ProjectProof ← Home

Privacy Policy

Effective: May 24, 2026 · Last updated: May 24, 2026

This Privacy Policy explains how Project Proof ("we," "us," or "ProjectProof") collects, uses, shares, and protects information when you use the ProjectProof mobile app, web services, and related features (together, the "Service"). It applies to data we receive about you as a ProjectProof account holder and to data we process on your behalf when you document a job site (photos, voice memos, notes, reports, and similar work product).

If you have questions about this policy or your data, contact us at privacy@projectproof.app.

1. The short version

What we collect. The work-site documentation you create (photos, videos, voice memos, notes, project metadata) plus the account information needed to give you access (email, sign-in identifier, and basic device information).

Why we collect it. To provide the Service: store your work, sync it across your devices, generate AI assistance you've enabled, and share it with people you choose to invite.

Who we share it with. Only the third parties needed to run the Service (a small list of infrastructure providers below) and people you explicitly share with. We do not sell your information. We do not share it for advertising. We do not allow AI providers to train on your content.

How we treat your content. Yes — we store your projects, photos, videos, voice memos, notes, and reports on our servers so the app can sync them across your devices. That content is encrypted at rest and in transit. We do not read, view, or browse it. We do not analyze it for marketing or product insights. We do not mine its metadata to build profiles or sell to anyone. The only operational measurements we collect are aggregate, non-identifying counts — for example, "average video length across all users," "average photos per project," or "total upload volume this week" — used solely to keep the Service running, troubleshoot issues, and plan capacity. No row of those metrics points back to you or your content.

What rights you have. You can access, export, and delete your data at any time from within the app. We also honor applicable rights under U.S. state privacy laws (including CCPA/CPRA) and other laws that apply to you.

2. Who we are

The ProjectProof Service is operated by Project Proof, based in the United States. For privacy inquiries, deletion requests, or any questions about this policy, write to privacy@projectproof.app.

ProjectProof is a job-site documentation tool for tradespeople and field-services professionals. The Service is designed for individuals and small businesses; it is not intended for use by people under 16.

3. What information we collect

3.1 Information you provide directly

3.2 Information collected automatically from your device

3.3 Calendar access

If you enable device calendar sync, ProjectProof reads and writes events in the calendars you select so your project schedule and your phone's calendar stay aligned. Calendar data is processed locally on your device for this purpose; we do not store a copy of unrelated calendar events on our servers.

3.4 Sensitive content in your uploads

Job-site photos may incidentally contain images of people (workers, clients, passersby), vehicle license plates, or identifying details of premises. You are responsible for obtaining any consents required by your jurisdiction or contract before capturing or uploading such content. We treat all uploaded content as confidential and protect it as described in section 7.

4. How we use information

We use the information described above to:

We do not use your personal information or your project content for advertising. We do not build advertising profiles on you. We do not allow third-party AI providers to train their models on your content (see section 5.2).

4.1 What our metrics include — and what they don't

To keep the Service running we collect a small set of aggregate, non-identifying measurements. These exist for service health, capacity planning, and troubleshooting — nothing else.

Examples of what we measure:

What those metrics do not contain:

We do not view, read, or browse the content of your projects. We do not analyze your content for marketing or product insights. We do not enrich, profile, or sell metadata derived from your content.

A handful of per-user counters do exist where they're required to operate the Service safely — for example, your daily import count (to enforce per-day limits that protect against runaway AI cost) and your account-level storage usage. These are scoped to your user ID for the sole purpose of enforcing limits and are not used for any other analysis.

5. Who we share information with

5.1 People you choose

When you share a project with a collaborator (by email invitation), the content of that project — within the scope and permission level you select — becomes visible to that person on their own ProjectProof account. When you generate a public link to a report or asset bundle, anyone with the link (and the optional password you set) can view it until the link expires or you revoke it.

5.2 Sub-processors (infrastructure providers)

We rely on the following third-party providers to operate the Service. Each is bound to confidentiality and security obligations under their respective contracts:

ProviderPurposeData handled
Cloudflare Hosting, edge compute (Workers), database (D1), object storage (R2), CDN All user content (encrypted at rest), account records, service logs
Google Firebase Authentication, push notifications (FCM) Email, provider identifier, device push token
Google ML Kit On-device OCR for document scans Document images (processed on your device, not uploaded for OCR)
OpenRouter Router that dispatches AI requests to model providers (e.g., Anthropic, Google, OpenAI) Photos, transcribed audio, OCR text, notes, and other content you send to an AI feature — sent only when the relevant AI feature runs, and configured for zero-retention / no-training
Apple App Store / Google Play App distribution and subscription billing Purchase tokens and subscription state; we do not receive your payment card

This list may change over time. Material changes to sub-processors will be reflected in this policy.

5.3 Other disclosures

We may disclose information when we believe in good faith that disclosure is necessary to: comply with applicable law, regulation, or valid legal process; protect the rights, property, or safety of ProjectProof, our users, or others; or investigate and address fraud, security, or technical issues. Where permitted, we will notify the affected user before disclosure.

If ProjectProof is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction. We will notify users by updating this policy (and, where required by law, by email) before any new owner materially changes how your data is handled. You may delete your account and data at any time, including before any such transfer takes effect.

5.4 What we do not do

6. International data transfers

ProjectProof is operated from the United States. Our sub-processors (notably Cloudflare) operate global infrastructure, which means your data may be processed in regions outside your country of residence. We rely on the contractual protections those providers offer to safeguard data during such transfers. Where applicable law requires additional safeguards (for example, the EU Standard Contractual Clauses), we rely on our sub-processors' adoption of those mechanisms.

ProjectProof is initially intended for users in the United States. If you access the Service from outside the U.S., you understand that your information is processed in the U.S. and other regions as described above.

7. How we protect your information

We take reasonable and appropriate technical and organizational measures to protect your information:

No system can be guaranteed 100% secure. If we become aware of a breach affecting your personal information, we will notify you in accordance with applicable law.

8. How long we keep your information

9. Your rights and controls

Regardless of where you live, ProjectProof gives you the following in-app controls:

9.1 California residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:

To exercise these rights, contact us through either of the two designated request channels: email privacy@projectproof.app, or open ProjectProof and go to Settings → Feedback. We will verify your identity (typically by asking you to respond from the email address associated with your account) and respond within the legally required time window. You may designate an authorized agent to act on your behalf with appropriate written authorization.

9.2 Users in other jurisdictions

If you access ProjectProof from outside the United States, you may have additional rights under your local privacy laws (for example, the EU and UK General Data Protection Regulations). To exercise any such rights, contact us at privacy@projectproof.app. We will work with you in good faith to honor applicable requests.

10. Children's privacy

ProjectProof is intended for use by adults in a professional or business context. The Service is not directed to, and we do not knowingly collect personal information from, children under 16. If we learn that we have collected personal information from a child under 16 without verified parental consent, we will delete it promptly. If you believe a child has provided us with personal information, contact us at privacy@projectproof.app.

11. Cookies and similar technologies

The ProjectProof mobile apps do not use cookies. Our public website (projectproof.app) and any public share link viewer use only the cookies and local storage strictly necessary to render the page and (for protected links) hold an authenticated viewing session. We do not use analytics or advertising trackers on these pages.

12. Subscriptions and payments

If you purchase a paid subscription, billing is processed by the Apple App Store or Google Play. We receive a purchase token and the status of your subscription from those platforms, but we do not receive or store your payment card details. The applicable platform's privacy policy governs how it handles your payment information.

13. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. If we make material changes that affect how we collect or use your personal information, we will notify you through the app or by email before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. How to contact us

For any privacy-related question, request, or concern, you may reach us through either of two designated channels:

Project Proof operates as an online-only service in the United States and does not maintain a public postal address for correspondence. If a written record of correspondence is required for a formal request (for example, by an authorized agent or in connection with a legal process), email is the appropriate channel and we will reply in writing.

We aim to acknowledge requests within five business days and respond substantively within the timeframes required by applicable law.