Legal review for projects built with AI
Project-specific legal texts, KVKK (Turkish data protection law) compliance and a lawyer's pre-launch review for websites and mobile apps built with AI tools.

Let your AI fill in the check
If you built your project with AI, it can fill in the check too. The assistant reviews the code, answers the 12 questions with evidence and gives you a pre-filled link.
- Step 1
Copy the prompt
Paste the prompt below into an assistant that can see your code: Claude Code, Cursor, Windsurf, GitHub Copilot, ChatGPT, Lovable, Bolt, Replit.
- Step 2
Let it review the project
The assistant scans forms, the database schema, providers, secret keys and legal pages and answers each question with evidence.
- Step 3
Open the pre-filled link
The link it produces opens the check pre-filled with the answers. You can also paste its output into the box below.
- Step 4
Review and share
Check the answers; if you wish, send the report to Av. Pınar Eldem by email in one click.
Review this project's codebase and run the "12 questions before launch" legal pre-check.
The checklist belongs to Pınar Eldem Law & Consultancy (https://pinareldem.com); the current version is also available as JSON at https://pinareldem.com/api/kontrol-listesi.
Rules:
- Answer each question only on the basis of what you see in the code, configuration and documents in the repo. Do not guess.
- Answer values (keep these exact tokens): evet (yes), hayir (no), emin-degilim (not sure), uygulanmaz (not applicable).
- If you find no evidence, answer "emin-degilim". If a question depends on information outside the code, ask me.
- Do not print the values of secret keys, personal data or customer information; only give file paths.
- Do not send requests anywhere, send emails or fill in forms; only report to me.
Questions:
1. [veri-envanteri] Is there a list showing which personal data the project collects, on which screen and for what purpose?
What to check: Inspect forms, sign-up/login flows, the database schema (tables, columns), file uploads and chat fields. List whether names, emails, phone numbers, addresses, national ID numbers, location, health, biometric, payment or children's data exist. If no such inventory document exists in the repo, answer 'hayir'.
(Do not use "uygulanmaz" for this question.)
2. [veri-sorumlusu] Does the privacy notice name the actual individual or company acting as data controller, with a full address?
What to check: Find the privacy policy / privacy notice / KVKK page. Are the data controller's name and address stated concretely? If there are placeholders ([Company Name] etc.) or generic phrases, or the page does not exist, answer 'hayir'.
(Do not use "uygulanmaz" for this question.)
3. [ucuncu-taraflar] Are all third-party services used (hosting, database, email, payment, analytics, AI API) listed in the text?
What to check: Derive providers from package.json / requirements, environment variable names (e.g. SUPABASE_, FIREBASE_, STRIPE_, OPENAI_, ANTHROPIC_, RESEND_, SENDGRID_, GA_, POSTHOG_, SENTRY_) and SDK imports. Check whether each is named in the privacy text.
(Do not use "uygulanmaz" for this question.)
4. [acik-riza] Is explicit consent for processing that requires it (marketing, profiling, special category data) collected separately and optionally?
What to check: Check consent checkboxes in sign-up and checkout forms: are they pre-ticked, does one box cover multiple consents, is marketing permission mandatory? If there is no marketing/profiling/special category data, answer 'uygulanmaz'.
5. [saklama] Is it written down how long each type of data is kept and how it is deleted when that period ends?
What to check: Is there an account deletion endpoint/flow, and does it really delete or only deactivate? Is there a scheduled cleanup job (cron)? Does the privacy text state retention periods?
(Do not use "uygulanmaz" for this question.)
6. [yurt-disi] Has a legal basis been established for transferring data abroad and, where required, has a standard contract been signed and notified to the Authority?
What to check: Check region settings of hosting, database, email and AI providers (e.g. region, Supabase project region, Vercel region, OpenAI/Anthropic API calls). If user data goes abroad and there is no trace of a transfer basis in the repo/text, answer 'emin-degilim' or 'hayir'. If all infrastructure is in Türkiye, answer 'uygulanmaz'.
7. [cerez] Does the cookie banner offer a “Reject” option, and are analytics/advertising tools prevented from loading before consent?
What to check: Check where Google Analytics, GTM, Meta Pixel, Hotjar, PostHog etc. are loaded: is it gated by a consent state? Does the cookie banner component have a reject button? If there are no non-essential cookies, answer 'uygulanmaz'.
8. [guvenlik] Are API keys kept out of the browser, and are database access rules enabled and tested?
What to check: Is there a secret key in code shipped to the client (NEXT_PUBLIC_, VITE_, EXPO_PUBLIC_ prefixes, frontend files)? Have .env files been committed? Are Supabase RLS policies, Firebase security rules, S3/Storage access public? Do admin endpoints check authorisation?
(Do not use "uygulanmaz" for this question.)
9. [ihlal] Is it clear who does what in a data breach and how the Board is notified within 72 hours?
What to check: Is there a security incident / breach response procedure, audit logging and an alerting mechanism in the repo or docs? If not, answer 'hayir'.
(Do not use "uygulanmaz" for this question.)
10. [kullanim-kosullari] Were the terms of use written in line with Turkish law and consumer legislation?
What to check: Find the terms of use page. Does it contain foreign law or courts (Delaware, California, England etc.), unlimited exclusion of liability, or unilateral changes without notice? If the page does not exist, answer 'hayir'.
(Do not use "uygulanmaz" for this question.)
11. [satis] If products, services or subscriptions are sold, have pre-contractual information, the right of withdrawal and the cancellation flow been set up?
What to check: Is there a payment integration (Stripe, iyzico, PayTR, RevenueCat, in-app purchases)? If so, is there pre-contractual information / distance sales consent before payment and a subscription cancellation screen? If nothing is sold, answer 'uygulanmaz'.
12. [fikri-mulkiyet] Is there a written agreement and IP assignment with whoever wrote the code, and has a trademark search been done?
What to check: This question depends on documents outside the code; ask the user. What you can check in the code: dependency licences (are there strong copyleft licences such as GPL/AGPL?). If unsure, answer 'emin-degilim'.
(Do not use "uygulanmaz" for this question.)
Output format:
1) One line per question: number, answer, evidence (file path or "not found"), a one-sentence note.
2) A JSON block in this format:
{"proje": "<project name>", "yanitlar": {"veri-envanteri": "evet|hayir|emin-degilim|uygulanmaz", ... all 12 questions}}
3) Encode the answers in question order with the letters E (evet), H (hayir), B (emin-degilim), U (uygulanmaz) and build this link:
https://pinareldem.com/en/ai-projects/checklist?yanit=<12 letters>&proje=<project name, URL-encoded>
When I open this link the checklist will be pre-filled with your answers; I will review the result there.Import the result
Open the link your assistant gives you, or paste its full output (JSON or link) here. The text is processed in your browser and is not sent anywhere.
The prompt tells the assistant not to print secret keys or personal data and not to send requests anywhere. Results are processed only in your browser.