Legal

Privacy policy

Draft — not yet reviewed by a lawyer.

The substance below is accurate about how the product works. It has not been through legal review and must be before this site is published or submitted to an app store.

Last updated 2 August 2026.

Who we are

FieldLog provides job-documentation software to trade businesses. When a business uses FieldLog, that business is the controller of the records it creates and we process those records on its behalf. This policy covers both what we collect directly and what we hold for our customers.

What is collected

When someone in the field submits a report, FieldLog records:

  • Photographs taken in the app, including a timestamp burned into the image itself
  • Location — GPS coordinates captured with each photo, where the device permits it, and a street address derived once per report
  • Three timestamps — the time the device reported, the time our server received it, and the difference between them. A device clock can be changed by its user, so the difference is recorded rather than assumed to be zero
  • The name of the person who created the report, and the job it belongs to
  • Notes and checklist answers typed by the person in the field
  • Account details — name, email address, and authentication data held by our identity provider

Location capture can be declined on the device. Reports still work without it; the coordinates are simply empty.

Location data, and who can see it

Coordinates are visible to the business that employs the person who took the photo. They are never shown on a report shared with a customer, and they are left out of the customer copy of a PDF by construction rather than by a setting. An internal copy that includes coordinates can be generated by the business, is labelled as internal, and downloads under a different filename.

Location is captured per photo. It is not continuous tracking: nothing is recorded between reports, and the app does not collect location in the background.

Share links are public URLs

A business can turn a report into a link and send it to a customer. That link opens without a login — the URL is the only credential. Anyone who has the link can view that one report, so it should be treated like a document attached to an email rather than like a password-protected page.

Links are long and random, expire, can be revoked at any time by the business, and carry instructions telling search engines not to index them. Sharing is opt-in for each individual report and is never applied in bulk.

How long it is kept

Records are kept for as long as the business’s account is open, because the value of the archive is that it reaches back. We do not commit to a fixed retention period in either direction — a promise to keep photographs for a set number of years is a cost commitment payable on accounts that may close long before then, and we would rather not make a promise of that shape.

When an account is closed, the company record is marked deleted immediately and stops being reachable. The stored photograph files are removed by a subsequent sweep rather than in the same instant, so there is a short window during which files exist but are unreachable. Export your data before closing the account — export is free, complete, and always available while the account is open.

Who processes data for us

We use these sub-processors. Each holds only what it needs to do its job.

ProviderWhat it handles
ClerkAccounts and sign-in
SupabaseDatabase — reports, notes, answers, coordinates
Cloudflare R2Photograph storage. The bucket is private; files are served through short-lived signed links
VercelHosting for the web dashboard and this site

What we do not do

  • We do not sell data, and we do not share it for advertising
  • We do not run advertising or analytics trackers in the app
  • This marketing site sets no cookies and loads no third-party scripts
  • Our own product telemetry records counts and timings only — never photo contents, note text, or customer names

Your rights

If you are a field worker or a customer of one of our customers, the business that holds your records is the first place to ask — they control the data. Write to us at hello@fieldlog.us and we will help either of you get to the right answer, including access, correction and deletion requests.

One thing to know: submitted reports cannot be edited by anyone, including administrators and us. A correction is recorded as a linked follow-up report. This is what makes the archive worth anything as evidence, and it means “correct this record” produces an addition rather than a rewrite.