Privacy Policy

PROVE IT — couple check-ins

Last updated: August 13, 2026

PROVE IT is a consent-based check-in app for two adults who deliberately pair their devices. One person can ask for proof, but the recipient decides whether to respond, decline, or ignore the request. There is no hidden or remote capture: a recipient must perform each photo, video, screen, battery, or location response on their own device.

Controller and contact

The data controller is Gergő Miklós, an independent developer based in Hungary. For privacy questions or requests, email miklos.gergo.98@gmail.com. PROVE IT is not operated by Apple, RevenueCat, Cloudflare, Hetzner, or Vercel.

Anonymous identity and display name

PROVE IT has no email, phone-number, password, or social-login sign-up. The app registers an anonymous device identity with the service: the server issues a random device id and secret access token, stores the device id, and stores only a SHA-256 hash of the token. The token and device id are kept in the iOS Keychain and can survive reinstalling the app. During onboarding you choose a display name. It does not have to be your legal name, and it is shown to the person you pair with.

Data we process

  • Device and profile data: random device id, hashed access token, platform, chosen display name, push token, and pair id.
  • Pairing data: short-lived pairing codes and the relationship between the two paired device identities.
  • Check-in and Night Watch data: who requested and must answer, the requested proof types, target app for Screen Proof, optional notes, deadlines, agreed schedule, delivery/seen timestamps, response time, and result such as completed, partial, declined, or missed.
  • Proof deliberately submitted: photos, videos, screen recordings, audio in proof videos, typed detail, battery state, current coordinates, or a route trail. Proof media can contain people, surroundings, notifications, or other information visible or audible during capture; understand what each capture includes before you send it.
  • On-device verification signals: a Proof Video uses Apple Vision on the phone to detect whether the prompted head movement occurred, and a Room Scan uses device motion to measure the turn. PROVE IT does not identify who a face belongs to, create a face template, or upload face landmarks, head angles, or raw motion-sensor readings. The video you deliberately submit can still contain a face and is handled as proof media above.
  • Subscription data: product id, purchase and entitlement events, trial or subscription status, renewal/expiry information, storefront data, and an anonymous RevenueCat subscriber id. Apple handles payment-card and Apple Account details; PROVE IT does not receive them.
  • Technical data: limited request, security, error, and delivery logs, including timestamps, IP address and user-agent information generated by hosting, network, and policy-site providers.

Route History and location

A one-time Location proof requests a current location only when you choose to answer. Route History is different and is optional. If you switch it on and grant location permission, PROVE IT continuously builds a rolling trail for up to 75 minutes on your device. With “Always” permission it can collect while the app is in the background; with “While Using” permission it collects only while the app is open. iOS shows its system location indicators and you can revoke permission at any time.

The rolling Route History is stored on-device only. It is not uploaded merely because collection is enabled or because someone asks for it. A route leaves your phone only when you open a Route request, review the result, and deliberately choose to send it. Turning Route History off stops collection and deletes the saved trail on that device.

No hidden or automatic proof capture

  • A partner can request proof but cannot activate your sensors or read your phone.
  • Every proof-capture screen is visible and requires action on the recipient’s device. iOS permission prompts and recording/location indicators remain visible.
  • An approved Night Watch can create requests on its agreed schedule, but it never captures or sends proof automatically.
  • You may decline a request or ignore it. Ignoring it can be recorded as missed after the deadline, but no proof is captured.

Technical processing that is automatic

Some non-capture operations happen automatically so the service works: the app registers its anonymous device identity, authenticates and synchronizes pair events, refreshes subscription status with Apple and RevenueCat, registers an APNs token if you allowed notifications, and runs retention/deletion jobs. A generic push can wake the app briefly to synchronize a request. None of these operations chooses an answer, activates a proof sensor, or sends proof on your behalf.

No content analysis or advertising use

We do not use submitted proof, notes, screen recordings, audio, or location for AI training, facial recognition, content profiling, advertising, or behavioural targeting. The app processes captures on your device to create proof and receipts; the service processes submitted content only as needed to authenticate, store, deliver, secure, retain, and delete it. We do not routinely inspect or moderate proof content. A narrowly limited disclosure may still be required by law or necessary to investigate a security incident or abuse report.

Purposes and GDPR legal bases

  • Provide the service and perform our contract (GDPR Article 6(1)(b)): register the anonymous identity, pair devices, deliver check-ins and proof, sync receipts, and determine subscription access.
  • Your consent (Article 6(1)(a)): optional iOS permissions and Route History collection. You can withdraw permission or turn Route History off at any time. This does not affect processing that was lawful before withdrawal.
  • Legitimate interests (Article 6(1)(f)): secure the service, prevent abuse and pairing-code attacks, diagnose failures, keep paired devices consistent, and understand subscription-level performance. We limit this to what is necessary and do not use proof content for advertising or profiling.
  • Legal obligations (Article 6(1)(c)): retain or disclose limited records where tax, accounting, consumer-protection, or lawful authority requests require it.

Sharing and service providers

Submitted check-ins and proof are shared with the one device paired with yours. We also use the following processors and platform providers:

  • Hetzner hosts the application API and database infrastructure.
  • Cloudflare provides network protection/tunnelling and R2 object storage for submitted proof media, and processes associated network metadata.
  • Apple provides APNs notifications, StoreKit/App Store payments, iOS permissions, and MapKit map rendering. Apple processes data under its own terms and privacy policy.
  • RevenueCat receives anonymous subscription and purchase events for entitlement support and subscription-level analytics. It does not receive your proof media, check-in notes, paired display name, or location from PROVE IT.
  • Vercel hosts this public policy/support site and may create standard access and security logs when you visit these pages. The policy site does not receive your in-app proof or pairing data.

We may disclose information where required by law or necessary to protect users and the service. We do not sell personal data.

International transfers

The controller is in Hungary. Hetzner, Apple, Cloudflare, RevenueCat, and Vercel may process data in the European Economic Area, the United States, or other countries. Where GDPR requires it, transfers rely on an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism provided by the relevant vendor. Contact us for more information about safeguards relevant to your data.

Retention

  • Submitted check-ins, event records, notes, proof media, and submitted coordinates or routes transit through and are stored by the service for paired delivery, then age out within 30 days. Unpairing or account deletion removes this data from the active service earlier. Residual database content is scheduled for deletion from rotating disaster-recovery backups when it reaches 30 days. If a rotation is interrupted, every overdue snapshot is retried on the next successful run. Backups are not used for ordinary app delivery.
  • Unused pairing codes expire after 24 hours.
  • The on-device Route History keeps only a rolling 75-minute window and is deleted immediately when you turn Route History off.
  • Local receipt records and downloaded/captured proof on each phone are separate from server retention. They can persist after the server copy expires and remain until that phone’s user deletes history or deletes their account. Unpairing removes cached proof media but can leave receipt records on each phone.
  • Device/profile and active pairing records remain until unpairing or account deletion. Push tokens remain until replacement or account deletion.
  • Apple and RevenueCat retain purchase and subscription records under their own policies and applicable legal obligations. Account deletion in PROVE IT does not erase Apple’s transaction history.
  • Infrastructure security and access logs are retained for the limited periods set by the relevant provider or needed to investigate security incidents and legal claims.

Unpairing, local deletion, and account deletion

  • Delete all history removes check-ins, receipts, and associated local media from your phone. It does not delete your partner’s local copies or your anonymous server identity.
  • Unpair ends the pair for both people and deletes the pair’s shared check-ins, plans, events, and proof media from the active service. Residual database content can remain in the rotating backup described above. Each phone may retain its own receipt records until its user deletes them.
  • Delete my account is available in the app. It ends any pair, deletes shared data from the active service, removes your active server device record, chosen display name and push token, clears the app’s local history, and deletes the Keychain identity after the server confirms deletion. Residual database content follows the scheduled backup deletion process described above.

Deleting the app alone is not account deletion because iOS may preserve the Keychain identity. Account deletion also does not cancel an App Store subscription; manage or cancel that separately in your Apple ID subscription settings.

Your GDPR rights

Depending on the circumstances, you may request access, correction, deletion, restriction, or portability of your personal data; object to processing based on legitimate interests; and withdraw consent. You also have the right to complain to a supervisory authority. In Hungary, this is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), at naih.hu.

Email miklos.gergo.98@gmail.com to exercise a right. Include the device id shown in the app’s You tab so we can identify the anonymous record. We may ask for additional verification to avoid disclosing or deleting the wrong person’s data. Statutory exceptions may apply, and you may contact your local supervisory authority as well as NAIH.

No ads, sale, or cross-app tracking

PROVE IT has no ads, ad identifiers, or ad networks. We do not sell personal data, use proof for advertising, or track you across other companies’ apps and websites. RevenueCat processes anonymous subscription events for the purposes described above; it does not turn proof or location into advertising profiles.

Security

Traffic uses HTTPS. Access tokens are stored in the iOS Keychain and only token hashes are stored by the API. Server media delivery checks pair membership. We limit retention and processor access, but no service can guarantee absolute security. Do not send content you do not want your paired partner to receive and potentially retain or export.

Adults only

You must be at least 18 years old to use PROVE IT. The service is not directed to children, and we do not knowingly process children’s data.

Changes

We may update this policy when the product, providers, or law changes. We will change the date above and, where a change is material, provide an appropriate in-app notice.

Questions or privacy requests: miklos.gergo.98@gmail.com. See also the Terms of Use and Support.