Skip to content
Deeta
  • How it works
  • Privacy
  • Who it’s for
  • Questions
Join the waitlist
  • How it works
  • Privacy
  • Who it’s for
  • Questions
Join the waitlist

Privacy, in plain English

Effective: September 29, 2026  ·  Last updated: September 18, 2026

This is our privacy policy written the way we would explain it to a friend, organised around the eleven HumanTerms commitments we hold ourselves to. The full legal version is the operative document and says exactly the same things in the register lawyers need. If you ever catch the two disagreeing, that is our mistake and we want to hear about it — humanterms@deeta.app.

The short version: your data lives on your phone. Your contacts and the details you keep about people are not stored on our servers, the few things that do leave are listed below by name, and there is no version of our business that involves selling any of it.

Contents

  1. Your data is yours
  2. It stays on your phone
  3. Sharing is something you do
  4. What we measure about the product
  5. What happens when you ask the AI something
  6. What we ask your phone for
  7. How the product is built to behave
  8. Choosing your AI — or none
  9. Getting your data out, and deleting it
  10. Everyone who touches anything
  11. How long anything is kept
  12. Research, children, and California
  13. Changes, and how to reach us

1. Your data is yours

Your contacts, your deets (the details you keep about people), your tags, groups and your own profile are stored on your phone, encrypted. We do not hold a copy on our servers. There is no "Deeta database of everyone's relationships" to breach, subpoena, sell, or change our minds about later — which is a stronger guarantee than any promise we could write here.

You can take it all with you at any time: Settings → Privacy → Export My Data writes an open bundle — one JSON file plus CSVs of your contacts and deets, and a copy of what our servers hold about your account — that is readable without us. And you can end it: Settings → Account → Delete My Account runs a real deletion on our servers, not a hidden "deactivated" flag, and offers to erase Deeta from your phone too. You confirm it from a link we email you; there is no request to support and no waiting period.

2. It stays on your phone

Deeta is local-first. Once you are signed in, the app works with no connection at all — search, browsing, editing, reminders. Deeta runs no cloud sync of its own.

So that nothing is lost when you change phones, Deeta's encrypted database is included in your phone's own iCloud or computer backup, and its key is kept in your iCloud Keychain. Both belong to your Apple account, and we cannot read or delete them. When you edit a contact's core details, Deeta also writes the change back to your phone's Contacts.

Here is everything that leaves your device:

  • A question you ask the AI, when answering it needs the cloud (section 5).
  • A share you deliberately send, its preview card, and later updates to it while "Keep updated" is on (section 3).
  • When you accept a share, your name and email, sealed so only the person who sent it can read them (section 3).
  • The text of a note you are saving, when your phone cannot structure it locally (section 5).
  • Product analytics and crash diagnostics, neither tied to your account, each with its own switch (section 4).
  • The sign-in traffic for your account. While you are signed in, this also includes a small record that your account opened the app that day, and a push address so live updates can reach you (section 4).
  • Things iOS sends to Apple on your behalf, not to us, and only if you use those features: the words you speak when you use Siri or dictation, and your already-coarse position when you ask a "near me" question, which iOS turns into a place name (section 5).
  • A request for the app's feature settings, from deeta.app.
  • A subscription check with RevenueCat when the app opens, which includes your account identifier once you are signed in.
  • Pseudonymous research events, only if a study opens and you opt in (section 12).

Things you save through the Share Sheet, inside iMessage, or with Siri and Shortcuts are stored as encrypted deets on your phone and are not sent to our servers. That includes the private, hashed map that remembers which iMessage conversation belongs to which contact.

  • Link previews: when you save a link, your phone fetches the preview, not us.
  • Clipboard in iMessage: Deeta can tell whether your clipboard holds a link without reading it, and only reads it when you tap "Save link from clipboard".
  • Clipboard in the app: it is read without a tap in two places — on first launch before you sign in, so a Deeta share link you copied can be picked up, and when you open "Have a share link?". iOS shows its own "Pasted from…" banner whenever that happens.

3. Sharing is something you do

Every share is an action you take, with a confirmation. You share a set of details, not your whole profile — five sets ship with the app and you can build more.

What travels is encrypted in a way we cannot read: the key lives only in the link itself, and our servers never hold it. A link expires after 24 hours, can be claimed once, and can be revoked from Settings → Sharing → Shared links. Revoking stops a link nobody has imported yet; it cannot take back a copy someone already imported. If someone re-shares a profile they received, the recipient gets a static snapshot — no live link back to you.

Two things about a link are visible without its key, and you should know them:

  • The preview card. So the link shows a preview in Messages or WhatsApp, your phone makes a card image with your first name, your profile photo, the set's name (you can turn that off) and, only if you choose, up to four details. If you share one of your contacts, the card shows their first name alongside yours. Anyone holding the link can open that card until the share expires or you revoke it, and a copy already loaded can linger in browser and app caches for up to a day after that.
  • A few facts about the share, such as how many details it has, whether it includes a birthday or photo, and what kind of set it is.

A Contact Info share also carries a normal contact card, so someone without Deeta can save you from the web page; anyone holding the full link can save it until the share expires.

Live updates. When you share your own details, "Keep updated" is on by default, so later edits to those details, and details you add to or remove from the set, reach the people you shared with.

  • What we and Apple can see. Each update is sealed on your phone before it leaves, and Deeta's servers and Apple's push service carry it without being able to read it. They do see your name — it is the notification the other person gets, "[name] updated contact info — tap to see", which never says what changed — when the update was sent, and the delivery metadata: account and link identifiers, a version number, and whether it was an edit or a removal.
  • Stopping them. Updates carry on until someone stops them. You can stop updating a person (their copy stays, frozen), take it back (it is removed from their phone as it connects), or revoke the share. Anyone receiving updates can set Always, Ask or Mute, or stop receiving, at Settings → Sharing → Live updates; a muted update arrives with no notification.
  • What we keep. We keep who receives whose updates and a history of when each started and ended, never the details, and delete that record 31 days after the updates end.

One more exchange to know about: when you accept someone's shared profile, your name and account email go to that person, so they can see who imported their details. There is no anonymous accept. It is sealed under a key we never hold, readable only by them.

4. What we measure about the product

Product analytics go through TelemetryDeck — which screens and features get used, and which plan you are on — under a random identifier that changes every time the app starts. TelemetryDeck's software adds your device model, OS version, screen size and orientation, language, region, time zone, light or dark mode and accessibility settings, plus simple counts like how many days you have used Deeta.

Crash diagnostics go through Firebase Crashlytics — device model, OS version, a crash-triage identifier.

Neither carries your Deeta account identifier, so neither is linked to you, and neither is ever used to follow you around other companies' apps or websites. Each has its own switch at Settings → About:

  • Send usage analytics is on by default.
  • Send crash reports is on by default outside the EU, EEA, UK and Switzerland, and off by default inside them.
  • If you have turned off "Allow Apps to Request to Track" in iOS, both stay off.

Our servers also count a few service events, like a question answered or a share created. Each one carries a new random identifier and nothing that points at you.

Some things here are linked to your account, and we are not going to bury them. Because the analytics above are deliberately anonymous, they cannot count people — so they cannot tell us how many humans use Deeta or whether anyone comes back. We measure that on our own servers instead. While you are signed in, the app records that your account opened Deeta on a given day, how many times, and roughly how many minutes in total, plus a rough size band for how many deets and contacts you keep ("25–49", never the exact number). We also keep a daily count of your AI questions and of your live-update connections, and, for billing, how many questions and tokens you have used this period, how many of those questions came through Siri, how many notes and voice memos you have turned into deets, and when you last asked.

That is the whole record — no screens, no actions, no content, nothing about who your contacts are or what you looked at. The raw rows are locked so that nobody can query them per person; only day-level totals across everyone reach a dashboard. They are kept for up to 24 months and deleted when you delete your account.

The analytics switches do not cover those records, deliberately. They are the only thing that tells us whether anyone uses Deeta at all, and an optional count is not a count. What bounds them instead: they run only while you are signed in, they hold no content of any kind, and they are deleted when you delete your account. We would rather set that out than let the switches imply more than they do.

We run no advertising SDKs, build no behavioural profile of you, and run no per-user experiments.

5. What happens when you ask the AI something

Nothing is kept. When a question needs the cloud, it goes through our proxy to an AI provider, the answer comes back, and both are discarded immediately. We have no server-side store of AI content. Plenty of questions never reach an AI at all — "what's Sarah's number?" is answered straight from your records, on your phone.

There is exactly one exception, and it is opt-in every time it happens: if a question is blocked as off-topic and you tap to tell us that looks wrong, that one question's text goes to a small review queue so we can fix the filter. Only we can read it, it is stored without any link to your account, the raw text is redacted 90 days after review, and anything never reviewed is deleted after 180 days.

What goes to the AI provider

When a question goes to the cloud, the question and the full records of the contacts it is about go to your AI provider — names, phone numbers, emails, addresses, birthdays, organizations, tags and deets. A broad question, or one naming someone Deeta cannot match, sends as much of your address book as fits. A question can also carry some of your own details and any AI preferences you have set, and a "near me" question carries your approximate area. Every provider we use is under commercial terms that forbid training on your content, and we keep nothing: the answer comes back and both are discarded on our side.

Two automatic exceptions to "your chosen provider", both controlled by Query Routing Optimization in Settings, which is on by default:

  • A small question can be answered on your phone first, if it can run a model.
  • On the Power plan, a question too big for your provider's model goes to Anthropic's Claude Sonnet 5.

Turn it off and your questions stay with your provider.

Turning notes into deets works differently, and we will not pretend otherwise

When your phone can do it, the parsing happens on the device and the text never leaves.

The raw text is sent — as written, together with the name of the contact it is for — to a third-party AI service in two cases: when your phone cannot parse it locally, or when on-device parsing fails and it is retried once. The service is Google's Gemini, with Anthropic's Claude as the fallback. People in the EU, EEA, UK and Switzerland get both on Google's EU infrastructure.

The text is discarded afterwards, nothing is stored, and you check every field before anything is saved. In Private Mode your notes are only parsed on your phone, and if that is not possible right now Deeta tells you rather than sending them — except the text of a digital business card page, which can still be sent if your phone cannot read the card itself.

Private Mode, and the rest of the cloud path

In Private Mode, the AI runs on your phone. It uses Apple's on-device model (iOS 26 with Apple Intelligence turned on) or, on the Power plan, Google's Gemma model, which you download to your phone from Hugging Face. No AI provider receives your contacts. It also picks up automatically when you have no signal.

What can still leave in Private Mode:

  • A web search for something public, written on your phone. A search containing a contact's name, a phone number, an email address or a sensitive topic like health is blocked; other details from your question can remain.
  • A content-free usage count.
  • One question, if you choose. If Private Mode cannot answer and you are online, Deeta offers to send that one question to the cloud provider you last chose, and nothing goes unless you tap.

Questions about public events near your contacts need the cloud, so Private Mode does not answer them.

People in the EU, EEA, UK and Switzerland — by where your App Store purchases are registered, or, without a purchase, where your App Store account is or where you are connecting from — get extra protection. Cloud questions go to EU-based AI infrastructure. A web search carrying a sensitive subject, like health or religion, is blocked from leaving the phone.

Web search uses the Brave Search API, on Plus and higher plans, always through our proxy, and Brave never gets your account identifier. What Brave receives depends on who is answering:

  • Your cloud provider: Brave gets your question as you typed it, up to 200 characters, with your approximate area — so it can include names or details.
  • Private Mode: Brave gets the screened search described above.
  • An event question: Brave gets the question with names, phone numbers and emails blocked.

If you use Siri or Apple dictation for voice input, Apple processes the spoken text; talking to Deeta inside the app is transcribed on your phone.

6. What we ask your phone for

  • Contacts, if you choose to bring your address book in.
  • Microphone and speech recognition, only when you tap to talk — the audio is transcribed on your phone and never leaves it.
  • Location, only while you are using the app and only for "near me" questions, deliberately coarse rather than a precise pin, used and then discarded.
  • Notifications, for reminders and live updates.
  • Your age range from Apple, during sign-up on iOS 26, so we can check you are old enough without asking for your birthday.

We do not ask for your camera, your photo library, your calendar, or your health data. Not "ask and let you decline" — the app ships without the permission strings, so iOS could not grant them to us if you tried.

7. How the product is built to behave

Our success metric is paid subscriptions, not time spent in the app — which is the decision that makes the rest possible. No infinite scroll, no autoplay, no streaks, no "people near you are active" nudges.

Notifications are birthday reminders, dates you asked to be reminded about, and updates from people who share live with you. Only if you turn them on, they also include a weekly digest, a monthly backup reminder, a gift idea before a birthday, and a weekly suggestion to add a detail about someone. Each can be switched off, and live updates can be muted per person. Cancelling is one screen.

8. Choosing your AI — or none

In Settings → AI Provider, on every plan including free, you choose who answers your questions: Anthropic (Claude), OpenAI, Google (Gemini) or xAI (Grok) — or, on a phone that can run it, Private Mode, which is not a provider at all. You also set a backup for when your first choice is down. Each provider handles your question under its own data-processing terms, and none of them is permitted to train on it.

Out of the box you get Private Mode if your phone can run it. Otherwise you start with OpenAI, with Google as backup. In the EU, EEA, UK and Switzerland, the choice is Google or Anthropic, both running on Google's EU infrastructure, starting with Google.

Two things worth being exact about, because the shorthand version of each would flatter us:

  • The backup slot can be set to None. That means no failover — if your provider is down the question fails instead of being quietly sent somewhere you did not pick. It is not an "AI off" switch, and we are not going to let it read like one.
  • Private Mode is the way to keep your contacts away from every AI provider, and on a phone that can run it, it is what you get by default. On a phone that cannot, the choice is which provider answers — or not using the assistant, which costs you nothing else: it is one tab, and your records, search, sharing, reminders and contact sync do not depend on it.

What the assistant will never do is act. It answers questions — it cannot send a message, share a profile, book anything or spend money on your behalf, and anything that would write to your records is proposed for you to confirm first.

9. Getting your data out, and deleting it

Both of these are buttons in the app, not requests you have to make to us:

  • Export — Settings → Privacy → Export My Data. An on-device JSON and CSV bundle, plus whatever we hold on our servers. This covers the right of access and the right to portability.
  • Delete — Settings → Account → Delete My Account. A hard-delete cascade across our systems. This covers the right to erasure.
  • Correct — you edit your own records whenever you like. That is rectification.

If you are in the EU, EEA or UK you also have the rights to restrict processing and to object; if you are in California you have the rights to know, to delete, to opt out of sale or sharing — we do not sell or share your data — and not to be treated differently for exercising them. We apply the same tools to everyone regardless of where they live. For anything that has to come to us instead, write to privacy@deeta.app; we will verify who you are and respond within 30 days.

10. Everyone who touches anything

The complete list, and what each one gets:

WhoWhat they get
SupabaseHosts our own backend, so this is us rather than a third party. Your login (email address, how you sign in, your multi-factor secret if you set one, and a record that you passed the age check), your plan, which account's share link brought you in if you joined through one, when you signed up and first shared, the push address for live updates, the encrypted shares, their preview cards and who claimed them, who receives your live updates, a public key for each device you sign in on, and the account-linked usage records in section 4. Not your contacts or deets.
Anthropic, OpenAI, Google, xAIWhichever answers: the text of a question, the relevant contact records, and sometimes some of your own details, your AI preferences or your approximate area. On the note-structuring path, Google and Anthropic receive raw text — see section 5.
Brave SearchA web search, as described in section 5. Never your account.
AppleMerchant of record for purchases; your own iCloud backup and iCloud Keychain, which hold Deeta's encrypted database and its key (section 2); the updates it delivers as push notifications, which show your name but never the details; the spoken text, if you use Siri or dictation; and your already-coarse coordinates, when iOS turns them into a place name for a "near me" question.
RevenueCatYour purchase and subscription state, and your account identifier once you are signed in. We never see card details.
TelemetryDeck, Firebase CrashlyticsProduct analytics and crash diagnostics, neither linked to your account.
Twilio SendGridThe emails our systems send: sign-up confirmation, password reset, account-deletion confirmation, and an affiliation-verification code. SendGrid gets the recipient address and that message.
CloudflareServes share-link pages, the pages our sign-in emails open, and the app's feature settings, so it sees those requests and your IP address, and keeps request logs for a few days.
Named academic researchersNothing unless a study opens and you opt in: then pseudonymous usage patterns, under a signed data-use agreement, and never names, contacts or content. See section 12.

Identity verification records only which methods you completed and when — never the underlying documents. Email verification records only that the email you already gave us was confirmed. Deeta does not offer phone or government-ID verification.

11. How long anything is kept

  • On your phone: as long as the app is installed. You decide. Your own device backups stay in your Apple account until you delete them.
  • Shares: ciphertext we cannot read, and their preview cards, deleted after 24 hours or when you revoke. A record of who claimed a share is kept for 12 months.
  • Live updates: deleted 31 days after they end.
  • Your account record, usage records, push addresses and everything else tied to your account: hard-deleted — not hidden — when you delete your account.
  • Consent records: your research and sensitive-data consent choices are kept as proof of consent, with your account detached.
  • AI content: never retained, except the opt-in off-topic report in section 5.
  • Backups of our systems: removed from live systems immediately, and aged out of encrypted backups within 30 days.

12. Research, children, and California

Research. No research study is open. If one opens and you are at a research-eligible university, you may be offered the chance to opt in, and only half of eligible users are ever shown the prompt. What is captured is pseudonymous usage patterns — never names, contacts, messages or personal details — shared only with named academic researchers under signed agreements, and nothing is shared with anyone until an ethics board has approved the study. You would be able to withdraw at any time in Settings → Privacy → Research Participation. When you delete your account the key that links those events to you is destroyed, so nobody — including us — can trace them back.

Children. There is a minimum age and it depends on where you are: 13 in the United States, 16 everywhere else — the EU digital-consent age, which we apply worldwide outside the US, and if your region is unclear the higher floor is the one that applies. During sign-up we check your age using Apple's age range where it is available, or by asking for your date of birth, and block anyone below the floor for their region. The date itself is not stored. If you think someone under the applicable age has given us information, write to privacy@deeta.app and we will delete it.

California. Your CCPA rights are covered in section 9, using the same in-app tools everyone else gets.

This page covers the Deeta app. The deeta.app website and its waitlists have their own Website Privacy Notice.

13. Changes, and how to reach us

If we change anything material you get an in-app banner and an email, with a 30-day window before it takes effect — and if the change would weaken a commitment on the HumanTerms page, that page says so 30 days ahead too. The effective date at the top of the legal policy always reflects the current version.

Privacy questions: privacy@deeta.app. Something on this page that does not match what the app does: humanterms@deeta.app.

Deeta LLC · 300 East Bay Dr PMB 17127543, Largo, FL 33770, USA.

Deeta

The private, structured memory layer for your relationships — and for the agents that will act on your behalf.

Product

  • How it works
  • Privacy by design
  • Common questions
  • Join the waitlist
  • Android

Who it’s for

  • Dating
  • Family & friends
  • Students
  • Networking
  • Sales
  • Realtors
  • Recruiters
  • Coaches
  • Professional services
  • Small business

Company

  • Send feedback
  • Get help
  • Privacy policy
  • Privacy in plain English
  • Terms of service
  • Website privacy notice
  • HumanTerms compliance
  • contact@deeta.app

© 2026 Deeta LLC  ·  300 EAST BAY DR PMB 17127543, Largo, FL 33770  ·  contact@deeta.app