🕊️ BlueSparrow Labs
  • Home
  • About
  • Apps
  • Blog
  • Contact
Back to Blue Sparrow
InspectMate

InspectMate Privacy Policy

How InspectMate handles field records, synchronization, documents and public links.

Updated 2026-08-24 [email protected]
PrivacyTermsDelete account
Offline-ready Core field records are held locally and synchronize through connected services
Professional records Inspectors decide what client, site, finding and evidence data to enter
Shared documents Anyone with an active report or invoice link may access its selected content
Privacy requests [email protected]
On this page
  1. Overview
  2. Data we handle
  3. How we use data
  4. Sharing and processors
  5. Storage and residency
  6. Cloud and backups
  7. Public links
  8. Retention
  9. Security
  10. Your rights
  11. Children and minors
  12. International transfers
  13. Changes
  14. Contact

This policy explains InspectMate's local workspace, connected services, professional records and the choices available to users and affected people.

Overview

Blue Sparrow is a solo developer based in India and operates InspectMate for independent inspectors and other field professionals. This policy explains what the mobile app, synchronization service, support and email tools, purchase services and hosted document pages handle. InspectMate applies data-minimisation, transparency, purpose-limitation, security and rights principles supported by the EU General Data Protection Regulation and other applicable privacy requirements.

InspectMate is offline-ready, not exclusively offline. A local database supports field capture and queued changes; signed-in workspaces synchronize supported records with the InspectMate API. Inspectors or their businesses generally decide why client, contact, site, inspection, photo and invoice information is entered or shared. For those professional records, that inspector or business is normally responsible for an appropriate basis, notices, accuracy, retention and recipient choices. Blue Sparrow handles connected copies to provide InspectMate while separately determining how account security, service operations, purchases and support information are handled.

Data we handle

Depending on the features used, InspectMate may handle:

  • Firebase and Google sign-in information such as a user identifier, email, display name and profile image.
  • Workspace information such as business name and contacts, inspector name, timezone, currency, units, tax settings, document preferences, logo and optional signature image.
  • Client and site information such as names, contact details, addresses, site labels, recipient preferences, notes and attachment references.
  • Job, template and inspection information such as schedules, status, checklist definitions, answers, notes, severity, recommendations, corrective actions and completion proof.
  • Photos and selected media, including file type, size, dimensions and upload-queue state.
  • Reports and invoices, including PDFs, lines, tax, totals, external payment records, receipt references and user-supplied payment instructions or QR material. InspectMate does not receive client bank-login credentials or settle client funds.
  • Hosted report and invoice information including high-entropy link tokens and hashes, expiry, revocation, document views and downloads with timestamps. The audited event implementation does not intentionally store a recipient IP address or browser user-agent with these events.
  • Synchronization, device and notification information such as an app-generated device identifier, platform, app version, timezone, push-permission state, Firebase Cloud Messaging token, queue state, request identifiers and service-security logs.
  • Google Play and RevenueCat product, transaction, receipt, subscription and entitlement state. Blue Sparrow does not receive full payment-card details.
  • Support, feedback, diagnostic and customer-email information deliberately submitted, including reply address, message, selected diagnostic state, recipient, delivery status and message identifiers. The support service also stores an account and workspace reference, an idempotency value and a hash derived from the requesting IP address for security and rate limiting.
  • Firebase Crashlytics crash, device and diagnostic information in non-debug app builds where collection is active.

InspectMate does not use an advertising identifier, sell personal information or currently include Firebase Analytics. Camera capture or image selection happens only when a user chooses that action. The Android app requests internet, notification, restart scheduling and vibration capabilities; notification access can be declined.

How we use data

Information is used as reasonably necessary to authenticate users; provide clients, sites, jobs, calendars, templates, inspections, corrective actions, reports, invoices and exports; synchronize records and media; create, deliver, expire and revoke hosted documents; show link access summaries; deliver customer email, support and optional notifications; validate purchases and entitlements; diagnose crashes; prevent abuse; secure the service; and meet applicable operational requirements.

Blue Sparrow does not sell or rent personal information and does not use InspectMate records for targeted advertising.

Sharing and processors

Limited information may be processed by:

  • Google and Firebase for Google sign-in, Firebase Authentication, Firebase Cloud Messaging, Crashlytics, Google Play distribution and billing.
  • Blue Sparrow's InspectMate API and infrastructure providers for PostgreSQL synchronization, media and document storage, public links, security and deletion.
  • The Blue Sparrow notification gateway and Firebase Cloud Messaging for enabled operational notifications.
  • RevenueCat and Google Play for purchase validation, renewal, cancellation and entitlements.
  • Blue Sparrow mail services for support, feedback, report or invoice email and delivery records.
  • The operating system, a user-selected app or destination, and recipients deliberately given a file, email or public link.

These third-party providers apply their own terms and privacy controls. Blue Sparrow may make a limited disclosure where required by applicable rules or reasonably necessary to address fraud, abuse or a serious security risk.

Storage and residency

Core working data is stored in InspectMate's local SQLite database and selected files on the device. Supported records, media, generated documents, email records and link events synchronize to the InspectMate service.

Blue Sparrow-controlled connected InspectMate content is intended to remain in European Union infrastructure, subject to verification of the live production datacentre, offsite backup region, retention jobs and deployment configuration. This is a qualified infrastructure commitment, not a claim that every InspectMate-related datum stays exclusively within the EU.

Google, Firebase, RevenueCat, Google Play, notification, mail, support and user-selected file services may process limited information in other regions. Blue Sparrow support access may occur from India when needed to answer a request or operate the service.

Cloud and backups

Synchronization can include workspace settings, clients, sites, jobs, templates, inspections, findings, corrective actions, photos, reports, invoices, external payment records, email state and public-link metadata. The app queues supported changes and media while offline and sends them when connectivity and an authenticated service are available.

The service repository includes tools intended to back up PostgreSQL data and uploaded media, with an example fourteen-day rolling configuration. The production schedule, region, encryption, access controls, restore drills and actual deletion lifecycle remain subject to operational verification. A protected backup may remain for a limited recovery period after deletion before it ages out.

PDFs, CSV exports, email attachments and files saved or shared through a device become ordinary copies controlled by their destination or recipient. Deleting InspectMate cannot retrieve a delivered copy.

Public links

InspectMate generates high-entropy tokenized links for hosted reports and invoices. The current service stores both the link token and its hash in the document-sharing record; access-event records use the token hash. A report can disclose business branding, inspector, client and job details and the PDF. An invoice can disclose business, client and job details, invoice number, status, currency, total, payment instructions or QR material and the PDF.

Anyone holding a working URL can access its content without signing in until expiry or revocation. Event records count views, downloads and attempts against expired or revoked documents. Those event records do not intentionally include an IP address or browser user-agent, although ordinary web-server access logs may process request network and browser information for operations and security. Current hosted pages do not identity-check recipients, and the audited frontend lacks explicit search-engine no-index metadata. Treat each URL as confidential, confirm the recipient, minimize content and revoke it when no longer appropriate. Expiry cannot remove a copy already downloaded or forwarded.

Retention

Local data remains until deleted through app features, cleared with app storage or removed with app data. Synchronized business records, media, documents, email records, link events, support information, purchase mirrors and security logs remain while reasonably needed for the feature, service integrity, applicable records or a verified deletion process. No fixed production period is promised where live evidence has not been verified.

The in-app deletion flow first unbinds push delivery and asks the API to delete the account. The API records the deleted Firebase identifier, deletes workspaces owned by that user and related database records, deletes the subscription mirror and user record, and then attempts to remove owned-workspace uploads. Upload removal is best effort after the database transaction. The app clears local tables and separately attempts to delete the Firebase Authentication identity, which may require recent Google authentication. Shared workspaces not owned by the deleting user and records controlled by another workspace may follow that workspace's decisions.

Backups, provider records, delivered emails and recipient or exported copies have separate lifecycles. Contact [email protected] if a deletion step fails. Account deletion does not cancel a Google Play subscription.

Security

InspectMate uses proportionate safeguards including authenticated HTTPS requests, workspace access checks, local application storage, high-entropy public-link tokens, hashed token values in access events, link expiry and revocation, queued transfer state, provider controls and blocking reuse of a deleted Firebase identifier.

Protect the device, Google account, PDFs, public URLs, media, payment instructions and exports. No device, transmission, local file or connected service can be guaranteed completely secure.

Your rights

Depending on location and applicable exceptions, a person may have rights to access, correct, receive, delete, restrict or object to processing of personal information and withdraw consent where consent is the basis. A person may contact a local data-protection authority. Applicable protections can include the EU and UK GDPR, India's Digital Personal Data Protection framework, US state privacy requirements, Brazil's LGPD, Canadian requirements and comparable rules elsewhere.

Users can edit many records, export supported data, manage notifications, revoke links and start deletion. A client or site contact whose information was entered by an inspector should normally contact that inspector or business first; Blue Sparrow will assist a verified workspace or respond directly where required. Email [email protected] with InspectMate in the subject. Proportionate verification may be requested.

Children and minors

InspectMate is intended for professionals and is not directed to children as account operators. An inspector should not enter a child's information unless genuinely needed for an appropriate professional purpose with the notices, permissions and safeguards required where the child lives. Do not place unnecessary child information in notes, photos, reports, invoices or public links. Contact [email protected] with a concern.

International transfers

Blue Sparrow-controlled content is intended for EU infrastructure subject to the verification described above. Google, Firebase, RevenueCat, Google Play, notification, mail, support and user-selected providers may process limited information elsewhere. Where required, Blue Sparrow and providers use appropriate contractual, adequacy or other lawful mechanisms with data-minimisation and security measures. EU users retain EU GDPR protections across necessary regional boundaries.

Changes

This policy may change when InspectMate, its providers or applicable requirements change. Material updates will be presented in the app or at https://bluesparrow.dev where appropriate, and the updated date will be revised.

Contact

For privacy questions, rights requests or deletion follow-up, email [email protected]. For general help, email [email protected]. Information is available at https://bluesparrow.dev.

Questions about this document? Email [email protected].

Blue Sparrow website
Facebook Email Terms Privacy
© 2026 BlueSparrow Labs. All rights reserved.