Privacy Policy
This Privacy Policy explains how SiteBrief LLC ("SiteBrief," "we," "our," or "us") collects, uses, shares, and protects personal information when you use our platform at sitebriefapp.com, our mobile applications, and related services (the "Service"). By using SiteBrief, you agree to the practices described in this policy. This policy applies both to account holders (service professionals in any industry) and to clients who access reports through a SiteBrief portal.
1. Who We Are
SiteBrief LLC is a Texas limited liability company. Our address for legal notices is 5900 Balcones Drive, Ste 100, Austin, TX 78731. We operate a mobile-first field documentation and walkthrough reporting platform for service providers, inspectors, and field professionals across any industry, including custom industries defined by the account holder.
2. Information We Collect
We collect the following categories of information:
- Account Information: Name, email address, phone number, company name, industry/trade, logo, and password (stored in hashed form) when you create an account.
- Project Data: Walkthrough reports, photos (which may include embedded metadata such as capture time and, if enabled on your device, location/EXIF data), voice notes and their transcriptions, Continuous Walkthrough audio recordings and their transcripts (on plans that include that feature), AI-generated summaries, client feedback threads, and electronic signatures created within the platform.
- Camera, Photo & Microphone Data: With your device-level permission, we access your camera, photo library, and microphone solely so you can capture site photos and record voice notes or Continuous Walkthrough audio. Continuous Walkthrough records audio only while a recording session you started is active and shown on screen; we do not otherwise access your camera, photos, or microphone in the background or for any other purpose.
- Client Information: Names and phone numbers of clients that account holders add to projects for the purpose of sending project portals and SMS notifications. If you are a client, the professional you work with provided this information to us.
- Sign-Off Record Data: When a client signs off on a project, we record the drawn signature image, the verified phone number or email address (confirmed by a one-time code sent to the contact information on file, with the method actually used stated in the record), the signing device's IP address, a timestamp, and a cryptographic content-integrity hash. This information becomes part of the permanent, tamper-evident project record and appears on the final PDF. Quick Agreement records (the change description, amount, optional photo and its hash, the verified contact and verification method, and timestamps) are recorded the same way and become part of the same project record.
- Payment Information: Subscription payments are processed by Stripe or by Apple/Google in-app purchase (managed via RevenueCat). We receive subscription status and transaction identifiers; we do not store your full payment card number.
- Usage & Billing Records: For plans with processed-audio minutes, we store per-walkthrough usage records (recorded duration, credited silence, and minutes charged, derived from transcription word timestamps) to compute your balance, show usage receipts, and resolve billing questions.
- Accounting Integration Data: If you connect QuickBooks Online, we store the connection tokens and the minimum data needed to create draft invoices (e.g., your QuickBooks company ID, customer names, and invoice line items from your signed-off reports). We access your QuickBooks data only to provide the integration, and you can disconnect at any time in Settings.
- Device & Usage Data: Browser type, device type, operating system, IP address, pages visited, feature usage, and error/diagnostic logs, for analytics, debugging, and security purposes.
- Communications: Messages sent through the platform's two-way thread system between account holders and clients, SMS delivery records, and any support correspondence with us.
- Local Storage & Cookies: We use cookies and browser local storage for authentication sessions, preferences, and essential Service functionality. Inside the logged-in app we do not use third-party advertising cookies. Our public marketing pages (such as the sitebriefapp.com landing page) use third-party advertising analytics pixels — currently the TikTok Pixel — which set cookies and collect information such as your IP address, device and browser information, and the pages you visit, to measure the performance of our advertising campaigns. These pixels never receive your project content, and they only load after you accept advertising cookies in the cookie banner. You can change your choice at any time through the “Cookie Preferences” link in the page footer, decline them entirely (the Service works fully either way), or block and delete their cookies through your browser settings.
3. How We Use Your Information
We use your information to:
- Provide, operate, secure, and improve the SiteBrief platform
- Send SMS notifications related to your projects (report deliveries, client responses, sign-off alerts, and capped automated sign-off reminders where enabled)
- Verify client identity via one-time codes (sent by SMS to the phone number on file, or by email if SMS cannot reach the client) before portal access and electronic signature
- Transcribe voice notes and Continuous Walkthrough audio, generate AI-assisted walkthrough report summaries, and compute processed-audio minute usage (including automatic silence credits) from transcript timestamps
- Create tamper-evident sign-off records and branded PDF reports
- Process subscriptions and manage billing
- Respond to support requests and account inquiries
- Detect, investigate, and prevent fraud, abuse, and security incidents
- Comply with legal obligations and enforce our Terms of Service
We do not use your content (reports, photos, voice notes) for advertising, and we do not sell it.
4. SMS Messaging: Opt-In & Opt-Out
SMS Opt-In: By creating an account or providing your phone number on the SiteBrief platform, you expressly consent to receive SMS text messages from SiteBrief LLC, including messages sent using automated technology. These messages include project notifications, client portal delivery links, identity verification codes, and — where the account holder enables them — a capped number of automated sign-off reminders that are never sent during local nighttime quiet hours and stop permanently on STOP, sign-off, delivery failure, or when the cap is reached. Consent is not a condition of purchase.
Opt-Out: You may opt out at any time by replying STOP to any SMS message from SiteBrief. You will receive a single confirmation message, after which no further messages will be sent unless you re-opt in. Reply HELP for assistance, or contact support@sitebriefapp.com. Message and data rates may apply; message frequency varies with project activity. Opting out will limit your ability to receive real-time project notifications and to complete SMS-verified sign-offs.
Clients: If you received a SiteBrief text, a professional you work with entered your number to send you a report. Reply STOP to stop receiving messages.
We do not use your phone number for marketing, and mobile phone numbers and SMS consent data are never sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. Phone numbers are shared with our SMS delivery provider (Twilio) solely to deliver the messages described above.
5. How We Share Your Information
We do not sell your personal information for money. Apart from the limited advertising measurement described below, we do not share it with third parties for their own marketing. We share information only with:
- Service Providers (processors): Firebase / Google Cloud (authentication, database, file storage), Netlify (hosting and serverless functions), Twilio (SMS delivery), Deepgram (voice-note and walkthrough transcription), Anthropic (AI report generation), and Stripe / RevenueCat / Apple / Google (payments and subscriptions). These providers process data only to provide their services to us and are bound by contractual data-protection obligations.
- Intuit (QuickBooks Online): Only if you connect the integration, we share the data needed to create draft invoices in your own QuickBooks account (customer name and invoice details from your signed-off reports). Intuit processes that data under its own terms and privacy policy.
- Your Clients / Your Service Professional: Project data, reports, photos, messages, and portal links are shared between the account holder and the client contacts designated on each project. The final signed PDF — including the signature, verified phone number, signing IP address, and integrity hash — is available to both parties.
- Advertising & Analytics Partners (TikTok and Meta): We use TikTok and Meta (Facebook) advertising tools to measure our ad campaigns. On our public marketing pages, the TikTok Pixel collects IP address, device/browser information, and page-visit events. In our iOS app (not our Android app), the Meta and TikTok SDKs send app events — such as installs, launches, session activity, and in-app purchase events — together with device information and IP address directly to Meta and TikTok for ad-campaign measurement, and install attribution is additionally reported through Apple's aggregated SKAdNetwork framework. We have disabled advertising-identifier (IDFA) collection in the Meta SDK, and our app does not request App Tracking Transparency permission, so Apple's advertising identifier is not made available to these SDKs. These partners process this data under their own privacy policies (Meta and TikTok). Your project content — reports, photos, audio, transcripts, and client information — is never shared with advertising partners.
- Legal Requirements: We may disclose information if required by law, subpoena, or court order, or where we believe disclosure is necessary to protect the rights, property, or safety of SiteBrief, its users, or the public, or to detect and prevent fraud or abuse.
- Business Transfers: If SiteBrief is involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction, subject to this policy.
6. Data Retention & Photo Deletion
Photos are scheduled for permanent deletion 14 days after a project is marked "Completed," and are removed at or shortly after that time. This is a deliberate design of the Service to manage storage. Export your project PDF, and keep your own copies of any photos you need, before this window closes. Photos preserved inside a signed PDF remain part of that record.
Plans with extended retention (e.g., Premium) retain project photos and clips for ninety (90) days after a project is marked "Completed" instead of 14 days. Continuous Walkthrough raw transcripts are retained for ninety (90) days after the walkthrough is assembled and are then permanently deleted; raw transcripts are accessible only to the account holder, and the generated report is unaffected. Walkthrough audio segments are deleted once transcription and assembly complete.
Text records, report summaries, feedback threads, signatures, and sign-off records are retained as part of the project record for as long as needed to provide the Service and preserve the integrity of records delivered to both parties. Signed sign-off records (the frozen sign-off PDF and its verification data) are retained for a minimum of seven (7) years from the date of sign-off. Account data is retained while your account is active and for up to 90 days after deletion, except that signed sign-off records may be retained after account deletion for the retention period above (or longer) to preserve the tamper-evident record already delivered to the other party and to comply with legal obligations. Diagnostic logs are retained for limited periods.
If a project is marked completed without a client sign-off, we generate and store one Completion Record PDF for that project with the project photos embedded, so the photographic content survives the photo deletion window above. This document is clearly marked UNSIGNED on every page; it is not a signed record and contains no signature, verification, or client identity data. It is retained for one (1) year from creation, is deleted earlier if the completion is undone or your account is deleted, and is superseded by the frozen signed PDF if the client later signs off.
Retention periods by category. The table below summarizes how long each category of data is kept:
| Data category | Retention period |
|---|---|
| Project photos and video clips | 14 days after the project is marked "Completed" (90 days on plans with extended retention). Photos preserved inside a signed PDF remain part of that record. |
| Completion Record PDF (unsigned; created when a project is completed without a client sign-off) | 1 year from creation; deleted earlier if the completion is undone or the account is deleted |
| Continuous Walkthrough audio segments | Deleted once transcription and report assembly complete |
| Continuous Walkthrough raw transcripts | 90 days after the walkthrough is assembled, then permanently deleted |
| Reports, feedback threads, signatures, and sign-off records | Life of the project record, for as long as needed to provide the Service and preserve record integrity |
| Signed sign-off records (frozen PDF and verification data) | Minimum 7 years from sign-off; may be retained after account deletion to preserve the record delivered to the other party |
| SMS consent and identity-verification records (consent text shown, timestamp, IP address) | Retained with the project record to evidence consent |
| One-time verification codes (OTP) | Valid for 10 minutes; codes are never stored in plain text |
| Account and profile data | While your account is active, plus up to 90 days after deletion (except signed sign-off records, above) |
| Billing and subscription records | As required for tax, accounting, and legal compliance |
| Diagnostic logs | Limited periods |
7. Data Security
We use industry-standard security measures, including Firebase Authentication, encrypted data transmission (HTTPS/TLS), access-controlled databases and storage rules, SMS one-time-code identity verification, and cryptographic integrity hashing of signed records. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential.
Data stored on your device. To make the Service work in the field (including offline), the app and the client portal keep a working copy of your project data — such as client names, contact details, project addresses, report content, and pending offline changes — in your device's browser or app storage. This on-device copy is protected by your device's own security (passcode, biometrics, encryption at rest on modern phones) rather than by our servers, and it is cleared when you sign out or when a different account signs in on the same device. If you use SiteBrief on a shared or unlocked device, anyone with access to that device profile may be able to view this locally stored data — we recommend using a device passcode and signing out on shared devices. If we become aware of a data breach affecting your personal information, we will notify you and the relevant authorities as required by applicable law.
8. Your Privacy Rights
Depending on your location, you may have the right to:
- Access / know the personal information we hold about you, including categories collected, sources, and purposes
- Correct inaccurate personal information
- Delete your account and personal information (subject to the sign-off record retention described in Section 6)
- Portability: receive a copy of your data in a usable format (e.g., project PDF export)
- Opt out of SMS communications at any time by replying STOP
- Non-discrimination: we will not discriminate against you for exercising your rights
These include rights under the California Consumer Privacy Act (CCPA/CPRA), the Texas Data Privacy and Security Act, and similar state laws. We do not sell your personal information for money. However, our use of advertising analytics pixels on our public marketing pages (Section 5) may be considered "sharing" for cross-context behavioral advertising under the CCPA. You may opt out of that sharing at any time using the "Do Not Sell or Share My Personal Information" link in the footer of sitebriefapp.com or the button of the same name inside the web app under Settings → Help & Legal, either of which disables advertising pixels in your browser. We also honor the Global Privacy Control (GPC) browser signal as an opt-out on our marketing pages. You may additionally email support@sitebriefapp.com with the subject "Do Not Sell or Share My Personal Information." To exercise any right, email support@sitebriefapp.com; we will verify your identity and respond within the time required by applicable law. You may also use an authorized agent where permitted. If you are in the EEA/UK, you may also have rights under the GDPR/UK GDPR, including the right to lodge a complaint with a supervisory authority; our legal bases are performance of contract, legitimate interests, consent, and legal obligation.
Clients: SiteBrief processes client information at the direction of the account holder who created the project. If you are a client and wish to access or delete your information, you may contact us directly or through the professional who sent you the report.
9. Photos, Recordings & Other People's Information
Account holders control what they photograph, record, and enter into the Service. Account holders are responsible for obtaining any consents required by law from persons who appear in photos or recordings, whose property is documented, or whose contact information is entered into the platform. If you believe your personal information was uploaded to SiteBrief without your consent, contact us at support@sitebriefapp.com and we will review and respond promptly.
10. Children's Privacy
SiteBrief is not directed to individuals under the age of 18, and we do not knowingly collect personal information from anyone under 18 (or under 13 for purposes of COPPA). If you believe a minor has provided us with personal information, contact us immediately and we will delete it.
11. International Users
SiteBrief is operated from the United States, and your information is processed and stored in the United States. If you access the Service from outside the U.S., you consent to the transfer of your information to the U.S., where privacy laws may differ from those in your jurisdiction.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email or in-app notification before they take effect where practicable, and will update the "Last Updated" date above. Continued use of SiteBrief after changes take effect constitutes acceptance of the updated policy.
13. Contact Us
For privacy-related questions or requests, contact:
SiteBrief LLC
5900 Balcones Drive, Ste 100
Austin, TX 78731
Email: support@sitebriefapp.com