Home Proof — Privacy policy
Effective 13 September 2026
Home details, addresses, contacts, dates, notes, photos, documents, and other records you choose are stored on this device in app-private storage. Home Proof has no user account, no developer-operated advertising, and no developer backend or hosted database. Nothing you record — no home name or address, no note, photo, video, document, or amount — is ever sent to the developer or to anyone else unless you send it yourself. The developer does not receive, sell, or use this data for marketing. The app holds Android’s Internet permission for one purpose only, the usage statistics described below, which you can switch off.
If you choose the optional receipt document scanner, Google Play services provides it through ML Kit. Receipt inputs and scan results are processed fully on-device and are not sent to Google. ML Kit sends Google device and app information, per-installation identifiers, performance and API-usage metrics, event and error data, and input and output sizes. Google uses these metrics for diagnostics and usage analytics, API maintenance and improvement, and misuse or abuse prevention. The metrics are encrypted in transit and are not shared with third parties. Google’s terms and privacy policy apply. These scanner metrics go to Google and not to the developer, who never receives them; they are separate from the usage statistics described next, which the developer does see as totals.
The app reports usage statistics to Google Analytics for Firebase so the developer can see how it is used. Only counts and labels are reported: the name of something that happened, such as the app being opened for the first time, a home being created, the plan sheet being shown, or a purchase finishing; the name of the screen in view; small numbers and fixed values such as a plan tier or an error code; the app language; whether a subscription is active; and, when one is bought, which plan it was and the price Google Play charged for it. Your records are never reported — no home names or addresses, no notes, no photos, videos, or documents, no amounts, no names, and no email addresses. Each report carries a random app-instance identifier Google assigns to this installation and the Android advertising identifier, which is how the developer learns which advertisement led to an install; neither carries your name, and the developer sees totals rather than people. Google also sees the Internet address each report arrives from, as any server does; it masks that address and uses it only to work out roughly which country or region the app is being used in. Google processes the statistics on the developer’s instructions under Google’s privacy policy at policies.google.com/privacy and the Firebase Data Processing and Security Terms. They are used to understand how the app is used, to improve it, and to measure the developer’s Google Ads campaign; they are never sold, and the developer does not build an advertising profile of you from them. Google keeps the underlying event and user records for up to 14 months and then deletes them; totals already drawn from them into Google’s reports remain. Outside the European Economic Area and the United Kingdom the setting starts switched on; in those places the app asks you first, on its welcome screen, and reports nothing until you agree. To stop all of this at any time, open Settings, then the Privacy card, and switch off “Share usage statistics”. This device then reports nothing further and the statistics data held on it is deleted. Android’s own controls apply as well — Delete advertising ID and the ads-personalization setting in your phone’s settings work for this app as they do for any other.
Data leaves app-private storage only when you choose a share, export, print, calendar, backup, restore, or household-sync action. Backups and household-sync data are encrypted before the selected storage provider receives them; encrypted sync data includes a random installation identifier so device snapshots can merge. CSV, PDF, calendar, print, and ordinary share outputs may be readable by the recipients, apps, and providers you select, whose own policies apply.
Google Play processes subscription purchases. Home Proof receives purchase status and purchase tokens needed to unlock or restore access and stores entitlement state locally; it never receives payment-card or bank details. Android and the system or provider apps you select handle permissions, camera, documents, calendars, printing, biometrics, notifications, text-to-speech, and storage access under their own policies.
Records remain until you delete them in Home Proof or uninstall it. Uninstalling removes app-private data, but exported files, backups, shared sync folders, calendar entries, recipient copies, and Google Play billing records remain under your or the relevant provider’s control and must be removed there. There is no app account or developer-held account data to delete. Usage statistics are the one exception and are covered above: switching the setting off stops them and deletes what this phone holds, and Google deletes the underlying records at the end of the retention period.
App-private files, database records, encrypted backups, and sync passphrases are protected using Android storage and Keystore controls, but no device is perfectly secure. Device encryption is offered as well and stays off unless you turn it on in Settings. With it on, the app’s database and its evidence files — photos, videos, imported documents, and signature images — are encrypted on this device. You choose the encryption password and are the only person holding it: it is never transmitted, the developer never receives it, and it cannot be recovered, reset, or bypassed by the developer or by the app. You type it when turning encryption on and again only to turn it off; in ordinary use the app opens your records with a key held by this device’s Android Keystore, so nothing is asked of you. Because no copy of that password exists anywhere else, records still sealed after this device’s Keystore key is gone cannot be opened without it. Files made for handing to someone else, such as reports and exports, stay outside this protection so they can be opened without the app. Device encryption changes neither the backup nor the household-sync format; those are sealed by your backup password and household-sync passphrase, separate secrets that never carry the encryption password.
For privacy questions about Home Proof, email erangross03@gmail.com. Material changes will be reflected in this notice and its effective date.
How to have your data deleted
Home Proof keeps your records only on your own phone; the developer never receives them. The only data that leaves the phone is the usage statistics described above. To delete them:
1. Open Home Proof, tap Settings, then the Privacy card, and switch off “Share usage statistics”. From that moment the app reports nothing further, and the statistics data held on this phone is deleted at once.
2. Uninstalling Home Proof deletes every record, photo, document and setting the app holds on the phone. Nothing of it exists anywhere else unless you exported or backed it up yourself.
3. For statistics already reported to Google, email erangross03@gmail.com from the phone in question and the developer will request their deletion through Google’s user-deletion route. Because the statistics carry no name, address or account, a request can only be honoured while the installation can still be identified.
What is deleted: the usage statistics, the random app-instance identifier and the advertising identifier tied to this installation. What Google keeps: aggregated totals already drawn into the developer’s reports, which no longer identify any installation. Google deletes the underlying event and user records in any case after at most 14 months.