Privacy Policy

Version 2.0.0 · Effective 2026-08-18

Last updated: 2026-08-18

This Privacy Policy describes how Alessandro Sappia processes personal data when you use the Mad AI: Angry Alarms iPhone and iPad app (the "App") and https://www.madaiapp.com (the "Site"). Version 2.0.0, effective 2026-08-18.

It covers only processing that actually occurs in the current product. We do not sell your data. We do not operate advertising tracking in the App.

1. Controller and contacts

Mad AI and Mad AI: Angry Alarms are trade names for a mobile application operated by Alessandro Sappia ("we", "our", or "us"), a natural person based in Abu Dhabi, United Arab Emirates.

Support, privacy, and complaints: madaisupport@gmail.com.

Mad AI is a product name, not a separate company. The operator of the App and this website is Alessandro Sappia.

No separate data protection officer is appointed at this time.

2. Scope

This policy applies to the Site and the App, including Sign in with Apple, goal sync, AI coaching, photo proof, subscriptions purchased through Apple, and support or complaint forms.

Guest use of the App keeps goals and chat on the device until you Sign in with Apple.

3. Data we process

Account

If you Sign in with Apple, we store your Apple user identifier (the "sub"). We do not request your email from Apple.

  • Apple user identifier — required to sync and call the API
  • Display name you type or that Apple provides — optional; used in on-device profile and sometimes in AI prompts
  • Access and refresh tokens — required while signed in

Goals and chat

  • Goal titles, details, deadlines, and completion status — stored on your device and, when signed in, on Cloudflare D1
  • Coach chat messages — stored on your device only; text is sent to AI providers when you chat

Photos

Proof photos are resized on your device, stripped of EXIF/GPS metadata, and sent as JPEG for a one-time automated check. Mad AI servers do not keep the file. Profile and coach avatars stay on the device.

Do not photograph identity documents, exam papers, health records, or other people without permission.

Purchases

Apple and RevenueCat process subscription status and transaction identifiers. Mad AI does not receive your full card number.

Notifications

Alarms and reminders are scheduled on your device. We do not collect a push token and we do not send remote push from our servers.

Site analytics

The Site uses Plausible Analytics and Vercel Web Analytics / Speed Insights for aggregated traffic and performance. They are not used to build advertising profiles. See Cookies and analytics.

What we do not collect in the App

  • Email address as an account field
  • Contacts or a social graph
  • Advertising identifier (IDFA)
  • Crash-reporting SDK data
  • Friend, leaderboard, or send-an-alarm data — those features are not offered

4. Purposes and conditions

Under UAE Federal Decree-Law No. 45 of 2021, we process data to perform the service you ask for (including Art. 4(9) contractual steps) and, where we rely on consent, on a recorded acknowledgement.

  • Operate accounts, goal sync, and security
  • Generate coach messages and verify proof photos
  • Provide Premium via Apple
  • Handle support, privacy requests, and complaints
  • Understand Site traffic in aggregate

Required vs optional: Sign in with Apple is required for sync, cloud AI chat, and photo verification. Guest mode is local. Analytics on the Site is not used for ads.

5. Processors and countries

We use these processors. They may process data outside the United Arab Emirates. Transfers are made so we can provide the App (including Art. 23 contractual necessity) and are disclosed here.

  • Apple — Sign in with Apple and App Store billing
  • Cloudflare — API (share.madaiapp.com), D1 database, logs
  • Google Gemini API — primary chat and vision
  • OpenRouter — fallback chat and vision; requests set data_collection to deny
  • Groq — further fallback chat and vision
  • RevenueCat — subscription status in the App
  • Vercel — Site hosting, Web Analytics, Speed Insights
  • Plausible — Site pageview analytics

Exact data-centre countries are chosen by those providers. We do not claim a UAE-only processing location.

Twilio appears in unused server code and is not enabled for the App.

6. AI, photos, and automated decisions

Coach replies and proof checks are generated automatically. Proof results can be wrong. You can retry with another photo and you can complain about a decision via the complaint form.

Mad AI does not train its own models on your content. We configure OpenRouter requests not to opt in to data collection. Google and Groq publish terms for their paid APIs stating they do not use API content to train their models. We do not offer a switch that allows training on Mad AI content.

Providers may still keep security logs under their own terms. We do not grant them a right to publish your photos.

7. Tracking, identifiers, and marketing

The App does not use App Tracking Transparency because it does not track you across other companies’ apps or websites for advertising. We do not collect IDFA.

We do not send marketing push notifications. Product alarms are service messages you configure.

Device identifiers used by Apple or RevenueCat for StoreKit are for purchase, not Mad AI advertising.

8. Security and backups

The API uses HTTPS. Refresh tokens are stored as hashes. Access tokens last about one hour. Cloudflare encrypts D1 at rest as part of their platform.

Cloudflare may keep managed backups for a vendor-defined window after deletion. We do not run a separate photo archive.

9. Retention and deletion

  • Proof photos: not stored on Mad AI servers after the request
  • Chat: on your device until you delete the account or the chat
  • Goals and Apple user id on our database: until you delete the account, then removed from active storage
  • Refresh tokens: up to 30 days, or sooner on logout or deletion

You can delete your account in the App (Account → Delete Account). That revokes sessions and deletes active server records. It does not cancel an Apple subscription. Manage that in your Apple ID settings.

10. Your rights

Depending on applicable UAE law, you may request:

  • Access and a copy of goal data we hold
  • Correction of inaccurate data you control in the App
  • Deletion of the account
  • Restriction or stopping of non-essential processing
  • Portability of goal data we store, in a machine-readable export
  • Withdrawal of consent for future optional processing

Use the in-app privacy tools, the Site form at /legal/privacy-requests, or madaisupport@gmail.com. We will give you a case ID.

You may also complain to the UAE Data Office. We do not promise a GDPR 72-hour deadline.

11. Children

The App can be installed by anyone whose Apple ID and device settings allow the App Store listing. We do not run a separate age gate. We do not design the App for children and we do not ask for a date of birth.

The App requires iOS or iPadOS 18.0 or later. That is an operating-system requirement, not a statement that users must be 18 years old.

12. Personal data incidents

If an incident is likely to prejudice the privacy, confidentiality, or security of your personal data, we will notify you and the competent UAE authority in line with the Personal Data Protection Law and its executive regulations. Timing follows those rules, not a foreign 72-hour standard.

13. Changes

Material changes get a new version number and effective date. The App will ask you to accept the new Terms and acknowledge this Policy before you continue signed-in features. We do not treat continued use alone as acceptance of material changes.

14. Contact

Operator: Alessandro Sappia, Abu Dhabi, United Arab Emirates.

Email: madaisupport@gmail.com

Document history

  • 2.0.0 (2026-08-18): Aligned with the current app and servers. Named processors. UAE governing law. Subscriptions, account deletion, complaints, and photo/AI behaviour as implemented.
  • 1.0.0 (2026-08-15): First public Privacy Policy and Terms.