Privacy Policy
Effective Date: September 3, 2026
Welcome to DueProof. We respect your privacy and have designed our application from the ground up with a “Privacy-First, Local-First” architecture. This Privacy Policy explains how we collect, use, and protect your information.
1. Our Privacy Philosophy
Unlike traditional apps, we do not force you to register an account to start using our core features. Your personal metadata is stored securely on your device, giving you complete data sovereignty.
2. Information We Collect
A. Local-First Storage (Data on Your Device)
Your detailed behavioral tags, usage history, and personal preferences are stored locally on your device using SQLite. This data never leaves your phone in an identifiable format.
B. Anonymized Cloud Data
- Anonymized Tag Aggregation (only while Personalized Recommendations is ON): We periodically upload a summary of your interest tags (e.g., “fitness”, “travel”) for matching and anonymous audience sizing. These tags are linked only to an anonymous UUID and are never connected to your real identity. With the feature off, this upload does not happen at all.
- Behavioral Summary (only while Personalized Recommendations is ON): Aggregated usage metrics (tag counts, activity patterns) are uploaded alongside tag data, including any interest requests you typed on an opportunity card (the text only — never any card content). These are anonymous summaries.
- District-Level Location: We do not collect or store precise GPS coordinates. If you grant location permissions, we only convert your location into a broad district-level hash (e.g., TW_taipei_daan).
- No Cross-App Tracking: We never ask for tracking permission, and the ad SDK we use serves non-personalized ads only (see Section 4). Nothing links your activity in DueProof to other apps or websites.
C. AI Processing
When you use AI OCR or Vision features, images are sent securely (HTTPS/TLS) to our AI providers for immediate analysis. Zero Retention: Images are deleted immediately after processing and are not used to train AI models.
AI Support Assistant: messages and any screenshots you send to the in-app assistant (“DueProof Assistant”) are forwarded to OpenAI to generate the reply, under the same no-training terms. The conversation is stored with your support ticket so a human can follow up. Please do not type passwords, card numbers or other sensitive personal data into the chat.
D. Personalized Recommendations
- Activity titles and text summaries are sent securely to our AI provider for interest matching.
- Anonymous interest tags describe what type of person you resemble, not who you are.
- Health-related tags are never used for advertising matching (GDPR Article 9 compliance).
- You can enable or disable this feature at any time in Settings. Turning it off immediately stops all uploads and AI analysis calls, and deletes the aggregated data already on our servers (if you are offline, the deletion completes on the next connection). Your device keeps organizing interest tags locally only — they never leave your phone while the feature is off, and exist solely so that re-enabling restores recommendations instantly.
E. P-Points and In-App Purchases
Transaction records are stored on our servers, linked to your anonymous UUID. In-App Purchases are processed entirely by Apple/Google. We do not process or store your payment card information.
F. AI Phone Reminders
If you opt-in, your phone number is stored securely (encrypted at rest) to enable reminder calls via third-party telephony providers. You can unbind your phone number at any time.
G. Marketplace Activity
- When you browse the marketplace, we record which listings you view, save, share or message about, under your anonymous identifier, to recommend similar listings. These records are not linked to your email or phone number and are deleted after 45 days.
- This applies whenever you use the marketplace and is separate from the Personalized Recommendations setting above, which governs interest-tag uploads only.
3. How We Use Your Information
- Pair you with relevant local events, flash sales, or merchants.
- Display “Opportunity Cards” matched to your anonymous interest tags. Matching is performed entirely on your device.
- Improve app stability by collecting anonymized crash logs.
- We do NOT sell your personal data.
4. Third-Party Services
- Supabase: Secure cloud database and authentication.
- AI Providers (OpenAI/Anthropic/Google): For intelligent data extraction. Our enterprise agreements prohibit data use for model training.
- Apple/Google: In-App Purchase processing.
- Sentry: Crash and performance diagnostics (stack traces, device model, OS version). Text and images are masked in the short screen replay captured around a crash; no name or email is attached.
- PostHog: Product analytics (which screens and features are used), keyed to an anonymous identifier. Never used for advertising.
- Google AdMob: Serves the banner ad shown to free-tier users. We request non-personalized ads only and do not ask for tracking permission; to deliver and measure ads the SDK receives device information such as device model, an app-scoped device identifier, and the approximate location derived from your IP address.
- hCaptcha: Bot protection when signing in.
- Twilio: Phone reminder call delivery.
5. Data Security
All data transmitted between your device and our servers is encrypted using HTTPS/TLS. Sensitive data is encrypted at rest. No raw personal data is permanently stored on our servers.
6. Data Retention and Deletion
- Local Data: Deleting the app immediately destroys all local data.
- Cloud Account: You can permanently delete your account and all associated data in Settings > Account > Delete Account — or request deletion without installing the app at dueproof.app/account/delete.
7. Children's Privacy
DueProof is not intended for children under the age of 13.
8. Contact Us
If you have questions about this Privacy Policy, please contact us at: privacy@dueproof.app
隱私權政策
生效日期:2026年9月3日
歡迎使用 DueProof(拍即丟)。我們非常重視您的隱私,並從底層打造了「隱私優先、本地優先」的架構。
1. 我們的隱私哲學
與傳統 App 不同,我們不強迫您註冊帳號即可使用核心功能。您的個人行為中介資料皆安全地儲存於您的設備上。
2. 我們收集什麼資料
A. 本地優先儲存
您的詳細行為標籤、使用歷史與個人偏好,皆使用 SQLite 儲存於您的手機本地端。這些資料永遠不會以可識別的格式離開您的手機。
B. 匿名化雲端資料
- 匿名標籤聚合(僅在開啟「個人化推薦」時):定期上傳興趣標籤摘要,僅連結至匿名 UUID;未開啟時此上傳完全不會發生。
- 行為摘要(僅在開啟「個人化推薦」時):聚合的使用指標,含您在情報卡上輸入的需求文字(僅文字本身),為匿名摘要。
- 行政區級位置:絕不收集精確 GPS 座標,僅轉換為行政區級雜湊值。
- 無跨 App 追蹤:我們不會向您索取追蹤權限,廣告 SDK 只投放非個人化廣告(見下方 F)。
C. AI 處理
當您使用拍照辨識時,該張圖片會透過 HTTPS/TLS 加密傳送給下列第三方 AI 服務進行辨識:
- Google Cloud Vision(Google LLC):文字辨識(OCR)。
- OpenAI(OpenAI, L.L.C.):理解單據內容,抽取到期日、金額與品項。
- Google Gemini(Google LLC):上述服務失敗時的備援辨識。
零保留原則:處理後立即刪除;我們與上述供應商的企業合約禁止將您的資料用於訓練 AI 模型。 首次拍照辨識前,App 會先明確告知並徵求您的同意; 您可以拒絕,改用手動建立卡片(完整的倒數與提醒功能不變,且不會上傳任何內容), 也可以隨時於「設定 → 拍照辨識(AI)」關閉。
D. 個人化推薦
- 產出匿名興趣標籤,描述「您像哪一類人」,而非「您是誰」。
- 健康相關標籤絕不用於廣告配對(符合 GDPR 第 9 條)。
- 可隨時在設定中啟用或停用。停用即停止所有上傳與 AI 分析,且伺服器上既有的彙總資料會立即刪除(離線時於下次連線自動完成)。裝置仍會在本機整理興趣標籤—— 這些資料不會離開您的手機,僅為重新開啟時能立即恢復。
E. 市集活動
- 當您瀏覽市集時,我們會以您的匿名識別碼記錄您瀏覽、收藏、分享或發起聊天的刊登, 用來推薦相似的刊登。這些記錄不會連結到您的電子郵件或手機號碼,並在 45 天後刪除。
- 此項記錄在您使用市集時即會發生,與上述「個人化推薦」開關無關—— 該開關僅控制興趣標籤的上傳。
F. 其他第三方服務
- Sentry:當機與效能診斷(錯誤堆疊、裝置型號、系統版本)。 當機前數秒的畫面回放會遮蔽所有文字與圖片,且不附帶姓名或 Email。
- PostHog:產品使用分析(哪些畫面與功能被使用), 以匿名識別碼記錄,絕不用於廣告。
- Google AdMob:向免費版用戶投放首頁橫幅廣告。 我們只請求非個人化廣告,也不會向您索取追蹤權限; 為了投放與計量,SDK 會取得裝置型號、App 範圍的裝置識別碼, 以及由 IP 推估的大致位置。
- hCaptcha:登入時的機器人防護。
- Supabase:雲端資料庫與帳號驗證;Apple / Google:App 內購買處理。
3. 資料安全
所有傳輸皆透過 HTTPS/TLS 加密。敏感資料採靜態加密儲存。
4. 資料刪除
- 本地資料:刪除 App 即銷毀所有本地資料。
- 雲端帳號:可在設定中永久刪除帳號與所有關聯資料;或不安裝 App 直接於 dueproof.app/account/delete 申請刪除。
5. 聯絡我們
隱私相關問題請聯絡:privacy@dueproof.app