ServiceProof

Privacy summary

This page explains the current ServiceProof V1 data model in plain language. It must be reviewed with the final App Store privacy disclosure and legal terms before a production release.

What stays on your device

Service report photos, customer signatures, and generated PDF reports are stored locally on the device. V1 does not enable iCloud synchronization or automatic upload of those report files. When you delete a report, the app removes the files it owns for that report from that device.

What the service processes

The ServiceProof service processes account credentials, sign-in method details, business profile details, industry and template selections, Report Credit balance and ledger events, and App Store purchase verification data. It does not use customer report notes, full addresses, photos, signatures, or PDF contents for analytics.

Security and fraud prevention

For high-value actions such as a Trial Credit grant, report finalization, purchase verification, and referral rewards, the service can process Apple App Attest verification data and short-lived challenges to protect against abuse. DeviceCheck tokens are used only for the Apple verification request and are not stored. The service retains the App Attest verification key and counter while an account is active; after permanent account deletion, those records are removed within 30 days. Trial eligibility summaries may be retained for up to 365 days and minimal security audit events for up to 180 days. Purchase, refund, Credit, debt, and related financial records are retained as needed to process transactions and meet applicable obligations.

Account deletion

You can request account deletion from Settings after recent re-authentication. The account enters a 30-day recovery period and active sessions are revoked. The current device clears its local ServiceProof reports, tasks, photos, signatures, PDFs, cache, and sign-in session after the request is accepted. Because V1 does not synchronize report files, other offline devices can clear their local files only when they next connect to the service. Cancelling deletion restores account access but cannot restore local files already removed from a device.

Permissions

Camera and photo-library access are requested only when you choose to add report images. You can decline permission and continue with other features. The app uses the system share sheet only when you choose to export or share a report.

Account security

Authentication tokens are stored in the iOS Keychain. Passwords are transmitted over HTTPS and stored by the service using a strong one-way password hash. Email verification and password-reset links are short-lived and single-use.

Contact

For support or privacy questions, email serviceproof@ansiotech.cn. Do not include customer photos, signatures, report PDFs, passwords, or verification codes in your message.