Privacy Policy
Our design principle is simple: your data lives on your device. Your contacts and the details you keep about people are not stored on our servers, and the narrow paths that do leave your device are described plainly below.
If you would rather read this without the legal register, the same policy is written in ordinary language at Privacy in plain English. Our public record of how all of this checks out against the product is at HumanTerms compliance.
1. Introduction and scope
Deeta is made by Deeta LLC ("Deeta," "we," "us"). Deeta is a private, on-device app for keeping rich, structured information about the people in your life.
This policy explains what information the Deeta app handles, where it lives, when it leaves your device, and the choices and rights you have. It covers the Deeta iOS app, including the web pages the app relies on: share links, and the pages that open from Deeta's sign-in emails. Our waitlists are covered separately by our Website Privacy Notice, wherever you join one — including the Android waitlist form that appears on a share page — as is the rest of the deeta.app marketing website. The effective date of the current version is shown at the top of this policy (see Section 13).
2. What we collect and where it lives
On your device. Your contacts, deets (the notes and structured details you keep about people), tags, groups, your own self-profile, and your AI preferences are stored on your iPhone, in an encrypted database. They are not stored on our servers. That database is included in your iPhone's own iCloud or computer backup (see Section 12), and when you edit a contact's core details, Deeta writes the change back to your iPhone's Contacts.
Account data. Your email address; how you sign in (email and password, Sign in with Apple, or Google); your multi-factor-authentication secret and hashed recovery codes, if you enable MFA; and a flag recording that you passed the age check. We also keep a profile record: your plan, the region of your App Store purchases, and, if you joined Deeta through someone's share link, which account's link brought you in. If you share, we also record when you signed up, when you first shared, and whether you joined through someone else's link.
Identity verification. If you verify your identity, we record only which methods you completed and when, never the underlying documents. Email verification records only that your email was confirmed. Deeta does not offer phone or government-ID verification. If you verify an academic affiliation, we keep your institutional email address and name for that purpose.
Transactional email. Emails our systems send (sign-up confirmation, password reset, account-deletion confirmation, and an affiliation-verification code) are delivered by Twilio SendGrid, which receives the recipient address and that message's content.
Subscription data. If you subscribe, we store your subscription state: a RevenueCat subscriber ID, the billing platform, your plan, renewal dates and billing events. We do not receive or store your card details.
Usage analytics. We use TelemetryDeck for product analytics: which features and screens are used, and context like your plan. Each app launch uses a new random identifier, so these events are not linked to your account and contain no names, contacts or content. TelemetryDeck's software also attaches your device model, OS version, screen size and orientation, language, region, time zone, light or dark mode and accessibility settings, and simple counts such as the date you started using Deeta and how many days you have used it. You can turn this off at Settings → About → Send usage analytics; it is on by default. Separately, our servers report a few service events, such as an AI question answered (with the plan, provider, model and size) or a share created, claimed or revoked. Each of these carries a new random identifier and nothing that identifies you or your device, so the in-app switch does not apply to them.
Account activity (first-party). Because the analytics above cannot count unique people, we separately record on our own servers, while you are signed in, that your account opened Deeta on a given day, how many times, and the approximate total time the app was in the foreground. With it we record coarse size bands for how many deets and contacts you keep (for example "25–49"), worked out on your iPhone, so the exact numbers never leave it. We also keep a daily count of your AI questions and a daily count of your live-update connections. These records are linked to your account and are declared as Product Interaction in our App Store privacy label. They contain no screen names, actions, content, or anything about who your contacts are. The underlying rows are not readable per user, only day-level aggregates are used, they are kept for up to 24 months, and they are hard-deleted when you delete your account. The analytics and crash-report switches do not govern these records.
Crash reports. We use Firebase Crashlytics to diagnose crashes. Crash reports carry standard device diagnostics (such as model, OS version, and a device identifier used for crash triage) but no Deeta account identifier, so they are not linked to your account. They are used only to fix bugs. You control them at Settings → About → Send crash reports: on by default outside the EU, EEA, UK and Switzerland, and off by default inside them or where your region is unknown. If you have turned off "Allow Apps to Request to Track" in iOS Settings, both usage analytics and crash reports stay off.
Push notifications. While you are signed in, your iPhone gives Deeta an Apple push address (a device token) so that live updates can reach you. We store it with your account, whether or not you have allowed notifications. It is removed when Apple reports it is no longer valid, or once the device has not been seen for 90 days, for example after you sign out.
Device keys. For each device you sign in on, we store a public key, kept for future end-to-end encrypted sync. The matching private key never leaves your iPhone, and nothing uses the public key today.
Feature settings. The app downloads its feature settings from deeta.app, which is served by Cloudflare. Cloudflare sees these requests, including your IP address, and keeps standard request logs for a few days.
3. Sharing and live updates
How a share works. You share a set of details, not your whole profile. Your iPhone encrypts the share with AES-256-GCM under a random key that exists only in the link itself. Our servers hold the encrypted copy and cannot read it. A share link expires after 24 hours, can be claimed (imported) once, and can be revoked at Settings → Sharing → Shared links.
The link preview card. So that a link shows a preview when you send it, your iPhone makes a card image showing your first name and profile photo, the name of the set (unless you turn that off for the set), and, only if you choose, up to four details from the set. When you share someone else's contact, the card shows their first name, plus your first name and photo. The card is stored on our servers at an unlisted address that anyone holding the link can open, and it is deleted when the share expires, when you revoke it, or when you delete your account. A copy that has already been loaded can stay in browser and app caches for up to a day after that. Anyone holding the link can also see a few facts about the share without its key, such as how many details it contains, whether it includes a birthday or a photo, and the type of set.
Contact cards on the web. A Contact Info share also carries a standard contact card, so someone who does not have Deeta can save your contact from the share page. The page uses the key in the link to open it, so anyone holding the full link can save that contact card until the share expires.
Revoking. Revoking stops a link that has not been claimed and deletes its card. It does not remove a copy someone has already imported.
Claims and receipts. When someone imports your share, we record who claimed it and when, and keep that record for 12 months. When you accept someone's share, your name and account email are sent to that person so they can see who imported their details. Sharing this is required; there is no anonymous accept. It is sealed under a key derived from the share that our servers never hold, so Deeta cannot read it. It waits on our servers until their app collects it, for up to 12 months. If you re-share a profile you received, it travels as a static snapshot with no live link back to the original sender.
Live updates. When you share your own details, "Keep updated" is on by default. While it is on, later edits, additions and removals to the shared details are sealed on your iPhone, under a key tied to that share, and delivered through our servers and Apple Push Notification service to each person you shared with. Deeta and Apple cannot read the details. They do see your name, which appears in the recipient's notification ("[name] updated contact info — tap to see"; the notification never says what changed), when the update was sent, and the delivery metadata: account and link identifiers, a version number, and whether it was an edit or a removal. We store who receives whose updates, each recipient's Always, Ask or Mute choice, and a history of those subscriptions starting and ending. We never store the details themselves.
Live updates do not expire. They continue until they are stopped:
- If you shared: choose "Stop updating" for a person, and their copy stays with them, frozen. Choose "Take back", and it is removed from their device as it connects. Or revoke the share.
- If you receive updates: choose Always, Ask or Mute, or "Stop receiving", at Settings → Sharing → Live updates. A muted update arrives silently, with no notification.
A live-update record is deleted 31 days after the updates end.
4. AI questions and third-party processing
Transient by default — nothing is kept. When one of your AI questions needs the cloud, Deeta sends it through our Supabase Edge Function proxy to an AI provider, returns the answer, and immediately discards both the question and the answer. There is no server-side storage of your AI content, with one narrow, opt-in exception. If an AI question is blocked as off-topic and you tap "This doesn't seem right?", that single question's text is written to a founder-only review queue so we can improve the filter. That path is consented per tap, locked down so only we can read it, stored without any link to your account, and time-limited: the raw text is redacted 90 days after review, and entries never reviewed are deleted after 180 days. For accounting, we keep usage counters tied to your account: questions and tokens used in each billing period, how many of those questions came through Siri, how many notes and voice memos you have turned into deets, when you last asked, and short-lived rate-limit counters. None of them contains any part of your question.
Where a question is answered. Many questions never reach AI at all. A question like "What's Sarah's number?" is answered by Deeta directly from your records, on your iPhone. The rest are answered by an AI model, either on your iPhone (Private Mode, below) or by the cloud AI provider you choose.
You choose the AI provider. On every plan, you choose which AI provider handles your questions at Settings → AI Provider. The full set of possible AI recipients is Anthropic (Claude), OpenAI, Google (Gemini) and xAI (Grok), and each processes your question under its own data-processing terms.
- The default. On a device where an on-device model is ready when you first use the app, the default is Private Mode. Otherwise it is OpenAI, with Google as backup.
- In the EU, EEA, UK and Switzerland (see below for how that is decided), the choice is Google or Anthropic, and the default is Google, with Anthropic as backup. There, both run on Google Vertex AI's EU infrastructure.
- The backup. You can set the backup to None, and then a provider outage fails the question instead of sending it elsewhere.
There are two exceptions to your choice:
- Query Routing Optimization (on by default; Settings → AI → Query Routing Optimization). With it on, if an on-device model is available, a question whose context is small enough may be answered on your iPhone first, before your chosen provider. And on the Power plan, a question whose context is too large for the model Deeta uses with your chosen provider is answered by Anthropic's Claude Sonnet 5 (in the EU, EEA, UK and Switzerland, running on Google Vertex AI's EU infrastructure). Turning it off confines questions to your chosen provider.
- A one-time offer. If you use Private Mode, it cannot answer a question, and you are online, Deeta offers to send that one question to the cloud provider you last chose. Nothing is sent unless you tap.
What a cloud question contains. When a question goes to a cloud provider, Deeta sends the question as you typed it and the full records of the contacts relevant to it: names, phone numbers, email addresses, postal addresses, birthdays, organizations, tags and deets. A broad question, or one naming someone Deeta cannot match, sends as much of your address book as fits the model's context. If you have allowed it, your AI preference notes are included too. Every provider we route to is used under commercial API terms that prohibit training on your content, and the exchange is transient on our side: answered and immediately discarded, with nothing stored on our infrastructure.
Private Mode. In Private Mode, AI reasoning over your data happens on your iPhone and no AI provider receives your contacts. It runs on Apple's on-device Foundation Models (iOS 26 or later, with Apple Intelligence turned on) or, on the Power plan, on Google's Gemma model, which you download to your iPhone from Hugging Face. Where one of these is available, it also answers automatically when you are offline. Three things can still leave your device:
- A web search. On Plus and higher plans, a question that needs public information can send a web search, written on your iPhone. A search containing one of your contacts' names, a phone number, an email address, or a sensitive topic such as health or religion is blocked and not sent. Other details from your question can remain.
- A usage counter update that contains nothing from your question.
- The one-time offer above, if you tap it.
Questions about public events near your contacts ("who do I know near the wildfires?") need a web search and a cloud model, so Private Mode does not answer them.
Users in the EU, EEA, UK and Switzerland. Deeta treats you as being in the EU, EEA, UK or Switzerland if your App Store purchases are registered there. Without a purchase, it also does so if your App Store account is there or you are connecting from there. For you:
- cloud questions and note structuring go to EU-based AI infrastructure, and only to providers with verified EU regional processing and storage;
- a web search that would carry special-category information (such as health or religion) is blocked from leaving your device, both when your provider answers and in Private Mode.
Turning notes into deets. When you turn spoken notes or text into structured deets, the parsing runs on your iPhone when an on-device model is available. It goes to the cloud in two cases, unless you use Private Mode: when your device cannot parse it locally, or when on-device parsing fails or takes too long, in which case it is retried once. The cloud service is Google's Gemini, with Anthropic's Claude as a fallback (in the EU, EEA, UK and Switzerland, both on Google Vertex AI's EU infrastructure; your provider choice does not apply to this step). It receives the raw text and the name of the contact it is for, and discards both immediately; nothing is stored. The text is sent as written, because the text itself is what is being structured. It is protected in other ways:
- the AI is instructed to extract only, never infer or diagnose;
- you review and confirm every field before anything is saved;
- nothing is retained.
In Private Mode, notes are parsed only on your iPhone. If that is not possible right now, Deeta says so rather than sending them. The one exception is the text of a digital business card page (see Section 11).
Questions that aren't about your contacts. If you ask something Deeta cannot answer from your own records, a general question, it is answered rather than refused, by your chosen provider. If the question turns out to be partly about the people you know, Deeta treats it as a question about your contacts instead.
For a genuine general question, no contact, deet about anyone else, tag or group travels with it. What can travel is a small amount about you: the details you have saved on your own record and marked "always share", so the answer fits you. Anything you marked never or ask is never sent. A detail that mentions one of your saved contacts is dropped before sending. A location question carries your approximate locality (see below). In Private Mode the question is answered on your iPhone. When you are offline nothing is sent.
Web search (Brave). Web search uses the Brave Search API, always called through Deeta's proxy, and is available on Plus and higher plans. Brave never receives your account identifier. What a search contains depends on the path:
- When your cloud provider answers: your question as typed (up to 200 characters) and your approximate locality, which can include names and details from your question.
- In Private Mode: the search written on your iPhone, screened as described above.
- For a question about events near your contacts: the question, today's date and your approximate locality, with names, phone numbers and email addresses blocked.
Location. On any plan, a "near me" question asks for location permission (only while using the app, at reduced accuracy). Your iPhone snaps the position to roughly 5 km, and iOS's own geocoder sends those coarse coordinates to Apple to turn them into a place name. Only that place name is sent onward, to your AI provider or to Brave. No precise position reaches Deeta, and location is never stored.
Voice. Speech you dictate in the app is transcribed on your iPhone. If you use Siri or Apple dictation, Apple processes the spoken text.
The assistant does not act. It answers questions; it cannot send messages, share your details or take any action on your behalf, and anything that would write to your records is proposed for you to confirm first.
5. Subscription billing
Subscriptions are purchased through the Apple App Store, and Apple is the merchant of record. RevenueCat receives your purchase and subscription state so Deeta can unlock your plan. The app checks your plan with RevenueCat each time it opens, whether or not you subscribe, and once you are signed in RevenueCat receives your account identifier. We do not receive or store your card details.
6. Research participation
Research participation is not open. If a study opens, this is how it will work:
- Who is asked. Only users at research-eligible academic institutions are offered it, and only half of eligible users are ever shown the consent prompt (a 50/50 split). The other half never see it, and no data about them is shared.
- What is captured. If you opt in, we capture pseudonymous usage patterns, with IDs derived by a one-way HMAC (see Section 10 for how these are destroyed on deletion). The event types are self-profile changes, sharing actions, contact imports, and AI-question events. No names, contacts, messages, or personal details are captured.
- Who receives it. Data is shared only with named academic researchers bound by signed Data Use Agreements, and not until an Institutional Review Board has approved the study.
- Withdrawing. You can withdraw at any time in Settings → Privacy → Research Participation, and your past data is excluded from future exports.
7. Children's privacy (COPPA)
Deeta has a region-based minimum age, matching Section 1 of our Terms of Service. You must be at least 13 in the United States, or at least 16 everywhere else: the EU digital-consent age under GDPR Art. 8, which we apply worldwide outside the U.S. Where your region is unclear, the higher floor applies.
During sign-up we check your age:
- where available, with Apple's age range signal from your Apple Account;
- otherwise, by asking for your date of birth.
Anyone below the floor for their region is blocked. Your date of birth is used only for that check and is not stored; our servers receive only a record that you passed.
We do not knowingly collect personal information from anyone below the applicable minimum age. If you believe someone below it has provided us information, contact privacy@deeta.app and we will delete it.
8. Your GDPR rights
If you are in the EU/EEA/UK, you have the rights to access, rectify, delete, port, restrict processing, and object. Most of these are built directly into the app:
- Access and portability (Articles 15 and 20): Settings → Privacy → Export My Data produces an on-device JSON + CSV bundle plus a copy of the data our servers hold about your account.
- Erasure (Article 17): Settings → Account → Delete My Account runs a hard-delete server cascade, confirmed through a link we email you, and offers to erase Deeta from your iPhone too.
- Rectification: you edit your own data at any time in the app.
For requests that arrive outside the app, write to privacy@deeta.app; we verify your identity and respond within 30 days.
9. Your CCPA rights
If you are a California resident, you have the rights to know, delete, and opt out of the sale or sharing of your personal information (we do not sell or share your data), and the right to non-discrimination for exercising them. These are satisfied by the same in-app Export My Data and Delete My Account tools, applied uniformly to all US users.
10. Data retention
- On your device: kept as long as the app is installed. You can remove it with Delete My Account (which offers to erase your iPhone's copy) and export it any time. Copies in your own device backups are covered in Section 12.
- Account, profile, subscription and verification records, push addresses, device keys, and usage and activity records: hard-deleted, not merely hidden, when you delete your account. Activity records are kept for up to 24 months before then. A push address from a device you have signed out of is removed once that device has not been seen for 90 days.
- Share links: encrypted payloads we cannot read, and their preview cards, are deleted when the share expires after 24 hours or when you revoke it.
- Claims and receipts: kept for 12 months.
- Live updates: records are deleted 31 days after the updates end; pending refresh requests after 7 days.
- Off-topic reports: as set out in Section 4.
- Consent records: your research and sensitive-data consent choices are kept as evidence of consent. When you delete your account, they stay without your account attached.
- Research events: identified by pseudonymous, HMAC-derived IDs tied to a per-user salt held on our servers. While that salt exists, the events are treated as personal data. When you delete your account, the salt and your mapping are permanently destroyed, so the remaining events can no longer be traced back to you by anyone, including us.
- AI content: never retained, except the opt-in off-topic report in Section 4.
- Backups of our systems: your data is removed from active systems immediately on erasure, and ages out of encrypted backups within our retention window (target: 30 days or less).
11. Saving links & notes ("Saved to Deeta")
- Capture surfaces. You can save content to a contact or to your own profile from the iOS Share Sheet, inside iMessage, or via Siri and Shortcuts. What you save is stored on your iPhone as an encrypted deet; our servers are not sent it. In iMessage, Deeta keeps a private, hashed map linking a conversation to a contact so captures land in the right place. That map is stored on your iPhone and is not sent to our servers.
- Clipboard. In iMessage, Deeta detects whether your clipboard holds a link without reading it, and reads it only when you tap "Save link from clipboard". In the app, the clipboard is read without a tap in two cases: on first launch before you sign in, if it holds a link, so a Deeta share link you copied can be picked up; and when you open "Have a share link?". iOS shows its "Pasted from…" banner whenever the clipboard is read.
- Link previews. When you share a link to Deeta, your iPhone (not our servers) fetches a preview from the destination site. The preview is not stored. The request uses iOS's standard user agent, which can identify the app making it.
- Siri and Shortcuts. When you ask Siri or Shortcuts to save something to a contact, Deeta matches the name against your contacts on your iPhone.
- Digital business cards (e.g., Blinq, HiHello, Popl). When you save a link to someone's digital business card, your iPhone fetches and parses the card into proposed deets, at your explicit request, and you review every field before anything is saved. The link is saved as a detail on the contact. If the card cannot be parsed on your iPhone, the text of the card page and the contact's name are sent to the note-structuring service described in Section 4, including in Private Mode. This reads the card owner's published contact details only to let you save a contact you were handed, the same as reading the card and typing it in. There is no server-side scraping, crawling, bulk collection, or access to login-walled content, and the saved copy is a one-time snapshot, not a live link.
12. Your device's own backups
So that your data survives a new phone, Deeta's encrypted database is included in your iPhone's own iCloud or computer backup. Its encryption key is kept in your iCloud Keychain, along with the keys for share links and live updates you have sent or received and the names of contacts you have shared. These belong to you, in your Apple Account: Deeta cannot read, list, or delete them. When you delete your account and choose to erase Deeta from your iPhone, the database and its key are removed from your iPhone and your iCloud Keychain. Backups you made earlier remain in your Apple Account until you delete them.
13. Changes to this policy
If we make material changes, we'll notify you with an in-app banner and by email, with a 30-day window. The effective date at the top of this policy always reflects the current version.
14. Contact
Questions about privacy? Email privacy@deeta.app.
Deeta LLC · 300 East Bay Dr PMB 17127543, Largo, FL 33770, USA.
15. Do Not Track and third-party tracking
The Deeta app does not track you across other companies' apps or websites. It contains no advertising software and does not ask for Apple's tracking permission. Because Deeta does no cross-site tracking, it does not respond differently to "Do Not Track" (DNT) signals: there is no cross-site tracking to turn off. The deeta.app marketing website is covered by our Website Privacy Notice.