Privacy Policy — ProofPocket
1. Who we are
ProofPocket is operated by KJLabs Studio ("we", "us", "our").
Contact: kjlabs.studio@gmail.com
Website: https://kjlabs.studio/
2. Summary
ProofPocket helps you store purchase documents, track warranties, and receive reminders.
Your archive is stored locally on your device by default. Some data is processed by our service providers when you use specific online features:
- When you scan a receipt, the app may send recognized OCR text and related structured data to our Supabase Edge Function for AI-assisted normalization, which is provided by Mistral AI, an EU-based provider.
- When you sign in, your archive is synchronized with your account across devices. This includes item details, documents, OCR results, reminder settings, and document images.
- We use RevenueCat to manage subscription entitlements, Firebase Analytics to understand aggregate product usage, Firebase Crashlytics to diagnose failures, and Firebase Cloud Messaging for optional push notifications.
We do not sell personal data or use it for targeted advertising.
3. Data we process
A. Local archive data
The app stores the following data locally on your device:
- receipt, invoice, warranty-card and other document images;
- OCR text and extracted document information;
- item names, merchants, prices, dates, warranty periods, notes, serial numbers and reminders;
- local app settings.
B. OCR and AI-assisted normalization
The app performs text recognition on device. To improve the structure and quality of extracted receipt information, it may send the recognized text, line items, barcode values, language and currency hints, timestamps, and limited item context to a Supabase Edge Function.
Document images are not sent to the AI-normalization service as part of this request. The OCR text itself may contain personal or purchase-related information that appears on a receipt or invoice. Before sending, the app attempts to remove obvious payment-card and loyalty-card numbers from the recognized text, but cannot guarantee that all such data is removed.
The Edge Function uses Mistral AI (operated by Mistral AI, a company based in Paris, France) to process this data. Mistral AI acts as a data processor for this processing. Data sent through Mistral's API is not used to train Mistral's models and is retained by Mistral for approximately 30 days for abuse-monitoring purposes before deletion. Mistral's La Plateforme processes data in the European Union by default; certain Mistral subprocessors may process data outside the EU, including in the United States, under appropriate transfer safeguards. Mistral's privacy policy is available at https://legal.mistral.ai/terms/privacy-policy.
The app may create an anonymous technical Supabase session for this processing. This is not presented as a ProofPocket account.
C. Special categories of data
Receipts and invoices you scan may occasionally contain information that reveals special categories of data (for example, pharmacy receipts listing medicines). We do not ask for this data and process it only as incidental content of the document you choose to scan, for the purpose of providing the OCR and normalization features. You can choose not to scan such documents.
D. Account and cloud-sync data
If you create or sign in to a ProofPocket account, we process:
- email address;
- display name, where provided by Apple, Google, or you;
- a unique account identifier;
- authentication and session data;
- your synchronized archive, including document metadata, OCR data, reminders, and document images.
After sign-in, synchronization may start automatically and continue after relevant local changes. Document images are stored in a private Supabase Storage bucket and are accessible only to the corresponding account under our access-control rules.
E. Subscription data
Payments are handled by Apple App Store or Google Play. We do not receive your full payment-card details.
RevenueCat processes subscription-related information, including a pseudonymous app user identifier, entitlement status, purchase and renewal information, product identifiers, and device/platform information necessary to manage subscriptions.
F. Usage and diagnostic data
If Firebase is enabled in the released app, Firebase Analytics may process product-interaction data such as app launches, screen views, feature usage, sign-in outcomes, item-management events, and subscription-flow events.
Firebase Crashlytics may process crash reports, stack traces, device and operating-system information, app version, and a pseudonymous user identifier when a user is signed in.
We do not intentionally send receipt or document contents to Analytics or Crashlytics.
G. Notifications
If you grant notification permission and the relevant notification features are active, we may process local reminder settings. For eligible signed-in users, Firebase Cloud Messaging may process a device push token to deliver warranty-related push notifications.
4. Why we process data
We process data to:
- provide document storage, OCR, warranty tracking, reminders, account access, synchronization, and subscription features;
- maintain security, prevent abuse, and troubleshoot failures;
- understand aggregate product usage and improve the app;
- comply with legal obligations.
Where applicable, we rely on performance of a contract, your consent, our legitimate interests in operating and improving the service, or legal obligations.
5. Service providers
We use the following processors or service providers:
- Supabase — authentication, database, Edge Functions, and cloud storage;
- Mistral AI — AI-assisted OCR normalization (EU-based processor; https://legal.mistral.ai/terms/privacy-policy);
- Apple and Google — sign-in and store payments;
- RevenueCat — subscription entitlement management;
- Google Firebase — Analytics, Crashlytics, and Cloud Messaging.
These providers may process data outside your country. Where required, we use appropriate safeguards for international transfers.
6. Retention
- Local archive data remains on your device until you delete it or uninstall the app.
- Synchronized account data is retained until you delete your account, subject to limited backup, security, fraud-prevention, or legal-retention periods.
- AI-normalization request data sent to Mistral AI is retained by Mistral for approximately 30 rolling days for abuse-monitoring purposes and then deleted, and is not used to train Mistral's models. Any transient data handled by the Supabase Edge Function is not persisted by us beyond what is needed to process the request and return a result.
- Analytics, crash, subscription, and push-token data are retained according to the applicable provider configuration and legal requirements.
7. Your choices and rights
You may manage notification permission in device settings, sign out, delete local data, and initiate account deletion in the app.
Depending on your location, you may have rights to access, correct, delete, restrict, or obtain a copy of your personal data, and to object to certain processing. Contact us at kjlabs.studio@gmail.com.
Deleting your account does not cancel an App Store or Google Play subscription. Subscription management is available through the relevant store.
8. Security
We use access controls and encryption in transit. Cloud document storage is private to the relevant account. No system can guarantee absolute security, and you should protect your device and account credentials.
9. Children
ProofPocket is not directed to children under 16, and we do not knowingly collect personal data from children under 16.
10. Changes
We may update this policy when the app or our processing changes. We will publish the current version at https://proofpocket.kjlabs.studio/privacy/.
11. Contact
For privacy questions or requests:
KJLabs Studio
kjlabs.studio@gmail.com