← InstantAI

Privacy Policy (iOS App)

InstantAI by North Tumbleweed LLC | Last updated April 17, 2026

This policy covers the InstantAI iOS app only. If you are using the web app at instantai.chat, see the web Privacy Policy, which additionally discloses the analytics and advertising tools used on the web.

1. Overview

North Tumbleweed LLC ("we", "us", "our") publishes InstantAI, an AI-powered chat assistant. This Privacy Policy describes how the InstantAI iOS app handles your data. A separate web Privacy Policy covers the web version at instantai.chat.

By using the InstantAI iOS app, you agree to the practices described in this policy. If you do not agree, please do not use the Service.

Cross-platform use. Your InstantAI account and subscription are shared between this iOS app and the web app at instantai.chat. If you sign in with the same account on both, your conversation history and custom instructions sync between them. When you use the iOS app, the data practices described in this policy apply. When you use the web app, the web Privacy Policy applies; it covers the additional analytics and advertising tools that run only on the web (Meta Pixel, TikTok Pixel, PostHog, Google Ads). The iOS app does not use any of those.

2. Data We Collect

2.1 Account Information

When you create an InstantAI account, we collect:

If you use Sign in with Apple with the "Hide My Email" option, we only receive the private relay email address Apple generates for you.

2.2 Messages and Conversations

We store your chat messages and conversation history to provide the Service. This includes:

Your chat history is stored so you can access it across devices and continue previous conversations. Chat content is scoped per-account via row-level security, meaning only you can read your own messages.

2.3 Uploaded Files and Images

When you upload or capture documents and images for analysis, these files are processed to generate AI responses. Images attached to a conversation are stored alongside the conversation so they remain visible in your chat history. Files and images are used solely to operate the chat feature and are not used for training, advertising, or any other purpose.

2.4 Product Interaction and Usage Data

We collect product interaction events to understand how the app is used and to improve the experience:

These events are linked to your account identifier so we can measure retention and feature usage. They are not shared with advertisers and are not used to build a marketing profile about you.

2.5 Marketing Attribution (AppsFlyer)

On iOS, we use AppsFlyer to measure which marketing channels bring new users to InstantAI. If you grant permission through Apple's App Tracking Transparency prompt, AppsFlyer receives your device's Advertising Identifier (IDFA) for attribution and SKAdNetwork conversion measurement. If you decline the prompt, the advertising identifier is not collected and AppsFlyer falls back to aggregate, non-personalized measurement. The app works exactly the same either way. See Section 8 ("App Tracking Transparency") for details on how to opt out. Full details on what AppsFlyer receives are in Section 7.5.

2.6 Network Identifiers and IP Address

When you interact with InstantAI, our backend logs the IP address of the incoming request. IP addresses are used for rate limiting, abuse detection, and security auditing (for example, to block sign-in attempts from suspicious patterns or to investigate misuse reports). IP addresses are stored in short-lived operational tables (event logs, device session records, upload audit logs) and are retained for up to 90 days before being deleted or anonymized. IP addresses are never shared with advertisers and are never used to build a marketing profile about you.

2.7 Purchase History

When you subscribe, we receive subscription events (purchase, renewal, cancellation) from Apple's App Store through our subscription provider RevenueCat. This data is linked to your account so we can grant the features you paid for. We do not see or store payment card details, billing addresses, or any other financial information.

2.8 Diagnostic and Crash Data

Standard iOS crash signatures may be transmitted by the operating system and by the SDKs we ship to help us fix bugs. Crash data is anonymous (not linked to your account) and is used only to improve app stability.

3. Camera Usage

InstantAI may request access to your device's camera when you choose to attach an image to a conversation. Camera usage works as follows:

4. AI Providers

To generate responses, your messages are sent to third-party AI providers for processing through our backend. This is how InstantAI works:

We do not send your email address, account information, or any personal identifiers to AI providers. Only the content of your messages (and any attached files relevant to the conversation) is transmitted for processing.

When web search is active, your AI retrieves information from the internet to give you current answers. Search queries are derived from your messages and sent to a search service to fetch relevant web content.

6. How We Use Your Data

We use your data strictly to provide, operate, and improve InstantAI:

PurposeData Used
AI chat responsesYour messages, sent to AI providers via our backend
Conversation history and syncMessages and metadata, stored in our database
Image analysisUploaded or captured images, sent to AI providers
Web searchSearch queries derived from your messages
Account managementEmail address, account identifier, and authentication state
Subscription managementPurchase events and entitlement status via RevenueCat
Custom instructionsYour personalization preferences, applied to conversations
Product analyticsScreen views, taps, and feature usage events, linked to your account identifier
Marketing attributionDevice advertising identifier via AppsFlyer, only with App Tracking Transparency consent
Abuse prevention and securityIP address and request metadata (retained for up to 90 days)
Crash diagnosticsAnonymous crash signatures

We do not sell your data. We do not use the content of your chat messages for advertising. We do not build marketing profiles from your chat content. Your conversations are not used to train AI models.

7. Third-Party Services

InstantAI integrates with the following third-party services. Each service has its own privacy policy governing the data it receives.

7.1 AI Inference Providers

Your messages and attached files are sent to third-party AI providers through our backend to generate responses. These providers process your input according to their own usage and privacy policies. We route requests through our servers and do not send your email address, account identifier, or any other personal identifier to these providers. We select providers whose terms do not permit the use of customer inputs for model training.

7.2 Search Provider (Tavily)

When web search is enabled, queries are sent to Tavily, a search API service, to retrieve relevant web content. Tavily receives the search query but not your account information or personal identifiers. Tavily's privacy policy governs its handling of search queries.

7.3 Authentication and Database (Supabase)

We use Supabase for account authentication and data storage. Supabase stores your account information, chat history, uploaded images, and custom instructions in the us-east-1 region (Amazon Web Services, Northern Virginia, United States). Your data is protected by row-level security, meaning only you can access your own rows. Supabase's privacy policy governs their handling of this data. International transfers from the European Economic Area, United Kingdom, and Switzerland to the United States are covered under Standard Contractual Clauses published by the European Commission, which Supabase has executed with its customers.

7.4 Subscription Management (RevenueCat)

We use RevenueCat to manage subscriptions on iOS. RevenueCat receives:

RevenueCat does not receive your chat messages, your email address, uploaded images, or any other content from the app. Payments are processed by Apple's App Store. Neither we nor RevenueCat see or store your payment card details or billing address.

7.5 Marketing Attribution (AppsFlyer)

On iOS, we use AppsFlyer to measure which marketing channels bring new users to InstantAI. AppsFlyer is an attribution and marketing measurement service. It helps us understand, at a cohort level, which advertising campaigns convert, so we can invest in what works.

AppsFlyer is the only third-party analytics and attribution tool used in the iOS app. We do not use Meta Pixel, TikTok Pixel, PostHog, Google Ads conversion tracking, or any other analytics or advertising SDK in the iOS app.

8. App Tracking Transparency

Apple requires iOS apps to ask for permission before collecting the device's Advertising Identifier (IDFA) for cross-app tracking or advertising measurement. InstantAI shows this prompt during onboarding because we use AppsFlyer for marketing attribution (see Section 7.5).

Your choice is fully respected:

You can change your choice at any time in iOS Settings → Privacy & Security → Tracking. You can also disable tracking globally for all apps in the same menu.

9. What We Do NOT Collect

We collect only what is necessary to operate the Service, measure how it is used, and understand which marketing channels bring new users. We do not profile you, sell your data, or use your chat content for advertising.

Specifically, the InstantAI iOS app does not collect or use:

10. Data Retention

Chat History

Your conversations, uploaded images, and custom instructions are stored in our database for as long as your account is active, so you can access them across devices. You can delete individual conversations at any time inside the app. We retain chat data until you delete individual conversations, delete your account, or request deletion by contacting us.

Account Data

Your account record (email, account identifier, authentication state, subscription tier) is retained for as long as your account exists.

Product Analytics and Attribution

Product interaction events and attribution events are retained for up to 24 months, after which they are anonymized or deleted by scheduled backend jobs. AppsFlyer applies its own retention policy to the event copies it receives.

IP Address and Operational Logs

IP addresses and operational logs (event log IPs, device-session creation IPs, upload audit IPs, rate-limit counters) are retained for up to 90 days and are then deleted or anonymized. These short-retention logs exist only for abuse prevention, rate limiting, and security incident response.

Subscription Data

RevenueCat and Apple retain subscription records as required by their own policies and applicable tax and accounting laws. We retain the entitlement status on your profile so we can grant the features you paid for.

AI Provider Retention

Once messages are processed by AI providers, their retention practices are governed by their own policies. We select providers whose contracts do not permit the use of customer inputs for model training and that delete inputs shortly after processing.

11. Account Deletion

You can delete your account at any time. Deleting your account is permanent and cannot be undone.

When you delete your account, we remove your account record, chat history, uploaded images, custom instructions, product analytics events, and any other data linked to your account. Deletion cascades across our database within a short period. Backups containing residual copies are overwritten on a rolling basis and are never used for any purpose other than disaster recovery.

If you have an active subscription, remember to cancel it separately before deleting your account (see Section 12), because subscriptions are managed by Apple and continue to auto-renew unless cancelled.

12. Subscription Management and Cancellation

InstantAI offers premium subscriptions on weekly, monthly, and yearly billing cycles. Current pricing is displayed at the time of purchase in the app.

Auto-renewal. Payment will be charged to your Apple Account at confirmation of purchase. Subscriptions automatically renew unless cancelled at least 24 hours before the end of the current period. Your payment method will be charged for renewal within 24 hours prior to the end of the current period.

How to cancel: open iOS Settings → [your name] → Subscriptions → InstantAI and tap Cancel Subscription. You can also cancel from inside the InstantAI app at Profile → Settings → Manage Subscription, which opens the same iOS settings page.

Cancellation takes effect at the end of the current billing period. You retain access to premium features until then. Refund requests for App Store purchases must be directed to Apple.

13. Children's Privacy

InstantAI is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account or provided us with personal information, please contact us and we will delete it promptly.

14. Your Rights Under GDPR (European Users)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights:

You can exercise many of these rights directly within the app by deleting conversations or deleting your account. For other requests, contact us and we will respond within 30 days.

Legal basis for processing: We process data based on (a) your consent (camera permission, App Tracking Transparency), (b) contract performance (providing the AI chat service you use), and (c) legitimate interest (subscription management and service operation).

15. Your Rights Under CCPA (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with the following rights:

To exercise these rights, contact us at the email address below. We will verify your identity and respond within 45 days.

16. Security

We implement reasonable security measures to protect your data in transit and at rest:

No method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

17. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of InstantAI after changes constitutes acceptance of the updated policy.

For material changes, we will make reasonable efforts to notify you within the app or via email.

18. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us:

North Tumbleweed LLC
Email: [email protected]
Web: instantai.chat