SM Site Walk

Privacy Policy

Effective date: August 1, 2026

The short version: SM Site Walk needs an account, and it sends your work off the phone. You record voice notes and shoot photos with no signal at all — nothing leaves the device while you walk. When you tap Finish, the recordings and photos are uploaded, the audio is transcribed by Groq, the transcript is organized into a report by Anthropic, and the finished report is emailed to the address you typed. Transcripts and finished reports are kept indefinitely so a report can be re-issued after a revisit; the raw audio and the full-resolution photos are deleted once the report has been delivered, and kept until you delete your account if no report ever goes out. The app has no ads, no analytics, and no tracking of any kind.

Who we are

SM Site Walk is made by SmartMetal. Questions about anything on this page go to bevans18@hotmail.com.

What we collect

All of the following is linked to your account:

We do not collect your location, your contacts, your calendar, your device advertising identifier, or anything from your iOS photo library.

What stays on the phone, and what leaves it

Capture is entirely offline. Recordings, photos and the walk's own notes-and-photos manifest are written to a private folder inside the app, and nothing is transmitted while you are walking the building — the app does not need a network connection until you tap Finish.

Two things about that on-device folder are worth saying plainly:

When you tap Finish, the audio files, both photo sizes and the manifest are uploaded over an encrypted connection (HTTPS) and the report is built. The upload, the transcription, the report and the email all happen at that point, and not before.

The row labels are made on the phone

Each row in the walk log is labelled with the first few words you said, so you can tell at minute 70 whether you already did the second-floor mechanical room. That label is produced by Apple's speech recognizer running on the device, with on-device recognition required.

The label is what stays on the phone. It is not sent to Apple, is not sent to us, is not uploaded with the walk, and never appears in the report. It exists only to label a row on your screen.

The recording it was made from is not. There is no second, private copy of your voice: the recognizer reads the same audio file the walk will upload, and at Finish that file goes to our storage and on to Groq like every other note. The label staying on the phone does not mean the recording does.

Who else receives your data, and exactly what they get

We use the following companies to run the service. Each one is used only for the step described. Their handling of the data on their side is governed by their own privacy terms, not by this page.

Vercel — running the service

Our server code runs on Vercel, and that is where your report is built. Every request the app makes to us lands there: the job name, every header field you typed, your typed notes, and the address you want the report sent to. So does everything the build touches — your recordings are read back into it to be sent to Groq, your photos are read back into it to be placed on the page, and the transcripts and the finished PDF and Word files are assembled there before they are stored.

The one thing that does not go through Vercel is the upload itself: when you tap Finish, the recordings and photos go from the phone straight to Supabase. Vercel is where the code runs, not where anything is filed. What it does keep is our server log, which records which address each report was delivered to.

Supabase — accounts, storage and database

Holds your account (email address and password credential), and stores everything you upload: the audio files, both sizes of every photo, the transcripts, the job and header details, the finished PDF and Word documents, your credit balance, and your purchase records.

Groq — speech to text

Each audio recording is sent to Groq's transcription API, which returns the text of what you said. Groq receives the audio itself. It does not receive your email address, your account, your photos, or the job details.

Anthropic — organizing the transcript into a report

The transcribed text of your notes, the job name, and the timing of each note and photo are sent to Anthropic's Claude API, which returns the organized body of the report. No photograph is ever sent to Anthropic. Nothing in this pipeline looks at your images — the model is told only that a photo was taken at a given moment. Your email address, your password, your header fields and your purchase history are not sent either.

Resend — sending the report

Resend delivers the finished email. It receives the recipient address you typed, the subject and body of the message, and — when the documents are small enough to attach — the PDF and Word report files themselves, which contain the report text, the verbatim transcript of your notes, the header fields you typed, and the 1200 px photos. Every one of these emails also carries signed download links for both documents, because corporate mail gateways strip attachments routinely. Those links stop working 30 days after they are issued. When the files are too large to attach at all, the links are the only copy in the email.

Apple — the purchase

Credits are bought through Apple's In-App Purchase. Apple handles the payment; we never see your card, your billing address or your Apple Account. So that a purchase can be attached to the right account, we pass Apple an opaque account identifier (the random ID of your SM Site Walk account), which Apple returns to us inside the signed receipt.

How long we keep things

A building can be walked more than once, and a second visit re-issues the report with the earlier visit included. That is the reason for the split below.

An email that has already been delivered is out of our hands — it is in the recipient's mailbox and we cannot recall it.

Deleting your account

In the app: Settings → Delete account → Yes, delete everything.

This permanently deletes, from our servers: every file stored for you — recordings that have not yet been purged, all photos, and every rendered report — followed by your account itself, which removes your jobs, your walks, your transcripts, your typed notes, your report history, your credit balance and your purchase records. The file deletion runs first and is verified; if it cannot complete, the account is not deleted and you are told to try again, rather than being left with files nothing can find.

Two things it does not do. It does not remove walks still stored on your phone — delete those jobs in the app, or delete the app. And it does not recall reports that have already been emailed.

No tracking, no ads, no analytics

The app contains no advertising, no analytics SDK, and no third-party tracking software. We do not use the advertising identifier, we do not track you across other companies' apps or websites, and we do not sell or rent your data or share it for advertising. The only companies that receive anything are the six named above, each for the step described.

Permissions the app asks for

Children's privacy

SM Site Walk is a tool for construction professionals. It is not directed at children, and we do not knowingly collect personal information from anyone under 13. If you believe a child has created an account, contact us and we will delete it.

Your choices

You can delete an individual note, photo or job in the app before you tap Finish, and you can delete your entire account at any time from Settings. For any other request about your data — a copy of it, a correction, a deletion — email bevans18@hotmail.com.

Changes to this policy

If what the app does with your data changes, this page is updated to match, with a new effective date at the top. The version you are reading is always the current one.

Contact

Anything on this page you want explained, challenged, or acted on — write to bevans18@hotmail.com.