🕊️ BlueSparrow Labs
  • Home
  • About
  • Apps
  • Blog
  • Contact
Back to Blue Sparrow
SiteLog

SiteLog Privacy Policy

How SiteLog handles local field records, synchronized content, location-stamped photos, dictation and intentional sharing.

Updated 2026-08-24 [email protected]
PrivacyTermsDelete account
Local-first work Core records begin in the device database
Sensitive context Review photos, signatures, GPS stamps and dictated text
Controlled sharing Tokenized links can be revoked or set to expire
Global rights Access, correction, export and deletion requests are supported
On this page
  1. Overview
  2. Data We Handle
  3. How We Use Data
  4. Sharing and Processors
  5. Storage and Residency
  6. Public Links
  7. Retention
  8. Security
  9. Your Rights
  10. Children
  11. International Transfers
  12. Changes
  13. Contact

SiteLog is a local-first construction logging service operated by Blue Sparrow. This policy explains the information involved in the mobile app, synchronized services and recipient-facing pages, with practical choices for users and the people represented in their records.

Overview

Blue Sparrow operates SiteLog as a solo developer based in India. SiteLog helps construction professionals create local field records, synchronize supported content, produce reports, and intentionally share selected daily logs, proof packets and handoff packs.

Blue Sparrow applies privacy principles reflected in the EU General Data Protection Regulation, the United Kingdom GDPR, privacy laws in the United States including applicable state rights, India's Digital Personal Data Protection framework, and other applicable regional requirements. This describes an operational commitment and is not a regulatory certification.

Blue Sparrow does not sell or rent personal data and does not use SiteLog project content for targeted advertising.

Plain-language summary

Working records start on the device. Supported records and files can synchronize to SiteLog services, while selected reports and handoffs can be shared with anyone who receives a valid link.

Data We Handle

Account data can include a Firebase identifier and Google-provided name, email address and profile image. Business and project content can include company details and logos, project names, addresses, contacts, crew and subcontractor details, labor information, daily activities, equipment, materials, deliveries, weather, delays, visitors, safety observations and private notes.

Files and evidence can include captured or imported photos, captions, visible photo stamps, signatures, generated PDFs, exports, proof packets, handoff packs, acknowledgement names and titles, and an optional acknowledgement signature file. A user can choose to place precise latitude and longitude visibly into the pixels of a captured photo. Uploading or sharing that photo also shares the visible coordinates; removing file metadata later does not remove a stamp already drawn into the image.

User-triggered dictation uses the device's configured speech-recognition service. SiteLog receives the resulting transcript and adds it to the editable text field. SiteLog does not intentionally retain the microphone audio, but the operating system or speech provider may process audio on the device or through its cloud services under device settings and provider terms. Saved transcript text becomes ordinary SiteLog content and can synchronize or be shared.

Technical data can include device ID, platform, app version, locale, timezone, push-permission state, Firebase Cloud Messaging token, synchronization operations, timestamps, request identifiers, quotas, entitlement state, and security or error records. Public delivery activity can include opening and download times, IP address, user agent, requested resource, acknowledgement activity and security outcomes.

How We Use Data

Information is used to authenticate accounts, operate projects and daily logs, maintain the local-first synchronization outbox, upload and retrieve files, generate documents, provide public delivery and acknowledgement flows, deliver notifications, enforce plan limits, verify purchases, respond to support, prevent misuse and maintain service reliability.

If a user requests weather autofill, SiteLog sends current or last obtained latitude and longitude to Open-Meteo to retrieve local weather. Android requests foreground fine or approximate location rather than background-location access. Location may also be used when the user chooses GPS photo stamping.

Depending on the context, processing is based on providing the requested service, the user's choices or consent, legitimate operational and security needs, a business user's instructions, or an applicable obligation. Permissions can be changed in device settings, although affected functions may stop working.

Sharing and Processors

Blue Sparrow discloses information only as needed to provide a requested feature, follow the user's sharing instruction, operate and secure the service, respond to a valid obligation, protect people, or support a business transition with appropriate safeguards.

Providers and platforms can include:

  • Google Sign-In and Firebase Authentication for account identity and access.
  • Firebase App Check and platform attestation providers for abuse protection.
  • Firebase Cloud Messaging and the Blue Sparrow notification service for push delivery.
  • Google Play for app distribution and billing, and RevenueCat for entitlement and purchase-state management.
  • Blue Sparrow's SiteLog API, database, file storage, infrastructure and backup providers for synchronized records, media, public pages and service continuity.
  • Open-Meteo for weather requests that include latitude and longitude selected by the user.
  • The device's platform speech-recognition provider for user-triggered dictation.
  • Blue Sparrow's support and mail services for messages a user chooses to send.

Third-party providers receive information needed for their role and apply their own terms, retention, security and geographic processing arrangements. A business user also discloses selected content directly to collaborators and recipients through exports, messages, files and public links.

Storage and Residency

SiteLog keeps the working database and queued files in the app's device sandbox. Android application backup is disabled and the checked-in backup rules exclude the app database, files and preferences, although device and operating-system behavior can change outside Blue Sparrow's control.

Blue Sparrow-controlled synchronized records, uploaded files and service backups are intended to remain in European Union infrastructure, subject to confirmation of the active production and backup deployment. This qualified intention does not apply to every provider or every item of data.

Blue Sparrow is operated from India and support access can occur from India. Google, Firebase, RevenueCat, Open-Meteo, platform speech recognition, mail, store and other providers may process limited identity, notification, billing, location-request, audio, communication or security data in other regions under their own infrastructure and applicable safeguards.

Public Links

SiteLog can create high-entropy, tokenized links for selected daily logs, proof packets and handoff packs. The service stores a hash of the secret token. Links can have an optional expiry and can be revoked, but anyone who obtains a working URL may access the content permitted by it.

Shared material can include project and site information, log entries, photos, visible GPS stamps, signatures, PDFs and handoff details. Handoff acknowledgement can collect a recipient's name, optional title and optional signature file. Delivery services can record opening, download and acknowledgement activity, including IP address and user agent.

Unlisted or tokenized does not mean confidential or impossible to discover. A recipient can forward, copy, download or capture content, and SiteLog does not currently promise that every public page carries effective search-exclusion controls. Users should review content and recipients, use expiry where available, revoke links promptly and avoid sharing unnecessary personal or sensitive information.

Retention

Local records remain until removed through app controls, account deletion, app-data clearing or uninstalling, subject to device behavior. Synchronized records and files generally remain while needed to provide the account and for limited periods afterward for deletion processing, security, service recovery, backup rotation, support, billing records or other valid operational needs. Exact public-access, log and backup schedules can vary by record and production configuration.

The in-app deletion flow requests deletion of the SiteLog backend account, clears local Drift data and signs out. Backend deletion removes database records through relationship cleanup and attempts to remove associated uploaded files after the database change. File cleanup is best effort and residual copies can persist temporarily in backups or provider systems.

The current flow does not itself delete the separate Firebase Authentication identity or cancel a Google Play subscription. Users should manage subscriptions in Google Play and can contact [email protected] for identity or residual-data assistance. Provider security logs, support communications, purchase records and backup copies follow their applicable retention rules.

Security

Safeguards include HTTPS or TLS in transit, provider-issued identity tokens, App Check attestation, authenticated API access, database access controls, device sandboxing, cryptographically random public-link tokens stored as hashes, expiry and revocation controls, and separation of local queues from server operations.

No system can promise complete security. Users should protect their device and Google account, keep the app updated, restrict site photographs and signatures to what is necessary, review visible GPS stamps, and report suspected unauthorized access promptly.

Your Rights

Depending on location and circumstances, a person may have rights to know or access personal data, correct it, receive a portable copy, delete it, restrict or object to processing, withdraw consent, opt out of qualifying sale or targeted advertising, and raise a concern with a privacy authority. SiteLog does not sell personal data or use project content for targeted advertising.

Users can edit many records, control permissions through device settings, revoke public links, use available exports and start in-app account deletion. For personal data entered by a contractor or employer, contact that organization first when practical because it controls the construction record.

To submit a request, email [email protected]. Blue Sparrow may verify identity, account access and authority before acting. Requests are handled within applicable timeframes and without unlawful discrimination. An authorized representative may be asked to show authority.

Children

SiteLog is a professional construction tool and is not directed to children. Blue Sparrow does not knowingly invite a child to create an operator account. Project notes or photos could incidentally include a minor; users must avoid collecting or sharing a minor's information unless it is necessary, appropriate, permitted and accompanied by any required guardian notice or permission.

If a parent or guardian believes a child's information was handled improperly, contact [email protected] so it can be reviewed and removed where appropriate.

International Transfers

Blue Sparrow is operated from India, Blue Sparrow-controlled synchronized content is intended for European Union infrastructure subject to production confirmation, and providers can process limited information in other countries. Privacy protections differ between regions.

Where safeguards are required, Blue Sparrow relies on available measures such as contractual protections, provider data-protection terms, recognized adequacy arrangements or consent where appropriate. The rights and contact channel in this policy remain available globally.

Changes

Blue Sparrow may update this policy when SiteLog, its providers or applicable requirements change. The updated date will change, and material changes may also be announced in the app or on https://bluesparrow.dev. Additional notice or consent will be provided where required.

Contact

Blue Sparrow is operated by a solo developer based in India.

  • Privacy and data requests: [email protected]
  • General support: [email protected]
  • Website: https://bluesparrow.dev

Email provides a practical way to verify and track requests without publishing additional contact details.

Questions about this document? Email [email protected].

Blue Sparrow website
Facebook Email Terms Privacy
© 2026 BlueSparrow Labs. All rights reserved.