Android-specific privacy policy. This policy applies only to FreightAudit package com.ryantinklepaugh.freightaudit. It does not change the iOS app’s privacy policy or receipt history.
Scope and controller
Uncommon Weather LLC controls the processing described here. Contact team@uncommonweather.com. FreightAudit is a document-first freight-payment reconciliation tool that links rate-confirmation terms, settlement lines, rule arithmetic, findings, evidence, and dispute status in one audit case.
Information handled
- camera or imported document images processed on the device
- ML Kit OCR text, source excerpts and bounding boxes
- audit cases, calculations, findings, evidence checklists, dispute lifecycle, and notes
- locally generated evidence reports and user-directed exports
- purchase entitlement and legal-choice evidence
Camera access is optional and used only when you choose to capture a document. Document images, OCR output, excerpts, audit cases, findings, and notes remain app-private and local and are not uploaded to Uncommon Weather, Supabase, or an artificial-intelligence service. Public EIA data requests contain no case or document content.
Product storage and providers
FreightAudit keeps document images, ML Kit OCR output, source excerpts and boxes, audit cases, calculations, evidence, lifecycle status, and notes in app-private local storage. Reports are generated in local cache and leave only through a user-directed Android share action.
Google ML Kit performs OCR on the device. Public EIA requests contain no case or document data. Google Play and RevenueCat process purchase and entitlement state. Supabase receives only privacy-minimal legal-choice evidence; FreightAudit has no product-data backend and does not send product notifications.
Legal-choice evidence and abuse prevention
To preserve your choice and prevent forged receipts, the app may send privacy-minimal evidence to Supabase-hosted services: package ID, document versions and hashes, acceptance or withdrawal state, coarse adult age band and role, timestamps, a random installation identifier, request identifiers, an Android Keystore public-key proof, and—when configured—Google Play Integrity verdict material. We also process connection metadata such as IP address, user agent, response status, and rate-limit state for security, reliability, and abuse prevention. We do not send your ordinary product records with legal-choice evidence.
Purchases
Google Play supplies transaction and purchase-token data, and RevenueCat supplies entitlement and offering state. We do not receive your full payment-card number.
Retention and deletion
Local records remain until the user deletes a case or all app data or removes the app. Temporary report files follow app-cache and deletion behavior. A report deliberately shared remains with the selected destination until removed there. Legal-choice evidence follows the separate evidentiary retention described below.
Server-side legal evidence is retained to prove and honor the choice, withdrawal, integrity, and retry history it records. Security logs are retained only as reasonably needed for fraud prevention, troubleshooting, and legal compliance. Contact us to request access or deletion; we may retain evidence where necessary to establish, exercise, or defend legal claims.
Choices and rights
You can deny optional Android permissions, decline or withdraw legal consent, manage purchases where applicable, and request privacy help. Depending on where you live, you may have rights to access, correct, delete, restrict, object, or appeal. We do not discriminate for exercising a privacy right.
Age boundary
The app is not directed to anyone under 18. We do not knowingly collect a precise birth date through the legal-choice flow.
Security and transfers
We use reasonable technical and organizational safeguards, but no device, network, or storage system is guaranteed secure. Providers may process information in the United States or other countries subject to applicable safeguards.