This policy explains exactly what data an app collects, why, who processes it on our behalf, how long it is kept, and how to have it deleted.
1. Introduction
USI Apps (“we”, “us”, “our”) publishes mobile applications (each an “App”, and together the “Apps”) on Google Play and the Apple App Store. This policy applies to all of them.
Not every App has every feature described here. Where an App does not offer a feature — for example voice input, file attachments, advertising or in-app purchases — the corresponding data is simply not collected by that App. Each App’s store listing shows a Data Safety summary describing that specific App.
We are the data controller for the data described here. To ask a question or to exercise any right in Section 9 or Section 10, email bilisamweb@gmail.com.
Some of our Apps provide AI assistants or characters. Those personas are not real people, and their replies are generated by artificial intelligence for support, entertainment and self-reflection. They are not professional, medical, psychological or legal advice, and they are not a substitute for a qualified professional or for emergency services.
2. No account, no sign-up
Our Apps do not ask you to register. We do not collect your name, email address, phone number, postal address, date of birth, gender, identity documents, or any social-media login.
Instead, when an App first runs it generates a random device code (for example mob_9f3c…). That code, combined with the App’s identifier, becomes your anonymous account. Anything you own inside the App — such as a credit balance or a chat history — is attached to that anonymous account and nothing else. The same device gets a separate anonymous account in each App.
To stop someone else from claiming your account, the App also generates a random device secret and a one-time recovery code. We store only a SHA-256 hash of each of them — never the values themselves. The recovery code is shown to you inside the App so you can move your balance to a new device if you lose the old one.
3. The data we collect
3.1 Identifiers and technical data
- The anonymous device code described in Section 2.
- Hashes of your device secret and recovery code.
- A rotating session token.
- Platform (Android / iOS / web), app version, language, time zone, user agent, login count and last login time.
- The IP address seen by our server at your most recent sign-in, kept for security and abuse prevention.
- A separate irreversible hash (SHA-256) of your IP address, used only to enforce limits such as “one free daily reward per network per day”. The raw IP address is not stored for that purpose.
- Device identifiers used by the Google services in the App: the advertising identifier (Google AdMob), the Firebase installation ID, and the push-notification token if you allow notifications.
3.2 Content you create
- Messages you send to an AI assistant and the replies you receive, stored so your conversation is still there next time you open the App.
- The text transcript of a live voice conversation.
- Photos and documents you choose to attach. These are stored on our storage provider and referenced by the conversation.
3.3 Voice
- When you use a microphone feature or a live voice conversation, your audio is transmitted so it can be converted into text and, for a live call, answered in real time.
- We do not store your audio. It exists only for the moments it takes to process it. Only the resulting text is saved, as described in 3.2.
3.4 Purchases
- The product you bought, the store order identifier, the store purchase token and signature, the reference price, and whether verification succeeded.
- Your in-app balance and the ledger of credits granted and spent, including rewarded-ad views.
- We never receive or store your card number, bank details or billing address. All payments are processed by Google Play or the Apple App Store; we only receive the confirmation of a purchase.
3.5 Analytics, diagnostics and advertising
- Firebase Analytics — aggregated in-app interactions (screens opened, features used).
- Firebase Crashlytics — crash reports and diagnostic data (device model, OS version, stack traces) so we can fix failures.
- Firebase Cloud Messaging — your push token, only if you grant the notification permission.
- Google AdMob — banner, interstitial and rewarded ads, using the advertising identifier.
3.6 What we do NOT collect
We do not request or collect: your location (our Apps ask for no location permission), your contacts, your calendar, your SMS or email, your browsing history, the list of apps installed on your device, health or fitness data, or any special-category data such as your ethnicity, religion, political opinions or sexual orientation.
Please also avoid typing information you do not want stored — such as full names, addresses, account numbers or health details about yourself or others — into a chat, because chat text is saved as described in Section 6.
4. Why we use your data (and on what legal basis)
| Purpose | Data used | Legal basis |
|---|---|---|
| Running the App: signing you in, delivering AI replies and voice calls, keeping your history, applying your balance | Identifiers, content, voice, purchases | Performance of a contract |
| Preventing fraud and abuse: stopping account takeover, blocking repeated claiming of free rewards, validating purchases | IP address, IP hash, identifiers, purchase records | Legitimate interests / legal duty |
| Improving the Apps: understanding which features are used, fixing crashes | Analytics, crash and diagnostic data | Legitimate interests |
| Showing ads to fund the free tier | Advertising identifier | Consent where required |
| Notifications you opted into | Push token | Consent |
| Meeting tax, accounting and legal duties | Purchase records | Legal duty |
We do not use your content to train our own AI models, and we do not sell your personal data.
5. Who processes your data
We use the following providers. They act on our instructions as processors, except for Google’s advertising services, which also act for their own purposes.
- OpenRouter — receives the text of your messages, and the URL of an attached image, in order to generate an AI reply.
- OpenAI — receives recorded audio for speech-to-text, and the live audio stream during a voice conversation.
- DigitalOcean (Spaces object storage) — stores the photos and documents you attach.
- Google Play Billing / Apple App Store — process purchases.
- Google Firebase (Analytics, Crashlytics, Cloud Messaging) — analytics, crash reporting and notifications.
- Google AdMob — serves and measures ads using the advertising identifier. This is the only case in which data is shared with a third party acting for its own purposes.
These providers may process data outside your country, including in the United States. Where required, such transfers rely on the European Commission’s Standard Contractual Clauses or an equivalent safeguard.
6. How long we keep data
| Data | Retention |
|---|---|
| Messages and voice transcripts | Until you delete the conversation in the App, or until your data is deleted under Section 7. |
| Attached photos and documents | Same as above. |
| Voice audio | Not stored. Processed transiently only. |
| Anonymous account, identifiers, balance and ledger | Until deletion under Section 7, or after 24 months of complete inactivity, whichever comes first. |
| Sign-in IP address | Overwritten at each new sign-in. |
| Abuse-prevention IP hashes | 90 days. |
| Crash and analytics data | Per Firebase defaults (up to 14 months for analytics; 90 days for crash data). |
| Purchase records | Up to 10 years, where tax and accounting law requires it. Kept even after account deletion, but detached from your content. |
7. Data deletion
7.1 Delete a single conversation, yourself, at any time
Open the conversation, use its menu and choose to clear it. Every message in that conversation, and its stored attachments, are permanently removed from our servers. This cannot be undone.
7.2 Delete everything (full account deletion)
Because our Apps have no login, we identify your data by your anonymous device code or your recovery code. To have all of it erased:
- Open the App, go to Settings and copy your recovery code (or your device code, shown in the same screen).
- Email bilisamweb@gmail.com with the subject “Data Deletion Request”. In the body, paste that code and state which App it belongs to.
- We reply to confirm, and complete the deletion within 30 days.
You may also send the request from our data deletion page.
A request covers the App whose code you send. If you use more than one of our Apps and want all of them erased, say so in the email and include the code from each one — the accounts are separate and cannot be linked by us.
7.3 What is deleted
- Your anonymous account record, session token and stored hashes.
- All messages and voice transcripts.
- All photos and documents you attached, deleted from object storage.
- Your balance, credit lots and credit ledger.
- Your push token and the analytics/crash identifiers we can map to you.
7.4 What is retained, and why
- Purchase and refund records required by tax and accounting law, kept for the period in Section 6 and separated from your content.
- Irreversible hashes used for abuse prevention, which cannot be traced back to you.
- Aggregated, anonymous statistics that no longer identify anyone.
7.5 Consequences
Deletion is permanent and irreversible. Any unused credits, remaining subscription time and your entire history are lost and cannot be restored or refunded. If you buy again afterwards, you start with a new anonymous account.
7.6 Uninstalling an App
Uninstalling removes the local copy of your data on the device, but it does not delete the data held on our servers. Use 7.1 or 7.2 for that. Note that clearing app data or uninstalling without saving your recovery code may make it impossible for us to identify your account for a later deletion request.
8. Security
All traffic between our Apps, our servers and our providers uses HTTPS/TLS. Device secrets and recovery codes are stored only as SHA-256 hashes, never in plain text. Access to production data is limited to the people who need it, and balances and purchases are validated on the server so they cannot be altered from a device. No system is perfectly secure, but we take these measures seriously and review them regularly. See also our security policy.
9. Your rights
Depending on where you live (including under the GDPR in the EU/UK and the KVKK in Türkiye), you may have the right to: access your data; correct it; have it erased; restrict or object to its processing; receive a portable copy; and withdraw consent at any time — for example by turning off notifications, or by resetting or opting out of ad personalisation in your device settings (Android: Settings › Google › Ads; iOS: Settings › Privacy & Security › Tracking).
To exercise a right, email bilisamweb@gmail.com and include your recovery code or device code so that we can locate the correct anonymous account. We answer within 30 days. Exercising a right is free; we will tell you in advance in the rare case a request is manifestly excessive.
If you are not satisfied with our response, you may lodge a complaint with your national data protection authority.
10. Children
Our Apps are not directed to children. Apps dealing with adult subject matter are not intended for anyone under 13, and we do not knowingly collect data from them; each App’s store listing states its content rating. Users under the age of majority in their country should only use an App with the consent and supervision of a parent or guardian. If you believe a child has provided us with data, email bilisamweb@gmail.com and we will delete it. See also our child safety standards.
11. Third-party links
Our Apps may contain links to third-party sites or stores. We do not control them and are not responsible for their privacy practices. Please read their policies before providing them with data.
12. Changes to this policy
We may update this policy as our Apps change. The “Last updated” date at the top always reflects the current version, and material changes will be announced inside the App or on the store listing. Continuing to use an App after an update means you accept the revised policy.
13. Contact
USI Apps
Email: bilisamweb@gmail.com
Deletion requests: bilisamweb@gmail.com, subject “Data Deletion Request”.