Skip to content
Apps99AI99Fit99Music99Posts99Split
STRICS IT GmbH
01Apps0299AI0399Fit0499Music0599Posts0699Split
Back to 99AI
99AI app icon
99AI · Legal / Privacy

Version 1.0 · Effective August 17, 2026

Privacy,without the fog.

What 99AI needs to create, bill, restore, and protect your work—and what never goes into Apple's refund review.

Default Refund sharing offIdentity Pseudonymous accountControl Withdraw or delete

On this page

01Who we are and what this covers02Pseudonymous account and security data03Prompts, reference media, and generations04Bring your own provider key05Purchases, subscriptions, and credit records06Optional information for Apple refund review07Retention, deletion, and replay protection08Purposes, providers, and international transfers09Your choices and rights10Security and policy changes
The short version

Your creative inputs go only where the selected generation needs them. Your provider key is not retained by STRICS. Apple receives no prompts or media for refund review—and only receives delivery information when you explicitly opt in.

01

Who we are and what this covers

99AI is provided by STRICS IT GmbH, Florian-Gmainer-Strasse 4, 4240 Freistadt, Austria. This product-specific policy covers the 99AI iPhone app, its Firebase backend, managed-credit subscriptions, the one-time bring-your-own-key unlock, and this 99HQ product page.

For privacy requests, access, correction, export, deletion, objection, or support, email hello@strics.at. Apple and each AI model provider also process data under their own terms when their services are used.

02

Pseudonymous account and security data

99AI uses Firebase Anonymous Authentication. It creates a random account identifier without asking for your name, email address, or password. We use that identifier to connect credit balances, purchases, generation jobs, consent choices, and account-deletion requests to the correct app account.

Firebase App Check, Apple platform security, and our infrastructure may process device-attestation data, IP address, request time, endpoint, app and operating-system version, response status, duration, and limited error details. We use this information to deliver the service, prevent fraud, enforce limits, investigate failures, and control provider costs. We do not use it for advertising or cross-app tracking.

03

Prompts, reference media, and generations

When you request an image or video, 99AI sends your prompt, selected reference images or start/end frames, model and format settings, and the minimum technical context needed for the request through the STRICS Firebase backend to the selected direct provider. Depending on your choice, that provider can be OpenAI, Google Gemini or Veo, xAI, or BytePlus (Seedance).

The backend may retain a prompt and limited job metadata in a transaction-linked usage record so it can reserve and settle credits, avoid duplicate charges, recover accepted jobs, troubleshoot delivery, and support refund or abuse review. Reference media is processed for the requested generation and is not added to a public dataset by STRICS. Generated results are returned to the app; the local gallery remains on your device, while providers may temporarily host or retain request data under their applicable API terms.

Do not submit unlawful, exploitative, infringing, confidential, or unnecessary third-party personal data. Provider safety systems can block a request. A blocked or failed attempt counts as used only when the provider actually charges STRICS for processing it; an unbilled failure is returned to your 99AI credit balance.

04

Bring your own provider key

A provider API key that you add is stored in the iOS Keychain on your device. For a BYOK request, the key is sent over encrypted HTTPS to the authenticated 99AI backend and used only to call the provider you selected. STRICS does not store it as a reusable cloud credential, place it in Firestore, or share it with Apple.

The selected provider can associate requests and charges with your provider account. You remain responsible for that account, its key security, quotas, fees, and provider terms. Removing the key in 99AI removes the local Keychain copy.

05

Purchases, subscriptions, and credit records

Apple processes App Store payments; STRICS does not receive your complete payment-card details. StoreKit provides signed product, transaction, original-purchase, renewal, expiration, refund, and revocation information so the backend can verify access and apply the correct credit allowance.

We keep limited entitlement, grant, balance, and usage-ledger records. They can include pseudonymous account and transaction links, product and period dates, credits granted, reserved, charged, or returned, delivery and finalization state, provider cost, and hashed replay-protection metadata. This prevents duplicate grants, makes purchase restoration possible, and lets us reconcile renewals and refunds. Raw signed StoreKit payloads are verified but are not retained as customer content.

06

Optional information for Apple refund review

The App Store refund-information setting is optional, off by default, and never required to purchase or use 99AI. If you affirmatively enable the current disclosure and later ask Apple for a refund, Apple may send 99AI a verified Consumption Request. Without current consent, 99AI does not answer that request with consumption information.

Within Apple's response window, 99AI may use the verified delivery record and transaction-linked chargeable credits to choose a recommendation. If at least 1% of the period's chargeable credits were used, 99AI may ask Apple to decline or reduce the refund. The response can contain delivery status, whether sample functionality was available, and that refund recommendation. For an auto-renewable subscription, 99AI does not send Apple a credit-usage percentage. Apple—not STRICS—makes the final refund decision, and mandatory consumer rights remain unaffected.

No prompt, reference image, generated image or video, provider API key, support email address, or generated content is included in this Apple response. You can withdraw consent at any time in 99AI Settings. Withdrawal stops future responses unless you opt in again under the then-current disclosure. Apple handles data it already received under Apple's policy; requests concerning Apple's copy can be made at privacy.apple.com.

07

Retention, deletion, and replay protection

Cloud records are kept only as long as reasonably needed for delivery, job recovery, billing, fraud prevention, support, disputes, accounting, and legal compliance. Short-lived response jobs expire; technical logs follow provider retention controls. Account deletion removes the active cloud account, linked generation records, consent choice, and saved local history and keys. Deleting the app or account does not cancel an Apple subscription.

To stop a deleted purchase from being credited repeatedly or stolen by another anonymous account, 99AI can retain narrowly scoped, one-way hashed StoreKit replay and recovery records with an expiry date. They do not contain prompts, media, email, API keys, or the deleted Firebase customer identifier. Remaining credits and the current period's allowance are forfeited on account deletion and are not reissued until a future eligible renewal.

08

Purposes, providers, and international transfers

We process account, generation, purchase, and feature data to perform our contract and deliver requested functions under Article 6(1)(b) GDPR. We process proportionate security, fraud-prevention, abuse, diagnostics, replay-protection, and cost-control data for our legitimate interests under Article 6(1)(f). Optional refund-information sharing relies on your consent under Article 6(1)(a), which you can withdraw. Accounting and legally required records are processed under Article 6(1)(c).

Our processors and recipients include Apple for StoreKit and App Store services; Google Firebase and Google Cloud for authentication, App Check, Firestore, Cloud Functions, and logs; OpenAI, Google, xAI, or BytePlus (Seedance) when selected for AI generation; and Vercel for 99hq.dev hosting. Processing may occur outside the EEA under an adequacy decision, standard contractual clauses, or another lawful safeguard.

09

Your choices and rights

You can keep Apple refund-information sharing off, withdraw it in Settings, remove provider keys, delete local generations, or delete the 99AI account. Subject to applicable law, you may request access, correction, deletion, restriction, portability, or objection by contacting hello@strics.at. Because the account is anonymous, we may need an in-app identifier or another verification step to locate the right records.

You may lodge a complaint with the Austrian Data Protection Authority at dsb.gv.at or the supervisory authority where you live or work. 99AI is not directed to children under 13; where local law requires parental consent at a higher age, a parent or guardian must provide it.

10

Security and policy changes

We use encrypted transport, iOS Keychain storage, Firebase access controls, signed StoreKit verification, App Check, validation, rate limits, idempotent billing records, and restricted secret access. No system is completely secure, but we assess and notify affected people and authorities when legally required.

We may update this policy when 99AI, its providers, or legal requirements change. A materially changed Apple refund disclosure requires a new in-app opt-in version. The current policy version and effective date remain published on this page.

Questions or rights request

Talk to a person.

hello@strics.at

STRICS IT GmbH · Florian-Gmainer-Strasse 4 · 4240 Freistadt · Austria

Made for the momentum.

Apps

99AI99Fit99Music99Posts99Split

Company

STRICS IT GmbHContact

Legal

99AI Support99AI Privacy99AI TermsImprintPrivacyTerms

Freistadt · Austria

Independent apps, built with intent.

© 2026 STRICS IT GmbH