Privacy Policy

Last updated 21 September 2026

Dekstr is a growth analytics service. It reads the analytics, advertising, payment and marketplace accounts you connect, turns them into findings and a weekly brief, and — only for content you approve — publishes posts to your Instagram account. This policy explains what we collect, why, who processes it, and how to have it deleted.

Who we are

Dekstr is operated by the sole proprietorship registered as ÖMER ÖGEDAY İNAN (tax office: Urla), address: İskele Mahallesi, 2018/8 Sk. No: 8, Urla/İzmir, Türkiye. We are the data controller for the personal data described in this policy. For anything about your data, write to privacy@dekstr.co.

What we collect

Visiting dekstr.co: the site loads no analytics, no advertising pixels and no tracking cookies. If you switch the language, a single preference cookie (gos_locale) remembers your choice; your theme and language choice are also kept in your browser's local storage and are not sent to us. Like any website, our hosting provider processes technical data such as your IP address to deliver the pages.

Waitlist: your email address, the site language you used, which sign-up form you used (for example the landing page or a blog post) and the time you signed up. After signing up you may optionally tell us your monthly ad spend band; if you do, we store that band. We also send ourselves an email notification of each new sign-up.

Call booking: after joining the waitlist you can book a call with us through Cal.com. That booking page is run by Cal.com; the details you enter there (such as your name and email) reach us as a booking and are handled under Cal.com's own privacy policy as well.

Account: Dekstr's product (app.dekstr.co) is currently open only to invited users. When you sign in with Google we receive your name, email address and Google account identifier, and store them to identify you and the workspaces you belong to. A sign-in cookie keeps you signed in for up to 30 days.

Connected sources: data from the accounts you explicitly connect. Google Analytics 4, Search Console and Google Ads are described in the next section. For payment and marketplace accounts (Stripe, iyzico, PayTR, Shopify, Trendyol, n11) you enter an API key; Dekstr reads payments, orders and refunds and keeps only daily totals per currency (order count, gross and net amounts, refunds and, where the source allows, the number of new customers). It does not store buyers' names, addresses or card details. Dekstr does not write to these accounts.

What you create in Dekstr: your company and audience description, content briefs and facts you type, generated drafts, captions, images and short videos, your approvals (who approved which post and when), and for published posts their link, platform identifier and statistics.

Google user data

Dekstr's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

Google sign-in (openid, email, profile): your name, email address and Google account identifier, used only to sign you in and identify your account.

Google Analytics 4 (analytics.readonly): daily sessions, engaged sessions and key events by channel. Used to show where your traffic comes from, to reconcile paid traffic with what happened on your site, and to attribute visits to the posts Dekstr published for you.

Google Search Console (webmasters.readonly): search queries, the pages they lead to, and daily clicks, impressions and average position. Used to compare organic demand with what you pay for.

Google Ads (adwords): the list of ad accounts you can access, and per campaign its name, status, type, currency and daily cost, impressions, clicks and conversions. Google offers no read-only scope for Ads; Dekstr uses this access only to read reports. It never creates, edits, pauses or deletes campaigns, budgets or ads.

How it is used: only to provide the features you see in Dekstr — your dashboard, findings, audience panel and weekly brief. To write the weekly brief and the audience panel, Dekstr sends summaries derived from this data (for example weekly session, click, cost and conversion totals, campaign names and top search queries) to Anthropic's Claude model, which writes the text you read. Content-generation requests to Anthropic contain only the brief and facts you type, not your Google data.

What we do not do: we do not sell Google user data; we do not use or transfer it for advertising, including retargeting or personalized ads; we do not use it to determine creditworthiness or for lending; and we do not use it to develop, improve or train generalized AI or machine-learning models. We transfer it to others only as needed to provide or improve the features described here, for security, to comply with the law, or as part of a merger or acquisition.

Human access: no person at Dekstr reads your Google user data unless you give us permission for specific data (for example when you ask for support), it is necessary for security purposes such as investigating abuse, it is required by law, or the data has been aggregated and anonymized for internal operations.

Revoking access: disconnect Google on the Connect page in Dekstr — this deletes the Google tokens we hold and stops all further reads. To also remove the permission on Google's side, visit https://myaccount.google.com/permissions.

Instagram publishing and statistics

Dekstr can publish posts to an Instagram professional account you give it access to. Every post is a separate row per account, and it goes out only after a person approved that exact row. Nothing unapproved is published, an approval can be withdrawn while the post is still waiting, and a post that misses its scheduled time is flagged as late instead of being published late.

After publishing, Dekstr reads the statistics of the posts it published — reach, views, likes, comment count, shares, saves and total interactions — to show you how they performed. It reads counts only, not the text of comments or your direct messages.

Publishing credentials are kept only on the publishing server operated by Dekstr, never in the application database. To publish, Instagram must fetch each image or video from a public web address, so the media for approved posts is stored on that server at an address that is not listed anywhere but can be opened by anyone who has it.

Posts for LinkedIn and Facebook are not published by Dekstr: a person posts them manually.

AI-generated content

When you ask Dekstr to draft content, the brief and facts you type are sent to Anthropic (Claude), which writes the post text. Images and short videos can be generated by Higgsfield from a visual description derived from your brief. Rendering the final images and videos runs on a server operated by Dekstr. Generated content is a draft until you approve it.

How it is stored

Access tokens, refresh tokens and API keys for connected sources are encrypted with AES-256-GCM before they are written to the database, and are never returned by Dekstr's interface, not even masked. Application data lives in a managed database hosted in the European Union (AWS, Ireland), and the website and application run on Vercel.

Who processes it for us

We do not sell your data and do not share it with advertisers. These providers process data on our behalf, each only for its function: Vercel (hosting of the website and application, USA); Turso (database, AWS eu-west-1, Ireland); Google (sign-in and the Google services you connect); Anthropic (text generation for briefs, audience panels and content drafts, USA); Resend (sending the weekly brief and service emails); Higgsfield (image and video generation); Meta (Instagram publishing and post statistics); Cal.com (call booking); Telegram (notifications to the Dekstr team, for example when an approved post must be shared manually, including its caption); a server operated by Dekstr (rendering and publishing). LinkedIn receives nothing from Dekstr today; LinkedIn posts are shared manually.

The payment and marketplace services you connect (Stripe, iyzico, PayTR, Shopify, Trendyol, n11) are sources we read from on your instruction; we send them nothing beyond the API requests needed to read your data.

Keeping and deleting your data

Disconnecting a source on the Connect page deletes the credentials we hold for it and stops all further reads. Data already imported from that source stays in your workspace until you ask us to delete it.

Account, workspace and connected-source data are kept while your workspace is in use. Waitlist entries are kept until you ask us to remove them. Write to privacy@dekstr.co and we will delete your waitlist entry, account or workspace data, including stored credentials. Posts already published to Instagram stay on Instagram until you delete them there.

KVKK (Turkey)

Under the Turkish Personal Data Protection Law No. 6698 (KVKK), the data controller is ÖMER ÖGEDAY İNAN, trading as Dekstr, İskele Mahallesi, 2018/8 Sk. No: 8, Urla/İzmir, Türkiye.

Purposes and legal bases: we process your data to run the waitlist and get in touch with you, to create and secure your account, to provide the service you use (reading connected sources, analysis, the weekly brief, content generation and approved publishing), and to keep the service secure. The legal bases are that processing is necessary for setting up or performing our contract with you (KVKK Art. 5(2)(c)), for our legitimate interests provided your fundamental rights are not harmed, such as security and answering your requests (Art. 5(2)(f)), and for complying with our legal obligations (Art. 5(2)(ç)).

Collection method: electronically, through the forms on dekstr.co, Google sign-in, the accounts and API keys you connect, and what you enter in the product.

Transfers abroad: to provide the service, personal data is transferred to the providers listed above that are located outside Türkiye — in particular Vercel and Anthropic in the United States, and our database provider in Ireland (EU).

Your rights under KVKK Article 11: to learn whether your personal data is processed; to request information if it is; to learn the purpose of processing and whether it is used accordingly; to know the third parties in Türkiye or abroad to whom it is transferred; to request correction if it is incomplete or inaccurate; to request its deletion or destruction under Article 7; to request that correction or deletion be notified to the third parties it was transferred to; to object to a result against you that arises solely from automated analysis; and to claim compensation if you suffer damage from unlawful processing.

How to apply: send your request to privacy@dekstr.co from the email address you used with Dekstr, or in writing to the address above. Tell us who you are and what you are asking for. We answer free of charge within the time limit set by KVKK Article 13.

Your rights under the GDPR (EU and EEA users)

If you are in the European Union or the European Economic Area, you have the right to access your personal data, have it corrected, have it erased, restrict its processing, receive it in a portable format, object to processing based on our legitimate interests, and withdraw any consent you gave at any time. We rely on the same grounds described above: performance of a contract (GDPR Art. 6(1)(b)), legitimate interests (Art. 6(1)(f)) and legal obligations (Art. 6(1)(c)).

To use these rights, write to privacy@dekstr.co. You also have the right to lodge a complaint with the data protection authority in the country where you live or work.

Changes to this policy

When what Dekstr does with your data changes, we update this page and the date at the top.