Privacy Policy
Last updated: August 17, 2026
Overview
proofit ("the App") is a sourdough baking companion developed by an independent developer. Your privacy matters. This policy explains what data the App collects, how it is used, and your rights.
Data Stored on Your Device
proofit is local-first. Baking data such as starters, feeding logs, recipes, bake history, timers, inventory, and settings is stored locally on your device using AsyncStorage. This data stays on your device unless you explicitly use online features such as recipe import, sharing, AI features, or optional Cloud Sync.
Optional Account and Cloud Sync
You can create an optional proofit account using email, Google, or Apple sign-in. If you enable Cloud Sync, proofit stores structured app data in Supabase so it can be backed up and restored on your devices. Synced data can include starters, feeding history, starter events, recipes, recipe folders, completed bakes, active bakes, flour inventory, availability, equipment, unit preferences, flour region, language, and theme. Premium Cloud Sync can also back up recipe and bake photos.
Camera and Photo Library
The App may request access to your camera and photo library to scan recipes via OCR, import recipe images, or capture photos of your bakes. Images selected for OCR or recipe import are processed on-device or sent to our OCR processing service solely to extract recipe text and are not retained after processing. If you choose to create a public shared recipe link with a recipe photo, that photo may be uploaded and stored with the shared recipe so the link can display it.
Notifications
The App may request permission to send local push notifications for baking timers and starter feeding reminders. These notifications are scheduled entirely on your device and do not involve any external server.
OCR and URL Import
When you use the recipe import feature (OCR or URL), the image or URL is sent to a Supabase Edge Function for processing. The data is used solely to extract recipe information and is not retained after the response is returned.
Analytics and Tracking
proofit uses PostHog for product analytics, crash diagnostics, and sampled session replay so we can understand feature usage, detect failures, debug user experience issues, and improve the app. Analytics may include app events, screens, device/app metadata, error information, and replay data such as a wireframe-style view of app interactions, taps, and navigation. Text fields, text content, images, system views, console logs, and network telemetry are masked or disabled in our app configuration.
proofit also uses the Meta SDK and RevenueCat Meta Ads integration for app install attribution and campaign performance measurement. On iOS, advertiser tracking and access to the advertising identifier are disabled unless you grant permission through Apple's App Tracking Transparency prompt. proofit does not show third-party ads and does not use Facebook Login.
Community
proofit has an optional in-app community where you can share bakes and ask for help. Taking part requires a proofit account and a public display name that you choose. If you use the community, we store the following data in Supabase (EU): your display name, the posts you publish (title, text, photos, and the recipe and bake data you choose to attach), your replies, likes and saved posts, the reports you submit, the users you block, and, if you enable notifications, a push token for your device. We also store when you accepted the community guidelines and which version of them you accepted.
Posts, replies, and your display name are visible to all community members. Reports and blocks are only visible to you and to us. Recipe and bake data attached to a post is a snapshot at the time of posting. That snapshot includes the source of the recipe (the category and the text you entered, for example a book with author and title). The source is published together with your post and stays in the snapshot, so it travels with the recipe when another member saves it.
To keep the community safe, new posts and replies are automatically checked by an AI moderation service (OpenAI moderation endpoint) before they are published, and reported content is reviewed manually. Moderation decisions, reports, and related events are logged for accountability. Content that violates the community guidelines can be hidden or removed and accounts can be banned. If a rights holder contacts us by email about content in the community, we store that message together with the details it contains (such as the link to the post and the work concerned) for as long as we need it to handle the case and to document the decision.
You can delete your own posts and replies at any time; photos are deleted from storage immediately. Deleting your proofit account removes your community profile, display name, blocks, notifications, and push tokens; your posts are deleted (photos immediately, the remaining post data within 30 days) and your replies are anonymized so they no longer carry your name. Reports you submitted are anonymized. See our community guidelines.
Third-Party Services
The App uses Supabase for authentication, Cloud Sync, shared recipes, and Edge Functions for recipe OCR/URL processing; PostHog for product analytics, crash diagnostics, and sampled session replay; RevenueCat for subscription entitlement management and Meta Ads attribution forwarding; Meta for app install attribution and campaign measurement; and Apple or Google for sign-in and subscription processing where applicable. We do not sell your personal data, show third-party ads, or use Facebook Login.
Relevant third-party privacy policies: Supabase, PostHog, RevenueCat, Meta, Apple, Google.
Data Retention and Deletion
Local app data can be deleted by clearing the app data or uninstalling the app. Cloud Sync data remains in your proofit account until you delete your cloud account in the app or contact us for deletion. Deleting your cloud account removes your Supabase Auth account and private synced cloud backup; local data on your device remains unless you delete it separately.
Your Rights
Depending on your location, you may have rights to access, correct, export, restrict, object to, or delete personal data we process. You can contact us to exercise these rights. You can also disable Cloud Sync or delete your cloud account from the app settings.
Children's Privacy
The App is not directed at children under 13. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date.
Contact
If you have questions about this privacy policy, please contact us at proofit.feedback@proton.me.