---
doc_id: POL-PRIV-002
title: Privacy Policy — draft with drafting notes
type: policy-public
status: draft
version: 2.3
date: 2026-09-25
created: 2026-09-07
last_reviewed: 2026-09-25
next_review: 2026-10-09
law_checked: 2026-09-25 (Apple 5.4 and DSA Recital 29 first-hand; GDPR Arts. 6, 13, 14, 21, 27 and Apple 5.1.1(i) read by AI reviewer; remainder pending EV-233)
owner: Legal Lead (to be appointed) with CTO
reviewers: [hidzo-counsel-reviewer (AI), U.S. privacy counsel, EU/UK privacy counsel]
counsel_needed: yes
counsel_status: none
jurisdictions: [US, US-CA, US-TX, US-FL, EU, UK, CH]
related: [POL-TOS-002, POL-ID-001, POL-COOK-001, POL-DEL-001, POL-SUB-001, POL-LE-001, DEC-2026-001, BRF-2026-001]
sources: [EV-001, EV-106, EV-206, EV-211a, EV-231, EV-233, EV-301, EV-303]
supersedes: POL-PRIV-002 v2.2 (2026-09-25)
print: true
confidentiality: INTERNAL — LEGAL (Part B becomes PUBLIC on publication)
---

# Privacy Policy — draft

> **Prepared for review by licensed counsel. Not legal advice.** Part B is the proposed public text; Parts A and C are internal.
> Statements about data practices that Engineering has not confirmed (EV-201 to EV-206) are bracketed `[ENGINEERING]`; unbracketed
> statements in Part B are limited to entity facts (EV-211a) and descriptions of legal rights. Part B may not be published while any bracket remains, and the publication gate in AUD-2026-09-11 §4 applies.

## Part A — Drafting brief (internal)

### A.1 What changed from v2.0 (2026-09-07)
| Topic | v2.0 | v2.1 | Reason |
|---|---|---|---|
| Apple Guideline 5.4 commitment | Missing | New §2 with two alternatives tied to the advertising decision | G-3; RSK-035; EV-106 (Verified) |
| Contacts | support@ with "Privacy Request" subject | privacy@ and legalrequests@ per POL-ID-001 | G-9; POL-ID-001 C.2(9) |
| Controller identity and address | Suite 9375 as "principal mailing address" | Entity block per DEC-2026-001 §6.1 | DEC-2026-001 |
| EU/UK representatives | "will be posted … before the requirement applies" | Explicit `[OPEN]` fields; DSA contact points | RSK-049; EV-231 |
| Feature-level data handling | "should remain on the device" | Stated as fact only after engineering confirmation; otherwise bracketed | KB-002 B2; G-14 |
| Cookies, deletion, subprocessors, legal requests | Detailed here | Summaries here; detail in POL-COOK-001, POL-DEL-001, POL-SUB-001, POL-LE-001 | Single source of truth |
| "Zareh" named as a provider | Named | Named only after its legal entity and country are verified and sanctions-screened | RSK-033 |
| U.S. state notice | General | Applicability statement pending research (EV-233) | — |
| Internal checklist | Inside the public text | Part C | Publication hygiene |

### A.2 Inputs that block publication
Engineering logging attestation (EV-201–205); SDK inventory from production builds (EV-206); advertising decision (BRF-2026-001 D4);
consent management live (P2-2); retention schedule implemented (POL-RET); mailboxes live; DEC-2026-001 adopted; claims clean-up
(P0-4) published at the same time; counsel sign-off.

## Part B — Proposed public text

# Privacy Policy

**Version:** 2.2 `[OPEN: renumber on publication]` · **Effective:** `[OPEN: date]` · **Last updated:** `[OPEN: date]`

`[COUNSEL: publish together with the change notice that corrects earlier references to "NebulaVPN Inc." and an address in Panama —
DEC-2026-001 §7.1; RSK-047]`

## Summary

- **Who we are:** HidzoVPN, Inc., a Florida corporation, is responsible for your personal information when you use HidzoVPN.
- **Your VPN traffic:** while the VPN is on, your internet traffic passes through our servers so that it can reach its destination. We do
  not record the websites you visit, the content of your traffic or your DNS queries `[ENGINEERING: logging attestation, EV-201–EV-205;
  claims register entry required]`.
- **What we do keep:** limited account, subscription, device and connection information needed to run the service, apply plan limits,
  prevent abuse and meet legal duties, for the periods in Section 11 `[ENGINEERING]`.
- **Advertising:** `[OPEN — BRF-2026-001 D4: describe the advertising model chosen; see Section 2]`
- **Your choices and rights:** Sections 13 to 16.

This Privacy Policy explains how HidzoVPN, Inc. ("**HidzoVPN**", "**we**", "**us**" or "**our**") collects, uses, shares and protects
personal information when you use our apps, websites, VPN service, accounts, billing and support (the "**Services**").

## 1. Who is responsible for your information

HidzoVPN, Inc., a Florida profit corporation (Florida Department of State document number P25000060442), is the controller of the personal
information described in this Policy. Mailing address: 7901 4th Street North, Suite 9375, Saint Petersburg, FL 33702, United States. Contact
details for each purpose are on our Legal Information page `[OPEN: link]`. Privacy requests: `[OPEN: privacy@hidzovpn.com]`.

Apple and Google (for app-store purchases and distribution) `[COUNSEL: and our payment processor, for its own fraud-prevention and legal
purposes; and, if applicable under Section 2, advertising providers]` process some information under their own privacy notices, as
independent businesses.

## 2. Our commitment for the VPN service

`[OPEN — BRF-2026-001 D4; COUNSEL — Apple Guideline 5.4 requires that apps offering VPN services "may not sell, use, or disclose to third
parties any data for any purpose, and must commit to this in their privacy policy" (EV-106, Verified). Choose one alternative. If
Alternative A is chosen, Sections 1, 3.5, 5, 7, 9, 13 and 16 must be conformed with an explicit platform split, and the Apple privacy label
rebuilt.]`

**Alternative A — no third-party data disclosure in the iOS app:**
In our iOS app, we do not sell data to third parties, and we do not disclose data to third parties or allow third parties to use it for their
own purposes. We disclose data only to service providers that process it on our instructions to provide the Services, and where the law
requires us to do so. `[COUNSEL: whether Apple, Google, the payment processor, Sign in with Apple/Google, resellers and a successor fit these
exceptions; whether voluntary emergency disclosure and "with your permission" (Section 9) must be excluded for iOS]`

**Alternative B — iOS as in Alternative A; advertising in the Free Service on Android and the website:**
`[COUNSEL and ENGINEERING: iOS text as in Alternative A. For Android and the website: name the advertising networks, the data they receive,
the consent obtained, and the Google Play VpnService prominent-disclosure screen (G-5). Not drafted until D4 is decided.]`

## 3. Information we process

### 3.1 Account information
If you create an account: your email address, an internal account identifier, your plan and subscription status, the devices linked to your
account and your sign-in method `[ENGINEERING: fields]`. If you sign in with Apple or Google, we receive an identifier and the email address the
provider shares (Apple may share a private relay address) `[ENGINEERING: sign-in methods offered]`. We do not receive your Apple or Google
password. One-time sign-in codes expire after `[ENGINEERING: 10 minutes]` and are stored only in protected form `[ENGINEERING]`.

### 3.2 Device and app information
When you use the app, with or without an account: an installation or device identifier, device model, operating system and app version,
language, time zone and the IP address used to contact our servers `[ENGINEERING: fields]`. In the Free Service, the installation identifier
is used to apply session limits and waiting periods and to prevent abuse `[ENGINEERING: EV-205]`.

### 3.3 VPN connection information
To connect you, our systems process: your IP address at the time of connection, a session identifier, your account or installation
identifier, the server and protocol selected, the internal tunnel address, connection status and errors, the number of simultaneous
connections, connection start and end times and the amount of data transferred `[ENGINEERING: confirm each field, where it is stored and for
how long — EV-201, EV-205]`. We use this information to establish and end connections, enforce device and plan limits, keep the network
reliable and prevent abuse. Section 11 states how long it is kept.

We do not record the content of your VPN traffic, the websites or destinations you visit, or your DNS queries, and we do not keep a history
that links those destinations to you. We do not use VPN traffic for advertising, analytics or profiling. `[ENGINEERING: attestation required
for both sentences; claims register entry required]`

The IP address from which you connect is visible to our systems while the connection is set up. The providers that host our servers and the
networks that carry traffic may process network information under their own legal obligations.

### 3.4 Purchase information
For trials and subscriptions: plan, purchase channel, transaction identifiers, dates, price, currency, billing country, subscription and
refund status and fraud signals. Apple and Google process payments for store purchases and send us confirmation of your entitlement. For
website purchases, our payment processor `[OPEN: Stripe entity]` collects your payment details; we receive `[ENGINEERING: e.g. a payment
token, card type and last four digits, billing country and payment status]`. `[OPEN — BRF-2026-001 D7: cryptocurrency purchases — wallet
address, transaction hash, asset and amount]`

### 3.5 Advertising and measurement information
`[OPEN — depends on Section 2 and the SDK inventory (EV-206)]` Where advertising is shown, the advertising provider may receive
`[ENGINEERING: list]`. Measurement and analytics tools may receive app events such as installation, account creation, trial start and
purchase `[ENGINEERING: named tools and events]`. We do not send VPN traffic, DNS queries, destinations, sign-in codes or payment details to
these providers `[ENGINEERING: EV-206]`.

### 3.6 Diagnostics and security information
Crash reports, app performance data, API request records, sign-in attempts, rate-limit events and abuse reports, used to keep the Services
working and secure `[ENGINEERING: whether these records contain IP addresses — CLM-024]`.

### 3.7 Support and communications
Messages and attachments you send us, and records of our replies. If you agree to receive marketing emails, your email address and your
preference.

### 3.8 Website information
IP address, browser and device type, pages viewed and cookie identifiers. See our Cookie Notice `[OPEN: link — POL-COOK-001]`.

### 3.9 Information from other sources
We receive information from: Apple and Google (sign-in, purchases and entitlements); our payment processor (payment status and fraud
signals); `[OPEN — D4: advertising and measurement providers]`; `[OPEN — POL-RTOS-001 §0: resellers, only the contact details needed to resolve a specific support or fraud case (POL-RPRIV-001 §2), if a reseller program is launched]`;
and people who report abuse, security vulnerabilities or legal issues to us.

### 3.10 What you must provide
You must give us an email address or sign-in identifier to create an account, and payment information to buy on our website. Without them we
cannot provide those parts of the Services. Using the Free Service without an account does not require them, but the app cannot connect
without the device and connection information in Sections 3.2 and 3.3 `[ENGINEERING: confirm]`.

## 4. Features that use information on your device

| Feature | What it uses | Where it stays |
|---|---|---|
| Split tunneling | The list of apps installed on your device, to let you choose which apps use the VPN `[ENGINEERING: platforms]` | On your device `[ENGINEERING: confirm]` |
| Trusted networks / auto-connect | Wi-Fi network names | On your device `[ENGINEERING: confirm]` |
| Location / local network permission | `[ENGINEERING: whether requested, and why]` | `[ENGINEERING]` |
| QR code scanning | Camera, only when you choose to scan `[ENGINEERING]` | The image is not stored or uploaded `[ENGINEERING: confirm]` |
| Paste / import | Clipboard, only when you tap Paste or Import `[ENGINEERING]` | On your device `[ENGINEERING: confirm]` |
| Custom configurations (BYOC) | Configuration files, keys and credentials you import | On your device, encrypted `[ENGINEERING: confirm]` |
| Notifications | A push token | Sent to Apple or Google to deliver notifications; `[ENGINEERING: whether stored on our servers]` |
| Weekly statistics | Your usage statistics | `[ENGINEERING: on device or on our servers — if on servers, reconcile with Section 11]` |

## 5. Why we use information

To provide and secure the Services; to manage accounts, subscriptions and billing; to apply Free Service limits and device limits; to prevent
fraud and abuse and enforce our Terms; to monitor the reliability and performance of our systems; to measure how the apps are used and how
users find us, without using VPN traffic; `[OPEN — D4: to show advertising as described in Sections 2 and 3.5]`; to respond to requests; to
send service messages and, with your agreement where required, marketing; and to meet legal obligations and defend legal claims.

## 6. Legal bases (European Economic Area, United Kingdom, Switzerland)

| Legal basis | Processing |
|---|---|
| Performance of a contract | Accounts, VPN connections, Free Service limits, subscriptions, billing, support |
| Legitimate interests | Security, fraud and abuse prevention, reliability, limited diagnostics, product improvement, legal claims; complying with U.S. tax, sanctions and legal-process requirements that apply to us |
| Consent | Non-essential cookies; storage of or access to information on your device that is not strictly necessary; personalized advertising; marketing emails; optional diagnostic uploads `[COUNSEL: legal basis for contextual advertising, if any — D4]` |
| Legal obligation | Obligations under the law of the European Union, the United Kingdom or Switzerland that apply to us `[COUNSEL]` |

You may withdraw consent at any time; this does not affect processing that took place before.

## 7. Sale, sharing and targeted advertising

We do not sell personal information for money. We do not sell your VPN traffic, browsing destinations or DNS queries, and we do not keep
records of them that could be disclosed `[ENGINEERING: attestation]`. `[OPEN — depends on Section 2:]` Under some U.S. state laws, giving
advertising providers identifiers or app activity for targeted advertising may count as "selling", "sharing" or "targeted advertising" even if
no money is paid. Where those laws apply to us, you can opt out as described in Section 16. If your browser sends a Global Privacy Control
signal, we treat it as a request to opt out of the sale or sharing of your personal information and of targeted advertising for that browser
or device and, if we know who you are, for your account `[ENGINEERING: confirm]` `[COUNSEL: which state laws apply — EV-233]`.

## 8. Cookies and similar technologies

See our Cookie Notice `[OPEN: link]` for our website. In our apps, `[ENGINEERING: describe the storage of or access to information on your
device that is not strictly necessary, the consent tool used (for example Google UMP or App Tracking Transparency), and how to change your
choice]`.

## 9. Who we share information with

- **Service providers** that host our servers and systems, deliver email and notifications, provide customer support, process payments,
  measure app performance and help prevent fraud. We require them to protect the information to the same standard as this Policy and to use it
  only to provide their services to us `[VERIFY: contract terms — POL-SUB-001]`. The current list is in our List of Service Providers
  `[OPEN: link — POL-SUB-001]`.
- **Apple and Google**, for app-store purchases and distribution, and **our payment processor** for website purchases `[COUNSEL: role]`.
- **Advertising and measurement providers** `[OPEN — Section 2]`.
- **Authorities, courts and parties to legal proceedings**, when we are legally required to do so, or in an emergency involving danger of death or serious physical injury, as described in our Law Enforcement Guidelines `[OPEN: link — POL-LE-001]`
  `[COUNSEL: whether to include voluntary emergency disclosure — Section 2]`. We can only provide information we actually hold.
- **Resellers** `[OPEN — POL-RTOS-001 §0]`: the contact details of a person who bought an Activation Code from that reseller, only where needed to resolve a specific support or fraud case; we do not tell resellers whether or by which account a code was activated `[POL-RPRIV-001 §§2, 9; COUNSEL — Section 2]`.
- **A buyer or successor** of our business, subject to this Policy.
- **Anyone else, with your permission** `[COUNSEL — Section 2]`.

## 10. International transfers

We are based in the United States. Your information is processed in the United States and in the countries where our service providers and
VPN servers are located `[OPEN: list countries or refer to POL-SUB-001]`. The European Commission has adopted an adequacy decision for the
United States only for organizations certified under the EU-U.S. Data Privacy Framework; HidzoVPN `[OPEN: is not]` certified `[VERIFY]`. For
transfers from the European Economic Area, the United Kingdom or Switzerland to countries without an adequacy decision, we use the European
Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or other lawful safeguards `[COUNSEL: confirm the
mechanism for each provider, given that HidzoVPN, Inc. is itself subject to the GDPR under Art. 3(2)]`. You can ask us for a copy of the
relevant safeguards.

## 11. How long we keep information

`[ENGINEERING and FINANCE: each period must be implemented before publication — POL-RET-000]`

| Information | How long |
|---|---|
| Account information | While your account exists; deleted within 30 days after we receive a deletion request, or after you confirm it if we ask you to `[ENGINEERING]` |
| Sign-in codes | Until they expire (`[ENGINEERING: 10 minutes]`) |
| Sign-in sessions and tokens | Until you sign out or they expire, and no longer than `[ENGINEERING: 30 days]` |
| Free Service limit state (installation identifier and timing) | `[ENGINEERING]` |
| Linked devices | While your account exists `[ENGINEERING]` |
| Live VPN session information | While the connection is active and up to `[ENGINEERING: 15 minutes]` after it ends |
| Usage statistics linked to an account or device | `[ENGINEERING: 24 hours]`, then deleted or de-identified |
| API, security and abuse records | Up to `[ENGINEERING: 30 days]`; up to 24 months where needed for a specific incident, dispute or legal obligation |
| Blocked device and payment identifiers (fraud and abuse) | Up to `[ENGINEERING and COUNSEL: 24 months]`, or longer only for a documented incident or legal claim |
| Crash and diagnostic reports | Up to `[ENGINEERING: 90 days]` |
| Analytics and advertising measurement | Up to `[ENGINEERING: 13 months]` |
| Push tokens | Until they become invalid, you disable notifications or you delete your account, then up to 30 days |
| Support messages | Up to 12 months after the request is closed, or until you delete your account, unless needed for an open matter |
| Marketing preferences | Until you unsubscribe; we keep a minimal record so that we respect your choice |
| Purchase, tax and accounting records | For the period tax and accounting law requires `[VERIFY and tax counsel: U.S. periods; EU VAT records may require up to 10 years]` |
| Records of privacy requests | Up to 5 years `[COUNSEL]` |
| Information covered by a legal hold or open dispute | Until the hold or dispute ends |
| Backups | Deleted information is removed from backups within `[ENGINEERING: 90 days]` |

"De-identified" means information that can no longer reasonably be linked to you; we do not try to re-identify it.

## 12. Deleting your account

You can delete your account in the app or as described in our Account and Data Deletion Policy `[OPEN: link — POL-DEL-001]` `[ENGINEERING:
in-app and web deletion]`. **Deleting your account cancels the renewal of a subscription bought on our website, but not of a subscription
billed by Apple or Google** `[ENGINEERING: automatic cancellation of the Stripe subscription]`. After deletion, we keep some information for
the periods in Section 11, for example tax records, fraud and security records, and information covered by a legal hold.

## 13. Your choices

You can: update your account information; unsubscribe from marketing emails; change advertising and tracking choices in the app and in your
device settings, including Apple's App Tracking Transparency `[OPEN — D4]`; change cookie choices on our website `[ENGINEERING: consent
management — BRF-2026-001 P2-2]`; change device permissions in your device settings; and delete your account.

## 14. Your rights

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your personal information, to object to or
restrict certain processing, to withdraw consent, to opt out of the sale or sharing of personal information or targeted advertising, and not
to be treated differently for exercising these rights.

To make a request, email `[OPEN: privacy@hidzovpn.com]` from your account email and tell us which right you want to use. If you use the app
without an account, include the installation identifier shown in `[ENGINEERING: Settings → About]`. We will verify your request in a way that
is proportionate and will reply within the time the law requires. If we refuse your request, we will explain why. To appeal, email the same
address with the subject "Privacy Appeal" within `[OPEN: 60]` days of our decision. Please do not send identity documents, passwords, sign-in
codes or payment card numbers.

You can also complain to the data-protection authority where you live or work.

## 15. Additional information for the European Economic Area, the United Kingdom and Switzerland

**Right to object.** You can object at any time to our use of your information based on legitimate interests, and to direct marketing. If you
object to direct marketing, we will stop.

`[COUNSEL — RSK-049; EV-231]`
- **EU representative (GDPR Article 27):** `[OPEN: name and address. Assessment: the Art. 27(2)(a) exemption is unlikely to apply to
  continuous processing]`
- **UK representative (UK GDPR Article 27):** `[OPEN]`
- **Swiss representative:** `[COUNSEL: whether required]`
- **Data Protection Officer:** `[COUNSEL: whether required]`

## 16. Additional information for U.S. residents

`[COUNSEL: state which state laws apply to HidzoVPN — EV-233; do not state that a law applies if its thresholds are not met. If the CCPA
applies, complete the table below under 11 CCR §7011(e).]`

| Category of personal information | Examples | Sources | Purposes | Categories of recipients | Sold or shared in the last 12 months? |
|---|---|---|---|---|---|
| Identifiers | Email, account ID, installation ID, IP address `[ENGINEERING]` | You; your device; Apple and Google | Sections 5, 9 | Service providers; app stores; `[OPEN]` | `[OPEN — D4]` |
| Customer and commercial records | Plan, purchases, refunds | You; payment processor; app stores | Billing, support, fraud | Service providers; payment processor | No `[VERIFY]` |
| Internet or network activity | App and website use, security records (not browsing destinations) | Your device | Operation, security, measurement | Service providers | `[OPEN — D4]` |
| Approximate location | Derived from IP address | Your device | Localization, security, tax | Service providers | `[OPEN — D4]` |
| Inferences | `[OPEN: only if used]` | — | — | — | — |

We do not use or disclose sensitive personal information for purposes other than those the law permits `[COUNSEL]`. We do not knowingly sell
or share the personal information of consumers under 16. To opt out of the sale or sharing of personal information or targeted advertising,
use `[OPEN: "Your Privacy Choices" link]` or send a Global Privacy Control signal (Section 7). You may use an authorized agent to make a request;
we may ask the agent for proof of authority and ask you to confirm the request. We will not discriminate against you for exercising your rights.

## 17. Security

We use administrative, technical and physical measures to protect personal information `[ENGINEERING: list only measures in place, e.g.
encryption in transit, access controls, monitoring of our systems]`. No method of transmitting or storing information is free of risk. If a security breach affects your
personal information, we will notify you and the authorities where the law requires.

## 18. Automated decisions

We use automated rules to authenticate sessions, apply plan and device limits, and detect suspicious sign-ins, payments and abuse
`[ENGINEERING: confirm]`. These rules may temporarily block a request or account. You can ask for a person to review a decision by contacting
us.

## 19. Children

The Services are for people aged 18 and over `[OPEN: align store age ratings — BRF-2026-001 P2-4]`. We do not knowingly collect personal
information from anyone under 18. If you believe a child has given us personal information, contact us and we will delete it.

## 20. Changes to this Policy

We will publish any update with its effective date. If a change is material, we will tell you in advance by email or in the app and, where the
law requires, ask for your consent. Earlier versions are available on request `[OPEN: or archive]`.

## 21. Contact

HidzoVPN, Inc., 7901 4th Street North, Suite 9375, Saint Petersburg, FL 33702, United States · Privacy: `[OPEN: privacy@hidzovpn.com]` ·
Legal Information page: `[OPEN: link]`. This Policy is written in English; if a translation differs, the English version prevails unless the
law of your place of residence requires otherwise.

## Part C — Drafting notes (internal)

### C.1 Legal basis
| Element | Basis | Label |
|---|---|---|
| VPN data commitment (§2) | Apple App Review Guideline 5.4 (updated 8 June 2026) | Verified (EV-106) |
| GDPR notice content (§§1, 6, 10, 11, 14, 15) | GDPR Art. 13 | Reported (A/B) — EU text as adopted, legislation.gov.uk (EV-255) |
| Representatives (§15) | GDPR Art. 27(1) applies as soon as Art. 3(2) applies; the Art. 27(2)(a) exemption needs processing that is occasional **and** unlikely to result in a risk — a continuous VPN service is unlikely to qualify (assessment); UK GDPR Art. 27; DSA Art. 13 | Art. 27 Reported (EV-255); DSA Recital 29 Verified (EV-231); `[COUNSEL: appoint or document exemption]` |
| U.S. state notice (§16) | CCPA "business" tests: revenue over $26,625,000 (adjusted from 1 Jan 2025), 100,000+ consumers or households bought/sold/shared, or 50%+ of revenue from selling or sharing (Cal. Civ. Code §1798.140(d)(1)) — the 50% test matters if ad revenue is "sharing"; privacy-policy content 11 CCR §7011(e); **mobile app must link the privacy policy in its settings menu (§7011(d))**; GPC honoured and its status displayed on the website (§7025(b), (c)(6)); a cookie banner is not by itself a valid sale/sharing opt-out (§7026(a)(4)). TDPSA: SBA small-business carve-out (§541.002(a)(3)) but no sale of sensitive data without consent (§541.107). Florida Digital Bill of Rights controller duties need >$1 billion revenue (Fla. Stat. §501.702) — not applicable | 11 CCR §§7011(d), 7025(c)(6), 7026(a)(4) Verified first-hand (CCPA regulations eff. 1 Jan 2026, EV-253); others Reported (EV-252, 254); applicability `UNKNOWN — evidence needed: CA user counts, SDK data flows, revenue split, SBA size status` |
| Cookies and consent (§§8, 13) | ePrivacy Directive Art. 5(3); UK PECR reg. 6 and Sch. A1 (in force 5 Feb 2026) | Reported (EV-256, EV-237) |
| Account deletion (§12) | Apple Guideline 5.1.1(v) (in-app deletion mandatory); Google Play User Data policy (in-app and web deletion) | Apple Verified first-hand (EV-257); Google Reported from official blog, live policy page `[VERIFY]` (EV-257) |
| App Tracking Transparency (§13) | Apple Guideline 5.1.2(i) — tracking needs ATT permission and may not be a condition of functionality or compensation (relevant to rewarded ads) | Reported (EV-257) |
| CIPA pen-register claims over website tags | Cal. Penal Code §638.51; SB 690 (enrolled, presented to the Governor 4 Sep 2026) would leave §638.51 website/app claims to the Attorney General; §631 unaffected | Pending — re-check after 30 Sep 2026 (EV-258) |
| No absolute privacy claims | Claims register (CLM-001–006, 009, 022, 024); FTC Act §5 | Internal rule |

### C.2 Engineering evidence required (A-INT)
EV-201 node logging per protocol; EV-202 DNS resolver retention; EV-203 API/auth log retention; EV-204 CDN/WAF logs; EV-205 session and device
limit state; EV-206 SDK manifest; EV-212 GTM export; EV-213 backup/log shipping; EV-214 hosting providers with countries.

### C.3 Limits of this analysis
Verified first-hand: Apple Guideline 5.4; DSA Recital 29. Pending research (EV-233): all other privacy law cited. Not reviewed: privacy laws of
Turkey (KVKK), Indonesia (PDP Law), Saudi Arabia (PDPL), UAE, Brazil and other markets (RSK-023). Facts unknown: all C.2 items. Counsel required:
U.S. privacy; EU/UK privacy; Apple 5.4 interpretation.

### C.3a Items added from the full AI review (2026-09-25)
Apple Guideline 5.1.1(i) (third parties must provide the same or equal protection) — §9; Apple 5.4 in-app data declaration before use — A.2
companion requirement; GDPR Arts. 13(2)(e) (§3.10), 14(2)(f) (§3.9), 21(4) (§15), 6(3) (U.S. obligations moved to legitimate interests,
§6); CCPA §7011(e) structure (§16); appeal route (§14); guest requests (§14); retention rows restored from POL-RET-000 (§11); GPC wording
aligned with the Cookie Notice (§7); Stripe role left to counsel (§§1, 9; POL-SUB-001 SUB-02); DPF status (§10). New claims-register entry
required for the §3.3 logging statements (the CLM-001 replacement wording about originating IP must not be used unless Engineering confirms no
source-IP retention).

### C.4 Review log
| Date | Reviewer | Verdict | Notes |
|---|---|---|---|
| 2026-09-07 | Counsel review draft v2.0 | — | EV-301 |
| 2026-09-23 | AUD-2026-09-11 | 14 gaps | G-1…G-14 |
| 2026-09-25 | Drafted v2.1 | — | See A.1 |
| 2026-09-25 | hidzo-counsel-reviewer (AI) | REVISE (1 Blocker; 17 Majors) | v2.2: Part B rewritten — Blocker PP-01 fixed (all unconfirmed practices bracketed; banner corrected); iOS-scoped Alt A; Alt B structure; see C.3a |
| 2026-09-25 | hidzo-counsel-reviewer (AI) — cross-document final audit; research memos EV-232–235 | REVISE (set: 1 Blocker, 8 Majors) | v2.3: cross-document redlines X-01–X-31 applied where they concern this document; authority labels updated from first-hand and research-memo checks (EV-238–264) |
