Privacy Policy

Last updated: September 2, 2026

Proofcam is published by Benoît Pouzet, independent developer (sole proprietorship), Nouméa, New Caledonia, RIDET 1 545 987.001, who acts as the data controller. Proofcam does not require an account, and we do not operate servers that store your photos or personal data. Processing is governed by the French Data Protection Act (law 78-17 of January 6, 1978) and the EU General Data Protection Regulation (GDPR), applicable in New Caledonia since June 1, 2019. For anything in this policy, contact [email protected].

A French version of this policy is available at proofcam.italofa.nc/fr/privacy.

The short version

Your photos stay on your device

Photos, stamped copies, thumbnails and their integrity fingerprints are stored in a vault inside the app, on your device only. Fingerprints are computed on the device. Nothing is uploaded to us; we have no server that could receive them. Photos leave your device only when you share them yourself with the system share sheet. Deleting a proof, or deleting the app, permanently deletes the corresponding data.

Location and address

With your permission, Proofcam reads your GPS position to stamp it on your photos and to show your live accuracy before you shoot. To turn coordinates into a street address, the app sends your coordinates to the Nominatim geocoding service operated by the OpenStreetMap Foundation (United Kingdom, a country covered by an EU adequacy decision). This happens while the camera screen is open (at most once every 30 seconds or 30 meters) and when an address is resolved later for photos taken offline.

What is sent: the coordinates, the app language (so the address comes back in your language), and a technical identifier of the app. What is not sent: your photos, your name, or any account or device identifier. The coordinates are used solely to resolve the address and are subject to the OSM Foundation privacy policy. Address data © OpenStreetMap contributors.

Time verification

To verify the time of a capture, the app sends a minimal HTTPS request to www.gstatic.com, a Google-operated endpoint, and reads only the date header of the response. No personal data is sent; like any internet request, it involves ordinary connection metadata (such as your IP address) on Google's side.

Purchases

Subscriptions are processed by the Apple App Store or Google Play. We never see your payment details. Subscription status is managed through RevenueCat, acting as our processor: it handles a randomly generated anonymous identifier and store receipt data, and nothing that names you. See the RevenueCat privacy policy and their data processing agreement.

App updates

The app periodically contacts the Expo update service (u.expo.dev) to fetch bug-fix updates. This involves ordinary connection metadata and the app version, nothing personal.

Analytics

We collect anonymous usage events with PostHog, hosted in the European Union (Frankfurt), in production builds only. This includes which screens are used, key product events (such as a capture or a completed purchase, with technical properties like the template used) and automatically captured touch interactions. Events never contain your coordinates, addresses, photos, fingerprints or any text you type. We never call any identification function: events remain tied to a random anonymous identifier. Legal basis: our legitimate interest in understanding and improving the app. You can object at any time by contacting us.

Crash and performance reports

We collect crash reports and performance traces with Sentry to keep the app reliable. These include technical device information and the names of the screens involved, never the content of your photos or stamps. Sentry processes this data in the United States, under standard contractual clauses. See the Sentry privacy policy.

Information you type in

If you fill in the Agency block (a name and contact of your choice), it is stored only on your phone and drawn into the stamp pixels of the photos you create with the Agency template. It is never transmitted to us. Whatever you stamp on a photo travels only where you share that photo.

Permissions

Proofcam requests two permissions: the camera (to take the photos) and precise location while the app is in use (to stamp where they were taken). It never requests background location, and it never accesses your photo library. Both permissions are required for the camera screen: if one is missing, the app explains it and waits. Analytics record only whether a permission was granted or denied.

Data retention

Everything stored on your device stays there until you delete it or delete the app. We keep nothing ourselves. Third parties listed above retain data according to their own policies: anonymous analytics and crash data are kept by PostHog and Sentry for limited periods, and purchase records are kept by Apple, Google and RevenueCat as required for subscription management.

Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection over data concerning you. Since the app holds your content on your device only, most of these rights are in your hands already: deleting the app removes your content entirely. For anything else, contact [email protected]. Purchase data is held by Apple or Google under your store account and is best exercised through them. You may also lodge a complaint with the French supervisory authority, the CNIL (3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France, cnil.fr).

Changes and contact

We may update this policy as the app evolves; the current version is always available at this address, with its date at the top. Questions or requests: [email protected].

← Proofcam