Transparency First

Privacy Policy

Effective date: March 2026 · Last updated: September 2026
🛡️
Section 01

Overview

✦

The short version: ProofPass is built around privacy. We only collect what we absolutely need, and we give you full control over your data at every step.

ProofPass is a privacy-first proof vault — designed from day one to keep your personal purchase records, warranties, and receipts exactly where they belong: under your control. We believe a useful app doesn't have to harvest your data, and we've built our entire infrastructure around that principle.

This Privacy Policy explains what information we collect (and what we never touch), how we use it, how we protect it, and the controls you have over it. We've written this in plain English on purpose — no legalese, no hidden clauses.

Local Mode users: If you use ProofPass without signing in, no data ever leaves your device. Your vault is stored locally on your phone, encrypted at rest. We have no visibility into it — ever.

Cloud Sync users (Pro): If you choose to back up and sync across devices, your vault data is end-to-end encrypted on your device before it's ever transmitted. This means even we cannot read what's in your vault. The keys live only on your device.

By using ProofPass, you agree to the practices described in this policy. If you have any questions or concerns, reach out to us at [email protected] — we're real people and we'll respond.

📋
Section 02

Information We Collect

We operate on a strict minimum-data philosophy. Here's exactly what we collect depending on how you use the app — and nothing more.

Local Mode (No Account)
🔒

Zero data collected. Everything — your receipts, warranties, item names, purchase dates — stays on your device. We collect nothing. Firebase Analytics, Crashlytics and Performance Monitoring are switched off in local mode — no usage analytics, no crash reports and no performance data are sent.

Google, Apple or Email Sign-In

If you create a ProofPass account (required for Pro cloud sync), we collect:

  • ✉ Email address — used solely for authentication. We use it to identify your account and, if you opt in, to send you important product notifications.
  • 👤 Display name — pulled from your Google or Apple profile or entered during sign-up. Used to personalize your in-app experience. Never shared externally.
  • 📊 Usage analytics (Firebase Analytics) — while you're signed in, we collect app usage events such as screens viewed, sign-in and sign-up, adding an item (and whether it was scanned or entered manually) and upgrading to Pro, linked to your account ID and an app instance ID. These events never include your receipts, item names, amounts or any other vault contents.
  • 🩺 Crash reports (Firebase Crashlytics) — if the app crashes while you're signed in, we receive a crash report: the error and stack trace, app version, device model and OS version. Crash reports never include vault contents.
  • ⚡ Performance data (Firebase Performance Monitoring) — while you're signed in, we collect app start times, screen rendering and network request timings, with device model, OS version and country, to find slow spots. It never includes vault contents.

Analytics, crash reporting and performance collection start when you sign in and stop as soon as you sign out or switch to local mode. Crash reports captured while you weren't signed in are deleted, not uploaded.

Pro Cloud Sync

If you subscribe to ProofPass Pro and enable cloud backup:

  • ☁ Encrypted vault data — your vault, including returns you are tracking (return steps, RMA and tracking numbers, ship-by dates), is fully encrypted on-device using AES-256 before being uploaded to Firebase Firestore. The ciphertext is what's stored in the cloud. We cannot decrypt it. So you can open your vault on another device, your vault key is also stored in the cloud — but only in encrypted form, locked with your sync password or recovery code, which never leave your device and which we never receive.
Gmail Import (Optional — Coming in a Future Version)

Gmail Import is not available in the current version of ProofPass. ProofPass does not currently request or access any Gmail data. When the feature is released, the following will apply if you choose to use it to automatically find purchase confirmation emails:

  • 📧 We request read-only access to your Gmail inbox, scoped to find purchase-related emails. We scan for receipt patterns, extract the relevant data (merchant, amount, date), and store only the extracted receipt data in your local vault. We do not store your email content, and we do not retain Gmail access tokens beyond your active session.
  • 🔒 Google API Services User Data Policy — Limited Use. ProofPass's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: (1) we use Gmail data only to find purchase receipts and create the entries you select in your vault — the user-facing feature you requested; (2) we do not transfer Gmail data to third parties, except as needed to provide that feature, to comply with law, or as part of a merger or acquisition with your consent; (3) we do not use Gmail data for advertising, including retargeting or interest-based ads; (4) no human reads your Gmail data, except with your explicit consent for specific messages, for security purposes, or to comply with law; and (5) we do not use Gmail data to develop, improve, or train generalized AI or machine-learning models. Email content is processed on your device and is not sent to ProofPass servers.
Launch Notifications (Optional)
  • 🔔 If you submit your email address through our "Get Notified" form on our website, we store it solely to send you a one-time launch notification. You can opt out at any time by emailing us.
⚙️
Section 03

How We Use Your Information

We use the data we collect for a small number of specific, clearly defined purposes. We don't use your data for advertising targeting, behavioral profiling, or anything you haven't consented to.

  • 🔑 Authentication — Your email and display name are used to verify your identity when you sign in and to maintain your account session across devices.
  • 🔄 Cross-device sync (Pro) — Your encrypted vault data is synced across your devices via Firebase Firestore. The sync process is entirely end-to-end encrypted; we transmit and store ciphertext only.
  • 📊 App improvement & stability (signed-in accounts) — Usage analytics, crash reports and performance data from Firebase Analytics, Crashlytics and Performance Monitoring are used only to understand which features are used, fix crashes and speed up the app. They are never used for advertising or sold.
  • 🔔 Warranty, return & recall notifications — ProofPass monitors warranty expiry dates and matches your product catalog against official government recall data. The matching runs on your device, and notifications are delivered through your device's notification system — your product details are not sent anywhere for this purpose.
  • 📣 Launch notifications (opt-in) — If you submitted your email to be notified at launch, we'll send you one notification when the app goes live. That's it.
🚫

We never sell, rent, trade, or share your personal data with third parties for their marketing or advertising purposes. Your data is yours. Full stop.

🔐
Section 04

Data Storage & Security

Security isn't a checkbox — it's the foundation of how ProofPass is built. Here's exactly what we do to protect your data at every layer.

On-Device Storage
  • 📱 Your local vault is stored in a Hive database with AES-256 encryption at rest. This means even if someone gained physical access to your device storage, they couldn't read your data without the encryption key.
  • 🔏 Your PIN and biometric credentials are stored in Flutter Secure Storage, which uses your device's native keychain (iOS Keychain / Android Keystore). This data is hardware-backed and is never transmitted over the network — not even to us.
Cloud Storage (Pro)
  • ☁️ Vault data is end-to-end encrypted before it leaves your device. We use AES-256-GCM with keys derived from your account credentials. The ciphertext is stored in Firebase Firestore — only you can decrypt it.
  • 🏗️ Firebase Firestore provides server-side encryption at rest as an additional layer, along with TLS 1.3 encryption in transit. Both layers are active simultaneously.
Authentication Security
  • 🛡️ Authentication is handled entirely by Google Firebase Authentication, which implements industry-standard OAuth 2.0 and OpenID Connect. We never receive or store your passwords — they're managed exclusively by Google's identity infrastructure.

While no system is 100% impenetrable, we've taken care to ensure that even in a worst-case breach scenario, your vault data would remain unreadable ciphertext. Your encryption keys live on your devices. The only copy on our servers is locked with your sync password or recovery code, which we never see.

🔗
Section 05

Third-Party Services

ProofPass integrates with a small set of trusted third-party services to deliver its features. Here's exactly who they are, what they receive, and why.

Google Firebase Auth + Firestore
Handles user authentication and encrypted cloud storage for Pro subscribers. Firebase receives your email address and display name for auth, and your encrypted vault ciphertext for sync. Firebase's infrastructure is SOC 2 and ISO 27001 certified.
Firebase Analytics, Crashlytics & Performance Signed-in accounts only
When you're signed in with Google, Apple or email, Google Firebase receives app usage events, crash reports and performance timings (with device model, OS version and an app instance ID) so we can improve and fix the app. None of it includes your vault contents. All three are switched off in local mode and stop when you sign out.
Google Sign-In Identity Provider
An optional way to authenticate using your Google account. If used, Google shares your email and display name with us via OAuth 2.0. You can revoke this access at any time via your Google Account settings under Third-Party Apps.
Google AdMob Ads (Free tier)
Free users see unobtrusive banner ads served by Google AdMob. AdMob may use your device's advertising ID (IDFA on iOS / GAID on Android) to serve contextual ads. You can opt out of personalized ads at the device level in your OS privacy settings. Pro subscribers see no ads.
Official recall databases Safety Recalls
Our servers (Google Firebase) regularly collect public recall data from official sources — for example CPSC, FDA and NHTSA (US), Health Canada and Transport Canada, OPSS, FSA and MHRA (UK), ACCC, FSANZ and TGA (Australia), EU Safety Gate and RappelConso, Product Safety NZ, and the Israel Ministry of Transport — and your device downloads that public data. Matching against your products happens on your device: your product details, brands and receipts are never sent to these agencies or to us to check for recalls.
Google ML Kit On-Device OCR
Used to extract text from receipt images (e.g., merchant name, purchase amount, date). ML Kit runs entirely on your device — no image or text data is sent to Google servers. This is a fundamental design choice: your receipts never leave your phone during OCR.

We periodically review our third-party integrations and will update this section if the list changes. We do not integrate any data broker, social media tracking, or advertising attribution services.

⚖️
Section 06

Your Rights & Controls

You're in charge. ProofPass is designed so that the most important privacy controls are built directly into the app — no emails to us required for most actions.

🗑️

Delete All My Data

Go to Settings → Delete All My Data to permanently wipe your local vault and all cloud backups simultaneously. This action is irreversible and takes effect immediately.

📤

Export My Vault

Go to Settings → Export My Vault to download your complete purchase history and warranty data as a CSV or PDF. Your data is portable and you can take it anywhere.

🔌

Revoke Gmail Access

If you used Gmail Import, revoke ProofPass's access at any time via myaccount.google.com → Security → Third-party apps. We immediately stop any further inbox access.

📵

Opt Out of Ads

On iOS: Settings → Privacy → Apple Advertising. On Android: Settings → Google → Ads → Opt out of Ads Personalization. Or simply upgrade to Pro — Pro subscribers see zero ads.

👤

Account Deletion

Deleting your account is included in the Delete All My Data flow — it wipes your cloud data and removes your authentication record from Firebase simultaneously.

📩

Opt Out of Email

If you signed up for launch notifications, you can opt out at any time by emailing [email protected] and we'll remove you immediately.

If you're in the EU, UK, or California, you also have formal rights under GDPR, UK GDPR, or CCPA respectively — including the right to access, correct, or object to processing of your personal data. Contact us at [email protected] and we'll respond within 30 days.

👶
Section 07

Children's Privacy

ProofPass is not directed at children under the age of 13, and we do not knowingly collect personal information from anyone under 13. The app is designed for adults managing their household purchases, warranties, and consumer records.

If you're a parent or guardian and you believe your child has provided us with personal information, please contact us immediately at [email protected]. We will promptly delete any such data from our systems and deactivate the associated account.

We comply with the Children's Online Privacy Protection Act (COPPA) and take our obligations seriously. If we ever discover that a user is under 13, we will immediately remove their data without waiting for a request.

📝
Section 08

Changes to This Policy

We may update this Privacy Policy from time to time — for example, when we add new features, change our infrastructure, or when laws and regulations require it. We'll always be transparent about what's changed and when.

When we make a meaningful update — anything that affects how your data is collected, used, or shared — we will:

  • 📱 Display a clear in-app notice the next time you open ProofPass, summarizing what changed and linking to the full updated policy.
  • 📅 Update the "Last Updated" date at the top of this page so you can always tell when the policy was last revised.

For minor changes — like fixing a typo, clarifying wording, or adding a new third-party service that doesn't change data handling — we'll update the page and the date without an in-app notice.

Your continued use of ProofPass after a policy update constitutes your acceptance of the revised policy. If you disagree with any changes, you can delete your account and data using the controls described in Section 6 before the changes take effect.

💬
Section 09

Contact Us

Privacy questions deserve real answers — not automated replies. If you have any questions about this Privacy Policy, want to exercise your data rights, or just want to understand something better, get in touch with us directly.

✉️

Privacy & data inquiries

[email protected]

We aim to respond to all privacy-related inquiries within 5 business days. For formal data subject access requests (GDPR, CCPA), we respond within 30 days as required by law.

ProofPass is developed and operated by Bela Apps. All data practices described in this policy are maintained by the Bela Apps team.