Privacy Policy
Summary — 60 seconds
HereProof stays on your phone.
HereProof is an iPhone app that turns a moment you capture into a shareable proof. We don't run a server that tracks you. We don't have accounts. We don't sell data. We don't use ads or analytics. We don't see your photos, your notes, or your location.
- Your photo stays on your device until you choose to share it using the normal iOS share sheet. Where it goes from there depends on which app you pick.
- Your note (the "Describe this moment" text) is rendered into the image you share. We never see it.
- Your location (the "Include location" toggle) is off by default. When on, HereProof reads your city from CoreLocation and renders it into the image. We never see it.
- Your presence-credit count is a small number stored in iOS app preferences on your device. It doesn't leave your phone.
If you delete the HereProof app, every piece of data HereProof stored on your device is gone.
What HereProof collects
On your device (never transmitted to us)
| What | When | Where it lives |
|---|---|---|
| Your presence-credit count (a small integer) | The first time HereProof runs, it seeds a count of 1. When you create a HereProof, it decrements by 1. | iOS app preferences on your iPhone. Deleted when you delete the app. |
| The photo you capture | Only while you're in the Create flow, until you tap Share or close the app. | In memory during the Create flow; never written to a separate file by HereProof; not uploaded anywhere. |
| The optional note you type ("Describe this moment") | Only if you type one. | Rendered into the shareable image as text on the bottom strip. Not stored separately once you leave the Create flow. |
| A coarse location fix (latitude, longitude, accuracy, city name) | Only if you turn on the "Include location" toggle and grant iOS permission. | Rendered into the shareable image as "City, State". Not stored separately once you leave the Create flow. |
| A timestamp of when you created the HereProof | Always, once you create one. | Rendered into the shareable image. |
| A small event log (e.g., "credit.consumed", "hereproof.created") | Internal diagnostics while the app is running. | In memory only. Not written to disk, not transmitted. Cleared when you close the app. |
Off your device (nothing)
HereProof v1 does not have a backend server. We do not collect, store, or transmit any data to Agile On Target LLC or to any third party.
There is no user account. No login. No sign-up. No email collection. No analytics SDK. No ad SDK. No crash reporting SDK.
What HereProof does NOT collect
- Your name, email address, phone number, or any contact information.
- Your Apple ID, iCloud ID, or any device identifier.
- Your contacts, address book, or social graph.
- Biometric data (face templates, Face ID data, fingerprint data). HereProof does not run facial recognition on the photo you capture.
- Your health, fitness, or medical data.
- Your financial or payment information.
- Your precise street address. Location, if enabled, is reverse-geocoded to a coarse "City, State" string and the raw coordinates are never sent to anyone — they are only drawn onto your shared image alongside the city name.
- Your browsing history, search history, or any data from other apps.
- Any advertising identifier.
- Any cryptocurrency, wallet, or blockchain data. HereProof v1 is not a crypto product; there are no wallets, no tokens, no on-chain activity.
iOS permissions HereProof asks for
HereProof asks for at most two iOS permissions. Both are entirely optional (you can deny either) and both prompt you with standard iOS dialogs.
Camera — prompted the first time you tap "Create a HereProof". The iOS prompt displays:
"HereProof uses the camera so you can capture the moment that becomes your HereProof."
Without camera permission, you cannot capture a HereProof. No other use of the camera occurs.
Location, while using the app — prompted the first time you tap "Create my HereProof" with the "Include location" toggle turned on. The iOS prompt displays:
"HereProof can attach the city where you captured a moment, so your HereProof remembers where you were. Location is optional."
We request only "While Using the App". We never request "Always Allow", and we never use background location. If you deny permission or leave the toggle off, HereProof still works — it just skips the location step.
HereProof does not ask for Microphone, Photo Library, Contacts, Calendar, Reminders, Health, HomeKit, Motion, Bluetooth, Local Network, or NFC.
What happens when you share a HereProof
When you tap Share on the success screen, iOS opens its standard share sheet. HereProof hands iOS a single image (your captured photo with the optional metadata strip rendered on it) and steps out of the way. Whatever happens next — sending to Messages, saving to Photos, posting to an app you chose — is governed by that app's privacy policy, not ours. We never see the share destination, and we never see what you do after leaving the share sheet.
HereProof does not share presence credits, internal identifiers, or any other data. The only thing that ever leaves HereProof via the share sheet is the rendered image you explicitly chose to share.
Data retention
- On-device data (credit count, in-memory artifacts, event log) exists only for as long as you have HereProof installed. Delete the app and everything goes with it. iOS also clears in-memory state when the app is terminated.
- Server-side data: none. We have no server that stores your data.
Your rights
Because HereProof v1 does not collect or store any of your data on our servers, the practical effect of most formal "data subject rights" is automatic:
- Right to be forgotten: delete the app.
- Right of access: there is no server-side record to access.
- Right to rectification: you can always retake a HereProof or edit the description / location toggle before committing.
- Right to data portability: your HereProof is an image. You can share it, save it, or send it anywhere iOS's share sheet supports.
- Right to object / withdraw consent: leave the Include location toggle off, or revoke camera / location permission in iOS Settings.
Children's privacy
HereProof is not directed at children under 13 and is not intended for use by children under 13. We do not knowingly collect information from children. Because we collect no personal information from anyone in v1, this is structurally enforced.
Security
Because HereProof v1 holds no server-side data, the attack surface for your data is limited to your own iPhone. iOS's standard protections apply: data stored in app preferences is only accessible to HereProof (not to other apps) while HereProof is installed; it is wiped when you delete the app.
The photo you capture is held in memory during the Create flow and is never written to a separate HereProof file. When you share it via iOS, you are handing it to another app (e.g., Messages); that app stores it according to its own policy.
International transfers
No transfers. We do not operate a server and we do not transfer your data across borders. Any cross-border handling of an image you shared happens inside the receiving app (e.g., Messages routes through Apple's infrastructure; another app may route through its own).
Changes to this policy
If HereProof's data handling changes — for example, when future versions introduce server-backed features currently deferred behind internal feature flags — we will update this policy, bump the Version and Effective Date at the top, and surface the change in the app's About screen. We will not retroactively apply any new data collection to HereProofs you created under a prior policy version.
Planned future capabilities (not in v1, not active): HereProof's long-term architecture includes a verifier service, on-chain anchoring, and payment rails. None of these are active in v1. When any of them ship, this policy will be updated in advance with a corresponding Effective Date, and those features will only activate for users on a build that post-dates the updated policy.