Privacy Policy
SnagProof stores your inspection data on your device. There is no account, and we operate no service that receives your reports.
Last updated 9 September 2026.
1. Summary
- No account, sign-in, email address or telephone number is required to use the app.
- Properties, rooms, condition ratings, notes, meter readings, photographs, signatures and generated reports are held only in the app's private storage on your device.
- We operate no server, database, sync service or backup of any kind. The app has nowhere to send anything to.
- The app contains no third-party software development kits at all. Subscriptions are handled by Apple's own StoreKit, which keeps the entitlement on your device, so not even your purchase status is transmitted to us.
- A report leaves your device only when you choose to share or export it.
- We do not sell or share personal data, do not use it for advertising, do not profile you and do not track you across other apps or websites.
- The app does not ask for permission to track, because it does not track.
2. Who we are
SnagProof is provided by Valentin Jieanu, a sole trader established in Abu Dhabi, United Arab Emirates (“we”, “us”, “our”). We are the controller of the limited personal data described in section 8.
Privacy correspondence: support@jiea.nu. We aim to acknowledge within seven days and to answer substantively within one month, which is the deadline the General Data Protection Regulation sets. Where a request is complex we may extend by up to two further months and will tell you if we do.
We are not required to appoint a statutory data protection officer, and have not done so. Privacy matters are handled by the owner personally.
3. Definitions
- App means the SnagProof application for iPhone.
- Personal data means information relating to an identified or identifiable living individual.
- Processing means anything done with personal data, including collecting, recording, storing, altering, disclosing and erasing it.
- Controller means the party that decides why and how personal data is processed.
- Processor means a party that processes personal data on a controller's behalf and on its instructions.
- Inspection Content means everything you record with the App: addresses, references, names, condition ratings, notes, meter readings, photographs, signatures, branding and generated reports.
- Data subject means the individual the personal data is about, which in this context is usually the buyer carrying out the inspection, and occasionally a developer's representative named in a note.
- UK GDPR and EU GDPR mean the United Kingdom and European Union General Data Protection Regulations respectively.
4. Scope
This notice covers the App and the websites at snagproof.jiea.nu and
jiea.nu. It does not cover:
- what a recipient does with a report after you send it to them, which is governed by that recipient's own practices and by the service you used to send it;
- Apple's processing of your Apple Account, payment method, download history and subscription, which Apple carries out as its own controller under its own privacy policy;
- your own handling of Inspection Content, which is addressed in section 5;
- any third-party website this notice links to.
5. Controller and processor roles
This is the most important section for professional users, because it determines who carries which legal obligation.
- You are the controller of Inspection Content. When you record an address, a person's name, notes about a home or photographs of its possessions, you decide why and how that personal data is processed. You are its controller.
- We are not a processor of Inspection Content. A processor processes personal data on a controller's behalf. Because Inspection Content never leaves your device and is never transmitted to us, we carry out no processing of it whatsoever. We therefore neither offer nor need a data processing agreement, standard contractual clauses or a sub-processor list in respect of it, and any request for one would be answered with a copy of this section.
- Your obligations as controller include, where applicable: identifying a lawful basis for the recording; providing those people with the information they are entitled to receive; honouring their rights of access, rectification, erasure, restriction, portability and objection; keeping the data no longer than necessary; keeping it accurate; applying appropriate security; and assessing whether a data protection impact assessment is required. These requirements differ by country, state, province and tenancy type.
- Practical security measures available to you are a device passcode, Face ID or Touch ID, prompt iOS updates, encrypted backups, Find My iPhone with remote erase, and deleting inspections you no longer need. We recommend all of them. A device without a passcode is materially less protected, because iOS file encryption is tied to it.
- Data minimisation is in your hands. The App does not require you to record anyone else's name, and never requires their contact details, date of birth or any identifier. Record the minimum that serves your purpose.
- We are the controller of the separate and limited personal data described in section 8.
6. UK and EU representation
We are established outside the United Kingdom and the European Economic Area. Where a controller outside those territories offers goods or services to individuals within them, Article 27 of the UK GDPR and of the EU GDPR can require the appointment of a written representative in the territory concerned, unless the processing is occasional, does not involve large-scale special category or criminal offence data, and is unlikely to result in a risk to individuals.
Our own processing is limited to subscription status and correspondence, as set out in section 8, and we hold no Inspection Content. We are reviewing whether a representative is required on that basis. If we appoint one, this section will name them and give their contact details, and they may be contacted instead of us on any matter relating to this notice. Until then, all requests should be sent to support@jiea.nu, which is monitored and will not delay your request.
7. What stays on your device
The following are written to the App's private container, protected by iOS application sandboxing, and are not transmitted to us:
| Category | Examples |
|---|---|
| Property records | Address, agency or unit reference |
| Inspection records | Visit type, dates, inspector name, property and unit details, developer name, handover date, defect descriptions and notes |
| Condition records | Rooms, line items, condition ratings, item notes, conditions carried forward from an earlier visit |
| Photographs | Images you capture or select, including those copied forward from an earlier inspection |
| Signatures | Handwritten marks captured on the device and the date each was given |
| Branding | Your company name, contact details and logo |
| Preferences | Your default inspector name and whether you have seen onboarding |
| Generated reports | PDF files produced on the device |
Photographs are stored as files in the App's own storage area, not in your system photo library, unless you separately choose to save one there. Reports are generated on demand into temporary storage and regenerated rather than cached indefinitely.
If you use iCloud Backup or encrypted local backups, iOS may include the App's data in your own backups. That backup is held under your Apple Account, not ours, and we have no access to it. Whether the App's data is included is determined by your iOS settings.
8. Record of processing
This is the complete set of personal data we process as controller. It is short, because the application itself sends us nothing.
| Data | Source | Purpose | Basis | Kept |
|---|---|---|---|---|
| Your email address and the content of your message | You, if you write to us | Answering you; keeping a record of the issue | Contract, or legitimate interests where no contract exists | Up to 24 months after closure |
| Connection metadata: IP address, timestamp, page, user agent | Your browser, via Cloudflare, when you visit our websites | Delivering the websites; preventing abuse | Legitimate interests | Cloudflare's own periods, typically days |
| Aggregated sales and download reporting | Apple | Understanding demand and meeting accounting obligations | Legitimate interests; legal obligation | Up to 7 years for tax purposes |
8.1 Subscriptions send us nothing
SnagProof Pro is sold through Apple. The application uses Apple's StoreKit framework, which records your entitlement on your own device and answers the only question the app asks: is this installation subscribed. That exchange is between your device and Apple. We are not a party to it and receive no identifier, no receipt and no record of your purchase.
Apple provides us with aggregated sales reporting, such as how many subscriptions were active in a month and in which countries. It identifies nobody.
Earlier drafts of this notice described a third-party subscription service. That service was removed before release precisely so that the statement above could be made without qualification.
8.2 What we do not collect
We do not collect your name, postal address, telephone number, date of birth, location at any level of precision, contacts, calendar, health or fitness data, financial account data, browsing history outside our own sites, advertising or device identifiers, purchase identifiers, or any usage, crash, behavioural or diagnostic telemetry. The application contains no analytics code and makes no network request of its own. Should that ever change, this notice will be updated before the change ships, the change will be described in the release notes, and Apple's privacy declarations will be updated to match.
Reminders
SnagProof can remind you to chase a developer, to escalate, and to walk the property again before the developer's liability period ends. The App works out those dates on your own device from the handover date and the defects you have recorded, and schedules them through Apple's local notification system. No reminder is sent from a server, nothing about your property or your defects leaves the device in order to schedule one, and we cannot see that a reminder exists or that one has fired. Turning notifications off in iOS Settings stops them, and nothing else about the App changes.
Writing up defects on your device
Where your device supports Apple Intelligence, the App can turn a sentence you dictate or type into a written-up defect with a severity and a trade. This runs on your device using Apple's on-device model. What you write or say is not sent to us, and we receive no copy of it and no record that the feature was used at all. If the feature is unavailable on your device, or you would rather not use it, every field it fills in can be typed by hand.
9. Device permissions
| Permission | Why we ask | If you decline |
|---|---|---|
| Camera | To photograph the condition of rooms and items. Images go directly into the App's own storage and are not sent anywhere. | The App works normally; you cannot capture new photographs. |
| Photo library | So you can attach images you already have, and choose a logo. iOS gives the App only the specific items you pick. | The App works normally; you cannot attach existing images. |
You can change either permission at any time in the iOS Settings application, and doing so does not affect data already recorded. We do not request location, contacts, microphone, calendar, reminders, Bluetooth, local network, motion, notification, HealthKit or HomeKit access. The App does not use HealthKit or HomeKit at all.
6.5 Subscription reporting
Our subscription provider presents purchase data back to us as aggregated reporting: how many people subscribe, how many cancel, how many trials convert. We use it to judge whether the product is working and what to build next. We declare this to Apple as an analytics use of purchase history, because Apple's definition of analytics includes measuring audience size.
This reporting is about the subscriber base as a whole. We do not build a profile of you, do not track individual behaviour, and cannot connect any of it to your name, your email address or your inspection content, none of which we hold.
10. Tracking, advertising and IDFA
- The App does not track you. It does not link data collected from it with data from other companies' apps or websites for advertising or measurement.
- The App does not access the Identifier for Advertisers, and therefore does not present the App Tracking Transparency permission prompt. If you ever see such a prompt attributed to SnagProof, it is not our software.
- We run no advertising, sell no advertising space and share nothing with data brokers, ad networks or attribution providers. There is no third-party software in the app that could do so on our behalf.
- Where a browser or platform sends a Do Not Track or Global Privacy Control signal, there is nothing for it to switch off, because we neither sell nor share personal data nor conduct targeted advertising.
- Our declarations in Apple's App Privacy section of the App Store are intended to match this notice. If you believe they diverge, tell us and we will correct whichever is wrong.
11. Local storage and cookies
The App stores small preferences on the device using the standard iOS preferences system: your default inspector name, your branding, and whether onboarding has been completed. These are ordinary application settings, remain on the device, and are removed when the App is deleted.
The websites set no cookies, use no local or session storage, and embed no pixels, beacons, fingerprinting scripts or third-party tags. No consent banner is presented because there is nothing to consent to.
12. The websites
The websites are static pages. They ask you for nothing, and the sign-in form at
jiea.nu/login is not connected to any authentication service, so anything
typed into it is not transmitted, stored or received by anyone.
The sites are delivered by Cloudflare, Inc., which in providing that service processes connection metadata as described in section 8. This is an unavoidable feature of using a content delivery network, and is necessary both to deliver the pages and to protect them from attack. Our basis is our legitimate interest in operating a secure website, and the impact on you is minimal.
We send no marketing email, operate no mailing list and have no newsletter. If you write to us, we reply; we will not add you to anything.
13. Legal bases
Where the UK or EU GDPR applies, we rely on the bases stated in the table in section 8. Expanded:
- Performance of a contract, Article 6(1)(b), for verifying a subscription and providing what you paid for.
- Legal obligation, Article 6(1)(c), for tax, accounting and statutory record keeping.
- Legitimate interests, Article 6(1)(f), for website security and delivery, for answering correspondence where no contract exists, and for establishing, exercising or defending legal claims. In each case we have weighed the processing against your interests and concluded it is limited in scope, is what a reasonable person would expect, and cannot sensibly be achieved another way. You may ask us for our assessment.
We do not rely on consent for any processing we carry out, so there is no consent for you to withdraw. We do not carry out direct marketing.
14. Special category data
We do not seek, request or knowingly process special category data, meaning data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data processed for identification, health data, or data concerning sex life or sexual orientation.
You should be aware, as controller, that photographing the interior of an occupied home can incidentally capture such information: medication on a worktop, a mobility aid, religious articles, political material, or images of children. Consider whether a photograph is necessary, whether it can be framed to exclude what is not relevant to condition, and whether your lawful basis and any applicable condition for processing special category data are satisfied. The App does not require you to photograph anything.
15. Signatures and biometrics
- A signature captured in the App is an image of a mark drawn on a touchscreen. The App records the resulting image and the date and time it was given.
- The App does not capture, measure or retain the dynamic characteristics that turn a signature into biometric data, such as pressure, stroke velocity, acceleration or pen angle, and does not use any signature to identify or verify a person's identity.
- On that basis we do not consider a captured signature to be biometric data processed for the purpose of uniquely identifying a natural person under Article 9 of the UK or EU GDPR, nor a biometric identifier under statutes such as the Illinois Biometric Information Privacy Act or the Texas Capture or Use of Biometric Identifier Act. Neither we nor the App performs any identification, verification or matching.
- Signatures are held on your device only. As controller you should collect one only where it serves your purpose, and should tell the signatory what it will be used for.
- The App is not a qualified or advanced electronic signature service and makes no claim about the legal effect of a signature it captures.
16. Payment data
Apple is the merchant of record for all purchases and acts as its own controller for the payment. We never receive, process, transmit or store your card number, card verification value, expiry date, bank details, billing address or Apple Account credentials, and we receive no identifier tied to your purchase. We are therefore outside the scope of the Payment Card Industry Data Security Standard, cannot see your payment method, and cannot charge you outside the App Store.
17. Service providers
| Provider | Role | Data | Primary location |
|---|---|---|---|
| Apple Inc. and Apple Distribution International Ltd | Distribution, payment, subscription management. Acts as its own controller | Apple Account, payment method, purchase history | United States; Ireland for EU customers |
| Cloudflare, Inc. | Processor, website delivery and protection | Connection metadata | Global edge network |
| Apple iCloud Mail | Processor, our support mailbox | Support correspondence | United States; Ireland |
Each provider is engaged under terms requiring confidentiality, appropriate security and processing only on our instructions where they act as processor. We do not permit them to use the data for their own purposes. Note that no provider in this list receives anything from the application itself: Apple's role concerns distribution and payment, and Cloudflare's concerns our websites. If we ever added a provider that received data from the app, this notice and Apple's privacy declarations would be updated before the change shipped.
18. International transfers
We are established in the United Arab Emirates and our providers are established in the United States and operate globally. Where personal data originating in the United Kingdom or the European Economic Area is transferred, the transfer relies on one of the following, as offered by the provider concerned: an adequacy decision; the European Commission's Standard Contractual Clauses; the United Kingdom's International Data Transfer Agreement or Addendum; or another mechanism recognised under Article 46.
Where required we have considered the destination country's laws and any supplementary measures needed. You may ask us which mechanism applies to a given provider. Inspection Content is not transferred anywhere, because it does not leave your device.
19. Retention
Retention periods appear in the table in section 8. In addition:
- Inspection Content is kept until you delete it. Deleting an inspection also deletes its photographs and signatures from device storage. Deleting a property deletes its inspections. Deleting the App removes the entire data container.
- Where we must keep records for tax or accounting, we keep only what the obligation requires and delete the rest.
- Where data is relevant to an actual or reasonably anticipated legal claim, we may retain it until the claim is resolved and any appeal period has expired.
- At the end of a retention period, data is deleted or irreversibly anonymised.
20. Security
Our security position is largely structural: the most sensitive data in this product never reaches us, so no breach of ours can expose it.
- Inspection Content sits in the App's sandboxed container, which other applications cannot read.
- Data at rest on the device is protected by iOS file encryption, keyed to your device passcode.
- All network communication by the App and the websites uses Transport Layer Security. The App makes no unencrypted network requests.
- Photographs are downscaled and re-encoded on capture, which strips camera metadata that the original file may have carried.
- Our developer, subscription and hosting accounts are protected by strong unique credentials and two-factor authentication, and access is limited to the owner.
- We keep no production copy of customer data to lose.
No method of storage or transmission is completely secure and we cannot guarantee absolute security. We are not responsible for the security of a device you have lost control of, or that has been jailbroken or modified to defeat iOS protections.
21. Your rights
Where the UK or EU GDPR applies you have the rights of access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and the right not to be subject to solely automated decisions with legal or similarly significant effect. Exercise any of them by writing to support@jiea.nu.
We will not charge you and will not treat you detrimentally for asking. We may request information to verify your identity, and may refuse a manifestly unfounded or excessive request, giving our reasons and telling you how to complain.
Two practical limits follow from the architecture:
- We cannot supply a copy of your Inspection Content, because we do not hold it. It is on your device, where you can already read, edit, export as PDF and delete all of it, which satisfies access and portability in substance.
- We cannot erase your Inspection Content on your behalf, for the same reason. You can, at any time, without asking us.
If someone contacts us about data you recorded, we will explain that we do not hold it and direct them to you as controller. We may pass their request to you if we can identify you, and you must respond to it.
22. Employees and colleagues
If you provide the App to employees or contractors, the inspector names and signatures they enter are personal data about them, and you are its controller. Tell them what is recorded and why. We receive none of it.
23. Deceased persons
The UK and EU GDPR do not apply to data about deceased people, though other duties of confidence may. Where an inspection concerns the property of someone who has died, handle the records with the same care and consider the interests of the estate and of surviving records.
24. Children
SnagProof is a professional tool. It is not directed at children, is rated for ages four and over only because it contains no objectionable content, and we do not knowingly collect personal data from anyone under thirteen, or under sixteen where local law sets that threshold. If you believe a child has given us personal data, contact us and we will delete it promptly.
If your records include information about children living at a property, you are its controller and should consider carefully whether recording it, and in particular photographing it, is necessary.
25. Automated decisions
We carry out no automated decision-making producing legal or similarly significant effects, and no profiling. Deterioration flags and condition counts in the App are arithmetic on values you entered yourself; they assess a worktop, not a person. Nothing in the App scores, ranks, predicts or infers anything about an individual.
26. Security incidents
If a breach of the limited data we hold occurs and is likely to result in a risk to individuals' rights and freedoms, we will notify the competent supervisory authority without undue delay and within seventy-two hours where required, and will inform affected individuals without undue delay where the risk is high. We will tell you what happened, what data was involved, what we are doing and what you can do.
A compromise of your own device, or of a service you sent a report to, is not a breach of ours. Assessing it, notifying where required and mitigating it are your responsibilities as controller, and we will assist with information where we can.
27. Government requests
We will disclose personal data to a public authority only where we are legally obliged to, and only what the obligation requires. We will satisfy ourselves that a request is valid, and will challenge one we consider overbroad or unlawful. Where we are permitted to notify you of a request we will do so.
We cannot be compelled to produce Inspection Content, because we do not have it. A request for it would have to be addressed to you.
28. Business transfers
If the business is sold, merged or reorganised, the data described in section 8 may transfer to the acquirer, who would be bound by terms no less protective than this notice for data collected before the transfer. We would announce such a change in the App's release notes and on this page before it took effect.
29. Anonymised data
We may create aggregated or anonymised statistics, for example total downloads or the proportion of subscribers on the annual plan. Once data is genuinely anonymised it is no longer personal data and this notice does not restrict its use. We do not attempt to re-identify anonymised data.
30. California
Under the California Consumer Privacy Act as amended by the California Privacy Rights Act, we disclose the following for the preceding twelve months.
- Categories collected: identifiers, limited to your email address if you write to us; and internet or network activity, limited to website connection metadata. Nothing is collected from the application.
- Categories of sources: you, and your browser via Cloudflare.
- Business purposes: as stated in sections 8 and 13.
- Categories disclosed for a business purpose: the above, to the service providers named in section 17, each under a contract restricting their use. No personal information is disclosed by the application, which transmits none.
- Sale or sharing: none. We have not sold personal information and have not shared it for cross-context behavioural advertising, and we have no actual knowledge of selling or sharing the personal information of consumers under sixteen.
- Sensitive personal information: we collect none, and therefore do not use or disclose any beyond the purposes for which a right to limit does not apply.
- Retention: as stated in section 8. We do not retain personal information for longer than reasonably necessary for the stated purpose.
- Your rights: to know, access, correct, delete, port, and to opt out of sale, sharing and certain profiling. Since we do not sell, share or profile, there is nothing to opt out of. Write to support@jiea.nu. We will respond within forty-five days, extendable once by a further forty-five where necessary.
- Authorised agents may act for you on proof of authorisation; we may still verify your identity directly.
- No discrimination: we will not deny you goods or services, charge a different price or provide a different quality because you exercised a right, and we operate no financial incentive programme.
31. Other US states
Residents of states with comprehensive privacy statutes, including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, Nebraska, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island, have broadly equivalent rights to confirm, access, correct, delete and port personal data, and to opt out of targeted advertising, sale and profiling in furtherance of decisions producing legal or similarly significant effects. We conduct none of those activities, so there is no opt-out to give.
We do not process sensitive data and therefore do not seek the consent some of those statutes require for it, and we conduct no data protection assessment because no triggering activity occurs. Requests, and appeals against a refusal, may be sent to support@jiea.nu; if we deny an appeal we will tell you how to contact your state attorney general.
32. Other countries
The App is available in many territories. The following also apply where relevant, and the same contact address serves for all of them.
| Territory | Law |
|---|---|
| United Arab Emirates | Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data |
| Switzerland | Federal Act on Data Protection, revised |
| Brazil | Lei Geral de Proteção de Dados |
| Canada | Personal Information Protection and Electronic Documents Act, and provincial equivalents |
| Australia | Privacy Act 1988 and the Australian Privacy Principles |
| New Zealand | Privacy Act 2020 |
| Japan | Act on the Protection of Personal Information |
| South Korea | Personal Information Protection Act |
| India | Digital Personal Data Protection Act 2023 |
| South Africa | Protection of Personal Information Act |
| Saudi Arabia | Personal Data Protection Law |
Where any of these grants you a right this notice does not mention, you have that right and we will honour it. Where one imposes a stricter standard than we describe, the stricter standard applies to that processing.
33. Accessibility of this notice
This page is plain HTML with semantic headings, sufficient colour contrast, no reliance on colour alone, and a table of contents. It respects your system light or dark appearance and your reduced-motion preference. If you need this notice in another format, such as large print or plain text, write to support@jiea.nu and we will provide one.
34. Third-party links
This notice and our sites link to third-party pages, including Apple's refund process and the privacy authorities named in section 36. We do not control those sites, do not endorse them, and are not responsible for their content, security or privacy practices. Read their own notices before providing them with information.
35. Changes
We may update this notice to reflect changes in the App, our providers or the law. The date at the top changes whenever we do. Material changes, in particular any change that would begin sending your data off the device, will be described in the App's release notes, will take effect prospectively only, and will never be applied retroactively to data already collected under an earlier version.
Continuing to use SnagProof after a change takes effect means you accept the updated notice. If you do not accept it, stop using the App and cancel any subscription. Earlier versions are available on request.
36. Complaints
Please raise any concern with us first at support@jiea.nu; we would rather have the chance to put it right. You may also complain to a data protection authority, and doing so does not affect any other remedy.
- United Kingdom: the Information Commissioner's Office,
ico.org.uk. - European Economic Area: the supervisory authority of your country of residence, your place of work, or the place of the alleged infringement.
- United Arab Emirates: the UAE Data Office.
- Elsewhere: your national or state privacy regulator.
You may also have a right to an effective judicial remedy, and in some territories to compensation for damage caused by a breach of data protection law.