Privacy notice
Who we are
AvoProof is operated by AvoSolution Ltd, a company registered in England and Wales (company number [company number]) with its registered office at [registered office address]. AvoSolution Ltd is the data controller for the personal data described here. You can reach us at support@avoproof.com.
We are registered with the Information Commissioner’s Office under registration number [ICO registration number].
What AvoProof is
AvoProof is a personal vault. You send it documents, by forwarding emails to your personal proof address or by uploading photos and files in the app, and it keeps the originals as tamper-evident evidence and builds records from them about your vehicles, home, travel, purchases, subscriptions, tickets and, if you choose to add them, your health and identity documents.
Because you decide what to send, the data we hold about you is largely what you have chosen to put in the vault. This notice explains what happens to it.
What we hold
| Data | Where it comes from | Why we hold it |
|---|---|---|
| Your sign-in email address, display name and session tokens | You, at sign-up and sign-in | To run your account and keep you signed in |
| The original emails, attachments, photos and files you send to the vault | You, by forwarding or uploading | To keep the evidence you asked us to keep, exactly as it arrived |
| Records extracted from those documents: assets, receipts, vehicles, insurance, mortgages, utilities, trips, bookings, tickets, subscriptions, memberships, tasks | Derived from your documents by automated extraction; confirmed or edited by you | To provide the service: reminders, the emergency screens, expense claims, search |
| Identity documents: passport, driving licence, national ID, proof of age, and other codes you choose to store | You | To have them at hand when you need them. Held only if you add them |
| Health information: medical profile, allergies, medications, vaccinations, medical insurance | You | For the emergency screens and travel readiness. Held only with your explicit consent (see below) |
| Emergency contacts and other people’s details that appear in your documents (a second passenger, another driver after an accident) | You, and the documents you forward | Because they are part of the evidence and the emergency information you asked us to keep |
| Your location, at the moment you open a roadside screen | Your device, with your permission | To show your position to read to an operator. Never stored |
| Fingerprints (hashes) of your documents, anchor records, and audit logs of erasures and operator access | Generated by the service | To prove integrity and to account for what was erased and who looked. These contain no document contents |
| Push notification endpoints and device details | Your device, if you enable reminders | To deliver reminders |
Why we are allowed to (lawful basis)
- Contract. Holding your documents, extracting records from them and reminding you about them is the service you signed up for.
- Explicit consent for health data. The Medical section stores special category data. We ask for your explicit consent the first time you open it, record when you gave it, and you can withdraw it at any time by deleting the Medical records or your account.
- Legitimate interests for the details of other people that appear in your documents and emergency contacts. We hold them only as part of your evidence, never build profiles of them, and delete them with your account.
- Legal obligation for the erasure and access logs we keep to demonstrate compliance.
How your documents are read
When a document arrives, automated software extracts the useful facts from it: the vendor and total on a receipt, the expiry on a policy, the flight number on a booking. This uses an AI model provided by a processor under a data processing agreement. The model’s output is a suggestion; nothing becomes a record until you confirm it, apart from receipts, which you can check and correct at any time.
We do not analyse the contents of your purchases across users, build marketing segments from them, or use your documents to train models. Inferences about you are not drawn from what you buy.
Who else processes your data
We use these providers to run the service. Each acts on our instructions under a data processing agreement.
| Provider | What they process | Why |
|---|---|---|
| Amazon Web Services (London region) | Your original documents, encrypted; the application servers; email sending and receiving | Hosting and storage |
| Supabase | Your account and the records in your vault | Database and sign-in |
| Anthropic | The text and images of the documents you send, at the moment they are read | Extracting records from documents. Anthropic is based in the United States; transfers are covered by standard contractual clauses |
| what3words | Your coordinates at the roadside | Your three-word location |
| OpenStreetMap and postcodes.io | Your coordinates at the roadside; a postcode you type | Nearest road, landmark and postcode; local authority for property data |
| Google Maps | Addresses you type or navigate to | Maps, navigation and address suggestions |
| Ideal Postcodes | A postcode you type | Address lookup |
| DVSA | A vehicle registration you type | MOT history |
| HM Land Registry open data | A property’s postcode | Sale history and house price index |
| DigiCert (timestamp authority) | A single daily hash of all new document fingerprints | Independent timestamping. No document contents leave AvoProof |
| Google, Apple and Mozilla push services | Reminder notifications, titles only | Delivering reminders to your device |
We do not sell your data, and we do not share it with anyone for advertising.
How long we keep it
- Your documents and records stay in your vault until you delete them or your account. Deleting a proof erases the original from our storage, including backup versions, within about two days.
- Deleting your account is a two-step process with a seven-day cooling-off period. After that, every record, document and photo belonging to the account is erased, and only a hash-based log that an erasure happened is kept.
- Audit logs (who accessed what, when something was erased) contain no document contents and are kept for [retention period].
Your rights
You have the right to access the data we hold about you, to correct it, to have it erased, to restrict or object to its processing, and to receive it in a portable form. Most of these you can do inside the app: every record is editable, every proof can be viewed and erased, and your account can be deleted from Settings. For a full copy of your data, or anything you cannot do in the app, email support@avoproof.com and we will respond within one month.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner’s Office at ico.org.uk.
Security
Your documents are stored encrypted, in the UK, under an encryption key we control and rotate. Every read of a document is logged. Records are protected so that one account can never read another’s. Photos in your vault are private and served only to you. Documents are fingerprinted on arrival and anchored daily with an independent timestamp authority so that any alteration is detectable. Operator access for support is logged and is never hidden inside the app.
If we ever suffer a breach that puts your rights at risk, we will tell the ICO within 72 hours and tell you without undue delay.
Children
AvoProof is for adults managing their own affairs. We do not knowingly accept accounts from anyone under 18.
Changes to this notice
We will post any changes here with a new version number and date. If a change affects how we use your data in a material way, we will tell you in the app first.
