Privacy Policy
Who we are
SM Site Walk is made by SmartMetal. Questions about anything on this page go to bevans18@hotmail.com.
What we collect
All of the following is linked to your account:
- Your email address and password. Used to sign you in and to tie your walks and your credits to you. The password is handled by our authentication provider; we never see it.
- Your voice recordings. Every note you record during a walk.
- Your photos. Every frame you shoot during a walk, in two sizes — a 2400 px original and a 1200 px copy that goes into the report.
- What you type. The job name, the walk type, the header fields at Finish (address, square footage, building type, general contractor, drawing set and revision, who walked it, and the weather), any typed notes, and the email address you want the report sent to — which may be someone other than you.
- Timing. When each note started, how long it ran, when each photo was taken, and whether the shutter fired while a note was recording. That is what lets the report put the right photo with the right paragraph.
- Purchase records. When you buy credits, we store Apple's transaction ID, the product ID, how many credits it granted, whether it was a production or sandbox purchase, and whether it was later refunded.
We do not collect your location, your contacts, your calendar, your device advertising identifier, or anything from your iOS photo library.
What stays on the phone, and what leaves it
Capture is entirely offline. Recordings, photos and the walk's own notes-and-photos manifest are written to a private folder inside the app, and nothing is transmitted while you are walking the building — the app does not need a network connection until you tap Finish.
Two things about that on-device folder are worth saying plainly:
- Because it is the app's Documents folder, it is included in your iPhone's iCloud or computer backup if you have backups switched on. That is Apple's backup, not ours; we cannot see it.
- Photos taken in SM Site Walk never enter your iOS photo library. The app opens the camera directly, saves the frame into its own folder, and has no "choose from library" path at all.
When you tap Finish, the audio files, both photo sizes and the manifest are uploaded over an encrypted connection (HTTPS) and the report is built. The upload, the transcription, the report and the email all happen at that point, and not before.
The row labels are made on the phone
Each row in the walk log is labelled with the first few words you said, so you can tell at minute 70 whether you already did the second-floor mechanical room. That label is produced by Apple's speech recognizer running on the device, with on-device recognition required.
The label is what stays on the phone. It is not sent to Apple, is not sent to us, is not uploaded with the walk, and never appears in the report. It exists only to label a row on your screen.
The recording it was made from is not. There is no second, private copy of your voice: the recognizer reads the same audio file the walk will upload, and at Finish that file goes to our storage and on to Groq like every other note. The label staying on the phone does not mean the recording does.
Who else receives your data, and exactly what they get
We use the following companies to run the service. Each one is used only for the step described. Their handling of the data on their side is governed by their own privacy terms, not by this page.
Vercel — running the service
Our server code runs on Vercel, and that is where your report is built. Every request the app makes to us lands there: the job name, every header field you typed, your typed notes, and the address you want the report sent to. So does everything the build touches — your recordings are read back into it to be sent to Groq, your photos are read back into it to be placed on the page, and the transcripts and the finished PDF and Word files are assembled there before they are stored.
The one thing that does not go through Vercel is the upload itself: when you tap Finish, the recordings and photos go from the phone straight to Supabase. Vercel is where the code runs, not where anything is filed. What it does keep is our server log, which records which address each report was delivered to.
Supabase — accounts, storage and database
Holds your account (email address and password credential), and stores everything you upload: the audio files, both sizes of every photo, the transcripts, the job and header details, the finished PDF and Word documents, your credit balance, and your purchase records.
Groq — speech to text
Each audio recording is sent to Groq's transcription API, which returns the text of what you said. Groq receives the audio itself. It does not receive your email address, your account, your photos, or the job details.
Anthropic — organizing the transcript into a report
The transcribed text of your notes, the job name, and the timing of each note and photo are sent to Anthropic's Claude API, which returns the organized body of the report. No photograph is ever sent to Anthropic. Nothing in this pipeline looks at your images — the model is told only that a photo was taken at a given moment. Your email address, your password, your header fields and your purchase history are not sent either.
Resend — sending the report
Resend delivers the finished email. It receives the recipient address you typed, the subject and body of the message, and — when the documents are small enough to attach — the PDF and Word report files themselves, which contain the report text, the verbatim transcript of your notes, the header fields you typed, and the 1200 px photos. Every one of these emails also carries signed download links for both documents, because corporate mail gateways strip attachments routinely. Those links stop working 30 days after they are issued. When the files are too large to attach at all, the links are the only copy in the email.
Apple — the purchase
Credits are bought through Apple's In-App Purchase. Apple handles the payment; we never see your card, your billing address or your Apple Account. So that a purchase can be attached to the right account, we pass Apple an opaque account identifier (the random ID of your SM Site Walk account), which Apple returns to us inside the signed receipt.
How long we keep things
A building can be walked more than once, and a second visit re-issues the report with the earlier visit included. That is the reason for the split below.
- Kept indefinitely, until you delete your account: the transcripts of your notes, the 1200 px photos, the report as generated, and every rendered PDF and Word file — including superseded revisions, because the earlier version may already have been forwarded to someone. Also your job and header details, your credit balance and your purchase records.
- Deleted once the report has been delivered: the raw audio recordings and the 2400 px full-resolution photos. They are removed from our storage as soon as the report goes out, and are not used for anything afterwards.
- If a report is never delivered, that deletion never runs. Delivery is the only thing that triggers it. So a walk that was uploaded and never finished, or one whose report failed for good, keeps its raw audio and full-resolution photos in our storage until you delete your account — or until you email us and ask, which we will do.
- Signed download links in the report email expire 30 days after they are issued.
- On your phone, a walk stays until you delete that job in the app or delete the app itself. Nothing on the device is removed on a schedule.
An email that has already been delivered is out of our hands — it is in the recipient's mailbox and we cannot recall it.
Deleting your account
In the app: Settings → Delete account → Yes, delete everything.
This permanently deletes, from our servers: every file stored for you — recordings that have not yet been purged, all photos, and every rendered report — followed by your account itself, which removes your jobs, your walks, your transcripts, your typed notes, your report history, your credit balance and your purchase records. The file deletion runs first and is verified; if it cannot complete, the account is not deleted and you are told to try again, rather than being left with files nothing can find.
Two things it does not do. It does not remove walks still stored on your phone — delete those jobs in the app, or delete the app. And it does not recall reports that have already been emailed.
No tracking, no ads, no analytics
The app contains no advertising, no analytics SDK, and no third-party tracking software. We do not use the advertising identifier, we do not track you across other companies' apps or websites, and we do not sell or rent your data or share it for advertising. The only companies that receive anything are the six named above, each for the step described.
Permissions the app asks for
- Microphone — to record your voice notes.
- Camera — to shoot job-site photos, straight into the app.
- Speech recognition — for the on-device row label described above.
- Notifications — for one thing only: telling you that a call or an alarm stopped your recording, so you do not keep talking into a dead microphone with the phone in your pocket. These are generated on the device; there is no push server.
Children's privacy
SM Site Walk is a tool for construction professionals. It is not directed at children, and we do not knowingly collect personal information from anyone under 13. If you believe a child has created an account, contact us and we will delete it.
Your choices
You can delete an individual note, photo or job in the app before you tap Finish, and you can delete your entire account at any time from Settings. For any other request about your data — a copy of it, a correction, a deletion — email bevans18@hotmail.com.
Changes to this policy
If what the app does with your data changes, this page is updated to match, with a new effective date at the top. The version you are reading is always the current one.
Contact
Anything on this page you want explained, challenged, or acted on — write to bevans18@hotmail.com.