🕊️ BlueSparrow Labs
  • Home
  • About
  • Apps
  • Blog
  • Contact
Back to Blue Sparrow
ProofPocket

ProofPocket Privacy Policy

How ProofPocket protects your local archive and handles optional account, recovery and support services.

Updated 2026-08-24 [email protected]
PrivacyTermsDelete account
Local source of truth The archive database is encrypted and stored on your device
Optional Drive copies Backup and recovery objects are encrypted before upload
Files you create Exports and shared copies need your protection
Privacy requests [email protected]
On this page
  1. Overview
  2. Data we handle
  3. How we use data
  4. Sharing and processors
  5. Cloud and backups
  6. Retention
  7. Security
  8. Your rights
  9. Children
  10. International transfers
  11. Changes
  12. Contact

This policy explains ProofPocket's encrypted local records, user-controlled files, connected metadata and privacy choices in plain language.

Overview

Blue Sparrow is a solo developer based in India and operates ProofPocket, a local-first proof-of-purchase organizer. This policy explains what the app and its optional connected features handle, why the information is needed and the choices available to you. ProofPocket is designed around data minimisation, purpose limitation, transparency and rights principles supported by the EU General Data Protection Regulation and other applicable privacy rules.

The encrypted database on your device is the core archive. Google sign-in, Firestore profile and entitlement fields, Crashlytics, support, purchases, Google Drive backup, portable recovery and any explicitly enabled Drive synchronization use the connections described below. ProofPocket does not sell personal information, display targeted advertising or use Firebase Analytics.

Data we handle

Depending on what you record or enable, ProofPocket may handle:

  • Item information such as name, store, category, purchase date, price and currency, return window, warranty duration, serial or model number, warranty provider, status, tags and notes.
  • Ownership contacts, claims, service history, maintenance plans and reminder schedules associated with an item.
  • Receipt images, PDFs, warranty files, product photos, document-scan results, barcode values and text extracted on the device with Google ML Kit.
  • Locally generated Proof Pack PDFs, ZIP bundles, inventory CSV files, preview files and export-history metadata.
  • Firebase and Google identity information such as user identifier, email, display name, profile photo URL and provider identifier.
  • Limited Firestore account and access fields such as created and updated timestamps, subscription status, product and expiry information, and VIP status or reason where applicable. ProofPocket does not intentionally upload receipt, item or attachment content to Firestore.
  • Google Play and RevenueCat purchase information such as product, receipt, transaction, trial, renewal, cancellation and entitlement state. Blue Sparrow does not receive your full payment-card details.
  • Crashlytics diagnostics in non-debug builds, including stack traces, app version, device and operating-system information, timestamps, technical grouping identifiers, the last screen or diagnostic breadcrumb, and limited feature-event context. These breadcrumbs are for reliability investigation, not advertising or behavioural audience measurement.
  • Support or feedback information you deliberately submit, including reply email, optional name and subject, message, app version, platform, locale and optional diagnostics for which the form requests permission.
  • Backup, recovery and synchronization metadata such as checkpoint time, object identifiers, schema and compatibility information, attachment counts, cursors, tombstones, success or failure state and account-bound recovery identifiers.

ProofPocket does not need precise location, contacts, SMS content, call history, microphone recordings, general browsing history or an advertising identifier for its current features. Android broad media permissions contributed by dependencies are removed; camera capture and system-selected imports occur only when you choose them. The operating system handles biometric verification and returns only an authentication result, not raw biometric data.

How we use data

Information is used only as reasonably necessary to:

  • Create, search and maintain your proof-of-purchase archive, reminders, item history and exports.
  • Authenticate the required app account and keep Drive access, restore boundaries and Premium state associated with the intended user.
  • Create, verify, list, retain, restore and delete encrypted Drive checkpoints and recovery objects when you enable those features.
  • Operate an explicitly compiled and enabled Drive synchronization mode for encrypted entity and deletion batches; this mode is disabled by default in the normal build configuration.
  • Process purchases, restore access and project limited entitlement or VIP state into the account profile.
  • Diagnose crashes and serious reliability failures in release builds.
  • Receive and answer support or feedback you choose to submit.
  • Protect accounts and services, prevent abuse and meet applicable privacy, consumer and operational requirements.

Receipt parsing, barcode scanning, archive search and most insights operate on the device. ProofPocket does not use your archive for targeted advertising or sell or rent it to others.

Sharing and processors

Blue Sparrow does not disclose archive information for independent advertising. Limited information may be processed by:

  • Google and Firebase for required Google sign-in, Firebase Authentication, App Check, the limited Firestore account profile, Crashlytics diagnostics, Google Drive app-data storage and Google Play distribution or billing.
  • RevenueCat for product configuration, purchase validation, receipt and entitlement state.
  • Blue Sparrow's attested support-request service and its delivery infrastructure when you submit contact or feedback information.
  • Google ML Kit components running on the device for document, text and barcode processing used by capture tools.
  • The operating system and the application, storage provider, printer or recipient you select when importing, opening, saving or sharing a file.

These third-party providers handle limited information under their own terms, privacy notices, retention controls and infrastructure. Blue Sparrow may also make a limited disclosure where required by applicable rules or reasonably needed to address fraud, abuse or a serious security threat.

Cloud and backups

ProofPocket requests the hidden Google Drive app-data scope only after you choose Drive protection or a related recovery action. This scope does not give ProofPocket general access to your visible Drive files. Google controls the physical location and infrastructure of Drive data.

Standard Drive backup can include an encrypted database snapshot, encrypted snapshot manifest and root index, and separately encrypted content-addressed attachment objects. Objects use authenticated encryption before upload. The standard account-linked key is derived from the signed-in Google or Firebase identity, so restore requires the same account. Free access retains the latest checkpoint; Premium can retain up to five checkpoints. Upload, background scheduling, retention repair and unreferenced-blob cleanup are best effort, and failed cleanup can leave an older encrypted object until a later successful run or explicit deletion.

Portable recovery is a separate disaster-recovery path. It creates an encrypted physical database checkpoint and protected attachment objects using a random backup master key that is available through the device profile and a user-managed recovery passphrase. Restore requires the matching Google or Firebase account and passphrase. ProofPocket verifies remotely returned objects before publishing or promoting a checkpoint. Blue Sparrow does not receive the passphrase or unwrapped backup master key and cannot reset the passphrase.

Portable local backup files are encrypted archives. Proof Pack PDFs, inventory CSV files and item ZIP exports are ordinary user-created files and are not described as encrypted by ProofPocket. Once saved, printed or shared, the selected destination and recipient control their copy.

An optional true-sync implementation can exchange encrypted entity batches, deletion tombstones and encrypted state through Drive app-data. It is controlled by build and account gates and is disabled by default. Standard ProofPocket releases should not be assumed to provide live multi-device merge synchronization merely because checkpoint backup is active.

Retention

Local archive data remains until you delete individual records, sign out through a flow that clears the device, complete account deletion, clear app storage or uninstall in a way that removes app data. Android system cloud backup and device-transfer extraction are disabled for ProofPocket. Exported, printed and recipient copies have independent lifecycles.

Drive checkpoint and recovery objects remain until retention cleanup or successful explicit deletion. Standard checkpoint retention is one for Free and up to five for Premium. Portable recovery uses its own rolling retention process. Because cleanup is best effort, older encrypted objects can temporarily remain. Firestore profile data remains while needed for account and entitlement features until deleted through the verified flow or another applicable request.

Crashlytics reports, Google Play and RevenueCat purchase records, support messages and provider security records follow the relevant feature need, applicable requirements and each provider's controls. Deleting ProofPocket does not cancel an active Google Play subscription.

The in-app account-deletion flow is designed to fail closed before identity deletion if required cleanup cannot complete. It attempts to delete portable recovery objects, standard Drive backups, Drive sync data, the Firestore user document, local recovery profile, local database, attachments, preferences and encryption keys, and then the Firebase Authentication account. Google session and RevenueCat session cleanup follow. A recent Google sign-in may be required, and Google Play subscription cancellation remains a separate action. Provider billing records, prior exports, recipient copies, support records and records required under applicable obligations are not automatically erased by this device flow.

Security

ProofPocket uses proportionate safeguards including an encrypted SQLite database with a device key held in secure storage, disabled Android backup, HTTPS, Firebase Authentication and App Check, scoped Drive permission, authenticated encryption for remote backup and synchronization objects, read-back verification before portable-checkpoint publication, and staged restore and deletion journals.

Attachment files can be encrypted at rest when the Premium attachment-encryption control is active. When that control is off, unavailable or paused after access changes, new attachments can remain ordinary app-private files even though the database is encrypted. Settings shows the current state. Exports are ordinary files. Protect your device, Google account, recovery passphrase and shared files, and keep an independent original of anything you cannot replace. No device, transmission, credential or connected service can be guaranteed completely secure.

Your rights

Depending on where you live and subject to applicable exceptions, you may have rights to know or access personal information, correct it, obtain a portable copy, delete it, restrict or object to processing, and withdraw consent where consent is the basis. You may also have a right to contact your local data-protection authority. These protections include, where applicable, the EU GDPR and EEA rules, UK GDPR, India's Digital Personal Data Protection framework, California and other US state privacy rules, Brazil's LGPD, Canada's privacy rules and comparable requirements elsewhere.

You can manage archive records, reminders, attachment encryption, Drive access, backups, exports, diagnostics context submitted with support, and account deletion through the app. Store subscriptions and provider-held copies may need to be managed in Google Play, Google Drive or the provider account.

Email [email protected] with ProofPocket in the subject and enough detail to identify the relevant account or request. Blue Sparrow may ask for proportionate verification and will respond within the period required where you live.

Children

ProofPocket is intended as a general household record organizer and is not directed to children. A parent or guardian should supervise use by anyone who cannot validly make account, purchase, backup or sharing choices. Do not store another person's identifying documents or details unless you have an appropriate reason and permission. Contact [email protected] if you believe a child's information has been provided inappropriately.

International transfers

Core archive records remain on the device unless you choose a Drive, export, support or sharing action. The documented Firestore project configuration targets an EU multi-region for limited profile metadata, but Firebase Authentication, Crashlytics, Google Drive, Google Play, RevenueCat, support delivery and user-selected file providers can process limited information outside your country or region. Blue Sparrow support access may occur from India.

Where safeguards are required for an international transfer, Blue Sparrow and relevant providers rely on appropriate contractual, adequacy or other lawful mechanisms and apply data-minimisation and security measures. ProofPocket does not claim that every item of connected metadata remains exclusively in the European Union. EU users retain the protections required by the EU GDPR when a necessary provider connection crosses a regional boundary.

Changes

This policy may change when ProofPocket, its providers or applicable requirements change. Material updates will be presented in the app or at https://bluesparrow.dev where appropriate, and the updated date will be revised. Earlier handling remains subject to the version applicable at that time unless a change must apply sooner for security or compliance.

Contact

Blue Sparrow is the developer and privacy contact for ProofPocket. For privacy questions or rights requests, email [email protected]. For general help, email [email protected]. Product and policy information is available at https://bluesparrow.dev.

Questions about this document? Email [email protected].

Blue Sparrow website
Facebook Email Terms Privacy
© 2026 BlueSparrow Labs. All rights reserved.