Privacy Notice
This notice explains what data is processed when you use yokla, why, how long it is kept and who it is shared with.
Last updated: 25 July 2026
1. Data controller
yokla (yokla.dev) is run as an individual project by Yusuf Erkan Darıyemez, who is the data controller. Use the contact links in the footer for any request.
2. Data processed
You do not have to create an account to use yokla; you can take an interview as a guest. What is processed depends on how you use it:
- Session — a random session cookie in your browser. Only its sha256 hash is stored server-side, never the value itself.
- Account (only if you sign in) — the e-mail address, display name and provider account id supplied by Google/GitHub. yokla never sees your password.
- Interview data — which questions you were served, your answers, whether they were correct, time spent per question, scores and topic statistics.
- Account origin — the IP address, browser User-Agent and country code seen when the account (including a guest account) was created. The country comes from the CDN that carries the request; no GeoIP database and no external lookup service is used, and city-level location is never computed or stored. All three are recorded once, at creation, and not updated on later logins. Purpose: investigating abuse and telling accounts apart in the admin screen.
- Usage counters — per-account and per-IP daily counters, used to enforce the daily interview limit.
- Question reports — if you report a question as faulty, the reason you picked and any note you wrote.
Deliberately not collected: machine/device name, MAC address, location, contacts, file access. Some of these cannot technically be read from a browser; none are requested.
3. Purposes
- Building, scoring and reporting your interview.
- Showing you your history, progress and review schedule.
- Benchmarking your score against other candidates who took the same interview. This is aggregate; nobody sees another candidate’s identity.
- Enforcing daily limits and preventing abuse (such as farming unlimited guest accounts).
- Measuring question-bank quality and fixing faulty questions.
Your data is not used for advertising, profiling or resale, and is not shared with third parties for marketing.
4. Retention
- Account origin (IP + User-Agent + country) — 90 days. After that these three fields are cleared automatically; your account and interview history are not deleted.
- Per-IP daily counters — 30 days, then deleted outright.
- Session record — 30 days (the session lifetime).
- Account and interview data — until the account is deleted. This data is the product itself (history, progress, benchmark), so it is kept for as long as you use it.
Expiry is not left to a manual step: deletion is performed by a scheduled task running server-side.
5. Cookies
yokla_session— strictly necessary. Carries your session; httpOnly, 30 days.yokla_theme— preference. Remembers your light/dark choice.yokla_oauth_state— strictly necessary, short-lived. CSRF protection during sign-in.
yokla has NO analytics, advertising or tracking cookies, and runs no third-party tracking script. That is also why there is no cookie consent banner — there is no tracking to consent to.
6. Third parties and international transfers
The providers below are involved only when you use the relevant feature, and only with the data that feature needs. Their servers are outside Türkiye, so the data involved is transferred abroad to that extent.
- Google / GitHub — only if you sign in with that provider: authentication.
- Job-ad matching providers — only if you use "start from a job ad": the ad text you paste is sent to a language-model / embedding provider to infer field and seniority. yokla does NOT store the ad text — it is matched and discarded. Even so, we recommend not pasting personal data (names, phone numbers, e-mail) into it.
- AI coach provider — only if you request an AI coach report: what is sent is your per-topic accuracy and aggregate statistics. Your name, e-mail and question texts are not sent.
- Infrastructure — server hosting, the CDN/proxy that carries traffic, and the cloud storage holding encrypted database backups.
7. What you choose to share
The result share link and the score credential are entirely opt-in. Nothing of yours is public unless you create one. If you do, anyone with the link can see that summary (field, seniority, score, topic breakdown) — question texts and your answers are not shared.
8. Your rights
You have the right to know whether your data is processed and to request information about it, to learn the purpose, to know the third parties it is transferred to, to have inaccurate data corrected, to have it erased, to have such actions notified to those third parties, and to seek compensation for damages.
If you want your account and all interview history deleted, just ask through the contact channels below. Requests are fulfilled to the extent your identity can be verified.
9. Contact
Send questions and data requests through the links in the footer (LinkedIn or yusufdariyemez.com).
When this notice changes, the "last updated" date at the top changes with it.