# Privacy Policy

**Version:** 2026-08-08.1  
**Effective date:** August 8, 2026

The Haze Corp LLC, a Nevada limited liability company doing business as loggit ("The Haze Corp," "loggit," "we," "us," or "our"), operates the loggit mobile application, website, and related services (collectively, the "Services").

This Privacy Policy explains what information we collect, how we use and disclose it, how long we retain it, and the choices available to you.

## 1. Scope

This Policy applies to information processed through the Services. It does not control the independent privacy practices of Apple, websites you visit, people with whom you share information, or third-party services you use outside loggit.

## 2. Information we collect

The information we collect depends on how you use loggit.

### Account and profile information

We may collect:

- email address;
- authentication and account identifiers;
- display name, handle, initials, or other profile information you provide;
- information provided by Sign in with Apple, subject to your Apple settings; and
- account status, creation date, and security-related information.

We do not receive your Apple Account password.

### Inventory and User Content

We process information you create, upload, scan, photograph, record, organize, import, share, or store, including:

- items, categories, collections, locations, spots, and hierarchy relationships;
- photos and attachments;
- receipts, warranties, service records, notes, reminders, and activity records;
- purchase price, current value, serial numbers, identifiers, and related metadata;
- QR-code records and assignments;
- trip, packing, bag, move, box, and status information;
- exported or imported records; and
- other content you choose to provide.

User Content is private by default except when you choose to share supported records or as otherwise described in this Policy.

### Sharing and collaboration information

When you share a supported Location, Spot, Item, or related hierarchy, we process:

- owner and recipient account identifiers;
- Viewer or Editor permissions;
- membership, invitation, acceptance, and revocation records; and
- the content and related records made available through the selected share.

### Photos, Smart Add, and AI-assisted features

When you intentionally use Smart Add, image analysis, label or receipt analysis, AI-assisted descriptions, or similar features, we may process the image, text, prompt, existing record context, and generated result needed to perform the request.

Relevant information may be transmitted to OpenAI or another disclosed processor solely to provide, secure, and troubleshoot the requested feature and operate the Services.

### Voice features

When you intentionally use a voice feature, audio is transmitted for transcription and command processing. loggit does not intentionally retain the original raw voice audio after processing is completed.

We may retain the resulting transcript, interpreted command, command status, and related usage record so that the requested action can be completed, displayed, audited, retried, secured, and improved.

Do not speak information you do not want processed.

### Barcode, ISBN, and product lookup

When you request barcode, ISBN, or product lookup, we may transmit the code or query to providers such as Go-UPC or Open Library.

When you ask loggit to retrieve information from a product URL, our server may request that webpage and process publicly returned metadata. The operator of that webpage may receive standard request information such as an IP address, timestamp, and user-agent string.

Third-party product information may be inaccurate or subject to the provider's own terms and privacy practices.

### Subscription and purchase information

Apple and RevenueCat may provide us with:

- subscription product and entitlement;
- purchase, renewal, expiration, cancellation, and restore status;
- transaction or original-transaction identifiers;
- storefront or currency-related information; and
- limited diagnostic information needed to verify access.

We do not receive or store your complete payment-card number from App Store purchases.

### Technical, analytics, and security information

We may process:

- app version and build number;
- operating-system and device-type information;
- timestamps, request logs, IP address, and network or service diagnostics;
- authentication, abuse-prevention, rate-limit, and security events;
- feature-use events and product-interaction events;
- subscription and quota status; and
- crash or error information collected by our infrastructure when applicable.

Our first-party analytics are designed to record events and limited operational metadata, not private inventory names, photos, notes, receipts, serial numbers, or other User Content.

We do not use advertising identifiers, an advertising SDK, or cross-app tracking at launch.

The website may use strictly necessary cookies or local storage for security, session handling, preferences, and core functionality. We do not use advertising cookies at launch. If we later enable nonessential website analytics or advertising technologies, we will update this Policy and provide any consent controls required by law.

### Communications and support

If you contact us, we may collect your email address, message, attachments, screenshots, device/app information you provide, and our support-response history.

Do not send passwords, authentication tokens, Apple authorization codes, private keys, complete payment-card information, or unnecessary sensitive content.

## 3. How we use information

We use information to:

- create, authenticate, secure, and maintain accounts;
- provide, store, organize, search, display, sync, share, export, and delete records;
- provide AI-assisted, Smart Add, voice, barcode, ISBN, QR, reminder, analytics, packing, moving, and related features;
- process and verify subscriptions, plan limits, and entitlements;
- provide customer and privacy support;
- detect, investigate, and prevent fraud, abuse, unauthorized access, and security incidents;
- troubleshoot errors, monitor service health, enforce rate limits, and maintain availability;
- understand feature adoption and improve the Services using limited first-party analytics;
- communicate service, security, legal, or account notices;
- comply with law, legal process, and platform requirements;
- enforce our Terms and protect users, loggit, and others; and
- establish, exercise, or defend legal claims.

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use personal information for targeted advertising.

## 4. How we disclose information

We may disclose information in the following circumstances.

### At your direction

We disclose supported records to another user when you intentionally share them and according to the permissions you select.

### Service providers

We use service providers that process information on our behalf or as necessary to provide their services, including:

- Supabase for authentication, database, storage, serverless functions, and infrastructure;
- Apple for Sign in with Apple, App Store distribution, StoreKit, purchases, subscriptions, and account or token operations;
- RevenueCat for subscription and entitlement management;
- OpenAI for selected AI, image, transcription, and language-processing features;
- Go-UPC for barcode or product lookup;
- Open Library for book or ISBN information;
- email and communications providers for support;
- network, hosting, security, and infrastructure providers; and
- website operators whose public pages you ask our server to retrieve.

These providers may process information under their own terms, privacy policies, contracts with us, and applicable law.

### Legal, safety, and security

We may disclose information when we reasonably believe disclosure is required by law, subpoena, court order, or legal process, or is necessary to:

- protect rights, safety, property, or security;
- investigate fraud, abuse, or a security incident;
- enforce our Terms;
- respond to lawful requests; or
- establish, exercise, or defend legal claims.

### Business transfers

Information may be transferred in connection with a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law and appropriate protections.

### Aggregated or de-identified information

We may use or disclose aggregated or de-identified information that cannot reasonably be linked to an individual, subject to applicable law. We will not attempt to re-identify information that we maintain as de-identified except to test whether our de-identification processes are effective or as permitted by law.

## 5. User Content, sharing, and visibility

Your private inventory is not a public profile.

When you share a Location, Spot, Item, or hierarchy, authorized recipients may receive access to the associated content according to the selected permissions. You are responsible for reviewing what is included and choosing appropriate recipients.

A recipient may copy, export, photograph, screenshot, or disclose information outside loggit. Revoking access prevents future in-app access but cannot retrieve copies already made outside the Services.

## 6. Data retention

We retain information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security, meeting legal or accounting obligations, resolving disputes, and enforcing agreements.

Retention depends on the type of information:

- active-account data and User Content are generally retained while your account remains active or until you delete the content;
- support communications may be retained as reasonably necessary to resolve requests, improve support, maintain security, and document our response;
- security, request, and infrastructure logs may be retained for limited periods determined by operational need and provider settings;
- subscription, entitlement, and transaction records may remain in Apple, RevenueCat, or related systems under their retention requirements and legitimate operational or legal needs;
- provider-managed backups may retain deleted information temporarily until overwritten or expired; and
- information may be retained where required or permitted by law.

### Legal-acceptance records

To establish, exercise, or defend legal claims, we retain a minimal legal-acceptance record for seven years after account deletion.

The retained record is limited to:

- Terms, Privacy Policy, and arbitration version identifiers;
- cryptographic hashes of the accepted documents;
- acceptance, reacceptance, and arbitration opt-out timestamps;
- acceptance method and type;
- app marketing version and build number;
- platform and operating-system version;
- a former account identifier; and
- account-deletion and scheduled-purge dates.

The retained record does not include inventory content, photos, notes, receipts, serial numbers, Apple tokens, authorization codes, payment-card information, or your plaintext email address. Expired legal-acceptance records are scheduled for deletion through a monitored purge process.

## 7. Account deletion

You may initiate deletion in the app through:

Profile → Account Safety → Delete Account

The deletion process is designed to remove your account, user-owned production database records, stored files, sharing relationships, usage records associated with the account, and authentication account.

For Sign in with Apple accounts, loggit attempts to exchange and revoke the associated Apple authorization before destructive deletion begins. If the required Apple verification or revocation fails, destructive deletion should not begin and you may retry.

Deleting your loggit account does not cancel an Apple subscription. Cancel the subscription separately through your Apple account or App Store subscription settings.

After deletion, limited information may remain as described in Section 6, including provider-managed backups, subscription or transaction systems, security records, and the seven-year minimal legal-acceptance record.

## 8. Your choices and privacy rights

Depending on your location and applicable law, you may have rights to:

- access personal information;
- correct inaccurate information;
- receive a copy or portable export;
- delete information;
- restrict or object to certain processing;
- withdraw consent where processing is based on consent;
- appeal a privacy-request decision; and
- receive information about categories of information and recipients.

Most User Content can be reviewed, corrected, or deleted directly in the app. Supported CSV and PDF exports are available through the app.

You may manage sharing permissions and revoke in-app access. You may manage subscriptions through Apple.

For other requests, email privacy@loggit.life. We may need to verify your identity and may deny or limit a request where permitted by law, including to protect another person's rights, maintain security, complete a transaction, comply with law, or retain information needed to establish or defend legal claims.

Authorized agents may submit requests where permitted by law, subject to verification of their authority and your identity.

We will not discriminate against you for exercising applicable privacy rights.

## 9. California and United States state privacy disclosures

Depending on applicable thresholds and law, residents of California and other states may have rights concerning access, correction, deletion, portability, sale, sharing, targeted advertising, profiling, and appeals.

loggit does not sell personal information and does not share personal information for cross-context behavioral advertising. loggit does not use personal information for targeted advertising.

Because we do not engage in those activities, a sale/share or targeted-advertising opt-out does not currently change our core processing. We will honor applicable legally recognized preference signals where required if our practices change.

We may collect the categories described in Section 2, including identifiers, customer records, commercial or subscription information, internet or electronic activity, photographs and audio, user-generated content, and inferences produced by requested automated features. We use and disclose those categories for the business and commercial purposes described in Sections 3 and 4.

## 10. Children

The Services are intended for a general audience and are not directed to children under 13. Users must be at least 13 years old, or the minimum age required by applicable law, to create an account or use the Services.

We do not knowingly collect personal information from children under 13. If we learn that a child under 13 has provided personal information without legally valid authorization, we will take reasonable steps to delete the account and information.

A parent or guardian who believes a child under 13 has used loggit may contact privacy@loggit.life.

## 11. Legal bases for processing

Where laws such as the European Economic Area, United Kingdom, or Swiss data-protection laws apply, we process personal information under one or more of these legal bases:

- performance of a contract, including providing your account, storing records, sharing at your direction, and managing subscriptions;
- legitimate interests, including securing, maintaining, troubleshooting, and improving the Services, preventing abuse, and protecting legal rights, where those interests are not overridden by your rights;
- consent, where we specifically request it and you may withdraw it; and
- compliance with legal obligations.

You may have the right to object to processing based on legitimate interests or to lodge a complaint with your local data-protection authority.

## 12. International processing

The Services are operated from the United States. Information may be processed in the United States and in other countries where our service providers operate.

Where required, we rely on appropriate contractual, legal, or other safeguards for cross-border processing. Laws in those locations may differ from the laws where you live.

## 13. Security

We use reasonable administrative, technical, and organizational safeguards designed for the nature of the information and Services. Safeguards include authentication, authorization controls, owner-scoped access rules, private storage, restricted administrative access, transport encryption, secret-management practices, rate limiting, and controlled production changes.

No internet, cloud, mobile, or storage system is completely secure. We cannot guarantee that attacks, compromised credentials, software vulnerabilities, service-provider failures, human error, or other events will never result in unauthorized access, loss, alteration, or disclosure.

You are responsible for securing your device and credentials, maintaining current software, and reviewing sharing permissions.

## 14. Third-party links and services

The Services may link to or retrieve information from third-party services and websites. Their independent practices are governed by their terms and privacy policies.

We are not responsible for third-party privacy, security, accuracy, availability, or conduct outside our reasonable control.

## 15. Changes to this Policy

We may update this Policy as the Services, providers, laws, or data practices change.

We will update the version and effective date and provide additional notice or request renewed acknowledgement where required. Material changes will be reflected in the website, in-app disclosures, and App Store privacy information as appropriate.

## 16. Contact

The Haze Corp LLC / loggit  
4044 Dean Martin Dr  
Las Vegas, NV 89103  
United States

Privacy: privacy@loggit.life  
Support: support@loggit.life  
Telephone: 833-224-2022  
Website: https://loggit.life