1. Who we are
Innologica Ltd, Sofia, Bulgaria ("we", "us"), is the data controller for the Proofy app and the website at getproofy.com. You can reach us at [email protected].
2. What Proofy does
Proofy lets you prove that a photo existed, unchanged, at a specific moment. When you take a photo in the app, a cryptographic fingerprint (SHA-256) of the file is sent to our server and time-stamped. The photo itself is uploaded only if you choose to share a link to it.
3. Data we process
3.1 When a photo is registered (every photo taken in the app)
- The SHA-256 fingerprint of the photo file, its size, type and pixel dimensions.
- The registration time as measured by our server, and the time elapsed since capture as measured by your device.
- Your device's wall-clock time and time zone at capture (used for diagnostics and for displaying local time).
- An anonymous device identifier created on first launch, together with the device model, operating-system version and app version. The identifier is backed by the device-attestation service of the phone's operating system (Apple App Attest on iPhone) and cannot be linked to your Apple or Google account by us.
- The IP address of the request, which is deleted after 30 days.
- Optionally, if you switch location on: latitude, longitude, accuracy, altitude and the age of the fix. We derive a coarse place label (city, country) from the coordinates.
3.2 When you share a proof
- The original photo file, which we verify against the registered fingerprint and store unchanged.
- Watermarked copies of the photo in reduced sizes, which are shown on the public proof page and in link previews.
- An optional note you write for the public page.
- The number of times the public page was viewed.
- The kind of app you shared the link to (for example "WhatsApp" or "copy link"), so we can improve the sharing experience. No content of your messages is ever seen by us.
3.3 When you visit the website
- Standard server logs (IP address, requested page, browser type, time), kept for 14 days for security and troubleshooting.
- On the Verify page, the fingerprint of the file you check is computed in your browser; only the fingerprint is sent to us. The file never leaves your device.
- If you use the support form: your name, e-mail address and message.
We use no cookies except one session cookie in the administrative area that is not available to the public. We use no third-party analytics, advertising or tracking of any kind.
4. Purposes and legal bases
- Providing the service — registering fingerprints, storing and displaying shared photos, answering verification requests. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
- Security and abuse prevention — device attestation, rate limiting, server logs. Legal basis: our legitimate interest in running a trustworthy service (Art. 6(1)(f)).
- Location — only when you enable it. Legal basis: your consent (Art. 6(1)(a)), which you can withdraw at any time by switching location off; earlier registrations keep the location they were made with until you unpublish them.
- Support — answering your requests. Legal basis: legitimate interest and, where applicable, contract.
- Product improvement — which share targets are used. Legal basis: legitimate interest; the data is not personal beyond the anonymous device identifier.
5. Retention
- Fingerprints, registration times and signed receipts are kept for as long as the service exists, because their purpose is to remain checkable. They contain no image content.
- Original photos and their watermarked copies are kept until you unpublish the proof. Unpublishing deletes the files immediately; backups are overwritten within 30 days.
- IP addresses are deleted 30 days after the request.
- Support e-mails are kept for up to 12 months.
6. Recipients and transfers
Data is stored on servers operated for us in the European Union. We share data only with providers strictly necessary to run the service (hosting; the device-attestation service of the phone's operating system — Apple App Attest on iPhone — for device verification; a map-tile and reverse-geocoding provider, OpenStreetMap, which receives only the coordinates you chose to attach). Public proof pages are, by their nature, visible to anyone who has the link. We do not sell data.
7. Your rights
Under the GDPR you may ask us for access to, correction or deletion of your personal data, restriction of or objection to its processing, and data portability. Because the app is anonymous, please contact us from the device concerned or quote the Proof IDs involved so that we can identify the records. You may also lodge a complaint with a supervisory authority, in particular the Commission for Personal Data Protection of the Republic of Bulgaria (cpdp.bg).
You can unpublish any proof yourself from the app at any time. Unpublishing removes the photo and its copies; the fingerprint and time-stamp remain so that the proof page can truthfully say that a registration existed and was withdrawn by its owner.
8. Children
The service is not directed at children under 16, and we do not knowingly collect their data.
9. Changes
We will post changes to this policy on this page and update the date above. Material changes will also be announced in the app.