Privacy Policy for Proofly on iOS
This Privacy Policy explains how Proofly ("we," "us," "our") collects, uses, shares, and retains information when you use the Proofly iPhone or iPad app, its Safari extension, your Proofly account, shopping research features, saved history, and Proofly Pro subscriptions. Reading this policy helps you understand what data leaves your device, where it goes, and what controls you have.
1. Scope
This policy applies to the Proofly iOS app (bundle ID com.downlabs.proofly) and its Safari Web Extension (com.downlabs.proofly.Extension). It does not cover third-party websites or services you visit using Safari or Proofly's research sources. Those services have their own privacy policies.
2. Information we collect and why
| Category | Specific data | Why we collect it | Where it is stored |
|---|---|---|---|
| Account information | Email address, hashed password (stored by Firebase), account UID, display name, optional profile photo (base64-encoded), onboarding selections, and legal acceptance timestamps. | Create and authenticate your Proofly account; sync preferences between the app and Safari extension; provide account management controls. | Firebase Authentication and Firestore (Google Cloud); Apple Keychain (access token only); App Group shared storage (session token shared with the extension). |
| Shopping research context | Product title, product-page URL, website domain, visible product metadata, your search query, selected research sources, requested post and comment depth, and the time a research check was started. | Run the research job you request, identify the product across sources, return relevant results, and maintain your research history. | Device local storage (chrome.storage.local in the extension); Firebase Firestore (your account's cloud history); Firebase Functions (during processing only). |
| Public source content | Publicly visible post text, comment text, captions, video titles and descriptions, public author or channel names, public engagement counts (likes, views), timestamps, and source URLs from the research sources you select (Reddit, YouTube, TikTok, Instagram, X, and others). | Identify relevant buyer discussions, produce summaries, detect repeated signals, and provide source references in your results. | Processed in-memory on your device during the research job. A compact summary version (up to 250 posts, 20 replies per post) is stored in Firebase Firestore as part of the shared research cache described in Section 4. |
| AI processing payload | Product name, product URL, research query, and relevant public post excerpts (text and source URL only — no social login credentials, private messages, or passwords). | Generate AI-assisted product summaries, sentiment analysis, repeated concerns, and decision insights using OpenAI via our secure Firebase Cloud Functions relay. | Sent from your device to Proofly's Firebase Cloud Functions (Google Cloud, United States), which forward the payload to OpenAI's API. OpenAI does not retain API inputs for training by default. Results are stored in Firebase Firestore as part of your research history. |
| Research results and shared cache | Generated summaries, sentiment scores, source cards, cached frontendData, product signals, source references, and usage counts. | Deliver results instantly; allow the app to sync your history; avoid repeating the same research job for the same product within a shared result cache (see Section 4 for details). | Firebase Firestore under a shared cache collection keyed by normalized product query. Retained for up to 90 days or until you delete your account. |
| Safari extension state | Extension connection status, selected platform authentication signals (whether you appear signed in to a source — not the credential itself), and extension-to-app heartbeat data. | Display extension status in the app; guide you through setup; synchronize entitlement and settings between the app and Safari extension. | App Group shared UserDefaults (group.com.downlabs.proofly) — on-device only. |
| Subscription and purchase data | Apple product identifier, RevenueCat app user ID, entitlement name, subscription status (active/expired/cancelled), purchase date, renewal date, expiration date, and active plan name. | Offer Proofly Pro; verify active subscriptions; restore purchases; unlock paid features; prevent duplicate access; share entitlement status with the Safari extension. | RevenueCat servers; Firebase Firestore (entitlement snapshot); Apple Keychain (entitlement token); App Group shared storage (extension-readable entitlement). |
| Usage counts | Number of product checks used in the current billing period, monthly limit, and reset date. | Apply plan limits, display remaining usage, and prevent quota abuse. | Firebase Firestore and chrome.storage.local in the extension. |
| Profile photo | Image data you select from your photo library, stored as a base64-encoded data URL. | Display your profile image in the app. | Firebase Firestore (your account document). Your photo library is accessed only when you explicitly tap the profile photo button. We do not access your library at any other time. |
| Support and diagnostics | Support emails you send, error messages, app version, service logs, operational timestamps, and security signals. | Respond to support requests, diagnose failures, prevent fraud, secure accounts, and maintain service reliability. | Email correspondence (support@proofly.im); Firebase operational logs (retained up to 30 days). |
3. Safari website access and source accounts
The Safari extension requires website access that you grant in iOS Settings → Safari → Extensions → Proofly. You can set access to "Ask," "Allow for One Day," or "Always Allow" and can revoke access at any time. Proofly injects its research overlay only when you activate it on a product page; it does not read or transmit page content from sites where you have not triggered a research job.
When you start a product check, the extension may temporarily open background Safari tabs for your selected research sources. These tabs are closed as soon as each source's collection step completes. Proofly reads only the publicly visible content those tabs load. It does not read private messages, direct messages, account settings, or content behind a login that requires your password — it uses only what your existing signed-in Safari session already makes visible on-screen.
Proofly does not store, transmit, or share your third-party social media passwords, authentication tokens, or session cookies with our servers. Authentication status is detected only from visible page signals and is stored locally on-device.
4. Shared research cache — how it works and what it means for you
To avoid unnecessary repeated processing and reduce costs, Proofly uses a shared research cache in Firebase Firestore. When a research job completes, a compact version of the results (post summaries, sentiment, source references — up to 250 posts per product) is stored under a normalized product query key accessible to all authenticated Proofly users.
This means that if another Proofly user has already researched the same product, you may receive cached results from that earlier job rather than triggering a new research run. Cached results are anonymous — no user identity or account information is stored with the cached product data. Cached results expire after 90 days. You can force a fresh research run by using the "Refresh" option in the app.
This shared cache is disclosed here because it means that public-source content collected during your research session may be used to serve results to other users of the service, in de-identified, aggregated form.
5. Third-party service providers
Proofly does not sell personal information and does not use your information for third-party advertising. We share data with the following service providers only as necessary to operate the service:
| Provider | Purpose | Data shared | Their privacy policy |
|---|---|---|---|
| Google Firebase (Google LLC) | Firebase Authentication (account login), Firestore (database), Cloud Functions (server-side logic including AI relay), and Cloud Storage (if applicable). | Email address, account UID, research history, subscription snapshot, usage counts, research results, and operational logs. | firebase.google.com/support/privacy |
| OpenAI (OpenAI, LLC) | AI-assisted product summarization, sentiment analysis, decision insights, and natural-language Q&A about research results. Requests are proxied through Proofly's Firebase Cloud Functions — OpenAI never receives your Proofly account credentials. | Product name, product URL, research query, and relevant public post excerpts (text and source URL). No social media passwords, private messages, or personal communications are ever sent. | openai.com/policies/privacy-policy |
| RevenueCat (RevenueCat, Inc.) | Subscription entitlement management, purchase validation, restore-purchases flow, and the in-app Customer Center for subscription management. | RevenueCat app user ID (linked to your Proofly account UID), Apple product identifier, subscription status, purchase date, renewal date, and expiration date. | revenuecat.com/privacy |
| Apple Inc. | App Store distribution, In-App Purchase billing, StoreKit receipt validation, subscription lifecycle management, and platform services. | Apple product identifier, purchase receipt, and billing information handled entirely by Apple. | apple.com/privacy |
| Google Favicon API | Fetching website favicons for display in your research history list (e.g., the small icon next to "amazon.com"). | The domain name of the product-page URL (e.g., "amazon.com") is sent to https://www.google.com/s2/favicons to retrieve the site icon. No account information is sent. |
policies.google.com/privacy |
| Google Fonts | Loading the Outfit typeface for the app's web-based extension interface. | Your IP address may be logged by Google when the font is loaded. No personal information from your Proofly account is shared. | policies.google.com/privacy |
6. AI-assisted processing — what is sent and when
AI features in Proofly include automatic product summarization (runs after a research job completes), decision insights, sentiment classification, and optional Q&A chat about your results.
What is sent to OpenAI via our Firebase relay:
- The product name or search query you entered or that was detected from the product page.
- The product page URL.
- Excerpts from publicly visible posts and comments collected from your selected sources (text and source URL only).
What is never sent to OpenAI:
- Your email address, account UID, or any Proofly account information.
- Your social media passwords, session cookies, or authentication tokens.
- Private messages, direct messages, or any non-public content.
- Your device identifiers or location.
OpenAI processes inputs to return AI-generated text responses only. By default, OpenAI does not use API inputs for model training. The AI relay runs inside Proofly's authenticated Firebase Cloud Functions — your OpenAI requests do not originate directly from your device.
If you do not wish to use AI-assisted features, you can disable them in Settings. Basic research results (source list, post excerpts, and sentiment signals) are available without AI processing.
7. Data retention periods
| Data type | Retention period | How to delete earlier |
|---|---|---|
| Account information (email, display name, profile photo) | Retained while your account is active. | Delete your account from Account → Delete account in the app. |
| Research history and results | Retained while your account is active, up to the history limit shown in the app. | Delete your account, or contact support@proofly.im to request earlier removal. |
| Shared research cache (de-identified) | Up to 90 days from the date of the research job. | Cache entries expire automatically. Deleting your account does not remove shared cache entries because they contain no personal information. |
| Subscription and entitlement data | Retained as long as legally required for accounting, dispute resolution, and fraud prevention (typically up to 7 years for financial records). | Account deletion removes the entitlement snapshot; billing records are controlled by Apple and RevenueCat. |
| Usage counts | Reset monthly; retained for up to 13 months for billing and fraud prevention. | Deleted when your account is deleted. |
| Support correspondence | Up to 3 years or as required for dispute resolution. | Contact support@proofly.im to request deletion of support records. |
| Operational and security logs | Up to 30 days in Firebase operational logging. | Expires automatically. |
| OpenAI request payloads | Not retained by Proofly after the response is received. Subject to OpenAI's data retention policy (see openai.com/policies/privacy-policy). | N/A — not stored by Proofly. |
| Local device data (extension storage, Keychain, App Group) | Retained until you sign out, delete the app, or clear Safari extension data. | Sign out from Account → Sign out. Uninstall the app to clear all local data. |
8. Account deletion and data removal
You can delete your Proofly account at any time from Account → Delete account in the iOS app. When account deletion completes successfully, Proofly:
- Deletes your Firebase Authentication account.
- Deletes your Firestore account document, research history, settings, usage data, and entitlement snapshot.
- Revokes your Firebase refresh token and signs the app and Safari extension out.
- Clears the local Keychain session and App Group shared state on the device where deletion was performed.
Account deletion does not automatically cancel an active Apple subscription. Subscriptions must be managed separately from your Apple Account settings. Active subscriptions continue to bill until cancelled through Apple regardless of account deletion status.
Deletion does not remove shared research cache entries because those entries are de-identified and contain no personal information linked to your account.
To request deletion of support correspondence or other data not removed automatically, email support@proofly.im. We will respond within 30 days.
9. Your rights and choices
- Access and correction: You can view and update your display name and profile photo in the app. For other data access or correction requests, email support@proofly.im.
- Deletion: Use Account → Delete account in the app, or email support@proofly.im.
- Safari access: Control or revoke extension access from iOS Settings → Safari → Extensions → Proofly at any time.
- AI features: Disable AI-assisted processing in Settings. This stops research data from being sent to OpenAI but does not affect basic source-collection features.
- Research sources: Change or deselect sources at any time in Proofly Settings.
- Subscription management: Manage or cancel Apple subscriptions from Proofly's Plan tab → Manage, or from your Apple Account subscription settings.
- Photo library: Proofly accesses your photo library only when you explicitly tap the profile photo button. You can deny this permission in iOS Settings → Privacy & Security → Photos → Proofly.
- Rights by region: Depending on where you live, you may have additional rights (e.g., access, portability, objection, or restriction of processing under GDPR; rights under CCPA/CPRA). Email support@proofly.im to exercise these rights. We will respond within the period required by applicable law.
10. Security
We use measures including HTTPS transport encryption, Firebase security rules, Apple Keychain for credential storage, App Group access controls, authenticated Cloud Functions, and RevenueCat's server-side purchase validation. No online system can guarantee absolute security. If you believe your account has been compromised, contact support@proofly.im immediately.
11. Tracking and advertising
Proofly does not use App Tracking Transparency (ATT) because it does not track you across other companies' apps or websites for advertising. Proofly does not sell personal information and does not include third-party advertising SDKs. Analytics calls in the app code are currently no-ops.
12. Children
Proofly is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to Proofly, contact support@proofly.im and we will delete it.
13. International data transfers
Proofly's infrastructure is operated primarily in the United States (Google Cloud and OpenAI) and RevenueCat servers (United States). If you are located outside the United States, your data is transferred to and processed in the United States. We rely on applicable legal mechanisms for such transfers where required by law.
14. Changes to this policy
We may update this policy when the service, data practices, or applicable law changes. We will update the effective date shown at the top of this page. For material changes, we will provide additional notice in the app or through another appropriate channel. Continued use of Proofly after the effective date of an updated policy constitutes your acceptance of the changes.
15. Contact us
For privacy questions, data deletion requests, or rights requests, contact:
- Email: support@proofly.im
- Subject line for privacy requests: "Proofly iOS Privacy Request"
- Response time: We aim to respond within 14 business days and will always respond within the period required by applicable law.