LEGAL · PRIVACY— THE ALL THING AI · HOUSTON, TX —PRACTICAL AI FOR EVERY LIFE
The All Thing AIThe All Thing AI
App Store
Legal · Last Updated April 3, 2026

Privacy Policy & Terms of Service for Assistant-App (AssistantAPP)

Welcome to AssistantApp ("we," "our," "us," "Company," "Service"), developed and operated by The All Thing AI LLC. This document serves as both our Privacy Policy and Terms of Service. By downloading, installing, accessing, or using our mobile application ("Application," "App"), you agree to be bound by these terms and our privacy practices.

IMPORTANT

PLEASE READ THESE TERMS CAREFULLY. BY USING OUR SERVICE, YOU AGREE TO BE LEGALLY BOUND BY THESE TERMS. IF YOU DO NOT AGREE, DO NOT USE THE APPLICATION.

PRIVACY POLICY

Collection of Your Information

We may collect information about you in a variety of ways. The information we may collect via the Application includes:

1. Personal Data

Personally identifiable information, such as your name, email address, phone number, company name, job title, and mailing address that you voluntarily provide when you register with the Application or update your profile. This information is securely managed by our authentication provider, Amazon Web Services (AWS) Cognito.

If you sign in using Google or Apple Sign-In, we receive your unique identifier, email address, display name, and email verification status from the identity provider. We request only the minimum scopes necessary: openid, email, and profile.

2. User-Generated Content

3. Financial Data

All financial information is stored and processed by our payment processors, including RevenueCat and Apple (App Store) for iOS, and RevenueCat and Google (Play Store) for Android. We do not collect or store any payment card details on our servers. RevenueCat receives your unique user identifier, subscription events, product identifiers, and purchase receipts for subscription management. We encourage you to review their respective privacy policies.

4. Device and Usage Data

Information our servers automatically collect when you access the Application, such as your IP address, device type, operating system, and usage patterns within the app, including tokens consumed and features used. This data is used for analytics, rate limiting, and to improve service reliability.

5. Health and Wellness Data

If you use the Health Hub feature, we collect:

If you grant access, we may read and write data from Apple HealthKit, including step count, active energy burned, body mass, and dietary energy consumed. HealthKit data is used solely within the app to provide personalized health insights and is not shared with third parties for advertising or data mining.

HEALTH DATA IS CONSIDERED SENSITIVE PERSONAL INFORMATION. Under GDPR, health data is "special category data" (Article 9) requiring explicit consent. Under CCPA/CPRA, it is classified as sensitive personal information. We process health data based on your explicit consent, which you provide by opting to use Health Hub features. You may stop using Health Hub features at any time.

6. Calendar and Meeting Data

If you connect calendar integrations, we collect:

We support the following calendar integrations:

Google Calendar: We request OAuth scopes including calendar, calendar.events, userinfo.email, drive.readonly, and meetings.space.readonly. This allows us to read and write calendar events, detect meeting URLs, and manage Google Meet integration.

Microsoft Outlook/Teams: We request OAuth scopes including OnlineMeetings.ReadWrite, Calendars.ReadWrite, and User.Read. This allows us to read and write calendar events and manage Teams meeting integration.

Zoom: We request OAuth scopes including meeting:write, meeting:read, recording:read, user:read, and webhook:read. This allows us to access meeting information and recordings.

Apple Calendar: Accessed locally on your device via iOS Calendar permissions. No OAuth required, but event data is synced to our servers for analysis and integration.

You may disconnect any calendar integration at any time through the app settings.

7. Biometric Authentication Data

If you enable biometric authentication (Face ID or Touch ID), your biometric data is processed entirely on your device using iOS native APIs.

YOUR BIOMETRIC DATA (FACIAL OR FINGERPRINT DATA) IS NEVER TRANSMITTED TO, COLLECTED BY, OR STORED ON OUR SERVERS. It remains exclusively in your device's secure enclave.

When biometric authentication is enabled, we store your authentication credentials (encrypted email/password for email users, or encrypted refresh token for social login users) in your device's encrypted Keychain. These credentials are released only after successful biometric verification on your device.

You may disable biometric authentication at any time. It is entirely optional.

8. Focus Mode and Digital Wellness Data

If you use the Focus Mode feature, we use Apple's FamilyControls, DeviceActivity, and ManagedSettings frameworks to help you manage app usage on your device. When Focus Mode is enabled, we collect:

WE DO NOT COLLECT THE IDENTITIES OR NAMES OF APPS YOU BLOCK. App tokens used for blocking remain entirely on your device within the App Group container. Only aggregate numerical statistics (counts and minutes) are synced to our servers.

Apple FamilyControls requires individual authorization on your device. You may revoke this authorization at any time in iOS Settings.

9. Push Notifications

If you enable push notifications, we collect your device push notification token (via Expo Push Service) to deliver notifications. You can manage notification preferences for specific categories (focus session alerts, pre-meeting alerts, override expiry notifications) within the app settings. You can disable all push notifications through your device settings at any time.

10. Scheduling Link Analytics

For scheduling links you share with others, we collect data from visitors including IP addresses, user agent information (truncated to 500 characters), click events, booking events, and timestamps. This data is used to provide you with analytics about your scheduling link performance and for rate limiting purposes.

11. QR Code Contact Information

When you generate a QR business card, your profile information (name, email, phone, company, title, address, and social links) is encoded in vCard format within the QR code. Once shared, this information is permanently embedded in the QR code and is no longer under our control.

12. On-Device Data Storage

We store certain data locally on your device:

On-device data is not transmitted to our servers except during synchronization of supported data types (events, records, clients).


Use of Your Information

We may use information collected about you via the Application to:


Artificial Intelligence and Automated Processing

We use third-party AI services to provide core features of the Application. When you use AI-powered features, your data is transmitted to external AI providers as follows:

1. Audio Transcription

Your audio recordings are processed by one or more of the following services:

Full audio recordings are transmitted to these services for processing.

2. AI Form Filling and Analysis

Your transcripts, form schemas, and related context are sent to OpenAI (GPT models) and/or Google AI (Gemini models) for:

3. Health AI Processing

If you use Health Hub features, the following data may be sent to OpenAI:

4. Business Card and Image Processing

Business card photos are sent to OpenAI Vision API to extract contact information including names, emails, phone numbers, and company details.

5. AI Data Retention and Training

IMPORTANT: Third-party AI providers may retain your data according to their own policies. We recommend reviewing:

We are committed to implementing data retention controls with our AI providers to minimize unnecessary data retention.

USER DATA INCLUDED IN AI PROMPTS MAY CONTAIN PERSONAL INFORMATION such as names, contact details, health metrics, and meeting content. This data is transmitted via encrypted connections (HTTPS/TLS) to AI provider servers located in the United States.


Disclosure of Your Information

We do not sell your personal information to third parties. We may share information we have collected about you in certain situations:

1. By Law or to Protect Rights

If we believe the release of information about you is necessary to respond to legal process, to investigate or remedy potential violations of our policies, or to protect the rights, property, and safety of others, we may share your information as permitted or required by any applicable law, rule, or regulation.

2. Third-Party Service Providers

We may share your information with third parties that perform services for us or on our behalf, including:

We only share the minimum information necessary for them to perform their designated functions. All data is transmitted via encrypted connections.

3. Business Transfers

We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.


Data Retention

We retain your personal information according to the following schedule:

If you wish to have specific data deleted, contact us at info@theallthing.ai.


Security of Your Information

We use administrative, technical, and physical security measures to help protect your personal information, including:

However, NO METHOD OF TRANSMISSION OVER THE INTERNET OR ELECTRONIC STORAGE IS 100% SECURE. We cannot guarantee absolute security of your information.


Audio Recording and Consent

The Application allows you to record audio, including during meetings.

YOU ARE SOLELY RESPONSIBLE FOR COMPLYING WITH ALL APPLICABLE RECORDING LAWS.

Many jurisdictions, including California, Illinois, Florida, Pennsylvania, and others, require the consent of all parties being recorded. Before recording any conversation or meeting involving other participants, you must:

We are not responsible for your failure to obtain required consent. Meeting recordings may capture the voices and speech of non-users who have not agreed to this Privacy Policy.


Your Privacy Rights

Depending on your location, you may have the following rights:

1. All Users

2. European Users (GDPR)

Under the General Data Protection Regulation, you have additional rights:

Lawful basis for processing: We process your personal data based on (a) your consent for optional features such as Health Hub and calendar integrations, (b) performance of our contract with you for core app functionality, and (c) our legitimate interests for analytics, security, and service improvement.

Cross-border transfers: Your data is processed in the United States (AWS us-east-1 region) and by US-based third parties (OpenAI, Google, Microsoft, RevenueCat). We rely on the EU-US Data Privacy Framework and Standard Contractual Clauses for lawful data transfers.

To exercise GDPR rights, contact us at info@theallthing.ai with "GDPR Request" in the subject line. We will respond within 30 days.

You have the right to lodge a complaint with your local supervisory authority.

3. California Residents (CCPA/CPRA)

Under the California Consumer Privacy Act and California Privacy Rights Act, you have the right to:

Categories of personal information collected: Identifiers (name, email, IP address), commercial information (subscription history), biometric information (Face ID/Touch ID verification on device only), internet activity (usage data, analytics), geolocation, audio/visual data (recordings, photos), health information, professional information, and inferences drawn from the above.

To submit a CCPA request, email info@theallthing.ai or call 713-614-6647. We will verify your identity and respond within 45 days.

4. Texas Residents

Under the Texas Capture or Use of Biometric Identifier Act (CUBI), we disclose that biometric identifiers used for authentication (Face ID/Touch ID) are processed entirely on your device and are never captured, stored, or transmitted by our servers.


Account Deletion

You have the right to delete your account and all associated data at any time.

How to delete your account: Navigate to Settings in the app, or contact us at info@theallthing.ai.

What happens when you delete your account:

1. Immediate deletion:

2. Subscription cancellation:

3. Authentication cleanup:

4. Audit trail retained:

We retain a deletion audit record containing only: your email address, account type at deletion, total chips/tokens consumed, and whether you used the free trial. This record is retained for legal compliance and fraud prevention.

5. Third-party data:

Data previously shared with third parties (OpenAI, Google, RevenueCat, etc.) is subject to their own retention and deletion policies. We cannot guarantee deletion of data already processed by third-party AI services.

Account deletion is permanent and cannot be undone. If you wish to use AssistantApp again, you will need to create a new account.


Data Breach Notification

In the event of a security breach affecting your personal information, we will:


Data Portability and Export

You may export your data in the following formats:

For a comprehensive export of all your personal information (including health data, usage metrics, and other data categories), contact us at info@theallthing.ai. We will provide this within 30 days.


Do Not Track

Our Application does not currently respond to Do Not Track (DNT) browser signals. However, as a mobile application, we do not engage in cross-site tracking. You can control data collection by managing your app permissions and opting out of optional features.


Tracking Technologies

We do not use traditional cookies. However, we use the following on-device storage mechanisms:

RevenueCat SDK may use device identifiers for subscription management and fraud detection.

TERMS OF SERVICE

Acceptance of Terms

By accessing and using this Application, you accept and agree to be bound by the terms and provision of this agreement. You must be at least 18 years old (or the age of majority in your jurisdiction) to create an account and enter into this agreement. If you are between 13 and 17 years of age, you may only use the Application with the consent and supervision of a parent or legal guardian who agrees to be bound by these Terms.

Service Description

AssistantApp provides audio transcription, AI-powered form filling, health and nutrition tracking, calendar management, digital wellness tools, and related productivity services on a subscription basis. The Service uses artificial intelligence and machine learning technologies provided by third parties (OpenAI, Google, Amazon) to process your data.

User Obligations and Prohibited Uses

You agree to use the Service only for lawful purposes and in accordance with these Terms. You agree NOT to:

AI-Generated Content

Content generated by AI features (form fills, health insights, meeting summaries, transcriptions, coaching advice) is provided for informational purposes only. AI outputs may contain errors, inaccuracies, or omissions.

YOU RETAIN OWNERSHIP OF YOUR ORIGINAL CONTENT (audio recordings, form data, health logs). AI-generated outputs derived from your content are licensed to you for your personal and business use. We retain no ownership rights over AI outputs generated from your data.

Health-related AI outputs (nutrition analysis, workout recommendations, health coaching) ARE NOT MEDICAL ADVICE. Always consult a qualified healthcare professional before making health decisions based on AI-generated insights.

Disclaimers and No Warranties

THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT ANY WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED.

WE SPECIFICALLY DISCLAIM:

Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW:

1. OUR TOTAL LIABILITY TO YOU SHALL NOT EXCEED THE AMOUNT YOU PAID TO US IN THE 12 MONTHS PRECEDING THE EVENT GIVING RISE TO LIABILITY

2. WE SHALL NOT BE LIABLE FOR:

3. SOME JURISDICTIONS DO NOT ALLOW LIMITATION OF LIABILITY, SO THESE LIMITATIONS MAY NOT APPLY TO YOU

Indemnification

You agree to defend, indemnify, and hold harmless the Company, its officers, directors, employees, agents, and affiliates from and against any and all claims, damages, obligations, losses, liabilities, costs, or debt, and expenses (including attorney's fees) arising from:

Governing Law and Dispute Resolution

1. Governing Law

These Terms shall be governed by and construed in accordance with the laws of the State of Texas, without regard to its conflict of law principles.

2. Mandatory Arbitration

Any dispute, claim, or controversy arising out of or relating to these Terms or the Service shall be settled by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules. The arbitration shall be conducted in Houston, Texas.

3. Class Action Waiver

You agree that any arbitration or legal proceeding shall be limited to the dispute between you and the Company individually. You waive any right to participate in class action lawsuits or class-wide arbitrations.

Force Majeure

We shall not be liable for any failure or delay in performance under these Terms which is due to circumstances beyond our reasonable control, including but not limited to acts of God, war, terrorism, pandemic, government regulations, or failures of third-party service providers.

Subscription Terms

1. Platforms

Subscriptions are available through the Apple App Store (iOS) and Google Play Store (Android). Payment processing is managed by RevenueCat in conjunction with the respective app store.

2. Billing

Subscriptions are billed monthly in advance. Payment will be charged to your Apple ID account or Google Play account at confirmation of purchase.

3. Auto-Renewal

Your subscription automatically renews each month unless cancelled at least 24 hours before the current period ends.

4. Cancellation

You may cancel your subscription at any time:

Cancellation will be effective at the end of the current billing period.

5. Token/Chip Purchases

One-time token (chip) purchases are non-subscription consumable purchases processed through the respective app store via RevenueCat.

6. No Refunds

All subscription fees and token purchases are non-refundable except as required by applicable law or the refund policies of Apple or Google.

Data Loss and Backup

YOU ARE SOLELY RESPONSIBLE FOR BACKING UP YOUR DATA. We may, but are not obligated to, maintain backups of your content. We are not liable for any loss, corruption, or deletion of your data.

Changes to Terms

We reserve the right to modify these Terms at any time. We will notify you of significant changes by updating the "Last Updated" date and, for material changes, by sending a notification through the app or to your registered email address. Your continued use of the Service after such modifications constitutes acceptance of the updated Terms.

Severability

If any provision of these Terms is found to be unenforceable or invalid, that provision will be limited or eliminated to the minimum extent necessary so that these Terms will otherwise remain in full force and effect.

Entire Agreement

These Terms constitute the entire agreement between you and the Company regarding the Service and supersede all prior agreements and understandings.

Policy for Children

We do not knowingly solicit information from or market to children under the age of 13. Users between 13 and 17 may use the Application only with parental or guardian consent.

If you become aware of any data we have collected from children under age 13 without parental consent, please contact us immediately using the contact information provided below. We will promptly delete such data from our systems.

For GDPR jurisdictions, the minimum age for consent to data processing is 16. Users under 16 in the EU/EEA require parental consent.

Third-Party Privacy Policies

We encourage you to review the privacy policies of our third-party service providers:

Contact Us

If you have questions or comments about this Privacy Policy, or wish to exercise any of your privacy rights, please contact us at:

The All Thing AI LLC

825 Town and Country Blvd, Suite 1200

Houston, TX 77024, USA

Email: info@theallthing.ai

Phone: 713-614-6647

Website: https://www.theallthingai.com/

For privacy-specific requests, include "Privacy Request" in your email subject line. We will acknowledge receipt within 2 business days and respond to your request within 30 days (extendable to 60 days for complex requests with notice).

By using AssistantApp, you acknowledge that you have read, understood, and agree to be bound by these Terms of Service and Privacy Policy.