Legal
Privacy Policy
Draft — pending legal review before launch. Last updated 24 July 2026.
What we process
- Your build (.ipa / TestFlight), used only to run the audit.
- Demo credentials you optionally provide, used only to reach screens behind sign-in, stored encrypted.
- Screen recordings and screenshots produced during agent runs. These exist only for the duration of the run: the screenshots and the single frame taken at the moment a task failed are embedded in your report, and the source recordings are destroyed with the build.
- Findings, stored in a normalized, structured form.
Retention and deletion
Your uploaded build, the screen recordings, and the source screenshots are deleted when the audit completes — the report records the exact UTC deletion time. A run that fails holds the build for a 72-hour retry window and is then deleted the same way. Demo credentials are deleted with the build.
We retain no evidence artifacts after delivery. The visual evidence is embedded inside the report you receive, which is the only copy in existence; we cannot re-issue it. Findings are retained only in de-identified form.
Benchmarks
We use findings in aggregate, anonymous and de-identified form to produce category benchmarks and research. No individual customer, application, or finding is ever shared in identifiable form.
Legal basis and your rights
Where the GDPR applies, processing is carried out to perform the audit you request (contract) and for our legitimate interest in de-identified benchmarking. You may request access to, correction of, or deletion of your personal data. Because the service does not use accounts, requests are tied to your device/purchase identifier.
No accounts, minimal identity
AccessProof does not require an account. Purchases and credits are handled through the Mac App Store and bound to a device identifier rather than a stored profile.
Contact
Privacy requests: privacy@accessproof.dev.