Last updated · 2026-04-26

Privacy

Eleven9s is a private media vault for photos, videos, and audio. This policy describes what we collect, where we store it, who else touches it, and what you can do about it. We try to describe the reality of our system plainly; where the answer is uncomfortable, we still say so.

Who runs Eleven9s

Eleven9s is operated by Apres AI LLC, a Colorado single-member limited liability company. For any data request, write support@eleven9s.apresai.dev — we aim to reply within 72 hours.

What we collect

  • Apple user identifier. When you tap Sign in with Apple, Apple gives us a stable per-app identifier (the sub claim of the identity token). We use it as your account key.
  • Email.Either your real Apple ID email or Apple's private relay address ending in @privaterelay.appleid.com. Per Apple Review Guideline 5.1.1(iii) we accept the relay — we cannot require the real one.
  • Passkeys. Public keys and credential identifiers for the passkeys you enroll on your devices. Private keys never leave your device.
  • Your media. Photos, videos, and audio you choose to import through the Share Extension or Import flow.
  • Metadata alongside your media. File size, SHA-256 hash, MIME type, dimensions, duration (for video), captured-at timestamp, any label you set, EXIF (including GPS) as embedded in the file you uploaded. We do not compute derived metadata server-side.
  • Subscription state.Once paid subscriptions launch, the product ID, status, and expiration returned by Apple's StoreKit. Apple handles payment; we never see card or bank data.

What we do NOT collect

  • No analytics SDKs.No Firebase, no Sentry, no Amplitude, no Mixpanel, no custom telemetry. Crash data, if any, comes only from Apple's built-in TestFlight / App Store Connect tooling.
  • No advertising identifiers. We do not request IDFA or the App Tracking Transparency prompt.
  • No contact list. Eleven9s never asks for access to your Contacts.
  • No Location Services. We do not request location permission. EXIF GPS coordinates, if embedded in your uploaded files, are read on-device only and stored with the rest of your metadata — never fetched live.
  • No cloud machine learning.No Rekognition, no Comprehend, no scene classification or OCR on our servers. All tagging that exists happens on your device via Apple's Vision framework (currently deferred; no cluster or scene data is collected in v1).
  • No behavioral profiling. We do not build user interest or demographic profiles for any purpose.

Where your data lives

All data is stored in AWS us-east-1, account 228029809749, subject to U.S. law. Specifically:

  • Media bytes go to the S3 bucket eleven9s-vault-prod-228029809749 with SSE-S3 server-managed encryption (AES-256 at rest), versioning enabled, and public access fully blocked.
  • Account and media index rows live in the DynamoDB table eleven9s-prod, under your user identifier.
  • Byte-fetches flow through our CloudFront distribution at media.eleven9s.apresai.dev. Your iOS client receives a signed cookie scoped to your user ID; that cookie cannot authorize anyone else's bytes.

An honest statement about operator access

We use AWS-managed encryption keys (SSE-S3), which means we, as operators, could in principle read your files. We do not, as a matter of policy. Access is limited to operational needs: restoring from backup, investigating an abuse report, or responding to a lawful government request. When we access data under any of those circumstances, we log the access and will tell you if legally permitted to.

We do not proactively scan your media for illegal content in v1. Before we reach 10,000 users we intend to adopt PhotoDNA or equivalent hash-based matching for known child sexual abuse material; we will update this policy and notify users before that goes live.

If you require the strongest possible privacy guarantee, an end-to-end encrypted vault where even the operator cannot read your files — that is not what Eleven9s offers today. We will say so again: we can read your files, we choose not to, and we describe the operational behavior that backs that choice throughout these docs.

Who else touches your data (subprocessors)

  • Apple Inc. Sign in with Apple, StoreKit (subscriptions), TestFlight (pre-release testing), App Store Connect (notifications). Governed by Apple's privacy policy.
  • Amazon Web Services, Inc.Storage and compute processor under AWS's Data Processing Addendum.

We use no other third parties. No advertising networks.

Your rights

  • Delete everything. In the Eleven9s app, go to Settings → Delete Account. Your account is marked for purge immediately; the hourly sweep job removes all media, metadata, passkeys, and account rows within 24 hours. S3 versioning ensures nothing lingers.
  • Stop using Sign in with Apple. In iOS Settings → your Apple ID → Sign in with Apple → Eleven9s → Stop Using. Apple sends us a consent-revoked notification and we mark your account for purge on the same cycle above.
  • Export your media. A full export tool is planned for a post-launch release. Until then, contact us and we will arrange a one-time export of your files.
  • Any other data request. Write support@eleven9s.apresai.dev.

Children

Eleven9s is rated 12+ on the App Store. We do not market the app to children, we are not in the Kids Category, and we do not knowingly collect data from users under 13. If you believe a minor has created an account, write support@eleven9s.apresai.dev and we will delete the account.

Changes to this policy

Non-material changes (clarifying language, new office address) take effect on the next deploy and are reflected in the “Last updated” date. Material changes — new categories of data, new subprocessors, a shift from our current operator-readable posture — will trigger a push notification inside the app and a minimum 30-day lead time before taking effect.

Contact

Questions, corrections, or requests: support@eleven9s.apresai.dev. Apres AI LLC is the data controller for the personal information described in this policy.