Privacy Policy — Ôwn (Payback) | An App Idea LLC

Payback Own ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how our mobile application handles your data when you use our consumer insights analysis service.

"Your data is never sold. Your vault is built on your phone and encrypted (AES-256). We don't keep your data on our servers. AI analysis runs only when you ask it to — and what's sent for that analysis isn't retained by us. You have read-only access to the sources you connect, and you can disconnect or delete everything at any time."

— Our promise to you, in plain language

Core Privacy Principle: Payback Own is designed with a local-first architecture. Most file selection, parsing, storage, and many analysis steps occur on your device. Some features also transmit data off-device, including Google sign-in/ profile data, AI analysis inputs, analytics sync records, and app-launch telemetry. We do not use your data for cross-app tracking, data-broker sharing, or third-party advertising.

01

Information We Access

When you use Payback Own, you may choose to provide access to:

1. Google Takeout Archives (ZIP files stored in Google Drive)

2. Meta (Facebook/Instagram) Exports (Folder structure uploaded to Google Drive)

Important: You control what data you provide. The App only accesses accounts, files, and exports that you explicitly connect or select. Depending on the feature you use, selected file contents, metadata, or derived signals may be transmitted to our backend and AI providers for processing.

Payback Own supports two sign-in providers — you may use whichever you prefer.

Sign in with Google

Sign in with Apple

Token storage: All authentication tokens are stored locally on your device in encrypted storage (iOS Keychain / Android Keystore). No passwords are collected or stored.

02

How We Process Your Data

Most file handling and storage occurs on your device:

When you use AI-powered features, some data is transmitted off-device:

You control when AI runs. AI analysis occurs only when you initiate Instant Analysis, Quick Analysis, Freestyle analysis, or another AI-backed feature in the app. You can delete your local persona and results at any time from Settings.

03

Third-Party Services

We operate backend services (Node.js/Express) to:

We engage third-party processors to deliver authentication, AI analysis, telemetry, and hosting. Each processor handles personal data on our behalf under an applicable Data Processing Agreement (DPA). For users in the EEA, UK, Switzerland, and other jurisdictions with cross-border transfer requirements, our processors maintain transfer safeguards such as the EU Standard Contractual Clauses, the UK International Data Transfer Agreement, or adequacy regulations.

04

Data Storage and Retention

You have complete control over your data:

05

Account & Data Deletion

This section fulfils Google Play and Apple App Store requirements for account and data deletion disclosures. Full standalone deletion policy: milehighinterface.com/payback/data-deletion.html

Ôwn (published as "Payback Own" by Mile High Interface LLC) is a local-first app that analyses your Google and Meta data exports to generate behavioural insights. Most processing happens on your device, but some features also use server-side authentication, AI processing, analytics sync, and app-launch telemetry services.

What this deletes immediately:

Email: hello@anappidea.llc
Subject: Data Deletion Request – Ôwn
Include: The email address linked to your Google account (used for sign-in)
Response time: Within 5 business days

We do not intentionally retain full raw export files, full email bodies, or full calendar event descriptions on our own servers after request completion.

06

Tracking, Analytics, and Server-Side Data

Payback Own does not use your data to track you across apps or websites owned by other companies.

When you sign in and use synced features, we may collect and store:

These records are used for app functionality, product personalization, and understanding aggregate category distribution, sync health, and feature usage. You can request access to, export, or delete this backend data from Settings or by emailing hello@anappidea.llc.

The app uses Expo / EAS Insights for launch telemetry and release-health monitoring. This may include EAS client ID, project ID, app version, platform and OS version, and app launch events. We do not currently run a separate crash-reporting or session-replay SDK beyond this operational telemetry.

07

Children's Privacy

Ôwn (Payback Own) is not intended for users under 13 years of age (or under 16 in the EEA, or under 18 in India). We do not knowingly collect data from children. If you believe a child has used the App, please contact us at hello@anappidea.llc.

India — additional note: Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), users under 18 are classified as children. We do not knowingly allow users under 18 in India to use the App without verified parental consent. If a parent or guardian believes their child has used the App, please contact us immediately to request data deletion.

08

Security Measures

09

Your Privacy Rights

If you are in the European Economic Area, you have additional rights under GDPR:

If you are a California resident, you have rights under CCPA:

We do not sell your personal data or use it for cross-app tracking. However, some processing does occur on our backend and with third-party providers as described in this policy.

If you are in the United Kingdom, you have rights under the UK GDPR as retained in UK law by the Data Protection Act 2018:

If you are in India, you have rights under the Digital Personal Data Protection Act, 2023:

Grievance Officer (India): Mile High Interface LLC
Email: hello@anappidea.llc
Subject: DPDP Grievance – Ôwn
Response: Acknowledgement within 48 hours; resolution within 30 days

10

International Data Transfers

United Kingdom: Data transferred outside the UK is subject to UK GDPR transfer requirements. We rely on appropriate UK-approved transfer mechanisms (such as the UK International Data Transfer Agreement or adequacy regulations) for these international data flows.

India: Data transferred outside India is subject to the DPDP Act's provisions on cross-border personal data transfers. We only transfer data to jurisdictions or entities that maintain adequate data protections consistent with the DPDP Act. By using the App, you consent to the transfer of your personal data to the United States and other countries where our service providers operate, subject to the protections described in this policy.

11

Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in legal requirements, new features or services, or improved security practices. We will notify you of material changes via in-app notification on next launch, the updated "Last Updated" date at the top of this policy, and email (if you've provided contact information for support). Continued use of the App after changes constitutes acceptance of the updated policy.

12

Data Breach Notification

In the unlikely event of a data breach affecting our backend proxy, we will notify affected users within 72 hours with details including the nature of the breach, data affected, and remediation steps. We will report to relevant authorities as required by law, including the UK Information Commissioner's Office (ICO) for UK users and India's Data Protection Board (DPB) for Indian users.

Because much of the app's content storage remains local to your device, on-device deletion significantly reduces exposure. However, server-side account data, analytics records, logs, and third-party AI processing data may still be affected by a provider-side incident.

13

Compliance

14

Contact Us

Mile High Interface LLC
Email: hello@anappidea.llc
Website: milehighinterface.com/payback/privacy.html
Response time: Within 5 business days