Last Updated: September 4, 2026
1. INTRODUCTION
This Privacy Policy ("Policy") governs the collection, storage, processing, and disclosure of personal data and technical information obtained through the Identify AI mobile application (the "Application", "Service", "we", "us", or "our").
We are committed to maintaining the confidentiality, integrity, and security of user information. This Policy applies to all individuals who download, install, access, or interact with the Application ("User", "you", or "your"). By accessing or utilizing the Application, you acknowledge that you have read, understood, and consented to the practices described in this Policy. If you do not agree with these practices, you must discontinue use of the Application immediately.
2. INFORMATION WE COLLECT
2.1. Information Provided Voluntarily by You
- Visual Data and Captured Media: When you capture a photograph through your device camera or select an image from your device storage to utilize identification features, the image file is temporarily processed to identify subjects (including plants, animals, insects, fungi, minerals, coins, and everyday objects) and to generate classification data.
- AI Consultation Inquiries: Textual inputs, questions, and contextual parameters submitted to our artificial intelligence consultation features are processed to generate relevant informational responses.
- Support Communications: If you submit an inquiry, feedback, or support request to our designated contact email (support@identifyai.app), we collect your email address, device model, operating system version, and any correspondence records necessary to diagnose and resolve your inquiry.
2.2. Information Collected Automatically
- Device and Hardware Identifiers: We automatically collect technical specifications regarding your mobile device, including device model, manufacturer, operating system version, system language settings, screen resolution, and pseudonymous device identifiers.
- Performance and Diagnostic Telemetry: In the event of an application malfunction or crash, diagnostic stack traces, memory state logs, and execution metrics are recorded to isolate and remedy software defects.
- Aggregated Usage Metrics: We collect non-personally identifiable usage statistics, such as feature engagement frequencies, navigation pathways, session durations, and identification category preferences to optimize system responsiveness and usability.
2.3. Financial and Transaction Metadata
- Subscriptions and In-App Purchases: Identify AI offers auto-renewable subscriptions processed exclusively via Google Play In-App Billing. We do not receive, store, or process complete payment card numbers, bank credentials, or direct financial billing information. We receive only non-sensitive transaction tokens and metadata from Google Play and our payment infrastructure provider (RevenueCat, Inc.), including subscription tier, active status, purchase timestamp, and renewal date.
3. LEGAL BASES FOR PROCESSING (GDPR AND APPLICABLE LAWS)
For users located within the European Economic Area (EEA), the United Kingdom, and equivalent jurisdictions, our legal bases for processing personal data under the General Data Protection Regulation (Regulation (EU) 2016/679) include:
- Performance of a Contract (Art. 6(1)(b) GDPR): Processing necessary to deliver core application functionality, including AI-driven object analysis, result delivery, and premium subscription fulfillment.
- Consent (Art. 6(1)(a) GDPR): Explicit permission granted by you via operating system runtime prompts for device hardware access, specifically camera capture and media library selection.
- Legitimate Interests (Art. 6(1)(f) GDPR): Processing necessary to maintain application security, diagnose stability issues, prevent fraudulent activity, and enhance user experience, provided such interests are not overridden by your fundamental rights.
- Compliance with Legal Obligations (Art. 6(1)(c) GDPR): Adherence to mandatory statutory, regulatory, tax, or accounting frameworks.
4. ARTIFICIAL INTELLIGENCE PROCESSING AND BIOMETRIC DISCLAIMER
- Ephemeral Analysis: Images submitted for identification are transmitted via secure cryptographic protocols (TLS/HTTPS) to cloud-based machine learning inference endpoints (including Google Cloud and Vertex AI infrastructure). Image processing is conducted ephemerally for the purpose of classification, feature extraction, and textual summary generation.
- No Biometric Identification: Identify AI is engineered to classify objects, fauna, flora, and general items. We do not extract facial geometry, biometric identifiers, or personal behavioral profiles from images, nor do we deploy facial recognition technology.
- Model Training: Images submitted through the standard consumer version of the Application are not utilized to train publicly accessible machine learning models without explicit authorization.
5. DEVICE PERMISSIONS
To execute core operations, the Application requests specific operating system permissions:
- Camera (android.permission.CAMERA): Required exclusively to capture real-time photographs of items for visual analysis.
- Read Media and Storage (android.permission.READ_MEDIA_IMAGES): Required when you choose to import existing photographs from your gallery for classification.
- Internet (android.permission.INTERNET): Required to establish encrypted connections with cloud processing endpoints, validate active subscription statuses, and transmit stability telemetry.
You retain the right to revoke these permissions at any time via your device operating system settings. Revocation of permissions will restrict corresponding features (such as disabling real-time camera capture).
6. THIRD-PARTY SERVICE PROVIDERS AND SUB-PROCESSORS
We engage vetted third-party vendors who provide specialized infrastructure, diagnostic tools, and payment services. These entities process data strictly under our instructions and in compliance with appropriate data processing agreements:
- Google LLC (Firebase Analytics, Crashlytics, Performance Monitoring, Remote Config, App Check): Real-time application health monitoring, stability diagnostics, and aggregated usage metrics. Privacy Policy: https://policies.google.com/privacy
- Google Cloud Platform and Vertex AI (Google LLC): Scalable visual inference and natural language processing infrastructure. Privacy Policy: https://cloud.google.com/terms/cloud-privacy-notice
- RevenueCat, Inc.: Subscription receipt validation, cross-platform entitlement tracking, and lifecycle management. Privacy Policy: https://www.revenuecat.com/privacy
- Google Play In-App Billing (Google LLC): Payment processing and subscription fulfillment. Terms: https://play.google.com/about/play-terms
7. DATA STORAGE, RETENTION, AND DELETION
- Local Storage: Your historical identification logs, pinned favorites, and organized collections are stored locally on your device within an encrypted Room SQLite database. You may permanently delete individual items or clear the entire history at any time through the in-app settings interface. Uninstalling the Application purges all locally stored data.
- Diagnostic Logs: Telemetry collected by diagnostic providers is retained on secure servers for a limited period (typically between 90 days and 14 months) before automated purging or aggregation into anonymous statistical records.
- Ephemeral Inference Buffers: Images transmitted for classification are retained in memory only for the duration required to generate the classification response, after which temporary processing buffers are discarded.
8. INTERNATIONAL DATA TRANSFERS
Information collected may be transferred to, stored, and processed in servers situated in the United States and other international jurisdictions where our service providers maintain facilities. When transfers occur from the EEA, UK, or Switzerland to countries without an adequacy decision, we ensure appropriate safeguards are implemented, including standard contractual clauses approved by the European Commission.
9. DATA SECURITY
We implement rigorous technical and organizational safeguards designed to protect personal information against unauthorized access, destruction, loss, alteration, or disclosure. All network communications are secured using Transport Layer Security (TLS 1.3/HTTPS) with standard cipher suites. While we employ industry-standard safeguards, no transmission over the Internet or electronic storage mechanism can be guaranteed to be absolutely secure.
10. DATA PROTECTION RIGHTS
In accordance with applicable data protection legislation (including GDPR, UK GDPR, CCPA/CPRA, and KVKK), you possess specific rights regarding your personal data:
- Right of Access: You may request confirmation of whether your data is being processed and obtain a copy of relevant records.
- Right to Rectification: You may request the correction of inaccurate or incomplete personal information.
- Right to Erasure: You may request the permanent deletion of personal information held by us, subject to statutory retention exceptions. Local discovery history can be erased directly within the Application.
- Right to Restriction of Processing: You may request the temporary suspension of processing under specified statutory grounds.
- Right to Data Portability: You may request your data in a structured, machine-readable format.
- Right to Object: You have the right to object to data processing grounded on legitimate interests.
- Right to Withdraw Consent: Where processing relies upon consent, you may withdraw your consent at any time without affecting the lawfulness of processing undertaken prior to withdrawal.
To submit a request regarding your statutory data rights, contact us at support@identifyai.app. We respond to verified requests within statutory timeframes.
11. CALIFORNIA PRIVACY DISCLOSURES (CCPA / CPRA)
Under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- We do not sell your personal information to third parties.
- We do not share your personal information for cross-context behavioral advertising.
- We do not collect or process sensitive personal information for purposes other than performing services reasonably expected by an average consumer.
12. PROTECTION OF MINORS
The Application is not intended for use by individuals under the age of 13 (or under 16 in specified jurisdictions). We do not knowingly collect personal information from children. If we discover that personal data from a minor has been received without verified parental consent, we will promptly execute procedures to delete such information from our records. If you believe a minor has provided information to us, please notify us at hallerappsinfo@.gmail.com
13. AMENDMENTS TO THIS PRIVACY POLICY
We reserve the right to revise or update this Policy at our discretion to accommodate technological modifications, regulatory revisions, or operational enhancements. Updates will be posted within this document, and the "Last Updated" date will reflect the revision time. Continued use of the Application after an amendment constitutes acceptance of the updated terms.
14. CONTACT AND REGULATORY INQUIRIES
For inquiries, notices, or grievances regarding this Privacy Policy or our data governance practices, please contact:
Identify AI
Email: hallerappsinfo@gmail.com