Privacy Policy
Soranova Privacy Policy
1. Introduction
This Privacy Policy explains how Soranova handles personal data when you use the app, website, and related services. It applies to users aged 18 and over.
2. Data Controller
Seyfi Can Zeyrek, an individual developer operating under the brand name Morrowline Apps (Morrowline Apps is a brand name only and is not a separate registered company), Esenyali Mahallesi 52/75 Sk. Izmir/Türkiye, is the controller for the processing described here. Contact us at sczgamesinfo@gmail.com or +90 555 027 76 81.
3. Scope
This Policy covers the current Android Soranova app and related services at https://soranova.morrowline.app/. If an iOS version is released, this Policy will apply to that version to the extent the same processing practices apply; platform-specific permission or store disclosures for iOS will be updated when that build ships.
4. Data We Collect
| Category | Examples | Purpose | Location | Retention | Shared with |
|---|---|---|---|---|---|
| Anonymous identifiers and technical data | Anonymous Firebase UID, FCM token, app language, app-instance information, App Check attestation | Authentication, cloud operation, notifications, integrity | Device and Firebase/Google services | Cloud records at least 30 days; later retention uncertain; some device preferences until uninstall/data clearing | Google Firebase / Google Cloud; RevenueCat for app-user ID |
| Prompts, parameters, and user media | Text prompts, generation parameters, camera-captured or selected photos/videos, selected audio where used | Generate requested image, video, or music content | Device, Firebase Firestore and Storage | Cloud records at least 30 days; later retention uncertain | Google Firebase / Google Cloud, fal.ai, each.labs |
| Generated content and project data | Generated image, video, and audio assets; asset metadata; titles; lyrics; workspace tags; local paths; Studio project payloads; token-balance records associated with the anonymous identifier | Save, deliver, display, and edit your projects and assets; track generation-related balances | Room database, DataStore, app files, Firestore, Storage | Local project/media duration may be unknown; cloud records at least 30 days and later retention uncertain | Google Firebase / Google Cloud; fal.ai and each.labs for generation-related processing |
| Preferences and local asset metadata | Onboarding state, premium state, notification preference, offer deadline, deleted/reported asset IDs | Remember preferences and app state | Device | Until uninstall/data clearing for identified preferences; other local duration may be unknown | Not shared merely because stored locally |
| Subscription information | Purchase transactions, products, Firebase UID as RevenueCat app-user ID, entitlement status | Purchase, restore, and provide subscription access | Google Play and RevenueCat services | Not established by the inventory | Google Play Billing and RevenueCat |
| Analytics and diagnostics | Analytics events, device/app information, app-instance identifier, crash logs, navigation context | Understand operation and diagnose failures | Firebase/Google services | Not established by the inventory | Google Firebase / Google Cloud |
5. How We Collect Data
We collect data you submit when using generation, editing, or purchase features; automatically through app operation and Firebase services; from Google Play and RevenueCat in connection with purchases; and through Android permissions when you choose to grant them.
6. Why We Use Data
We use data to provide anonymous sign-in, generation, editing, asset storage and delivery, subscription access, purchase restoration, optional completion notifications, security and integrity checks, analytics, and crash diagnosis.
7. Legal Bases
For EEA and UK users, we use:
- contract performance for requested app features, purchases, cloud features linked to the anonymous identifier, and operational completion notifications;
- legitimate interests for security, integrity, service maintenance, and crash diagnosis; and
- consent where required for permissions or communications.
For Turkish users, the relevant grounds include contractual necessity, legitimate interest, and explicit consent where required. See the separate KVKK Aydınlatma Metni for Turkish disclosures.
8. Sensitive Permissions
Camera
We request Android camera permission only when you choose to capture media for a generation feature. Captured media may be stored on your device and uploaded through Firebase services for the requested workflow. You can revoke the permission in Android Settings → Apps → Soranova → Permissions → Camera.
Notifications
If you grant notification permission, we may synchronize an FCM registration token and app language to send optional operational notifications when a generated video or asset is complete. Notifications are not required for basic access and can be disabled in Android settings.
Record Audio
RECORD_AUDIO is declared in the Android manifest. The current app evidence does not show a runtime microphone request or microphone capture, storage, or upload through that permission.
9. Sharing and Processors
We share data only as needed to operate the services described above:
- Google Firebase / Google Cloud: authentication, Firestore, Storage, Functions, Messaging, Analytics, Crashlytics, Remote Config, and App Check.
- RevenueCat: subscription entitlement and customer information using the Firebase UID as app-user ID.
- Google Play Billing: purchase transactions and subscription products.
- fal.ai (fal - Features & Labels, Inc.): AI model inference for generation features. fal’s API Services terms state that fal will not use Client Content to create, train, or develop fal’s products or services, except for models designated as Excluded Models (for example, models marked Pending Enterprise Ready or another designation fal notifies in advance). If a request uses a third-party model via fal, fal states that Client Content is transferred to that third party.
- each.labs (each::labs, Inc.): AI and generation-related processing. each::labs’s privacy policy states that it uses information to deliver Services, improve operations, and conduct research, among other purposes, and does not include an explicit company-wide commitment identical to fal’s “no training” clause. each::labs’s terms also describe licenses needed to provide its Services.
We do not sell your personal information for money. Processors receive personal information to provide services for us, not as a purchase of your data by us. We do not control every independent use those providers make under their own published terms; those terms apply to processing they perform.
10. International Transfers
Firebase/Google processing is confirmed in us-central1. fal.ai, each.labs, RevenueCat, and Google Play Billing may process data where their services operate; each::labs’s privacy policy states that the company and servers are located in the United States and that personal information may be processed in the United States or other countries where it maintains facilities. Other providers’ exact locations are not fully established in the inventory. Where required, we use safeguards available under applicable law for the relevant transfer.
11. Retention
Cloud Firestore and Firebase Storage records are retained for at least 30 days. Retention after that minimum is uncertain; we do not promise that cloud records are deleted at the end of 30 days. Device preferences and local asset metadata may be removed when you uninstall the app or clear app data. Local project, media, cache, and catalog-file retention may vary and is not fully established in the inventory.
12. Your Rights
Depending on your location and applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where processing relies on it. Send requests to sczgamesinfo@gmail.com; we may need information reasonably necessary to verify a request. We aim to respond to verified requests without undue delay and within 30 days, or within the longer period permitted by applicable law when an extension is allowed and we notify you.
EEA and United Kingdom
You may lodge a complaint with the data-protection authority in your habitual residence, place of work, or the place of an alleged infringement. There is no appointed Data Protection Officer in the current service context; use the contact above.
California
California residents may request to know, access, correct, or delete personal information and may exercise any available right to opt out of sale or sharing or to limit the use of sensitive personal information. Categories that may be collected are described in Section 4 and may include identifiers, internet or network activity and app information, user-generated content, commercial/subscription information, and generation parameters you submit. We disclose personal information to the processors listed in Section 9 for the purposes described in this Policy. Based on the current inventory, Soranova does not enable advertising and does not engage in cross-context behavioral advertising. We do not sell personal information for money. Disclosures to service providers that operate Soranova for us are described in Section 9; we do not claim to control every independent practice those providers describe in their own policies. You may use an authorized agent where applicable law permits.
Türkiye
Turkish users have the rights in Article 11 of KVKK. The separate KVKK Aydınlatma Metni provides the Turkish disclosure text.
13. Anonymous Account and Deletion Requests
Soranova uses an anonymous Firebase identifier. There is no in-app account deletion control at this time. To request deletion of identifiable cloud data associated with that anonymous identifier, contact sczgamesinfo@gmail.com. After we verify the request, we will delete or de-identify personal data under our control without undue delay and within 30 days, or within the longer period permitted by applicable law when an extension is allowed and we notify you. We will also take reasonable steps to instruct processors that process data for us, where applicable. Residual copies may remain for a limited time in backups or under a processor’s own retention schedule, consistent with Section 11. Uninstalling removes device-local data and does not enable restoration from the server; it does not itself promise deletion of cloud records.
14. Children
Soranova is for people aged 18 and over. We do not intend to offer the service to children under 18.
15. Security
We use technical and organizational measures intended to protect data appropriate to the service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
16. Automated Processing
Soranova processes prompts, generation parameters, and media through Firebase services and AI providers to generate requested content. Soranova does not operate its own foundation-model training on your Content; generation is performed through the processors described in Section 9, subject to those providers’ published terms (including fal’s training restrictions and exceptions, and each::labs’s stated purposes). Based on the current inventory, Soranova does not make solely automated decisions producing legal effects or similarly significant effects about you.
17. Changes to This Policy
We may update this Policy when our services or legal obligations change. We will post the updated version at https://soranova.morrowline.app/en/privacy/ and update the date above.
18. Contact
For privacy questions or requests, contact Seyfi Can Zeyrek (brand: Morrowline Apps) at sczgamesinfo@gmail.com, +90 555 027 76 81, or Esenyali Mahallesi 52/75 Sk. Izmir/Türkiye. See the Terms of Use for service terms.

