UZYTAK Field Report · Android
Privacy Policy
UZYTAK is the software brand of UZYTAK. App support and legal enquiries: support@uzytak.com.
1. Scope and responsibility
This policy covers UZYTAK Field Report for Android, its translation and entitlement services, and the public websites uzytak.com and teams.uzytak.com. The Field Teams application itself has separate service terms and privacy information at onboarding. The data controller is UZYTAK. Privacy contact: privacy@uzytak.com. You remain responsible for having authority to record and share information about your clients, employees and other people. UZYTAK does not obtain ownership of your reports.
2. Reports and media on your device
Photos, annotations, signature images, report text, templates, work-profile details and any chosen location information are stored in the app’s local private storage. The core reporting tools work offline. Report contents are not uploaded merely to check a trial or purchase entitlement. The app relies on Android and device storage protections; it does not independently encrypt the entire local database or promise end-to-end encryption of exported reports.
You choose when to export a PDF, make a backup, copy a captured photo to Gallery or share with another app. Those external copies are handled by the recipient or destination service. Removing an app record does not remove exported copies. Uninstalling, clearing app data or losing the device can remove local work. There is no automatic UZYTAK cloud report archive; keep your own backups.
3. Optional AI Translation
When you request translation, the necessary report-facing text, source and target languages and relevant terminology/profession context are sent over HTTPS to the UZYTAK backend and OpenAI’s API. This may include custom field titles, options, values, notes and captions. Text that you enter can contain personal information; it is not automatically anonymized. Send only what is necessary and review translated text before sharing.
The translation payload does not include the whole report, photos, handwritten signature pixels or your device’s private installation key. Structured identity fields are not automatically translated. Personal information typed into prose can still be transmitted with that prose.
The backend does not intentionally keep report or translation content beyond what processing requires unless a specific production feature needs storage. The current exception is an encrypted response cache and duplicate-request response handling, with a 24-hour expiry, to reuse translations and avoid duplicate processing. Source text is processed in memory; keyed digests support caching and idempotency. A same-language cached result can contain the source wording. Encryption does not make cached content anonymous. Operational token/cost analytics contain pseudonymous references, model, token counts, timing, status and estimated cost, not report text or images.
Translation currently uses OpenAI’s Responses API with store:false. We do not claim that Zero Data Retention or EU-only provider processing is enabled. OpenAI states that API inputs and outputs are not used to train or improve its models by default unless the customer explicitly opts in. Its default abuse-monitoring logs can include prompts, responses and derived metadata and are retained for up to 30 days, with longer retention possible where legally required or reasonably necessary to protect services or third parties from harm. Provider prompt caching can separately retain encrypted model-cache state for up to 24 hours. store:false does not disable all these forms of retention. These provider rules are distinct from UZYTAK’s own cache and log limits. See OpenAI’s current API data controls.
4. Camera, microphone, location and files
- Camera access supports the capture you choose. Importing media uses the system picker rather than unrestricted access to the photo library.
- Microphone access supports optional speech-to-text. The app keeps recognized text, not a voice-recording archive. Android’s selected recognition service may process audio online. On-device recognition depends on the device and installed language support; text entry remains an alternative.
- Location is optional and can be precise or approximate according to Android permission settings. It is used for capture/report context, not background tracking. You control whether available GPS details appear in the PDF. Typed addresses sent for translation are a separate text data flow.
- Files are used for local reports, PDF export and chosen backup/import operations. On older Android versions, explicit Gallery saving can require legacy storage permission.
You can revoke permissions in Android settings. Denial limits the relevant optional function rather than authorizing unrelated access.
5. Trial, purchases and service authorization
No UZYTAK email/password registration is required. Online authorization uses a pseudonymous installation identity, public key, attestation evidence and signed challenges. The installation private key stays in Android Keystore. Entitlement records include opaque report-completion references/counts, request state and purchase/grant history. These support the three-completed-report allowance, purchase restoration, permanent Founding rights and abuse prevention.
Google Play handles checkout. UZYTAK receives purchase identifiers/tokens and verification status and verifies purchases with Google’s services; Google notifications can update that status. UZYTAK does not receive your payment-card number or Google password. Entitlement checks do not request report photos, customer details, GPS, notes or templates. This release uses key-attested authorization; no Play Integrity Device Recall deployment is claimed.
The app includes Google Play Billing and Google Play services location components. These services and Android speech recognition can process their own technical/service data under their providers’ policies. There is no app-level advertising, personalized-ad or Firebase Analytics integration. This does not mean third-party services process no diagnostics.
6. Website, support and security
The public websites have no analytics scripts, advertising pixels or visitor account database. Fonts and graphics are hosted with the website. The Field Teams demo form sends your name, company, work email, plan interest, team size, languages and workflow description through our Hostinger website mail handler to teams@uzytak.com when you submit. These details are used to respond to your enquiry, not to subscribe you to a mailing list. The general contact form can also prepare an email in your own email application. Do not send passwords, API keys or unnecessary client records.
For form security, the handler uses a signed challenge, a hidden spam field, request timing and hashed rate-limit counters. It does not save the form contents in a website database. Security counters and challenge-use records expire within 24 hours. Mail and ordinary hosting logs are handled separately by their services. Enquiry correspondence follows the correspondence retention period below.
Website/API hosting and network services handle connection data such as IP addresses, request times and user-agent information. Authentication outcomes, request sizes and unusual request patterns can be used for security. No advertising ID or IMEI/serial-based invasive fingerprinting is used by the app’s entitlement design. Temporary authorization restrictions are not a determination of your legal rights; contact support if you believe access was restricted incorrectly.
7. Purposes, recipients and international processing
Data is used to provide requested reporting-related online functions, administer purchases and entitlements, respond to support, secure the services and meet applicable legal obligations. Processing necessary to provide a requested service is based on the relevant contractual relationship; security and service-operation processing may rely on legitimate interests, subject to applicable safeguards and objections. Where consent is required, it must be specific and withdrawable. An Android permission alone is not a complete legal basis for every use of another person’s data.
The production services use OVHcloud for the backend hosted in Frankfurt, Hostinger for this website, OpenAI for requested translation and Google for Play purchase verification. The device’s chosen speech service, the email services involved when you contact us and recipients you choose for exports handle their respective data flows. A Frankfurt server does not make the whole service EU-only.
The following describes verified published provider mechanisms, not a claim that a separately negotiated agreement has been signed: OpenAI’s DPA identifies OpenAI Ireland Ltd. for EEA/Swiss customers and provides for SCCs or an applicable adequacy decision for onward transfers. OVHcloud’s published privacy safeguards describe SCCs for processing outside the EEA. Hostinger’s privacy policy describes contractual safeguards using European Commission standard clauses. Google’s transfer framework notice describes applicable adequacy frameworks and SCCs where required. These statements do not imply that every transfer uses the same mechanism or that an EEA contracting entity excludes international processing. Contact us for information about the arrangements applicable to your data.
8. Retention and removal
- Local reports and media: retained until you delete them or remove the app’s data. Hiding a report from history is not the same as deleting all its files. Manage exported PDFs, Gallery copies and backups separately.
- Encrypted translation responses: the production configuration expires response/cache content after 24 hours. A running background cleanup removes expired response content on its next cycle; outages can delay that cycle. Content-free request tombstones are kept separately to prevent duplicate processing.
- Operational token/cost telemetry: a 90-day retention window. Cleanup runs when telemetry is recorded or maintained, so records awaiting the next maintenance cycle can remain longer during inactivity or an outage. These events contain technical and cost information, not report text, and are not a user-facing translation quota.
- Server/application logs: application-container logs rotate automatically by size, keeping up to three files of approximately 5 MB per container. Older files are replaced as new logs are written; the elapsed retention time depends on activity, not a fixed 30-day deadline. Other system and hosting logs follow their operational rotation and security requirements. Logs are used for troubleshooting, service operation and security, not advertising.
- Recovery copies and hosting backups: the deployed application does not run an automated rolling-backup schedule for your reports. Operational recovery copies can be made for deployment or incident recovery and do not have an application-enforced automatic expiry. They are restricted to recovery purposes and retained only while needed for that purpose or an applicable legal obligation. Hostinger’s published web-hosting backup schedule describes six weeks for weekly copies and seven days for daily copies where enabled; this concerns hosted website files, not a UZYTAK cloud archive of your local reports. We do not promise that every server/provider backup disappears within 30 days.
- Support and privacy correspondence: maximum 24 months after the case is closed, except specific records that must be retained under applicable law.
- Purchase, entitlement, tax and legal records: retained only for the period required by applicable law. A specific legal retention requirement must be identified rather than treating all records as permanently exempt from deletion.
- Installation, completion and duplicate-request references: limited to what the relevant service/security purpose requires and subject to approved deletion requests; identifiers do not justify indefinite retention merely because they are pseudonymous.
Provider-side records are subject to the separate provider rules described above. Removing a local report does not automatically erase independent server authorization or purchase records or information you separately sent to support. Request server-side deletion through the privacy contact; no UZYTAK login account is required. Approved requests remove active data promptly. Any recovery copy that cannot immediately be selectively changed remains restricted until replaced or removed; an applicable deletion request must be reapplied before restored data returns to ordinary use. We explain any relevant retention exception when responding. Cache expiry is not a claim of immediate forensic erasure from database pages or backups.
9. Your rights and requests
Where applicable, you can request access, correction, erasure, restriction, portability, object to relevant processing and withdraw consent without affecting prior lawful processing. Contact privacy@uzytak.com with “Privacy request” and enough information to identify the relevant service or purchase; do not send passwords or private keys. Proportionate verification may be necessary. We cannot retrieve or remotely erase records held only on your device or copies held by recipients.
We respond to data-subject requests within one month of receipt. If an extension permitted by applicable law is necessary, we explain the reason and extension within that first month. Approved deletion requests are carried out promptly for active data, with recovery copies handled as described above. Any retained legal record must be distinguished from data approved for deletion. You may complain to the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), or another competent authority. This policy does not limit applicable statutory rights.
10. Changes
Updates to processing will be reflected here with a revised date. Material changes requiring notice or consent will not be treated as accepted merely because you previously used the app. See the Terms of Use for report responsibility and purchase conditions.