Introduction
Ajda ("Ajda", "the App", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we handle information when you use our iOS application.
The short version: Comparisons and history stay on your device. No account is required. Optional cloud AI extraction happens only after you consent. Analytics can be turned off. We do not sell data or use advertising/tracking across other companies’ apps.
Who We Are
Ajda is provided by independent developer Saud Alsaeed, the controller of the personal data described here. For privacy questions or rights requests, contact:
Email: ajda@saudalsaeed.com
What Ajda Does
Ajda compares grocery offers. Comparison inputs, calculations, results, and history are stored locally with SwiftData. Text recognition runs on device by default. Ajda does not use precise location, sell data, serve advertising, or track anyone across other companies’ apps or websites.
Data We Process and Why
Local Comparisons and History
Prices, quantities, offer details, and results remain on your device for comparison, history, and sharing. They are not sent to Ajda’s servers.
Optional Cloud Extraction
After a clear notice and your affirmative choice, Ajda strips EXIF, downsizes the image, and sends its pixels to a Supabase Edge Function, through Cloudflare AI Gateway, to the AI model provider. The image is used only to answer that request, is not written to Supabase Storage or retained by the model provider for training, and is not used to train models. You can disable cloud extraction and continue with manual entry and on-device recognition.
Anonymous Cloud Identity
On first cloud use, Supabase creates a silent anonymous identifier without a name, email, password, or visible account. It supports authentication, quota enforcement, abuse prevention, and subscription entitlement linking. App Attest and DeviceCheck support app/device integrity and fraud prevention.
Analytics and Diagnostics
Unless you opt out, Ajda sends PostHog EU Cloud bounded usage events, pseudonymous identifiers supplied by the SDK, masked session replays, crash data, and diagnostics. Ajda event properties exclude prices, product names, recognized text, barcodes, images, names, email addresses, and phone numbers. Replay images, text inputs, and sensitive views are masked. You can opt out in Settings without losing functionality.
Purchases and Subscriptions
Apple processes payments. RevenueCat processes purchase history, subscription status, and the anonymous app user ID to provide paid AI quota and restore purchases. Supabase mirrors entitlement state so quota is enforced server-side.
Automatic Technical Data
Service providers may process IP address, device/OS information, and request logs as necessary for security, delivery, fraud prevention, and troubleshooting.
Data We Do Not Collect
Ajda does not ask you to create an account or provide a name, email address, or phone number. We do not collect precise location, advertising identifiers for tracking, or payment card details (Apple handles payments).
Purposes of Processing
We process data necessary to provide requested services, administer subscriptions and quota, secure Ajda, and prevent abuse. We rely on limited product analytics and reliability diagnostics, with minimization and your right to opt out. Cloud-image transfer occurs only after your affirmative action.
Service Providers and International Transfers
Ajda uses Supabase (AWS Zurich), Cloudflare AI Gateway, an AI model provider (OpenAI at launch under zero-retention/no-training settings), PostHog EU Cloud (AWS Frankfurt), RevenueCat, and Apple. Data may therefore be processed outside Saudi Arabia under each provider’s terms and applicable safeguards.
Supabase
Anonymous authentication, extraction function, usage quota, and entitlement state.
Cloudflare AI Gateway
Routes extraction requests and provides operational controls.
AI Model Provider
Reads the image for a transient extraction request under zero-retention / no-training settings at launch.
PostHog (Analytics)
EU Cloud analytics, masked session replay, and crash/diagnostics — opt-out available in Settings.
RevenueCat & Apple
Purchase processing, subscription status, and restore. We do not receive your payment card details.
No Advertising
Ajda does not include advertising SDKs, does not show ads, and does not share data with advertising networks for tracking.
Retention
Local comparisons remain until you delete them or uninstall Ajda. Cloud extraction images last only for the request. Structured extraction cache and content hash: up to 30 days. AI usage counters: rolling 30 days, with aggregates up to 90 days for abuse analysis. PostHog events, masked replays, and diagnostics: capped at 12 months or less where supported. Purchase and subscription records: as needed for delivery, restoration, legal obligations, and Apple/RevenueCat policies. Security logs: only for a proportionate period.
Your Rights and Choices
Subject to the Saudi Personal Data Protection Law, you may have rights to be informed, access data, obtain a copy, request correction or destruction, withdraw consent where applicable, object, and complain to the competent authority. In Ajda you can:
- Delete local history and memory from Ajda Settings
- Use “Delete my cloud data” to delete the anonymous identity and linked server data and request PostHog deletion, with analytics stopped
- Disable analytics or cloud extraction at any time
- Contact us for requests that cannot be completed in-app
Children’s Privacy
Ajda is not intended to knowingly collect children’s personal data.
Security
We use transport encryption, access controls, Row Level Security, app attestation, and data minimization. No electronic system is completely secure.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be published with an updated effective date at the top of this page.
Contact Us
If you have questions about this Privacy Policy or wish to exercise rights that cannot be completed in-app, contact us at:
Email: ajda@saudalsaeed.com