Privacy Policy
1. Operator and Privacy contact
Operator/Data Controller: JoCoding, Inc., a Delaware corporation. Registered address: 1111B S Governors Ave, STE 80543, Dover, DE 19904, United States. Telephone: +1 (231) 450-5622. Privacy contact and access-request desk: mu07010@jocoding.net. Website: jocoding.io.
2. Service and local-first model
AI Limits Tracker helps a user view normalized usage windows, reset timing, current usage, widgets, and local alerts for compatible AI providers. The app does not require a JoCoding account. When a compatible connection is available and the user chooses it, the device communicates directly with the selected provider.
3. Information processed by the app
| Information | Purpose | Location and disclosure |
|---|---|---|
| Provider access/refresh credentials and expiry, and the account name the provider returned at sign-in | Authenticate user-requested provider access and show which account a row belongs to | Stored in device Keychain. On Apple devices the items may sync through the user’s own iCloud Keychain to the user’s other devices running this app, so a device that did not perform the sign-in can name the account. Not sent to JoCoding. |
| Provider/account identifier, local alias, internal account ID | Identify and organize connected accounts | Stored on device and may sync through CloudKit private DB on the user’s iCloud account. Provider email addresses are not included in this CloudKit record. A full email-shaped alias is redacted from widget and diagnostic output. |
| Normalized usage percentage, window/reset time, retrieval time | Dashboard, widgets, and local alerts | Latest normalized usage snapshot stored on device and synced through CloudKit private DB on the user’s iCloud account. Not sent to JoCoding. |
| Preferences, alert rules, retry/recovery state, onboarding version, entitlement feature state | Remember local settings and protect feature behavior | Stored locally. No receipt, raw transaction ID, or purchase token is stored by this release. |
| Anonymous App User ID, App Store purchase receipts, subscription status | Validate optional AI Limits Pro and restore entitlements | Sent to RevenueCat for purchase validation and subscription analytics. Not a JoCoding account. Provider credentials and usage values are not sent. |
| Redacted diagnostic categories | Explain errors on the device | Displayed locally. There is no automatic crash or support upload SDK. |
| App event names and properties (for example app open, screen selection, paywall view), an anonymous analytics identifier, app version, OS version, device model, and coarse region derived from the request IP address | Understand which features are used and diagnose product problems | Sent to PostHog (United States). Provider credentials, provider account identifiers, and usage values are not included. |
| Install and session signals, device vendor identifier (IDFV), IP address, app version, and — only where tracking is allowed — the advertising identifier (IDFA) | Attribute an app install to the marketing campaign that led to it | Sent to AppsFlyer. On iOS the app shows the App Tracking Transparency prompt. Only if you allow tracking is the advertising identifier collected, and install and conversion events shared with Meta Platforms for advertising measurement. If you decline, neither happens. |
On Apple devices, provider credentials and the account name the provider returned at sign-in may sync through the user’s own iCloud Keychain. Provider/account identifiers, local aliases, internal account IDs, and the latest normalized usage snapshot may sync through CloudKit private DB on the user’s iCloud account. Provider email addresses are not synced through CloudKit. JoCoding does not receive or have access to the contents of the user’s iCloud Keychain or private CloudKit database through the app.
The app does not intentionally request name, phone number, address, contacts, location, photos, camera, microphone, advertising identifier, health information, biometric template, political/religious information, government identifiers, or payment information. Device authentication for App Lock is performed by iOS; the app does not receive biometric data.
4. Collection method and purpose
Information is entered by the user, created locally during app use, or returned directly to the device by a provider chosen by the user. It is processed to display usage, manage connections, preserve current usage, schedule local notifications, publish credential-free widgets, and delete local state safely.
5. Providers, third parties, and international transfer
JoCoding does not receive or sell provider credentials or usage values and does not disclose them to independent advertisers or data brokers. Direct provider authentication and usage requests are governed by the selected provider’s privacy terms and may be processed in the provider’s countries. Apple provides App Store distribution, iOS secure storage, device authentication, widgets, background scheduling, and local notifications under Apple’s terms. RevenueCat receives App Store and Google Play purchase receipts, subscription status, and an anonymous app user identifier to validate purchases and provide subscription analytics. JoCoding does not send Provider credentials or usage values to RevenueCat. Cloudflare serves this policy website; ordinary web request metadata may be processed in Cloudflare’s network. PostHog receives app usage events and an anonymous analytics identifier as a processor for product analytics; its servers are located in the United States. AppsFlyer receives install and session signals to attribute installs to marketing campaigns. On iOS, only if you allow tracking in the App Tracking Transparency prompt does AppsFlyer receive the advertising identifier and share install and conversion events with Meta Platforms for advertising measurement; if you decline, no advertising identifier is collected and no device-level data is shared for advertising. You can change this choice at any time in iOS Settings › Privacy & Security › Tracking. The site has no marketing analytics script or form database.
6. Retention and deletion
- Credentials and account metadata remain until disconnect or Delete all local data succeeds.
- The latest normalized usage snapshot is replaced by the next successful refresh and removed when its account is deleted.
- Rules, retry state, local onboarding, widget snapshots, and scheduled local notifications are removed by the applicable disconnect or full local deletion flow.
- Deleting local app data does not delete data held by a selected provider or Apple account history.
7. Destruction procedure
The app removes secure-storage credentials before removing related local database records, widget files, and scheduled alerts. If secure storage cannot be cleared, it does not report full deletion as complete. Electronic local records are removed through the app and operating-system storage interfaces.
8. Your rights and requests
You can disconnect an account or delete all local data in Settings. You may also request access, correction, deletion, restriction, objection, consent withdrawal, or portability where applicable by emailing the Privacy contact. We may request limited information needed to verify the request. We respond within the period required by applicable law and explain any lawful limitation. You can turn off usage analytics sharing at any time in Settings.
9. Security safeguards
Safeguards include iOS secure storage, PKCE and state checks for browser authentication, HTTPS, response-size/time/redirect limits, environment separation, credential-free widget schemas, Android backup exclusion, and shared redaction of authorization headers, tokens, cookies, OAuth code/state, and full email addresses. No system is perfectly secure; protect the device passcode and provider account.
10. Children and automated decisions
The service is intended for users aged 16 and older and is not directed to children under 16. It does not use personal data to make a solely automated decision that determines legal rights, eligibility, price, credit, employment, insurance, or access.
11. Changes, access requests, and remedies
Material changes are posted here with a new effective date. Privacy access requests and complaints are handled at the contact above. Korean users may also contact the Personal Information Dispute Mediation Committee (1833-6972, kopico.go.kr), KISA Privacy Infringement Report Center (118, privacy.kisa.or.kr), Prosecution Service (1301), or National Police (182). EU/EEA users should read the dedicated GDPR notice.
JoCoding, Inc. · mu07010@jocoding.net · +1 (231) 450-5622