SiteLog Privacy Policy
How SiteLog handles local field records, synchronized content, location-stamped photos, dictation and intentional sharing.
SiteLog is a local-first construction logging service operated by Blue Sparrow. This policy explains the information involved in the mobile app, synchronized services and recipient-facing pages, with practical choices for users and the people represented in their records.
Overview
Blue Sparrow operates SiteLog as a solo developer based in India. SiteLog helps construction professionals create local field records, synchronize supported content, produce reports, and intentionally share selected daily logs, proof packets and handoff packs.
Blue Sparrow applies privacy principles reflected in the EU General Data Protection Regulation, the United Kingdom GDPR, privacy laws in the United States including applicable state rights, India's Digital Personal Data Protection framework, and other applicable regional requirements. This describes an operational commitment and is not a regulatory certification.
Blue Sparrow does not sell or rent personal data and does not use SiteLog project content for targeted advertising.
Data We Handle
Account data can include a Firebase identifier and Google-provided name, email address and profile image. Business and project content can include company details and logos, project names, addresses, contacts, crew and subcontractor details, labor information, daily activities, equipment, materials, deliveries, weather, delays, visitors, safety observations and private notes.
Files and evidence can include captured or imported photos, captions, visible photo stamps, signatures, generated PDFs, exports, proof packets, handoff packs, acknowledgement names and titles, and an optional acknowledgement signature file. A user can choose to place precise latitude and longitude visibly into the pixels of a captured photo. Uploading or sharing that photo also shares the visible coordinates; removing file metadata later does not remove a stamp already drawn into the image.
User-triggered dictation uses the device's configured speech-recognition service. SiteLog receives the resulting transcript and adds it to the editable text field. SiteLog does not intentionally retain the microphone audio, but the operating system or speech provider may process audio on the device or through its cloud services under device settings and provider terms. Saved transcript text becomes ordinary SiteLog content and can synchronize or be shared.
Technical data can include device ID, platform, app version, locale, timezone, push-permission state, Firebase Cloud Messaging token, synchronization operations, timestamps, request identifiers, quotas, entitlement state, and security or error records. Public delivery activity can include opening and download times, IP address, user agent, requested resource, acknowledgement activity and security outcomes.
How We Use Data
Information is used to authenticate accounts, operate projects and daily logs, maintain the local-first synchronization outbox, upload and retrieve files, generate documents, provide public delivery and acknowledgement flows, deliver notifications, enforce plan limits, verify purchases, respond to support, prevent misuse and maintain service reliability.
If a user requests weather autofill, SiteLog sends current or last obtained latitude and longitude to Open-Meteo to retrieve local weather. Android requests foreground fine or approximate location rather than background-location access. Location may also be used when the user chooses GPS photo stamping.
Depending on the context, processing is based on providing the requested service, the user's choices or consent, legitimate operational and security needs, a business user's instructions, or an applicable obligation. Permissions can be changed in device settings, although affected functions may stop working.
Storage and Residency
SiteLog keeps the working database and queued files in the app's device sandbox. Android application backup is disabled and the checked-in backup rules exclude the app database, files and preferences, although device and operating-system behavior can change outside Blue Sparrow's control.
Blue Sparrow-controlled synchronized records, uploaded files and service backups are intended to remain in European Union infrastructure, subject to confirmation of the active production and backup deployment. This qualified intention does not apply to every provider or every item of data.
Blue Sparrow is operated from India and support access can occur from India. Google, Firebase, RevenueCat, Open-Meteo, platform speech recognition, mail, store and other providers may process limited identity, notification, billing, location-request, audio, communication or security data in other regions under their own infrastructure and applicable safeguards.
Public Links
SiteLog can create high-entropy, tokenized links for selected daily logs, proof packets and handoff packs. The service stores a hash of the secret token. Links can have an optional expiry and can be revoked, but anyone who obtains a working URL may access the content permitted by it.
Shared material can include project and site information, log entries, photos, visible GPS stamps, signatures, PDFs and handoff details. Handoff acknowledgement can collect a recipient's name, optional title and optional signature file. Delivery services can record opening, download and acknowledgement activity, including IP address and user agent.
Unlisted or tokenized does not mean confidential or impossible to discover. A recipient can forward, copy, download or capture content, and SiteLog does not currently promise that every public page carries effective search-exclusion controls. Users should review content and recipients, use expiry where available, revoke links promptly and avoid sharing unnecessary personal or sensitive information.
Retention
Local records remain until removed through app controls, account deletion, app-data clearing or uninstalling, subject to device behavior. Synchronized records and files generally remain while needed to provide the account and for limited periods afterward for deletion processing, security, service recovery, backup rotation, support, billing records or other valid operational needs. Exact public-access, log and backup schedules can vary by record and production configuration.
The in-app deletion flow requests deletion of the SiteLog backend account, clears local Drift data and signs out. Backend deletion removes database records through relationship cleanup and attempts to remove associated uploaded files after the database change. File cleanup is best effort and residual copies can persist temporarily in backups or provider systems.
The current flow does not itself delete the separate Firebase Authentication identity or cancel a Google Play subscription. Users should manage subscriptions in Google Play and can contact [email protected] for identity or residual-data assistance. Provider security logs, support communications, purchase records and backup copies follow their applicable retention rules.
Security
Safeguards include HTTPS or TLS in transit, provider-issued identity tokens, App Check attestation, authenticated API access, database access controls, device sandboxing, cryptographically random public-link tokens stored as hashes, expiry and revocation controls, and separation of local queues from server operations.
No system can promise complete security. Users should protect their device and Google account, keep the app updated, restrict site photographs and signatures to what is necessary, review visible GPS stamps, and report suspected unauthorized access promptly.
Your Rights
Depending on location and circumstances, a person may have rights to know or access personal data, correct it, receive a portable copy, delete it, restrict or object to processing, withdraw consent, opt out of qualifying sale or targeted advertising, and raise a concern with a privacy authority. SiteLog does not sell personal data or use project content for targeted advertising.
Users can edit many records, control permissions through device settings, revoke public links, use available exports and start in-app account deletion. For personal data entered by a contractor or employer, contact that organization first when practical because it controls the construction record.
To submit a request, email [email protected]. Blue Sparrow may verify identity, account access and authority before acting. Requests are handled within applicable timeframes and without unlawful discrimination. An authorized representative may be asked to show authority.
Children
SiteLog is a professional construction tool and is not directed to children. Blue Sparrow does not knowingly invite a child to create an operator account. Project notes or photos could incidentally include a minor; users must avoid collecting or sharing a minor's information unless it is necessary, appropriate, permitted and accompanied by any required guardian notice or permission.
If a parent or guardian believes a child's information was handled improperly, contact [email protected] so it can be reviewed and removed where appropriate.
International Transfers
Blue Sparrow is operated from India, Blue Sparrow-controlled synchronized content is intended for European Union infrastructure subject to production confirmation, and providers can process limited information in other countries. Privacy protections differ between regions.
Where safeguards are required, Blue Sparrow relies on available measures such as contractual protections, provider data-protection terms, recognized adequacy arrangements or consent where appropriate. The rights and contact channel in this policy remain available globally.
Changes
Blue Sparrow may update this policy when SiteLog, its providers or applicable requirements change. The updated date will change, and material changes may also be announced in the app or on https://bluesparrow.dev. Additional notice or consent will be provided where required.
Contact
Blue Sparrow is operated by a solo developer based in India.
- Privacy and data requests: [email protected]
- General support: [email protected]
- Website: https://bluesparrow.dev
Email provides a practical way to verify and track requests without publishing additional contact details.