WorkProof

WorkProof Privacy Policy

Version: 2.0 Last updated: September 26, 2026 Effective date: September 26, 2026 Applies to: WorkProof mobile application for Android (Google Play) and iOS (Apple App Store), and the WorkProof cloud sync and purchase-verification services.


At-a-Glance Summary

This summary is for convenience. The full policy below governs.

Question Short answer
Where is my data stored? Primarily on your device in the App's private storage. Uploaded to our servers only if you sign in and enable cloud sync.
Do you sell my data? No. We do not sell personal information for money. See Section 10 for the limited advertising-related sharing on the free tier.
Do you track my location in the background? No. The App has no background location capability. Location is captured only at the instant you tap clock in/out.
Do you use my face for biometrics? No. We never extract facial geometry, create biometric templates, or perform facial recognition. See Section 5.7.
Why are there ads? The free tier is funded by optional rewarded video ads (Google AdMob). You may instead pay per export, or subscribe to Pro to remove all ads.
Can I delete everything? Yes. In the App (Profile → Clear local data / Delete account) or by emailing lxr@goheydot.com. See Section 15.
How do I contact you? lxr@goheydot.com — the single contact address for all privacy matters, including all GDPR, UK GDPR, CCPA/CPRA, and other rights requests.

1. Who We Are

1.1 Data Controller

The data controller responsible for your personal data is:

WorkProof is a work-hour evidence and wage-tracking tool. It helps workers create tamper-evident attendance records — photo, timestamp, and location — for the purpose of protecting their own wage claims, and to calculate wages owed based on those records.

1.2 EU and UK Representation

If you are in the European Economic Area ("EEA"), the controller is 深圳市嘿点数字科技有限公司 (Shenzhen Heidian Digital Technology Co., Ltd.). Where required by Article 27 GDPR, our representative in the European Union is not yet appointed — we will appoint one as required by Article 27 GDPR and update this Policy. Where required by Article 27 UK GDPR, our representative in the United Kingdom is not yet appointed — we will appoint one as required by Article 27 UK GDPR and update this Policy.

1.3 Trader Information (EU Digital Services Act)

For the purposes of the EU Digital Services Act and consumer law, we act as a trader: (unified social credit code 91440300MAKL00C76Q) 深圳市嘿点数字科技有限公司 (Shenzhen Heidian Digital Technology Co., Ltd.), Room 101, Building A, Tower 2, Jindimingfeng Garden, No. 55 Baosha 1st Road, Baolong Community, Baolong Street, Longgang District, Shenzhen, Guangdong, China, contact lxr@goheydot.com. The App is distributed through Google Play and the Apple App Store, which display our trader status on the store listing.

1.4 Data Protection Officer

We are not currently required to appoint a statutory Data Protection Officer. Privacy enquiries are handled by our privacy contact at lxr@goheydot.com.


2. Scope of This Policy

This policy describes how we collect, use, disclose, transfer, retain, and protect personal information when you:

  1. install and use the WorkProof Android app distributed on Google Play;
  2. install and use the WorkProof iOS app distributed on the Apple App Store;
  3. use our backend services (data synchronization, attendance-record verification, and in-app purchase verification); or
  4. interact with our support channels or receive notifications from us.

This policy does not apply to third-party services that have their own privacy policies, including Google (Play Billing, AdMob, Firebase), Apple (App Store, Sign in with Apple, APNs), and any device manufacturer services. We identify each third party we use in Section 10 and link to their policies.

This policy is not a contract. The contract governing your use of the App is our Terms of Service.


3. Definitions


4. How Data Flows in WorkProof (Architecture Overview)

Understanding the architecture makes the rest of this policy easier to read:

   ┌────────────────────────── YOUR DEVICE (authoritative store) ──────────────────────────┐
   │  Camera photo  ──►  watermarking (time + location burned in)                          │
   │  GPS fix       ──►  precise coordinates at the moment of clock in/out                 │
   │  Record        ──►  SHA-256 / MD5 hashes + serial number  ──►  local SQLite database  │
   │  Photos + PDF exports stored in app-private files (unreadable by other apps)           │
   └───────────────────────────────────────────────────────────────────────────────────────┘
                     │                                              │
        (only if you sign in AND enable sync)          (only when you request an export)
                     ▼                                              ▼
   ┌───────────────────────────────┐              ┌──────────────────────────────────────┐
   │  OUR SYNC BACKEND             │              │  DEVICE-LEVEL SERVICES               │
   │  FastAPI service + SQLite     │              │  Google Play Billing / StoreKit (pay)│
   │  Photo files on server storage│              │  AdMob (rewarded ads, free tier only)│
   │  Purchase-token verification  │              │  Firebase Auth / FCM / Crashlytics   │
   └───────────────────────────────┘              └──────────────────────────────────────┘

Two consequences worth stating plainly:


5. Information We Collect

We collect only what the features you use require. Each category below states what we collect, why, whether it is required, and where it goes.

5.1 Core Evidence Data (created by you)

Data element What it is Why we collect it Where it lives
Clock-in/out photos Photos you take inside the App at clock in/out. Watermarked on-device with time and location. May incidentally show your face or bystanders' faces. Evidence that you were physically present at that time Device (always); our servers if Sync is on
Precise GPS coordinates Latitude, longitude, accuracy radius, captured at the instant you clock in/out Evidence that you were at the work site Device; servers if Sync is on
Derived address string Human-readable coordinates string produced on-device Display convenience in the record list Device; servers if Sync is on
Timestamps Clock-in and clock-out times from the device clock Core purpose of the service Device; servers if Sync is on
Tamper-evidence metadata SHA-256 / MD5 digests, previous-record hash, serial number Makes records verifiable and shows whether a record was altered after creation Device; servers if Sync is on
Work context Employer/boss label, work-site label, free-text remarks you type Grouping records for settlement Device; servers if Sync is on
Edit and deletion history Which record was modified or deleted, and when Preserves the integrity of the remaining evidence Device; servers if Sync is on

Required vs. optional. Photo and timestamp are the core of the feature. Location is optional: if you deny location permission, the record is still created but is marked as lacking location evidence, and we tell you honestly that this weakens its evidentiary value. Employer/site labels and remarks are optional. You can use the App at all times in Guest Mode, in which case none of this leaves your device.

No content inspection. We do not scan, classify, or analyze the content of your photos for any purpose other than watermarking on your device. We do not read your device photo gallery; camera photos are taken inside the App only.

5.2 Account Information (only if you choose to sign in)

Signing in is optional; the App is fully usable in Guest Mode. If you sign in:

Sign-in method Data we receive Notes
Google Sign-In (via Firebase Authentication) Google account identifier, display name, email address, profile photo URL We never receive your Google password
Sign in with Apple (via Firebase Authentication) Apple account identifier, name you consent to share, email address (real or Apple private relay) We never receive your Apple ID password
Guest Mode None No account, no uploads

We also process Firebase Authentication user identifiers and session tokens strictly to keep you signed in and to attribute synced records to your account.

5.3 Purchase and Subscription Information

Payments are processed entirely by Google Play Billing (Android) or the Apple App Store (iOS). We never receive, see, or store your card number, bank details, or full payment credentials.

What we receive and store for entitlement verification:

We use this only to confirm that you are entitled to Pro (ad-free, unlimited exports) or to a one-time export credit, to prevent duplicate redemption of the same purchase, to restore purchases on a new device, and to satisfy tax and accounting record-keeping duties.

Payment data is not collected by us at all. Google's and Apple's own privacy policies govern the payment transaction itself.

5.4 Device, Technical, and Diagnostic Information

Data Purpose Where processed
Device model, OS name and version, app version, device language and time zone Compatibility, correct rendering and localization, support Device; crash reports
IP address Delivering API requests, rate limiting, abuse prevention, security Transiently in server logs (retained up to 30 days)
Crash reports and stack traces (Firebase Crashlytics) Diagnosing and fixing crashes Google Firebase (retained per Section 12)
Installation identifier / FCM registration token Delivering push notifications you enabled Google Firebase Cloud Messaging
Advertising identifier (Android Advertising ID / iOS IDFA) Serving and measuring rewarded advertisements on the free tier (Section 5.5) Google AdMob

We do not currently collect behavioural usage analytics. The App does not enable a product-analytics collector. If we enable one in the future, we will update this policy, disclose the provider, and — where required — obtain consent first.

5.5 Advertising Data (Free Tier Only)

The free tier of WorkProof is supported by optional rewarded video advertisements delivered by Google AdMob.

5.6 Location Data — Specific Disclosures

Because location is legally sensitive, we disclose the following in detail:

  1. We collect precise location (exact GPS coordinates) only at the moment you actively clock in or out, with the App in the foreground and your location permission granted.
  2. We do not collect location in the background, we have no background location permission in the App manifest, and we do not track your movements continuously or build location histories beyond the records you create.
  3. We do not use location for advertising, profiling, or sale.
  4. Location permission can be denied. The App remains usable; records will be marked as lacking location evidence.
  5. You may revoke the permission at any time in system settings; future collection stops immediately. Records already created are unaffected unless you delete them.
  6. Location data is not shared with AdMob or any advertising network. Ads are requested without your location.

5.7 Photos, Facial Images, and Biometric Data

5.8 Guest Mode

In Guest Mode: no account information is collected, no Core Evidence Data is uploaded to us, and no advertising identifier is used for ads you do not request. The trade-offs are stated in the App: no cross-device sync, no cloud backup, and purchase restoration is limited to what the app store restores for the same store account and device.

5.9 Information We Do NOT Collect

For transparency, and to align with the Google Play Data Safety declaration, we do not collect, process, or store:

5.10 Sources of Data

We obtain personal data from three sources only: (a) directly from you (records you create, information you type, permissions you grant); (b) from identity providers you choose (Google, Apple); and (c) automatically from your device (technical, diagnostic, and advertising-identifier data as described above). We do not purchase personal data from data brokers, and we do not receive personal data from third-party trackers.


6.1 Purposes

Purpose Data used GDPR / UK GDPR legal basis
Creating, timestamping, watermarking, and storing attendance records Core Evidence Data Performance of a contract (Art. 6(1)(b)); consent for precise location and camera (Art. 6(1)(a))
Calculating hours, wages, advances, and settlements Core Evidence Data, Work Data Performance of a contract (Art. 6(1)(b))
Generating PDF evidence reports and sharing/exporting them at your instruction Core Evidence Data, Work Data Performance of a contract (Art. 6(1)(b))
Optional cloud backup and cross-device synchronization Core Evidence Data, account identifier Performance of a contract / your consent to Sync
Verifying purchases, restoring entitlements, preventing duplicate redemption Purchase information Performance of a contract (Art. 6(1)(b)); legal obligation for tax records (Art. 6(1)(c))
Authenticating you and securing your session Account information, IP address Performance of a contract (Art. 6(1)(b))
Delivering notifications you enabled (clock reminders, sync status) FCM token, notification preferences Consent (Art. 6(1)(a)), withdrawable at any time
Serving and measuring rewarded ads on the free tier Advertising identifier, IP, device/app info Consent (Art. 6(1)(a)) in the EEA/UK/Switzerland; legitimate interests (Art. 6(1)(f)) where non-personalized and permitted elsewhere
Server-side verification of attendance-record hashes Record hash, serial number Performance of a contract; legitimate interests in maintaining integrity of the service
Diagnosing crashes and improving stability Crash reports, device info Legitimate interests (Art. 6(1)(f))
Preventing fraud, abuse, and unauthorized access; rate limiting IP address, purchase information, request metadata Legitimate interests (Art. 6(1)(f))
Responding to legal process, and establishing or defending legal claims Relevant records Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f))
Complying with accounting, tax, and consumer-protection law Purchase records Legal obligation (Art. 6(1)(c))

6.2 No Automated Decision-Making About You

We do not use your personal data for automated decision-making that produces legal effects or similarly significantly affects you, within the meaning of Article 22 GDPR. Wage calculations are deterministic arithmetic on the numbers you enter; they are not profiling. We do not score you, and we do not make decisions about your employment — we are not your employer.

6.3 Marketing

We do not send marketing email or push notifications. Notifications you enable are functional (for example, a reminder to clock out). If we ever introduce promotional messaging, we will obtain prior consent where required and provide a one-tap unsubscribe.


Permission When requested Purpose How to withdraw Consequence of withdrawal
Camera On first clock-in attempt Capture the evidence photo System Settings → Apps → WorkProof → Permissions → Camera Cannot capture evidence photos; the App's core flow is unavailable
Precise location On first clock-in attempt Bind the record to a place System Settings → Apps → WorkProof → Permissions → Location → Deny Records are created without location evidence
Notifications When you enable reminders Clock-in/out reminders, sync notices System Settings → Apps → WorkProof → Notifications No reminders; no other impact
Advertising ID / tracking (iOS ATT) On first ad request on the free tier Rewarded advertising System Settings (Android: Ads → Delete advertising ID; iOS: Tracking) or our in-app ad-consent settings Ads become non-personalized or unavailable; other features unaffected
Cloud Sync In-App toggle (signed-in users) Server backup and multi-device use Toggle off in App settings New records stay device-only; previously synced data remains until deleted
Sign-in Your action Sync, cross-device use, purchase restore Sign out in the App, or delete your account Sync stops; local data remains on device until you delete it

Withdrawing consent does not affect the lawfulness of processing performed before withdrawal. Where processing is based on a contract rather than consent (for example, purchase verification), a request for erasure is handled under Section 14, subject to our legal retention obligations.


8. Guest Mode, Sync, and Your Choices at a Glance

You want What to do
Use the App with zero data leaving the phone Stay in Guest Mode; never enable Sync
Keep data on device but get crash fixes Sign in optional; crash reporting uses device-level identifiers only
Back up to our servers Sign in and enable Sync
Stop all server-side processing Turn Sync off; request deletion (Section 15)
Remove ads entirely Subscribe to Pro
Never see personalized ads Decline ad consent where prompted, or disable the advertising ID in system settings
Exit everything Delete account in-App, then uninstall. If you never enabled Sync, we hold nothing.

9. In-App Purchases and Advertising: Data-Side Details

This section explains the data aspects of monetization. Your contractual rights and obligations (pricing, renewal, refunds) are in the Terms of Service, Sections 6 and 7.


10. How We Share Information

10.1 Service Providers (Processors)

We share personal data only with the providers below, each bound by a data-processing agreement and permitted to process the data solely on our instructions:

Provider Service Personal data involved Location of processing
Google LLC — Firebase Authentication Sign-in Account identifier, email, display name United States and other Google regions
Google LLC — Firebase Cloud Messaging Push notifications FCM token, delivery metadata United States and other Google regions
Google LLC — Firebase Crashlytics Crash diagnostics Device model, OS version, app version, stack traces United States and other Google regions
Google LLC — Google Play Billing and Play Developer API Payment processing and server-side entitlement verification Purchase token, order ID, product ID, purchase state United States and other Google regions
Google LLC — Google AdMob Rewarded advertising (free tier) Advertising identifier, IP address, device/app information, ad events United States and other Google regions
Apple Inc. — App Store / StoreKit / APNs / Sign in with Apple iOS distribution, payment, push, sign-in Purchase tokens, device token, Apple account identifier and relay email United States and other Apple regions
Cloudflare, Inc. Cloud hosting of the sync backend and server-side photo storage Core Evidence Data that you chose to sync, IP address Cloudflare's global edge network (content served from data centres worldwide)

If we add or replace a processor that materially affects your data, we will update this policy before the change takes effect.

Note for Google Play reviewers and users: the App includes no advertising SDK other than Google AdMob, and no analytics SDK is active. There are no third-party trackers or data brokers in the App.

We may disclose personal data when we believe in good faith that disclosure is required by law, regulation, legal process, or governmental request; to enforce our Terms of Service; to detect, prevent, or address fraud, security, or technical issues; to protect our rights, property, or safety, and those of our users or the public; or to establish, exercise, or defend legal claims. Where legally permitted, we will notify you of such a request and seek to narrow its scope.

10.3 Sale, Sharing, and Cross-Context Behavioral Advertising

10.4 Business Transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy, and the acquiring entity will remain bound by the commitments made here unless you consent otherwise.

10.5 Aggregated and De-Identified Data

We may create aggregated or de-identified statistics (for example, total records verified) that cannot reasonably be used to identify you. We do not attempt to re-identify de-identified data, and we contractually prohibit recipients from doing so.


11. International Data Transfers

Our service providers process data globally. If you are in the EEA, the UK, or Switzerland, transfers of your personal data outside those regions are protected by:

You may request a copy of the relevant safeguards by emailing lxr@goheydot.com. Where you use the App in Guest Mode and never enable Sync, no international transfer of your Core Evidence Data occurs at all — the data stays on your device.

Server location. Synced records and server-side photo storage are hosted in Cloudflare's global edge network (content served from data centres worldwide). Backups, if any, remain within Cloudflare's global edge network.


12. Data Retention

Data Retention period Basis
Core Evidence Data on your device Until you delete the record, clear local data, or uninstall the App You control it
Core Evidence Data synced to our servers Deleted within 30 days of your deletion request or account deletion; incidental backups purged within 90 days Contract, then erasure
Server-side photos Deleted with the corresponding record, on the same schedule Same
Account identifiers (sign-in) Until account deletion, then within 30 days Contract
Purchase-token verification records Up to 7 years from the transaction, in minimized form (token, product, date, result) Tax, accounting, and fraud-prevention legal obligations
Crash reports and stack traces 90 days, per Crashlytics configuration Legitimate interests
Server access logs including IP 30 days, then deleted or anonymized Security and abuse prevention
Push notification tokens Until you disable notifications, sign out, or the App is uninstalled Consent
Support correspondence 24 months from last contact Legitimate interests
Advertising-related data held by AdMob Governed by Google's retention settings and its own privacy policy Google's controller obligations

Evidentiary integrity caveat, stated honestly: when you delete a record, the deletion event itself (which record, when) may be retained in the integrity log so that your remaining records can still be verified as unaltered. The deleted photo and its content are not recoverable.

When retention periods expire, we delete or irreversibly anonymize the data.


13. How We Protect Your Data

No system is perfectly secure. If you believe your data has been compromised, contact lxr@goheydot.com immediately.


14. Your Privacy Rights

14.1 EEA, UK, and Switzerland (GDPR / UK GDPR)

You have the right to:

  1. Access — obtain confirmation of whether we process your personal data, and a copy of it;
  2. Rectification — have inaccurate or incomplete data corrected;
  3. Erasure — have your data deleted, subject to legal retention obligations (for example, purchase records required by tax law);
  4. Restriction — restrict processing while a dispute about accuracy or lawfulness is resolved;
  5. Portability — receive your records in a structured, commonly used, machine-readable format (we provide JSON/CSV export plus your photo files), and to transmit them to another controller where technically feasible;
  6. Object — object to processing based on legitimate interests, including crash diagnostics and abuse-prevention logging;
  7. Withdraw consent — at any time, for consent-based processing (location, camera, notifications, sync, advertising);
  8. Not be subject to automated decisions — see Section 6.2;
  9. Lodge a complaint with a supervisory authority — for example the ICO in the UK, or your national data protection authority in the EEA. We would appreciate the chance to resolve your concern first.

14.2 California (CCPA / CPRA)

California residents have the right to:

  1. Know / access the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties to whom we disclosed it;
  2. Delete personal information we hold, subject to statutory exceptions;
  3. Correct inaccurate personal information;
  4. Opt out of sale or sharing — we do not sell; for the limited advertising-related sharing described in Section 10.3, use the opt-out methods listed there;
  5. Limit the use and disclosure of sensitive personal information — we use precise geolocation only to deliver the feature you requested, and you may withdraw consent at any time;
  6. Non-discrimination — we will not deny service, charge different prices, or provide a lower quality of service because you exercised a privacy right. Note that choosing not to watch ads or not to purchase does change which features are available; those are product tiers, not retaliation;
  7. Data portability — receive your information in a readily usable format.

The categories of personal information we have collected in the preceding 12 months are those listed in Section 5; the business purposes are those listed in Section 6; the categories of recipients are those listed in Section 10.

14.3 Other U.S. State Privacy Laws

Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Kentucky, Maryland, Minnesota, Rhode Island, and other states with comprehensive privacy legislation may exercise rights of access, correction, deletion, portability, and opt-out of targeted advertising and sale through the same channels described here. Where a state provides a right to appeal our decision, you may appeal by replying to our decision email with the subject line "Privacy Appeal"; we will respond in writing within the statutory period.

14.4 Brazil (LGPD), Canada (PIPEDA), Australia, Japan, Korea

Users in other jurisdictions may exercise equivalent rights of confirmation, access, correction, anonymization, portability, deletion, and objection. Canadian users may contact us regarding our handling under PIPEDA; Australian users may contact us regarding the Australian Privacy Principles; Japanese users may request disclosure of retained personal data under the APPI; Korean users may exercise rights under PIPA. Our single contact address for all such requests is lxr@goheydot.com.

14.5 How to Exercise Your Rights

14.6 In-App Self-Service (fastest route)

14.7 Platform-Level Deletion

Google Play and the Apple App Store provide account-deletion request routes from the store listing or from the platform privacy controls. Requests submitted there reach the same processing queue described above.


15. How to Delete Your Data (Step by Step)

  1. On device. Open the App → Profile → Clear local data to erase all local records and photos. Uninstalling the App also deletes local data.
  2. Server-side. If you enabled Sync: Profile → Delete account. This deletes your account identifier and triggers deletion of synced records and photos within 30 days (backups within 90 days).
  3. By email. Send a deletion request to lxr@goheydot.com from your registered email address, or include record serial numbers if you are a Guest Mode user. We will confirm in writing once deletion is complete.
  4. What we keep. We retain minimized purchase-verification records for tax and accounting purposes (Section 12), and we may retain limited information necessary to comply with law, resolve disputes, and prevent fraud. Anything we retain is kept to the minimum required and is not used for any other purpose.
  5. Timeline. We acknowledge requests promptly and complete deletion within 30 days (or 45 days where a state law permits an extension, with notice).

16. Children's Privacy


17. Do Not Track, Global Privacy Control, and Cookies


The App links to external pages — for example, our privacy policy and terms on workproof.app, and store pages for payment management — and to the App Store or Play Store for purchases. Those destinations are governed by their own privacy policies. We are not responsible for the privacy practices of third-party sites and services, and we encourage you to read their policies.

Third-party privacy policies relevant to your use of WorkProof:


19. Changes to This Policy

We may update this policy to reflect changes in our practices, technology, or the law.

If you do not agree with a revised policy, you may stop using the App, delete your data, and — where applicable — cancel your subscription.


20. How to Contact Us

For every privacy matter, including all rights requests, complaints, and questions:

If you are not satisfied with our response, you may complain to your local supervisory authority. In the EU/EEA this is your national data protection authority; in the UK, the Information Commissioner's Office (ico.org.uk); in California, the California Privacy Protection Agency; in Brazil, the ANPD; in Australia, the OAIC; in Canada, the Office of the Privacy Commissioner.


Appendix A — Google Play Data Safety Declaration Mapping

Use this table to complete the Data safety form in Google Play Console. It reflects what the App actually does.

Data type (Play taxonomy) Collected Shared Required or optional Purposes Encrypted in transit Deletion available
Photos (user-generated) Yes — clock-in photos With service providers only if Sync enabled (no ad networks) Optional (feature-driven) App functionality Yes Yes — in-app or by request
Precise location Yes — at clock-in/out only No Optional (user may deny) App functionality Yes Yes
Name Yes (from Google/Apple sign-in) No Optional (Guest Mode available) Account management, app functionality Yes Yes
Email address Yes (from sign-in) No Optional Account management Yes Yes
User IDs Yes (Firebase UID, Google/Apple account ID) No Optional Account management, fraud prevention Yes Yes
Other user-generated content (work records, wage config, remarks) Yes No Optional App functionality Yes Yes
Purchase history Yes (product, token, order ID, state) With Google/Apple as processors Required for purchases App functionality, fraud prevention, accounting Yes Minimized retention; deletion on request subject to tax law
App interactions (ad events) Handled by AdMob With Google (advertising) Optional (free tier) Advertising Yes Via Google; opt-out available
Device or other IDs (advertising ID) Yes (AdMob, free tier) With Google (advertising) Optional Advertising Yes Yes — reset/delete in device settings
Diagnostics / crash logs Yes (Crashlytics) With Google (processor) Optional Analytics (stability), app functionality Yes Yes — 90-day retention
Device model, OS version, app version Yes With processors Required for operation App functionality, analytics Yes Via crash-log retention

Declarations that are "No": health and fitness; financial info beyond the purchase token (no card data at all); messages; contacts; calendar; audio files; files and documents (except the PDF you generate locally and share by your own action); web browsing history; installed apps; race/ethnicity, religion, sexual orientation, political beliefs (never collected); background location (not collected).

Security practices to declare: data is encrypted in transit; users can request data deletion; a data-deletion mechanism is provided in-app and by email; the app does not target children; independent security review: [YES/NO — state truthfully]. If a data-deletion URL is requested, use https://workproof.app/delete-account.


Appendix B — Permission-to-Purpose Map

Permission Purpose Trigger Data leaving device
CAMERA Capture the clock-in/out evidence photo User taps shutter Only if Sync is on
ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION Bind record to a place User taps clock in/out Only if Sync is on
INTERNET / ACCESS_NETWORK_STATE Sync, purchase verification, ad delivery Sync, purchase, ad request Yes, as described in Section 10
POST_NOTIFICATIONS Reminders and sync notices User enables reminders No — token only
AD_ID Rewarded advertising on the free tier User requests an ad Advertising ID to AdMob
Background location Not requested — the App has no background location capability — —
Storage / media library Not requested — the App never reads your gallery — —

Appendix C — Sub-Processors and Processing Locations

Sub-processor Role Processing location Safeguard for international transfers
Google LLC (Firebase, Play, AdMob) Authentication, messaging, crash diagnostics, payments, advertising United States, EU, and other Google regions EU SCCs; EU–U.S. Data Privacy Framework where certified
Apple Inc. iOS payments, push, sign-in United States and other Apple regions EU SCCs; adequacy where applicable
Cloudflare, Inc. Sync backend and photo storage Cloudflare's global edge network (content served from data centres worldwide) Standard Contractual Clauses (SCCs)

We will publish an updated list at least 30 days before adding a new sub-processor that processes Core Evidence Data, and you may object by contacting us.


Appendix D — Glossary


Appendix E — Version History

Version Date Changes
1.0 August 18, 2026 First published policy (pre-monetization).
2.0 September 26, 2026 Added advertising (Google AdMob) disclosures and advertising-identifier processing; expanded purchase and subscription data disclosures including consumable export credits; added EU/UK advertising consent (UMP), CCPA/CPRA advertising opt-out, and Global Privacy Control statements; added trader information under the EU Digital Services Act; added data-deletion URL and step-by-step deletion section; expanded retention, sub-processor, and international-transfer tables; added Google Play Data Safety mapping (Appendix A), permission-to-purpose map (Appendix B), and glossary; clarified that no behavioural analytics SDK is active; clarified biometric non-collection in light of BIPA/COTA/MHMDA.

© 2026 深圳市嘿点数字科技有限公司 (Shenzhen Heidian Digital Technology Co., Ltd.). All rights reserved. WorkProof is a trademark of 深圳市嘿点数字科技有限公司 (Shenzhen Heidian Digital Technology Co., Ltd.).