Effective date and last updated: August 24, 2026
Application Version: 2.0.0+
Application Package ID: com.donetrue.app
Official Canonical URLs: https://umbrabyte.app/en/donetrue/privacy/ and https://umbrabyte.app/en/privacy/
This privacy policy applies to the Android mobile application DoneTrue: Jobsite Camera & Field Evidence (identified by package name com.donetrue.app), developed and published by Umbrabyte Apps (operated by sole proprietor Cristian Donet Segura). It complements the general Umbrabyte Privacy Policy and serves as the official, binding privacy policy linked within the app and its Google Play Store listing.
Plain language summary: DoneTrue is a camera-first, offline jobsite workspace built for contractors, tradespeople, renovators, and surveyors. All jobsite photo documentation, GPS coordinates for photo watermarks, voice dictation notes, client records, estimates, expenses, work orders, punch lists, and TrueProof cryptographic signatures are processed and stored strictly locally on your device in SQLite Room and private app sandbox storage. Umbrabyte operates no remote backend servers to intercept your work or client data, requires no user account, includes zero advertisements, zero tracking SDKs, and never sells or rents personal data. Data only leaves your device when you explicitly choose to share files or export backups, when user-configured cloud/CRM integrations are enabled by you, when Google Play processes an optional subscription, or when contacting direct support.
This plain-language summary does not replace the comprehensive legal and technical terms set forth below.
1. Scope and key facts
DoneTrue empowers trade professionals to document jobsite progress, capture before-and-after evidence with Ghost Cam alignment, verify original image integrity via on-device cryptographic watermarks (TrueProof SHA-256 / ECDSA P-256), and generate professional PDF reports, estimates, and invoices without relying on cloud infrastructure.
- No user account or login required: The application requires no account creation, passwords, phone numbers, or registration credentials.
- 100% On-Device / Offline-First Processing: Image processing, metadata embedding, photo watermarking, cost calculations, PDF generation, and speech transcription run locally on your device hardware.
- No Umbrabyte cloud servers: Umbrabyte does not own, operate, or maintain cloud servers to host, inspect, or backup your photos or client database.
- Contractor as Data Controller under GDPR: When you store client contact information (names, phone numbers, jobsite addresses) in DoneTrue, you act as the data controller for your clients’ information. DoneTrue serves as your local offline tool.
- Zero advertisements or marketing trackers: The application contains zero advertising networks, tracking SDKs, or third-party analytics libraries (no Firebase Analytics, Mixpanel, or AppsFlyer). The app manifest explicitly avoids advertising identifiers.
- No data sales: Umbrabyte never sells, rents, leases, or trades user data or client information under any circumstances.
- Platform integration: Optional PRO subscriptions are processed through official Google Play Billing APIs. In-App Update checks utilize official Google Play Core APIs.
2. Data Controller
The developer and data controller for any personal data received directly by Umbrabyte (such as email communications with customer support) is:
- Full Name: Cristian Donet Segura
- Studio Name: Umbrabyte Apps
- Business Address: Calle Pintor Camarón, nº 24, 12560 Benicasim, Castellón, Spain
- Tax ID (NIF): 20468489F
- D-U-N-S® Registered Number: 374071851
- Privacy & Support Contact: support@umbrabyte.app
- Official Website: https://umbrabyte.app
Google LLC acts as an independent data controller for transactions processed via Google Play Store and Google Play Billing under its own privacy policies.
3. Data processed by the application
3.1 Information stored and processed strictly on device
All records are stored within private app sandbox storage and SQLite Room database on your device:
| Data Category | Information Elements | Storage Location & Retention |
|---|---|---|
| Jobsite photos & evidence | Captured photos, before/after Ghost Cam frames, high-resolution original images, markup drawings | Private local app storage (LocalFileService) on device |
| Location coordinates | Approximate and precise GPS coordinates embedded into photo metadata watermarks and proximity matching | Embedded into photo EXIF / SQLite database on device |
| Voice dictation notes | Transcribed text notes dictated by user over photos | Private local SQLite Room database (VoiceNotesDao); audio recordings are not stored |
| Client records | Client names, contact phone numbers, emails, and job addresses entered by contractor | Private local SQLite Room database (ClientsDao) |
| Financial & project records | Estimates, invoices, expenses, time tracking logs, work orders, catalog items, and client signatures | Private local SQLite Room database (ProjectsDao, EstimatesDao) |
| TrueProof cryptographic data | SHA-256 image hashes and ECDSA P-256 digital signatures generated in Android KeyStore | Embedded into photo metadata and local database |
| Purchase status & PRO entitlement | Cached local PRO subscription entitlement status | Private local preferences (DataStore) on device |
Encrypted backups (.dtbackup) |
Full database and media archive encrypted with AES-256-GCM using user’s password | Stored in user-selected local file directory |
3.2 Android permissions and device access
Android permissions are requested transparently with contextual rationale only when you initiate features that require them:
| Permission / Capability | Purpose & Technical Function | Necessity & Handling |
|---|---|---|
android.permission.CAMERA |
Captures jobsite photos, before/after evidence, and optical alignments | Required for camera viewfinder; photos stored in private app sandbox |
android.permission.ACCESS_FINE_LOCATION & ACCESS_COARSE_LOCATION |
Embeds GPS coordinates and location metadata into photo watermarks and suggests nearby active jobsites | Optional; requested only while app is in foreground / in-use with a 6-second timeout. Never accessed in background |
android.permission.RECORD_AUDIO |
Transcribes spoken job notes directly into text via Android system SpeechRecognizer | Optional; active only while holding the microphone button. Audio is never recorded or saved to disk/servers |
android.permission.POST_NOTIFICATIONS |
Displays local alerts for scheduled job reminders and work order tasks (Android 13+) | Optional; generated 100% locally on device |
android.permission.RECEIVE_BOOT_COMPLETED |
Reschedules pending reminder alarms after device restart | Used strictly for local alarm restoration |
android.permission.INTERNET |
Reverse geocoding of GPS coordinates into human-readable street addresses, user-configured cloud backup, and Play Billing | Used for online geocoding, user-enabled webhooks, and billing |
com.android.vending.BILLING |
Connects to Google Play Billing API for optional PRO subscriptions | Used when subscribing or restoring PRO |
The application does NOT request or use background location (ACCESS_BACKGROUND_LOCATION), broad storage access (WRITE_EXTERNAL_STORAGE), exact alarm permissions (SCHEDULE_EXACT_ALARM), package scanning (QUERY_ALL_PACKAGES), contacts list, SMS, or advertising IDs.
3.3 User-configured integrations and exports
- Cloud Backup: Optional backup to user’s own cloud storage (Google Drive, Dropbox, OneDrive, WebDAV) is disabled by default. When enabled by you, data transfers directly from your device to your cloud provider.
- CRM Webhooks: Optional webhook dispatch to your CRM or custom API is disabled by default. When configured, payloads are signed with HMAC-SHA256, strictly over HTTPS, and local private IP ranges are rejected.
- PDF & File Sharing: Exporting signed PDF estimates, work orders, or image bundles occurs through standard Android system interfaces (
IntentandFileProvider). You select the recipient.
3.4 Data Umbrabyte does NOT receive
During standard use of DoneTrue, Umbrabyte does not receive, intercept, or store on servers:
- Photos, before/after comparisons, or jobsite evidence.
- GPS coordinates or project addresses.
- Client names, phone numbers, or email addresses.
- Estimates, invoices, hourly rates, or financial totals.
- Audio recordings or voice transcriptions.
- Encryption passwords used for backup files.
4. External services & monetization terms
4.1 Distribution and subscriptions via Google Play Billing
DoneTrue is free to install with core functionality. Optional DoneTrue PRO subscriptions are processed via official Google Play Billing:
- Billing terms: Payments, tax collection, currency conversion, and receipts are handled exclusively by Google Play. Umbrabyte never receives or stores credit card numbers or financial credentials.
- Subscription management & cancellation: Subscriptions automatically renew unless cancelled at least 24 hours before the end of the billing period. You can manage or cancel your subscription anytime in Google Play Store > Payments & subscriptions.
- Refunds: Governed by the Google Play Refund Policy.
- Offline access guarantee: Core features remain functional offline even without an active subscription.
4.2 In-app updates via Google Play Core
DoneTrue integrates official Google Play Core APIs to verify if an updated version is available on Google Play and deliver seamless updates.
4.3 Third-party SDKs and telemetry policy
DoneTrue contains zero third-party analytical or advertising SDKs. Network communications are strictly limited to reverse geocoding via system services, user-configured webhooks, and Google Play Store platform services over TLS 1.3 / HTTPS.
5. Purposes and legal bases
Under the European Union General Data Protection Regulation (GDPR) and UK GDPR, processing activities rely on:
| Activity / Feature | Purpose | Legal Basis under GDPR |
|---|---|---|
| Jobsite documentation & calculations | Provide requested app workspace and tool functionality | Contract performance (Art. 6.1.b GDPR) |
| Camera & GPS location access | Real-time photo capture & metadata watermarking | Explicit user consent via runtime permission (Art. 6.1.a GDPR) |
| Voice dictation over photos | Real-time speech transcription into text notes | Explicit user consent via runtime permission (Art. 6.1.a GDPR) |
| PRO subscriptions & billing | Process subscriptions, verify entitlements & statutory accounting | Contract performance (Art. 6.1.b) & Legal compliance (Art. 6.1.c GDPR) |
| In-app updates & security | Keep application secure, stable, and up to date | Legitimate interest (Art. 6.1.f GDPR) |
| Customer support | Respond to technical inquiries or privacy rights requests | Contractual / pre-contractual steps (Art. 6.1.b) & Legitimate interest (Art. 6.1.f) |
6. Data retention, deletion & management
| Data Type | Retention Period | Deletion & Management Method |
|---|---|---|
| Local photos, projects, client records & notes | Retained until manually deleted by user or app uninstalled | Delete within app, clear app data under Android Settings, or uninstall app |
Encrypted backup files (.dtbackup) |
Controlled by user in local storage | Manual file deletion in file manager |
| Local PRO purchase status | Duration of app installation; restorable via Google Play | Automatically synchronized with Google Play account |
| Transaction records in Play Console | Statutory tax and accounting retention periods (5 to 10 years) | Maintained by Google and Umbrabyte for legal compliance |
| Support correspondence | Up to 3 years to resolve technical and legal inquiries | Periodic inbox deletion |
Data Deletion: DoneTrue does not maintain user accounts on developer servers. To permanently erase all data, clear storage in Settings > Apps > DoneTrue > Storage > Clear Data or uninstall the app. Note that tax laws in certain jurisdictions may require contractors to retain job invoices and signed work orders for 5 to 10 years.
7. Data security
- Operating system sandboxing: All local databases and media files are isolated within Android’s private UID sandbox.
- TrueProof Cryptographic Signatures: Photos can be digitally sealed using ECDSA P-256 keys generated in Android hardware KeyStore.
- Backup Encryption: Exported
.dtbackuparchives support AES-256-GCM encryption with a user-defined password that is never stored or transmitted. - Biometric App Lock: Optional biometric lock (fingerprint/face) via Android BiometricPrompt to protect access on shared devices.
- Encrypted Transport: Network communication for Play Billing, geocoding, and webhooks strictly requires TLS 1.3 / HTTPS.
usesCleartextTraffic="false"is strictly enforced.
8. Your rights worldwide
You hold comprehensive privacy rights across global jurisdictions:
- European Union & EEA (GDPR / RGPD & Spanish LOPDGDD): Right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), and right to withdraw consent. You also have the right to lodge a complaint with the Agencia Española de Protección de Datos (AEPD) at https://www.aepd.es.
- United Kingdom (UK GDPR & DPA 2018): Full consumer rights enforceable via the Information Commissioner’s Office (ICO).
- United States & California (CCPA / CPRA / CalOPPA & US State Laws): Right to know, access, delete, and correct personal information. Umbrabyte does not sell or share user personal data for cross-context behavioral advertising. We respect Global Privacy Control (GPC) signals.
- Brazil (LGPD): Rights under Article 18, including confirmation, access, correction, anonymization, and deletion, enforceable via the ANPD.
- Canada (PIPEDA): Fair information handling and access rights via OPC.
- Australia (Privacy Act 1988 & APPs): Principles for respectful, transparent data handling via OAIC.
- Japan (APPI) & South Korea (PIPA): Full statutory compliance for local privacy mandates.
To exercise any privacy rights, contact us directly at support@umbrabyte.app.
9. Children’s privacy
DoneTrue is a professional utility designed for tradespeople and contractors. It is not directed to children under 16 years of age (or local statutory age). We do not knowingly collect data from children.
10. Changes to this privacy policy
We may update this policy periodically to reflect application enhancements or regulatory requirements. Any updates will be published at this canonical web address with an updated effective date.
11. Contact information
Cristian Donet Segura — Umbrabyte Apps
Calle Pintor Camarón, nº 24
12560 Benicasim, Castellón, Spain
Tax ID (NIF): 20468489F
D-U-N-S® Number: 374071851
Email: support@umbrabyte.app
Website: https://umbrabyte.app
أسئلة حول خصوصيتك؟
إذا كانت لديك أسئلة حول معالجة البيانات أو ترغب في ممارسة حقوقك، فاتصل بنا مباشرة.
support@umbrabyte.app