Privacy Policy
Effective: May 24, 2026 · Last updated: May 24, 2026
This Privacy Policy explains how Project Proof ("we," "us," or "ProjectProof") collects, uses, shares, and protects information when you use the ProjectProof mobile app, web services, and related features (together, the "Service"). It applies to data we receive about you as a ProjectProof account holder and to data we process on your behalf when you document a job site (photos, voice memos, notes, reports, and similar work product).
If you have questions about this policy or your data, contact us at privacy@projectproof.app.
1. The short version
What we collect. The work-site documentation you create (photos, videos, voice memos, notes, project metadata) plus the account information needed to give you access (email, sign-in identifier, and basic device information).
Why we collect it. To provide the Service: store your work, sync it across your devices, generate AI assistance you've enabled, and share it with people you choose to invite.
Who we share it with. Only the third parties needed to run the Service (a small list of infrastructure providers below) and people you explicitly share with. We do not sell your information. We do not share it for advertising. We do not allow AI providers to train on your content.
How we treat your content. Yes — we store your projects, photos, videos, voice memos, notes, and reports on our servers so the app can sync them across your devices. That content is encrypted at rest and in transit. We do not read, view, or browse it. We do not analyze it for marketing or product insights. We do not mine its metadata to build profiles or sell to anyone. The only operational measurements we collect are aggregate, non-identifying counts — for example, "average video length across all users," "average photos per project," or "total upload volume this week" — used solely to keep the Service running, troubleshoot issues, and plan capacity. No row of those metrics points back to you or your content.
What rights you have. You can access, export, and delete your data at any time from within the app. We also honor applicable rights under U.S. state privacy laws (including CCPA/CPRA) and other laws that apply to you.
2. Who we are
The ProjectProof Service is operated by Project Proof, based in the United States. For privacy inquiries, deletion requests, or any questions about this policy, write to privacy@projectproof.app.
ProjectProof is a job-site documentation tool for tradespeople and field-services professionals. The Service is designed for individuals and small businesses; it is not intended for use by people under 16.
3. What information we collect
3.1 Information you provide directly
- Account information. When you sign in (typically with Google or another supported provider via Firebase Authentication), we receive your email address and a provider-issued identifier. We do not receive or store your provider password.
- Profile information. Optional fields you choose to fill in: display name, company name, company logo, phone, address, website, and a public contact email shown on your reports.
- Project content. Everything you create or upload while documenting your work: project names, addresses, client and subcontractor records, photos, videos, voice memos, scanned documents, notes, checklists, reports, schedule events, and to-do items.
- Communications. Feedback, bug reports, and support messages you send us through the app or by email.
3.2 Information collected automatically from your device
- Camera, microphone, and storage access. Only when you actively use those features. Photos, videos, and voice memos are created on your device and uploaded to your account.
- Location. If you grant location permission, we tag photos and other captures with the GPS coordinates at the moment of capture and (best-effort) the reverse-geocoded street address. Location can be disabled at the OS level or per-capture.
- EXIF metadata. Photos you import from your gallery may include the original capture date and (rarely) embedded GPS data; we preserve these so an imported photo is filed under its actual creation time.
- Device identifier. A stable Android identifier (or iOS equivalent) used to attribute captures to the device they came from (so the "I just took the wrong photo on this device" undo window works correctly). Not used for cross-app tracking or advertising.
- Push notification token. A Firebase Cloud Messaging (FCM) or APNs token so other devices on your account, and recipients of shared projects, can receive sync notifications. Disabling notifications on your device clears the token's effect.
- Device and app context. Device model, OS version, and app version are sent only when you submit feedback or when a request fails (for diagnostic purposes).
- Network and service logs. Standard request logs (HTTP method, route, status, timing, an opaque request ID) are retained for operations and abuse prevention. These logs are kept free of personal content; user identifiers appear only in the form needed to scope rate limits and quotas.
3.3 Calendar access
If you enable device calendar sync, ProjectProof reads and writes events in the calendars you select so your project schedule and your phone's calendar stay aligned. Calendar data is processed locally on your device for this purpose; we do not store a copy of unrelated calendar events on our servers.
3.4 Sensitive content in your uploads
Job-site photos may incidentally contain images of people (workers, clients, passersby), vehicle license plates, or identifying details of premises. You are responsible for obtaining any consents required by your jurisdiction or contract before capturing or uploading such content. We treat all uploaded content as confidential and protect it as described in section 7.
4. How we use information
We use the information described above to:
- Authenticate you and keep your account secure;
- Store, organize, and synchronize your project content across your devices;
- Generate the AI-assisted features you have enabled — photo descriptions and tags, voice transcription and structuring, document summarization, daily summaries, report proofreading, and translation;
- Render your content into reports, daily logs, and exports you request;
- Share content with the recipients you invite and apply the per-type permissions you assign them;
- Send transactional notifications (sync events, share invitations, share acceptances, daily summary readiness if you opt in);
- Operate, debug, and improve the Service (including aggregate usage metrics that are not tied to identifiable content);
- Enforce our terms, prevent abuse (rate limits, daily caps), and comply with our legal obligations.
We do not use your personal information or your project content for advertising. We do not build advertising profiles on you. We do not allow third-party AI providers to train their models on your content (see section 5.2).
4.1 What our metrics include — and what they don't
To keep the Service running we collect a small set of aggregate, non-identifying measurements. These exist for service health, capacity planning, and troubleshooting — nothing else.
Examples of what we measure:
- Average length of voice memos and videos uploaded;
- Average number of photos per project;
- Total daily / weekly upload volume across the user base;
- Counts of AI calls per feature (used to monitor cost and catch abuse spikes);
- Request error rates, response timing, and similar service-health signals.
What those metrics do not contain:
- The content of your photos, videos, voice memos, notes, or reports;
- The names of your projects, clients, or subcontractors;
- Anything that lets us — or anyone reading the metrics — reconstruct what your specific project work looks like.
We do not view, read, or browse the content of your projects. We do not analyze your content for marketing or product insights. We do not enrich, profile, or sell metadata derived from your content.
A handful of per-user counters do exist where they're required to operate the Service safely — for example, your daily import count (to enforce per-day limits that protect against runaway AI cost) and your account-level storage usage. These are scoped to your user ID for the sole purpose of enforcing limits and are not used for any other analysis.
5. Who we share information with
5.1 People you choose
When you share a project with a collaborator (by email invitation), the content of that project — within the scope and permission level you select — becomes visible to that person on their own ProjectProof account. When you generate a public link to a report or asset bundle, anyone with the link (and the optional password you set) can view it until the link expires or you revoke it.
5.2 Sub-processors (infrastructure providers)
We rely on the following third-party providers to operate the Service. Each is bound to confidentiality and security obligations under their respective contracts:
| Provider | Purpose | Data handled |
|---|---|---|
| Cloudflare | Hosting, edge compute (Workers), database (D1), object storage (R2), CDN | All user content (encrypted at rest), account records, service logs |
| Google Firebase | Authentication, push notifications (FCM) | Email, provider identifier, device push token |
| Google ML Kit | On-device OCR for document scans | Document images (processed on your device, not uploaded for OCR) |
| OpenRouter | Router that dispatches AI requests to model providers (e.g., Anthropic, Google, OpenAI) | Photos, transcribed audio, OCR text, notes, and other content you send to an AI feature — sent only when the relevant AI feature runs, and configured for zero-retention / no-training |
| Apple App Store / Google Play | App distribution and subscription billing | Purchase tokens and subscription state; we do not receive your payment card |
This list may change over time. Material changes to sub-processors will be reflected in this policy.
5.3 Other disclosures
We may disclose information when we believe in good faith that disclosure is necessary to: comply with applicable law, regulation, or valid legal process; protect the rights, property, or safety of ProjectProof, our users, or others; or investigate and address fraud, security, or technical issues. Where permitted, we will notify the affected user before disclosure.
If ProjectProof is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction. We will notify users by updating this policy (and, where required by law, by email) before any new owner materially changes how your data is handled. You may delete your account and data at any time, including before any such transfer takes effect.
5.4 What we do not do
- We do not sell your personal information.
- We do not share your data for cross-context behavioral advertising.
- We do not authorize any AI provider we use to train models on your content. Our OpenRouter integration is configured for zero-retention / no-training; on-device features (Android's built-in speech recognition, ML Kit OCR) run locally and do not transmit your content to Google for training when configured according to those services' on-device modes.
- We do not use your content for our own AI training beyond per-request inference for the feature you triggered.
6. International data transfers
ProjectProof is operated from the United States. Our sub-processors (notably Cloudflare) operate global infrastructure, which means your data may be processed in regions outside your country of residence. We rely on the contractual protections those providers offer to safeguard data during such transfers. Where applicable law requires additional safeguards (for example, the EU Standard Contractual Clauses), we rely on our sub-processors' adoption of those mechanisms.
7. How we protect your information
We take reasonable and appropriate technical and organizational measures to protect your information:
- Encryption in transit. All connections between the app and our servers use TLS.
- Encryption at rest. Sensitive content fields in our database (project, capture, note, client, and subcontractor PII) are encrypted at the column level. Media files in object storage are encrypted at rest with an application-managed key, in addition to provider-side disk encryption.
- Access control. Permissions to your projects are scoped per recipient and per content type. Public share links can be password-protected.
- Rate limiting and abuse prevention. Per-user limits prevent runaway costs and bulk extraction.
- Operational logging. Logs used for debugging and abuse prevention are scrubbed of personal content; only stable identifiers (user IDs, request IDs) appear in our structured logs.
- Local device storage. On Android, the local database uses SQLCipher to encrypt cached data on your device.
No system can be guaranteed 100% secure. If we become aware of a breach affecting your personal information, we will notify you in accordance with applicable law.
8. How long we keep your information
- Account and project content. Retained as long as your account is active. You can delete individual items at any time from within the app.
- Account deletion. When you delete your account (Settings → Data Management → Delete Account), we delete your projects, captures, notes, reports, daily logs, profile data, and associated media from our active systems. Cached backups may persist for a short period (typically up to 30 days) before being fully purged. See our Account & Data Deletion page for full instructions, including how to request deletion if you can no longer access the app.
- Service logs. Standard request logs are retained for a limited operational window (typically up to 30 days) and then deleted or aggregated.
- Aggregate metrics. Non-identifying counts (e.g., daily upload totals) may be retained longer for capacity planning and abuse detection.
- Legal holds. We may retain information longer where required by law or to enforce our agreements.
9. Your rights and controls
Regardless of where you live, ProjectProof gives you the following in-app controls:
- Access: view all your data within the app at any time;
- Export: Settings → Data Management → Export Account Data downloads a full ZIP of your projects and media;
- Correction: edit profile, project, capture, and note content in place;
- Deletion: delete individual items, projects, or your entire account;
- Sharing controls: revoke shares and public links at any time;
- AI feature controls: disable any AI feature (descriptions, transcription, document scan, daily summary) at any time from Settings → AI.
9.1 California residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- Right to know: what categories of personal information we collect, where we get it, why we use it, and who we share it with — all disclosed in this policy;
- Right to access: request a copy of the specific personal information we hold about you;
- Right to delete: request deletion of personal information we collected from you, subject to legal exceptions;
- Right to correct: request correction of inaccurate personal information;
- Right to opt out: we do not "sell" or "share" personal information for cross-context behavioral advertising, so there is no opt-out required — but you can confirm this in writing by contacting us;
- Right to limit use of sensitive personal information: we do not use sensitive personal information for purposes beyond those expressly permitted under California law;
- Right to non-discrimination: we will not penalize you for exercising any of these rights.
To exercise these rights, contact us through either of the two designated request channels: email privacy@projectproof.app, or open ProjectProof and go to Settings → Feedback. We will verify your identity (typically by asking you to respond from the email address associated with your account) and respond within the legally required time window. You may designate an authorized agent to act on your behalf with appropriate written authorization.
9.2 Users in other jurisdictions
If you access ProjectProof from outside the United States, you may have additional rights under your local privacy laws (for example, the EU and UK General Data Protection Regulations). To exercise any such rights, contact us at privacy@projectproof.app. We will work with you in good faith to honor applicable requests.
10. Children's privacy
ProjectProof is intended for use by adults in a professional or business context. The Service is not directed to, and we do not knowingly collect personal information from, children under 16. If we learn that we have collected personal information from a child under 16 without verified parental consent, we will delete it promptly. If you believe a child has provided us with personal information, contact us at privacy@projectproof.app.
11. Cookies and similar technologies
The ProjectProof mobile apps do not use cookies. Our public website (projectproof.app) and any public share link viewer use only the cookies and local storage strictly necessary to render the page and (for protected links) hold an authenticated viewing session. We do not use analytics or advertising trackers on these pages.
12. Subscriptions and payments
If you purchase a paid subscription, billing is processed by the Apple App Store or Google Play. We receive a purchase token and the status of your subscription from those platforms, but we do not receive or store your payment card details. The applicable platform's privacy policy governs how it handles your payment information.
13. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. If we make material changes that affect how we collect or use your personal information, we will notify you through the app or by email before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
14. How to contact us
For any privacy-related question, request, or concern, you may reach us through either of two designated channels:
- Email: privacy@projectproof.app
- In-app: open ProjectProof and go to Settings → Feedback to send a message that reaches the same team.
Project Proof operates as an online-only service in the United States and does not maintain a public postal address for correspondence. If a written record of correspondence is required for a formal request (for example, by an authorized agent or in connection with a legal process), email is the appropriate channel and we will reply in writing.
We aim to acknowledge requests within five business days and respond substantively within the timeframes required by applicable law.