Privacy Policy

Effective Date: October 3, 2026

App: PutIt — Android package com.yifora.putit
Operator: YIFora LLC
Company registration: Ohio, USA
Support, privacy and data/account-deletion requests: yiforallc@gmail.com

1. Scope

This Policy explains how PutIt processes information when you use its account, item organizer, Notes, Downloads, location and reminder tools, translation, ingredient scanner, Friends, messaging, calls and Premium features. Different features use different storage and processing methods. Local storage does not mean that every related operation, such as speech recognition, map loading, recovery email or sharing, stays on your device.

The intended distribution of PutIt’s first public release is the United States only. YIFora LLC is not currently targeting the European Union/European Economic Area, the United Kingdom, Japan or other international markets. Before expanding distribution to another country or territory, YIFora LLC will review this Privacy Policy, the Terms & Conditions and the applicable legal requirements for that market. This intended distribution scope is not a statement that all processing or service providers are located in the United States, and it does not exclude mandatory laws or rights that otherwise apply.

Downloads Cloud Sync and Backup and the in-app account-deletion action are currently temporarily disabled. See Sections 3 and 9.

2. Accounts and profile information

PutIt uses Clerk for account registration, email verification, sign-in, sessions and password recovery. These processes involve your email address, authentication information and verification details. PutIt uses your Clerk user identifier to associate data and purchases with your account, and the account-creation date to determine the account-based trial period.

PutIt also processes profile information, such as your display name, profile photo, username and public identifier, account status and associated timestamps. Profile information may appear to other users in user-search results, friend requests and communications. A search using an email address can be submitted to Clerk to identify a matching account; search results return public profile information rather than disclosing the matching email address. PutIt does not import your phone’s address book.

3. Your content and where it is stored

Items. Saved item descriptions and associated information, photos and any attached audio are processed by PutIt servers. The current item-entry screen converts dictation to text and does not attach an audio file for that dictation. Structured records are stored in the server database, and uploaded media in object storage. Local item data is also used as a cache; it is not an independent cloud backup.

Notes. Notes, folders, formatted content and attachments are stored locally on your device, separately for each account. Notes content is not synchronized to PutIt cloud storage. Private Notes use additional local PIN/key-based encryption for protected content. This does not mean that every note or all data stored by the app are encrypted in that way. Viewing protected content requires decrypted information in memory and may involve temporary viewing files managed by the app.

Private PIN recovery involves verifying your signed-in account through PutIt and its email through Clerk, and sending a recovery code through Resend. Recovery records include verification and authorization information, protected identifiers linking the request to the content concerned, and attempt information. This email flow does not send your note content or PIN to the email service.

Notes moved to Trash become eligible for local permanent cleanup after seven days. Cleanup depends on the app running and successfully performing its cleanup process; deletion at an exact instant on the seventh day is not guaranteed.

Downloads. Imported files, folders and their organizational information are currently kept locally on your device. Cloud Sync and Backup are temporarily disabled. These local files are not backed up by that feature and are not promised to return after reinstalling PutIt or moving to another device. Use a separate copy for important files.

Sharing and exports. When you share, export, save outside the app or open content in another app, that content is made available to the recipient or selected service. Copies outside PutIt’s control are governed by that recipient’s actions or the other service’s practices. Authorized media access may use time-limited download links; anyone who possesses such a link may be able to access its content while it remains valid. Avoid distributing links or content you intend to keep private.

4. Camera, microphone and speech processing

The camera is used when you choose to take or select content, scan a barcode, analyze a translation image, save a car photo or make a video call. The microphone is used for voice input, voice messages/recordings and voice or video calls.

Voice input in item entry, voice search, Where Am I and translation uses the device’s native speech-recognition service through the app. These calls do not require exclusively on-device recognition. Depending on the device and recognition service, audio may be processed by the operating system’s speech provider over the network.

Voice input in reminder editing and reminder-location search instead records audio and sends it to PutIt, which submits it to OpenAI through the Replit AI integration proxy for transcription. The resulting text is returned to the app and may become content you save.

The current Android translation screen uses Google ML Kit for on-device text translation and image-text recognition. Language models may be downloaded from Google’s services. Camera image analysis is initiated by your action; the preview is not a continuous upload to PutIt. This screen does not use PutIt’s cloud image-text recognition service. Do not assume that the speech-recognition portion is offline simply because text/image translation is local.

5. Location, background access, maps and reminders

Where Am I. PutIt obtains location when you request the feature, resolves addresses, displays maps, and lets you save named places. Saved names, addresses and coordinates are stored through PutIt servers. Address/place searches and selected-coordinate lookups may use Photon/Komoot, including the search text, coordinates or geographic search context. Native address resolution uses the device’s location/geocoding services.

Location reminders. PutIt stores reminder text, status, whether time scheduling is enabled and the scheduled time, selected location/geofence details and record timestamps on its servers, and maintains information needed for local scheduling. With the relevant permission, device location monitoring uses background location to detect arrival at an enabled reminder location while the app is not open. This does not continuously upload a GPS track for the reminder. Time reminders and location alerts are scheduled locally and depend on device permissions and operation.

Masari. When you start recording a driving trip, PutIt processes location points, accuracy, timestamps, speed where available, duration and distance. Active driving tracking uses background location updates and an active Android location service during tracking. Trip history, measurement settings, and the saved car location, note and optional photo are stored locally.

When you request a walking route, the starting and destination coordinates are sent through PutIt to OpenRouteService. The full driving history is not submitted by that route request. Upstash Redis is used to limit requests with a protected account identifier derived by hashing and a short-lived request count; that information does not contain GPS coordinates.

Map and sharing services. Embedded maps request map images from OpenStreetMap and load Leaflet map-display resources from unpkg. These requests disclose the map area being viewed and network request information. Opening Google Maps or using your device’s share controls sends the chosen location link and accompanying content to that service or recipient. Sharing a saved car location does not automatically share your current location. Sharing a location through a PutIt conversation stores it as conversation content for the participants.

You can control location permissions in Android settings. Background location is used for enabled geofences and user-started driving tracking, not merely because the app has a location-related feature.

6. Halal Scanner and Calculator

The ingredient scanner reads a barcode and submits it to PutIt, which queries USDA FoodData Central and Open Food Facts for the matching product and published ingredient information. The barcode, product information and classification results are processed for that lookup. Classification uses ingredient rules; it does not send product photographs to an AI classifier.

The tool checks for pork and its derivatives in the published ingredient list associated with the exact barcode. It is not a halal certificate, fatwa or determination that every aspect of a product is religiously acceptable.

Calculator operations are performed locally on your device, rather than uploaded to PutIt for calculation.

7. Friends, messages, calls and notifications

PutIt processes friend-search information, friend requests and relationship/block records. Messages may contain text, photos, files, voice messages, shared item snapshots and locations. Servers store conversation content, attachment references and information such as participant identifiers, timestamps and delivery/read status. Conversation access is restricted to participants, but this Policy does not represent messaging as end-to-end encrypted.

Voice and video calls use WebRTC. PutIt processes participant identifiers, call type, call state and timing/history information. Cloudflare Workers supports call connection setup. Audio/video media is intended to travel directly between participants when the connection permits; PutIt does not promise that every connection follows the same network path.

Expo and Firebase Cloud Messaging are used for remote notifications, including messages and incoming calls. Push-token and device information is processed to deliver them. Message notification settings can control whether notifications, sound, vibration and previews are enabled; disabling previews changes the notification content sent for that purpose. Notification display may reveal content to people who can see your device. Local reminder notifications do not all use this remote delivery process.

Some friend-management/removal actions are temporarily unavailable. This does not change the processing of relationship, block, message and call data by the relevant services.

8. Premium, support and operational information

Google Play Billing processes Android subscription purchases. RevenueCat associates purchase/subscription information and Premium entitlement status with the app-user identity and supports purchase restoration. PutIt receives product and entitlement information; payment-card information is handled by Google Play rather than collected by PutIt. Google Play processes payment information under its own terms.

Halal, Translation and Calculator are permanently free. Notes, Reminders, Masari, Downloads and Where Am I share one 15-day access period beginning at account creation. Friends requires paid Premium without this trial. Items allow up to 15 saved items without Premium and up to 1,000 with Premium. The internal account-based trial does not create a Google Play subscription or raise the item limit.

Support requests, where the email service is configured, include your subject, message, sender email, Clerk user identifier and any optional screenshot, sent through Resend to YIFora LLC’s support contact. Do not include passwords or unrelated sensitive information.

Servers and the app process operational information for troubleshooting, service security, access control and abuse/request limits. Records can include request identifiers, the action and service address requested, response status, errors and diagnostic information, account-related identifiers or references to stored content. Recovery request limits use account information and a protected summary derived from network information; image-text recognition and product lookups also use request limits. Protective measures for logs do not guarantee that every diagnostic record contains no personal information.

9. Retention, deletion and controls

YIFora LLC retains personal information only for as long as appropriate to provide the service, for legitimate operational, security or legal purposes, and as required or permitted by applicable law. Retention depends on the type of information, its use, available deletion controls, shared conversations and any applicable legal obligations. This is not a promise of a uniform retention period or an automatic purge schedule.

This Policy does not promise a single retention period for all cloud records, logs, backups, support messages or service providers. Local Notes, Downloads and Masari content follow the behavior described in this Policy, including eligibility for Notes Trash cleanup after seven days, with deletion dependent on the app successfully performing cleanup. Expiry of a verification code, sign-in credential, request counter or download link does not mean that every related record or backup has been deleted. No fixed deadline for completing account, storage, provider or backup deletion is promised here.

You may edit or delete content through the controls that are available for the feature. Android permissions and message-notification settings can also limit processing or display. Turning off permission may prevent the related feature from working; it does not by itself delete content already saved or shared.

Current account-deletion availability: the in-app account-deletion action is temporarily disabled. Contact YIFora LLC at yiforallc@gmail.com regarding privacy, personal-data or account-deletion requests, where applicable. Sending an email or selecting a disabled button is not confirmation that deletion has been completed. Ordinary emails do not automatically trigger account deletion, and there is no separate automated verification process for deletion requests sent by ordinary email. Additional information may be needed to establish ownership and handle a request lawfully; do not email your password, Private PIN, recovery keys or verification codes.

If the in-app account-deletion service becomes available, it requires a signed-in account verified through Clerk, rather than relying on an email address stated in a message. When available and accepting a request, it blocks further use of that account, removes personal server records and arranges cleanup of related storage and Clerk account data. Acceptance of a request does not mean that all provider cleanup is complete. This description is not a statement that the service is currently available. No completion deadline or automatic processing of emailed requests is promised.

Account deletion does not necessarily remove conversation messages, message-linked attachments, shared item snapshots or call/history references needed by other participants. A limited account reference may remain instead of the removed display profile, together with records needed to complete deletion and keep related data consistent. Such records may remain after account deletion for the relevant service, legitimate operational, security or legal purpose, subject to applicable law; no general automatic purge deadline is promised. Deleting your account does not necessarily remove another participant’s conversation/history, previously delivered attachments, or copies saved elsewhere. No immediate deletion from all recipient devices or provider backups is guaranteed.

Deleting PutIt or its account is not subscription cancellation. Manage subscriptions separately through Google Play. Locally stored Notes, Downloads and Masari content may be lost when app data is cleared or the app is removed; Android device/system backup behavior is not a PutIt cloud-backup guarantee.

10. Service providers, security and your rights

The service providers and recipients described above include Clerk; PutIt’s server database and hosting infrastructure, including Replit hosting; Replit’s storage and AI integration services; Google Cloud Storage; OpenAI for the described transcription; Google/Android speech, location and ML Kit services; Photon/Komoot; OpenStreetMap and unpkg; OpenRouteService and Upstash; USDA FoodData Central and Open Food Facts; Cloudflare; Expo and Firebase Cloud Messaging; RevenueCat and Google Play; Resend; and services or recipients you choose when sharing/opening content.

PutIt uses Replit hosting, a server database, and the storage, AI and other services disclosed above. This Policy does not specify every underlying database subcontractor, the actual hosting/storage geography, all provider processing locations, or provider retention/training settings. Ohio company registration is not a statement that data are stored in Ohio or exclusively in the United States. Service providers may process information outside your country of residence. This Policy does not promise a specific data-storage region or transfer mechanism, or make a blanket statement that all information is never sold or disclosed; the content licence in the Terms separately gives no right to sell user content or use it for unrelated advertising or independent commercial exploitation.

Security measures include sign-in verification for server access, checks that users own or are participants in the content they access, time-limited media access, request limits and local protection of Private Notes. These measures do not guarantee absolute security, protect all ordinary Notes with the Private encryption scheme, or establish end-to-end protection for every communication.

Depending on applicable United States federal or state law, including its residency and business-applicability requirements, you may have rights to request access, correction, deletion or a copy of personal information, and to object to, restrict or opt out of specified processing, or withdraw consent where consent is applicable. This does not assert that every state privacy statute applies to YIFora LLC or gives every user identical rights. Contact yiforallc@gmail.com for these requests. Verification may be needed before providing account information. This statement does not promise an in-app export function for every category or a fixed response deadline. Any response or deletion deadline, appeal opportunity or other mandatory requirement imposed by applicable law remains applicable; no dedicated in-app appeal process is promised.

United States-only intended distribution for the first public release does not itself mean that Google Play country availability or geographic access restrictions are in place. Subscription pricing regions and supported languages do not determine app distribution countries. This Policy does not impose geographic restrictions, and United States-only distribution does not imply United States-only storage or provider processing.

11. Children, changes and languages

PutIt is not directed to children under 13. Users under 13 are not permitted to create or use a PutIt account. Users aged 13 but under 18 should use PutIt with the permission of a parent or legal guardian where required by applicable law.

YIFora LLC does not knowingly collect personal information from children under 13. If YIFora LLC becomes aware that such information has been collected, it will take appropriate steps to delete it, subject to applicable law. To raise a concern about a child’s information, contact yiforallc@gmail.com. This does not promise instantaneous deletion from every shared history or backup, or waive child-specific protections imposed by law.

This age policy is a rule for account use, not a representation that PutIt provides an age-verification or parental-consent verification system.

This Policy may be updated to reflect actual changes to PutIt or its processing practices. Privacy and Terms text are available through Settings. PutIt does not provide a dedicated policy-update acknowledgement process or a record of acceptance tied to a particular version. Updating displayed text does not by itself establish that you received notice or consented to processing that requires consent. Any notice or consent required by applicable law remains required; no automatic notice delivery or fixed advance-notice period is promised.

The English and Arabic versions are intended to have materially equivalent meaning. If there is a discrepancy in translation, the English version is the reference version to the extent permitted by applicable law. This does not reduce any mandatory user, consumer, privacy or language rights, or override an applicable legal requirement concerning the version provided to you.