Privacy Policy
This policy explains what SiteProof collects when you use the service, how we use it, when we share it, and the rights you have over your data.
1. Information We Collect
We collect the minimum information needed to run SiteProof and produce your client-ready reports:
- Account information: your name, email address, and password (stored hashed) when you create an account.
- Report content: the photos, voice or typed notes, captions, severity tags, and other assets you upload into a report.
- Payment metadata: billing handled by Stripe — we receive the plan you chose, the last four digits of the card, and the charge status. We never see or store full card numbers.
- Device and log data: IP address, browser type, and basic usage events for security, fraud prevention, and diagnosing service problems.
2. How We Use Your Information
We use the information we collect to provide and improve the SiteProof service, generate the reports you create, process your subscription through Stripe, and communicate with you about your account and reports.
When you use the AI-assisted damage-notes feature, the photos and any short captions you attach are sent to our AI provider so it can draft condition notes, severity tags, and suggested next steps. Drafts stay on your account until you save or discard them; we do not use your photos or reports to train third-party AI models.
We also send transactional email — receipts, report-delivery notifications, and service notices tied to your use of SiteProof. We do not send marketing email without your consent.
3. How We Share Your Information
We never sell your information. We share it only with the parties listed below, and only to the extent needed to run the service:
- Stripe, our payment processor, to handle subscription charges, invoices, and refunds. Stripe handles card data under its own privacy policy.
- Our AI provider, strictly to draft damage notes from the photos and short captions you attach in a report. The provider only processes the content of the active draft.
- The report's intended recipient, when you explicitly send a report. The recipient sees the content of that report and nothing else about your account.
- Legal authorities, if we receive a valid subpoena, court order, or other legal process — or to investigate suspected violations of our terms.
4. Your Rights (CCPA / GDPR)
Depending on where you live, you have some or all of the rights below. We honor these rights for every SiteProof user regardless of jurisdiction.
- Access — request a copy of the personal data we hold about you.
- Correction — ask us to fix inaccurate account or report data.
- Deletion — ask us to delete your account, reports, and associated personal data.
- Portability — receive your data in a machine-readable format.
- Opt out of "sale" — SiteProof does not sell personal data, but California residents may submit a formal opt-out request and we will honor it.
- Lodge a complaint with your local data-protection authority if you believe we have mishandled your data.
To exercise any of these rights, email siteproof-5@polsia.app. We respond within 30 days.
5. Contact Us
Questions about this policy, your data, or your rights? Email siteproof-5@polsia.app and we'll get back to you.
Last updated: 2026-07-16