legal obligations and to support safety, security and abuse prevention — for example moderation records, reports, financial transaction records, and consent records (your acceptance of the Terms and your age declaration). Encrypted technical backups are retained for up to 30 days for disaster-recovery purposes, are not user-accessible during that time, and are then permanently purged.
If a photo or video is blocked by the automatic check described above, the post is never created and the file is removed from the area other users can reach. The frame the check actually looked at is copied to a private area that only we can open, is kept there for up to 90 days so that it can be used if a decision has to be made about the account, and is then deleted automatically; the record of the decision itself remains. If you delete your account, that copy is deleted together with your other photos and videos.
Anonymized log and error data — which does not identify you personally — may be retained for up to 30 days for security, fraud prevention, and abuse mitigation purposes.
Some data may be retained longer where required by law (for example, tax records, legal hold orders, or regulatory compliance).
7. Your Rights Under Applicable Laws
Depending on where you live, you may have certain rights regarding your personal data under applicable privacy laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Children's Online Privacy Protection Act (COPPA), and the Turkish Personal Data Protection Law No. 6698 (KVKK).
7.1. Under GDPR (European Union / EEA)
- Right to Information: Learn which data is being processed
- Right of Access: Obtain a copy of your data
- Right to Rectification: Have incorrect or incomplete data corrected
- Right to Erasure ("Right to be Forgotten"): Request deletion of your data
- Right to Restrict Processing: Request restriction of certain processing activities
- Right to Data Portability: Receive your data in a machine-readable format
- Right to Object: Object to certain data processing
- Automated Decision-Making: Right not to be subject to solely automated profiling
7.2. Under CCPA (California, USA)
- Right to Know: Know what personal information is collected, used, shared, or sold
- Right to Delete: Request deletion of personal information collected from you
- Right to Opt-Out: Opt-out of the sale of personal information (BeMatrx does not sell personal data)
- Right to Non-Discrimination: Receive equal service and price even when you exercise your privacy rights
7.3. Under COPPA (USA, children under 13)
BeMatrx is intended only for people aged 17 and over, and we do not knowingly collect personal information from anyone under 17. Where COPPA applies, we also meet its requirements for children under 13. If a parent or guardian discovers their child under 13 has created an account, they may contact us at privacy@bematrx.com to review, delete, or stop further collection of their child's information. We comply with applicable child protection laws including GDPR (EU, children under 16), COPPA (USA, children under 13), and KVKK (Türkiye, minor consent provisions).
7.4. Under KVKK (Türkiye)
- Right to Information: Learn whether your personal data is being processed
- Right of Access: Request information about the processing of your data
- Right to Rectification: Have incomplete or inaccurate data corrected
- Right to Erasure: Request deletion or destruction of your data
- Right to Object: Object to results arising from automated processing
- Right to Compensation: Claim damages for unlawful processing
To exercise any of these rights, email us at privacy@bematrx.com. We commit to responding to your requests within 30 days.
Delete Your Account: You can delete your account directly within the App via "Settings > Danger Zone > Delete Account".
8. Data Security
We take the following measures to protect your data:
- Passwords are encrypted using bcrypt algorithm
- All data transmission is encrypted using HTTPS/TLS
- Database access is protected by Row Level Security (RLS)
- Regular security audits and updates are performed
- If a data incident affects your personal information, we investigate promptly and notify affected users and the relevant authorities when required by applicable law
No system is 100% secure; however, we follow industry best practices.
9. International Data Transfers
Your personal data may be transferred outside of Türkiye. Our service providers process data in the United States or the European Union; the usage-analytics provider's servers are located in the European Union. These transfers are made to countries with adequate protection or secured with standard contractual clauses.
10. Children's Privacy
BeMatrx is intended for users aged 17 and over. We do not knowingly collect personal information from anyone under 17. If you believe a user under 17 has provided us with personal information, please contact privacy@bematrx.com and we will take appropriate action, including account removal where applicable.
For details on how we protect minors, prevent grooming, and handle reports of child sexual abuse material (CSAM), see our Child Safety Standards.
11. Cookies and Tracking Technologies
The BeMatrx mobile app does not itself use traditional cookies (the player of a video provider shown inside the App may use its own). However, we use the following technologies:
- Device Identifiers: For session management and security
- Push Tokens: Identifiers provided by Apple/Google to send notifications
- Local Storage: To store session information and preferences on your device
12. Advertising
Currently, no third-party advertising is shown in BeMatrx. If we introduce advertising in the future, this Privacy Policy will be updated and the relevant advertising providers (such as AdMob, Unity Ads) will be listed here.
13. In-App Purchases
Currently, there are no in-app purchases in BeMatrx. If added in the future, payment processing will be managed by Apple App Store and Google Play; BeMatrx will not have access to your credit card information.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When significant changes occur, we will notify you through the App or via your registered email address. If you do not accept the updated policy, you may close your account.
The last update date is shown at the top of this page.
15. Contact Us
If you have questions or concerns about our Privacy Policy, please contact us:
Email: privacy@bematrx.com
Address: Antalya, Türkiye
Web: bematrx.com
16. Supervisory Authority
If you believe that your data protection rights have been violated, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction:
Türkiye (KVKK)
If you reside in Türkiye, you may file complaints regarding your data with the Personal Data Protection Authority (KVKK):
Web: www.kvkk.gov.tr
European Union / EEA (GDPR)
If you reside in the European Union or EEA (including Iceland, Liechtenstein, and Norway), you have the right to lodge a complaint with your national Data Protection Authority (DPA). You can find the contact details of all EU DPAs here:
European Data Protection Board: edpb.europa.eu/about-edpb/about-edpb/members_en
Alternatively, you may contact the European Data Protection Supervisor (EDPS):
Web: www.edps.europa.eu
United States — California (CCPA)
If you are a California resident, you may file a complaint with:
California Attorney General: oag.ca.gov/privacy/ccpa
California Privacy Protection Agency (CPPA): cppa.ca.gov
Other Jurisdictions
If you reside outside these jurisdictions, you may contact your local data protection or consumer protection authority.
This Privacy Policy is governed by the laws of the Republic of Türkiye. In the event of any conflict between different language versions of this document, the English version shall prevail.