JobRig

Privacy Policy

Effective date: 2026-08-28 · Version 1

JobRig ("the app") is a set of calculation tools for tradespeople, published by the developer ("we", "us"). This policy explains what data the app and the jobrig.app website do and do not handle. It is written to satisfy the Google Play and Apple App Store privacy requirements and the transparency duties of the GDPR (and it voluntarily follows the CCPA's standards), in plain language, because you should be able to read it.

What the app stores on your device

The app saves your settings and display preferences, for example whether you last used basic or advanced mode, light or dark theme, and degrees or percent slope. It saves a few housekeeping values, for example the date the app was first installed, a settings-format version number, and the answer to the update check described below. It saves your share and export preferences, meaning the format, units and options a new export starts from, and a set of one-time markers recording which first-run tips you have already been shown. It also keeps a few running counts of your own use, such as how many times the app has been opened and how many days you have used it. Those counts are only recorded while usage analytics is switched on, with one exception: a count of the days you have opened the app is kept whatever your analytics choice, so the app can wait until you have used it a few times before it offers you the chance to rate it in the store. That count is a number on your device and is never sent anywhere. All of this:

A few more things live on your device: your analytics consent choice and the date you gave it (settings like any other), and the random per-install identifiers used by crash reporting and usage analytics. Those identifiers are described in their own sections, and unlike everything above, an identifier travels with the report or event it marks. If your phone is offline when a crash report or a usage event is ready to send, it waits on your device and travels when you are next online. When you turn analytics off, anything still waiting is sent one last time and then cleared along with the identifier; if you are offline at that moment nothing is sent and the waiting events are cleared unsent. Events we have already received are kept for the period described under How long data is kept.

The app does not send your calculation values anywhere on its own. It does not store them either: the numbers you type live in the app's working memory while you use it, and they are gone when you close the app.

They leave your device only when you decide to share or save a drawing, and then only where you send them. Saving puts the image or PDF on your own device: on Android in a JobRig album in your gallery (images) or a folder you pick (PDFs), on iPhone in your photos (images) or through the share sheet (PDFs). Sharing hands the finished file straight to the app you choose, whose own privacy policy then applies. Either way it never passes through us, and the temporary working copy the app made is deleted right afterwards.

If you reset the app's settings, your preferences return to their defaults. Everything else described above, including your privacy choices, is kept, because none of it is a preference you chose.

Checking for a required update

When you open the app, JobRig asks our own website for one small file that lists which versions of the app are still supported. It is a plain download, the same kind your phone makes when it opens a web page: the app uploads nothing, there is no identifier in it, and it says nothing about you or about what you have calculated. What it does carry is what any web request carries, your address on the network and a line naming the app and its version. We use it to retire a version of the app that turns out to give wrong answers or to break a rule we have to follow, to know when to offer you the chance to rate the app in the store, and to carry the wording and the timings of the messages this section describes.

Because it is an ordinary internet request, your IP address reaches the website host that serves the file, in the same way it does when you visit any website, and is logged there in the ordinary course of delivering it (see Our website). We do not use those logs to identify anyone, and nothing about the request is stored with your device or joined to anything else.

If your phone is offline, or the file cannot be reached, nothing is sent, nothing happens on screen, and the app keeps working normally. It remembers the last answer, and the dates around it, on your device. The app does need to reach the file occasionally, though: if around six months pass with no successful check, it starts asking you to go online once, and if you still have not after a further two weeks it waits for a connection before it will open. It warns you before that point, and any single successful check clears it completely.

Why we are allowed to do this (GDPR legal basis): legitimate interest (Article 6(1)(f)): being able to withdraw a version of our own app that is giving people wrong measurements, being able to tell whether an installed copy is still one we can vouch for, and choosing a sensible moment to ask whether you would rate the app.

Crash reports

To fix problems, the app sends one kind of diagnostic: a crash report, sent when the app stops unexpectedly, or when a part of it stops working in a way we need to know about. If sharing or saving a drawing fails, it also sends a short fixed note saying which step failed and nothing more, so we can find out why. That note carries no image, no file, and none of your numbers. That channel reports nothing else. The other two things the app sends are described in their own sections: Checking for a required update, which uploads nothing at all, and Usage analytics, which only exists if you said yes to it.

A report contains the error details and technical information about the device and the app at the moment it happened, such as your device model, your operating-system version, the app version and similar diagnostic details, plus a random identifier created when the app is installed, an industry-standard way to count how many devices a bug affects. Reports are not built from what is on your screen: the numbers you type never go into one, and no screenshot or picture of the screen is ever attached. What a report carries instead is the technical description of the fault, written by software rather than taken from your work. Your IP address is used transiently to deliver the report over the internet (as with any internet request), and is not stored with the report.

Reports are processed for us by Sentry, our crash-reporting processor, with EU data residency. They are used solely to diagnose and fix bugs, are never sold, are never shared with anyone for their own use except where the law compels us to disclose them, and expire automatically (see How long data is kept). Sentry's own privacy terms are at sentry.io/privacy.

You can turn crash reports off at any time, in Settings, under Privacy, with the row called Crash reports. With it off, the app builds no reporting connection at all, so nothing is collected and nothing is sent from that device. Your choice is recorded on your device only, and it survives resetting the app's settings.

Why we are allowed to do this (GDPR legal basis): legitimate interest (Article 6(1)(f)): keeping a working app working. The balance is straightforward: the data is minimal, not linked to your identity, limited to technical fault details, and auto-expiring, so our interest in fixing bugs does not override your rights or freedoms. And you can switch it off, so our interest never has the last word.

Separately from all of the above, the app stores themselves give us reports about how the app behaves, such as crash logs and performance summaries that Apple and Google collect from the devices they run on. That collection is theirs, not ours: we do not choose what it gathers, we cannot switch it off on your behalf, and it is governed by Apple's and Google's own privacy policies rather than this one. What reaches us is diagnostics about the app, never anything that identifies you.

Usage analytics (only if you say yes)

To improve the app, we ask whether we may collect usage information that is not linked to your identity: which features you tap, the settings you choose, how you move through the app, how long things take, and coarse metadata about the numbers you work with, such as how many digits a number has or which fraction denominator you picked, but never the measurements themselves. What "asking" means here:

Analytics are processed for us by PostHog as our processor; see posthog.com/privacy. Legal basis: consent (GDPR Article 6(1)(a)), and withdrawing it is as easy as giving it.

What the app does not do

The app does not:

Permissions

The app requests these permissions:

The app also has standard system capabilities that never prompt you: internet access (used to fetch the supported-versions file, to deliver crash reports and, if you consented, usage events; see Checking for a required update, Crash reports and Usage analytics), a check of whether the device is currently online, and keeping the screen awake (used only while the keep-screen-awake setting is on; it touches no data). A few more are declared by the software libraries the app is built on rather than by us, and belong to the app's own internal plumbing rather than to anything it asks of you. None of them is used to read what you type.

When you email us

If you write to support@jobrig.app, we receive your email address, whatever you choose to put in the message, and anything you attach, which for a support request is often a screenshot. Today that is the only way information capable of identifying you reaches us, and it reaches us because you sent it, not because the app collected it. We use it to answer you and to fix what you reported, and for nothing else.

Your message takes the ordinary route email takes. It is forwarded by the company that hosts our website, and it then sits in a mailbox run by a mail provider, where the developer is the only person who reads it, until it is deleted (see How long data is kept).

Why we are allowed to do this (GDPR legal basis): legitimate interest (Article 6(1)(f)): answering someone who has written to us for help.

Your rights

If you are in the EU/EEA or UK (GDPR): you have the rights of access, rectification, erasure, restriction, objection, and portability, and the right to withdraw any consent at any time (usage analytics is currently the only consent-based thing here; withdrawing is the Analytics row in Settings, under Privacy, and takes effect immediately). To exercise any of them, email us (see Contact). One honest caveat: because nothing we receive is linked to your identity, we usually cannot connect any report or event to you, and the GDPR (Article 11) says we do not have to collect extra data about you just to be able to. If we cannot act on a request for that reason, we will say so plainly. You can also complain to us directly, at support@jobrig.app, and we will look into it and tell you what we found. You always have the right to complain to a supervisory authority as well: your national data-protection authority in the EU/UK, or the Privacy Protection Authority in Israel.

Right to object, specifically: more than one thing here runs on our legitimate interest rather than on your consent, and GDPR Article 21 gives you the right to object to each of them. Crash reporting you can stop yourself, without writing to us: the Crash reports row in Settings, under Privacy, stops it on that device immediately and completely. One thing changes with it: if the app ever breaks in front of you, the error screen no longer says a report was sent, because none was. If you have written to us, we stop handling your message when you stop writing to us. The update check is the one with no switch, and the honest answer is the plain one: it uploads nothing about you, and the only way to stop it is to stop using the app. The website is the same, because a page cannot be sent to you without an address to send it to.

If you are in California (CCPA/CPRA): as with everyone, everywhere, we do not sell personal information and do not share it for cross-context behavioral advertising (as the CCPA defines those terms), and never have; we restate it here voluntarily, in California's own words. You have the rights to know, correct, and delete; the honest limit described under the GDPR paragraph above applies here too: we usually cannot tell which installation is yours, and California law does not require us to collect more information just to reidentify you. We will never discriminate against you for exercising any privacy right.

If you are in Israel (Privacy Protection Law): the developer is based in Israel, so Israeli law applies to us directly. You have the right to ask what information about you we hold, to ask us to correct it if it is wrong or out of date, and to ask us to delete it. The honest limit described under the GDPR paragraph above applies here too. Ask us at support@jobrig.app. You can also complain to the Privacy Protection Authority.

Everyone, everywhere: the same privacy standard applies. JobRig is available in almost every country, and many of them have privacy laws of their own. We have not written a separate section for each, because we do not apply a lower privacy standard depending on where you opened it. If your local law gives you a right this policy does not name, write to us: we will honour it where it applies to you and where the law in question gives it to you, and if we cannot, we will say so plainly and tell you why.

How long data is kept

International transfers

Crash reports are ingested and stored in the European Union. Sentry is operated by a US company, so limited access from outside the EU can occur in operating the service; that processing is governed by a data-processing agreement incorporating the EU Standard Contractual Clauses (with the UK Addendum for UK users). Usage events (only if you consented) are stored in the European Union too, on PostHog's EU cloud; PostHog is also operated by a US company, and its own DPA carries the same clauses and the same addendum. Cloudflare, which serves the jobrig.app website and logs the IP address behind each request in the ordinary course of doing so, whether it comes from a browser visiting the site or from the app downloading the supported-versions file (see Our website and Checking for a required update), handles that data under its own data-processing addendum, which its standard terms incorporate wherever European personal data is involved. We are based in Israel, a country the European Commission currently recognizes as providing adequate data protection.

Mail sent to support@jobrig.app may be stored outside the European Union, on the mail provider's servers.

The Standard Contractual Clauses named above are the European Commission's published standard text, so anyone can read them in full. If you want to know which safeguards cover a particular transfer, email support@jobrig.app and we will tell you.

Children's privacy

JobRig is a work tool and is not directed at children under 13. If where you live sets a higher minimum age for agreeing to this kind of data collection on your own, our terms ask you to use JobRig with a parent's or guardian's consent. That applies in particular to Usage analytics, which is the one thing here that runs on your agreement: if you are under that age, please leave it switched off unless a parent or guardian says otherwise. Nothing else in the app depends on it, and declining changes nothing. Beyond the limited data described above (which is about how the app is used, not about who is using it), we do not knowingly collect personal data from anyone, including children: the app has no accounts and no messaging. If you are a parent or guardian and believe a child has somehow sent us personal data, contact us and we will delete whatever we can identify.

Our website (jobrig.app)

The website is a static informational site: we put no cookies, no analytics, and no tracking on it, and it has no sign-in or data-entry forms, so the site itself collects nothing about you, by design. It is hosted by Cloudflare, whose infrastructure logs visitor IP addresses and standard browser error reports in the ordinary course of serving any website (for security and delivery), as every web host does. We use Cloudflare only to serve the site and do not use those logs to identify visitors. Cloudflare acts as our processor for the site; its privacy policy is at cloudflare.com/privacypolicy. Why this is allowed (GDPR legal basis): legitimate interest (Article 6(1)(f)): securely delivering the site, the same routine logging every web host performs. These logs are kept by Cloudflare under its own short retention schedule for security operations; we never receive, store, or use them ourselves.

Security

Today, there is no JobRig server, no user database, and no account system. The little that can travel (the crash reports and, only with your consent, the usage events) is encrypted in transit (HTTPS/TLS), minimized by design, and handled by reputable processors under data-processing agreements. No system is perfectly secure, but there is very little here to attack. If a security incident ever affected the limited data described here, we would act promptly to contain it, tell the relevant authorities where the law requires, and, where the law requires telling you, tell you the same way we announce a change to this policy (see Changes to this policy), and on our store listings.

If you believe you have found a security problem in the app or on the website, please tell us at support@jobrig.app and we will look into it.

Who processes data for us

Each is bound by a written agreement that requires it to handle the data only on our documented instructions, to keep it confidential and to protect it with appropriate security measures, and not to use it for its own marketing or advertising. PostHog's agreement also bars PostHog and the companies it uses from using the data to train or develop AI models.

No one else, apart from the providers that carry email to us, and except where the law compels us to disclose something. If this list ever grows, this policy changes first (see Changes).

If JobRig is ever taken over by someone else, or moves into a company, the data described here would move with the app so it keeps working. That is a change of who runs JobRig, not a sale of your data: we do not sell it now and a handover is not a way around that. You would be told through this policy first, on the same terms as any other material change (see Changes).

Changes to this policy

If anything material changes (what data is handled, why, or by whom), this policy will be updated with a new effective date before the change ships, and the store privacy declarations will be updated to match. The published page at jobrig.app/privacy carries that new date, and that date is the notice; where a change is significant enough to need saying out loud, the app also shows you a notice the next time you open it after the update that carries it. Minor clarifications that do not change substance may be made at any time.

Who is responsible for your data

The data controller for JobRig and jobrig.app is Raz Sharabi, an individual developer based in Israel, who is also the person responsible for protecting personal data here and can be reached at support@jobrig.app.

Contact

Questions or requests about this policy: support@jobrig.app