MyHRProof helps you privately document what happens to you at work. Privacy is the product, so this policy is written to be read, not buried. In plain terms: your incident records are encrypted with a key only you hold. When they sync to the cloud, we store only scrambled text we cannot read.
This policy describes the MyHRProof mobile app as it works today. The app now includes optional accounts and encrypted cloud sync, so your records can be backed up and restored on a new device. This document explains exactly what that means for your data.
Short version: To use accounts and cloud backup, you sign up with your email and a password. Your incidents and media are protected by end-to-end (zero-knowledge) encryption — when they sync to our cloud we store only encrypted data and cannot read your incidents, media, password, recovery code, or decryption key. Information reaches a third party only for accounts and sync (Supabase), payments (Apple, Stripe & RevenueCat), and, if you use the Charlie assistant, the message you type (Anthropic).
1. What we collect, and what we don’t
Account information (stored by us, via Supabase)
- Your email address and a password you choose, used to create and sign in to your account. Passwords are handled by our authentication provider and are never stored by us in readable form.
Encrypted incident data (synced to the cloud, but unreadable to us)
- Incident records — descriptions, category, and the date/time you record — and evidence you attach (audio recordings, photos, and videos). These are encrypted on your device before they leave it. When they sync to our cloud, the server stores only ciphertext and “wrapped” keys. We, our staff, an employer, or anyone we disclose data to cannot read the content, because we never hold the key that would decrypt it.
- Location — if you choose to tag an incident, its GPS coordinates are stored as part of that encrypted record. Location is optional and only captured when you add it to an incident.
- Voice transcription — recordings are transcribed on your device. The audio itself is not sent anywhere for transcription; if you attach it to an incident, it syncs as encrypted evidence like any other attachment.
Information handled by a third party when you use a specific feature
- Subscriptions (Apple, Stripe + RevenueCat): When you subscribe in the app, Apple processes the payment; when you subscribe on the web, Stripe processes it. RevenueCat, our subscription manager, receives your transaction details and an app identifier so the app knows which plan you have. We never receive your full card details.
- Charlie assistant (Anthropic): When you send a message to Charlie, the text you type is sent through our backend to Anthropic to produce a reply, along with the standard network information (such as your IP address) that any internet request includes, which we use only to prevent abuse. Charlie messages are not part of your encrypted incident record, so please do not include names or identifying details in Charlie messages. Your Charlie messages are not used to train AI models.
We do not collect: your contacts, browsing history, advertising identifiers, or cross-app tracking data. We collect limited first-party usage analytics — which features are used and when — on our own systems, to improve the app; this never includes your incident content, media, or descriptions. We do not use third-party analytics or advertising SDKs, and the app does not track you across other apps or websites.
2. How your information is used
- To create and secure your account and let you sign in.
- To let you document, review, back up, and restore your own incidents across your devices.
- To provide the features you choose to use (voice transcription, evidence attachments, location tagging, the Charlie assistant).
- To process, manage, and restore your subscription.
We do not use your information for advertising, and we do not profile you.
3. Third parties and subprocessors
We keep the list of companies that process data on our behalf short and purposeful:
- Supabase — stores your account (email) and your encrypted incident data and media, and provides authentication. Supabase never receives your decryption key and cannot read your incident content.
- Anthropic — receives the text of the messages you send to the Charlie assistant, to generate a reply.
- RevenueCat, Apple, and Stripe — process and manage subscriptions and payments.
Each of these processes data under its own privacy policy. We do not sell your data to anyone.
4. Data retention and deletion
- Deleting an incident in the app removes it from your device and from your cloud sync.
- Deleting your account removes your account, your incidents, and your vault keys. You can do this from within the app. Because deleting your vault keys destroys the only means of decrypting your data, any of your encrypted content becomes permanently unreadable at that point.
- Please note: immediately after account deletion, some already-uploaded encrypted media files may remain in cloud storage as orphaned ciphertext until a later routine cleanup removes them. Because the key that wrapped them has been destroyed, this leftover data is unreadable by anyone, including us.
- Apple, Stripe, and RevenueCat retain purchase records as required for billing and tax purposes, under their own policies.
- Anthropic processes Charlie messages to generate a reply, under its own policies.
5. Your rights
Depending on where you live (including under the California CCPA/CPRA and the EU/UK GDPR), you may have rights to access, correct, delete, or export personal information a company holds about you. You can delete your account and its data at any time from within the app. For any other request, or for information a third party processes on our behalf (Supabase, Anthropic, Apple, Stripe, RevenueCat), you may contact us and we will help you exercise applicable rights. We do not sell or “share” personal information as those terms are defined under CCPA/CPRA.
6. Children
MyHRProof is intended for people in the workforce and is not directed to children under 16. We do not knowingly collect information from children under 16. If you believe a child has used the app, contact us and we will help.
7. Security
Your incident content and media are protected with end-to-end, zero-knowledge encryption. A random 256-bit data encryption key encrypts your vault; that key is “wrapped” by keys derived from your password and a one-time recovery code using PBKDF2-SHA256 (100,000 iterations), and the content itself is encrypted with AES-256. The server stores only the encrypted data and the wrapped keys — never your password, recovery code, or the decryption key. Because of this design, if you lose both your password and your recovery code, your data cannot be recovered — nobody, including us, holds an escrow copy of your key. The app also blanks its screen in the device’s app switcher so your incidents aren’t visible in a preview. No method of storage or transmission is 100% secure, but zero-knowledge encryption means that even a breach of our cloud storage exposes only unreadable ciphertext.
8. Changes to this policy
If we make material changes, we will update this page and, where appropriate, notify you in the app before the change affects you.
9. Contact
Questions about privacy? Email privacy@myhrproof.com.