UNdrift app icon UNdrift العربية

Legal

UNDRIFT PRIVACY POLICY

Effective date: 1 September 2026
Version: 2026.09.01

This Privacy Policy explains how UNdrift handles information.

The provider is Samer Kamal Saleem Haddad, acting as sole proprietor and trading as GIVE ME THE MIC ADVERTISING SERVICES, a Sole Establishment operating under Abu Dhabi Economic Licence No. CN-5665616, United Arab Emirates. The Sole Establishment is not a separate limited liability company.

UNdrift is designed as a local-first iOS app. Most relationship information stays on the user's device. Selected information leaves the device only for clearly identified functions, primarily optional AI features, Apple purchase and entitlement processing, anonymous usage analytics, support communications, and ordinary website or server operations.

1. Scope

This Policy covers the UNdrift iOS app, its backend services, the UNdrift website and legal pages, subscriptions, and support interactions.

It does not govern Apple, OpenAI, WhatsApp, Telegram, Messages, carriers, or other independent services. Their own privacy terms apply to their independent processing.

2. Information stored locally on your device

UNdrift may store the following in the App's private local database:

  1. people you add, including name, optional phone number, preferred communication channel, tags, VIP status, time zone, and desired contact cadence;
  2. relationship descriptions and summaries;
  3. notes you attach to a person;
  4. touch logs, including date, outcome, channel, and an optional short note;
  5. reminders, snooze settings, queue settings, theme, notification preferences, AI permissions, legal acceptance records, and similar settings;
  6. a locally cached circle insight and its refresh timestamp, when that feature is enabled; and
  7. local subscription-entitlement state received from Apple.

This information is not uploaded to an UNdrift account or general cloud database in the current production version. Account and cloud-sync code may exist internally but is disabled in the current production configuration. UNdrift will update this Policy, App Store disclosures, deletion controls, and consent flows before enabling account or cloud-sync functionality in production.

3. Contacts and external communications

When you add a person using Apple's contact picker, Apple provides only the contact you select. UNdrift does not scan or upload your entire address book.

UNdrift does not read your call history, message history, or incoming message content. It does not automatically send a message. You choose the recipient, review the content, and initiate the final handoff or transmission through an external communication service.

External services may process the information you send under their own privacy policies.

4. Local backups and deletion

UNdrift may create a rotating set of local backup files inside the App's local container. These backups are intended to help recover the circle if the active database becomes unavailable or corrupted.

An ordinary in-app reset may delete the active people database, notes, logs, settings, and scheduled notifications while preserving previously created local backup files. If backups remain, deleted relationship information may still be recoverable from them. The App should clearly disclose this before reset and provide a separate way to delete local backups.

Deleting the App normally removes its local app container, subject to iOS behaviour, device backups, iCloud device backup, restored-device copies, or other systems controlled by you or Apple.

The Provider has no general server copy of the local relationship database to delete.

5. Optional AI features

UNdrift may offer the following optional AI functions:

  1. a message starter;
  2. a rewrite of a draft you provide;
  3. talking points for a voice note;
  4. a relationship brief; and
  5. circle insights about the overall contact pattern in your circle.

AI features remain disabled until you give separate express permission for the relevant processing. Accepting the Terms of Use is not AI permission.

5.1 User-initiated drafting, rewriting, voice points, and relationship briefs

Depending on the function, UNdrift may send the following to the UNdrift backend and OpenAI:

  1. a person's display name or first name;
  2. status in the App, cadence, preferred channel, and relationship summary;
  3. selected recent notes and touch-log summaries;
  4. the current draft and requested rewrite style; and
  5. whether you requested text or voice-note assistance.

5.2 Circle insights

Circle insights use a different data set and processing purpose. When you separately enable this function, opening the Insights screen may cause UNdrift to request a refreshed analysis no more than once per calendar day, subject to availability and caching.

The request may include:

  1. aggregate circle-health score;
  2. due and drifting counts;
  3. touchpoint count and active-touch days;
  4. per-person first name or a local pseudonymous label;
  5. relationship status and cadence;
  6. days since last touch;
  7. touch count in the recent period; and
  8. VIP status.

Circle insights do not require note text or touch-log text. Where technically practicable, UNdrift should use pseudonymous labels instead of real names for this function and restore names locally on the device.

5.3 Separate permissions and withdrawal

UNdrift should maintain separate consent scopes for:

  1. user-initiated AI drafting and relationship assistance; and
  2. circle insights that may refresh when you open the Insights screen.

You may decline either scope and continue using the non-AI core of the App. You may withdraw permission in Settings. Withdrawal stops future transmissions for that scope but does not affect processing that lawfully occurred before withdrawal.

If the Provider materially changes the AI processor, the purposes, the data categories, or the automatic-refresh behaviour, UNdrift will update the disclosure and request new permission where required.

6. How AI requests are processed

AI requests travel over HTTPS from the App to the UNdrift backend, which is currently hosted on infrastructure supplied by Hostinger and protected by a reverse proxy. The backend verifies subscription entitlement, applies rate limits and request limits, forwards the necessary request to OpenAI's API, and returns the result.

The UNdrift application does not intentionally write AI prompt or output content to a user-profile database. Operational infrastructure may generate limited security and diagnostic logs, such as IP address, timestamp, requested route, response status, rate-limit event, and error metadata. These logs must not intentionally contain full note text or full AI output and should ordinarily be retained for no longer than 30 days unless a longer period is reasonably necessary for a security incident, fraud investigation, legal requirement, or dispute.

AI inputs and outputs may also be screened by automated safety systems operated by OpenAI or the Provider to detect and prevent serious abuse, including credible threats, exploitation, fraud, and other prohibited conduct. Safety screening is used for service security, abuse prevention, and legal compliance, not for advertising.

OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer expressly opts in. UNdrift configures Responses API requests with store: false, which prevents ordinary Responses application-state storage for those requests. This setting does not by itself eliminate OpenAI's standard abuse-monitoring logs. OpenAI states that such logs may contain prompts, responses, and related metadata and are ordinarily retained for up to 30 days unless law requires longer retention. Zero Data Retention or Modified Abuse Monitoring applies only if the relevant OpenAI organisation or project has been approved and configured for it.

UNdrift does not claim UAE data residency or Zero Data Retention unless the production OpenAI project has been formally approved and configured for those controls and the regional API endpoint is actually used.

7. Apple purchases and subscription proof

UNdrift Pro is purchased through Apple's App Store. Apple processes the payment and payment credentials. UNdrift does not receive your full payment-card details.

For paid AI access, the App sends Apple's signed transaction proof to the UNdrift backend. The proof may contain product identifier, purchase and expiry information, transaction identifiers, environment, and other StoreKit entitlement data. It is used to verify an active subscription, prevent abuse, and apply rate limits. It is not intended to reveal your name, Apple Account email, or payment-card number to UNdrift.

Apple separately processes purchases, refunds, billing, tax, and App Store analytics under Apple's terms and privacy policy.

8. Notifications and widgets

UNdrift schedules local notifications on the device. It does not require a remote push-notification server for the current production reminder system.

The home-screen widget uses a small shared local file. The current design shows a mood and count, not contact names. The widget does not independently access the UNdrift relationship database or send data to a server.

9. Anonymous product analytics

UNdrift may send a small set of anonymous usage events to the UNdrift backend so the Provider can understand whether the App's core functions are working, for example whether reminders lead to saved reach-outs. This measurement is first-party: UNdrift does not use third-party analytics or advertising SDKs.

Each analytics event is limited to:

  1. the name of a core action or screen, such as completing onboarding, viewing the Today queue, saving a reach-out, opening the subscription screen, or completing a purchase;
  2. coarse category values, such as an outcome type, a bucketed count ("2-4" or "15+"), a subscription period, or a one-word answer to an in-app feedback question;
  3. the App version and the device language code;
  4. an event time rounded to the hour; and
  5. a random installation identifier generated on the device.

Analytics events do not contain names, phone numbers, notes, message content, relationship summaries, AI inputs or outputs, precise timestamps, advertising identifiers, or Apple Account information. The random installation identifier is created by the App without reference to your identity or device hardware and is not linked to contact details, purchase records, or AI requests.

Analytics is enabled by default. You can turn it off at any time in Settings. Turning it off stops future collection and deletes events not yet sent from the device. The backend discards event types and fields outside its approved list and stores accepted events on the infrastructure described in Section 6.

10. Website and support information

When you visit the UNdrift website, Netlify or another hosting provider may process ordinary web-server information such as IP address, browser and device information, requested page, timestamp, referring page, and security or diagnostic information. UNdrift does not use advertising cookies or third-party marketing trackers in the current website.

If you email support, the Provider receives the information in your email, including your email address and anything you choose to include. Support information is used to respond, troubleshoot, protect the service, and comply with law. Do not include sensitive relationship notes unless necessary.

Support correspondence is retained only as long as reasonably necessary for support, security, accounting, legal compliance, or dispute resolution.

11. Purposes and legal bases

Depending on the context and applicable law, UNdrift processes information to:

  1. perform the contract and provide requested App functions;
  2. act on your separate consent for optional AI processing;
  3. verify purchases and prevent fraud or abuse;
  4. measure aggregate feature usage through the anonymous analytics described in Section 9, subject to your ability to opt out in Settings;
  5. protect the App, users, and infrastructure;
  6. respond to support and legal requests; and
  7. comply with legal obligations.

Where processing relies on consent, consent must be clear, specific, provable, and easy to withdraw. Where another legal basis is used, the Provider will apply it only where permitted by applicable law.

You are responsible for having authority or another lawful basis to enter and transmit information about another person. Do not use AI features to transmit another person's sensitive or confidential information without lawful authority.

12. Service providers and international processing

Relevant service providers may include:

  1. Apple, for App Store distribution, StoreKit purchases, entitlement verification, and Apple-controlled analytics;
  2. OpenAI, for optional AI processing;
  3. Hostinger and associated infrastructure providers, for the UNdrift backend, including optional AI processing and anonymous analytics events;
  4. Netlify and associated infrastructure providers, for the website and legal pages; and
  5. email and network providers used for support or transmission.

These providers may process information in countries outside your residence. The Provider will use contractual, technical, organisational, and other safeguards appropriate to the service and applicable law. Mandatory data-transfer rights are preserved.

13. Retention

Local relationship information remains on your device until you delete it, reset it, remove the App, or the device or operating system removes it. Local backups may remain after an ordinary reset until separately deleted or until the App container is removed.

UNdrift AI requests are processed transiently and are not intentionally stored in an UNdrift user-content database. Limited operational logs may be retained as described above.

Anonymous analytics events described in Section 9 are retained on the UNdrift backend only as long as reasonably necessary to evaluate and improve the App.

OpenAI's standard API retention may apply as described in Section 6.

Apple, Hostinger, Netlify, email providers, and other independent or contracted providers retain information according to their roles, contractual settings, and legal obligations.

14. Security

UNdrift uses reasonable measures appropriate to its current architecture, including iOS sandboxing, device encryption provided by iOS, HTTPS/TLS for network requests, server-side storage of the OpenAI API key, StoreKit entitlement verification, rate limits, request-size limits, and restricted production configuration.

No system can guarantee absolute security. You are responsible for protecting your device passcode, Apple Account, backups, and email account.

15. Your choices and rights

Depending on applicable law, you may have rights to information, access, correction, deletion, restriction, objection, portability, withdrawal of consent, and complaint to a regulator.

Because most relationship information stays on your device, you can view, change, reset, or delete much of it directly in the App. For information held by the Provider, contact the addresses below.

You may turn off anonymous product analytics at any time in Settings, as described in Section 9.

The Provider may need to verify your request and may retain information where legally required or necessary to establish, exercise, or defend legal claims.

16. Children

UNdrift is not directed to children under 13 and does not knowingly permit them to use the App. A parent or guardian must supervise a minor who is legally permitted to use the App.

Do not enter or transmit personal data about a child unless you are legally authorised and the processing is lawful, necessary, and appropriate.

17. Changes

The Provider may update this Policy when the App, providers, law, security measures, or data practices change. Material changes will be presented through an appropriate notice, and new consent will be requested where required.

The effective date and version identify the current Policy.

18. Provider and contact

Provider:
Samer Kamal Saleem Haddad
acting as sole proprietor and trading as GIVE ME THE MIC ADVERTISING SERVICES
a Sole Establishment operating under Abu Dhabi Economic Licence No. CN-5665616

Licensing authority:
Abu Dhabi Registration Authority, Department of Economic Development, Abu Dhabi, United Arab Emirates

Business address shown on the current economic licence:
Abu Dhabi, Emirate of Abu Dhabi, United Arab Emirates

Telephone:
+971 58 567 1381

Privacy, support, and legal email:
samer@thaka2.ai

Support:
https://undrift-app.netlify.app/support/

You may direct privacy questions, requests, and complaints to these contact details.