# VerityGold Privacy Policy

Effective date: June 11, 2026

Last updated: June 11, 2026

This is the privacy policy for VerityGold, an iOS app published by RiteUpAI (the "Developer", "we", "us"). This policy explains exactly what happens with your data when you use the app.

## TL;DR

- VerityGold collects nothing. Nothing you enter or import leaves your device.

- We do not run any analytics. We do not have a server. We have no way to see what you do in the app.

- Permissions you grant (Contacts, Apple Health, Calendar, Camera) are used only to bring data into your device's local copy of the app.

- If you choose to enable iCloud sync (in a future version of the app), your data is stored in your iCloud account and never reaches us. Apple's iCloud terms apply to that storage.

If you'd like the longer version with the legal-style detail, keep reading.

---

## 1. Who we are

VerityGold is published by RiteUpAI. Bundle identifier `com.riteupai.VerityGold`. For privacy questions: support@riteupai.com.

## 2. What VerityGold does

VerityGold is a personal Master Data Management (MDM) app. It helps you build one trusted, unified profile of yourself and the people, accounts, subscriptions, and other records in your life by:

- Importing data from your iOS Contacts, Apple Health, Calendar, CSV files, and scanned documents.

- Detecting duplicate records across the data you've imported.

- Letting you merge, hide, edit, and audit the unified profiles that result.

All of this happens on your device only. There is no VerityGold server, no third-party analytics, no advertising SDK, no telemetry.

## 3. Data we do NOT collect

We do not collect, transmit, log, store, or otherwise have access to:

- Your personal contacts.

- Your health data.

- Your calendar events or attendees.

- Photographs of documents you scan.

- Text recognized from those scans.

- The contents of CSVs you import.

- The records, subjects, lineage entries, or stewardship tasks you create inside VerityGold.

- Your usage patterns inside the app.

- Diagnostic crash data except what Apple's TestFlight / App Store automatically gathers if you opt in to share crash reports with developers in iOS Settings. That sharing is controlled by you in iOS Settings, not by VerityGold.

If you provide bug reports or support requests by email, the contents of those emails (which you authored) are received and read by us — see Section 8.

## 4. Permissions VerityGold requests

| Permission | What we read | Why | What leaves your device |

|---|---|---|---|

| Contacts | Names, emails, phone numbers, addresses, birthdays, organization, job title | To create source records in the Person domain | Nothing |

| Apple Health | Only the fields you toggle on in Smart Import → Configure Apple Health: characteristics (DOB, biological sex, blood type), body measurements, vitals, activity, sleep | To populate your Health-domain unified profile | Nothing |

| Calendar (full access) | Attendee email addresses from events in the past 6 months | To enrich your contact records with meeting frequency. We do not store event titles, descriptions, locations, or any content beyond attendee emails. | Nothing |

| Camera | Images of documents you choose to scan | To extract text from those images on-device using Apple's Vision framework | Nothing. Images aren't stored — only the recognized text. |

You can revoke any permission at any time in iOS Settings → Privacy. The corresponding feature will stop working but VerityGold will continue to function.

## 5. AI processing

VerityGold uses Apple's Foundation Models framework for some on-device AI features (entity-resolution tie-breaking, accuracy scoring, natural-language queries). Those features:

- Run entirely on your device, on Apple's hardware, using Apple's models.

- Do not transmit your data to OpenAI, Anthropic, Google, or any other third-party AI provider.

- Require a device that supports Apple Intelligence; on devices that don't, the AI features are hidden and the rest of the app works normally. The prompts sent to the model contain attribute values you've already imported (e.g. "Sarah Mitchell, sarah@example.com…"); these stay on-device.

Apple's privacy disclosures cover the on-device behavior of Foundation Models. See [apple.com/privacy](https://www.apple.com/privacy/).

## 6. iCloud sync (when enabled)

Future versions of VerityGold may sync your records to your own iCloud account via Apple's CloudKit (currently disabled in this build). When enabled:

- Data syncs between your iOS devices that are signed into the same Apple ID.

- Storage and transit are handled by Apple's CloudKit infrastructure under Apple's terms ([apple.com/legal/internet-services/icloud](https://www.apple.com/legal/internet-services/icloud/)).

- We — the Developer — have no access to your iCloud private database. We cannot see your data even with a court order. Only Apple, acting on your account credentials, can.

If you don't want iCloud sync, you can leave it off; VerityGold works fully on a single device.

## 7. Children

VerityGold is not directed at children under 13. We do not knowingly collect or process information from children. If a child uses the app, the app still collects nothing — the same privacy posture applies.

## 8. Support communications

If you email us for support, we receive your email address and the message you sent. We use this only to reply. We don't add your address to any mailing list. We retain support correspondence for the time it takes to resolve your issue and a reasonable period afterward (typically up to 12 months).

## 9. Your rights (GDPR / CCPA)

Because VerityGold collects no personal data, the data-subject rights granted by GDPR (access, rectification, erasure, portability, restriction, objection) and CCPA (know, delete, opt-out of sale, non-discrimination) all have a simple answer: we hold no data about you to access, correct, delete, port, etc.

The records, subjects, and lineage entries you create inside the app live on your device. You exercise control over them directly:

- Access: Profile → Unified profiles / Source records / Subjects.

- Rectification: Edit any record's fields via the Edit button.

- Erasure: Delete the app from your device. Or use Profile → Reset to demo data (DEBUG builds only) to wipe local data while keeping the app installed.

- Portability: Export-to-CSV is on the post-v1 roadmap.

## 10. Changes to this policy

If we change this policy in a way that materially affects how the app handles your data, we will update the "Last updated" date and post a notice in the app on next launch. Because the app collects nothing today, the only changes that would matter materially are if the app started collecting something — which we currently have no plan to do.

## 11. Contact

Questions: support@riteupai.com.

---

Effective as of June 11, 2026. This policy accurately reflects the app's behavior as of v1.0.