InstantAI by North Tumbleweed LLC | Last updated April 17, 2026
North Tumbleweed LLC ("we", "us", "our") publishes InstantAI, an AI-powered chat assistant available on iOS and the web at instantai.chat. This Privacy Policy explains what information we collect when you use InstantAI, how we use it, and what rights you have regarding your data.
By using InstantAI, you agree to the practices described in this policy. If you do not agree, please do not use the Service.
When you create an InstantAI account, we collect:
If you use Sign in with Apple with the "Hide My Email" option, we only receive the private relay email address Apple generates for you.
We store your chat messages and conversation history to provide the Service. This includes:
Your chat history is stored so you can access it across devices and continue previous conversations. Chat content is scoped per-account via row-level security, meaning only you can read your own messages.
When you upload or capture documents and images for analysis, these files are processed to generate AI responses. Images attached to a conversation are stored alongside the conversation so they remain visible in your chat history. Files and images are used solely to operate the chat feature and are not used for training, advertising, or any other purpose.
We collect product interaction events to understand how the app is used and to improve the experience:
These events are linked to your account identifier so we can measure retention and feature usage. They are not shared with advertisers and are not used to build a marketing profile about you.
iOS. On iOS, we use AppsFlyer to measure which marketing channels bring new users to InstantAI. If you grant permission through Apple's App Tracking Transparency prompt, AppsFlyer receives your device's Advertising Identifier (IDFA) for attribution and SKAdNetwork conversion measurement. If you decline the prompt, the advertising identifier is not collected and AppsFlyer falls back to aggregate, non-personalized measurement. The app works exactly the same either way. See Section 8 ("App Tracking Transparency") for details on how to opt out.
Web. On the web at instantai.chat, we use Meta Pixel, TikTok Pixel, PostHog, and Google Ads conversion tracking to measure marketing effectiveness and understand how people use the product. These tools use cookies and local storage to recognize return visits and attribute conversions. In the European Economic Area, United Kingdom, and Switzerland, none of these tools load until you accept the consent banner. See Section 7a ("Web Analytics & Advertising") for the full breakdown.
When you interact with InstantAI, our backend logs the IP address of the incoming request. IP addresses are used for rate limiting, abuse detection, and security auditing (for example, to block sign-in attempts from suspicious patterns or to investigate misuse reports). IP addresses are stored in short-lived operational tables (event logs, device session records, upload audit logs) and are retained for up to 90 days before being deleted or anonymized. IP addresses are never shared with advertisers and are never used to build a marketing profile about you.
When you subscribe, we receive subscription events (purchase, renewal, cancellation) from Apple's App Store (on iOS) or Stripe (on the web) through our subscription provider RevenueCat. This data is linked to your account so we can grant the features you paid for. We do not see or store payment card details, billing addresses, or any other financial information.
Standard iOS and web crash signatures may be transmitted by the operating system and by the SDKs we ship to help us fix bugs. Crash data is anonymous (not linked to your account) and is used only to improve app stability.
InstantAI may request access to your device's camera when you choose to attach an image to a conversation. Camera usage works as follows:
To generate responses, your messages are sent to third-party AI providers for processing through our backend. This is how InstantAI works:
When web search is active, your AI retrieves information from the internet to give you current answers. Search queries are derived from your messages and sent to a search service to fetch relevant web content.
We use your data strictly to provide, operate, and improve InstantAI:
| Purpose | Data Used |
|---|---|
| AI chat responses | Your messages, sent to AI providers via our backend |
| Conversation history and sync | Messages and metadata, stored in our database |
| Image analysis | Uploaded or captured images, sent to AI providers |
| Web search | Search queries derived from your messages |
| Account management | Email address, account identifier, and authentication state |
| Subscription management | Purchase events and entitlement status via RevenueCat |
| Custom instructions | Your personalization preferences, applied to conversations |
| Product analytics | Screen views, taps, and feature usage events, linked to your account identifier |
| Marketing attribution (iOS) | Device advertising identifier via AppsFlyer, only with ATT consent |
| Marketing attribution (web) | Cookies and events via Meta Pixel, TikTok Pixel, PostHog, and Google Ads — consent-gated for EU/UK/EEA visitors |
| Abuse prevention and security | IP address and request metadata (retained for up to 90 days) |
| Crash diagnostics | Anonymous crash signatures |
We do not sell your data. We do not use the content of your chat messages for advertising. We do not build marketing profiles from your chat content. Your conversations are not used to train AI models. When web search is active, your AI retrieves information from the internet to give you current answers.
InstantAI integrates with the following third-party services. Each service has its own privacy policy governing the data it receives.
Your messages and attached files are sent to third-party AI providers through our backend to generate responses. These providers process your input according to their own usage and privacy policies. We route requests through our servers and do not send your email address, account identifier, or any other personal identifier to these providers. We select providers whose terms do not permit the use of customer inputs for model training.
When web search is enabled, queries are sent to Tavily, a search API service, to retrieve relevant web content. Tavily receives the search query but not your account information or personal identifiers. Tavily's privacy policy governs its handling of search queries.
We use Supabase for account authentication and data storage. Supabase stores your account information, chat history, uploaded images, and custom instructions in the us-east-1 region (Amazon Web Services, Northern Virginia, United States). Your data is protected by row-level security, meaning only you can access your own rows. Supabase's privacy policy governs their handling of this data. International transfers from the European Economic Area, United Kingdom, and Switzerland to the United States are covered under Standard Contractual Clauses published by the European Commission, which Supabase has executed with its customers.
We use RevenueCat to manage subscriptions across iOS and the web. RevenueCat receives:
RevenueCat does not receive your chat messages, your email address, uploaded images, or any other content from the app. On iOS, payments are processed by Apple's App Store. On the web, payments are processed by Stripe. Neither we nor RevenueCat see or store your payment card details or billing address.
On iOS, we use AppsFlyer to measure which marketing channels bring new users to InstantAI. AppsFlyer is an attribution and marketing measurement service. It helps us understand, at a cohort level, which advertising campaigns convert, so we can invest in what works.
t.appsflyer.com, register.appsflyer.com, conversions.appsflyer.com, app.appsflyer.com, api2.appsflyer.com, and onelink.meAppsFlyer is used only in the iOS app. The web app at instantai.chat does not use AppsFlyer.
The web app at instantai.chat uses four third-party tools to measure marketing effectiveness and understand product usage. These tools are not used in the iOS app. For visitors from the European Economic Area, the United Kingdom, and Switzerland, every tool in this section is gated behind the cookie consent banner that appears on your first visit — none of them load until you accept. Visitors outside these regions are treated as consent-given by default, consistent with US privacy norms; you can still decline by choosing "Decline" if the banner is shown to you or by using browser-level controls.
_fbp, fr), your browser and device characteristics, the URL you visit, and a set of discrete events — PageView, ViewContent (paywall shown), StartTrial, CompleteRegistration, Lead (onboarding completed), and Purchase._ttp), device and browser signals, the URL you visit, and the same set of events as Meta Pixel (page view, paywall view, checkout start, signup complete, purchase complete).us.i.posthog.com), hosted on Amazon Web Services in the United States.gtag.js, conversion ID AW-18004637415) that attributes Google Ads clicks to signups and purchases on instantai.chat._gcl_au, _gcl_aw), a click identifier (gclid) from Google ad links, page views, and conversion events (sign_up, begin_checkout, purchase).Independent of the third-party tools above, our backend writes a first-party record of significant events (for example signup, subscription, paywall view, feature use). This record includes the event name, a small payload describing the event, a device identifier, your account identifier (once signed in), and a tab-scoped session identifier. First-party event logging is necessary to operate the Service (detect abuse, deliver features you paid for, support your account) and is therefore always active, even if you decline the third-party consent banner. First-party events are stored in our database and are subject to the retention rules in Section 10.
This section explains the cookies, local storage keys, and session storage keys that the web app at instantai.chat may create on your device. It does not apply to the iOS app, which does not use browser cookies.
| Name | Type | Purpose |
|---|---|---|
instantai_cookie_consent | localStorage | Records your choice on the consent banner (accepted or declined). EU/UK/EEA visitors only. |
instantai_session | sessionStorage | Random per-tab session identifier used to group events within a single browsing tab. |
instantai_device | localStorage | Random device identifier used for first-party event logging and abuse prevention. |
| Name | Type | Purpose |
|---|---|---|
instantai_first_touch | localStorage | The UTM parameters and referrer captured on your first visit. Used so we can credit the marketing channel that introduced you to InstantAI. |
instantai_last_touch | localStorage | The UTM parameters and referrer captured on your most recent visit. |
When you accept the consent banner (or when you visit from outside the EU/UK/EEA), the following third-party cookies may be set by the tools described in Section 7a. Names and purposes below are current at the time of writing; each provider may change them.
| Cookie | Set by | Purpose |
|---|---|---|
_fbp, fr | Meta Pixel (facebook.com) | Ad attribution and audience building. |
_ttp | TikTok Pixel (tiktok.com) | Ad attribution. |
_gcl_au, _gcl_aw | Google Ads (googletagmanager.com, google.com) | Conversion tracking for Google Ads campaigns. |
ph_* (various) | PostHog (us.i.posthog.com) | Product-analytics session and person identification. |
You can clear cookies at any time through your browser's settings (for example, Safari → Settings → Privacy → Manage Website Data; Chrome → Settings → Privacy and security → Cookies and other site data). To reset your consent choice and see the banner again on your next visit (EU/UK/EEA), clear local storage for instantai.chat. We also honor browser-level "Do Not Track" and "Global Privacy Control" signals where required by applicable law.
On iOS, Apple requires apps to ask for permission before collecting the device's Advertising Identifier (IDFA) for cross-app tracking or advertising measurement. InstantAI shows this prompt during onboarding because we use AppsFlyer for marketing attribution (see Section 7.5).
Your choice is fully respected:
You can change your choice at any time in iOS Settings → Privacy & Security → Tracking. You can also disable tracking globally for all apps in the same menu.
Specifically, InstantAI does not collect or use:
Your conversations, uploaded images, and custom instructions are stored in our database for as long as your account is active, so you can access them across devices. You can delete individual conversations at any time inside the app. We retain chat data until you delete individual conversations, delete your account, or request deletion by contacting us.
Your account record (email, account identifier, authentication state, subscription tier) is retained for as long as your account exists.
Product interaction events and attribution events are retained for up to 24 months, after which they are anonymized or deleted by scheduled backend jobs. Third-party analytics and ad-tech providers (Meta, TikTok, Google, PostHog) apply their own retention policies to the copies of events they receive.
IP addresses and operational logs (event log IPs, device-session creation IPs, upload audit IPs, rate-limit counters) are retained for up to 90 days and are then deleted or anonymized. These short-retention logs exist only for abuse prevention, rate limiting, and security incident response.
RevenueCat, Apple, and Stripe retain subscription records as required by their own policies and applicable tax and accounting laws. We retain the entitlement status on your profile so we can grant the features you paid for.
Once messages are processed by AI providers, their retention practices are governed by their own policies. We select providers whose contracts do not permit the use of customer inputs for model training and that delete inputs shortly after processing.
You can delete your account at any time. Deleting your account is permanent and cannot be undone.
When you delete your account, we remove your account record, chat history, uploaded images, custom instructions, product analytics events, and any other data linked to your account. Deletion cascades across our database within a short period. Backups containing residual copies are overwritten on a rolling basis and are never used for any purpose other than disaster recovery.
If you have an active subscription, remember to cancel it separately before deleting your account (see Section 12), because subscriptions are managed by Apple or Stripe and continue to auto-renew unless cancelled.
InstantAI offers premium subscriptions on weekly, monthly, and yearly billing cycles. Current pricing is displayed at the time of purchase in the app and on the web.
Auto-renewal. Subscriptions automatically renew at the end of each billing period unless cancelled at least 24 hours before the renewal date. Your payment method will be charged for renewal within 24 hours prior to the end of the current period.
How to cancel:
Cancellation takes effect at the end of the current billing period. You retain access to premium features until then. Refund requests for App Store purchases must be directed to Apple. For web purchases, contact us directly.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights:
You can exercise many of these rights directly within the app by deleting conversations or deleting your account. For other requests, contact us and we will respond within 30 days.
Legal basis for processing: We process data based on (a) your consent (camera permission), (b) contract performance (providing the AI chat service you use), and (c) legitimate interest (subscription management and service operation).
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with the following rights:
To exercise these rights, contact us at the email address below. We will verify your identity and respond within 45 days.
We implement reasonable security measures to protect your data in transit and at rest:
No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of InstantAI after changes constitutes acceptance of the updated policy.
For material changes, we will make reasonable efforts to notify you within the app or via email.
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us:
North Tumbleweed LLC
Email: [email protected]
Web: instantai.chat