This is our public record of compliance with the HumanTerms Pledge — eleven commitments about how software should treat the people who use it. Each one below says what the commitment is, what we do about it, and how you can check we are doing it rather than take our word for it. Every check below is something you can run yourself.
Deeta's founder is a founding individual signatory of the Pledge, and Deeta LLC has signed it as a company. The eleven commitments are reproduced in full below, so nothing on this page depends on you following that link.
Who we know, the details we record about them, and our personal data are ours to keep, port, share, or delete. None of it is sold or used against us.
How we comply
Your contacts, deets, tags, groups and self-profile live in an encrypted database on your device, and in your phone's own backup (commitment 2). We hold no server-side copy of them. The user content we keep on a server is what you deliberately share: the share itself, encrypted under a key we never hold so we cannot read it, and the preview card that lets the link show your first name, photo, set name and, if you choose, a few details (when you share one of your contacts instead, the card shows that contact's first name alongside yours), which anyone holding the link can see until the share expires 24 hours later or you revoke it (a copy already loaded can stay in caches for up to a day after that). When someone accepts a share you sent, we keep a record of the two accounts and the time for 12 months. It is how their name reaches your "Who has your profile" list, and how they can still turn on live updates for it later. And if someone joins Deeta through your share link, their account records that it was yours. Both are deleted if either of you deletes your account. Some things pass through our servers without being kept — a question you ask the AI, the text of a note being structured, a live update you send — and commitment 5 sets out exactly what happens to AI content, including the single narrow case where something is retained.
Take it with you at any time. Settings → Privacy → Export My Data writes an open bundle — export.json plus contacts.csv and deets.csv — that you can read, keep, or load into something else. No email request, no waiting period.
Delete means delete. Settings → Account → Delete My Account runs a hard-delete cascade on the server side, not a hidden "deactivated" flag, and offers to wipe the local database too. Consent records are the one exception: they are kept as proof of consent, with your account detached, and the privacy policy names it.
Every company that touches anything, named: Supabase (your login and account record), RevenueCat (your subscription state), TelemetryDeck (analytics, not linked to your account), Firebase Crashlytics (crash diagnostics, no account identifier), Twilio SendGrid (the handful of emails our systems send), whichever AI provider answers, and Brave for web search. Apple too, in five roles: merchant of record for purchases, the iCloud backup and Keychain your own Apple account holds (commitment 2), and — because these are iOS features rather than ours — delivering live updates as push notifications, the words you speak if you use Siri or dictation, and your coarse position when iOS turns it into a place name for a "near me" question. Cloudflare serves share links, the pages our sign-in emails open, and the app's feature settings. And if — and only if — a research study opens and you opt in, pseudonymous usage patterns reach named academic researchers under a signed agreement. None of them holds your contact graph.
We have no data-broker relationships. We do not sell or share your information with anyone, ever. There is no advertising model here to fund.
How to verify
Put a network monitor in front of the app — Proxyman, Charles, or Little Snitch — and use it normally on first launch. Nothing carrying your contacts leaves. Then run the export and open the JSON: it is your data, in a format nothing about Deeta is needed to read. Then delete the account, confirm the emailed link, and try to sign back in with your email and password: the account is gone. Signing in with Apple or Google after that starts a new, empty account.
02
Local by default.
Compliant
What we store about ourselves and the people in our lives stays on our devices unless we explicitly choose otherwise.
How we comply
The app is local-first: an encrypted SQLite database on your phone is the real store, not a cache in front of a server. Search, browsing, editing, tags, groups and reminders all work with no connection at all.
Deeta has no cloud sync of its own, and Deeta's servers don't hold a copy of your records. So that nothing is lost when you change phones, the encrypted database is included in your iPhone's own iCloud or computer backup, and its key is kept in your iCloud Keychain. Both belong to your Apple account, and Deeta can't read or delete them. When device-to-device sync ships it will be off by default and end-to-end encrypted, and this page will say so on the day it lands.
Here is everything that leaves your device — the whole list, grouped by what causes it.
Whenever you use the app: a request for the app's feature settings; a subscription check with RevenueCat; product analytics and crash diagnostics, neither tied to you, each with its own switch; and, while you are signed in, the sign-in traffic for your account, your account identifier to RevenueCat so it can confirm your plan, a push address so live updates can reach you, and a small per-day record that your account opened the app, which commitment 4 describes in full.
Only when you use the feature: a question you ask the AI, when it needs the cloud to answer; a share you deliberately send, its preview card, and later updates to it while Keep updated is on; when you accept a share, your name and email, sealed so only the person who sent it can read them; the text of a note you are saving, when your phone cannot structure it locally; and two things iOS sends to Apple on your behalf rather than to us — the words you speak if you use Siri or dictation, and your already-coarse position when iOS turns it into a place name for a "near me" question.
Only if you opt in: pseudonymous research events, if a study opens, you are at a research-eligible university, and you accept the consent prompt. Never names, contacts or content; shared only with named academic researchers under signed agreements; withdrawable at any time.
Sharing is never automatic. See commitment 3.
How to verify
Turn on airplane mode after signing in. Everything except cloud AI answers, sharing and live updates carries on working, and on a phone that runs Private Mode the assistant keeps answering too — that is what "local-first" has to mean to be worth claiming. Leave the network monitor running for a normal session and see how quiet it is.
03
Sharing is an act, not a setting.
Compliant
Every share is explicit, scoped, and revocable. We never auto-forward, never re-broadcast, never turn a single share into a license to keep distributing.
How we comply
Every share is an action you take, with a confirmation step. There is no auto-sharing setting, no background social loop, and no behaviour that broadcasts anything by default.
Shares are scoped to a set of details, not to your whole profile. Five sets ship with the app — Contact Info, Family, Professional, Dating and Custom — and you can build as many more as you like. You choose which set a given person gets.
One link, one claim (patent pending). A share link is redeemable once by default, so forwarding it does not quietly create a second live subscription to your details.
Revocation is in the app, not in an email to us. Settings → Sharing → Shared links lists every open share link you have sent and revokes any of them.
If someone re-shares a profile they received, what travels is a static snapshot. There is no live link back to you, and your later edits do not flow to a person you never shared with.
Live updates follow a share you chose to send. When you share a set, Keep updated is on by default, so later edits to those details, and details you add to or remove from the set, reach the people you shared with. Each edit is sealed on your phone before it leaves. Deeta's servers and Apple's push service carry it but can't read it, though they do see your name, when the update was sent, and its delivery metadata — account and link identifiers, a version number, and whether it was an edit or a removal — never the detail itself. You can stop it at any time from Settings → Sharing → Shared links → Who has your profile, or for a whole set from Settings → Sharing → Deet Sets, and anyone receiving updates can stop or mute them from Settings → Sharing → Live updates.
How to verify
Share a profile to a second account on another device, then forward that same link to a third device and try to import it — Deeta will not import it a second time. Then send a new link, revoke it from Settings → Sharing → Shared links before anyone opens it, and watch it stop working.
04
Use is not surveillance.
Compliant
Aggregate data about the product is ours. Individual data about you is yours.
What we collect
Feature usage through TelemetryDeck — which screens and features get used, and context like which plan you are on, under a random identifier that changes every time the app starts. TelemetryDeck's software adds your device model, OS version, screen size and orientation, language, region, time zone, light or dark mode and accessibility settings, and simple counts like how many days you have used Deeta. Your account identifier is not attached, so these events are not linked to you. Its switch is Settings → About → Send usage analytics, on by default.
Crash diagnostics through Firebase Crashlytics — device model, OS version, and a crash-triage identifier. No Deeta account identifier, so again not linked to you. Its switch is Settings → About → Send crash reports, on by default outside the EU, EEA, UK and Switzerland and off by default inside them. If Allow Apps to Request to Track is off in iOS Settings, both switches are off and cannot be turned on.
Service events from our servers — a question answered, a share created — each under a new random identifier, not linked to you.
Referral and live-update records, tied to your account. If you share, we note when you signed up, when you first shared, and whether you joined through someone else's link. Each live-update connection keeps a dated log of when it started, paused or stopped.
Usage counters for billing, tied to your account — how many AI questions and tokens you have used this period, how many of those questions came through Siri, how many notes and voice memos you have turned into deets, and when you last asked. Never the question, never the answer.
A per-day activity record on our own servers, which is tied to your account. TelemetryDeck and Crashlytics are anonymous by design, which means they cannot count people — we cannot tell from them how many humans use Deeta or whether anyone came back. So while you are signed in we record, on our own backend, that your account opened Deeta on a given day, how many times, and roughly how many minutes in total, with a rough size band for how many deets and contacts you keep ("25–49", never the exact number), a daily count of your AI questions, and a daily count of your live-update connections. That is the entire record: no screens, no actions, no content, nothing about who your contacts are. The raw rows are locked so nobody can query them per person — only day-level totals across everyone reach a dashboard — and they are kept for up to 24 months and deleted when you delete your account.
The analytics switches do not cover those per-day records, and that is deliberate rather than an oversight. Turning both switches off stops the two anonymous SDKs; the day records keep going. We have kept it that way because it is the only thing that tells us whether anyone uses Deeta at all — it is a count, not a record of what you did — and because making it optional would make it useless for the one question it answers. What it is bounded by instead: it runs only while you are signed in, it holds no content of any kind, and it is deleted when you delete your account. You are entitled to weigh that for yourself, which is why it is written here rather than left out.
What we do not do
No advertising SDKs of any kind. No Meta SDK, no AdMob, no AppLovin, no attribution beyond what Apple does for every app on the store.
No behavioural profile of you as an individual, and no per-user experiments.
No selling, sharing or syndicating behavioural data. There is nobody we would sell it to, because that is not the business.
How to verify
In the app, Settings → About has both switches. Turn them off with a network monitor running and watch the TelemetryDeck and Crashlytics traffic stop. Using the app still sends the activity heartbeat described above, which we only ever see as totals across everyone.
05
Memory is not material.
Compliant
What you note about another person — a child's name, an allergy, a coffee order — is a memory. Not training data. Not an ad signal. Not a behavioral input.
How we comply
No provider trains on your data. Every AI provider we route to is used under commercial or enterprise terms that prohibit training on the content we send.
What leaves, leaves as written. When a question goes to the cloud, your question and the full records of the contacts it is about go to your AI provider — names, phone numbers, emails, addresses and deets. A broad question about your contacts ("who likes sushi?"), or a question about one of your contacts that Deeta can't match to a name ("what does my dentist like?"), sends every contact, up to the model's limit. A question can also carry some of your own details and any AI preferences you have set, and a "near me" question carries the nearest city. All of it is answered and immediately discarded on our side, under terms that forbid the provider training on it. On the Power plan, a question too large for the model Deeta uses with your provider goes to Anthropic's Claude Sonnet 5 instead; turning off Query Routing Optimization keeps every question with your chosen provider.
Nothing is kept on our side. No prompt and no response is stored on Deeta's infrastructure. There is exactly one exception and it is opt-in per use: if Deeta ever blocks a question as off-topic and you tap to tell us that looks wrong, that one question's text goes to a review queue so we can fix the filter. It is stored without any link to your account, the raw text is redacted 90 days after review, and anything never reviewed is deleted after 180 days.
Turning notes into deets is a different path, and we will not blur the two. When your phone can, the parsing happens entirely on the device. When it cannot, or when on-device parsing fails and is retried, the text you are saving is sent — as written, with the name of the contact it is for — to Google's Gemini, with Anthropic's Claude as the fallback, and is then discarded. That text is sent as written, because the text itself is the thing being structured. It is protected its own way: an instruction to extract only and never infer or diagnose, EU-based servers for people in the EU, EEA, UK and Switzerland, nothing retained, and your review of every field before anything is saved. In Private Mode your notes stay on the phone; a digital business card's page is the one thing that can still be sent to be read.
We do not aggregate your contacts, your deets or your relationships into any dataset that is sold, shared, or used against your interest.
How to verify
The strongest check is Private Mode: turn it on on a phone that can run it, ask about a named contact with a network monitor running, and no AI provider is involved at all. Section 4 of the privacy policy documents every path in detail, and the plain-English version says the same thing without the legal register.
06
Our devices are ours.
Compliant
The microphone, camera, location, clipboard, and other capabilities of your device are off by default. Access requires explicit permission, a visible indicator, and a clear benefit to you.
What we ask for, and when
Contacts — asked once, when you choose to bring your address book in. Decline it and the app works; you add people yourself.
Microphone and speech recognition — only when you tap to talk. Speech is transcribed on your iPhone and the audio never leaves it. iOS shows its own recording indicator throughout.
Location — only while you are using the app, only when a question needs it ("what's near me"), and deliberately coarse, never a precise pin. Used to fetch an answer and then discarded, never stored.
Notifications — for reminders and live updates, asked when you turn them on.
Clipboard — to pick up a Deeta share link you copied before installing: read once on first launch, only if it holds a web address, and again when you open "Have a share link?". iOS shows its own paste notice when it happens.
Your age range from Apple — during sign-up on iOS 26, so we can check you are old enough without asking for your birthday.
What we never ask for
Deeta does not request your camera, your photo library, your calendar, or HealthKit. Not "asks and you can decline" — the app ships without the permission strings for them, so iOS could not grant them to us if you wanted it to. If a future feature needs one, it arrives with the release that needs it and this page changes first.
How to verify
Decline every prompt at first launch and use the app anyway — only the specific features that need what you declined are affected. Then open iOS Settings → Privacy & Security and walk the categories: Contacts, Microphone, Speech Recognition and Location list Deeta with a switch you control, and Camera, Photos, Calendar and Health do not list us at all.
07
Software serves the relationship.
Compliant
The product is designed to be useful, not to maximize the time you spend inside it.
How we comply
Our primary success metric is paid subscription revenue — not daily active users, not session length, not engagement. That choice is what makes the rest of this list survivable when growth is slow.
No infinite scroll, no autoplay, no stories, no streaks. Nothing in the product is designed to be hard to put down.
Notifications are utility only: birthday reminders, dates you asked to be reminded about, updates from people who share live with you, and, only if you turn them on, a weekly digest, a monthly backup reminder, a gift idea before a birthday, and a weekly suggestion to add a detail about someone. Each is individually switchable, and live updates can be muted per person.
Cancelling is one screen, with no retention gauntlet and no offer designed to wear you down.
How to verify
This one is checked by using the product. Look for the patterns that would be there if we were optimising for time-in-app: an endless feed, a streak, a "people are active near you" nudge, a cancellation flow that argues with you. They are not there. We do watch usage numbers to catch quality regressions; they are not what we are trying to grow.
08
AI is our agent, not yours.
Compliant
The AI inside Deeta works for you. It is not summarized back to us, not profiled, not monetized.
How we comply
Questions and answers are transient on our infrastructure — we do not store them, with the single opt-in exception described in commitment 5.
We do not generate summaries, profiles or behavioural insight from your AI use and feed them back into product or marketing systems. There is no pipeline that could; the content is gone before anything downstream could read it.
Your question goes to the provider that answers it — the one you chose, with the exceptions set out in commitment 5 — under terms that forbid training on it.
Monitoring at the proxy uses metadata only — latency, error rates, which model — never content.
How to verify
Use the assistant for a while, then export your data from Settings → Privacy → Export My Data. The copy of what our servers hold includes your AI question counts and nothing you asked or were told, because none of it is stored with your account.
09
We choose the model.
Compliant
You can choose which AI provider sees your data, or use none at all.
How we comply
Settings → AI Provider, on every plan including free. Your primary can be Anthropic (Claude), OpenAI, Google (Gemini) or xAI (Grok) — in the EU, EEA, UK and Switzerland, Google or Anthropic, both on Google's EU infrastructure — or, on an iPhone that can run it, Private Mode, which is not a provider at all. You also pick a backup for when the first one is having a bad day.
The backup slot can be set to None, which means exactly what it says and nothing more: no failover. If your provider is down, the question fails rather than being quietly sent somewhere you did not choose. It is a discipline setting, not an off switch — we would rather be precise about that than let it read as more than it is.
Private Mode is the off switch, and on an iPhone that can run it, it is the default. The reasoning runs on the device itself — Apple's on-device model, or on the Power plan Google's Gemma model downloaded to your phone — and no AI provider receives your contacts. When you ask about something public, a web search can go out; one that contains a contact's name, a phone number or an email address is blocked. On a device that cannot run it, Private Mode is hidden rather than shown greyed out (the downloadable model's row stays, marked as needing a newer iPhone), and the out-of-the-box cloud setting is OpenAI with Google as backup (Google with Anthropic in the EU, EEA, UK and Switzerland).
The product works without AI. The assistant is one tab. Your records, search, sharing, reminders, tags and the two-way sync with your phone's contacts do not depend on it or on any provider being reachable — so on an older iPhone, where Private Mode is not available, simply not using that tab costs you nothing else.
We have no hard dependency on any single provider, and no revenue relationship that would make us prefer one for you.
How to verify
Open Settings → AI Provider on a free account and switch the primary between the providers offered in your region — no plan gates it. Set the backup to None and confirm a provider outage fails rather than silently rerouting. On an iPhone that can run it, select Private Mode, put a network monitor in front of the app and ask something about a contact: no AI provider is contacted. On any iPhone, ignore the AI tab entirely for a week and check that nothing else in the app degrades.
10
No action without authorization.
Compliant
The AI doesn't send messages, share details, schedule events, or take any action in your life without your explicit authorization or a standing rule you have set.
How we comply
The assistant answers questions. It cannot send a message, post anything, share a profile, book a table, spend money, or contact anyone on your behalf. Those capabilities are not gated behind a setting — they do not exist in the product.
Anything Deeta would add to your records is proposed to you first. When Deeta turns a note, a voice memo or someone's digital card into structured details, you see every field and confirm it before it is saved. The rule is propose, never write.
Deeta does not act while you are not looking. There is no background process that decides something on your behalf. Live updates from people who share with you follow the setting you choose for each of them — Always, Ask or Mute — except that when they delete a detail or take it back, it comes off your copy straight away.
If we ever add anything that acts rather than answers, it will require either your authorization for that specific action or a standing rule you set yourself — and it will be described here before it ships, not after.
How to verify
Try to make it act. Ask it to text someone, to email an introduction, to share a profile for you, to add a calendar invitation. It will tell you what it can do instead, because there is nothing behind those requests to call.
11
Show your work.
Compliant
Our data practices, algorithmic decisions, and AI architecture are documented in plain English, verifiable against actual practice, and updated when things change.
How we comply
This page exists, at the /humanterms path every signatory uses, and it is updated when a practice changes — not annually, and not when it gets embarrassing.
There are two privacy policies and they say the same thing: the legal one, and the plain-English one organised around these eleven commitments. If you ever find them disagreeing, that is a bug and we want to hear about it.
Marketing is checked against this page, not the other way round. If a claim on our home page is stronger than what is written here, the marketing is wrong and gets corrected.
How to verify
You are reading it. If you find a gap between this page and what the product does, email humanterms@deeta.app. That is not a formality: a gap someone else finds first is worse for us than one we fix.
Specific disclosures
Three things worth naming directly.
Some of what we do, and some of what we plan to do, sits close enough to the edge of a commitment that it deserves saying out loud rather than being left for someone to discover.
Opt-in data licensing with a revenue share
Not built
At some future point we may offer a way to opt in to sharing aggregate preference data with specific partners — dining preferences with restaurant groups, say. If we ever do, the deal is: your data is yours, and if you choose to license it, you share in what it earns.
What it would have to be
Off by default. Always.
Granular, per category and per partner.
Described in plain English — what is shared, and with whom.
Revocable, with future data excluded from that moment.
A direct revenue share to the people taking part.
What we will never do
Share or sell your data without an explicit opt-in.
Bury that opt-in in a terms-of-service update.
Use one blanket "agree" toggle for every category.
Share anything that can identify you individually.
Make taking part a condition of using the product.
This feature does not exist today. Nothing has been licensed, and nobody has been approached. If it is ever built it gets its own page here first.
Aggregate geography, for deciding where to grow
Policy in force
We hold aggregate counts of where Deeta is used — how many people in a city or a country — and we use them to decide which markets to work on, and to show prospective partners that there is demand in their area. This is product performance data of the kind every consumer app holds about itself.
What we do
Hold counts by city, region and country.
Reference those counts in conversations with prospective partners.
Apply a minimum threshold of 50 — we never quote a number below it.
Use it internally to choose where to expand.
What we do not do
Hand geographic datasets to anyone.
Quote counts under 50, where small numbers stop being anonymous.
Break the counts down by demographics or behaviour.
Share individual identities, locations or activity. Ever.
Performance analytics for businesses with a profile
Roadmap
Further out, businesses with a Deeta profile — a restaurant, a hotel, a service provider — would get analytics about their own profile, the way a business gets insights about its own listing elsewhere. These describe how the product performed for the business, never who used it.
What a business would receive
How often the assistant referenced their profile.
How many people have saved it.
Aggregate reach and update activity.
All of it subject to the same minimum of 50.
What they would never receive
Individual identities, contacts or activity.
What anyone asked, or when, or from where.
Demographic or behavioural segmentation.
Any count small enough to identify a person.
Standing commitments
Four rules we hold ourselves to.
These are not part of the Pledge. They are ours, and they are the operating rules that make the eleven above hold up over time.
Thirty days' notice before anything weakens. If a change would make any commitment on this page less true, we say so here and in the app thirty days before it takes effect — not in the release notes afterwards.
Anyone can report a gap. If our marketing, this page, or our policies claim something the product does not do, tell us at humanterms@deeta.app and we will answer. There is no bounty and no payment — it is an open channel, and we would rather hear it from you than read it somewhere else.
Marketing matches implementation. Claims about privacy and AI are checked against this page before they are published. When they disagree, the marketing changes.
Reviewed quarterly, externally from year two. We walk every claim on this page against the shipping product each quarter. An external review starts in year two, when the revenue supports it — we would rather commit to that honestly than promise an audit we cannot yet pay for.
This page describes Deeta's public commitments to the people who use it. It is not a contract or a warranty. Where a commitment here conflicts with applicable law or a legal obligation binding on us, the law controls, and we will disclose that conflict here. Questions about the Pledge itself go to humanterms.org; questions about how we are keeping it go to humanterms@deeta.app.