Privacy Policy — draft
Prepared for review by licensed counsel. Not legal advice. Part B is the proposed public text; Parts A and C are internal. Statements about data practices that Engineering has not confirmed (EV-201 to EV-206) are bracketed [ENGINEERING]; unbracketed statements in Part B are limited to entity facts (EV-211a) and descriptions of legal rights. Part B may not be published while any bracket remains, and the publication gate in AUD-2026-09-11 §4 applies.
Part A — Drafting brief (internal)
A.1 What changed from v2.0 (2026-09-07)
| Topic | v2.0 | v2.1 | Reason |
|---|---|---|---|
| Apple Guideline 5.4 commitment | Missing | New §2 with two alternatives tied to the advertising decision | G-3; RSK-035; EV-106 (Verified) |
| Contacts | support@ with "Privacy Request" subject | privacy@ and legalrequests@ per POL-ID-001 | G-9; POL-ID-001 C.2(9) |
| Controller identity and address | Suite 9375 as "principal mailing address" | Entity block per DEC-2026-001 §6.1 | DEC-2026-001 |
| EU/UK representatives | "will be posted … before the requirement applies" | Explicit [OPEN] fields; DSA contact points | RSK-049; EV-231 |
| Feature-level data handling | "should remain on the device" | Stated as fact only after engineering confirmation; otherwise bracketed | KB-002 B2; G-14 |
| Cookies, deletion, subprocessors, legal requests | Detailed here | Summaries here; detail in POL-COOK-001, POL-DEL-001, POL-SUB-001, POL-LE-001 | Single source of truth |
| "Zareh" named as a provider | Named | Named only after its legal entity and country are verified and sanctions-screened | RSK-033 |
| U.S. state notice | General | Applicability statement pending research (EV-233) | — |
| Internal checklist | Inside the public text | Part C | Publication hygiene |
A.2 Inputs that block publication
Engineering logging attestation (EV-201–205); SDK inventory from production builds (EV-206); advertising decision (BRF-2026-001 D4); consent management live (P2-2); retention schedule implemented (POL-RET); mailboxes live; DEC-2026-001 adopted; claims clean-up (P0-4) published at the same time; counsel sign-off.
Part B — Proposed public text
Privacy Policy
Version: 2.2 [OPEN: renumber on publication] · Effective: [OPEN: date] · Last updated: [OPEN: date]
[COUNSEL: publish together with the change notice that corrects earlier references to "NebulaVPN Inc." and an address in Panama — DEC-2026-001 §7.1; RSK-047]
Summary
- Who we are: HidzoVPN, Inc., a Florida corporation, is responsible for your personal information when you use HidzoVPN.
- Your VPN traffic: while the VPN is on, your internet traffic passes through our servers so that it can reach its destination. We do not record the websites you visit, the content of your traffic or your DNS queries [ENGINEERING: logging attestation, EV-201–EV-205; claims register entry required].
- What we do keep: limited account, subscription, device and connection information needed to run the service, apply plan limits, prevent abuse and meet legal duties, for the periods in Section 11 [ENGINEERING].
- Advertising: [OPEN — BRF-2026-001 D4: describe the advertising model chosen; see Section 2]
- Your choices and rights: Sections 13 to 16.
This Privacy Policy explains how HidzoVPN, Inc. ("HidzoVPN", "we", "us" or "our") collects, uses, shares and protects personal information when you use our apps, websites, VPN service, accounts, billing and support (the "Services").
1. Who is responsible for your information
HidzoVPN, Inc., a Florida profit corporation (Florida Department of State document number P25000060442), is the controller of the personal information described in this Policy. Mailing address: 7901 4th Street North, Suite 9375, Saint Petersburg, FL 33702, United States. Contact details for each purpose are on our Legal Information page [OPEN: link]. Privacy requests: [OPEN: [email protected]].
Apple and Google (for app-store purchases and distribution) [COUNSEL: and our payment processor, for its own fraud-prevention and legal purposes; and, if applicable under Section 2, advertising providers] process some information under their own privacy notices, as independent businesses.
2. Our commitment for the VPN service
[OPEN — BRF-2026-001 D4; COUNSEL — Apple Guideline 5.4 requires that apps offering VPN services "may not sell, use, or disclose to third parties any data for any purpose, and must commit to this in their privacy policy" (EV-106, Verified). Choose one alternative. If Alternative A is chosen, Sections 1, 3.5, 5, 7, 9, 13 and 16 must be conformed with an explicit platform split, and the Apple privacy label rebuilt.]
Alternative A — no third-party data disclosure in the iOS app: In our iOS app, we do not sell data to third parties, and we do not disclose data to third parties or allow third parties to use it for their own purposes. We disclose data only to service providers that process it on our instructions to provide the Services, and where the law requires us to do so. [COUNSEL: whether Apple, Google, the payment processor, Sign in with Apple/Google, resellers and a successor fit these exceptions; whether voluntary emergency disclosure and "with your permission" (Section 9) must be excluded for iOS]
Alternative B — iOS as in Alternative A; advertising in the Free Service on Android and the website: [COUNSEL and ENGINEERING: iOS text as in Alternative A. For Android and the website: name the advertising networks, the data they receive, the consent obtained, and the Google Play VpnService prominent-disclosure screen (G-5). Not drafted until D4 is decided.]
3. Information we process
3.1 Account information
If you create an account: your email address, an internal account identifier, your plan and subscription status, the devices linked to your account and your sign-in method [ENGINEERING: fields]. If you sign in with Apple or Google, we receive an identifier and the email address the provider shares (Apple may share a private relay address) [ENGINEERING: sign-in methods offered]. We do not receive your Apple or Google password. One-time sign-in codes expire after [ENGINEERING: 10 minutes] and are stored only in protected form [ENGINEERING].
3.2 Device and app information
When you use the app, with or without an account: an installation or device identifier, device model, operating system and app version, language, time zone and the IP address used to contact our servers [ENGINEERING: fields]. In the Free Service, the installation identifier is used to apply session limits and waiting periods and to prevent abuse [ENGINEERING: EV-205].
3.3 VPN connection information
To connect you, our systems process: your IP address at the time of connection, a session identifier, your account or installation identifier, the server and protocol selected, the internal tunnel address, connection status and errors, the number of simultaneous connections, connection start and end times and the amount of data transferred [ENGINEERING: confirm each field, where it is stored and for how long — EV-201, EV-205]. We use this information to establish and end connections, enforce device and plan limits, keep the network reliable and prevent abuse. Section 11 states how long it is kept.
We do not record the content of your VPN traffic, the websites or destinations you visit, or your DNS queries, and we do not keep a history that links those destinations to you. We do not use VPN traffic for advertising, analytics or profiling. [ENGINEERING: attestation required for both sentences; claims register entry required]
The IP address from which you connect is visible to our systems while the connection is set up. The providers that host our servers and the networks that carry traffic may process network information under their own legal obligations.
3.4 Purchase information
For trials and subscriptions: plan, purchase channel, transaction identifiers, dates, price, currency, billing country, subscription and refund status and fraud signals. Apple and Google process payments for store purchases and send us confirmation of your entitlement. For website purchases, our payment processor [OPEN: Stripe entity] collects your payment details; we receive [ENGINEERING: e.g. a payment token, card type and last four digits, billing country and payment status]. [OPEN — BRF-2026-001 D7: cryptocurrency purchases — wallet address, transaction hash, asset and amount]
3.5 Advertising and measurement information
[OPEN — depends on Section 2 and the SDK inventory (EV-206)] Where advertising is shown, the advertising provider may receive [ENGINEERING: list]. Measurement and analytics tools may receive app events such as installation, account creation, trial start and purchase [ENGINEERING: named tools and events]. We do not send VPN traffic, DNS queries, destinations, sign-in codes or payment details to these providers [ENGINEERING: EV-206].
3.6 Diagnostics and security information
Crash reports, app performance data, API request records, sign-in attempts, rate-limit events and abuse reports, used to keep the Services working and secure [ENGINEERING: whether these records contain IP addresses — CLM-024].
3.7 Support and communications
Messages and attachments you send us, and records of our replies. If you agree to receive marketing emails, your email address and your preference.
3.8 Website information
IP address, browser and device type, pages viewed and cookie identifiers. See our Cookie Notice [OPEN: link — POL-COOK-001].
3.9 Information from other sources
We receive information from: Apple and Google (sign-in, purchases and entitlements); our payment processor (payment status and fraud signals); [OPEN — D4: advertising and measurement providers]; [OPEN — POL-RTOS-001 §0: resellers, only the contact details needed to resolve a specific support or fraud case (POL-RPRIV-001 §2), if a reseller program is launched]; and people who report abuse, security vulnerabilities or legal issues to us.
3.10 What you must provide
You must give us an email address or sign-in identifier to create an account, and payment information to buy on our website. Without them we cannot provide those parts of the Services. Using the Free Service without an account does not require them, but the app cannot connect without the device and connection information in Sections 3.2 and 3.3 [ENGINEERING: confirm].
4. Features that use information on your device
| Feature | What it uses | Where it stays |
|---|---|---|
| Split tunneling | The list of apps installed on your device, to let you choose which apps use the VPN [ENGINEERING: platforms] | On your device [ENGINEERING: confirm] |
| Trusted networks / auto-connect | Wi-Fi network names | On your device [ENGINEERING: confirm] |
| Location / local network permission | [ENGINEERING: whether requested, and why] | [ENGINEERING] |
| QR code scanning | Camera, only when you choose to scan [ENGINEERING] | The image is not stored or uploaded [ENGINEERING: confirm] |
| Paste / import | Clipboard, only when you tap Paste or Import [ENGINEERING] | On your device [ENGINEERING: confirm] |
| Custom configurations (BYOC) | Configuration files, keys and credentials you import | On your device, encrypted [ENGINEERING: confirm] |
| Notifications | A push token | Sent to Apple or Google to deliver notifications; [ENGINEERING: whether stored on our servers] |
| Weekly statistics | Your usage statistics | [ENGINEERING: on device or on our servers — if on servers, reconcile with Section 11] |
5. Why we use information
To provide and secure the Services; to manage accounts, subscriptions and billing; to apply Free Service limits and device limits; to prevent fraud and abuse and enforce our Terms; to monitor the reliability and performance of our systems; to measure how the apps are used and how users find us, without using VPN traffic; [OPEN — D4: to show advertising as described in Sections 2 and 3.5]; to respond to requests; to send service messages and, with your agreement where required, marketing; and to meet legal obligations and defend legal claims.
6. Legal bases (European Economic Area, United Kingdom, Switzerland)
| Legal basis | Processing |
|---|---|
| Performance of a contract | Accounts, VPN connections, Free Service limits, subscriptions, billing, support |
| Legitimate interests | Security, fraud and abuse prevention, reliability, limited diagnostics, product improvement, legal claims; complying with U.S. tax, sanctions and legal-process requirements that apply to us |
| Consent | Non-essential cookies; storage of or access to information on your device that is not strictly necessary; personalized advertising; marketing emails; optional diagnostic uploads [COUNSEL: legal basis for contextual advertising, if any — D4] |
| Legal obligation | Obligations under the law of the European Union, the United Kingdom or Switzerland that apply to us [COUNSEL] |
You may withdraw consent at any time; this does not affect processing that took place before.
7. Sale, sharing and targeted advertising
We do not sell personal information for money. We do not sell your VPN traffic, browsing destinations or DNS queries, and we do not keep records of them that could be disclosed [ENGINEERING: attestation]. [OPEN — depends on Section 2:] Under some U.S. state laws, giving advertising providers identifiers or app activity for targeted advertising may count as "selling", "sharing" or "targeted advertising" even if no money is paid. Where those laws apply to us, you can opt out as described in Section 16. If your browser sends a Global Privacy Control signal, we treat it as a request to opt out of the sale or sharing of your personal information and of targeted advertising for that browser or device and, if we know who you are, for your account [ENGINEERING: confirm] [COUNSEL: which state laws apply — EV-233].
8. Cookies and similar technologies
See our Cookie Notice [OPEN: link] for our website. In our apps, [ENGINEERING: describe the storage of or access to information on your device that is not strictly necessary, the consent tool used (for example Google UMP or App Tracking Transparency), and how to change your choice].
9. Who we share information with
- Service providers that host our servers and systems, deliver email and notifications, provide customer support, process payments, measure app performance and help prevent fraud. We require them to protect the information to the same standard as this Policy and to use it only to provide their services to us [VERIFY: contract terms — POL-SUB-001]. The current list is in our List of Service Providers [OPEN: link — POL-SUB-001].
- Apple and Google, for app-store purchases and distribution, and our payment processor for website purchases [COUNSEL: role].
- Advertising and measurement providers [OPEN — Section 2].
- Authorities, courts and parties to legal proceedings, when we are legally required to do so, or in an emergency involving danger of death or serious physical injury, as described in our Law Enforcement Guidelines [OPEN: link — POL-LE-001] [COUNSEL: whether to include voluntary emergency disclosure — Section 2]. We can only provide information we actually hold.
- Resellers [OPEN — POL-RTOS-001 §0]: the contact details of a person who bought an Activation Code from that reseller, only where needed to resolve a specific support or fraud case; we do not tell resellers whether or by which account a code was activated [POL-RPRIV-001 §§2, 9; COUNSEL — Section 2].
- A buyer or successor of our business, subject to this Policy.
- Anyone else, with your permission [COUNSEL — Section 2].
10. International transfers
We are based in the United States. Your information is processed in the United States and in the countries where our service providers and VPN servers are located [OPEN: list countries or refer to POL-SUB-001]. The European Commission has adopted an adequacy decision for the United States only for organizations certified under the EU-U.S. Data Privacy Framework; HidzoVPN [OPEN: is not] certified [VERIFY]. For transfers from the European Economic Area, the United Kingdom or Switzerland to countries without an adequacy decision, we use the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or other lawful safeguards [COUNSEL: confirm the mechanism for each provider, given that HidzoVPN, Inc. is itself subject to the GDPR under Art. 3(2)]. You can ask us for a copy of the relevant safeguards.
11. How long we keep information
[ENGINEERING and FINANCE: each period must be implemented before publication — POL-RET-000]
| Information | How long |
|---|---|
| Account information | While your account exists; deleted within 30 days after we receive a deletion request, or after you confirm it if we ask you to [ENGINEERING] |
| Sign-in codes | Until they expire ([ENGINEERING: 10 minutes]) |
| Sign-in sessions and tokens | Until you sign out or they expire, and no longer than [ENGINEERING: 30 days] |
| Free Service limit state (installation identifier and timing) | [ENGINEERING] |
| Linked devices | While your account exists [ENGINEERING] |
| Live VPN session information | While the connection is active and up to [ENGINEERING: 15 minutes] after it ends |
| Usage statistics linked to an account or device | [ENGINEERING: 24 hours], then deleted or de-identified |
| API, security and abuse records | Up to [ENGINEERING: 30 days]; up to 24 months where needed for a specific incident, dispute or legal obligation |
| Blocked device and payment identifiers (fraud and abuse) | Up to [ENGINEERING and COUNSEL: 24 months], or longer only for a documented incident or legal claim |
| Crash and diagnostic reports | Up to [ENGINEERING: 90 days] |
| Analytics and advertising measurement | Up to [ENGINEERING: 13 months] |
| Push tokens | Until they become invalid, you disable notifications or you delete your account, then up to 30 days |
| Support messages | Up to 12 months after the request is closed, or until you delete your account, unless needed for an open matter |
| Marketing preferences | Until you unsubscribe; we keep a minimal record so that we respect your choice |
| Purchase, tax and accounting records | For the period tax and accounting law requires [VERIFY and tax counsel: U.S. periods; EU VAT records may require up to 10 years] |
| Records of privacy requests | Up to 5 years [COUNSEL] |
| Information covered by a legal hold or open dispute | Until the hold or dispute ends |
| Backups | Deleted information is removed from backups within [ENGINEERING: 90 days] |
"De-identified" means information that can no longer reasonably be linked to you; we do not try to re-identify it.
12. Deleting your account
You can delete your account in the app or as described in our Account and Data Deletion Policy [OPEN: link — POL-DEL-001] [ENGINEERING: in-app and web deletion]. Deleting your account cancels the renewal of a subscription bought on our website, but not of a subscription billed by Apple or Google [ENGINEERING: automatic cancellation of the Stripe subscription]. After deletion, we keep some information for the periods in Section 11, for example tax records, fraud and security records, and information covered by a legal hold.
13. Your choices
You can: update your account information; unsubscribe from marketing emails; change advertising and tracking choices in the app and in your device settings, including Apple's App Tracking Transparency [OPEN — D4]; change cookie choices on our website [ENGINEERING: consent management — BRF-2026-001 P2-2]; change device permissions in your device settings; and delete your account.
14. Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict certain processing, to withdraw consent, to opt out of the sale or sharing of personal information or targeted advertising, and not to be treated differently for exercising these rights.
To make a request, email [OPEN: [email protected]] from your account email and tell us which right you want to use. If you use the app without an account, include the installation identifier shown in [ENGINEERING: Settings → About]. We will verify your request in a way that is proportionate and will reply within the time the law requires. If we refuse your request, we will explain why. To appeal, email the same address with the subject "Privacy Appeal" within [OPEN: 60] days of our decision. Please do not send identity documents, passwords, sign-in codes or payment card numbers.
You can also complain to the data-protection authority where you live or work.
15. Additional information for the European Economic Area, the United Kingdom and Switzerland
Right to object. You can object at any time to our use of your information based on legitimate interests, and to direct marketing. If you object to direct marketing, we will stop.
[COUNSEL — RSK-049; EV-231]
- EU representative (GDPR Article 27): [OPEN: name and address. Assessment: the Art. 27(2)(a) exemption is unlikely to apply to continuous processing]
- UK representative (UK GDPR Article 27): [OPEN]
- Swiss representative: [COUNSEL: whether required]
- Data Protection Officer: [COUNSEL: whether required]
16. Additional information for U.S. residents
[COUNSEL: state which state laws apply to HidzoVPN — EV-233; do not state that a law applies if its thresholds are not met. If the CCPA applies, complete the table below under 11 CCR §7011(e).]
| Category of personal information | Examples | Sources | Purposes | Categories of recipients | Sold or shared in the last 12 months? |
|---|---|---|---|---|---|
| Identifiers | Email, account ID, installation ID, IP address [ENGINEERING] | You; your device; Apple and Google | Sections 5, 9 | Service providers; app stores; [OPEN] | [OPEN — D4] |
| Customer and commercial records | Plan, purchases, refunds | You; payment processor; app stores | Billing, support, fraud | Service providers; payment processor | No [VERIFY] |
| Internet or network activity | App and website use, security records (not browsing destinations) | Your device | Operation, security, measurement | Service providers | [OPEN — D4] |
| Approximate location | Derived from IP address | Your device | Localization, security, tax | Service providers | [OPEN — D4] |
| Inferences | [OPEN: only if used] | — | — | — | — |
We do not use or disclose sensitive personal information for purposes other than those the law permits [COUNSEL]. We do not knowingly sell or share the personal information of consumers under 16. To opt out of the sale or sharing of personal information or targeted advertising, use [OPEN: "Your Privacy Choices" link] or send a Global Privacy Control signal (Section 7). You may use an authorized agent to make a request; we may ask the agent for proof of authority and ask you to confirm the request. We will not discriminate against you for exercising your rights.
17. Security
We use administrative, technical and physical measures to protect personal information [ENGINEERING: list only measures in place, e.g. encryption in transit, access controls, monitoring of our systems]. No method of transmitting or storing information is free of risk. If a security breach affects your personal information, we will notify you and the authorities where the law requires.
18. Automated decisions
We use automated rules to authenticate sessions, apply plan and device limits, and detect suspicious sign-ins, payments and abuse [ENGINEERING: confirm]. These rules may temporarily block a request or account. You can ask for a person to review a decision by contacting us.
19. Children
The Services are for people aged 18 and over [OPEN: align store age ratings — BRF-2026-001 P2-4]. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us and we will delete it.
20. Changes to this Policy
We will publish any update with its effective date. If a change is material, we will tell you in advance by email or in the app and, where the law requires, ask for your consent. Earlier versions are available on request [OPEN: or archive].
21. Contact
HidzoVPN, Inc., 7901 4th Street North, Suite 9375, Saint Petersburg, FL 33702, United States · Privacy: [OPEN: [email protected]] · Legal Information page: [OPEN: link]. This Policy is written in English; if a translation differs, the English version prevails unless the law of your place of residence requires otherwise.
Part C — Drafting notes (internal)
C.1 Legal basis
| Element | Basis | Label |
|---|---|---|
| VPN data commitment (§2) | Apple App Review Guideline 5.4 (updated 8 June 2026) | Verified (EV-106) |
| GDPR notice content (§§1, 6, 10, 11, 14, 15) | GDPR Art. 13 | Reported (A/B) — EU text as adopted, legislation.gov.uk (EV-255) |
| Representatives (§15) | GDPR Art. 27(1) applies as soon as Art. 3(2) applies; the Art. 27(2)(a) exemption needs processing that is occasional and unlikely to result in a risk — a continuous VPN service is unlikely to qualify (assessment); UK GDPR Art. 27; DSA Art. 13 | Art. 27 Reported (EV-255); DSA Recital 29 Verified (EV-231); [COUNSEL: appoint or document exemption] |
| U.S. state notice (§16) | CCPA "business" tests: revenue over $26,625,000 (adjusted from 1 Jan 2025), 100,000+ consumers or households bought/sold/shared, or 50%+ of revenue from selling or sharing (Cal. Civ. Code §1798.140(d)(1)) — the 50% test matters if ad revenue is "sharing"; privacy-policy content 11 CCR §7011(e); mobile app must link the privacy policy in its settings menu (§7011(d)); GPC honoured and its status displayed on the website (§7025(b), (c)(6)); a cookie banner is not by itself a valid sale/sharing opt-out (§7026(a)(4)). TDPSA: SBA small-business carve-out (§541.002(a)(3)) but no sale of sensitive data without consent (§541.107). Florida Digital Bill of Rights controller duties need >$1 billion revenue (Fla. Stat. §501.702) — not applicable | 11 CCR §§7011(d), 7025(c)(6), 7026(a)(4) Verified first-hand (CCPA regulations eff. 1 Jan 2026, EV-253); others Reported (EV-252, 254); applicability UNKNOWN — evidence needed: CA user counts, SDK data flows, revenue split, SBA size status |
| Cookies and consent (§§8, 13) | ePrivacy Directive Art. 5(3); UK PECR reg. 6 and Sch. A1 (in force 5 Feb 2026) | Reported (EV-256, EV-237) |
| Account deletion (§12) | Apple Guideline 5.1.1(v) (in-app deletion mandatory); Google Play User Data policy (in-app and web deletion) | Apple Verified first-hand (EV-257); Google Reported from official blog, live policy page [VERIFY] (EV-257) |
| App Tracking Transparency (§13) | Apple Guideline 5.1.2(i) — tracking needs ATT permission and may not be a condition of functionality or compensation (relevant to rewarded ads) | Reported (EV-257) |
| CIPA pen-register claims over website tags | Cal. Penal Code §638.51; SB 690 (enrolled, presented to the Governor 4 Sep 2026) would leave §638.51 website/app claims to the Attorney General; §631 unaffected | Pending — re-check after 30 Sep 2026 (EV-258) |
| No absolute privacy claims | Claims register (CLM-001–006, 009, 022, 024); FTC Act §5 | Internal rule |
C.2 Engineering evidence required (A-INT)
EV-201 node logging per protocol; EV-202 DNS resolver retention; EV-203 API/auth log retention; EV-204 CDN/WAF logs; EV-205 session and device limit state; EV-206 SDK manifest; EV-212 GTM export; EV-213 backup/log shipping; EV-214 hosting providers with countries.
C.3 Limits of this analysis
Verified first-hand: Apple Guideline 5.4; DSA Recital 29. Pending research (EV-233): all other privacy law cited. Not reviewed: privacy laws of Turkey (KVKK), Indonesia (PDP Law), Saudi Arabia (PDPL), UAE, Brazil and other markets (RSK-023). Facts unknown: all C.2 items. Counsel required: U.S. privacy; EU/UK privacy; Apple 5.4 interpretation.
C.3a Items added from the full AI review (2026-09-25)
Apple Guideline 5.1.1(i) (third parties must provide the same or equal protection) — §9; Apple 5.4 in-app data declaration before use — A.2 companion requirement; GDPR Arts. 13(2)(e) (§3.10), 14(2)(f) (§3.9), 21(4) (§15), 6(3) (U.S. obligations moved to legitimate interests, §6); CCPA §7011(e) structure (§16); appeal route (§14); guest requests (§14); retention rows restored from POL-RET-000 (§11); GPC wording aligned with the Cookie Notice (§7); Stripe role left to counsel (§§1, 9; POL-SUB-001 SUB-02); DPF status (§10). New claims-register entry required for the §3.3 logging statements (the CLM-001 replacement wording about originating IP must not be used unless Engineering confirms no source-IP retention).
C.4 Review log
| Date | Reviewer | Verdict | Notes |
|---|---|---|---|
| 2026-09-07 | Counsel review draft v2.0 | — | EV-301 |
| 2026-09-23 | AUD-2026-09-11 | 14 gaps | G-1…G-14 |
| 2026-09-25 | Drafted v2.1 | — | See A.1 |
| 2026-09-25 | hidzo-counsel-reviewer (AI) | REVISE (1 Blocker; 17 Majors) | v2.2: Part B rewritten — Blocker PP-01 fixed (all unconfirmed practices bracketed; banner corrected); iOS-scoped Alt A; Alt B structure; see C.3a |
| 2026-09-25 | hidzo-counsel-reviewer (AI) — cross-document final audit; research memos EV-232–235 | REVISE (set: 1 Blocker, 8 Majors) | v2.3: cross-document redlines X-01–X-31 applied where they concern this document; authority labels updated from first-hand and research-memo checks (EV-238–264) |