Privacy Policy

Last updated 18 August 2026

Proof holds evidence about disputes people are in: photographs of damage, receipts, letters from a landlord, notes from a phone call. We treat that as the most sensitive category of data we could hold, and the app is built accordingly.

Who we are

Proof is made by Kode Foundry. For anything in this policy, write to hello@kodefoundry.com.

What Proof stores

What Proof never does

Where your records live

Records are written to your iPhone first, encrypted at rest by iOS with file protection that keeps them unreadable while the device is locked. They are then copied to your account on Google Cloud Platform, run for us through Firebase.

Access is enforced at the database itself, not only in the app. Every read and write checks that the account asking owns the record. No rule anywhere grants access for knowing an identifier.

Sharing

A case leaves your account only when you build a file or create a link. A link carries a token generated on our server with 160 bits of randomness, and we store only a hash of it, so a copy of our database does not hand anybody a working link. You choose what the link shows, you can add a passphrase, you can set an expiry, and revoking it takes effect at once.

Who else is involved

Neither is given your records for their own purposes. Nobody else receives them.

How long we keep things

Your records stay until you delete them. A deleted case sits in a restore window for 30 days and is then removed. Expired share links are cleared nightly.

Your control

Children

Proof is not for children under 13, and we do not knowingly collect their data.

Changes

If this policy changes in a way that affects what we do with your records, we will say so in the app before the change takes effect.