Where your data sits and who can reach it
This page lists only the measures in place today. What we do not offer yet is listed further down; if a measure is not on this page, it does not exist.
YouReply Manage holds the plan of a research project: the brief, phases, tasks, comments and due dates. Raw participant data is not stored here; survey responses stay in YouReply Survey and statistical analysis in YouReply Analyze. The product does not accept file attachments.
Authentication lives in the central YouReply account. YouManage stores no passwords; the session is carried by a signed, short-lived cookie.
Transport and delivery
Every request over HTTPS
The website and the app are served over HTTPS only; HTTP requests are permanently redirected and HSTS is sent to the browser (two years, including subdomains).
Browser protections
Pages cannot be framed by other sites, content type sniffing is disabled, and a Content Security Policy is applied on the website.
Cookies and tracking
No non-essential script loads on the website before consent, and even the map embed stays off until you allow it. You can withdraw your choice at any time.
Identity and sessions
One sign-in, central account
Sign-in happens through the central YouReply account. There is no separate password in YouManage, and you move between products with the same session.
Session cookie
The session cookie is httpOnly and Secure, sent with SameSite=Lax, signed on the server and expires after seven days.
Sign-out applies everywhere
When you sign out of the central account the YouManage session is invalidated too. Deleted or inactive accounts cannot sign in.
Enterprise single sign-on (beta)
Connecting an enterprise identity provider with SAML 2.0 or OIDC is offered with setup support. Unsigned SAML assertions are rejected and the connection is only made to a domain verified in DNS. The feature is in beta.
Access and roles
Role-based permissions
The workspace has Administrator, Project Manager, Team Member and Viewer roles; a project also has Owner, Contributor and Viewer. A Viewer cannot change anything.
Enforced on the server
Permissions are checked on the server, not in the interface: an action you cannot see cannot be performed with a direct request either.
Change history
Task and project changes are recorded with who and when, and shown in the task detail. Account-level membership, role and plan events are kept in an immutable audit log available to the account administrator.
Support access
For support purposes, authorized YouReply staff can open a session on your behalf through a short-lived, single-use link. This access is used only for a support request or an incident investigation.
Data, backups and deletion
Where the data lives
Project data is kept in a MySQL database on servers managed by YouReply. Transactional e-mails and contact form messages are sent through Amazon Web Services' e-mail service in the European Union (Frankfurt) region.
Backups
Backups are pulled by a separate backup server; the production server has no permission to delete them. The YouManage database is backed up several times during the day, every backup is integrity-checked and a corrupt backup is not kept. Backups are deleted at the end of the retention period.
Archive instead of delete
Projects are archived rather than deleted and can be restored; deleting a comment removes its content. This keeps an accidental deletion from turning into data loss.
Downloading and deleting account data
You can download your account data as JSON from the central YouReply account. An account deletion request has a seven-day undo window; after that the account record is anonymized while invoice records subject to statutory retention are kept. For deletion of project content, write to kvkk@youreply.com.tr.
No artificial intelligence
Calculations in the product follow rules defined in source code. The content you enter is never sent to a language model or a third-party AI service.
Sub-processors
To deliver the service, the providers below may process personal data on our behalf and on our instructions. The list covers the providers actually used by the product.
Hosting infrastructure
- Purpose
- Application servers and database
- Processing location
- Servers managed by YouReply
Amazon Web Services (Amazon SES)
- Purpose
- Transactional e-mail, contact form messages, verification codes
- Processing location
- European Union (Frankfurt)
iyzico
- Purpose
- Card payments
- Processing location
- Türkiye
Paraşüt
- Purpose
- Invoicing
- Processing location
- Türkiye
VatanSMS
- Purpose
- SMS verification codes (central account)
- Processing location
- Türkiye
Google (Analytics)
- Purpose
- Website usage measurement, only if you consent to cookies
- Processing location
- Google infrastructure, including the United States
For a data processing agreement (DPA), write to kvkk@youreply.com.tr. This page is updated when the list changes.
What we do not offer yet
The following do not exist today. Presenting a missing control as present would defeat the purpose of a security page; if you need one of these, tell us and it moves up the roadmap.
- Two-step verification (TOTP or a security key)
- Sign-in with a Google or Microsoft account
- Directory synchronization (SCIM)
- An independent security certification (such as ISO 27001 or SOC 2) or a published penetration test report
- A ready export and automated deletion flow for project content
- A client portal with separate stakeholder access
Reporting a vulnerability
If you believe you have found a vulnerability, write to us directly. We will confirm receipt, verify it and fix it. Please give us a reasonable window to respond before disclosing it publicly.
Need more detail for an assessment?
Get in touch for a vendor assessment, a data processing agreement or an information security questionnaire.