Privacy and data

Privacy Policy

Effective date: July 13, 2026

Overview

Proofy is a proof-of-ownership vault for receipts, invoices, warranties, and related documents. Proofy is local-first: saved proof entries and attached documents remain available on your device. If you are eligible and iCloud sync is enabled, Proofy also stores a copy in your private iCloud database so it can sync across your Apple devices and support recovery.

Proofy does not show ads, does not track you across apps or websites, and does not require a Proofy account.

Information You Add

You may add proof details such as store names, item names, prices, purchase dates, warranty dates, notes, OCR text, model numbers, serial numbers, and attached images or PDFs. This information is used to create, search, display, edit, export, and share your proof vault.

Camera, Photos, and Files

Proofy asks for camera access to scan receipts, invoices, and warranty documents. Proofy asks for photo library access when you choose to import images. You can also choose files from inside Proofy.

Imported documents are copied into Proofy's local app storage so they remain available in your vault.

iCloud Sync and Recovery

iCloud sync and 30-day deleted-proof recovery are included with Proofy Pro. When enabled, proof details and eligible attached documents are stored in the private CloudKit database associated with your Apple account. This data counts toward your iCloud storage quota and is processed by Apple under your iCloud terms and settings.

Proofy does not receive your Apple ID credentials and does not require a separate Proofy account. You can turn sync off in Settings; doing so keeps the existing local and iCloud copies. If paid access ends, Proofy pauses uploads and ongoing sync while allowing recovery of an existing iCloud vault.

Deleted proofs remain in Recently Deleted for 30 days. After that, Proofy removes their documents and retains a compact deletion record for up to 90 additional days to prevent an older offline device from restoring deleted data.

New attachments are limited to 49 MB so they remain below CloudKit's asset limit. Existing larger documents remain on the device and are identified in Proofy as not eligible for iCloud sync.

Proofy Pro and Pro AI Extraction

Free users can use 10 free AI reads online, and Proofy Pro subscribers can use ongoing AI extraction. When you use Pro AI extraction, Proofy sends the selected proof document and OCR context to Proofy’s HTTPS extraction service. This may include the selected image or PDF, rendered page images, OCR or document text, file type, expected currency, locale, and time zone. The service forwards the content needed for extraction to the configured AI extraction provider, such as OpenCode or OpenAI, to generate editable draft suggestions such as store, date, total, item names, and title.

Pro AI results are suggestions only. You can review and edit the draft before saving it in your vault.

Proofy uses an anonymous install identifier to enforce the free AI quota. For Proofy Pro requests, Proofy may send signed App Store transaction information to verify that an active subscription unlocks the feature. Proofy's AI service stores quota and rate-limit counters using hashed identifiers, and it is designed as a request-response extraction service that does not intentionally store uploaded proof documents. Cloudflare and the configured AI provider may process and temporarily retain request metadata or content under their own terms and policies as needed to operate the service, provide security, prevent abuse, maintain reliability, and comply with legal obligations.

Proofy does not use proof documents, OCR text, AI extraction content, install identifiers, or subscription entitlement information for advertising, marketing, data brokerage, or cross-app tracking.

Purchases

Proofy Pro subscriptions are handled by Apple through the App Store. Proofy receives purchase entitlement status from Apple so the app and Proofy’s service can unlock purchased features and enforce service limits. Proofy does not receive your full payment card details.

Store Logos

When Store Logos is enabled and Proofy must discover a merchant domain, including when you choose Use automatic logo without a website, Logo.dev receives the merchant or store name as a Brand Search query. When Proofy requests the automatic logo, Logo.dev receives the merchant domain, your IP address, and the request timestamp to deliver the image, meter usage, protect its service, and maintain reliability. Logo.dev processes this information under its privacy policy.

Proofy saves the resolved merchant domain so it can reuse the same logo without repeating a search. Automatic Logo.dev image bytes are not stored in Proofy's cloud service. You can disable Store Logos, correct a merchant website, choose a custom logo stored with your vault, or use Proofy's default store icon.

Logos provided by Logo.dev. Store logos are trademarks of their respective owners and are used only for identification. Their display does not imply sponsorship or endorsement of Proofy by the merchant.

System Search and Shortcuts

If Spotlight and Siri visibility is enabled, Proofy indexes proof and store metadata on your device so you can find saved proofs through Apple system search and app shortcuts. You can turn this off in Proofy Settings.

Exporting and Deleting Data

You can export active proof metadata and stored documents from Proofy. Deleting a proof moves it to Recently Deleted for 30 days. You can restore it during that period or delete it permanently. Permanent deletion removes the proof and documents from the device and, when sync is active, from iCloud.

Deleting the Proofy app removes locally stored Proofy data from that device. An existing synced iCloud vault may remain available for restoration unless you permanently deleted its contents.

Contact

For privacy questions or support, contact support@mannbadal.com.