Privacy policy
Last updated: 6 October 2026
In brief
- FM Auditor is built to work on your phone first. You can use it without an account. Signed out, your reports stay on the phone and nothing leaves it unless you share a file yourself.
- If you sign in, your reports, photos and profile sync to our server in Ireland, run for us by Supabase, so they are backed up and available on your other devices.
- Auditor AI is an optional paid feature. After you tap Start using Auditor AI, the text of your findings goes through our server to TypeSafe in the United States for checking. Nothing is sent before that. Report check runs on your phone and sends nothing anywhere.
- The route you record on site stays on your phone. But the PDF and Excel files you create include a Route map page and map links by default, and those files carry the route with them when you share them.
- When you share a report, you choose where it goes. Copy link makes a web link that works for 7, 30 or 90 days. Anyone with the link can download that one file until it expires, and we cannot yet switch a link off early.
- We do not run analytics or crash reporting, show adverts, track you across other apps or sell your data. Dictation is turned into text on your phone.
- You can ask us to delete your account and everything in it by emailing privacy@fmauditor.app. In-app deletion is coming.
- You have rights under UK data protection law and the UAE data protection law, including access, correction and deletion. You can complain to the ICO in the UK or to the UAE Data Office.
Who we are and how to contact us
FM Auditor is made by [Placeholder: developer's legal name, trading name and company number if any], of [Placeholder: postal address]. In this policy, "we" and "us" means that developer, and "you" means the person using FM Auditor.
We are the controller of the personal data described here. That means we decide how and why it is used.
- Privacy questions and requests: privacy@fmauditor.app [Placeholder: confirm this mailbox is live and monitored]
- Everything else: support@fmauditor.app [Placeholder: confirm this mailbox is live and monitored]
[Placeholder: if we are not established in the UK, name a UK representative under Article 27 of the UK GDPR and give their contact details, or record why one is not needed.]
[Placeholder: ICO registration number, or a note that we are exempt from the data protection fee.]
If your employer gave you FM Auditor to use at work, your employer may also be a controller of the audit records you produce. Ask them for their own privacy notice. This policy covers what we do.
How FM Auditor works
The short version:
- Local first. Everything you create is stored on your phone in the app's own database. You can create reports, take photos, record the route, run Report check and export PDF, Excel and zip files without ever signing in.
- Optional account. If you sign in, the app syncs your reports, photos, profile and settings to our server. Syncing is what lets you back up your work and use it on another device. Sign out, and syncing stops.
- What leaves the phone, and when. Data leaves your phone only in these cases: you sign in and sync; you share a file through the share sheet; you tap Copy link; you use Auditor AI after agreeing to it; the app asks Apple for map tiles or a place name; someone opens a map link in a report you shared; or you email us.
Everything below explains each of those in more detail.
The data we collect and why
The table lists each kind of data, where it comes from, why we use it, the legal reason we rely on, and how long we keep it. The sections after the table add detail where it matters.
| What | Where it comes from | Why we use it | Lawful basis | How long we keep it |
|---|---|---|---|---|
| Account and sign-in: your email address, which sign-in method you used and that provider's account ID for you, a one-time code sent by email, and a session token on your phone | You, or Apple, Google or Microsoft when you sign in with them | To create your account, sign you in, keep it secure and sync your data | Contract: providing the account you asked for. Legitimate interests: keeping accounts secure | Until your account is deleted. The session token stays on your phone until you sign out |
| Name and profile photo from Apple or Google | Apple or Google, when you sign in with them | To fill in your first and last name if they are empty, and your profile photo if you have none, so they can print on your reports | Contract | As part of your profile, until you change it or delete your account |
| Profile and company details: first name, last name, job role, company name, company email, company phone, logo, profile photo, report types and audiences | You | To print on your reports, show in the app and sync between your devices | Contract | Until you delete your account. Replaced logo and profile photo files are not purged today [Placeholder: retention period for replaced logo and profile photo files] |
| Report content: sites (name, client, address), areas and their boundaries, reports (title, date, notes, sign-off names, signature images), findings (remarks, location text, status, priority, assignee name, due date, closeout remarks, grade, verifier name, follow-up check results), checklists, readings and answers, photos with captions, markup and the time taken, text snippets and your own output layouts | You, and the places and people you audit | To store your reports, sync them between your devices and build your PDF, Excel and zip files | Contract: syncing and storing the reports you ask us to keep. Legitimate interests: holding the names and images of other people that you put in your reports, on your instructions | While the report is in your account. Trashed reports are purged 30 days after you trash them. Everything goes when your account is deleted |
| Location: the pin on each finding and photo (latitude, longitude, accuracy and where the fix came from), area boundaries you draw, and a Location text that Apple's geocoder may fill in with an address | Your phone's location services, the GPS data in library photos you add, your own drawing, and Apple's reverse geocoding | To pin findings where they were found, draw maps and map links in reports, and give new findings a place name | Contract: these are part of the reports you sync. You control the location permission at all times | With the finding or photo, until it is purged or your account is deleted |
| The route: time, position, accuracy and speed, about every 5 metres or 5 seconds while a report is open, or while the phone is locked if you allow it | Your phone's location services | To draw the Route map page, with start and end times and distance, in your PDF and Excel outputs | Not collected by us. It never leaves your phone unless you share a file that prints it | On your phone until you tap Delete route or the report is permanently deleted |
| Auditor AI text: remarks (up to 1,200 characters), location text and area name (up to 300, for place questions), closeout remarks (up to 1,200), the checklist item (up to 300), the remarks of up to three earlier findings (to spot duplicates), plus which questions to ask, the grading scale and the deadline | The text you type or dictate into a finding | To run Auditor AI checks and show you suggestions | Consent: you tap Start using Auditor AI, and you can switch it off at any time | Our server does not store the text. Answers are cached on your phone only. TypeSafe keeps request records under its own terms [Placeholder: confirm TypeSafe's retention period, or whether zero data retention applies to our account] |
| Auditor AI usage and plan: how many findings you checked each day (UTC), how much text was sent (counted in tokens), and which plan you are on | Generated by our server | To apply the daily cap of 3,000 findings per account, and to know who has Pro | Contract: operating the plan you are on | Not purged today [Placeholder: retention period for usage and plan rows, 12 months after the end of the month suggested for usage] |
| Shared files: a PDF or Excel file you create with Copy link | You, when you tap Copy link | To give you a web link you can send to anyone | Contract: you asked for the link | The link works for 7, 30 or 90 days, your choice. The file itself is not purged today [Placeholder: retention period for shared files, deletion 30 days after the link expires suggested] |
| Support messages: your email address, what you write and anything you attach | You, when you email us | To answer you and fix problems | Legitimate interests: helping you and improving the app | [Placeholder: retention period for support email, 24 months after the last message suggested] |
| Auditor AI waitlist: your account ID and when you joined | You, when you tap to join | To tell you when Auditor AI is ready | Consent: you choose to join and can leave at any time | Until you leave the waitlist or delete your account |
| Technical records: the IP address and request details our hosting provider logs for each request, and our own logs of event names, counts, timings and statuses (never your report text) | Your phone, when it talks to our server | To keep the service running, spot abuse and fix faults | Legitimate interests: security and reliability | [Placeholder: Supabase platform log retention period] |
Two things the table does not show, because they never leave your phone: a copy of your user ID and a random device ID that the app uses to tell its own records apart. Neither syncs.
Account and sign-in
Signing in is optional. You can sign in with a one-time code sent to your email, with Apple, with Google or with Microsoft.
- Email code. We send a six-digit code to your address. It expires after ten minutes. [Placeholder: name the email provider that sends sign-in codes and where it is based.]
- Apple. Apple gives us your email address and, the first time, your name. If you choose Hide My Email, Apple gives us a relay address instead of your real one, and that is fine with us.
- Google. Google gives us your email address, your name and a link to your profile picture. We use the name only if your first and last name are empty. We download the picture, resize it to 512 pixels and use it as your profile photo only if you have none. You can change or remove it afterwards.
- Microsoft. Microsoft gives us your email address. We do not ask for your picture.
Each provider also gives us a stable account ID so we can recognise you next time. We do not see your password for any of these services.
Report content
Your reports are yours. We store them so that you can sync and share them. In practice they contain personal data about other people as well as you:
- Photos may show people. Site photos can include staff, contractors, visitors, ID badges and vehicle number plates. The app does not detect or blur faces. You decide what to photograph and you are responsible for having the right to do so where you work.
- Signatures. When a report is signed off, the app stores the auditor's name, the site representative's name and both signatures as images, with the time of signing.
- Names you type. Assignees, verifiers, site representatives and anyone you mention in remarks are stored exactly as you type them.
- Checklists and readings. Checklist answers and any readings you enter are stored with the report.
If you add a photo from your library, the app reads the GPS position from the file, keeps it as the finding's pin, and then re-saves the photo without any of its original metadata. Photos taken with the camera get their position from the phone's location service, not from the file.
Location
FM Auditor asks for location permission in two ways. "While using" is asked when you open the Capture or Pin screens. "Always" is asked only if you turn on Keep recording when the phone is locked in your Profile. You can change either in iOS Settings at any time.
- Pins at the shutter. While the Capture screen is open, the app watches your position at high accuracy. When you take a photo it uses a fix no more than 10 seconds old, or the last fix within 60 seconds, or none. Pins are stored and synced at full precision.
- The route. If Record route is on (it is on by default) and you have granted permission, the app records your position about every 5 metres or 5 seconds while a screen for that report is open, or while the phone is locked if you allowed that. The route is stored only on your phone. It is never synced and it is never in the zip export.
- Area boundaries. Areas you draw on the map are stored with your reports and sync.
- Place names from Apple. When a new pinned finding has no area and no Location text, the app asks Apple's geocoder for a place name and writes the answer, which can be a street address such as a road and district, into the Location text. That text then syncs like the rest of the finding, and it is one of the fields sent to Auditor AI if you use it. You can edit or clear it.
- Maps in the app. Maps are drawn with Apple Maps. Apple receives requests for the map areas you look at, under Apple's own privacy policy. Open in Maps opens Apple Maps or a Google Maps link that contains the coordinates of the pin.
- Maps in your outputs. The standard layout prints a Route map page into the PDF and Excel: a picture of the pins, area outlines and route lines, the start and end times, the distance, and "Prepared by" with your name. A Map column is also on by default, giving each pinned finding a Google Maps link with coordinates to five decimal places. Google receives those coordinates only if someone opens a link. Both can be switched off in the layout. If they are on, any file you share or link carries the route and the pins with it.
Auditor AI
Auditor AI checks the text of your findings and suggests improvements. It is a paid feature. Today, Pro is switched on by hand for beta testers, and there is nothing to buy in the app yet.
Three things must be true before anything is sent: your account must be on the Pro plan; the report's Auditor AI switch must be on (it is on by default); and you must have tapped Start using Auditor AI on this phone. Turning off the Profile switch withdraws that consent, and checks stop.
Once you start, checks run automatically as you write. For each finding, the app sends to our server the remarks, the location text and area name when a place question is asked, the closeout remarks for closeout questions, the checklist item for checklist matching, and the remarks of up to three earlier findings so duplicates can be spotted, together with the question keys, the grading scale and the deadline. The app does not send photos, pins, the route, the site or client name, the report title, the assignee or your user ID.
Our server passes the remarks, any matching glossary terms and the questions, with the location, area, closeout, checklist and earlier remarks folded into their instructions, to TypeSafe in the United States. It does not send your user ID or email address. The answers come back to your phone and are cached there only.
Three points to be clear about:
- Location text may contain an address. Because Apple's geocoder can fill in the Location text, the text sent for a place question may include a street address. Names you type into any of these fields are sent too.
- No training. TypeSafe has told us it does not use your text to train its models. It may keep request records for as long as it needs them, and may keep technical logs and statistics derived from your text. [Placeholder: confirm TypeSafe's retention terms and whether zero data retention is available to us.]
- No remark text in our logs. Our server logs event names, counts, timings, statuses and field names. It never logs your text, and it does not log your user ID.
Auditor AI gives suggestions. It never edits your text, and you remain responsible for every finding. See the Terms of use.
Report check
Report check is the set of free checks that run on your phone. It does not send anything anywhere.
Sharing
You choose how a report leaves the phone:
- Share sheet. The app hands the PDF, Excel or zip file to the iOS share sheet. From there it goes wherever you send it: Mail, Messages, AirDrop, a cloud drive or another app. We do not see where it goes. You can add a short message with the report title, site, date and finding counts.
- Copy link. This needs an account. The app uploads the file to your own private folder on our server and gives you a web link that works for 7, 30 or 90 days (30 by default). Anyone who has the link can download that one file until it expires. Today, links cannot be revoked early in the app, and the uploaded files are not deleted after the link expires. If you need a link switched off, email us and we will delete the file.
- Zip export. A zip of one report contains the original photos, marked-up copies, signatures, the PDF and Excel from that visit, a report.json file (report, sections, areas with boundaries, findings with pins, photo records with position, time, caption and markup, checklist runs and answers) and a findings.csv. An export of all reports has one folder per report without the PDF and Excel. The zip never includes the route, sync flags, photo quality scores or your settings. It is written to the phone and shared through the share sheet. It is never uploaded.
Once you have sent a file to someone, that copy is theirs. Deleting your account does not recall it.
Support
If you email us, we keep your message and address so that we can answer you. If you send screenshots or files, we see whatever is in them.
Auditor AI waitlist
You can join a waitlist for Auditor AI inside the app. We store your account ID and the time you joined, and you can leave at any time. The app says we will let you know when Auditor AI is ready. [Placeholder: decide how waitlist members will be contacted (email to the sign-in address, or an in-app notice), confirm the message will be a single notice with no further marketing, and record consent at the moment of joining.]
What we do not collect
- No analytics or crash reporting. The app sends no usage statistics and no crash logs today. If we add either, we will update this policy and the App Store privacy label first, and we will not include your report text in them.
- No advertising and no tracking. There are no adverts, no advertising identifiers and no third-party tracking. We do not combine data from FM Auditor with data from other companies.
- Dictation stays on the phone. When you dictate a finding, Apple's on-device speech recognition turns it into text. The audio is not sent to us or to Apple's servers by the app.
- No contacts, calendar, health or browsing data. The app does not ask for them.
- No push notification tokens. Reminders at 08:00 on a report's next due date are scheduled on the phone itself.
- No sale of data. We do not sell or rent personal data to anyone.
Who we share data with
We use a small number of companies to run FM Auditor. They act on our instructions, and they may not use your data for their own purposes.
| Who | What they do for us | Where |
|---|---|---|
| Supabase | Hosts our database, file storage, sign-in service and server code. Everything you sync lives here | Ireland (AWS region eu-west-1) [Placeholder: confirm the project region in the Supabase dashboard and accept the Supabase data processing addendum] |
| TypeSafe | Processes the text of your findings for Auditor AI, only after you agree | United States |
| Apple | Sign in with Apple; map tiles and map snapshots; place names from coordinates; on-device speech recognition; Apple Maps links; local reminders | Apple services, worldwide, under Apple's own privacy policy |
| Sign-in with Google; your profile picture when you sign in that way; Google Maps links in reports (Google receives coordinates only when a link is opened) | Google services, worldwide, under Google's own privacy policy | |
| Microsoft | Sign-in with Microsoft (Entra ID) | Microsoft services, worldwide, under Microsoft's own privacy policy |
| [Placeholder: email provider for sign-in codes] | Sends the one-time sign-in code to your email address | [Placeholder: location] |
Apple, Google and Microsoft act as independent controllers for the parts of sign-in and maps that happen on their side. Their privacy policies apply to that.
We also share data when you tell us to. If you share a file or send a link, the people you send it to get the report, including any names, photos, pins and the Route map page in it. If you email a report to a client, your client has it.
We will disclose personal data if the law requires it, for example to comply with a court order, or if it is necessary to protect someone's safety or to defend a legal claim. If our business is sold or merged, your data may transfer to the new owner, and this policy will continue to apply to it.
International transfers
Our users are mainly in the United Kingdom and the United Arab Emirates. Our server is in Ireland, and Auditor AI uses a provider in the United States.
If you are in the UK. Your data is covered by the UK GDPR. Ireland is in the European Economic Area, which the UK's adequacy regulations treat as providing adequate protection, so syncing to our server needs no extra safeguard. Auditor AI sends text to the United States. We rely on [Placeholder: choose the mechanism and confirm it is in place: the UK Addendum to the EU Standard Contractual Clauses signed with TypeSafe, together with a transfer risk assessment; or the UK Extension to the EU-US Data Privacy Framework if TypeSafe is listed as certified for it]. You can ask us for a copy of the safeguards we use.
If you are in the UAE. Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data applies to personal data processed in the UAE outside the DIFC and ADGM free zones. Under it, personal data may be transferred abroad to a country that the UAE Data Office recognises as having adequate protection, or otherwise where safeguards such as a contract binding the recipient to equivalent protection are in place, where you give your express consent to the transfer, or where the transfer is necessary to perform a contract with you. Syncing to Ireland is necessary to provide the account you asked for and is covered by our contract with Supabase. Auditor AI text goes to the United States only after your express consent in the app, and we [Placeholder: confirm the contractual safeguards with TypeSafe and obtain UAE counsel's confirmation of the transfer basis once the Executive Regulations and any adequacy list are published].
Apple, Google and Microsoft handle their own international transfers under their own terms.
How long we keep data
- On your phone. Your data stays until you delete it. Trashed items are kept for 30 days and then purged when the app starts. Delete now is available for a trashed report that has never synced.
- Trash on the server. When you trash a synced report, the server marks it as trashed too. A daily job permanently deletes anything trashed more than 30 days ago, together with its photo and signature files.
- Account data. Your profile and settings, your plan, your Auditor AI usage counts and your waitlist entry are kept until you delete your account or, for the waitlist, until you leave it. Today these are not purged on any other schedule. [Placeholder: set retention periods for the settings row of an inactive account, usage rows and plan rows.]
- Shared files. Files you create with Copy link are kept after the link expires. We are adding a job to delete them. [Placeholder: set and publish the retention period for shared files.]
- Replaced files. If you replace your logo or profile photo, the old file is not deleted today. A profile photo you remove is deleted. [Placeholder: set the retention period for replaced logo and profile photo files.]
- Support email. [Placeholder: set the retention period for support email.]
- Server logs. [Placeholder: state the Supabase platform log retention period.]
We are committed to publishing fixed periods for each of the items marked above and to purging data on that schedule.
Security
On the server:
- Every synced table uses row level security. You can read and write only your own rows, and the sync service forces your user ID onto everything you send.
- Files are kept in a private storage bucket. You can reach only your own folder. Access during sync uses signed links that expire after five minutes.
- Shared files are reachable only through a signed link that expires after the period you chose.
- Your plan can be read only by you and written only by our server. Your usage counts can be read only by you.
- Only a publishable key ships in the app. The keys for TypeSafe and for full database access exist only on the server.
- Browser sign-in uses PKCE. Sign in with Apple uses a hashed nonce. All traffic uses TLS.
On your phone:
- The app's database is a standard SQLite file. It is not separately encrypted beyond the protection iOS applies to the app's files. Photos and generated files are stored in the app's Documents folder with the iOS default protection.
- Your session token is stored in the app's own storage, not in the iOS Keychain.
- A passcode or Face ID on the phone, and keeping iOS up to date, protect this data. If you lose the phone, use Find My to erase it.
No system is perfectly secure. If a breach puts your rights at risk, we will tell the ICO within 72 hours where the UK GDPR requires it, tell the UAE Data Office as the PDPL requires, and tell you without undue delay where the risk to you is high.
Your rights
Under the UK GDPR, you have the right to:
- be told how your data is used (this policy);
- get a copy of your personal data;
- have inaccurate data corrected;
- have your data deleted in many cases;
- restrict how we use it while a dispute is sorted out;
- receive the data you gave us in a portable form (the zip export does this for your reports);
- object to processing based on legitimate interests, and to any direct marketing;
- withdraw consent at any time, without affecting what was done before (for Auditor AI, switch it off in your Profile; for the waitlist, tap to leave);
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects. Auditor AI makes no such decisions. It only suggests, and you decide.
Under the UAE PDPL, you have similar rights: to be told what we process and why and who we share it with, to access and receive your data, to correct it, to have it erased, to restrict or stop processing, to object to automated decisions, and to complain to the UAE Data Office.
To use any of these rights, email privacy@fmauditor.app from the address on your account, or tell us by any other means. You do not have to use a form. We will answer within one month. If your request is complex, we may take up to two further months and will tell you why. We do not charge a fee unless a request is clearly unfounded or excessive. We may ask you to confirm your identity first, for example by replying from your sign-in address.
If you are unhappy with how we handle your data, please tell us first and we will try to put it right. You also have the right to complain to a regulator:
- United Kingdom: the Information Commissioner's Office, at ico.org.uk/make-a-complaint or on 0303 123 1113.
- United Arab Emirates: the UAE Data Office. [Placeholder: add the Data Office's complaint route once it is operational; at the time of writing the Telecommunications and Digital Government Regulatory Authority acts as the interim point of contact.]
Deleting your account and data
Today. Email privacy@fmauditor.app from your sign-in address and ask us to delete your account. We will confirm it is you, delete your account and everything linked to it, and confirm when it is done. [Placeholder: commit to a completion time, 30 days suggested.]
Soon. We are adding Delete account to the app, so that you can start deletion yourself without emailing us.
What deletion removes. Your sign-in record, profile and settings, plan, usage counts and waitlist entry; all your sites, areas, reports, findings, checklists, snippets and layouts; your photos, signatures, logo and profile photo in storage; and any files you created with Copy link, which stops those links working.
What deletion does not remove.
- The data on your phone. Delete the app, or delete reports inside it, to clear that.
- Copies of reports you have already shared or sent. Those belong to the people you sent them to.
- Records we must keep by law, if any, and server logs until they expire on their normal schedule.
Sign out is not deletion. Signing out ends the session on that phone. Your data stays on the phone and on the server, and your plan shows as free until you sign in again.
Deleting the route. Open the report and tap Delete route. The route is also removed when the report is permanently deleted.
Deleting reports. Trashed reports are kept for 30 days on the phone and on the server, then purged. Delete now is available for trashed reports that have never synced.
Children
FM Auditor is a professional tool for facilities management auditors. It is not for anyone under 18, and we do not knowingly collect data from children. There is no age gate because the app is not aimed at or marketed to children. If you believe a child has created an account, email us and we will delete it.
Our website
Our website at fmauditor.app sets no cookies and loads no analytics. It is static pages. [Placeholder: if the "Get notified at launch" form collects email addresses, name the provider that stores them, state that the lawful basis is consent, say how to unsubscribe, and set a retention period.]
[Placeholder: when the Featurebase feedback widget or portal is switched on, add: the feedback widget is provided by Featurebase, a third party with its own privacy policy and its own cookies; what you post there is governed by Featurebase's terms; and a link to its policy.]
Changes to this policy
When we change how FM Auditor handles your data, we will update this policy, change the date at the top and summarise what changed. If a change affects what we send to a third party or asks for new consent, we will tell you in the app before it takes effect. The current version is always at fmauditor.app/privacy and is linked from the App Store listing and from inside the app.
Contact
[Placeholder: developer's legal name] [Placeholder: postal address] privacy@fmauditor.app support@fmauditor.app