Privacy Policy
Last updated: 2026-08-24
1. Data controller
Lagodish Tech operates RealityProof and is the controller of personal data processed through the RealityProof iOS application, website, public verification service, and related APIs (together, the “Service”).
- Operator: Lagodish Tech
- Country / city: Poland, Warsaw
- Address: Złota 75A, 00-819 Warszawa (Wola), Poland
- Privacy contact: support@realityproof.app
We have not appointed a Data Protection Officer. Send privacy and data-rights requests to the privacy contact above.
2. Data we collect
The data depends on the features and disclosure level you choose:
- Proof and session data — verify ID, hashed owner token, disclosure level, bundle and artifact hashes, verification results, status, plan snapshot, and capture timing when selected.
- Scan artifacts — artifact hashes by default. If temporary file retention is available and you enable it, scene files, sensor sidecars, proof bundles, presentation copies, and related metadata are uploaded for the selected lifetime. Temporary public file hosting is disabled in the initial release.
- Location — only when you grant iOS location permission and choose a disclosure level that includes location.
- Device and attestation data — app version, device model, operating system, Apple App Attest key identifier and assertion material, hardware signature evidence, and a derived attestor identifier used for integrity, quota, and abuse prevention. Public app-key details are shown only at a disclosure level that includes them.
- Subscription and purchase data — a randomly generated app account token, StoreKit product ID, original and latest transaction IDs, purchase, expiration, and revocation dates, App Store environment, a hash of the signed transaction, and the resulting plan status. We do not receive your full payment-card details or Apple Account password.
- Analytics data — after website analytics consent, Google Analytics 4 may receive pages viewed, session information, approximate region, and browser/device details. When enabled in the iOS app, Firebase Analytics records app interactions, sessions, approximate region, device information, and bounded purchase-flow events without advertising identifiers.
- Support data — the contact method and message you submit, together with limited request metadata such as IP-derived country and abuse-prevention signals.
- Service and security logs — Cloudflare, Vercel, and API request metadata needed for delivery, reliability, rate limiting, fraud detection, and security.
3. How data is collected
- Directly from you when you capture, publish, disclose, or contact us;
- From the app and device when they create proof and attestation material;
- From Apple when StoreKit verifies or updates a subscription transaction;
- Automatically from hosting, security, and analytics services as described above.
4. Purposes and legal bases
For EEA and UK users, we rely on the following legal bases:
- Contract — creating and verifying proofs, applying the selected disclosure level, administering subscriptions and plan limits, and responding to service requests.
- Legitimate interests — protecting the Service, preventing fraud, replay and abuse, maintaining reliability, and handling ordinary support. We balance these interests against affected users’ rights.
- Consent — optional location access and disclosure, website analytics cookies, and any other feature for which consent is requested. Consent can be withdrawn at any time.
- Legal obligation — tax, accounting, consumer, law-enforcement, and compliance records when applicable.
We do not sell or rent personal data and do not use proof data for advertising.
5. Public verification and disclosure
A verify ID can be queried without authentication. The response follows the selected disclosure level:
- Hashes only — status, proof level, hashes, and public check names;
- Time only — hash-only fields plus selected capture timing;
- Time + location — time fields plus captured location when available;
- Full proof — checks, artifact metadata, retained links, nonce details, and app-key detail needed for deeper third-party verification.
Anyone who receives a verify ID may query and copy the disclosed fields. Do not publish a verify ID or select a more revealing level unless you are comfortable with that exposure.
6. Service providers and recipients
- Apple — StoreKit subscriptions and App Attest integrity checks;
- Cloudflare — network protection, delivery, and opt-in R2 artifact storage;
- Vercel — website, API hosting, and serverless execution;
- Postgres infrastructure provider — proof, entitlement, and verification records;
- Google — consent-gated Google Analytics 4 and Firebase Analytics;
- SpaceComputer Orbitport — optional satellite nonce and experimental witness services;
- Telegram and email providers — support and contact-form delivery;
- Public verification users and networks — fields you disclose and future public hash anchoring.
Providers act under their own terms and data-processing commitments. Where personal data is transferred outside the EEA or UK, we rely on an applicable adequacy decision, contractual safeguards such as Standard Contractual Clauses, or another lawful transfer mechanism. You may request information about applicable safeguards from us.
7. Retention and deletion
- Local captures remain on the iPhone until you delete the scan or app, erase the device, or otherwise lose local storage. They are not a cloud backup.
- Hash proof records are retained while needed to provide public verification, preserve security and fraud evidence, and resolve disputes. We assess deletion requests against those purposes and applicable legal obligations.
- If temporary artifact hosting is enabled, retained files expire after the lifetime selected in the app, currently constrained by the Service to between one hour and seven days.
- Subscription records are retained while needed to administer entitlements, prevent purchase fraud, resolve billing disputes, and comply with accounting and legal obligations.
- Support messages and service logs are retained only while needed for the request, security purpose, dispute, or provider-configured operational period.
- Analytics data follows the retention settings of the relevant Google Analytics or Firebase property. Cookie lifetimes are listed in our Cookie Policy.
Public blockchain transactions and information already copied by independent third parties may be technically impossible for us to erase.
8. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, portability, restriction, or objection. You may deny or revoke iOS permissions, choose a less revealing disclosure level, and change website analytics consent through the Cookie settings control in the footer. Withdrawing consent does not affect processing that was lawful before withdrawal.
Send requests to support@realityproof.app. We may ask for information necessary to verify that a request relates to you. You may also complain to your local data-protection authority. Our lead supervisory authority is the Urząd Ochrony Danych Osobowych (UODO) in Poland.
9. Required and optional data
Proof hashes, session integrity data, and device attestation are necessary to publish a verifiable proof. StoreKit transaction data is necessary to activate and maintain Pro. Without those data, the corresponding publishing or subscription feature cannot operate. Location, expanded disclosure, temporary file retention, analytics, and contact-form use are optional.
10. Automated decisions
Automated cryptographic checks may accept or reject a proof session or subscription entitlement. They do not make decisions that produce legal or similarly significant effects about a person. Contact support if you believe an automated check is incorrect.
11. Security
We use HTTPS, scoped upload URLs, hashed owner and attestor identifiers, transaction signature verification, access controls, and secret redaction. No service is perfectly secure. Avoid scanning sensitive people, spaces, documents, or objects unless you are comfortable with the selected disclosure level.
12. Children
The Service is not directed to children under 13. Where local law sets a higher age for independent consent to online services, a parent or guardian must provide any required authorization.
13. Changes and contact
We may update this policy as the Service or law changes. We will update the date above and provide additional notice when a material change requires it. Questions and requests may be sent to support@realityproof.app or by post to Lagodish Tech, Złota 75A, 00-819 Warszawa (Wola), Poland.