Privacy, in plain language.

Field Report is designed so field evidence can remain on your device. This policy explains the smaller set of information used for accounts, purchase access, support, and the website.

Effective October 7, 2026

1. Scope

This policy applies to the Field Report mobile application and the website at brightkitss.com. It does not apply to third-party services such as Google Play, which publish their own policies.

The current public website does not use advertising cookies, behavioral analytics, or third-party tracking pixels.

2. Information kept on your device

Project details, customer and site information, photos, descriptions, annotations, signatures, report settings, backups, and generated PDF reports are stored locally by the app. Field Report uploads a PDF snapshot and its issue titles only when you explicitly publish a customer link. This may include the photos, site details and signatures present in that PDF. You can also explicitly assign a team task: its selected issue details and before photos are uploaded, along with rectification photos and notes submitted by the assignee. When an administrator enables a team project, its name and membership permissions are stored online. Authorized members can submit issue descriptions and photos directly to that project. Other project contents stay on your device. Anyone with the link can view the snapshot without an account. Later local edits do not automatically update it.

Offline speech recognition runs on the device. The app uses microphone audio to produce text and does not retain the raw audio recording after recognition.

3. Account and purchase information

A verified email account is required before using the mobile app. Passwords, when set, are stored using salted Argon2id hashes. The service processes your normalized email address, a stable account identifier, verification requests, session credentials, and security rate-limit data. Session tokens are stored as hashes on the server. Account records can be counted to understand how many verified users have registered; project contents and usage events are not sent for this count.

If Google Play purchasing becomes available and you buy or restore Pro, the service processes purchase identifiers and entitlement status needed to verify ownership, prevent one order from being assigned to multiple accounts, and restore access. Field Report does not receive your payment-card details.

The seven-day trial is tied to the earliest registration of your verified email, rather than installation on a device. We retain a hashed normalized-email identifier and its original trial start date to prevent repeat trials after reinstalling or deleting and recreating an account. This limited record does not contain your project data or the email address itself.

The account service is hosted in Japan. Account information may therefore be processed outside your country.

4. Contact form

When you send the website contact form, we process the name, email address, topic, and message you provide. The website service sends that information to the Field Report support inbox. It is not added to your mobile projects or used to analyze field evidence.

Do not include passwords, verification codes, purchase tokens, or confidential customer photos and reports in the form.

5. Service providers

  • Google Play may provide purchase and license information when billing is enabled.
  • Gmail SMTP delivers verification and contact emails.
  • Amazon Web Services hosts the account and contact service in Japan.
  • Cloudflare provides DNS, TLS edge protection, network security, and the Turnstile human-verification challenge shown before requesting a login code. Cloudflare receives challenge and network data such as IP address to assess abuse; Field Report sends the resulting token and IP address to Cloudflare for server-side verification.

These providers may process network metadata such as IP addresses under their own terms and policies.

Customer report links and feedback

Customer links expire after 30 days. You can revoke a link in the app; revocation immediately blocks access and removes the online PDF. Feedback, including the optional self-reported name, selected issue, response and message, is available to the publisher until expiry. These replies are not authenticated customer approvals and do not automatically change issue status.

Expired shares and feedback are removed from the live service within one hour. Account deletion removes all your shared reports and feedback. Shared report and feedback contents are excluded from routine database backups. Customers may retain any copies they have already downloaded. Link requests use IP addresses temporarily for abuse rate limits. Shared content is hosted in Japan.

6. Retention

  • On-device content remains until you delete it, clear app data, or remove the app. Use project backups if you need to transfer or preserve work.
  • Account email and active sessions remain until account deletion or the applicable session expiry and revocation process.
  • Security rate-limit records are temporary. The hashed email trial identifier and original start date are retained for as long as this trial offer is available to prevent repeat trials.
  • Contact messages are retained only as reasonably needed to reply, resolve the request, and maintain support records.
  • Encrypted purchase identifiers and limited order history may be retained after account deletion where necessary to prevent purchase reassignment, fraud, or entitlement disputes. Account access is disabled when deletion is confirmed.

7. Your choices

After email sign-in, you can use the core local workflow without uploading project evidence. Signing out locks the app until you sign in again but does not delete local projects. A signed-in user can request permanent account deletion in the app; see the account deletion guide.

Deleting an account is not a Google Play refund and does not delete projects, photos, or reports stored on the device. Those must be deleted locally. Local projects are not separated by email account on the same device.

8. Security and changes

The service uses HTTPS, restricted network access, hashed session credentials, encrypted stored purchase tokens, and rate limits. No system can guarantee absolute security, so keep your device protected and do not share verification codes.

We may update this policy as the product and its release status change. The effective date at the top will be revised when material changes are published.

Questions about this policy can be sent through the contact form using the “Privacy request” topic.

Team licensing

For team licenses, we store the purchaser, assigned member accounts, and assignment dates to manage access. Administrators can view the email addresses of members they authorize. Members can see the email address of their authorizing administrator. This does not grant administrators access to members’ local projects or photos. Deleting an account removes its team memberships; deleting the purchasing account also removes its team authorizations.

Team task collaboration

Task uploads are limited to the selected issue description, project name, due date and selected photos. The current assignee can access only tasks assigned to their account while their team and project memberships are valid and the project is active. Submitting rectification evidence also requires the project’s rectification permission. The administrator can review task submissions and import approved evidence into their local project and report. Reassignment or revocation removes the former assignee’s online access, but cannot remove copies they already saved.

Cloud tasks and submission history remain until the administrator deletes the closed task or an involved account is deleted. We store cloud entitlement expiry, team storage usage and monthly image download totals to enforce plan allowances. Cloud expiry pauses photo transfers without automatically deleting cloud evidence. Deleting a cloud task does not remove approved evidence already imported into a local project, report or backup. Rectification drafts are saved on the device under the signed-in account and can be edited or removed before submission. Cloud task photos are compressed and location metadata is removed before upload. The service is hosted in Japan. Shared team photos are stored encrypted in a private Amazon S3 bucket in Japan; the app retrieves them through authenticated server requests. Deleting cloud evidence removes its online access immediately. Unreferenced photo objects are normally removed within 24–48 hours by scheduled cleanup; copies already saved on devices, in reports or backups are not removed by that cleanup.

Team projects and member reports

Administrators choose project members and separately control issue reporting and rectification permissions. Project identity, customer details, PDF formatting, branding and signatures remain under administrator control. Members see issues they reported and tasks assigned to them. Reports are added directly without an approval step; administrators can synchronize the evidence into their existing local project, PDF and backups.

Removing a project member revokes online access but keeps their submitted reports in the project. Administrators can delete cloud reports; this does not remove copies already synchronized to devices, PDFs or backups. Account deletion removes reports submitted by that account and projects owned by it. Unsent issue drafts are stored locally under the signed-in account. Photo location metadata is removed before upload.