Privacy Policy — Proof
Effective date: 18 August 2026
Last updated: 18 August 2026
1. Who we are
Proof is a mobile application for habit commitment and partner accountability, published by Liberty Tech.
Liberty Tech is the data controller for the personal data described in this policy.
Contact: privacy@libertytech.fr
2. What we collect
We collect only what the app needs to work. There is no analytics SDK, no advertising SDK, no crash-reporting SDK, and no tracking of you across other apps or websites.
Account and sign-in
- Your email address, used to identify your account and to send you a six-digit sign-in code.
- Your first name, which you provide at sign-up. Your partner sees it, so that they know whose goals they are looking at.
- If you sign in with Google or Apple: the stable account identifier that provider gives us, and the email address attached to it. We do not receive your provider password.
- A device identifier generated by the app on first launch, used to create your initial session.
- Your time zone, used to decide when your day starts and ends.
What you create in the app
- Your goals — their name, icon, rhythm (daily or weekly), and any reminder time you set.
- Your completions and misses, with the local calendar day each belongs to.
- Reactions you send to your partner.
- The pairing between you and your partner.
Notifications
- A push notification token for your device, and whether it is iOS or Android. This is what lets us deliver a notification to that device and nothing else.
Security
- Session tokens, so you stay signed in.
- Your email address is used briefly as a rate-limiting key to stop someone requesting unlimited sign-in codes for your address.
We do not collect your location, your contacts, your photos, your phone number, your browsing history, or any biometric or health data.
3. Why we collect it, and our legal basis
| What | Why | Legal basis (GDPR) |
|---|---|---|
| Email, first name, sign-in identifiers | To create your account, sign you in, and show your partner who you are | Performance of a contract |
| Goals, completions, misses, reactions, pairing | To provide the service — this is the service | Performance of a contract |
| Time zone | To judge your day in your own local time | Performance of a contract |
| Push token | To send you reminders and tell you about your partner's activity | Performance of a contract |
| Session tokens, rate-limiting | To keep your account secure | Legitimate interest |
We do not use your data for advertising or profiling, and we do not sell it.
4. What your partner can see
Proof exists to make your commitments visible to one other person. When you pair with someone, that person can see:
- your first name;
- the names of your goals;
- whether you completed or missed each of them, each day;
- reactions exchanged between you.
They cannot see your email address, your sign-in method, or anything about any other person you may have been paired with. Pairing is mutual and requires an invite code — nobody can add you without your action.
5. Who else processes your data
| Processor | What for | Where |
|---|---|---|
| Hostinger | Hosting for our servers and database | EU data centre |
| Resend | Sending sign-in codes and account emails | EU / US, under Standard Contractual Clauses |
| Google (Firebase Cloud Messaging) | Delivering push notifications, on both iOS and Android | Google Cloud |
| Google / Apple | Verifying your identity if you choose Sign in with Google or Apple | Google / Apple |
We do not share your data with advertisers, data brokers, or anyone else.
Firebase Cloud Messaging receives only the push token and the notification content needed to deliver a message. We use no other Firebase product — no Firebase Analytics, no Crashlytics, no Firebase Authentication.
6. How long we keep it
- While your account exists, we keep your data so the app can work.
- If you delete your account — from Settings, or by emailing us — deletion is immediate and permanent. Your goals, history, reactions, pairing, sessions and push tokens are erased. We do not keep a shadow copy, and it cannot be undone.
- If you start signing up and never finish, the empty account created at first launch is deleted automatically after 7 days.
- Backups are retained for up to 30 days, after which deleted data disappears from them too.
7. Your rights
Under the GDPR you may:
- access the personal data we hold about you;
- correct it if it is wrong;
- delete it — the app does this directly, from Settings;
- object to or restrict our processing;
- receive a copy of your data in a portable format;
- complain to a supervisory authority. In France that is the CNIL.
Email privacy@libertytech.fr and we will respond within one month.
8. Children
Proof is not directed at children and is not intended for anyone under 13 (or the minimum age of digital consent in your country, where that is higher). We do not knowingly collect data from children. If you believe a child has given us personal data, email us and we will delete it.
9. Security
Traffic between the app and our servers is encrypted with TLS. Sign-in tokens are stored in the operating system's secure storage — Keychain on iOS, Keystore on Android. Our database is not reachable from the public internet.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your personal data, we will notify you and the relevant supervisory authority as the GDPR requires.
10. International transfers
Our servers are in the EU. Some processors listed in section 5 may process data outside the EU; where they do, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
11. Changes to this policy
If we change this policy materially, we will update the date at the top and notify you in the app before the change takes effect.
12. Contact
privacy@libertytech.fr
Liberty Tech — France