Privacy Policy
What we collect, why we collect it, who else can see it, how long we keep it, and how to get it back or have it deleted — on this website and in the CoreProof Field app.
- Who we are
- What we collect on this website
- What the CoreProof Field app collects
- What never leaves your device
- Why we collect it
- Who else sees it
- Where it is stored
- How long we keep it
- How we protect it
- Cookies, analytics and usage counting
- AI, this website and the app
- Access, correction and deletion
- Complaints
- Changes to this policy
- Contact
1. Who we are
CoreProofAI is a survey and design software business based in Australia. This website, and the CoreProof Field app, are operated by CoreProofAI.
No company has been registered yet, so there is no company name, ACN or ABN to give you. When one exists it goes here, and until then this line stays as it is rather than becoming a number that looks official:
LEGAL ENTITY — NOT YET REGISTERED ACN — NONE ABN — NONE
When you deal with this website or the app, you are dealing with us directly. There is no sales agency, no reseller and no data broker in between.
We do not rely on it. We handle personal information as though the Australian Privacy Principles apply, because a business asking you to trust it with survey records and site photographs should not be arguing about whether it has to. Where this policy says we will do something, treat it as a commitment we intend to be held to.
2. What we collect on this website
Only what you type into a form, plus anonymous traffic measurement. We do not buy personal information from anyone, and we do not build profiles of visitors.
Information you give us
| Where | What | Required? |
|---|---|---|
| CoreProof Field waitlist | Name, email address. Optionally organisation, the kind of work you do, which device you would use, and which tier you are waiting for. | Name and email only |
| Emailing support | Whatever you put in the email — your address, your name if you sign it, and anything you describe or attach. | You choose all of it |
| Password reset page | The new password you type, and the one-time recovery token from the link in your email. Both are sent straight to the account service and neither is stored by this website. See section 3. | Required to complete a reset |
Three other forms exist in this site's source — a general contact form, an Intake Pack download and a Readiness Check — and none of them is published today. If any is published later, this table gains a row before it goes live, not after.
Information collected automatically
Cookies, analytics and the app's usage counter are all in section 10, stated exactly.
Our hosting provider processes technical information such as IP addresses in the ordinary course of serving and protecting the site. We do not use that information to identify you.
3. What the CoreProof Field app collects
CoreProof Field is a survey app you install on your own device. It is local-first by design: your sites, plans, photographs, notes and reports live on the device. A small, specific set of things does leave it, and this section names every one of them.
Your account
| What | Where it goes | Why |
|---|---|---|
| Email address | Supabase project, Sydney | It is how you sign in, how a sign-in code reaches you, and how a password reset reaches you. |
| Password | Supabase project, Sydney | It is stored hashed by the account service. We never see it and cannot recover it — a forgotten password is reset, never retrieved. The app holds it only for the instant of the one request that proves it, and keeps sign-in tokens on the device afterwards. |
| Sign-in tokens | Your device only | They keep you signed in. After the first sign-in the app opens offline indefinitely. |
| Templates, saved blocks, sections and block categories | Supabase project, Sydney | Only if you turn sync on — it is off until you do, and you are asked first — and then on every tier. These are the shapes you build rather than the work you do with them: a template is a list of questions, a block is a drawn symbol. A block traced off a floor plan keeps that outline at its real size in millimetres, with any labels typed on it, so a shape taken from a real building carries that much of its geometry. No site, photograph, note, on-site measurement or signature travels with them. Delete a shape and the next sync clears its contents here, leaving a note that it is gone so another device cannot put it back; that note is not removed on a schedule. Deleting your account deletes all of it. |
Your report letterhead (the profile)
So that a report can print under your name rather than ours, the app offers a profile. Every field is optional, and an empty field is stored as nothing at all rather than as a blank line on your paperwork. What you fill in is saved to the same Supabase project so it follows you to a new device:
- Display name and company;
- a contact block: phone, email, website;
- a brand colour;
- an optional logo image (PNG, JPEG or WebP, up to 2 MB), stored in a private bucket where the only account that can read, replace or delete it is yours.
These details are yours to publish — they are printed on the documents you hand to your client. We do not use them for anything else, and we do not read them.
Photographs
- Photographs you take or attach are stored on the device, inside your site.
- When the app saves a photo it re-encodes the image and strips the camera metadata out of the file, including any GPS position the camera wrote into it. If that re-encode cannot be done on your device, the app keeps the original bytes and tells you so on the spot, because at that point the file still carries whatever the camera put in it and you are the only person who can decide what to do about that.
- Photographs are not uploaded to us. They leave your device only when you export or share a report, a sheet or a site backup — by whatever means you choose, to whoever you choose.
Location
- Location is collected only if your device grants the app permission. Decline, and every other part of the app still works; the app asks once and does not nag.
- Where permission is given, the app records one position when you create a site, and one position per photograph.
- The device is asked for a position far less often than that suggests, and we would rather be exact than flattering: a batch of photos triggers one request, not one per shutter, and a fix is reused for up to two minutes before the radio is asked again. So several photographs taken at one doorway carry the same position, and a photograph's stamp can be a couple of minutes old. It is a position, not a stopwatch.
- You are never tracked continuously. There is no background location, no trail, no movement history — there are only those individual fixes, each tied to a thing you did.
- Those fixes are kept on the device with your work, are used to place the site on a map and to print where a photograph was taken, and are not sent to us.
- A photograph's printed position comes from this app-side fix, not from the image file — the file has had its metadata stripped (above).
4. What never leaves your device
Stated as a list, because a promise this specific should be checkable:
- Sites, buildings, levels and rooms;
- floor plans, sheets, dimensions and markup;
- photographs and their annotations;
- notes, inspection registers and defect schedules;
- per-site and per-building details you type — addresses, references, the people you name;
- per-photo and per-site location fixes;
- sign-offs — the name typed by whoever signed, their signature, and the moment they gave it. The signer is often not you: a building manager or a client’s representative. A signature is printed in that site’s report and stays on the device that took it — it is not in the
.coreproofbackup and it is not uploaded by a cloud backup; - exported PDFs, CSVs, DXFs and
.coreproofbackups — they are saved by your device, to your device.
None of that is uploaded to CoreProofAI. It is not on a server we run, we cannot look at it, and we could not produce it if somebody asked us to.
The one thing that changed, and when
From 3 September 2026, if you turn sync on, the shapes you build are kept with your account: your templates, saved blocks, sections and block categories. They are the things a person otherwise rebuilds by hand on a new tablet. Until that date they stayed on the device, and this page said so; it is called out here rather than quietly amended above.
Corrected 5 September 2026, and in the direction that matters. The paragraph above ended “and they hold no survey work — a template is a list of questions, a block is a drawn symbol”. That was wrong about blocks. The app lets you box-select walls straight off the floor plan of the building you are surveying and keep them as a block, and it keeps them at their real size in millimetres, with whatever labels you typed on them. So a saved block can carry a to-scale outline of part of a real building. It is bounded — roughly a room or a small apartment’s worth — and it is the only survey-derived thing that travels, but the old sentence denied it outright and that is the wrong way for a privacy page to be wrong. It is also why sync is now off until you turn it on: the previous wording described something that started on its own.
Everything in the list above is unchanged. No site, sheet, photograph, note, register entry, measurement or signature is uploaded by the act of surveying, on any tier, signed in or not. If you never sign in, nothing at all leaves the device.
If you lose the device, we cannot restore your work, because we do not have it. Export your sites.
5. Why we collect it
- To tell you when CoreProof Field is released. If you join the waitlist, that is what the waitlist is for.
- To answer you. If you email support, we need somewhere to reply.
- To give you an account, so the app knows who you are, can let you back in on a new device, and can reset a password you have forgotten.
- To print your reports under your name, which is the whole purpose of the profile and the logo.
- To place your work on a map and to record where a photograph was taken — on your device, for your report.
- To understand which parts of the site are useful, in aggregate, so we build the right things first.
6. Who else sees it
Inside CoreProofAI, the list of people with access is very short — today it is one person. Nobody at CoreProofAI reads your survey work, because we do not have it.
We use a small number of service providers to run the site, the app's accounts and our email. They process information on our behalf, under their own terms and privacy policies.
| Provider | What it handles | Their policy |
|---|---|---|
| Supabase | The app's accounts. Email addresses, hashed passwords, the report profile, and the logo bucket. Hosted in Sydney. It writes the sign-in and password-reset emails, which Resend then delivers. No survey content. | supabase.com/privacy |
| Resend | Delivers the app's account emails — the sign-in code and the password-reset link. It handles the address the email is going to and the contents of that email. Sent from its Tokyo region. No survey content. | resend.com/legal/privacy-policy |
| Cloudflare | Hosts this website and the app, and provides the cookieless website analytics. | cloudflare.com/privacypolicy |
| Web3Forms | Delivers form submissions from this website to our inbox. | web3forms.com/privacy |
| Microsoft 365 | Our email. Anything you send us is stored in our mailbox. | privacy.microsoft.com |
| GoDaddy | Domain registration and DNS only. Does not receive form data. | godaddy.com/legal |
The app also draws map backgrounds from an open map-tile service when you ask it for a map. Asking for a tile tells that service which part of the world you are looking at, in the ordinary way any map on the web works. No account information and no survey content goes with the request.
And when you type a site address, that address is looked up. The app sends it to the G-NAF national address service on the Digital Atlas of Australia — an Australian Government dataset, served from Esri’s ArcGIS platform — to turn it into a location for the cover map. The app’s own Legal screen carries the same disclosure, and is honest that we have not confirmed whether that platform places the lookup outside Australia. The address you typed is the whole of what is sent — there is no account information, no identifier and no other survey content in the request — and it happens only when you enter an address. See section 7.
We may also disclose personal information where we are required to by law. If that ever happens and we are permitted to tell you, we will.
If the business is ever sold or restructured, personal information may transfer with it. Any buyer would be bound by this policy for information collected under it.
7. Where it is stored
Your account data is in Australia. The app's Supabase project — email addresses, hashed passwords, the report profile and the logo bucket — is hosted in the Sydney region. That was a deliberate choice, not a default.
Your survey work is on your device, wherever you are — your sites, photographs, drawings, sheets, notes and the reports you export. We hold no copy of any of it.
With one exception, and it is the first thing you will type. When you enter a site address on a cover page, that address is sent to the G-NAF national address service published on the Digital Atlas of Australia (served from Esri’s ArcGIS platform) so the app can find the location and draw the map. The address leaves your device; nothing else does — no photographs, no notes, no measurements, no account details, and no other part of the site. If you never type an address, nothing is sent. This page used to say your survey work was on your device and “nowhere else”, full stop, which was not true of that one field.
Beyond that, our providers operate globally, so information may still be stored or processed outside Australia. Concretely: the emails carrying your sign-in code and your password-reset link are delivered by Resend from its Tokyo region, so your email address and the contents of that one email leave Australia even though your account record does not; website form submissions pass through Web3Forms; our mailbox is Microsoft 365; Cloudflare serves the site and the app from a global network; and a provider's own support, backup or abuse-handling systems may sit elsewhere even where the data does not.
We choose established providers with published privacy commitments, and we keep the number of them deliberately small. We cannot, however, guarantee that an overseas recipient will handle your information in a way that meets Australian standards in every respect, and you should read this paragraph as a disclosure rather than a promise about foreign law.
8. How long we keep it
Real periods, not placeholders. We would rather commit to a number and stick to it.
| Information | Kept for |
|---|---|
| Your account (email, hashed password) | For as long as the account is open. Ask us to close it and we delete the account and its profile within 30 days. There is no cooling-off copy kept beyond that, and no shadow record of a deleted account. |
| Your report profile and logo | The same life as the account. Clear a field and the old value is overwritten, not archived; delete the logo and the file is deleted from the bucket. |
| Everything on your device | Until you delete it. We have no copy, so we have no period to state and nothing to expire. |
| Waitlist entries | Until CoreProof Field is released, then 12 months, unless you ask us to remove you sooner. If Field has not been released within 24 months of you joining, we will delete the list or write and ask whether you still want to be on it. |
| Support emails | 24 months after our last exchange with you. |
| Client records under a signed engagement | 7 years after the engagement ends, to meet Australian record-keeping and tax obligations. |
| Analytics | Aggregate only, retained by Cloudflare under their retention settings. No personal information to delete. |
When a period ends we delete the information or de-identify it. Deletion from backups may take longer, but we do not restore deleted personal information from a backup for any purpose other than disaster recovery.
9. How we protect it
- This site and the app are served over HTTPS; everything sent to us is encrypted in transit.
- Passwords are hashed by the account service, never stored as text and never visible to us. That is also why we can only reset one, never tell you what it was.
- Your profile row and your logo are fenced to your own account at the database, not merely in the app: the rules are written so that one account cannot read, replace or delete another's, and there is no provider-wide read.
- The app talks only to the one account service it was built with, sends no cookies, and refuses to follow a redirect — a reply cannot send your password or token somewhere else.
- Our mailbox is protected by multi-factor authentication.
- Access is limited to people who need it. Today that is a very short list.
- We collect as little as we can get away with, because the safest record is the one we never made — and the strongest thing in this policy is a design decision, not a promise: your survey work is not on our servers to lose.
No system is perfectly secure, and we will not pretend otherwise. If a data breach occurs that is likely to cause you serious harm, we will tell you and notify the Office of the Australian Information Commissioner, applying the Notifiable Data Breaches scheme as our standard whether or not we are legally required to.
10. Cookies, analytics and usage counting
This website
We use Cloudflare Web Analytics to count visits. It is cookieless and privacy-first: it does not use client-side state to track you across sites, and it does not fingerprint individuals. We see aggregate numbers, such as how many people opened the home page, not who they were. The counter runs on the home page and nowhere else — no other page on this site carries it, including the one you are reading now.
This website sets no advertising cookies and runs no advertising or social media trackers. That is why you are not being shown a cookie consent banner.
The CoreProof Field app
We are describing it here rather than staying quiet about it, because "we built it but it is not on" is exactly the kind of thing a privacy policy should say out loud.
The switch that turns it off is already there, in the app's Settings, and you can set it today. It is a standing refusal held on your device: it is checked every time something could be counted, and again before anything could be sent, so a choice you make now still holds if a destination is ever configured.
If we ever turn it on, we would be reporting anonymous counts of app activity — how many sites were started, how often a feature was used — and never the contents of your work: no site names, no addresses, no plans, no photographs, no notes, no positions. Before that happens we will:
- update this policy and change the version at the top of the page;
- email account holders before it takes effect;
- and say in the app what is counted, beside the switch that is already there.
The app carries no advertising, no third-party analytics library, and no advertising or tracking cookie of any kind. It stores data on your device so that it can work with no signal at all, which is a requirement of the job, not a tracking mechanism.
11. AI, this website and the app
The name says AI, so this deserves a direct answer rather than a footnote.
AI tools are used internally to help build our software and to help encode engineering standards into rules. That is development work, and it is separate from anything you type into this site or the app.
The CoreProof products themselves are deterministic: outputs come from rules that cite the clause they came from and are reviewed by a qualified person. Where AI has been involved in producing anything a customer relies on, we disclose it. If you are assessing us and want the detail, ask and we will provide our internal AI and third-party material disclosure record.
12. Access, correction and deletion
You can ask us at any time to:
- Tell you what we hold about you;
- Correct anything that is wrong or out of date;
- Delete it — including closing your account, deleting your profile and logo, or removing you from the waitlist;
- Send you a copy of what you gave us.
It does not reach your device, and it could not. Your sites, photographs, drawings, sheets, notes and exported reports were never uploaded to us, so there is nothing of them for us to delete. They stay on your device and the app keeps opening them; removing them is yours to do, and section 4 is the reason. The letterhead your device prints from is a copy held on the device: deleting the account does not clear that copy, and you can still change or clear it in the app afterwards.
Today we do this by hand, when you ask. The service that would perform a deletion from inside the app is not switched on yet, so email is the route that works — and it is a route that never depended on our software working, which is the point of stating it here rather than waiting. Write to the address below and we complete it within 30 days, as section 8 says.
Email support@coreproofai.com. We aim to respond within 5 business days and to complete the request within 30 days.
There is no charge. We may need to confirm your identity first, and we will only ask for what is necessary to do that. If we cannot action a request in full, for example because we must retain a record to meet a legal obligation, we will tell you why in writing.
You do not need an account, a form, or a particular form of words. An email saying "take me off the waitlist" is enough.
13. Complaints
If you think we have mishandled your personal information, tell us first at support@coreproofai.com. We will acknowledge it within 5 business days and give you a written response within 30 days.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner: oaic.gov.au, or 1300 363 992.
14. Changes to this policy
We will update this policy as the business changes. The version number and date at the top always tell you which version you are reading.
If a change materially reduces the protections described here, and we hold your email address, we will email you before it takes effect rather than quietly republishing the page.
Two changes are already coming.
- CoreProofAI is to be incorporated as an Australian proprietary company. When that completes, this policy will be reissued in the company's name with its ACN, the placeholders in section 1 will be replaced with real identifiers, and the company will assume the commitments made here.
- This draft must be reviewed by a lawyer, and the review may change it. Version 3.0 will be the reviewed one, and the draft banner comes off then — not before.
15. Contact
Privacy questions, access requests, corrections, deletions and complaints all go to the same place, and a person reads it.
There is no postal address to give you yet, for the same reason there is no ACN: REGISTERED ADDRESS — NONE YET
CoreProofAI · Australia · Support · Terms of Use