ProofPocket Privacy Policy
1. Who is the controller of your data?
The controller of personal data processed in connection with the ProofPocket app (the "App") is KJLabs Studio ("we", "us").
For privacy matters, contact us at: kjlabs.studio@gmail.com.
Website: https://kjlabs.studio/.
2. Scope of this Policy
This Policy explains how we process data when you use the App on iOS or Android, including accounts, synchronisation, ProofPocket+, shared spaces, document scanning and import, OCR, optional AI processing, and warranty reminders.
ProofPocket is a purchase-document archive, not a budgeting or accounting app. You can use the core local archive without an account or an internet connection.
3. The data we process
The data processed depends on the features you use.
| Feature | Categories of data |
|---|---|
| Local archive | Document images and files, such as receipts, invoices, nameplate photos and imported PDFs; their OCR text; and data you enter, including product name, merchant, brand, serial and order number, purchase date and price, currency, warranty term, notes and reminder settings. A document may contain your personal data or that of another person. |
| Account | Email address, account identifier, selected sign-in provider and technical data needed for authentication. You may sign in with email, Apple or Google. |
| Synchronisation | The archive data above, record identifiers, change and deletion markers, and document files — only when you sign in and synchronisation is enabled. |
| Shared spaces | Space name, member identifiers, member email addresses visible to authorised members, roles, membership dates, invitation tokens, and documents and archive data added to that space. |
| Notifications | Device notification token, pseudonymous installation identifier, platform, App version, language and time zone. A notification may include a product name and warranty date or status. |
| ProofPocket+ | Entitlement status, customer/subscription identifier, and offer, renewal and purchase information supplied by the store platform through RevenueCat. We do not receive your full payment-card number. |
| Diagnostics and analytics | Events concerning use of the App, such as adding an item, showing or completing a ProofPocket+ purchase, sign-in and PDF import; screen information; and error or technical-configuration information. Our own events do not include receipt content, OCR content or document images. |
| Support or promotional reward, where available | The content of your request and contact details you provide, including an email address needed to handle the request or send information about a reward. |
We do not request access to contacts, location or the microphone. Camera and photo library access is used only after you choose a scanning or import action. The system notification permission is requested contextually when you enable reminders.
4. Purposes and legal bases
| Purpose | GDPR legal basis |
|---|---|
| Providing the local archive, on-device OCR, search, document management and local reminders | Performance of a contract or steps taken before entering into a contract — Article 6(1)(b) GDPR. When data remains only on your device, we generally do not process it on our servers. |
| Creating and operating an account, signing in, synchronising and restoring your archive | Article 6(1)(b) GDPR. |
| Shared spaces, invitations and member permissions | Article 6(1)(b) GDPR. A person sharing documents is responsible for having an appropriate basis to disclose other persons' data to members of that space. |
| Billing ProofPocket+, checking entitlements, restoring purchases and preventing misuse | Article 6(1)(b) and (f) GDPR; our legitimate interest is secure and accurate provision of the service. Apple or Google process the purchase and payment under their store terms. |
| Sending warranty notifications | Article 6(1)(b) GDPR and, where required by applicable law, your consent granted through the operating system settings. |
| Security, fault prevention, establishment, exercise or defence of claims | Article 6(1)(f) GDPR; our legitimate interests are App security, service continuity and protection of our rights. |
| Usage analytics | Consent, where required by applicable rules on accessing information on a device or using device identifiers; in all cases subject to the privacy controls and settings described in the App. |
| Meeting legal obligations | Article 6(1)(c) GDPR. |
Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing before it was withdrawn.
5. OCR and optional AI processing
We primarily recognise text from images on your device, using Apple Vision on iOS or ML Kit on Android. OCR output and document data extracted from it are stored locally and, if you enable synchronisation, are synchronised in the same way as other archive data.
In some flows, the App may use optional cloud services to:
- structure and supplement receipt OCR, for example merchant, totals, line items, date, brand or order number; or
- read the content of an imported PDF document.
For those purposes, our Supabase function and then our AI provider, Mistral AI, receive either OCR text and related metadata or the whole imported PDF file. For receipts, we try to filter selected lines that resemble masked payment or loyalty-card data, but this filter is not a substitute for your review. Do not send a document to the AI feature if you do not want its content processed in the cloud.
For AI-normalisation requests, Mistral does not use data sent through its API to train its models and retains it for approximately 30 days for abuse monitoring before deletion. The App may create an anonymous technical Supabase session solely for this processing; it is not presented as a ProofPocket account.
The AI service is assistive. It may return incomplete or inaccurate results and does not make decisions that produce legal effects concerning you. Check results before saving them. If the App cannot reach the AI service, the core local archive remains available.
6. Recipients and service providers
We use providers that process data on our documented instructions or act as independent controllers for their own services.
| Provider | Role / purpose |
|---|---|
| Supabase | Authentication, database, server functions and storage of synchronised files. |
| Mistral AI | PDF OCR and optional AI structuring of OCR data. For AI normalisation, Mistral acts as a processor; its privacy policy: legal.mistral.ai/terms/privacy-policy. |
| RevenueCat | Subscription status and the ProofPocket+ entitlement. |
| Apple and Google | App distribution, sign-in where selected, subscription purchase and, depending on platform, notification delivery. |
| Firebase (Google) | Analytics, crash reporting and push-notification infrastructure where those services are configured in the relevant version of the App. |
We may also disclose data to public authorities or other recipients where required by law or necessary to establish, exercise or defend legal claims.
We do not sell personal data or use document content for behavioural advertising. We do not carry out "tracking" as that term is used by the App Store rules.
7. Transfers outside the EEA
The providers above may process data outside the European Economic Area, depending on the selected configuration and infrastructure. Where a transfer requires safeguards, we use a mechanism provided for by the GDPR, in particular an adequacy decision of the European Commission or standard contractual clauses with any required supplementary measures.
To obtain information about the mechanism used for a particular provider or a copy of the relevant safeguards, write to kjlabs.studio@gmail.com.
8. Retention periods
| Data | Retention period |
|---|---|
| Local-only data | Until you delete it from the App or remove the App/system data from your device. |
| Synchronised data | Until you delete it or delete your account, subject to the period necessary for backups, security, fraud prevention or legal obligations. |
| Account data | Until account deletion, subject to data we must retain under law or for claims during the applicable limitation period. |
| Push tokens | Until the token is revoked, you sign out or you delete your account. |
| Billing and entitlement data | For the duration of the subscription and then for the period required for accounting, legal compliance and claims. |
| AI-normalisation request data at Mistral | Approximately 30 days for abuse monitoring, then deleted; not used to train Mistral models. |
| Diagnostics and analytics | In accordance with the relevant provider's configuration, security needs and legal obligations. |
Deleting an account in Settings removes the account and cloud-stored data and documents, as well as local data on the device from which the process is started. It does not cancel a subscription purchased in the App Store or Google Play; you must cancel that subscription in the relevant store settings.
9. Your rights
Subject to the conditions set out in the GDPR, you may request access to, rectification, erasure, restriction of processing or portability of your data, and object to processing based on our legitimate interests. Send requests to kjlabs.studio@gmail.com.
You also have the right to lodge a complaint with the data-protection supervisory authority competent for your habitual residence, place of work or the place of the alleged infringement. In Poland, this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
Providing account data is voluntary, but necessary to create an account, use synchronisation or use shared spaces. You may still use local features that do not require an account or network connection. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
10. Security
We use reasonable technical and organisational safeguards, including access controls, authentication, account-data isolation and shared-space permissions. No transmission or storage method is completely secure. Protect your device, account and invitation links, and do not share documents with unauthorised people.
11. Children
The App is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with data without required consent, contact us at kjlabs.studio@gmail.com.
12. Changes to this Policy
We may update this Policy when App features, our processing or the law changes. For a material change, we will publish a new update date and, where required, notify you in the App or through another appropriate channel.