Aha! Privacy Policy
Effective Date: October 8, 2026
Last Updated: October 8, 2026
Operator: Onda Development, LLC, doing business as Aha!
Location: Phoenix, Arizona, United States
Email: hi@theaha.app
Website: https://theaha.app
Privacy Policy: https://theaha.app/privacy
1. Introduction
Welcome to Aha!, a real-world discovery and learning platform operated by Onda Development, LLC, doing business as Aha! (“Aha!,” “we,” “us,” or “our”).
Aha! helps people discover, identify, understand, and remember the world around them through camera-based identification, artificial intelligence, location-based exploration, educational experiences, and destination knowledge.
We respect your privacy and are committed to protecting personal information.
This Privacy Policy explains:
- What information we collect.
- How we use that information.
- How camera, image, location, and AI features process information.
- When information is shared with service providers and other parties.
- How children's and families' information is handled.
- How subscriptions, community features, and partner services process information.
- How our public destination knowledge and commercial intelligence products differ from personal user information.
- How long information is retained.
- How to access, correct, download, or delete information.
- What privacy rights and choices may be available to you.
This Privacy Policy applies to Aha!'s websites, iOS and Android applications, partner portals, discovery experiences, and related services (collectively, the “Services”).
By using the Services, you acknowledge the practices described in this Privacy Policy. Where applicable law requires consent, we will request it separately.
Our Terms of Service and End User License Agreement are available at https://theaha.app/terms.
2. Our Privacy Principles
We design Aha! around the following principles:
Purpose limitation. We collect and use personal information for identified, legitimate purposes related to providing, securing, improving, and operating the Services.
Data minimization. We seek to collect only information reasonably necessary for the relevant purpose.
User control. Users should be able to manage available privacy settings, sharing preferences, device permissions, and account deletion.
Children's privacy. Children's personal information requires additional protections.
Responsible AI. Camera images, location information, and discovery interactions should not automatically become unrestricted training or commercial data.
Institutional data rights. Knowledge contributed by destinations, parks, and other partners is governed by its own permissions and licensing arrangements.
Transparency. We seek to explain how information is processed and when it is shared.
3. Categories of Information We Collect
Depending on how you use Aha!, we may collect the following categories of information.
3.1 Account and Profile Information
When you register or maintain an account, information may include:
- Name or display name.
- Email address.
- Authentication credentials or authentication-provider identifiers.
- Account ID.
- Profile photograph or avatar.
- Selected preferences.
- Language and region settings.
- Subscription status.
- Account creation and activity timestamps.
- Family or guardian relationships where applicable.
If you sign in through Apple, Google, or another supported identity provider, we receive information authorized by that provider and your selected privacy settings.
We do not require access to your Apple or Google account password.
3.2 Camera, Photographs, and Discovery Content
When you use Aha!'s camera or upload features, we may process:
- Photographs or images you capture or select.
- Objects or subjects depicted in those images.
- Associated image metadata, where available and permitted.
- AI-generated identifications.
- Explanations and lessons.
- Quiz responses.
- Discovery history.
- Saved Aha! Moments.
- User corrections and feedback.
- Sharing and collection preferences.
Images may contain personal information, including identifiable people, signs, addresses, location clues, or other sensitive details.
We encourage users to avoid submitting sensitive or unnecessary personal information in images.
3.3 Location Information
When you enable location-based functionality, we may process:
- Precise location, if you authorize it.
- Approximate location.
- Coordinates associated with a discovery.
- User-selected destinations or search areas.
- Geographic context associated with photographs.
- Location-based discovery interactions.
- Nearby places and attractions.
Location information may be obtained from device permissions, user selections, network information, or geographic metadata.
We use location information to provide relevant discovery experiences, nearby attractions, contextual explanations, and related functionality.
We do not require continuous background location tracking merely to provide standard camera-based discovery.
Any background location processing, if introduced, will require appropriate disclosure, permissions, and compliance with applicable platform rules.
You can manage device location permissions through your operating system.
3.4 Learning and Engagement Information
We may collect:
- Discoveries completed.
- Lessons viewed.
- Quiz participation and responses.
- Saved learning progress.
- Collections.
- Topics explored.
- Feature interactions.
- Achievement or progress information.
- Engagement with discovery recommendations.
This information helps us provide learning continuity, personalization, and service functionality.
3.5 Device and Technical Information
When you use the Services, we may automatically collect:
- Device type and model.
- Operating system and version.
- Application version.
- Browser type.
- IP address.
- General geographic region inferred from network information.
- Device language.
- Session identifiers.
- Crash reports.
- Diagnostic information.
- Performance measurements.
- Security events.
- Error logs.
- Technical usage information.
Where applicable, we may use device or application identifiers for authentication, fraud prevention, diagnostics, and permitted analytics.
We do not use prohibited persistent device identifiers or circumvent platform privacy restrictions.
3.6 Subscription and Transaction Information
If you purchase a subscription, we may receive:
- Subscription plan.
- Purchase or transaction identifier.
- Subscription start and renewal dates.
- Payment status.
- Cancellation status.
- Refund status.
- Billing platform.
- Country or currency information.
Purchases made through Apple or Google are processed by the respective platform.
We generally do not receive full payment-card numbers for purchases processed by those platforms.
If direct payments are offered, authorized payment processors may collect and process billing information under their own privacy practices.
3.7 Communications and Support
If you contact us, we may collect:
- Name.
- Email address.
- Message content.
- Support requests.
- Attachments.
- Feedback.
- Correspondence history.
- Information necessary to investigate or resolve the issue.
3.8 Community and Shared Content
If you choose to share discoveries or participate in community features, we may process:
- Public display name.
- Shared images.
- Discovery descriptions.
- Public collections.
- Comments or reactions, where supported.
- Sharing preferences.
- Reports and moderation information.
Content marked public may be visible to other users and, depending on the feature, visitors who are not signed in.
3.9 Partner and Business Information
For authorized organizations, we may collect:
- Organization name.
- Business contact information.
- Representative names and roles.
- Business email addresses.
- Organization identifiers.
- Destination or park associations.
- Subscription and billing records.
- Administrative activity.
- QR Discovery Point activity.
- Partner dashboard interactions.
- Knowledge Hub activity.
- Submitted organizational materials.
- Data-rights permissions and acceptance records.
- Contractual and commercial correspondence.
3.10 Cookies and Similar Technologies
Our website and web-based Services may use cookies, local storage, session identifiers, and similar technologies for:
- Authentication.
- Security.
- User preferences.
- Session continuity.
- Performance.
- Analytics.
- Subscription functionality.
Where required by law, we will obtain consent before using nonessential cookies or similar tracking technologies.
Additional information may be provided through a cookie notice or preference mechanism.
4. How We Use Information
We may use information to:
- Create and manage accounts.
- Authenticate users.
- Provide camera-based identification.
- Generate AI-powered explanations and lessons.
- Personalize discovery recommendations.
- Enable location-based exploration.
- Save discoveries and learning progress.
- Provide quizzes and educational features.
- Operate subscriptions and billing.
- Deliver notifications users have enabled.
- Provide customer support.
- Maintain security and prevent fraud.
- Detect abuse and enforce community standards.
- Diagnose errors and improve reliability.
- Evaluate aggregate product performance.
- Support authorized destination and park experiences.
- Operate partner portals and business services.
- Comply with legal obligations.
- Protect users, organizations, and the Services.
- Perform other purposes disclosed at collection or authorized by the user.
We do not use personal information for materially unrelated purposes without an appropriate legal basis, disclosure, or consent where required.
5. Camera and Image Processing
Camera-based discovery is a central feature of Aha!.
When you capture or select an image for identification, the image may be processed by Aha!'s systems and authorized AI or infrastructure providers.
Processing may include:
- Detecting the subject of an image.
- Identifying objects or places.
- Generating descriptions.
- Associating geographic context.
- Creating educational content.
- Supporting quizzes.
- Producing discovery recommendations.
- Identifying errors or misuse.
Camera access requires applicable device permissions.
We do not need unrestricted access to your entire photo library when you select an individual image through a supported system picker.
Image Storage
Images may be stored when necessary to support saved discoveries, account history, sharing, moderation, security, or other disclosed functionality.
Images used for temporary processing should not be retained longer than necessary for the relevant purpose.
Saved or shared images may remain associated with your account until deleted, subject to legitimate retention requirements.
AI Provider Processing
Images and associated prompts may be transmitted to authorized AI service providers when necessary to generate the requested experience.
Those providers may process information under contractual and technical restrictions applicable to their services.
Provider retention and model-training practices depend on the services and configurations actually used by Aha!.
Aha! will not represent that images are never retained or never used for training unless that claim is supported by the relevant technical configuration and provider agreements.
Sensitive Images
Users should avoid uploading images containing:
- Government identification documents.
- Financial account information.
- Medical records.
- Intimate or sexually explicit material.
- Sensitive information about children.
- Private documents.
- Information belonging to another person without authorization.
We may restrict or remove content that presents privacy or safety risks.
6. Artificial Intelligence and Data Processing
Aha! may use third-party or internally operated AI technologies to identify subjects, generate explanations, personalize experiences, and organize knowledge.
Information processed by AI systems may include:
- User-submitted images.
- Text prompts.
- Selected discovery topics.
- Relevant geographic context.
- Approved destination knowledge.
- Learning preferences.
- Previous discoveries where necessary for the requested feature.
We seek to limit information sent to AI systems to what is reasonably necessary.
Model Training
Aha! distinguishes among:
- Processing information to answer a user's request.
- Retrieving information from a knowledge database.
- Creating embeddings or search indexes.
- Evaluating service quality.
- Training, fine-tuning, or distilling AI models.
These are not identical activities.
Submitting a private image or document for identification does not, by itself, grant unrestricted permission to sell that material or use it for unrelated model training.
Any use of personal information for model training must comply with applicable law, disclosed practices, provider terms, and required permissions.
Partner-contributed institutional knowledge is additionally subject to its source-specific rights and agreements.
7. Location Privacy
Location helps Aha! connect discoveries to the physical world.
We may use location to:
- Identify nearby attractions.
- Improve geographic context.
- Suggest relevant discoveries.
- Associate discoveries with places.
- Support destination experiences.
- Enable user-selected exploration modes.
We distinguish between approximate and precise location where technically supported.
Precise location is more sensitive and should be accessed only where necessary for a feature and authorized by the user.
Location History
Location-associated discoveries may be retained as part of your account history if that feature is enabled.
This does not mean Aha! continuously records every place you visit.
We do not sell identifiable individual movement histories to destination partners, advertisers, or commercial data customers.
Location Sharing
Sharing a discovery publicly may reveal information about where the discovery occurred.
Where supported, users should be able to review location information before sharing.
We may suppress, generalize, or restrict geographic information when necessary to protect users, children, sensitive locations, or other legitimate interests.
8. Children's Privacy and Kid Mode
Aha! may provide learning experiences designed for families and children.
Protecting children's personal information is a priority.
For purposes of this section, a “child” generally means a person under 13 in the United States, or a person below another applicable age threshold under relevant law.
8.1 Parental Authorization
Where required, Aha! will obtain verifiable parental consent before collecting, using, or disclosing a child's personal information.
Children under 13 may not independently create standard adult accounts.
Family or child profiles must be created or authorized through appropriate parent or guardian controls where required.
8.2 Information Associated With Child Profiles
Depending on the features enabled and the permissions provided, child-related information may include:
- Child profile name or nickname.
- Age range or age-related eligibility information.
- Learning preferences.
- Discoveries.
- Quiz results.
- Educational progress.
- Selected photographs.
- Parent or guardian account association.
We seek to minimize collection of children's personal information.
8.3 Children's Images and Location
Images submitted through child-oriented experiences may contain personal information.
We seek to avoid unnecessary retention or disclosure of children's images and precise location information.
Features involving children's camera use, location, or image uploads must be configured consistently with applicable parental consent requirements and platform policies.
8.4 Public Sharing
Children under 13 should not have unrestricted public posting, public profiles, or direct communication with unknown users.
Child-oriented experiences may limit or disable public sharing, messaging, and community functionality.
8.5 Advertising and Commercial Data
We do not sell children's personal information.
We do not use children's personal information for behavioral advertising.
Children's identifiable information, private discovery histories, and precise location data are not eligible for Aha!'s commercial destination-intelligence licensing products.
8.6 Parental Rights
Parents and guardians may contact hi@theaha.app to request:
- Access to personal information associated with their child.
- Correction of inaccurate information.
- Deletion of a child profile and associated information.
- Withdrawal of applicable consent.
- Information about relevant data practices.
We may take reasonable steps to verify parental authority before fulfilling requests.
8.7 Educational and School Use
Where schools or educational organizations participate, additional contractual and legal protections may apply.
School participation does not automatically authorize commercial use of student information.
Aha! will not treat school participation or fundraising affiliation as permission to sell students' personal information.
9. Notifications and Communications
Aha! may send notifications concerning:
- Account security.
- Subscription status.
- Saved discoveries.
- Educational reminders.
- Relevant discovery opportunities.
- Product updates.
- Partner activity.
- Service announcements.
Push notifications require applicable device permissions.
You may disable push notifications through device settings.
Where supported, you may also manage notification categories within Aha!.
Marketing emails may include an unsubscribe mechanism where required.
Certain transactional, legal, security, or account-related communications may continue as necessary.
We do not require users to accept promotional push notifications as a condition of using unrelated core functionality.
10. Discovery History, Collections, and Personalization
Aha! may retain discoveries, lessons, quizzes, collections, and related activity to provide continuity and personalized learning.
This information may be used to:
- Restore prior discoveries.
- Recommend relevant topics.
- Track learning progress.
- Improve the relevance of educational experiences.
- Support account features.
Users may be able to delete individual discoveries or collections through available controls.
Account deletion initiates deletion of associated personal discovery history, subject to applicable retention exceptions.
Private discoveries are not automatically made public.
11. Community Sharing and Visibility
Aha! may support public and private sharing.
Information you intentionally make public may be accessible to other users or visitors and may be indexed by search engines where the feature permits public indexing.
Public content may include:
- Display name.
- Shared discovery.
- Photograph.
- Description.
- Selected location.
- Public collection information.
Before sharing, users should consider whether the content reveals their identity, home, workplace, children, travel patterns, or other sensitive information.
Private account information and private discoveries are not intended for public display.
We may remove or restrict public content for privacy, safety, legal, or moderation reasons.
12. Destination and Park Partner Analytics
Aha! may provide analytics to destination marketing organizations, Chambers of Commerce, parks, businesses, and other authorized partners.
These analytics may include:
- QR Discovery Point scans.
- Discovery engagement.
- Attraction interactions.
- Topic popularity.
- Aggregate visitor interest.
- Campaign attribution.
- General geographic patterns.
- Subscription referral activity.
- Business engagement.
- Content performance.
Our intended approach is to provide aggregate or appropriately de-identified insights rather than unrestricted access to identifiable consumer activity.
Partners should not receive a user's private images, personal learning history, precise movement history, or other identifiable personal information merely because that user interacts with a destination experience.
Where individual-level information must be shared to provide a requested feature, administer a referral, fulfill a contract, or meet a legal obligation, the sharing must be supported by an appropriate legal basis and disclosure.
We may apply aggregation thresholds, suppression, geographic generalization, or other safeguards to reduce re-identification risk.
13. Public Destination Authority Corpus
Aha! maintains or may develop a public knowledge collection concerning destinations, parks, attractions, places, geographic features, businesses, history, wildlife, and other discovery subjects.
This collection may include:
- Publicly available factual information.
- Authorized partner submissions.
- Public destination descriptions.
- Geographic and place relationships.
- Educational explanations.
- Publicly authorized derived knowledge.
- Public source references.
- Verified corrections.
The public Authority Corpus is distinct from private user accounts and private partner knowledge.
Publication of destination information does not authorize publication of private consumer information.
Where public listings contain personal information about business representatives or other individuals, applicable privacy rights and correction procedures remain available.
14. Partner Knowledge Hub and Institutional Data
Authorized destination, park, business, and institutional partners may contribute documents, datasets, maps, research, media, interpretive materials, and other information through Aha!'s Knowledge Hub.
Partner materials may contain personal information, including employee contact details, photographs, or other identifiable information.
Partners are responsible for having appropriate authority and lawful grounds to provide such information.
Aha! processes Partner Content according to applicable agreements, selected permissions, and legal obligations.
Partner permissions may distinguish among:
- Private partner-service use.
- Broader Aha! network use.
- Public web publication.
- Public API distribution.
- Derived knowledge use.
- Park Pack distribution.
- Commercial intelligence licensing.
- Raw-content redistribution.
- Media reuse.
- AI model training.
- Fine-tuning and distillation.
Uploading a document does not automatically make it publicly available or commercially licensable.
Aha! may maintain source lineage, attribution, rights records, review history, and access controls.
15. Commercial Intelligence and Data Licensing
Aha! may develop commercial products based on authorized institutional knowledge and appropriately aggregated or de-identified information.
Potential products include destination intelligence, structured place information, educational context, knowledge graphs, APIs, and enterprise datasets.
Commercial products must respect applicable data rights, licensing conditions, and privacy obligations.
Aha! does not treat the following as unrestricted commercial licensing assets:
- Private consumer photographs.
- Identifiable personal discovery histories.
- Precise individual movement histories.
- Children's personal information.
- Private communications.
- Restricted partner documents.
- Confidential institutional information.
- Sensitive personal information.
Where Aha! uses aggregated behavioral information to understand discovery interests, we will apply safeguards appropriate to the data and use case.
Data described as de-identified must meet applicable legal standards and be subject to reasonable measures designed to prevent re-identification.
Participation in the Aha! Intelligence Network does not override consumer privacy rights.
Any commercial use of personal information requiring notice, consent, opt-out, or other legal safeguards will be handled accordingly.
16. When We Share Information
We may disclose information to the following categories of recipients where necessary and permitted.
16.1 Service Providers
Authorized providers may support:
- Cloud hosting and storage.
- Authentication.
- AI processing.
- Image analysis.
- Database services.
- Analytics.
- Error monitoring.
- Customer support.
- Email delivery.
- Push notifications.
- Payment processing.
- Security and fraud prevention.
Service providers receive information appropriate to their role and are subject to applicable contractual, technical, and legal requirements.
16.2 Apple and Google
Apple and Google may process information related to application distribution, subscriptions, billing, device permissions, and platform services under their respective privacy policies.
16.3 Other Users
Information you deliberately share publicly may be visible to other users.
16.4 Authorized Partners
We may share relevant information with authorized destination, park, business, school, or other partners where necessary to provide agreed services and consistent with applicable privacy protections.
16.5 Legal and Safety Disclosures
We may disclose information when reasonably necessary to:
- Comply with applicable law.
- Respond to lawful legal process.
- Protect the safety of users or others.
- Investigate fraud or abuse.
- Enforce our Terms.
- Protect our rights and property.
16.6 Business Transactions
Information may be transferred in connection with a merger, acquisition, financing, reorganization, asset sale, or similar transaction, subject to applicable privacy laws and contractual restrictions.
16.7 With Your Direction
We may share information when you specifically request or authorize it.
17. Sale and Sharing of Personal Information
We do not sell children's personal information.
We do not sell identifiable individual location histories or private user photographs as commercial destination-intelligence products.
We do not authorize destination partners to purchase unrestricted access to identifiable consumer discovery histories.
Certain privacy laws define “sale,” “sharing,” or “targeted advertising” broadly, including some disclosures involving advertising technologies even when no money changes hands.
If Aha! engages in practices covered by those definitions, we will provide required notices, choices, and opt-out mechanisms.
Users may contact hi@theaha.app regarding applicable privacy choices.
18. Analytics, Advertising, and Attribution
Aha! may use analytics to understand product performance, feature engagement, errors, and general usage trends.
Partner attribution may measure whether visitors engage with QR codes, destination campaigns, or referral links.
We seek to avoid unnecessary collection of sensitive information for these purposes.
If we introduce third-party advertising, cross-app tracking, or targeted advertising technologies, we will provide required disclosures and obtain consent or provide opt-out mechanisms where applicable.
On Apple devices, tracking subject to Apple's App Tracking Transparency requirements will not occur without the applicable authorization.
Children's experiences will be subject to additional advertising and tracking restrictions.
19. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, subject to legal requirements and legitimate operational needs.
Retention may depend on:
- Whether an account remains active.
- Whether a discovery is saved.
- Whether content has been shared.
- Subscription and transaction requirements.
- Security and fraud-prevention needs.
- Applicable legal obligations.
- Pending disputes.
- User deletion requests.
Account Information
Generally retained while the account remains active and deleted or de-identified after account deletion, subject to lawful exceptions.
Discovery Images and History
Retained as needed for saved discoveries, user-selected sharing, and related functionality.
Temporary processing data should be deleted when no longer necessary.
Transaction Records
May be retained for applicable accounting, tax, fraud-prevention, and legal obligations.
Security Logs
May be retained for a limited period appropriate to security, diagnostics, and legal needs.
Partner Records
May be retained according to applicable agreements, rights-management requirements, and legal obligations.
Backups
Deleted information may remain temporarily in secured backups until normal backup expiration or deletion procedures complete.
Backups should not be used to restore deleted personal information into active services except where legally necessary and appropriately controlled.
Specific retention schedules may be disclosed in supplementary notices or updated versions of this Policy.
20. Account and Data Deletion
You may request deletion of your Aha! account and associated personal information.
In-App Deletion
Where account creation is available, an account-deletion option will be provided within the app.
Web Deletion
Aha! will provide an accessible web-based account-deletion request method at:
https://theaha.app/delete-account
You may also request deletion by contacting:
Subject: Account Deletion Request
We may request reasonable verification to protect against unauthorized deletion.
Following a verified request, we will delete or de-identify associated personal information as required by law, subject to permitted retention exceptions.
Deletion of an account is not merely account deactivation.
Certain records may be retained where necessary for legal compliance, financial recordkeeping, security, fraud prevention, or dispute resolution.
Deleting an Aha! account does not automatically cancel an Apple- or Google-managed subscription.
Users should separately cancel subscriptions through the relevant billing platform.
21. Your Privacy Rights and Choices
Depending on your jurisdiction, you may have rights to:
- Know whether we process your personal information.
- Access personal information.
- Correct inaccuracies.
- Delete personal information.
- Obtain a portable copy of eligible information.
- Withdraw consent where processing is based on consent.
- Opt out of certain sales or sharing.
- Opt out of certain targeted advertising.
- Object to or restrict certain processing.
- Appeal a denied privacy request where required.
- Avoid unlawful discrimination for exercising privacy rights.
You may submit requests to hi@theaha.app.
We may verify identity or authority before responding.
Authorized agents may submit requests where permitted by law.
We will respond within applicable statutory deadlines.
22. U.S. State Privacy Rights
Residents of certain U.S. states may have additional rights under applicable consumer privacy laws.
These rights may include access, correction, deletion, portability, and opt-outs concerning covered data uses.
The availability and scope of these rights depend on applicable law, exemptions, and whether Aha! is subject to the relevant statute.
Where required, we will provide mechanisms for exercising applicable rights and appealing decisions.
We will honor legally recognized privacy preference signals where applicable.
We will not discriminate against individuals for exercising protected privacy rights.
Requests may be directed to hi@theaha.app.
23. California Privacy Disclosures
California residents may have rights under the California Consumer Privacy Act, as amended, where applicable.
Categories of personal information potentially processed include:
- Identifiers.
- Customer records information.
- Commercial and subscription information.
- Internet or electronic activity.
- Geolocation information.
- Audio, electronic, or visual information.
- Inferences related to preferences.
- Other information described in this Policy.
Sensitive personal information, where collected, is used only for disclosed purposes and subject to applicable restrictions.
The categories of sources, business purposes, and recipient categories are described throughout this Policy.
Where legally required, Aha! will provide applicable notices and methods for exercising rights to know, correct, delete, opt out, and limit certain uses of sensitive personal information.
Aha! will not claim that personal information has not been sold or shared for a statutory reporting period unless that statement has been verified against its actual practices.
24. International Privacy Rights
Aha! may be accessed outside the United States.
Where the European Economic Area, United Kingdom, or other jurisdictions' privacy laws apply, additional rights and obligations may arise.
Legal Bases
Where required, processing may rely on:
- Performance of a contract.
- Consent.
- Compliance with legal obligations.
- Legitimate interests, where permitted.
- Protection of vital interests.
- Other lawful bases.
International Transfers
Personal information may be processed in the United States or other locations where Aha! or authorized providers operate.
Where required, international transfers will be supported by appropriate legal mechanisms and safeguards.
International Requests
Individuals may contact hi@theaha.app to exercise applicable rights.
Where legally required, Aha! will provide additional jurisdiction-specific disclosures, contact information, or representative details.
25. Information Security
We use or seek to maintain reasonable administrative, technical, and organizational safeguards appropriate to the information processed.
Such measures may include:
- Encrypted communications.
- Access controls.
- Authentication.
- Restricted administrative permissions.
- Monitoring and logging.
- Security testing.
- Service-provider reviews.
- Data minimization.
- Backup and recovery controls.
- Segregation of private and public information.
- Rights-aware access to institutional knowledge.
No system is completely secure.
We cannot guarantee that unauthorized access, disclosure, alteration, or loss will never occur.
If a security incident triggers notification obligations, we will provide required notices in accordance with applicable law.
26. Data Accuracy and Automated Decisions
Aha! uses AI to produce educational content and recommendations.
AI-generated identifications, classifications, or recommendations may be inaccurate.
Users may be able to submit corrections or feedback.
We do not intend ordinary discovery recommendations or quiz results to make legally significant decisions about individuals.
If automated processing with legally significant effects is introduced, we will provide any additional notices, rights, or safeguards required by applicable law.
27. Sensitive Places and Cultural Knowledge
Certain geographic and cultural information requires additional protection.
Examples include:
- Sensitive archaeological locations.
- Sacred or restricted cultural sites.
- Endangered species habitats.
- Protected ecological locations.
- Private residences.
- Restricted park facilities.
- Confidential institutional information.
Aha! may suppress, generalize, restrict, or remove such information to protect people, communities, cultural resources, and natural environments.
Authorization to contribute content does not automatically authorize unrestricted publication or commercialization.
28. Third-Party Websites and Services
The Services may link to websites, applications, attractions, destinations, or other third-party resources.
We do not control independent third-party privacy practices.
Users should review the privacy policies of third-party services before providing personal information.
29. Business and Institutional Accounts
Where Aha! processes personal information on behalf of an organization, the organization's instructions and applicable data-processing agreement may govern certain activities.
Organizations are responsible for determining their lawful basis for providing employee, visitor, student, member, or other personal information to Aha!.
Aha! may act as an independent controller/business for some processing and as a processor/service provider for other processing, depending on the circumstances and applicable agreements.
Separate data-processing agreements may apply where required.
30. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our Services, technologies, legal obligations, or privacy practices.
The current version will be available at:
We will update the effective or last-updated date when changes are made.
For material changes, we will provide additional notice or obtain consent where required by law.
Changes will not retroactively authorize uses of personal information requiring consent without obtaining that consent.
31. Contact Us
For privacy questions, data requests, account deletion, children's privacy inquiries, or concerns about information handling, contact:
Onda Development, LLC d/b/a Aha!
Phoenix, Arizona
United States
Email: hi@theaha.app
Website: https://theaha.app
Privacy Policy: https://theaha.app/privacy
Terms of Service: https://theaha.app/terms
Account Deletion: https://theaha.app/delete-account
© 2026 Onda Development, LLC. All rights reserved.
