Privacy Policy
Last updated 2026-10-07
AppEvidence is a phone-testing and evidence-capture tool. This policy describes, as accurately as we can based on how the app and its backend actually work, what data AppEvidence collects, how it is used, and how you can have it deleted. It also covers emails you choose to send to AppEvidence support, which are handled separately from the app — see Emails you send to support.
Account and sign-in data
You sign in to AppEvidence with your Google account, through Google's own Firebase Authentication and Credential Manager services. Google's sign-in service may retain your email address as part of your Google account record; that is Google's own infrastructure, not something AppEvidence's servers store. AppEvidence's own backend stores only an opaque identifier derived from your Google account, together with internal account status and timestamps (such as when your account was created and when you last signed in) — not your email address or display name.
Testing sessions and plan allowance
When you start, resume or capture in a testing session, the app sends the name of that action and the session's identifier (created on your device) with your signed-in session, so the server can confirm your access. Resuming and capturing are checked but not recorded. When you start a new testing session, the server records it so it can count your free-trial and monthly plan sessions: a one-way hash of the session identifier, when the session was started, whether it counted as a free-trial, plan or free-period session, and the plan it counted against, together with running totals of the sessions you have started. These records are linked to your AppEvidence account, contain no evidence content and nothing about the app you are testing, and are kept until your account is deleted. If you started any free-trial sessions, a minimal one-way coded record of how many is kept after your account is deleted, only so that the free trial is not given again to the same Google account; it contains no email address, name, evidence or session content and is not linked to the deleted account. See the Account Deletion page for details.
Evidence and test data
The screenshots, recordings, logs, and other evidence you capture while using AppEvidence to test an app are packaged and stored entirely on your own device. AppEvidence's backend has no route that accepts or stores this evidence content. If you choose to export or share a captured evidence package, that only happens when you explicitly use your device's own share function to send it somewhere yourself — AppEvidence does not upload it on your behalf.
App Health diagnostics
The version of AppEvidence published on Google Play does not send diagnostic data. Internal development builds can send a small, fixed set of operational signals — app version, build number, device class, Android API level, and workflow stage and error-category codes — to help us keep the app stable. That data is deliberately kept separate from your account: it is restricted to a fixed, narrow set of fields that structurally cannot include your evidence content, file paths, account identity, email address, or Billing information, and it is never linked back to your account. It follows its own retention schedule, independent of your account.
Subscriptions and payments
AppEvidence offers monthly subscriptions through Google Play. Payments are processed by Google Play: AppEvidence never receives your card or other payment details, and does not receive or store order numbers or prices. When you subscribe or change plan, the app sends the purchase token Google Play issues, together with the plan and your AppEvidence account identifier, to AppEvidence's backend, which checks the purchase with Google Play and acknowledges it. The app also gives Google Play a one-way hash of your AppEvidence account identifier, so that a purchase can be matched to the account that made it.
To provide your plan, the backend keeps a record of your subscription linked to your AppEvidence account: the plan, its state (for example active, pending or expired), when the current period ends, and when it was last checked with Google Play. The purchase token is stored only in encrypted form, using Google Cloud Key Management Service, and is otherwise referred to by a keyed hash. These records are kept until your account is deleted. Google Play keeps its own records of your purchases under Google's terms. Subscriptions are managed and cancelled in Google Play; deleting your AppEvidence account does not cancel a Google Play subscription.
Data we do not sell or share
AppEvidence does not sell your personal data, and we do not use any third-party analytics, advertising, or crash-reporting service. The following Google services process data collected through the app on AppEvidence's behalf, for the specific purposes below, and for no other purpose:
- Firebase Authentication and Android Credential Manager — to sign you in with your Google account.
- Google Play Billing and the Google Play Developer API — to process subscriptions, and to verify, acknowledge and check the status of purchases.
- Google Cloud (Firestore, Cloud Run, Cloud KMS, Cloud Scheduler) — to run AppEvidence's backend and store the account, testing-session and subscription records described above.
No other party receives data collected through the app. Emails you choose to send to AppEvidence support are handled as described in the next section.
Emails you send to support
If you email AppEvidence support at app.evidnc@gmail.com, we receive what you choose to send: your email address, the name shown in your email, the subject and message, any attachments you include, and standard email details such as the date. Please do not send passwords, sign-in or recovery codes, payment card or bank details, or screenshots and evidence that you do not need us to see.
Our support mailbox is a Gmail account, so your email is stored by Google as part of that mailbox.
To help us read and sort support emails and prepare replies, we use ChatGPT, an AI assistant provided by OpenAI, connected to our support mailbox. When we do, OpenAI processes your support email, including your email address and the content you sent, to provide that assistance. Some routine questions may receive an automatic reply that uses answers we have written and approved in advance; other enquiries require review before a reply is sent. OpenAI's handling of this information is governed by OpenAI's own policies, including its Privacy Policy and its Google app data controls, which describe how data from connected Google apps is used and the exceptions that apply.
Support emails are separate from the app. The app itself does not send your screenshots, recordings, evidence packages, or other captured content to OpenAI or to our support mailbox. Material like that reaches us only if you choose to attach it to an email.
We use support emails only to handle your support or account-deletion request. We do not use them for advertising and we do not sell them.
How long we keep support emails. Our practice is to delete support correspondence from the support mailbox 12 months after the last message in the conversation. Emails about account deletion follow the same 12-month practice. Our practice is to delete the ChatGPT history we used to process a support email after 30 days. Deleting something from Gmail or ChatGPT does not mean it is erased from Google's or OpenAI's systems at that moment; each provider's own retention and deletion policies, including their documented exceptions, apply.
Security
We apply several concrete safeguards to the data described above:
- Your Google account identity is stored behind a keyed HMAC index rather than as a plain, directly searchable value.
- Purchase tokens are stored only encrypted with Google Cloud Key Management Service, and are otherwise referred to by a keyed hash.
- Server requests are rate-limited to guard against abuse, and rate-limit tracking retains no raw identifying source information.
- Application logs automatically redact sensitive fields (such as tokens, credentials, and identifiers) before they are ever written.
- All traffic between the app and our backend is encrypted in transit (HTTPS/TLS).
- Background account-deletion processing authenticates itself using a Google-issued identity token bound to a single, specific caller — not broad network trust.
Account deletion
You can request deletion of your AppEvidence account and the data associated with it at any time, whether or not you still have the app installed. See the Account Deletion page for exactly what is deleted, what is briefly retained afterward and for how long, and how to request deletion if you can no longer sign in.
Changes to this policy
If AppEvidence's data practices change, this page will be updated to describe them.
Contact
Questions about this policy or AppEvidence's data practices: app.evidnc@gmail.com