Legal
Effective date: 1 September 2026
Version: 2026.09.01
This Privacy Policy explains how UNdrift handles information.
The provider is Samer Kamal Saleem Haddad, acting as sole proprietor and trading as GIVE ME THE MIC ADVERTISING SERVICES, a Sole Establishment operating under Abu Dhabi Economic Licence No. CN-5665616, United Arab Emirates. The Sole Establishment is not a separate limited liability company.
UNdrift is designed as a local-first iOS app. Most relationship information stays on the user's device. Selected information leaves the device only for clearly identified functions, primarily optional AI features, Apple purchase and entitlement processing, anonymous usage analytics, support communications, and ordinary website or server operations.
This Policy covers the UNdrift iOS app, its backend services, the UNdrift website and legal pages, subscriptions, and support interactions.
It does not govern Apple, OpenAI, WhatsApp, Telegram, Messages, carriers, or other independent services. Their own privacy terms apply to their independent processing.
UNdrift may store the following in the App's private local database:
This information is not uploaded to an UNdrift account or general cloud database in the current production version. Account and cloud-sync code may exist internally but is disabled in the current production configuration. UNdrift will update this Policy, App Store disclosures, deletion controls, and consent flows before enabling account or cloud-sync functionality in production.
When you add a person using Apple's contact picker, Apple provides only the contact you select. UNdrift does not scan or upload your entire address book.
UNdrift does not read your call history, message history, or incoming message content. It does not automatically send a message. You choose the recipient, review the content, and initiate the final handoff or transmission through an external communication service.
External services may process the information you send under their own privacy policies.
UNdrift may create a rotating set of local backup files inside the App's local container. These backups are intended to help recover the circle if the active database becomes unavailable or corrupted.
An ordinary in-app reset may delete the active people database, notes, logs, settings, and scheduled notifications while preserving previously created local backup files. If backups remain, deleted relationship information may still be recoverable from them. The App should clearly disclose this before reset and provide a separate way to delete local backups.
Deleting the App normally removes its local app container, subject to iOS behaviour, device backups, iCloud device backup, restored-device copies, or other systems controlled by you or Apple.
The Provider has no general server copy of the local relationship database to delete.
UNdrift may offer the following optional AI functions:
AI features remain disabled until you give separate express permission for the relevant processing. Accepting the Terms of Use is not AI permission.
Depending on the function, UNdrift may send the following to the UNdrift backend and OpenAI:
Circle insights use a different data set and processing purpose. When you separately enable this function, opening the Insights screen may cause UNdrift to request a refreshed analysis no more than once per calendar day, subject to availability and caching.
The request may include:
Circle insights do not require note text or touch-log text. Where technically practicable, UNdrift should use pseudonymous labels instead of real names for this function and restore names locally on the device.
UNdrift should maintain separate consent scopes for:
You may decline either scope and continue using the non-AI core of the App. You may withdraw permission in Settings. Withdrawal stops future transmissions for that scope but does not affect processing that lawfully occurred before withdrawal.
If the Provider materially changes the AI processor, the purposes, the data categories, or the automatic-refresh behaviour, UNdrift will update the disclosure and request new permission where required.
AI requests travel over HTTPS from the App to the UNdrift backend, which is currently hosted on infrastructure supplied by Hostinger and protected by a reverse proxy. The backend verifies subscription entitlement, applies rate limits and request limits, forwards the necessary request to OpenAI's API, and returns the result.
The UNdrift application does not intentionally write AI prompt or output content to a user-profile database. Operational infrastructure may generate limited security and diagnostic logs, such as IP address, timestamp, requested route, response status, rate-limit event, and error metadata. These logs must not intentionally contain full note text or full AI output and should ordinarily be retained for no longer than 30 days unless a longer period is reasonably necessary for a security incident, fraud investigation, legal requirement, or dispute.
AI inputs and outputs may also be screened by automated safety systems operated by OpenAI or the Provider to detect and prevent serious abuse, including credible threats, exploitation, fraud, and other prohibited conduct. Safety screening is used for service security, abuse prevention, and legal compliance, not for advertising.
OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer expressly opts in. UNdrift configures Responses API requests with store: false, which prevents ordinary Responses application-state storage for those requests. This setting does not by itself eliminate OpenAI's standard abuse-monitoring logs. OpenAI states that such logs may contain prompts, responses, and related metadata and are ordinarily retained for up to 30 days unless law requires longer retention. Zero Data Retention or Modified Abuse Monitoring applies only if the relevant OpenAI organisation or project has been approved and configured for it.
UNdrift does not claim UAE data residency or Zero Data Retention unless the production OpenAI project has been formally approved and configured for those controls and the regional API endpoint is actually used.
UNdrift Pro is purchased through Apple's App Store. Apple processes the payment and payment credentials. UNdrift does not receive your full payment-card details.
For paid AI access, the App sends Apple's signed transaction proof to the UNdrift backend. The proof may contain product identifier, purchase and expiry information, transaction identifiers, environment, and other StoreKit entitlement data. It is used to verify an active subscription, prevent abuse, and apply rate limits. It is not intended to reveal your name, Apple Account email, or payment-card number to UNdrift.
Apple separately processes purchases, refunds, billing, tax, and App Store analytics under Apple's terms and privacy policy.
UNdrift schedules local notifications on the device. It does not require a remote push-notification server for the current production reminder system.
The home-screen widget uses a small shared local file. The current design shows a mood and count, not contact names. The widget does not independently access the UNdrift relationship database or send data to a server.
UNdrift may send a small set of anonymous usage events to the UNdrift backend so the Provider can understand whether the App's core functions are working, for example whether reminders lead to saved reach-outs. This measurement is first-party: UNdrift does not use third-party analytics or advertising SDKs.
Each analytics event is limited to:
Analytics events do not contain names, phone numbers, notes, message content, relationship summaries, AI inputs or outputs, precise timestamps, advertising identifiers, or Apple Account information. The random installation identifier is created by the App without reference to your identity or device hardware and is not linked to contact details, purchase records, or AI requests.
Analytics is enabled by default. You can turn it off at any time in Settings. Turning it off stops future collection and deletes events not yet sent from the device. The backend discards event types and fields outside its approved list and stores accepted events on the infrastructure described in Section 6.
When you visit the UNdrift website, Netlify or another hosting provider may process ordinary web-server information such as IP address, browser and device information, requested page, timestamp, referring page, and security or diagnostic information. UNdrift does not use advertising cookies or third-party marketing trackers in the current website.
If you email support, the Provider receives the information in your email, including your email address and anything you choose to include. Support information is used to respond, troubleshoot, protect the service, and comply with law. Do not include sensitive relationship notes unless necessary.
Support correspondence is retained only as long as reasonably necessary for support, security, accounting, legal compliance, or dispute resolution.
Depending on the context and applicable law, UNdrift processes information to:
Where processing relies on consent, consent must be clear, specific, provable, and easy to withdraw. Where another legal basis is used, the Provider will apply it only where permitted by applicable law.
You are responsible for having authority or another lawful basis to enter and transmit information about another person. Do not use AI features to transmit another person's sensitive or confidential information without lawful authority.
Relevant service providers may include:
These providers may process information in countries outside your residence. The Provider will use contractual, technical, organisational, and other safeguards appropriate to the service and applicable law. Mandatory data-transfer rights are preserved.
Local relationship information remains on your device until you delete it, reset it, remove the App, or the device or operating system removes it. Local backups may remain after an ordinary reset until separately deleted or until the App container is removed.
UNdrift AI requests are processed transiently and are not intentionally stored in an UNdrift user-content database. Limited operational logs may be retained as described above.
Anonymous analytics events described in Section 9 are retained on the UNdrift backend only as long as reasonably necessary to evaluate and improve the App.
OpenAI's standard API retention may apply as described in Section 6.
Apple, Hostinger, Netlify, email providers, and other independent or contracted providers retain information according to their roles, contractual settings, and legal obligations.
UNdrift uses reasonable measures appropriate to its current architecture, including iOS sandboxing, device encryption provided by iOS, HTTPS/TLS for network requests, server-side storage of the OpenAI API key, StoreKit entitlement verification, rate limits, request-size limits, and restricted production configuration.
No system can guarantee absolute security. You are responsible for protecting your device passcode, Apple Account, backups, and email account.
Depending on applicable law, you may have rights to information, access, correction, deletion, restriction, objection, portability, withdrawal of consent, and complaint to a regulator.
Because most relationship information stays on your device, you can view, change, reset, or delete much of it directly in the App. For information held by the Provider, contact the addresses below.
You may turn off anonymous product analytics at any time in Settings, as described in Section 9.
The Provider may need to verify your request and may retain information where legally required or necessary to establish, exercise, or defend legal claims.
UNdrift is not directed to children under 13 and does not knowingly permit them to use the App. A parent or guardian must supervise a minor who is legally permitted to use the App.
Do not enter or transmit personal data about a child unless you are legally authorised and the processing is lawful, necessary, and appropriate.
The Provider may update this Policy when the App, providers, law, security measures, or data practices change. Material changes will be presented through an appropriate notice, and new consent will be requested where required.
The effective date and version identify the current Policy.
Provider:
Samer Kamal Saleem Haddad
acting as sole proprietor and trading as GIVE ME THE MIC ADVERTISING SERVICES
a Sole Establishment operating under Abu Dhabi Economic Licence No. CN-5665616
Licensing authority:
Abu Dhabi Registration Authority, Department of Economic Development, Abu Dhabi, United Arab Emirates
Business address shown on the current economic licence:
Abu Dhabi, Emirate of Abu Dhabi, United Arab Emirates
Telephone:
+971 58 567 1381
Privacy, support, and legal email:
samer@thaka2.ai
Support:
https://undrift-app.netlify.app/support/
You may direct privacy questions, requests, and complaints to these contact details.