Privacy Policy for Tadah

Effective date: June 18, 2026 Last updated: August 20, 2026

Tadah ("Tadah", "we", "us") is an iOS app that helps you understand letters, bills, and official documents and turn them into reminders and checklists. This policy explains what data the app handles and what happens to it.

The short version: you can use Tadah without an account, and then your items stay on your device. Scanning asks your permission before it sends anything, and usage statistics are sent only if you agree when we ask. Four things can leave your phone: (1) only if you agree at the first scan, the text of a document you scan is sent for AI processing; (1a) under that same permission, in the moving and renting guides only, a ZIP code you type — with your answers to that guide's questions — is sent to look up local utility companies (with the permission off the guides don't even ask for a ZIP); (2) if you sign in, your saved items are backed up to your account on our backend so they survive a new phone and appear on your other devices — your scanned photos are not uploaded; and (3) only if you agree when we ask on first launch (or switch them on later), pseudonymous usage statistics — which features you use, never your content — are sent to a backend we run. You can turn (1) and (3) off anytime in Profile → Privacy, and you can use the app signed out to avoid (2).


1. Who is responsible

Tadah is operated as a sole proprietorship based in New York, United States. Questions about this policy: support.tadah@gmail.com.

(If a business entity such as an LLC is formed later, this section will be updated with its legal name and address.)


2. What we collect and process

Stored on your device

If you never sign in, we have no server copy of your items and cannot see them. Uninstalling the app removes the local data.

Your account and backed-up items (only if you sign in)

Signing in is optional. It exists so your items survive signing out, a reinstall, or a new phone, and so they can appear on more than one device.

What is sent to OpenAI when you scan

- a daily value, used for the per-network limit. It changes every day, so today's counter cannot be matched to yesterday's.

- a monthly value, used only for app versions that don't send an install identifier, because their allowance is counted per month. It stays the same for one calendar month, which means requests from the same network within that month are linked to each other — still not to your address, and not to you.

Both are deleted after 60 days. Cloudflare separately records your IP in their own request logs, as any host does, under their retention and their privacy policy — so "we don't keep it" is true of us and not of the internet.

GUIDES are generated on your device

Every built-in guide — including the sensitive ones (money/banking, taxes, immigration (USCIS), medical, and similar) — has its checklist, its wording and its translation built entirely on your device, from text shipped inside the app. No guide's content is sent to OpenAI, and guides work with no network at all.

The one exception: looking up your local utility companies. In the moving and renting guides you can type the ZIP code of your new home. If you do, that ZIP code and your answers to that guide's questions are sent so we can name the electricity, gas, water and internet providers that serve the area. This is covered by the same Send content to AI permission as scanning — with it off, the ZIP question isn't shown at all and nothing is sent. Leaving the ZIP blank also skips it, and the guide still works either way. Sensitive guides never do this lookup, and no other guide asks for a ZIP.

This does not apply to scanning, where the recognized text is sent to OpenAI as described above, however sensitive the document is. Note that once you add a guide's checklist to your list, that item is backed up to your account like any other item if you are signed in.

Pseudonymous usage statistics (sent to a backend we run)

To understand whether Tadah actually helps — for example, of the items you add, how many you come back and complete — the app can send a small amount of usage data to a backend we operate (a Cloudflare database). It carries no name, email, or account, but it does carry a random identifier that stays the same for this installation — so it is better described as pseudonymous than anonymous: we cannot tell who you are from it, but events from one installation can be seen as belonging together. What it contains:

This is first-party data, used only to improve Tadah. It is not advertising, is not sold or shared, and is not used to track you across other apps or websites.

We ask you, and nothing is sent unless you say yes. Tadah asks this question once, on the first launch, with a plain No thanks next to the Share usage data button — declining changes nothing else about how the app works. Whatever you answer, the same setting lives under Profile → Privacy and you can switch it on or off at any time; switching it off stops new events immediately. If you have never answered, it is off.

How long we keep it. AI usage counters are deleted after 60 days. Deletion records for synced items are removed after 180 days, and revoked sign-in sessions after 30 days; a session that simply goes unused expires after 90 days. Ask us and we will delete your usage events sooner.

We do NOT


3. Third parties that may process data

ProviderWhat they processWhy
OpenAIOnly if you turn on Send content to AI. That one permission covers both AI paths: the full recognized text of any document you scan/upload (may include sensitive personal info), and — in the moving and renting guides only — a ZIP code you type plus your answers to that guide's questions. With the permission off, neither is sent and the guides don't ask for a ZIP. Guide checklists themselves are not sent — they are built and translated on your device. May be retained ~30 days for abuse monitoring; not used for training.To generate the summary and steps, and to look up local utility companies
CloudflareYour IP address (when proxying the AI request — see the note below on their request logs); the usage statistics we store, if you have turned them on; and — if you sign in — your backed-up items, your family profiles, and your session recordsTo proxy the AI request without shipping the OpenAI key, to store usage statistics, and to host your account backup
AppleDevice storage, on-device OCR, local notifications; App Store purchasesStandard iOS functionality and subscription billing
ResendSends account emails (password-reset codes) — receives your email addressDelivering the code that lets you back into your account
RevenueCatYour Tadah user identifier and your subscription statusTo manage Tadah Plus subscriptions and tell the app (and our backend) whether your account is Plus

We use these providers to deliver Tadah, and we require them by contract to protect your information to a standard equivalent to this policy, to use it only to provide their service to us, and not to use it for their own purposes. We choose them, and we remain accountable to you for the data we send them. You can also review their own privacy policies (OpenAI, Cloudflare, Apple, RevenueCat).


4. Data retention


5. Your choices and rights

California (CCPA) and EU/UK (GDPR): if you are signed in, we hold your Tadah user identifier, the items you have saved, and any family-profile names you have entered, and you have the right to access, correct, port, or delete them — email us at the address above and we will action it. We do not sell or share personal information, and we do not use it for advertising or cross-context behavioural profiling. If you never sign in, we hold no account — no email address, no saved items, no family profiles. That is not the same as holding nothing: if you turn on Send content to AI, the text of a scanned document is processed as described above; our provider processes your IP address to deliver the request; and if you agree to usage statistics, those carry a random install identifier. Those paths are all optional and all switchable off in Profile → Privacy.


6. Children

Tadah is not directed to children under 13 and we do not knowingly collect data from them. (COPPA.)


7. Security


8. Changes to this policy

We may update this policy as the app evolves (for example, if we add accounts, sync, or analytics). We will revise the "Last updated" date above, and material changes will be reflected in the app.


9. Contact

Tadah Supportsupport.tadah@gmail.com