Document libraryکتابخانه‌ی اسناد

Privacy Policyحریم خصوصی

What information we collect about users and what we do with it.چه اطلاعاتی از کاربر می‌گیریم و با آن چه می‌کنیم.Privacy Policy

Draft — not final. Do not publish until our lawyer approves it.پیش‌نویس است و هنوز نهایی نیست؛ تا تأیید وکیل منتشر نشود.

It still has 114 gaps, shown in yellowهنوز ۱۱۴ جای خالی دارد که زرد نشان داده شده [OPEN: …] · What to fill inچه چیزی پر شود

The text below is in English — the official text.متن زیر انگلیسی است؛ متن رسمی همین است.
Technical detailsجزئیات فنی
draftپیش‌نویس
IDشناسهPOL-PRIV-002
Versionنسخه2.3
OwnerمسئولLegal Lead (to be appointed) with CTO
Counsel reviewبررسی وکیلnone
Next reviewبررسی بعدی2026-10-09
Fileفایلknowledge-base/05-Policies-Public/drafts/POL-PRIV-002_PRIVACY_POLICY_v2.3-draft.md

Privacy Policy — draft

Prepared for review by licensed counsel. Not legal advice. Part B is the proposed public text; Parts A and C are internal. Statements about data practices that Engineering has not confirmed (EV-201 to EV-206) are bracketed [ENGINEERING]; unbracketed statements in Part B are limited to entity facts (EV-211a) and descriptions of legal rights. Part B may not be published while any bracket remains, and the publication gate in AUD-2026-09-11 §4 applies.

Part A — Drafting brief (internal)

A.1 What changed from v2.0 (2026-09-07)

Topicv2.0v2.1Reason
Apple Guideline 5.4 commitmentMissingNew §2 with two alternatives tied to the advertising decisionG-3; RSK-035; EV-106 (Verified)
Contactssupport@ with "Privacy Request" subjectprivacy@ and legalrequests@ per POL-ID-001G-9; POL-ID-001 C.2(9)
Controller identity and addressSuite 9375 as "principal mailing address"Entity block per DEC-2026-001 §6.1DEC-2026-001
EU/UK representatives"will be posted … before the requirement applies"Explicit [OPEN] fields; DSA contact pointsRSK-049; EV-231
Feature-level data handling"should remain on the device"Stated as fact only after engineering confirmation; otherwise bracketedKB-002 B2; G-14
Cookies, deletion, subprocessors, legal requestsDetailed hereSummaries here; detail in POL-COOK-001, POL-DEL-001, POL-SUB-001, POL-LE-001Single source of truth
"Zareh" named as a providerNamedNamed only after its legal entity and country are verified and sanctions-screenedRSK-033
U.S. state noticeGeneralApplicability statement pending research (EV-233)—
Internal checklistInside the public textPart CPublication hygiene

A.2 Inputs that block publication

Engineering logging attestation (EV-201–205); SDK inventory from production builds (EV-206); advertising decision (BRF-2026-001 D4); consent management live (P2-2); retention schedule implemented (POL-RET); mailboxes live; DEC-2026-001 adopted; claims clean-up (P0-4) published at the same time; counsel sign-off.

Part B — Proposed public text

Privacy Policy

Version: 2.2 [OPEN: renumber on publication] · Effective: [OPEN: date] · Last updated: [OPEN: date]

[COUNSEL: publish together with the change notice that corrects earlier references to "NebulaVPN Inc." and an address in Panama — DEC-2026-001 §7.1; RSK-047]

Summary

  • Who we are: HidzoVPN, Inc., a Florida corporation, is responsible for your personal information when you use HidzoVPN.
  • Your VPN traffic: while the VPN is on, your internet traffic passes through our servers so that it can reach its destination. We do not record the websites you visit, the content of your traffic or your DNS queries [ENGINEERING: logging attestation, EV-201–EV-205; claims register entry required].
  • What we do keep: limited account, subscription, device and connection information needed to run the service, apply plan limits, prevent abuse and meet legal duties, for the periods in Section 11 [ENGINEERING].
  • Advertising: [OPEN — BRF-2026-001 D4: describe the advertising model chosen; see Section 2]
  • Your choices and rights: Sections 13 to 16.

This Privacy Policy explains how HidzoVPN, Inc. ("HidzoVPN", "we", "us" or "our") collects, uses, shares and protects personal information when you use our apps, websites, VPN service, accounts, billing and support (the "Services").

1. Who is responsible for your information

HidzoVPN, Inc., a Florida profit corporation (Florida Department of State document number P25000060442), is the controller of the personal information described in this Policy. Mailing address: 7901 4th Street North, Suite 9375, Saint Petersburg, FL 33702, United States. Contact details for each purpose are on our Legal Information page [OPEN: link]. Privacy requests: [OPEN: [email protected]].

Apple and Google (for app-store purchases and distribution) [COUNSEL: and our payment processor, for its own fraud-prevention and legal purposes; and, if applicable under Section 2, advertising providers] process some information under their own privacy notices, as independent businesses.

2. Our commitment for the VPN service

[OPEN — BRF-2026-001 D4; COUNSEL — Apple Guideline 5.4 requires that apps offering VPN services "may not sell, use, or disclose to third parties any data for any purpose, and must commit to this in their privacy policy" (EV-106, Verified). Choose one alternative. If Alternative A is chosen, Sections 1, 3.5, 5, 7, 9, 13 and 16 must be conformed with an explicit platform split, and the Apple privacy label rebuilt.]

Alternative A — no third-party data disclosure in the iOS app: In our iOS app, we do not sell data to third parties, and we do not disclose data to third parties or allow third parties to use it for their own purposes. We disclose data only to service providers that process it on our instructions to provide the Services, and where the law requires us to do so. [COUNSEL: whether Apple, Google, the payment processor, Sign in with Apple/Google, resellers and a successor fit these exceptions; whether voluntary emergency disclosure and "with your permission" (Section 9) must be excluded for iOS]

Alternative B — iOS as in Alternative A; advertising in the Free Service on Android and the website: [COUNSEL and ENGINEERING: iOS text as in Alternative A. For Android and the website: name the advertising networks, the data they receive, the consent obtained, and the Google Play VpnService prominent-disclosure screen (G-5). Not drafted until D4 is decided.]

3. Information we process

3.1 Account information

If you create an account: your email address, an internal account identifier, your plan and subscription status, the devices linked to your account and your sign-in method [ENGINEERING: fields]. If you sign in with Apple or Google, we receive an identifier and the email address the provider shares (Apple may share a private relay address) [ENGINEERING: sign-in methods offered]. We do not receive your Apple or Google password. One-time sign-in codes expire after [ENGINEERING: 10 minutes] and are stored only in protected form [ENGINEERING].

3.2 Device and app information

When you use the app, with or without an account: an installation or device identifier, device model, operating system and app version, language, time zone and the IP address used to contact our servers [ENGINEERING: fields]. In the Free Service, the installation identifier is used to apply session limits and waiting periods and to prevent abuse [ENGINEERING: EV-205].

3.3 VPN connection information

To connect you, our systems process: your IP address at the time of connection, a session identifier, your account or installation identifier, the server and protocol selected, the internal tunnel address, connection status and errors, the number of simultaneous connections, connection start and end times and the amount of data transferred [ENGINEERING: confirm each field, where it is stored and for how long — EV-201, EV-205]. We use this information to establish and end connections, enforce device and plan limits, keep the network reliable and prevent abuse. Section 11 states how long it is kept.

We do not record the content of your VPN traffic, the websites or destinations you visit, or your DNS queries, and we do not keep a history that links those destinations to you. We do not use VPN traffic for advertising, analytics or profiling. [ENGINEERING: attestation required for both sentences; claims register entry required]

The IP address from which you connect is visible to our systems while the connection is set up. The providers that host our servers and the networks that carry traffic may process network information under their own legal obligations.

3.4 Purchase information

For trials and subscriptions: plan, purchase channel, transaction identifiers, dates, price, currency, billing country, subscription and refund status and fraud signals. Apple and Google process payments for store purchases and send us confirmation of your entitlement. For website purchases, our payment processor [OPEN: Stripe entity] collects your payment details; we receive [ENGINEERING: e.g. a payment token, card type and last four digits, billing country and payment status]. [OPEN — BRF-2026-001 D7: cryptocurrency purchases — wallet address, transaction hash, asset and amount]

3.5 Advertising and measurement information

[OPEN — depends on Section 2 and the SDK inventory (EV-206)] Where advertising is shown, the advertising provider may receive [ENGINEERING: list]. Measurement and analytics tools may receive app events such as installation, account creation, trial start and purchase [ENGINEERING: named tools and events]. We do not send VPN traffic, DNS queries, destinations, sign-in codes or payment details to these providers [ENGINEERING: EV-206].

3.6 Diagnostics and security information

Crash reports, app performance data, API request records, sign-in attempts, rate-limit events and abuse reports, used to keep the Services working and secure [ENGINEERING: whether these records contain IP addresses — CLM-024].

3.7 Support and communications

Messages and attachments you send us, and records of our replies. If you agree to receive marketing emails, your email address and your preference.

3.8 Website information

IP address, browser and device type, pages viewed and cookie identifiers. See our Cookie Notice [OPEN: link — POL-COOK-001].

3.9 Information from other sources

We receive information from: Apple and Google (sign-in, purchases and entitlements); our payment processor (payment status and fraud signals); [OPEN — D4: advertising and measurement providers]; [OPEN — POL-RTOS-001 §0: resellers, only the contact details needed to resolve a specific support or fraud case (POL-RPRIV-001 §2), if a reseller program is launched]; and people who report abuse, security vulnerabilities or legal issues to us.

3.10 What you must provide

You must give us an email address or sign-in identifier to create an account, and payment information to buy on our website. Without them we cannot provide those parts of the Services. Using the Free Service without an account does not require them, but the app cannot connect without the device and connection information in Sections 3.2 and 3.3 [ENGINEERING: confirm].

4. Features that use information on your device

FeatureWhat it usesWhere it stays
Split tunnelingThe list of apps installed on your device, to let you choose which apps use the VPN [ENGINEERING: platforms]On your device [ENGINEERING: confirm]
Trusted networks / auto-connectWi-Fi network namesOn your device [ENGINEERING: confirm]
Location / local network permission[ENGINEERING: whether requested, and why][ENGINEERING]
QR code scanningCamera, only when you choose to scan [ENGINEERING]The image is not stored or uploaded [ENGINEERING: confirm]
Paste / importClipboard, only when you tap Paste or Import [ENGINEERING]On your device [ENGINEERING: confirm]
Custom configurations (BYOC)Configuration files, keys and credentials you importOn your device, encrypted [ENGINEERING: confirm]
NotificationsA push tokenSent to Apple or Google to deliver notifications; [ENGINEERING: whether stored on our servers]
Weekly statisticsYour usage statistics[ENGINEERING: on device or on our servers — if on servers, reconcile with Section 11]

5. Why we use information

To provide and secure the Services; to manage accounts, subscriptions and billing; to apply Free Service limits and device limits; to prevent fraud and abuse and enforce our Terms; to monitor the reliability and performance of our systems; to measure how the apps are used and how users find us, without using VPN traffic; [OPEN — D4: to show advertising as described in Sections 2 and 3.5]; to respond to requests; to send service messages and, with your agreement where required, marketing; and to meet legal obligations and defend legal claims.

Legal basisProcessing
Performance of a contractAccounts, VPN connections, Free Service limits, subscriptions, billing, support
Legitimate interestsSecurity, fraud and abuse prevention, reliability, limited diagnostics, product improvement, legal claims; complying with U.S. tax, sanctions and legal-process requirements that apply to us
ConsentNon-essential cookies; storage of or access to information on your device that is not strictly necessary; personalized advertising; marketing emails; optional diagnostic uploads [COUNSEL: legal basis for contextual advertising, if any — D4]
Legal obligationObligations under the law of the European Union, the United Kingdom or Switzerland that apply to us [COUNSEL]

You may withdraw consent at any time; this does not affect processing that took place before.

7. Sale, sharing and targeted advertising

We do not sell personal information for money. We do not sell your VPN traffic, browsing destinations or DNS queries, and we do not keep records of them that could be disclosed [ENGINEERING: attestation]. [OPEN — depends on Section 2:] Under some U.S. state laws, giving advertising providers identifiers or app activity for targeted advertising may count as "selling", "sharing" or "targeted advertising" even if no money is paid. Where those laws apply to us, you can opt out as described in Section 16. If your browser sends a Global Privacy Control signal, we treat it as a request to opt out of the sale or sharing of your personal information and of targeted advertising for that browser or device and, if we know who you are, for your account [ENGINEERING: confirm] [COUNSEL: which state laws apply — EV-233].

8. Cookies and similar technologies

See our Cookie Notice [OPEN: link] for our website. In our apps, [ENGINEERING: describe the storage of or access to information on your device that is not strictly necessary, the consent tool used (for example Google UMP or App Tracking Transparency), and how to change your choice].

9. Who we share information with

  • Service providers that host our servers and systems, deliver email and notifications, provide customer support, process payments, measure app performance and help prevent fraud. We require them to protect the information to the same standard as this Policy and to use it only to provide their services to us [VERIFY: contract terms — POL-SUB-001]. The current list is in our List of Service Providers [OPEN: link — POL-SUB-001].
  • Apple and Google, for app-store purchases and distribution, and our payment processor for website purchases [COUNSEL: role].
  • Advertising and measurement providers [OPEN — Section 2].
  • Authorities, courts and parties to legal proceedings, when we are legally required to do so, or in an emergency involving danger of death or serious physical injury, as described in our Law Enforcement Guidelines [OPEN: link — POL-LE-001] [COUNSEL: whether to include voluntary emergency disclosure — Section 2]. We can only provide information we actually hold.
  • Resellers [OPEN — POL-RTOS-001 §0]: the contact details of a person who bought an Activation Code from that reseller, only where needed to resolve a specific support or fraud case; we do not tell resellers whether or by which account a code was activated [POL-RPRIV-001 §§2, 9; COUNSEL — Section 2].
  • A buyer or successor of our business, subject to this Policy.
  • Anyone else, with your permission [COUNSEL — Section 2].

10. International transfers

We are based in the United States. Your information is processed in the United States and in the countries where our service providers and VPN servers are located [OPEN: list countries or refer to POL-SUB-001]. The European Commission has adopted an adequacy decision for the United States only for organizations certified under the EU-U.S. Data Privacy Framework; HidzoVPN [OPEN: is not] certified [VERIFY]. For transfers from the European Economic Area, the United Kingdom or Switzerland to countries without an adequacy decision, we use the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or other lawful safeguards [COUNSEL: confirm the mechanism for each provider, given that HidzoVPN, Inc. is itself subject to the GDPR under Art. 3(2)]. You can ask us for a copy of the relevant safeguards.

11. How long we keep information

[ENGINEERING and FINANCE: each period must be implemented before publication — POL-RET-000]

InformationHow long
Account informationWhile your account exists; deleted within 30 days after we receive a deletion request, or after you confirm it if we ask you to [ENGINEERING]
Sign-in codesUntil they expire ([ENGINEERING: 10 minutes])
Sign-in sessions and tokensUntil you sign out or they expire, and no longer than [ENGINEERING: 30 days]
Free Service limit state (installation identifier and timing)[ENGINEERING]
Linked devicesWhile your account exists [ENGINEERING]
Live VPN session informationWhile the connection is active and up to [ENGINEERING: 15 minutes] after it ends
Usage statistics linked to an account or device[ENGINEERING: 24 hours], then deleted or de-identified
API, security and abuse recordsUp to [ENGINEERING: 30 days]; up to 24 months where needed for a specific incident, dispute or legal obligation
Blocked device and payment identifiers (fraud and abuse)Up to [ENGINEERING and COUNSEL: 24 months], or longer only for a documented incident or legal claim
Crash and diagnostic reportsUp to [ENGINEERING: 90 days]
Analytics and advertising measurementUp to [ENGINEERING: 13 months]
Push tokensUntil they become invalid, you disable notifications or you delete your account, then up to 30 days
Support messagesUp to 12 months after the request is closed, or until you delete your account, unless needed for an open matter
Marketing preferencesUntil you unsubscribe; we keep a minimal record so that we respect your choice
Purchase, tax and accounting recordsFor the period tax and accounting law requires [VERIFY and tax counsel: U.S. periods; EU VAT records may require up to 10 years]
Records of privacy requestsUp to 5 years [COUNSEL]
Information covered by a legal hold or open disputeUntil the hold or dispute ends
BackupsDeleted information is removed from backups within [ENGINEERING: 90 days]

"De-identified" means information that can no longer reasonably be linked to you; we do not try to re-identify it.

12. Deleting your account

You can delete your account in the app or as described in our Account and Data Deletion Policy [OPEN: link — POL-DEL-001] [ENGINEERING: in-app and web deletion]. Deleting your account cancels the renewal of a subscription bought on our website, but not of a subscription billed by Apple or Google [ENGINEERING: automatic cancellation of the Stripe subscription]. After deletion, we keep some information for the periods in Section 11, for example tax records, fraud and security records, and information covered by a legal hold.

13. Your choices

You can: update your account information; unsubscribe from marketing emails; change advertising and tracking choices in the app and in your device settings, including Apple's App Tracking Transparency [OPEN — D4]; change cookie choices on our website [ENGINEERING: consent management — BRF-2026-001 P2-2]; change device permissions in your device settings; and delete your account.

14. Your rights

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict certain processing, to withdraw consent, to opt out of the sale or sharing of personal information or targeted advertising, and not to be treated differently for exercising these rights.

To make a request, email [OPEN: [email protected]] from your account email and tell us which right you want to use. If you use the app without an account, include the installation identifier shown in [ENGINEERING: Settings → About]. We will verify your request in a way that is proportionate and will reply within the time the law requires. If we refuse your request, we will explain why. To appeal, email the same address with the subject "Privacy Appeal" within [OPEN: 60] days of our decision. Please do not send identity documents, passwords, sign-in codes or payment card numbers.

You can also complain to the data-protection authority where you live or work.

15. Additional information for the European Economic Area, the United Kingdom and Switzerland

Right to object. You can object at any time to our use of your information based on legitimate interests, and to direct marketing. If you object to direct marketing, we will stop.

[COUNSEL — RSK-049; EV-231]

  • EU representative (GDPR Article 27): [OPEN: name and address. Assessment: the Art. 27(2)(a) exemption is unlikely to apply to continuous processing]
  • UK representative (UK GDPR Article 27): [OPEN]
  • Swiss representative: [COUNSEL: whether required]
  • Data Protection Officer: [COUNSEL: whether required]

16. Additional information for U.S. residents

[COUNSEL: state which state laws apply to HidzoVPN — EV-233; do not state that a law applies if its thresholds are not met. If the CCPA applies, complete the table below under 11 CCR §7011(e).]

Category of personal informationExamplesSourcesPurposesCategories of recipientsSold or shared in the last 12 months?
IdentifiersEmail, account ID, installation ID, IP address [ENGINEERING]You; your device; Apple and GoogleSections 5, 9Service providers; app stores; [OPEN][OPEN — D4]
Customer and commercial recordsPlan, purchases, refundsYou; payment processor; app storesBilling, support, fraudService providers; payment processorNo [VERIFY]
Internet or network activityApp and website use, security records (not browsing destinations)Your deviceOperation, security, measurementService providers[OPEN — D4]
Approximate locationDerived from IP addressYour deviceLocalization, security, taxService providers[OPEN — D4]
Inferences[OPEN: only if used]————

We do not use or disclose sensitive personal information for purposes other than those the law permits [COUNSEL]. We do not knowingly sell or share the personal information of consumers under 16. To opt out of the sale or sharing of personal information or targeted advertising, use [OPEN: "Your Privacy Choices" link] or send a Global Privacy Control signal (Section 7). You may use an authorized agent to make a request; we may ask the agent for proof of authority and ask you to confirm the request. We will not discriminate against you for exercising your rights.

17. Security

We use administrative, technical and physical measures to protect personal information [ENGINEERING: list only measures in place, e.g. encryption in transit, access controls, monitoring of our systems]. No method of transmitting or storing information is free of risk. If a security breach affects your personal information, we will notify you and the authorities where the law requires.

18. Automated decisions

We use automated rules to authenticate sessions, apply plan and device limits, and detect suspicious sign-ins, payments and abuse [ENGINEERING: confirm]. These rules may temporarily block a request or account. You can ask for a person to review a decision by contacting us.

19. Children

The Services are for people aged 18 and over [OPEN: align store age ratings — BRF-2026-001 P2-4]. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us and we will delete it.

20. Changes to this Policy

We will publish any update with its effective date. If a change is material, we will tell you in advance by email or in the app and, where the law requires, ask for your consent. Earlier versions are available on request [OPEN: or archive].

21. Contact

HidzoVPN, Inc., 7901 4th Street North, Suite 9375, Saint Petersburg, FL 33702, United States · Privacy: [OPEN: [email protected]] · Legal Information page: [OPEN: link]. This Policy is written in English; if a translation differs, the English version prevails unless the law of your place of residence requires otherwise.

Part C — Drafting notes (internal)

ElementBasisLabel
VPN data commitment (§2)Apple App Review Guideline 5.4 (updated 8 June 2026)Verified (EV-106)
GDPR notice content (§§1, 6, 10, 11, 14, 15)GDPR Art. 13Reported (A/B) — EU text as adopted, legislation.gov.uk (EV-255)
Representatives (§15)GDPR Art. 27(1) applies as soon as Art. 3(2) applies; the Art. 27(2)(a) exemption needs processing that is occasional and unlikely to result in a risk — a continuous VPN service is unlikely to qualify (assessment); UK GDPR Art. 27; DSA Art. 13Art. 27 Reported (EV-255); DSA Recital 29 Verified (EV-231); [COUNSEL: appoint or document exemption]
U.S. state notice (§16)CCPA "business" tests: revenue over $26,625,000 (adjusted from 1 Jan 2025), 100,000+ consumers or households bought/sold/shared, or 50%+ of revenue from selling or sharing (Cal. Civ. Code §1798.140(d)(1)) — the 50% test matters if ad revenue is "sharing"; privacy-policy content 11 CCR §7011(e); mobile app must link the privacy policy in its settings menu (§7011(d)); GPC honoured and its status displayed on the website (§7025(b), (c)(6)); a cookie banner is not by itself a valid sale/sharing opt-out (§7026(a)(4)). TDPSA: SBA small-business carve-out (§541.002(a)(3)) but no sale of sensitive data without consent (§541.107). Florida Digital Bill of Rights controller duties need >$1 billion revenue (Fla. Stat. §501.702) — not applicable11 CCR §§7011(d), 7025(c)(6), 7026(a)(4) Verified first-hand (CCPA regulations eff. 1 Jan 2026, EV-253); others Reported (EV-252, 254); applicability UNKNOWN — evidence needed: CA user counts, SDK data flows, revenue split, SBA size status
Cookies and consent (§§8, 13)ePrivacy Directive Art. 5(3); UK PECR reg. 6 and Sch. A1 (in force 5 Feb 2026)Reported (EV-256, EV-237)
Account deletion (§12)Apple Guideline 5.1.1(v) (in-app deletion mandatory); Google Play User Data policy (in-app and web deletion)Apple Verified first-hand (EV-257); Google Reported from official blog, live policy page [VERIFY] (EV-257)
App Tracking Transparency (§13)Apple Guideline 5.1.2(i) — tracking needs ATT permission and may not be a condition of functionality or compensation (relevant to rewarded ads)Reported (EV-257)
CIPA pen-register claims over website tagsCal. Penal Code §638.51; SB 690 (enrolled, presented to the Governor 4 Sep 2026) would leave §638.51 website/app claims to the Attorney General; §631 unaffectedPending — re-check after 30 Sep 2026 (EV-258)
No absolute privacy claimsClaims register (CLM-001–006, 009, 022, 024); FTC Act §5Internal rule

C.2 Engineering evidence required (A-INT)

EV-201 node logging per protocol; EV-202 DNS resolver retention; EV-203 API/auth log retention; EV-204 CDN/WAF logs; EV-205 session and device limit state; EV-206 SDK manifest; EV-212 GTM export; EV-213 backup/log shipping; EV-214 hosting providers with countries.

C.3 Limits of this analysis

Verified first-hand: Apple Guideline 5.4; DSA Recital 29. Pending research (EV-233): all other privacy law cited. Not reviewed: privacy laws of Turkey (KVKK), Indonesia (PDP Law), Saudi Arabia (PDPL), UAE, Brazil and other markets (RSK-023). Facts unknown: all C.2 items. Counsel required: U.S. privacy; EU/UK privacy; Apple 5.4 interpretation.

C.3a Items added from the full AI review (2026-09-25)

Apple Guideline 5.1.1(i) (third parties must provide the same or equal protection) — §9; Apple 5.4 in-app data declaration before use — A.2 companion requirement; GDPR Arts. 13(2)(e) (§3.10), 14(2)(f) (§3.9), 21(4) (§15), 6(3) (U.S. obligations moved to legitimate interests, §6); CCPA §7011(e) structure (§16); appeal route (§14); guest requests (§14); retention rows restored from POL-RET-000 (§11); GPC wording aligned with the Cookie Notice (§7); Stripe role left to counsel (§§1, 9; POL-SUB-001 SUB-02); DPF status (§10). New claims-register entry required for the §3.3 logging statements (the CLM-001 replacement wording about originating IP must not be used unless Engineering confirms no source-IP retention).

C.4 Review log

DateReviewerVerdictNotes
2026-09-07Counsel review draft v2.0—EV-301
2026-09-23AUD-2026-09-1114 gapsG-1…G-14
2026-09-25Drafted v2.1—See A.1
2026-09-25hidzo-counsel-reviewer (AI)REVISE (1 Blocker; 17 Majors)v2.2: Part B rewritten — Blocker PP-01 fixed (all unconfirmed practices bracketed; banner corrected); iOS-scoped Alt A; Alt B structure; see C.3a
2026-09-25hidzo-counsel-reviewer (AI) — cross-document final audit; research memos EV-232–235REVISE (set: 1 Blocker, 8 Majors)v2.3: cross-document redlines X-01–X-31 applied where they concern this document; authority labels updated from first-hand and research-memo checks (EV-238–264)