Proof Pocket Privacy Policy
Draft dated 2026-09-28. The analytics consent and retention rules described here must be implemented before publication. This text does not change app or provider settings.
Controller and scope
Karol Burdziński Funky Devs is the controller of the personal data described below. Contact us about privacy and your rights at contact@proofpocket.com. This policy covers the Proof Pocket mobile app, proofpocket.com, Document Copy Planner and correspondence with us.
Documents and technical data
Vault documents, scans and files are encrypted and stored on your device. We do not operate a server storing your vault and do not know your master password. You do not need a Proof Pocket account. Optional backups, exports and sharing are described below.
Purchase, diagnostic and usage data are processed separately. These include installation and purchase identifiers and may include IP addresses. They can be personal data even when we do not know your name. Data sent to providers is not limited to aggregate statistics. We do not sell data or use it to personalise advertising. The app does not obtain precise GPS location.
Purposes, data and legal bases
| Purpose and service | Data | GDPR legal basis |
|---|---|---|
| Purchases and Pro entitlements — RevenueCat and Apple/Google | RevenueCat user ID, transaction identifiers and history, product, entitlement status and country | Contract performance, Article 6(1)(b); accounting obligations where applicable to us — Article 6(1)(c) |
| Feature usage analysis — Firebase Analytics | Usage events, installation identifier, app and device information, approximate country derived from IP | Prior consent — Article 6(1)(a); refusing or withdrawing consent does not restrict core vault functions |
| Error diagnostics — Sentry | Error and crash reports, technical logs, app and OS version, device model and IP | Article 6(1)(f), our legitimate interest in security and fixing errors; where accessing information on your device requires consent, prior consent is also required |
| Answering messages and complaints | Email address, correspondence and purchase details you provide | Contract support — Article 6(1)(b); complaint obligations — (c); other enquiries — (f), our legitimate interest in answering them |
| Establishing, exercising or defending claims | Necessary correspondence and transaction or incident information | Article 6(1)(f), protecting rights in a specific dispute |
Data needed to complete a purchase or handle a request is necessary for that activity; without it we may be unable to carry it out. Optional analytics requires separate information and an appropriate legal basis. Using the app, accepting terms or reading this policy is not consent. We do not use these data to make solely automated decisions with legal or similarly significant effects on you.
Cloud Backup, Sharing and Transfer
Cloud backup is optional and off by default. The app encrypts it on your device using your master password and sends it directly to your iCloud Drive or Google Drive account. We do not store these backups on our own server or receive your master password. Storage in your account is governed by your chosen cloud provider’s policies.
On Android, Google Drive backup asks for permission to see, edit, create and delete only the specific Google Drive files you use with this app (the "drive.file" scope). The Application uses this permission only to create, list, download and delete its own backup files. It cannot see any other files in your Google Drive. The Application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data received from Google APIs is not used for advertising, is not sold, and is not transferred to anyone else.
When you share or export a document or a case, or move your vault to another device, the files go directly where you send them: through your device's share sheet, or over your local network to your other device. They do not pass through any server of the Service Provider.
Exporting an individual document always creates an encrypted file. Your recipient and chosen sharing app may process it under their own policies. Camera and file permissions support functions you initiate and can be changed in system settings.
Website and Document Copy Planner
Document Copy Planner selections and entered content are processed locally in your browser. Exports are created on your device. We do not save your plan contents on our own server.
The website uses Vercel Web Analytics for aggregate visit measurement. Vercel receives information such as the page URL, referral source, browser, device and approximate location. Vercel’s documentation states that the service uses no analytics cookies and discards the visitor session identifier after 24 hours. This is not a deletion deadline for all aggregate statistics. See Vercel Web Analytics.
Recipients and international transfers
Data described for external services is sent to the relevant providers. Providers acting on our instructions process data under processing agreements; Apple and Google may also determine their own purposes for their stores and cloud accounts. Data may be disclosed to authorised authorities where required by law, and to advisers where necessary for a specific claim and supported by a legal basis. Believing disclosure could be useful is not itself a legal basis.
Service providers may process data outside the European Economic Area, including in the USA. Transfers require a basis under Chapter V GDPR, such as an adequacy decision covering the recipient or European Commission standard contractual clauses. The RevenueCat DPA and Sentry DPA describe these providers’ transfer safeguards. Google transfer information is available in the linked Firebase documentation. Contact us to request information about transfers of your data and a copy of the relevant safeguards.
Retention
- Firebase Analytics: the configured user and event data retention period is 2 months. This setting does not cover standard aggregate reports; see Google’s explanation.
- Sentry: we delete diagnostic reports no later than 2 months after collection.
- RevenueCat: we retain data needed to validate and restore purchases for the duration of the entitlement, including lifetime access. Transaction history and profiles are not automatically deleted after one month. You may request erasure; data no longer needed to support the entitlement is deleted, subject to legal obligations and specific claims described below.
- Routine correspondence: up to 2 months after the matter is closed. Complaint records are kept longer only where needed for legal obligations or claims.
- Vercel Web Analytics: the session identifier is discarded after 24 hours. Aggregate statistics follow Vercel’s service rules; we do not promise automatic deletion of those statistics after 2 months.
- Records required by law are kept for the applicable statutory period; information needed for a specific dispute is kept until the relevant limitation period expires or proceedings finally conclude, if later.
Backups in your cloud account stay there until you delete them. The Application keeps the 3 most recent backups and deletes older ones automatically. You can turn off cloud backup in the Application's settings at any time, delete backups from your iCloud Drive or Google Drive, and remove the Application's access to Google Drive in your Google Account settings.
Uninstalling does not automatically erase data already sent to providers or cloud backups. You can delete local files in the app; exported copies must be deleted separately where they are stored.
Your rights and choices
Depending on the legal basis and circumstances, you may request access, rectification, erasure, restriction and portability. You may object to processing based on legitimate interests for reasons relating to your situation. Where consent is the basis, you can withdraw it at any time as easily as you gave it, without affecting the lawfulness of earlier processing.
Send requests to contact@proofpocket.com. We normally respond within one month; we explain any legally permitted extension and its reasons within that period. We may request information necessary to locate your data or verify your request, such as a transaction reference. We do not request your master password or copies of vault documents. If we cannot link data to you, we will explain this; we do not collect extra identifying data solely for future identification.
You may complain to the President of the Polish Personal Data Protection Office (UODO) or another competent supervisory authority, particularly where you habitually reside, work or believe an infringement occurred.
Children, security and policy updates
The app is not directed at children under 13. Where processing relies on consent for a service offered directly to a child, the local age threshold applies; in Poland, a guardian's consent or authorisation is required below 16. Being 13 does not replace this requirement. Contact us about concerns involving a child's data.
We use safeguards appropriate to the risks, including vault encryption. Do not send passwords or confidential scans in support requests. We date policy revisions and give legally required notice of material changes before new processing begins. A new purpose requires an appropriate legal basis and, where that basis is consent, separate consent. Continued use does not mean consent to changes.