Jeeks OS

Privacy Policy

Last updated 22 September 2026

This is the privacy policy of Jeeks OS — the app and the service operated by JEEKSSHIRE 24 LLC. It says what the app stores, who it is shared with and why, and how to erase all of it. We do not sell your data, we do not hand it to ad networks and we embed no advertising trackers.

1. Who is responsible

Jeeks OS is an app for iPhone, iPad and Mac plus its server side (api.jeeksshire24.com). Public pages live on jos.jeeksshire24.com; this page is one of them.

Questions about privacy, access to your data or deletion — by e-mail to jeeksshire024@gmail.com. We do answer such requests.

Servers and file storage are located in the European Union (Frankfurt, Germany), at DigitalOcean. Some of the calls to AI contractors may travel through a transit node of our own outside the EU (in the United States) — that is how the contractors’ own geo-blocks are worked around.

2. What we collect

Only what the service needs to work. We do not buy any data about you from anyone.

  • Account — e-mail address, name and an irreversible password hash. If you signed in with Apple, Google or Yandex — the identifier they issue; the password of that account never reaches us.
  • Profile — display name, @handle, bio, avatar and phone number, if you filled them in.
  • Content — posts, comments, articles, tasks, messages and attachments. Bodies of direct messages are stored on the server encrypted (AES-256-GCM). A feedback or support request may optionally include one photo or document.
  • AI usage — your prompt and the result: an image, a video, a written transcript. Finished work stays in your personal list of AI results inside the app and is deleted after 60 days.
  • Mail, if you connected a mailbox — its password or access token is stored encrypted only, while the sender address, the subject and an excerpt of the body are kept in our database in plain text: without that, search over your mail cannot work.
  • Signing in with Google or Yandex is a different thing and stores no tokens at all.
  • Verification documents — only if you applied for the verified badge yourself. They are stored apart from other files and are served in an isolated mode: scripts inside a document cannot run, and a PDF is served as an attachment, for download only.
  • Payments — amount, currency, order number and status, payment method. The card number, expiry and code never reach us at all: only the payment provider sees them.
  • Device — platform, app version and a notification token (a push cannot be delivered without it).
  • Product analytics — events about using the app: launch, opening a tool, search. These events are tied to your account and are not anonymous.
  • IP address — for protecting free ⚡ from farming and for counting views it is turned into an irreversible hash and stored in that form only. But in security cards (“sign-in”, “sign-up”, “password changed”, “password reset requested”, “e-mail change requested”) the address is kept as is — otherwise they would not do their job: showing you where the sign-in came from.
  • Your chat with the AI Assistant — it syncs between your devices through our server and is kept there as a snapshot, unencrypted and with no retention period. Only deleting your account removes it.

3. Why we use it

We rely on three grounds: performance of the contract with you (the reason you installed the app), our legitimate interest in the security and development of the service, and legal requirements for payment records. There is no advertising profiling.

  • To make the service work: show the feed and the messages, run your AI request, deliver a notification.
  • To take payment and keep order records.
  • To protect the service: rate-limit requests, catch farming of free ⚡ and show you the security events of your account.
  • To understand which tools people use and to develop the app.

4. Who we share with

Data leaves us only to contractors that perform a specific job triggered by your action. Each of them is named: “third parties” without names is not a disclosure, it is an excuse.

Separately about AI, because it is the most sensitive transfer of all: when you press the button of an AI tool, your prompt and the files you attached — the text, a photo of a face or of a product, audio — go to the AI contractor in full, as they are. Before the FIRST such send the app asks for your consent and sends nothing without it; you can withdraw the consent at any moment — “Privacy & security” → “Sending data to AI”. Withdrawing it turns the AI tools off rather than hiding them, and everything else in the app keeps working.

  • Anthropic (Claude) — the text of your request and of your chat with the assistant when you use AI.
  • BytePlus ModelArk (ByteDance) — the prompt and source frames for generating images and video.
  • fal.ai — the photo and the audio for the talking-head avatar: those runs are started by our web services; the app no longer has that screen.
  • OpenAI — audio for speech recognition; the text for voice-over goes there only from our web services — the app no longer has that screen.
  • Apple — App Store purchases and subscriptions, push delivery (APNs), Sign in with Apple.
  • T-Bank — payments in roubles; Stripe — international payments.
  • Google and Yandex — signing in, if you chose that way.
  • SMTP.bz — delivery of our e-mail (confirmation codes, notices): the recipient address and the letter itself go there.
  • SocialFetch and Apify — the public social-network pages and clips whose links you provided yourself for reach analysis: those runs are started by our web services (the UGC dashboard), the app no longer has those screens — the link itself goes there so that views and likes come back; Yandex Disk — public links you provided yourself.
  • DigitalOcean — server hosting and file storage.

5. How long we keep it

  • Account and content — while the account exists.
  • AI generations — 60 days, then both the record and the file are deleted.
  • Notifications, including security cards with an IP address — 90 days.
  • Payment records stay after the account is deleted, but no longer point at you: amounts, dates and order numbers are needed to reconcile with the bank, while the link to the person is cleared.
  • Feedback and support requests — only the optional attached file is automatically deleted after 90 days during the next daily cleanup, so within 91 days after receipt. For a request sent from an account, its text and contact details are cleared when that account is deleted. A guest request is kept while needed to handle it, investigate recurring problems and maintain support history; you may ask us to delete it with a verified request through the contacts in this policy, unless we must keep it.
  • Feedback notification e-mail — starting 16 September 2026, it contains only the ticket ID, request type, time and an instruction to open the protected admin dashboard; it no longer contains the request text, contact details, user ID, device or app details, or the attachment filename. Copies of older notification e-mails may remain with SMTP.bz and in the administration mailbox even after an in-app account deletion; you may ask us to delete them with a verified request through the contacts in this policy, unless the law requires us to keep them.

6. Your rights

These rights apply the same everywhere — in the EU (GDPR), in California (CCPA/CPRA) and in any other country.

  • See and correct your data — the profile and the settings inside the app.
  • Delete the account together with its data — right in the app: Settings → “Delete account”. It is irreversible and happens immediately, without writing to support.
  • Opt out of the personalised feed — the ‘Personalized “For you” feed’ switch in profile settings.
  • Take your page out of search results — the “Keep my page out of search engines” switch in profile settings.
  • Limit who may message you, and block anyone.
  • Get a copy of your data or ask a question about processing — by e-mail to jeeksshire024@gmail.com.
  • Complain to the supervisory authority of your country if you believe we mishandled your data.

7. What we do not do — and what the app does not have

Plainly about the things that do not exist, so that they do not read as a promise.

  • There is no “download my data archive” button in the app: we assemble a copy by hand, on request.
  • There is no separate consent and no “turn analytics off” switch: product events are collected from everyone who signed in.
  • There is no end-to-end encryption of messages. Bodies of direct messages are encrypted on the server and the key is stored apart from the database — that protects against a stolen database, not against us: technically the server can decrypt a message. We will not promise the impossible.
  • We do not sell data, we show no advertising and we embed no third-party advertising or analytics SDKs.

8. How it is protected

Traffic goes over HTTPS/TLS only. The password is kept as an irreversible hash. Direct messages and the mailbox password are encrypted with AES-256-GCM; the encryption key lives apart from the database and never reaches the app. Verification documents are stored separately and are served with execution of their content forbidden. Signing out kills the session on the server and removes the notification token from the device.

9. Children

The service is not intended for children under 13, and we do not knowingly collect their data. If such data has reached us anyway — write to us and we will delete both the data and the account.

10. Purchases and subscriptions

Subscriptions and ⚡ packs are sold through the App Store (Apple), as well as through T-Bank and Stripe. Deleting your account does NOT cancel an App Store subscription: it has to be cancelled separately on the device — Apple ID settings → “Subscriptions”. A refund for an App Store purchase is Apple’s decision; when Apple tells us about a refund, we withdraw what that purchase granted.

11. About these pages

Public pages (a post, a profile, an article) open without the app and show only what a person published themselves. The site sets no cookies and carries no counters, no advertising pixels and not a single script — that is fixed by its content security policy. Web-server logs of these pages are kept without IP addresses; technical logs of the API server may contain the request IP — they are needed to investigate failures and attacks.

If you do not want your page in search engines, turn on “Keep my page out of search engines” in the app. The direct link keeps working — otherwise the links you have already shared would break.

12. Changes

The current version of this document always lives at this address, with the update date at the top of the page. We will announce significant changes inside the app.

Terms of Use

Write to us about privacy · jeeksshire024@gmail.com