Effective and last updated: August 14, 2026

Privacy Policy for Proofly on iOS

This Privacy Policy explains how Proofly ("we," "us," "our") collects, uses, shares, and retains information when you use the Proofly iPhone or iPad app, its Safari extension, your Proofly account, shopping research features, saved history, and Proofly Pro subscriptions. Reading this policy helps you understand what data leaves your device, where it goes, and what controls you have.

1. Scope

This policy applies to the Proofly iOS app (bundle ID com.downlabs.proofly) and its Safari Web Extension (com.downlabs.proofly.Extension). It does not cover third-party websites or services you visit using Safari or Proofly's research sources. Those services have their own privacy policies.

2. Information we collect and why

Category Specific data Why we collect it Where it is stored
Account information Email address, hashed password (stored by Firebase), account UID, display name, optional profile photo (base64-encoded), onboarding selections, and legal acceptance timestamps. Create and authenticate your Proofly account; sync preferences between the app and Safari extension; provide account management controls. Firebase Authentication and Firestore (Google Cloud); Apple Keychain (access token only); App Group shared storage (session token shared with the extension).
Shopping research context Product title, product-page URL, website domain, visible product metadata, your search query, selected research sources, requested post and comment depth, and the time a research check was started. Run the research job you request, identify the product across sources, return relevant results, and maintain your research history. Device local storage (chrome.storage.local in the extension); Firebase Firestore (your account's cloud history); Firebase Functions (during processing only).
Public source content Publicly visible post text, comment text, captions, video titles and descriptions, public author or channel names, public engagement counts (likes, views), timestamps, and source URLs from the research sources you select (Reddit, YouTube, TikTok, Instagram, X, and others). Identify relevant buyer discussions, produce summaries, detect repeated signals, and provide source references in your results. Processed in-memory on your device during the research job. A compact summary version (up to 250 posts, 20 replies per post) is stored in Firebase Firestore as part of the shared research cache described in Section 4.
AI processing payload Product name, product URL, research query, and relevant public post excerpts (text and source URL only — no social login credentials, private messages, or passwords). Generate AI-assisted product summaries, sentiment analysis, repeated concerns, and decision insights using OpenAI via our secure Firebase Cloud Functions relay. Sent from your device to Proofly's Firebase Cloud Functions (Google Cloud, United States), which forward the payload to OpenAI's API. OpenAI does not retain API inputs for training by default. Results are stored in Firebase Firestore as part of your research history.
Research results and shared cache Generated summaries, sentiment scores, source cards, cached frontendData, product signals, source references, and usage counts. Deliver results instantly; allow the app to sync your history; avoid repeating the same research job for the same product within a shared result cache (see Section 4 for details). Firebase Firestore under a shared cache collection keyed by normalized product query. Retained for up to 90 days or until you delete your account.
Safari extension state Extension connection status, selected platform authentication signals (whether you appear signed in to a source — not the credential itself), and extension-to-app heartbeat data. Display extension status in the app; guide you through setup; synchronize entitlement and settings between the app and Safari extension. App Group shared UserDefaults (group.com.downlabs.proofly) — on-device only.
Subscription and purchase data Apple product identifier, RevenueCat app user ID, entitlement name, subscription status (active/expired/cancelled), purchase date, renewal date, expiration date, and active plan name. Offer Proofly Pro; verify active subscriptions; restore purchases; unlock paid features; prevent duplicate access; share entitlement status with the Safari extension. RevenueCat servers; Firebase Firestore (entitlement snapshot); Apple Keychain (entitlement token); App Group shared storage (extension-readable entitlement).
Usage counts Number of product checks used in the current billing period, monthly limit, and reset date. Apply plan limits, display remaining usage, and prevent quota abuse. Firebase Firestore and chrome.storage.local in the extension.
Profile photo Image data you select from your photo library, stored as a base64-encoded data URL. Display your profile image in the app. Firebase Firestore (your account document). Your photo library is accessed only when you explicitly tap the profile photo button. We do not access your library at any other time.
Support and diagnostics Support emails you send, error messages, app version, service logs, operational timestamps, and security signals. Respond to support requests, diagnose failures, prevent fraud, secure accounts, and maintain service reliability. Email correspondence (support@proofly.im); Firebase operational logs (retained up to 30 days).

3. Safari website access and source accounts

The Safari extension requires website access that you grant in iOS Settings → Safari → Extensions → Proofly. You can set access to "Ask," "Allow for One Day," or "Always Allow" and can revoke access at any time. Proofly injects its research overlay only when you activate it on a product page; it does not read or transmit page content from sites where you have not triggered a research job.

When you start a product check, the extension may temporarily open background Safari tabs for your selected research sources. These tabs are closed as soon as each source's collection step completes. Proofly reads only the publicly visible content those tabs load. It does not read private messages, direct messages, account settings, or content behind a login that requires your password — it uses only what your existing signed-in Safari session already makes visible on-screen.

Proofly does not store, transmit, or share your third-party social media passwords, authentication tokens, or session cookies with our servers. Authentication status is detected only from visible page signals and is stored locally on-device.

4. Shared research cache — how it works and what it means for you

To avoid unnecessary repeated processing and reduce costs, Proofly uses a shared research cache in Firebase Firestore. When a research job completes, a compact version of the results (post summaries, sentiment, source references — up to 250 posts per product) is stored under a normalized product query key accessible to all authenticated Proofly users.

This means that if another Proofly user has already researched the same product, you may receive cached results from that earlier job rather than triggering a new research run. Cached results are anonymous — no user identity or account information is stored with the cached product data. Cached results expire after 90 days. You can force a fresh research run by using the "Refresh" option in the app.

This shared cache is disclosed here because it means that public-source content collected during your research session may be used to serve results to other users of the service, in de-identified, aggregated form.

5. Third-party service providers

Proofly does not sell personal information and does not use your information for third-party advertising. We share data with the following service providers only as necessary to operate the service:

Provider Purpose Data shared Their privacy policy
Google Firebase (Google LLC) Firebase Authentication (account login), Firestore (database), Cloud Functions (server-side logic including AI relay), and Cloud Storage (if applicable). Email address, account UID, research history, subscription snapshot, usage counts, research results, and operational logs. firebase.google.com/support/privacy
OpenAI (OpenAI, LLC) AI-assisted product summarization, sentiment analysis, decision insights, and natural-language Q&A about research results. Requests are proxied through Proofly's Firebase Cloud Functions — OpenAI never receives your Proofly account credentials. Product name, product URL, research query, and relevant public post excerpts (text and source URL). No social media passwords, private messages, or personal communications are ever sent. openai.com/policies/privacy-policy
RevenueCat (RevenueCat, Inc.) Subscription entitlement management, purchase validation, restore-purchases flow, and the in-app Customer Center for subscription management. RevenueCat app user ID (linked to your Proofly account UID), Apple product identifier, subscription status, purchase date, renewal date, and expiration date. revenuecat.com/privacy
Apple Inc. App Store distribution, In-App Purchase billing, StoreKit receipt validation, subscription lifecycle management, and platform services. Apple product identifier, purchase receipt, and billing information handled entirely by Apple. apple.com/privacy
Google Favicon API Fetching website favicons for display in your research history list (e.g., the small icon next to "amazon.com"). The domain name of the product-page URL (e.g., "amazon.com") is sent to https://www.google.com/s2/favicons to retrieve the site icon. No account information is sent. policies.google.com/privacy
Google Fonts Loading the Outfit typeface for the app's web-based extension interface. Your IP address may be logged by Google when the font is loaded. No personal information from your Proofly account is shared. policies.google.com/privacy

6. AI-assisted processing — what is sent and when

AI features in Proofly include automatic product summarization (runs after a research job completes), decision insights, sentiment classification, and optional Q&A chat about your results.

What is sent to OpenAI via our Firebase relay:

What is never sent to OpenAI:

OpenAI processes inputs to return AI-generated text responses only. By default, OpenAI does not use API inputs for model training. The AI relay runs inside Proofly's authenticated Firebase Cloud Functions — your OpenAI requests do not originate directly from your device.

If you do not wish to use AI-assisted features, you can disable them in Settings. Basic research results (source list, post excerpts, and sentiment signals) are available without AI processing.

7. Data retention periods

Data type Retention period How to delete earlier
Account information (email, display name, profile photo) Retained while your account is active. Delete your account from Account → Delete account in the app.
Research history and results Retained while your account is active, up to the history limit shown in the app. Delete your account, or contact support@proofly.im to request earlier removal.
Shared research cache (de-identified) Up to 90 days from the date of the research job. Cache entries expire automatically. Deleting your account does not remove shared cache entries because they contain no personal information.
Subscription and entitlement data Retained as long as legally required for accounting, dispute resolution, and fraud prevention (typically up to 7 years for financial records). Account deletion removes the entitlement snapshot; billing records are controlled by Apple and RevenueCat.
Usage counts Reset monthly; retained for up to 13 months for billing and fraud prevention. Deleted when your account is deleted.
Support correspondence Up to 3 years or as required for dispute resolution. Contact support@proofly.im to request deletion of support records.
Operational and security logs Up to 30 days in Firebase operational logging. Expires automatically.
OpenAI request payloads Not retained by Proofly after the response is received. Subject to OpenAI's data retention policy (see openai.com/policies/privacy-policy). N/A — not stored by Proofly.
Local device data (extension storage, Keychain, App Group) Retained until you sign out, delete the app, or clear Safari extension data. Sign out from Account → Sign out. Uninstall the app to clear all local data.

8. Account deletion and data removal

You can delete your Proofly account at any time from Account → Delete account in the iOS app. When account deletion completes successfully, Proofly:

Account deletion does not automatically cancel an active Apple subscription. Subscriptions must be managed separately from your Apple Account settings. Active subscriptions continue to bill until cancelled through Apple regardless of account deletion status.

Deletion does not remove shared research cache entries because those entries are de-identified and contain no personal information linked to your account.

To request deletion of support correspondence or other data not removed automatically, email support@proofly.im. We will respond within 30 days.

9. Your rights and choices

10. Security

We use measures including HTTPS transport encryption, Firebase security rules, Apple Keychain for credential storage, App Group access controls, authenticated Cloud Functions, and RevenueCat's server-side purchase validation. No online system can guarantee absolute security. If you believe your account has been compromised, contact support@proofly.im immediately.

11. Tracking and advertising

Proofly does not use App Tracking Transparency (ATT) because it does not track you across other companies' apps or websites for advertising. Proofly does not sell personal information and does not include third-party advertising SDKs. Analytics calls in the app code are currently no-ops.

12. Children

Proofly is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to Proofly, contact support@proofly.im and we will delete it.

13. International data transfers

Proofly's infrastructure is operated primarily in the United States (Google Cloud and OpenAI) and RevenueCat servers (United States). If you are located outside the United States, your data is transferred to and processed in the United States. We rely on applicable legal mechanisms for such transfers where required by law.

14. Changes to this policy

We may update this policy when the service, data practices, or applicable law changes. We will update the effective date shown at the top of this page. For material changes, we will provide additional notice in the app or through another appropriate channel. Continued use of Proofly after the effective date of an updated policy constitutes your acceptance of the changes.

15. Contact us

For privacy questions, data deletion requests, or rights requests, contact: