WorkProof Privacy Policy
Version: 2.0 Last updated: September 26, 2026 Effective date: September 26, 2026 Applies to: WorkProof mobile application for Android (Google Play) and iOS (Apple App Store), and the WorkProof cloud sync and purchase-verification services.
At-a-Glance Summary
This summary is for convenience. The full policy below governs.
| Question | Short answer |
|---|---|
| Where is my data stored? | Primarily on your device in the App's private storage. Uploaded to our servers only if you sign in and enable cloud sync. |
| Do you sell my data? | No. We do not sell personal information for money. See Section 10 for the limited advertising-related sharing on the free tier. |
| Do you track my location in the background? | No. The App has no background location capability. Location is captured only at the instant you tap clock in/out. |
| Do you use my face for biometrics? | No. We never extract facial geometry, create biometric templates, or perform facial recognition. See Section 5.7. |
| Why are there ads? | The free tier is funded by optional rewarded video ads (Google AdMob). You may instead pay per export, or subscribe to Pro to remove all ads. |
| Can I delete everything? | Yes. In the App (Profile → Clear local data / Delete account) or by emailing lxr@goheydot.com. See Section 15. |
| How do I contact you? | lxr@goheydot.com — the single contact address for all privacy matters, including all GDPR, UK GDPR, CCPA/CPRA, and other rights requests. |
1. Who We Are
1.1 Data Controller
The data controller responsible for your personal data is:
- Legal entity: 深圳市嘿点数字科技有限公司 (Shenzhen Heidian Digital Technology Co., Ltd.)
- Registered address: Room 101, Building A, Tower 2, Jindimingfeng Garden, No. 55 Baosha 1st Road, Baolong Community, Baolong Street, Longgang District, Shenzhen, Guangdong, China
- Product name: WorkProof
- Contact email (all purposes, including data protection): lxr@goheydot.com
- Website: https://workproof.app
WorkProof is a work-hour evidence and wage-tracking tool. It helps workers create tamper-evident attendance records — photo, timestamp, and location — for the purpose of protecting their own wage claims, and to calculate wages owed based on those records.
1.2 EU and UK Representation
If you are in the European Economic Area ("EEA"), the controller is 深圳市嘿点数字科技有限公司 (Shenzhen Heidian Digital Technology Co., Ltd.). Where required by Article 27 GDPR, our representative in the European Union is not yet appointed — we will appoint one as required by Article 27 GDPR and update this Policy. Where required by Article 27 UK GDPR, our representative in the United Kingdom is not yet appointed — we will appoint one as required by Article 27 UK GDPR and update this Policy.
1.3 Trader Information (EU Digital Services Act)
For the purposes of the EU Digital Services Act and consumer law, we act as a trader: (unified social credit code 91440300MAKL00C76Q) 深圳市嘿点数字科技有限公司 (Shenzhen Heidian Digital Technology Co., Ltd.), Room 101, Building A, Tower 2, Jindimingfeng Garden, No. 55 Baosha 1st Road, Baolong Community, Baolong Street, Longgang District, Shenzhen, Guangdong, China, contact lxr@goheydot.com. The App is distributed through Google Play and the Apple App Store, which display our trader status on the store listing.
1.4 Data Protection Officer
We are not currently required to appoint a statutory Data Protection Officer. Privacy enquiries are handled by our privacy contact at lxr@goheydot.com.
2. Scope of This Policy
This policy describes how we collect, use, disclose, transfer, retain, and protect personal information when you:
- install and use the WorkProof Android app distributed on Google Play;
- install and use the WorkProof iOS app distributed on the Apple App Store;
- use our backend services (data synchronization, attendance-record verification, and in-app purchase verification); or
- interact with our support channels or receive notifications from us.
This policy does not apply to third-party services that have their own privacy policies, including Google (Play Billing, AdMob, Firebase), Apple (App Store, Sign in with Apple, APNs), and any device manufacturer services. We identify each third party we use in Section 10 and link to their policies.
This policy is not a contract. The contract governing your use of the App is our Terms of Service.
3. Definitions
- "App" — the WorkProof mobile application.
- "Core Evidence Data" — the attendance records you create: photos, timestamps, GPS coordinates, work-site and employer labels, notes, hashes, and serial numbers.
- "Work Data" — wage configuration, advance-payment records, settlements, and calculated wage figures.
- "Guest Mode" — use of the App without signing in to any account.
- "Sync" — the optional, user-enabled upload of records to our servers.
- "Pro" — the paid annual subscription that removes advertising and unlocks unlimited PDF exports.
- "Personal data" / "personal information" — information relating to an identified or identifiable natural person, or as defined by applicable law.
- "Processing" — any operation performed on personal data, as defined in Article 4 GDPR.
4. How Data Flows in WorkProof (Architecture Overview)
Understanding the architecture makes the rest of this policy easier to read:
┌────────────────────────── YOUR DEVICE (authoritative store) ──────────────────────────┐
│ Camera photo ──► watermarking (time + location burned in) │
│ GPS fix ──► precise coordinates at the moment of clock in/out │
│ Record ──► SHA-256 / MD5 hashes + serial number ──► local SQLite database │
│ Photos + PDF exports stored in app-private files (unreadable by other apps) │
└───────────────────────────────────────────────────────────────────────────────────────┘
│ │
(only if you sign in AND enable sync) (only when you request an export)
▼ ▼
┌───────────────────────────────┐ ┌──────────────────────────────────────┐
│ OUR SYNC BACKEND │ │ DEVICE-LEVEL SERVICES │
│ FastAPI service + SQLite │ │ Google Play Billing / StoreKit (pay)│
│ Photo files on server storage│ │ AdMob (rewarded ads, free tier only)│
│ Purchase-token verification │ │ Firebase Auth / FCM / Crashlytics │
└───────────────────────────────┘ └──────────────────────────────────────┘
Two consequences worth stating plainly:
- If you use Guest Mode, no Core Evidence Data ever leaves your device.
- Deleting the App removes all local data. If you never enabled Sync, that is the end of it — we hold nothing.
5. Information We Collect
We collect only what the features you use require. Each category below states what we collect, why, whether it is required, and where it goes.
5.1 Core Evidence Data (created by you)
| Data element | What it is | Why we collect it | Where it lives |
|---|---|---|---|
| Clock-in/out photos | Photos you take inside the App at clock in/out. Watermarked on-device with time and location. May incidentally show your face or bystanders' faces. | Evidence that you were physically present at that time | Device (always); our servers if Sync is on |
| Precise GPS coordinates | Latitude, longitude, accuracy radius, captured at the instant you clock in/out | Evidence that you were at the work site | Device; servers if Sync is on |
| Derived address string | Human-readable coordinates string produced on-device | Display convenience in the record list | Device; servers if Sync is on |
| Timestamps | Clock-in and clock-out times from the device clock | Core purpose of the service | Device; servers if Sync is on |
| Tamper-evidence metadata | SHA-256 / MD5 digests, previous-record hash, serial number | Makes records verifiable and shows whether a record was altered after creation | Device; servers if Sync is on |
| Work context | Employer/boss label, work-site label, free-text remarks you type | Grouping records for settlement | Device; servers if Sync is on |
| Edit and deletion history | Which record was modified or deleted, and when | Preserves the integrity of the remaining evidence | Device; servers if Sync is on |
Required vs. optional. Photo and timestamp are the core of the feature. Location is optional: if you deny location permission, the record is still created but is marked as lacking location evidence, and we tell you honestly that this weakens its evidentiary value. Employer/site labels and remarks are optional. You can use the App at all times in Guest Mode, in which case none of this leaves your device.
No content inspection. We do not scan, classify, or analyze the content of your photos for any purpose other than watermarking on your device. We do not read your device photo gallery; camera photos are taken inside the App only.
5.2 Account Information (only if you choose to sign in)
Signing in is optional; the App is fully usable in Guest Mode. If you sign in:
| Sign-in method | Data we receive | Notes |
|---|---|---|
| Google Sign-In (via Firebase Authentication) | Google account identifier, display name, email address, profile photo URL | We never receive your Google password |
| Sign in with Apple (via Firebase Authentication) | Apple account identifier, name you consent to share, email address (real or Apple private relay) | We never receive your Apple ID password |
| Guest Mode | None | No account, no uploads |
We also process Firebase Authentication user identifiers and session tokens strictly to keep you signed in and to attribute synced records to your account.
5.3 Purchase and Subscription Information
Payments are processed entirely by Google Play Billing (Android) or the Apple App Store (iOS). We never receive, see, or store your card number, bank details, or full payment credentials.
What we receive and store for entitlement verification:
- product identifier (for example
pro_access_annualorpdf_export_single); - purchase token and order identifier issued by Google or Apple;
- purchase state (purchased, pending, cancelled) and, for subscriptions, expiry timestamp;
- the verification timestamp and result.
We use this only to confirm that you are entitled to Pro (ad-free, unlimited exports) or to a one-time export credit, to prevent duplicate redemption of the same purchase, to restore purchases on a new device, and to satisfy tax and accounting record-keeping duties.
Payment data is not collected by us at all. Google's and Apple's own privacy policies govern the payment transaction itself.
5.4 Device, Technical, and Diagnostic Information
| Data | Purpose | Where processed |
|---|---|---|
| Device model, OS name and version, app version, device language and time zone | Compatibility, correct rendering and localization, support | Device; crash reports |
| IP address | Delivering API requests, rate limiting, abuse prevention, security | Transiently in server logs (retained up to 30 days) |
| Crash reports and stack traces (Firebase Crashlytics) | Diagnosing and fixing crashes | Google Firebase (retained per Section 12) |
| Installation identifier / FCM registration token | Delivering push notifications you enabled | Google Firebase Cloud Messaging |
| Advertising identifier (Android Advertising ID / iOS IDFA) | Serving and measuring rewarded advertisements on the free tier (Section 5.5) | Google AdMob |
We do not currently collect behavioural usage analytics. The App does not enable a product-analytics collector. If we enable one in the future, we will update this policy, disclose the provider, and — where required — obtain consent first.
5.5 Advertising Data (Free Tier Only)
The free tier of WorkProof is supported by optional rewarded video advertisements delivered by Google AdMob.
- When ads appear: only when a free-tier user taps Export PDF and voluntarily selects "Watch a short ad to export free". Pro subscribers never see ads anywhere in the App.
- What AdMob may process: advertising identifier or app-set identifier, IP address, coarse device and app information, and ad interaction events (impression, click, completion). This processing is carried out by Google as an independent controller for its own advertising purposes.
- What we receive: aggregate revenue and performance reporting from AdMob. We do not receive a profile of you, and we do not build advertising profiles.
- Consent in the EEA, UK, and Switzerland: before any ad is requested in those regions, we present a consent dialog powered by Google's User Messaging Platform. If you refuse consent, ads are requested in non-personalized form only, or no ad is requested at all. You can revisit your consent choice from the App's settings.
- United States: you may opt out of personalized advertising through your device settings (Android: Settings → Privacy → Ads → Delete advertising ID or Opt out of Ads Personalization; iOS: Settings → Privacy & Security → Tracking) or by contacting us. See Section 10.3 for how this interacts with California law.
- No ads to children: the App is not directed to children (Section 16), and we do not knowingly serve personalized advertising to children.
5.6 Location Data — Specific Disclosures
Because location is legally sensitive, we disclose the following in detail:
- We collect precise location (exact GPS coordinates) only at the moment you actively clock in or out, with the App in the foreground and your location permission granted.
- We do not collect location in the background, we have no background location permission in the App manifest, and we do not track your movements continuously or build location histories beyond the records you create.
- We do not use location for advertising, profiling, or sale.
- Location permission can be denied. The App remains usable; records will be marked as lacking location evidence.
- You may revoke the permission at any time in system settings; future collection stops immediately. Records already created are unaffected unless you delete them.
- Location data is not shared with AdMob or any advertising network. Ads are requested without your location.
5.7 Photos, Facial Images, and Biometric Data
- Clock-in photos are taken to document presence. They may incidentally contain faces — yours, or the faces of other people in the frame.
- We do not perform facial recognition, face matching, facial geometry measurement, biometric template extraction, emotion detection, or any automated identification of persons. No biometric identifier or biometric information, as those terms are defined by the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (COTA), the Washington My Health My Data Act, GDPR Article 9, or any comparable law, is collected, generated, stored, or shared by WorkProof.
- Photos are processed on-device to burn in a watermark (time, location) and to compute content hashes. These operations are cryptographic and non-biometric.
- If you are subject to a workplace rule about photographing colleagues or premises, complying with that rule is your responsibility (see the Terms of Service, Section 7.3).
5.8 Guest Mode
In Guest Mode: no account information is collected, no Core Evidence Data is uploaded to us, and no advertising identifier is used for ads you do not request. The trade-offs are stated in the App: no cross-device sync, no cloud backup, and purchase restoration is limited to what the app store restores for the same store account and device.
5.9 Information We Do NOT Collect
For transparency, and to align with the Google Play Data Safety declaration, we do not collect, process, or store:
- Passwords of any kind (authentication is delegated to Google and Apple);
- Credit card, debit card, or bank account numbers;
- Government identifiers: national ID numbers, Social Security numbers, passport numbers, driver's licence numbers;
- Health data, genetic data, or data revealing racial or ethnic origin, religious beliefs, trade-union membership, political opinions, sex life, or sexual orientation (GDPR Article 9 special categories);
- Contacts, address book, call logs, SMS or MMS content;
- Your device photo library, videos, or files outside the App sandbox;
- Background or continuous location, or movement/motion sensor history;
- Browsing history, or data from other apps;
- Keystroke logging, clipboard content, or microphone/screen recordings;
- Advertising data from networks other than AdMob;
- Usage analytics (not currently enabled).
5.10 Sources of Data
We obtain personal data from three sources only: (a) directly from you (records you create, information you type, permissions you grant); (b) from identity providers you choose (Google, Apple); and (c) automatically from your device (technical, diagnostic, and advertising-identifier data as described above). We do not purchase personal data from data brokers, and we do not receive personal data from third-party trackers.
6. How We Use Your Information, and Our Legal Bases
6.1 Purposes
| Purpose | Data used | GDPR / UK GDPR legal basis |
|---|---|---|
| Creating, timestamping, watermarking, and storing attendance records | Core Evidence Data | Performance of a contract (Art. 6(1)(b)); consent for precise location and camera (Art. 6(1)(a)) |
| Calculating hours, wages, advances, and settlements | Core Evidence Data, Work Data | Performance of a contract (Art. 6(1)(b)) |
| Generating PDF evidence reports and sharing/exporting them at your instruction | Core Evidence Data, Work Data | Performance of a contract (Art. 6(1)(b)) |
| Optional cloud backup and cross-device synchronization | Core Evidence Data, account identifier | Performance of a contract / your consent to Sync |
| Verifying purchases, restoring entitlements, preventing duplicate redemption | Purchase information | Performance of a contract (Art. 6(1)(b)); legal obligation for tax records (Art. 6(1)(c)) |
| Authenticating you and securing your session | Account information, IP address | Performance of a contract (Art. 6(1)(b)) |
| Delivering notifications you enabled (clock reminders, sync status) | FCM token, notification preferences | Consent (Art. 6(1)(a)), withdrawable at any time |
| Serving and measuring rewarded ads on the free tier | Advertising identifier, IP, device/app info | Consent (Art. 6(1)(a)) in the EEA/UK/Switzerland; legitimate interests (Art. 6(1)(f)) where non-personalized and permitted elsewhere |
| Server-side verification of attendance-record hashes | Record hash, serial number | Performance of a contract; legitimate interests in maintaining integrity of the service |
| Diagnosing crashes and improving stability | Crash reports, device info | Legitimate interests (Art. 6(1)(f)) |
| Preventing fraud, abuse, and unauthorized access; rate limiting | IP address, purchase information, request metadata | Legitimate interests (Art. 6(1)(f)) |
| Responding to legal process, and establishing or defending legal claims | Relevant records | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
| Complying with accounting, tax, and consumer-protection law | Purchase records | Legal obligation (Art. 6(1)(c)) |
6.2 No Automated Decision-Making About You
We do not use your personal data for automated decision-making that produces legal effects or similarly significantly affects you, within the meaning of Article 22 GDPR. Wage calculations are deterministic arithmetic on the numbers you enter; they are not profiling. We do not score you, and we do not make decisions about your employment — we are not your employer.
6.3 Marketing
We do not send marketing email or push notifications. Notifications you enable are functional (for example, a reminder to clock out). If we ever introduce promotional messaging, we will obtain prior consent where required and provide a one-tap unsubscribe.
7. Permissions We Request, and How to Withdraw Consent
| Permission | When requested | Purpose | How to withdraw | Consequence of withdrawal |
|---|---|---|---|---|
| Camera | On first clock-in attempt | Capture the evidence photo | System Settings → Apps → WorkProof → Permissions → Camera | Cannot capture evidence photos; the App's core flow is unavailable |
| Precise location | On first clock-in attempt | Bind the record to a place | System Settings → Apps → WorkProof → Permissions → Location → Deny | Records are created without location evidence |
| Notifications | When you enable reminders | Clock-in/out reminders, sync notices | System Settings → Apps → WorkProof → Notifications | No reminders; no other impact |
| Advertising ID / tracking (iOS ATT) | On first ad request on the free tier | Rewarded advertising | System Settings (Android: Ads → Delete advertising ID; iOS: Tracking) or our in-app ad-consent settings | Ads become non-personalized or unavailable; other features unaffected |
| Cloud Sync | In-App toggle (signed-in users) | Server backup and multi-device use | Toggle off in App settings | New records stay device-only; previously synced data remains until deleted |
| Sign-in | Your action | Sync, cross-device use, purchase restore | Sign out in the App, or delete your account | Sync stops; local data remains on device until you delete it |
Withdrawing consent does not affect the lawfulness of processing performed before withdrawal. Where processing is based on a contract rather than consent (for example, purchase verification), a request for erasure is handled under Section 14, subject to our legal retention obligations.
8. Guest Mode, Sync, and Your Choices at a Glance
| You want | What to do |
|---|---|
| Use the App with zero data leaving the phone | Stay in Guest Mode; never enable Sync |
| Keep data on device but get crash fixes | Sign in optional; crash reporting uses device-level identifiers only |
| Back up to our servers | Sign in and enable Sync |
| Stop all server-side processing | Turn Sync off; request deletion (Section 15) |
| Remove ads entirely | Subscribe to Pro |
| Never see personalized ads | Decline ad consent where prompted, or disable the advertising ID in system settings |
| Exit everything | Delete account in-App, then uninstall. If you never enabled Sync, we hold nothing. |
9. In-App Purchases and Advertising: Data-Side Details
This section explains the data aspects of monetization. Your contractual rights and obligations (pricing, renewal, refunds) are in the Terms of Service, Sections 6 and 7.
- Pro subscription (
pro_access_annual). On purchase we receive a purchase token and order identifier, verify them with the Google Play Developer API or Apple's verification endpoint, store the verification result and expiry, and unlock ad-free unlimited export. When the subscription lapses, the App re-checks entitlement with the store. - Per-export purchase (
pdf_export_single). A consumable product. We verify the purchase, grant exactly one export credit, and mark the token as redeemed so the same purchase can never be redeemed twice. Consumed tokens are retained in minimized form for fraud prevention and accounting. - Restoring purchases. Restoring re-queries the store for active entitlements. Consumable products are not restorable, by store design.
- Rewarded ads. Watching an ad grants one export credit only if the ad network confirms a completed view (
onUserEarnedReward). No credit is granted for skipping, closing early, or a failed ad load. We do not receive your identity from the ad network. - We never sell or share your Core Evidence Data, Work Data, photos, or location with advertisers, and we never serve ads inside your records or PDF reports.
10. How We Share Information
10.1 Service Providers (Processors)
We share personal data only with the providers below, each bound by a data-processing agreement and permitted to process the data solely on our instructions:
| Provider | Service | Personal data involved | Location of processing |
|---|---|---|---|
| Google LLC — Firebase Authentication | Sign-in | Account identifier, email, display name | United States and other Google regions |
| Google LLC — Firebase Cloud Messaging | Push notifications | FCM token, delivery metadata | United States and other Google regions |
| Google LLC — Firebase Crashlytics | Crash diagnostics | Device model, OS version, app version, stack traces | United States and other Google regions |
| Google LLC — Google Play Billing and Play Developer API | Payment processing and server-side entitlement verification | Purchase token, order ID, product ID, purchase state | United States and other Google regions |
| Google LLC — Google AdMob | Rewarded advertising (free tier) | Advertising identifier, IP address, device/app information, ad events | United States and other Google regions |
| Apple Inc. — App Store / StoreKit / APNs / Sign in with Apple | iOS distribution, payment, push, sign-in | Purchase tokens, device token, Apple account identifier and relay email | United States and other Apple regions |
| Cloudflare, Inc. | Cloud hosting of the sync backend and server-side photo storage | Core Evidence Data that you chose to sync, IP address | Cloudflare's global edge network (content served from data centres worldwide) |
If we add or replace a processor that materially affects your data, we will update this policy before the change takes effect.
Note for Google Play reviewers and users: the App includes no advertising SDK other than Google AdMob, and no analytics SDK is active. There are no third-party trackers or data brokers in the App.
10.2 Legal Disclosures
We may disclose personal data when we believe in good faith that disclosure is required by law, regulation, legal process, or governmental request; to enforce our Terms of Service; to detect, prevent, or address fraud, security, or technical issues; to protect our rights, property, or safety, and those of our users or the public; or to establish, exercise, or defend legal claims. Where legally permitted, we will notify you of such a request and seek to narrow its scope.
10.3 Sale, Sharing, and Cross-Context Behavioral Advertising
- We do not sell personal information for monetary or other valuable consideration, as "sale" is defined by the CCPA/CPRA and other U.S. state privacy laws.
- We do not share your Core Evidence Data, Work Data, photos, location, or account information with advertisers.
- Limited advertising disclosure. On the free tier, requesting a rewarded ad involves disclosing your advertising identifier and IP address to Google AdMob. Under the CCPA/CPRA as interpreted by the California Privacy Protection Agency, disclosure of an identifier to an advertising network for cross-context behavioral advertising can constitute "sharing." We therefore provide the opt-out described below, even though we receive no money for your personal information.
- How to opt out of advertising-related sharing: (1) decline the ad-consent prompt where shown; (2) disable or reset the advertising identifier in device settings (Android: Settings → Privacy → Ads; iOS: Settings → Privacy & Security → Tracking); (3) subscribe to Pro, which removes advertising entirely; or (4) email lxr@goheydot.com and we will flag your account as ad-consent-denied.
- We honor the Global Privacy Control (GPC) signal where it is technically applicable to our web properties, and we do not use personal data for cross-context behavioral advertising beyond what is described above.
- Sensitive personal information. Precise geolocation can qualify as sensitive personal information under the CPRA. We use it solely to provide the record-keeping feature you request, we do not use it for inferring characteristics, and you may withdraw location consent at any time. We do not "use or disclose sensitive personal information for purposes other than those permitted by CPRA regulations."
10.4 Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy, and the acquiring entity will remain bound by the commitments made here unless you consent otherwise.
10.5 Aggregated and De-Identified Data
We may create aggregated or de-identified statistics (for example, total records verified) that cannot reasonably be used to identify you. We do not attempt to re-identify de-identified data, and we contractually prohibit recipients from doing so.
11. International Data Transfers
Our service providers process data globally. If you are in the EEA, the UK, or Switzerland, transfers of your personal data outside those regions are protected by:
- European Commission Standard Contractual Clauses (and, for the UK, the International Data Transfer Addendum to the EU SCCs issued by the ICO), incorporated into our agreements with each processor; and/or
- the EU–U.S. Data Privacy Framework and its UK Extension, where the recipient is certified; and/or
- where the destination country has an adequacy decision.
You may request a copy of the relevant safeguards by emailing lxr@goheydot.com. Where you use the App in Guest Mode and never enable Sync, no international transfer of your Core Evidence Data occurs at all — the data stays on your device.
Server location. Synced records and server-side photo storage are hosted in Cloudflare's global edge network (content served from data centres worldwide). Backups, if any, remain within Cloudflare's global edge network.
12. Data Retention
| Data | Retention period | Basis |
|---|---|---|
| Core Evidence Data on your device | Until you delete the record, clear local data, or uninstall the App | You control it |
| Core Evidence Data synced to our servers | Deleted within 30 days of your deletion request or account deletion; incidental backups purged within 90 days | Contract, then erasure |
| Server-side photos | Deleted with the corresponding record, on the same schedule | Same |
| Account identifiers (sign-in) | Until account deletion, then within 30 days | Contract |
| Purchase-token verification records | Up to 7 years from the transaction, in minimized form (token, product, date, result) | Tax, accounting, and fraud-prevention legal obligations |
| Crash reports and stack traces | 90 days, per Crashlytics configuration | Legitimate interests |
| Server access logs including IP | 30 days, then deleted or anonymized | Security and abuse prevention |
| Push notification tokens | Until you disable notifications, sign out, or the App is uninstalled | Consent |
| Support correspondence | 24 months from last contact | Legitimate interests |
| Advertising-related data held by AdMob | Governed by Google's retention settings and its own privacy policy | Google's controller obligations |
Evidentiary integrity caveat, stated honestly: when you delete a record, the deletion event itself (which record, when) may be retained in the integrity log so that your remaining records can still be verified as unaltered. The deleted photo and its content are not recoverable.
When retention periods expire, we delete or irreversibly anonymize the data.
13. How We Protect Your Data
- Local-first design. Your authoritative data store is on your device, in app-private storage that other apps cannot read (Android app sandbox; iOS container with data protection).
- Encryption in transit. All communication with our backend uses HTTPS/TLS. Certificate validation is not disabled in release builds.
- Integrity controls. Every record carries SHA-256 hashes chained to the previous record, plus a unique serial number, so tampering is detectable. PDF exports embed the serial number and hashes for independent verification.
- No stored passwords. Authentication is delegated to Google and Apple; we never handle your credentials.
- Server safeguards. Access-controlled infrastructure, least-privilege staff access (no staff member has routine access to user evidence content), audit logging, and encrypted storage volumes where the hosting provider supports them.
- Secrets handling. API keys, service-account credentials, and signing material are kept outside the application binary and rotated periodically. The server authenticates API requests with a bearer key; production keys are not shipped in the client.
- Rate limiting and abuse prevention on public endpoints.
- Vulnerability management. We monitor dependency advisories and update SDKs; security-relevant updates are prioritized.
- Breach notification. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware, and notify affected users without undue delay where the risk is high, as GDPR Articles 33–34 require. For U.S. state laws, we will notify affected residents and regulators as required by applicable law.
No system is perfectly secure. If you believe your data has been compromised, contact lxr@goheydot.com immediately.
14. Your Privacy Rights
14.1 EEA, UK, and Switzerland (GDPR / UK GDPR)
You have the right to:
- Access — obtain confirmation of whether we process your personal data, and a copy of it;
- Rectification — have inaccurate or incomplete data corrected;
- Erasure — have your data deleted, subject to legal retention obligations (for example, purchase records required by tax law);
- Restriction — restrict processing while a dispute about accuracy or lawfulness is resolved;
- Portability — receive your records in a structured, commonly used, machine-readable format (we provide JSON/CSV export plus your photo files), and to transmit them to another controller where technically feasible;
- Object — object to processing based on legitimate interests, including crash diagnostics and abuse-prevention logging;
- Withdraw consent — at any time, for consent-based processing (location, camera, notifications, sync, advertising);
- Not be subject to automated decisions — see Section 6.2;
- Lodge a complaint with a supervisory authority — for example the ICO in the UK, or your national data protection authority in the EEA. We would appreciate the chance to resolve your concern first.
14.2 California (CCPA / CPRA)
California residents have the right to:
- Know / access the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties to whom we disclosed it;
- Delete personal information we hold, subject to statutory exceptions;
- Correct inaccurate personal information;
- Opt out of sale or sharing — we do not sell; for the limited advertising-related sharing described in Section 10.3, use the opt-out methods listed there;
- Limit the use and disclosure of sensitive personal information — we use precise geolocation only to deliver the feature you requested, and you may withdraw consent at any time;
- Non-discrimination — we will not deny service, charge different prices, or provide a lower quality of service because you exercised a privacy right. Note that choosing not to watch ads or not to purchase does change which features are available; those are product tiers, not retaliation;
- Data portability — receive your information in a readily usable format.
The categories of personal information we have collected in the preceding 12 months are those listed in Section 5; the business purposes are those listed in Section 6; the categories of recipients are those listed in Section 10.
14.3 Other U.S. State Privacy Laws
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), Montana (MCDPA), Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Kentucky, Maryland, Minnesota, Rhode Island, and other states with comprehensive privacy legislation may exercise rights of access, correction, deletion, portability, and opt-out of targeted advertising and sale through the same channels described here. Where a state provides a right to appeal our decision, you may appeal by replying to our decision email with the subject line "Privacy Appeal"; we will respond in writing within the statutory period.
14.4 Brazil (LGPD), Canada (PIPEDA), Australia, Japan, Korea
Users in other jurisdictions may exercise equivalent rights of confirmation, access, correction, anonymization, portability, deletion, and objection. Canadian users may contact us regarding our handling under PIPEDA; Australian users may contact us regarding the Australian Privacy Principles; Japanese users may request disclosure of retained personal data under the APPI; Korean users may exercise rights under PIPA. Our single contact address for all such requests is lxr@goheydot.com.
14.5 How to Exercise Your Rights
- Email: lxr@goheydot.com
- Response time: within 30 days for GDPR requests; within 45 days for CCPA/CPRA requests (extendable once by a further 45 days with notice); within statutory periods elsewhere.
- Verification: we verify your identity using your signed-in account email, or, for Guest Mode users, information sufficient to match specific records (for example, a record serial number and approximate date). We request only what is necessary and do not use verification data for other purposes.
- Authorized agents: may submit requests with signed authorization. We may require the consumer to verify identity directly.
- Fees: none, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse, with reasons.
14.6 In-App Self-Service (fastest route)
- Delete individual records: Record list → long-press the record → Delete.
- Delete all local data: Profile → Clear local data (or uninstall the App).
- Delete account and server data: Profile → Delete account (available when signed in). Server data is purged within 30 days.
- Stop advertising personalization: App settings → ad consent, or system settings for the advertising identifier.
- Export your data: Export to PDF from any record or settlement; contact us for a machine-readable JSON/CSV export.
14.7 Platform-Level Deletion
Google Play and the Apple App Store provide account-deletion request routes from the store listing or from the platform privacy controls. Requests submitted there reach the same processing queue described above.
15. How to Delete Your Data (Step by Step)
- On device. Open the App → Profile → Clear local data to erase all local records and photos. Uninstalling the App also deletes local data.
- Server-side. If you enabled Sync: Profile → Delete account. This deletes your account identifier and triggers deletion of synced records and photos within 30 days (backups within 90 days).
- By email. Send a deletion request to lxr@goheydot.com from your registered email address, or include record serial numbers if you are a Guest Mode user. We will confirm in writing once deletion is complete.
- What we keep. We retain minimized purchase-verification records for tax and accounting purposes (Section 12), and we may retain limited information necessary to comply with law, resolve disputes, and prevent fraud. Anything we retain is kept to the minimum required and is not used for any other purpose.
- Timeline. We acknowledge requests promptly and complete deletion within 30 days (or 45 days where a state law permits an extension, with notice).
16. Children's Privacy
- WorkProof is designed for working adults. It is not directed to children, and we do not knowingly collect personal data from children under 13 (or under 16 in EEA member states that adopted a lower digital age of consent threshold under national law, or the applicable age in your jurisdiction).
- In the Google Play Console and App Store Connect listings we declare the app's target audience as adults (18+). We do not participate in Google Play's "Designed for Families" programme, and the App contains no content intended for children.
- We do not knowingly serve personalized advertising to children, and we do not knowingly process children's personal data for advertising.
- If we learn we have collected personal data from a child, we will delete it promptly. Parents or guardians may contact lxr@goheydot.com, and we will act within 30 days.
- Because the App is a workplace tool, users must be of legal working age in their jurisdiction, which in most jurisdictions means at least 16 and often 18.
17. Do Not Track, Global Privacy Control, and Cookies
- The App does not use cookies and does not include a web browser or web-view tracking layer for advertising.
- The App does not respond to browser "Do Not Track" signals, because it does not operate as a website. Where our website is concerned, we honor the Global Privacy Control opt-out preference signal to the extent required by applicable law.
- Local storage on your device (SQLite database, preferences, cached files) is used to operate the App, not for tracking.
- No third-party tracking technologies are embedded in the App other than the advertising SDK described in Section 5.5.
18. Third-Party Links and Services
The App links to external pages — for example, our privacy policy and terms on workproof.app, and store pages for payment management — and to the App Store or Play Store for purchases. Those destinations are governed by their own privacy policies. We are not responsible for the privacy practices of third-party sites and services, and we encourage you to read their policies.
Third-party privacy policies relevant to your use of WorkProof:
- Google: https://policies.google.com/privacy
- Google Play: https://play.google.com/about/play-terms/
- Google AdMob: https://support.google.com/admob/answer/6128543
- Firebase: https://firebase.google.com/support/privacy
- Apple: https://www.apple.com/legal/privacy/
- Apple App Store: https://www.apple.com/legal/internet-services/itunes/
19. Changes to This Policy
We may update this policy to reflect changes in our practices, technology, or the law.
- Material changes will be communicated in the App (an in-app notice) and, where required, by email to your registered address, before the change takes effect.
- The "Last updated" date at the top always reflects the current version.
- Where a change requires consent under applicable law — for example, a new purpose for location data or a new advertising practice — we will ask for your consent rather than rely on continued use.
- Version history is maintained in Appendix E. Previous versions are available on request.
If you do not agree with a revised policy, you may stop using the App, delete your data, and — where applicable — cancel your subscription.
20. How to Contact Us
For every privacy matter, including all rights requests, complaints, and questions:
- Email: lxr@goheydot.com
- Postal address: Room 101, Building A, Tower 2, Jindimingfeng Garden, No. 55 Baosha 1st Road, Baolong Community, Baolong Street, Longgang District, Shenzhen, Guangdong, China
- Response times: acknowledgement within 5 business days; substantive response within 30 days (GDPR) or 45 days (CCPA/CPRA, extendable with notice).
If you are not satisfied with our response, you may complain to your local supervisory authority. In the EU/EEA this is your national data protection authority; in the UK, the Information Commissioner's Office (ico.org.uk); in California, the California Privacy Protection Agency; in Brazil, the ANPD; in Australia, the OAIC; in Canada, the Office of the Privacy Commissioner.
Appendix A — Google Play Data Safety Declaration Mapping
Use this table to complete the Data safety form in Google Play Console. It reflects what the App actually does.
| Data type (Play taxonomy) | Collected | Shared | Required or optional | Purposes | Encrypted in transit | Deletion available |
|---|---|---|---|---|---|---|
| Photos (user-generated) | Yes — clock-in photos | With service providers only if Sync enabled (no ad networks) | Optional (feature-driven) | App functionality | Yes | Yes — in-app or by request |
| Precise location | Yes — at clock-in/out only | No | Optional (user may deny) | App functionality | Yes | Yes |
| Name | Yes (from Google/Apple sign-in) | No | Optional (Guest Mode available) | Account management, app functionality | Yes | Yes |
| Email address | Yes (from sign-in) | No | Optional | Account management | Yes | Yes |
| User IDs | Yes (Firebase UID, Google/Apple account ID) | No | Optional | Account management, fraud prevention | Yes | Yes |
| Other user-generated content (work records, wage config, remarks) | Yes | No | Optional | App functionality | Yes | Yes |
| Purchase history | Yes (product, token, order ID, state) | With Google/Apple as processors | Required for purchases | App functionality, fraud prevention, accounting | Yes | Minimized retention; deletion on request subject to tax law |
| App interactions (ad events) | Handled by AdMob | With Google (advertising) | Optional (free tier) | Advertising | Yes | Via Google; opt-out available |
| Device or other IDs (advertising ID) | Yes (AdMob, free tier) | With Google (advertising) | Optional | Advertising | Yes | Yes — reset/delete in device settings |
| Diagnostics / crash logs | Yes (Crashlytics) | With Google (processor) | Optional | Analytics (stability), app functionality | Yes | Yes — 90-day retention |
| Device model, OS version, app version | Yes | With processors | Required for operation | App functionality, analytics | Yes | Via crash-log retention |
Declarations that are "No": health and fitness; financial info beyond the purchase token (no card data at all); messages; contacts; calendar; audio files; files and documents (except the PDF you generate locally and share by your own action); web browsing history; installed apps; race/ethnicity, religion, sexual orientation, political beliefs (never collected); background location (not collected).
Security practices to declare: data is encrypted in transit; users can request data deletion; a data-deletion mechanism is provided in-app and by email; the app does not target children; independent security review: [YES/NO — state truthfully]. If a data-deletion URL is requested, use https://workproof.app/delete-account.
Appendix B — Permission-to-Purpose Map
| Permission | Purpose | Trigger | Data leaving device |
|---|---|---|---|
CAMERA |
Capture the clock-in/out evidence photo | User taps shutter | Only if Sync is on |
ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION |
Bind record to a place | User taps clock in/out | Only if Sync is on |
INTERNET / ACCESS_NETWORK_STATE |
Sync, purchase verification, ad delivery | Sync, purchase, ad request | Yes, as described in Section 10 |
POST_NOTIFICATIONS |
Reminders and sync notices | User enables reminders | No — token only |
AD_ID |
Rewarded advertising on the free tier | User requests an ad | Advertising ID to AdMob |
| Background location | Not requested — the App has no background location capability | — | — |
| Storage / media library | Not requested — the App never reads your gallery | — | — |
Appendix C — Sub-Processors and Processing Locations
| Sub-processor | Role | Processing location | Safeguard for international transfers |
|---|---|---|---|
| Google LLC (Firebase, Play, AdMob) | Authentication, messaging, crash diagnostics, payments, advertising | United States, EU, and other Google regions | EU SCCs; EU–U.S. Data Privacy Framework where certified |
| Apple Inc. | iOS payments, push, sign-in | United States and other Apple regions | EU SCCs; adequacy where applicable |
| Cloudflare, Inc. | Sync backend and photo storage | Cloudflare's global edge network (content served from data centres worldwide) | Standard Contractual Clauses (SCCs) |
We will publish an updated list at least 30 days before adding a new sub-processor that processes Core Evidence Data, and you may object by contacting us.
Appendix D — Glossary
- CCPA/CPRA — California Consumer Privacy Act as amended by the California Privacy Rights Act.
- Controller / Processor — the entity deciding why and how personal data is processed / the entity processing it on the controller's behalf.
- Core Evidence Data — see Section 3.
- GDPR — EU General Data Protection Regulation 2016/679; UK GDPR is the UK's equivalent as retained in domestic law.
- LGPD — Brazil's Lei Geral de Proteção de Dados.
- Personal data — information relating to an identified or identifiable person.
- Processing — any operation on personal data.
- Rewarded ad — an advertisement a user voluntarily watches in exchange for an in-app benefit (here, one free PDF export).
- SCCs — Standard Contractual Clauses approved by the European Commission for international transfers.
- Sync — optional upload of records to our servers.
- Tamper-evident — designed so that after-the-fact alteration is detectable, through chained hashes and serial numbers.
Appendix E — Version History
| Version | Date | Changes |
|---|---|---|
| 1.0 | August 18, 2026 | First published policy (pre-monetization). |
| 2.0 | September 26, 2026 | Added advertising (Google AdMob) disclosures and advertising-identifier processing; expanded purchase and subscription data disclosures including consumable export credits; added EU/UK advertising consent (UMP), CCPA/CPRA advertising opt-out, and Global Privacy Control statements; added trader information under the EU Digital Services Act; added data-deletion URL and step-by-step deletion section; expanded retention, sub-processor, and international-transfer tables; added Google Play Data Safety mapping (Appendix A), permission-to-purpose map (Appendix B), and glossary; clarified that no behavioural analytics SDK is active; clarified biometric non-collection in light of BIPA/COTA/MHMDA. |
© 2026 深圳市嘿点数字科技有限公司 (Shenzhen Heidian Digital Technology Co., Ltd.). All rights reserved. WorkProof is a trademark of 深圳市嘿点数字科技有限公司 (Shenzhen Heidian Digital Technology Co., Ltd.).