xPrufy — Privacy & Data Policy
Last updated: July 6, 2026 · Applies to iOS and Android
xPrufy is designed around a simple principle: your evidence stays on your device. No account is required. No media files leave your phone unless you explicitly share or export them. This policy explains exactly what data is processed, where it goes, and your rights. The app provides cryptographic integrity aids (hashes, signatures, optional anchors); it is not a substitute for independent professional review where your situation requires it.
The following data is created and stored on your device in the app sandbox. The app does not automatically upload your media files to our servers:
Evidence files (photos, videos, audio)
GPS coordinates attached to each capture
SHA-256 file hashes, record hashes, chain-of-custody metadata, and reliability fields
Metadata signatures: RSA-SHA256 over capture metadata (default on new installs: Standard mode, software-protected key material). Professional mode adds a small device identity certificate in metadata. Device-Bound mode on Android may store the RSA private key in Keystore / TEE / StrongBox when available. If RSA signing fails at capture time, a hardware-backed HMAC from the security chip may be used instead.
Storage encryption keys and your Recovery Key (handled via platform secure storage / Keystore / Secure Enclave as the operating system provides)
Device integrity flags (root/emulator/debugger detection)
Security event log
App settings and preferences
The app does not automatically upload your media files to our servers. When enabled or available, the following network requests may be made:
SHA-256 hashes → OpenTimestamps calendars for Bitcoin anchoring
(a.pool.opentimestamps.org, b.pool.opentimestamps.org)
SHA-256 binding digests (hashes) → RFC 3161 timestamp authorities — not your media file bytes; the app tries these in order until one responds, then records which service stamped the digest:
timestamp.digicert.com (DigiCert)
timestamp.sectigo.com (Sectigo)
timestamp.globalsign.com/tsa/r6advanced1 (GlobalSign)
freetsa.org (FreeTSA)
NTP time service (pool.ntp.org) — UDP; device clock verification; not TLS; best-effort on benign networks
HTTPS Date header fallback (Google, Cloudflare, Microsoft) — HTTPS HEAD only, reads the Date header over TLS; tried in order until one succeeds (www.google.com, www.cloudflare.com, www.microsoft.com)
Google Play Age Signals API (Android only) — before capture, the app may call this API to check age eligibility. Google processes the request under its terms; the app does not persist age-band values from that API on device.
Examples of third-party endpoints used for these features include OpenTimestamps calendar/pool services, RFC 3161 timestamp authorities such as DigiCert, Sectigo, GlobalSign, and FreeTSA, and network time checks using pool.ntp.org plus HTTPS Date-header checks from Google, Cloudflare, or Microsoft.
All external requests carry standard network metadata (your IP address, request timestamp). We do not control or log this — it is received only by the third-party services listed. No media files, GPS coordinates, or personal identifiers are intentionally sent for timestamping or clock-check requests. RFC 3161 traffic uses binding digests only, as described.
When you choose to export or share data, that content leaves the device because you initiated it. Examples: Settings → Back Up Files (writes an EvidenceBackup_….zip to your usual export folder, often Downloads — includes media, metadata, and your HMAC Recovery Key, and can include RSA signing identity material if you choose; not password-protected by the app); Export with Proof from All Files (select records → Export with proof on the bottom bar) or from a record's detail screen ⋮ menu (ZIP with integrity export materials and per-item PDF where applicable); plain-file share from the same detail ⋮ menu or All Files → Share file(s) (strips integrity context the app attaches to records); Advanced → Export Audit Trail (JSON — active evidence and recycle bin only, not permanently removed items); Advanced → Evidence Signing → Export signing identity (RSA key JSON — plaintext when the mode allows it); and OS share sheets. Protect backup and export files like sensitive files.
Tapping stored GPS coordinates on an evidence record's detail screen opens a maps view outside this app only when you tap: on iOS this typically opens Apple Maps; on Android the system may open or offer a maps app for the location link; on web or some desktop platforms an OpenStreetMap page may open in your browser. Those providers process the request under their own terms and privacy policies. We do not receive your coordinates through that action.
When Bitcoin anchoring is used, the SHA-256 hash of your evidence is submitted to the Bitcoin blockchain. Once confirmed, it is publicly visible on that public ledger and is not something the app developer can edit or delete. The hash is a mathematical fingerprint only and reveals nothing about the content, location, or nature of your evidence.
The app requests the following permissions, used only as described:
Camera — capturing photo and video evidence only
Microphone — capturing audio evidence and video soundtracks only when you start a recording
Location (precise GPS) — attaching coordinates to evidence you choose to capture; stored on-device only
Storage/Files — saving evidence files to device storage and reading files for import/re-linking you request; files stay on-device unless you export or share them
Keep screen awake (Android) — during large export or backup operations so the process is less likely to be interrupted
Network access — timestamping, clock checks, connectivity checks, and the Google Play Age Signals check on Android before capture
xPrufy is not directed at children under 13 and does not knowingly collect data from anyone under 13. Use requires agreement to Terms of Use which require users to be at least 18 years old. The app is rated 17+ (iOS) and Mature (Android).
The current app version is designed without:
Advertising networks or SDKs
Analytics or crash-reporting SDKs (no Firebase, no Crashlytics, no Mixpanel, no Amplitude)
Tracking pixels or fingerprinting
Cross-app tracking
Sale of your evidence data
Your use of the current app version is not profiled or monetised in any way.
All data is held only on your device for as long as you choose. There is no server-side copy to delete.
Items moved to the recycle bin are kept for up to 30 days, then permanently deleted automatically unless you restore or permanently remove them sooner.
When you permanently remove an item from the recycle bin, the app drops that record from its active metadata (it is not kept in a separate deleted list).
To delete all app data immediately: open Settings → Advanced, then Panic Wipe (you choose Secure wipe or Quick wipe for evidence files).
To delete all data on uninstall: simply uninstall the app.
Note: SHA-256 hashes submitted to Bitcoin cannot be deleted. This is a fundamental property of public blockchains. The hash reveals nothing about your files and cannot be linked to you.
Because we do not operate a cloud account for your evidence:
Right of access — data you keep in the app is on your device and in exports you create
Right to erasure — use Settings → Advanced → Panic Wipe or uninstall (see also blockchain permanence above)
Right to portability — use Settings → Back Up Files (full ZIP), Export with Proof (All Files selection or a record's detail ⋮ menu), Advanced → Export Audit Trail (JSON; active + recycle bin only), and other export tools you choose
Right to restriction — disable optional features in Advanced (for example strict capture)
We do not act as a data controller for your evidence data. If you record other people, you are the data controller and are responsible for compliance with GDPR, CCPA, PIPEDA, or other applicable law.
IMPORTANT: If you record other individuals without their consent, YOU become the data controller under GDPR and are responsible for:
Obtaining valid consent where required by law
Providing privacy notices to recorded individuals
Honoring data subject access requests
Maintaining records of processing activities
Complying with lawful basis requirements (Article 6 GDPR)
This app is a tool. Legal compliance is YOUR responsibility.
Your evidence vault (record list, recycle bin, and related metadata) is encrypted at rest with AES-256-GCM. Keys are 32-byte values derived via SHA-256 from your Recovery Key (not PBKDF2). Photo, video, and audio files on disk are stored as normal media files in app storage — they are hashed and signed in the vault but are not individually encrypted by the app. Protect the device (screen lock, full-disk encryption) and treat exports/backups as sensitive. The HMAC Recovery Key is stored via platform secure storage (Android Keystore / iOS Keychain as the OS provides). RSA signing identity exports from Advanced (Evidence Signing) are plaintext JSON — protect those files like passwords. The HMAC Recovery Key is included inside full ZIP backups from Back Up Files, not as a separate app export. Some recovery or signing materials may be included in backups or exports you create, so protect those files carefully. Capture metadata is signed with RSA by default (see section 2 for modes). Protect the device with your system screen lock and full-disk encryption. No consumer device app can guarantee absolute security in every threat model, especially on rooted, jailbroken, modified, or otherwise compromised devices.
If we update this policy materially, the in-app Terms of Use version number will be incremented and you will be asked to re-agree on next launch. Minor clarifications may be made without notification. If paid features are introduced in future versions, this policy and the Terms of Use will be updated before release.
For privacy questions or concerns about this policy, contact us at:
kallabahekuran@gmail.com
You may also contact us through the support channel listed on the app store page for xPrufy.