ProofKit Privacy Policy
Effective 10 August 2026
ProofKit is a condition-documentation app for Android, published by Arcane Systems Inc. This policy explains what ProofKit does with your information.
The short version: ProofKit has no account, no server, and no analytics. Your photos, videos, notes, and packs are created on your device, encrypted on your device, and stay there until you choose to share or export them.
What ProofKit collects
Arcane Systems Inc. collects nothing from ProofKit. There is no account to create, no sign-in, no profile, and no server that ProofKit sends your content to.
The app creates and stores the following on your device only:
- Photos and video you capture in ProofKit, or import through the Android photo picker.
- Text you type: pack names, item and location labels, make and model, colour, serial numbers, company names, booking or reference numbers, notes, and screen-reader descriptions.
- Timestamps recorded when a file is captured or imported, plus your device's time-zone offset at that moment.
- Technical details about each file: type, dimensions, size, clip length, and a SHA-256 digest of its contents.
- A local history log of actions taken in a pack, such as "photo captured for Front" or "pack archived". It records what changed, never the contents of a note.
- Your settings: theme, haptics, screen transitions, app lock, reminders, and your saved export choices.
Camera and photos
ProofKit asks for camera permission the first time you try to capture something, and explains why before asking. The camera is only active while a capture screen is open and visible. ProofKit never records in the background.
ProofKit does not request microphone permission and does not record audio. Video clips are captured without sound.
To bring in photos you already have, ProofKit uses the Android photo picker. You choose the specific files; the app never receives access to your whole photo library. ProofKit does not request broad media permissions such as READ_MEDIA_IMAGES.
Imported files are labelled as imported and kept distinct from files captured in ProofKit. If an imported photo carries its own capture time in its metadata, ProofKit reads it and records it as the file's own claim, separately from the time ProofKit received the file. ProofKit never rewrites the metadata of a stored original.
Location
ProofKit does not request location permission and does not read your location.
If you type a location label for a capture session, that is text you wrote and it is stored like any other note. You can leave it out of exports.
Photos you import may contain location coordinates in their own metadata. ProofKit does not read those coordinates for its own purposes. When you export, metadata is removed from the shared copies unless you explicitly choose to include raw photo metadata.
How your content is stored
Media files are encrypted with AES-256-GCM before being written to ProofKit's private storage area. Sensitive text fields — notes, reference numbers, addresses, serial numbers, descriptions — are encrypted individually in the app's database.
The encryption keys are generated inside the Android Keystore and never leave it. There is no copy of your key in the app's code, in its settings, or anywhere off your device.
ProofKit is excluded from Android cloud backup and from device-to-device transfer. That is deliberate: a backup of encrypted data whose key cannot leave the device would be unreadable, and copying your photos somewhere you did not ask for is not something the app should do.
Because there is no cloud copy, ProofKit cannot recover your data. If you uninstall the app, clear its data, lose the device, or reset your device screen lock, packs encrypted with the previous key may become permanently unreadable. Export anything you need to keep.
Sharing and exports
Nothing is shared unless you initiate it. When you export a pack, ProofKit builds the file inside its own storage and hands it to the Android share sheet only when you tap share. You choose the destination app; ProofKit never emails, uploads, or transmits anything on your behalf, and never contacts a rental company, landlord, or insurer.
Exported files can contain personal information — faces, number plates, house numbers, documents, serial numbers. ProofKit shows you exactly what an export will include and lets you leave out notes, location labels, reference numbers, raw photo metadata, and the history log, or blur details in a redacted copy first.
Once you have shared a file, the recipient has their own copy. Neither you nor ProofKit can withdraw it.
Notifications
Reminders are scheduled on your device from dates you enter, and notification permission is only requested when you turn reminders on.
ProofKit never uses your location, calendar, email, or booking confirmations to decide when to remind you. A reminder names the pack and nothing else, so nothing sensitive appears on your lock screen.
Analytics, advertising, and tracking
ProofKit contains no analytics SDK, no crash-reporting SDK, no advertising, and no tracking or cross-app profiling.
Arcane Systems Inc. does not sell or share personal or sensitive information, and does not use your content to train any model.
Diagnostic logging is stripped from release builds so that notes, labels, file paths, and metadata cannot end up in a device log.
Purchases
ProofKit Pro is sold through Google Play Billing. Google processes the purchase; ProofKit never sees or handles your payment details.
The app stores only whether a Pro entitlement is currently active, and the product identifier, on your device. Google's handling of your purchase is covered by Google's own privacy policy.
Whatever your subscription status, packs you have already created stay openable, exportable, and deletable.
Children
ProofKit is not directed at children and is not designed for use by children. It collects no information from anyone, including children.
Your control over your data
Because everything is on your device, you hold the controls:
- Delete an individual photo, note, comparison, or export at any time.
- Delete a whole pack, with its media, in one action.
- Delete every trace of ProofKit's data — database, media, exports, thumbnails, settings, and encryption keys — from You → Delete all ProofKit data.
- Uninstalling the app also removes its private storage.
- Export a full copy of any pack as a PDF or ZIP bundle whenever you want.
There is no account to delete, because there is no account. If you have a question about your data, or a request under a privacy law that applies to you, write to the address below.
What ProofKit does not claim
ProofKit helps you organise documentation. It is not legal advice and does not create certified, tamper-proof, or guaranteed admissible evidence. Whether any record is accepted depends on the facts, the recipient, and the law that applies.
The SHA-256 digests ProofKit records can show that a file has not changed since it was exported. They cannot show when or where a photograph was taken, that a device clock was accurate, or what condition anything was in outside the records shown.
Changes to this policy
If this policy changes, the updated version will be published with a new effective date, both in the app and at the address given in the Play Store listing. Material changes will be noted in the app's release notes.
Contact
Arcane Systems Inc. — arcanesystemsinc@gmail.com
Please include your device model and the ProofKit version shown in You → About and legal, which helps answer questions accurately.