Privacy Policy
Effective date: 2026-08-28 · Version 1
JobRig ("the app") is a set of calculation tools for tradespeople, published by the developer ("we", "us"). This policy explains what data the app and the jobrig.app website do and do not handle. It is written to satisfy the Google Play and Apple App Store privacy requirements and the transparency duties of the GDPR (and it voluntarily follows the CCPA's standards), in plain language, because you should be able to read it.
What the app stores on your device
The app saves your settings and display preferences, for example whether you last used basic or advanced mode, light or dark theme, and degrees or percent slope. It saves a few housekeeping values, for example the date the app was first installed, a settings-format version number, and the answer to the update check described below. It saves your share and export preferences, meaning the format, units and options a new export starts from, and a set of one-time markers recording which first-run tips you have already been shown. It also keeps a few running counts of your own use, such as how many times the app has been opened and how many days you have used it. Those counts are only recorded while usage analytics is switched on, with one exception: a count of the days you have opened the app is kept whatever your analytics choice, so the app can wait until you have used it a few times before it offers you the chance to rate it in the store. That count is a number on your device and is never sent anywhere. All of this:
- is stored locally, using the device's standard app storage, and stays on your device, except as described under Usage analytics: on Android the app opts out of Google device backups entirely; on iOS a copy may exist inside your own device backup (iCloud or local), which only you control,
- contains no personal information, and
- is removed when you uninstall the app (on iOS, a copy may persist inside your own backup until that backup rotates).
A few more things live on your device: your analytics consent choice and the date you gave it (settings like any other), and the random per-install identifiers used by crash reporting and usage analytics. Those identifiers are described in their own sections, and unlike everything above, an identifier travels with the report or event it marks. If your phone is offline when a crash report or a usage event is ready to send, it waits on your device and travels when you are next online. When you turn analytics off, anything still waiting is sent one last time and then cleared along with the identifier; if you are offline at that moment nothing is sent and the waiting events are cleared unsent. Events we have already received are kept for the period described under How long data is kept.
The app does not send your calculation values anywhere on its own. It does not store them either: the numbers you type live in the app's working memory while you use it, and they are gone when you close the app.
They leave your device only when you decide to share or save a drawing, and then only where you send them. Saving puts the image or PDF on your own device: on Android in a JobRig album in your gallery (images) or a folder you pick (PDFs), on iPhone in your photos (images) or through the share sheet (PDFs). Sharing hands the finished file straight to the app you choose, whose own privacy policy then applies. Either way it never passes through us, and the temporary working copy the app made is deleted right afterwards.
If you reset the app's settings, your preferences return to their defaults. Everything else described above, including your privacy choices, is kept, because none of it is a preference you chose.
Checking for a required update
When you open the app, JobRig asks our own website for one small file that lists which versions of the app are still supported. It is a plain download, the same kind your phone makes when it opens a web page: the app uploads nothing, there is no identifier in it, and it says nothing about you or about what you have calculated. What it does carry is what any web request carries, your address on the network and a line naming the app and its version. We use it to retire a version of the app that turns out to give wrong answers or to break a rule we have to follow, to know when to offer you the chance to rate the app in the store, and to carry the wording and the timings of the messages this section describes.
Because it is an ordinary internet request, your IP address reaches the website host that serves the file, in the same way it does when you visit any website, and is logged there in the ordinary course of delivering it (see Our website). We do not use those logs to identify anyone, and nothing about the request is stored with your device or joined to anything else.
If your phone is offline, or the file cannot be reached, nothing is sent, nothing happens on screen, and the app keeps working normally. It remembers the last answer, and the dates around it, on your device. The app does need to reach the file occasionally, though: if around six months pass with no successful check, it starts asking you to go online once, and if you still have not after a further two weeks it waits for a connection before it will open. It warns you before that point, and any single successful check clears it completely.
Why we are allowed to do this (GDPR legal basis): legitimate interest (Article 6(1)(f)): being able to withdraw a version of our own app that is giving people wrong measurements, being able to tell whether an installed copy is still one we can vouch for, and choosing a sensible moment to ask whether you would rate the app.
Crash reports
To fix problems, the app sends one kind of diagnostic: a crash report, sent when the app stops unexpectedly, or when a part of it stops working in a way we need to know about. If sharing or saving a drawing fails, it also sends a short fixed note saying which step failed and nothing more, so we can find out why. That note carries no image, no file, and none of your numbers. That channel reports nothing else. The other two things the app sends are described in their own sections: Checking for a required update, which uploads nothing at all, and Usage analytics, which only exists if you said yes to it.
A report contains the error details and technical information about the device and the app at the moment it happened, such as your device model, your operating-system version, the app version and similar diagnostic details, plus a random identifier created when the app is installed, an industry-standard way to count how many devices a bug affects. Reports are not built from what is on your screen: the numbers you type never go into one, and no screenshot or picture of the screen is ever attached. What a report carries instead is the technical description of the fault, written by software rather than taken from your work. Your IP address is used transiently to deliver the report over the internet (as with any internet request), and is not stored with the report.
Reports are processed for us by Sentry, our crash-reporting processor, with EU data residency. They are used solely to diagnose and fix bugs, are never sold, are never shared with anyone for their own use except where the law compels us to disclose them, and expire automatically (see How long data is kept). Sentry's own privacy terms are at sentry.io/privacy.
You can turn crash reports off at any time, in Settings, under Privacy, with the row called Crash reports. With it off, the app builds no reporting connection at all, so nothing is collected and nothing is sent from that device. Your choice is recorded on your device only, and it survives resetting the app's settings.
Why we are allowed to do this (GDPR legal basis): legitimate interest (Article 6(1)(f)): keeping a working app working. The balance is straightforward: the data is minimal, not linked to your identity, limited to technical fault details, and auto-expiring, so our interest in fixing bugs does not override your rights or freedoms. And you can switch it off, so our interest never has the last word.
Separately from all of the above, the app stores themselves give us reports about how the app behaves, such as crash logs and performance summaries that Apple and Google collect from the devices they run on. That collection is theirs, not ours: we do not choose what it gathers, we cannot switch it off on your behalf, and it is governed by Apple's and Google's own privacy policies rather than this one. What reaches us is diagnostics about the app, never anything that identifies you.
Usage analytics (only if you say yes)
To improve the app, we ask whether we may collect usage information that is not linked to your identity: which features you tap, the settings you choose, how you move through the app, how long things take, and coarse metadata about the numbers you work with, such as how many digits a number has or which fraction denominator you picked, but never the measurements themselves. What "asking" means here:
- Freely given. It is a real question: nothing is pre-ticked, and declining never blocks or limits the app in any way.
- Withdrawable. You can turn analytics off at any time in Settings, under Privacy, with the row called Analytics; it takes effect immediately. Switching it off is itself recorded and sent, as the last usage event that installation sends unless you turn analytics back on, so that we can tell a withdrawal from a device that simply stopped being used; switching it back on is recorded the same way.
- No values. Events never contain your measurements: not the numbers you type, and not the answers the app works out for you. What they do contain includes feature names, the options you have chosen, counts, coarse descriptions (for example a rough band for how steep a triangle is), how long things took, and a handful of technical fields that let us put the events back in order and know which version of our own event format they were written in. They also carry a random per-install identifier of their own: the same kind crash reports use, but a separate one, and the two datasets share no key. It exists so we can count devices, not identify people. Each event also carries the same technical device context as a crash report, plus your screen size, and your language, region and time zone settings, which are read from the phone's own settings and say how the phone is set up rather than where it is. Once per session it also carries a few coarse characteristics of the device itself, such as a rough memory band, roughly how old the model is, and how long the app took to start.
- Not linked to you, rather than anonymous. Because that per-install identifier stays the same until you switch analytics off or uninstall the app, events from one installation can be grouped together, so calling them anonymous would overstate it (switching analytics off deletes the identifier from your device, and a fresh one is created only if you ever switch it back on). We hold nothing that names you, and nothing that lets us reach you.
- Screenshots, on iPhone and iPad only. If you take a screenshot while you are on a calculator screen, we record that it happened, whether an answer was on screen at the time, and the mode and units you were working in. Never the image, never what was on it. Apple's system tells the app that a screenshot was taken; it does not hand the app the picture.
- No means no. If you decline, that choice is recorded on your device only, and while you have declined nothing is sent from that installation: with no consent on record the app does not even start the analytics software, so there is nothing to send and nowhere to send it from. Crash reports are separate and have their own switch, described under Crash reports.
- Looking back. If you do say yes, the first events include a short summary of the setup you just went through, such as which options you chose along the way, and the app opening you were in when you said yes. The same holds if you never answered the question and switch analytics on in Settings later: the opening you were in then is what travels. Nothing is sent while the question is unanswered; it is gathered on your device and only travels once you have said yes. If you declined and later changed your mind, nothing recorded before that is released.
- Your IP address, like any internet request, is used to deliver each event. It is also read once, as the event arrives, to work out which country you are in, and is then discarded rather than stored. The country is the only thing kept from it: not your city, not your region, not coordinates, and not the address itself. We use it to see which countries the app is used in.
Analytics are processed for us by PostHog as our processor; see posthog.com/privacy. Legal basis: consent (GDPR Article 6(1)(a)), and withdrawing it is as easy as giving it.
What the app does not do
The app does not:
- collect your name, email, phone number, or anything that identifies you as a person (the random per-install identifier used by crash reporting, described under Crash reports, is not tied to your name or account; if you write to us yourself, see When you email us);
- read or access your contacts, photos, microphone, or camera. Saving a drawing is the one place photos come up, and it is add-only, described under Permissions;
- ask your phone where it is. The app requests no location permission, uses no location service, and reads no satellite, Wi-Fi or cell-tower position, so it never learns where you are from your device. The one piece of geography we do see is the country, worked out from the internet address your phone already uses to reach us and described under Usage analytics. That country is why the app stores list location as something the app collects;
- track you for advertising: the app reads no advertising identifier on either platform, contains no advertising or ad-measurement code, and belongs to no ad network. Nothing it collects is ever used to profile you or follow you across apps or sites. Usage analytics, if you said yes to it, is a separate thing and is described under Usage analytics;
- feed your data to artificial intelligence: the app has no AI features, and we never use crash reports or usage events to train an AI model, ours or anyone else's.
Permissions
The app requests these permissions:
- Vibrate: used only to provide haptic feedback (a small vibration) when you tap keys and buttons. It accesses no data.
- Add to Photos (iPhone only, and only if you save a drawing as an image): used only to add the image you asked to save to your photos. It is the add-only permission, so the app cannot read, scan, or open your existing photos, and nothing leaves your device. Saving as a PDF uses no photo permission at all; it goes through the share sheet. On Android the app asks for no photo permission of any kind.
The app also has standard system capabilities that never prompt you: internet access (used to fetch the supported-versions file, to deliver crash reports and, if you consented, usage events; see Checking for a required update, Crash reports and Usage analytics), a check of whether the device is currently online, and keeping the screen awake (used only while the keep-screen-awake setting is on; it touches no data). A few more are declared by the software libraries the app is built on rather than by us, and belong to the app's own internal plumbing rather than to anything it asks of you. None of them is used to read what you type.
When you email us
If you write to support@jobrig.app, we receive your email address, whatever you choose to put in the message, and anything you attach, which for a support request is often a screenshot. Today that is the only way information capable of identifying you reaches us, and it reaches us because you sent it, not because the app collected it. We use it to answer you and to fix what you reported, and for nothing else.
Your message takes the ordinary route email takes. It is forwarded by the company that hosts our website, and it then sits in a mailbox run by a mail provider, where the developer is the only person who reads it, until it is deleted (see How long data is kept).
Why we are allowed to do this (GDPR legal basis): legitimate interest (Article 6(1)(f)): answering someone who has written to us for help.
Your rights
If you are in the EU/EEA or UK (GDPR): you have the rights of access, rectification, erasure, restriction, objection, and portability, and the right to withdraw any consent at any time (usage analytics is currently the only consent-based thing here; withdrawing is the Analytics row in Settings, under Privacy, and takes effect immediately). To exercise any of them, email us (see Contact). One honest caveat: because nothing we receive is linked to your identity, we usually cannot connect any report or event to you, and the GDPR (Article 11) says we do not have to collect extra data about you just to be able to. If we cannot act on a request for that reason, we will say so plainly. You can also complain to us directly, at support@jobrig.app, and we will look into it and tell you what we found. You always have the right to complain to a supervisory authority as well: your national data-protection authority in the EU/UK, or the Privacy Protection Authority in Israel.
Right to object, specifically: more than one thing here runs on our legitimate interest rather than on your consent, and GDPR Article 21 gives you the right to object to each of them. Crash reporting you can stop yourself, without writing to us: the Crash reports row in Settings, under Privacy, stops it on that device immediately and completely. One thing changes with it: if the app ever breaks in front of you, the error screen no longer says a report was sent, because none was. If you have written to us, we stop handling your message when you stop writing to us. The update check is the one with no switch, and the honest answer is the plain one: it uploads nothing about you, and the only way to stop it is to stop using the app. The website is the same, because a page cannot be sent to you without an address to send it to.
If you are in California (CCPA/CPRA): as with everyone, everywhere, we do not sell personal information and do not share it for cross-context behavioral advertising (as the CCPA defines those terms), and never have; we restate it here voluntarily, in California's own words. You have the rights to know, correct, and delete; the honest limit described under the GDPR paragraph above applies here too: we usually cannot tell which installation is yours, and California law does not require us to collect more information just to reidentify you. We will never discriminate against you for exercising any privacy right.
If you are in Israel (Privacy Protection Law): the developer is based in Israel, so Israeli law applies to us directly. You have the right to ask what information about you we hold, to ask us to correct it if it is wrong or out of date, and to ask us to delete it. The honest limit described under the GDPR paragraph above applies here too. Ask us at support@jobrig.app. You can also complain to the Privacy Protection Authority.
Everyone, everywhere: the same privacy standard applies. JobRig is available in almost every country, and many of them have privacy laws of their own. We have not written a separate section for each, because we do not apply a lower privacy standard depending on where you opened it. If your local law gives you a right this policy does not name, write to us: we will honour it where it applies to you and where the law in question gives it to you, and if we cannot, we will say so plainly and tell you why.
How long data is kept
- Crash reports: set to expire on Sentry's servers after about 90 days (Sentry's current setting).
- Usage events (only if you consented): kept on PostHog's EU servers for about one year (PostHog's current setting). Your consent choice itself is stored on your device only.
- Emails you send us: kept while we deal with your question and for a short while afterwards, then deleted. Until then they sit in the mailbox described under When you email us. They are never added to any mailing list.
- What stays on your device: everything listed under What the app stores on your device, plus your privacy choices. All of it until you uninstall the app.
International transfers
Crash reports are ingested and stored in the European Union. Sentry is operated by a US company, so limited access from outside the EU can occur in operating the service; that processing is governed by a data-processing agreement incorporating the EU Standard Contractual Clauses (with the UK Addendum for UK users). Usage events (only if you consented) are stored in the European Union too, on PostHog's EU cloud; PostHog is also operated by a US company, and its own DPA carries the same clauses and the same addendum. Cloudflare, which serves the jobrig.app website and logs the IP address behind each request in the ordinary course of doing so, whether it comes from a browser visiting the site or from the app downloading the supported-versions file (see Our website and Checking for a required update), handles that data under its own data-processing addendum, which its standard terms incorporate wherever European personal data is involved. We are based in Israel, a country the European Commission currently recognizes as providing adequate data protection.
Mail sent to support@jobrig.app may be stored outside the European Union, on the mail provider's servers.
The Standard Contractual Clauses named above are the European Commission's published standard text, so anyone can read them in full. If you want to know which safeguards cover a particular transfer, email support@jobrig.app and we will tell you.
Children's privacy
JobRig is a work tool and is not directed at children under 13. If where you live sets a higher minimum age for agreeing to this kind of data collection on your own, our terms ask you to use JobRig with a parent's or guardian's consent. That applies in particular to Usage analytics, which is the one thing here that runs on your agreement: if you are under that age, please leave it switched off unless a parent or guardian says otherwise. Nothing else in the app depends on it, and declining changes nothing. Beyond the limited data described above (which is about how the app is used, not about who is using it), we do not knowingly collect personal data from anyone, including children: the app has no accounts and no messaging. If you are a parent or guardian and believe a child has somehow sent us personal data, contact us and we will delete whatever we can identify.
Our website (jobrig.app)
The website is a static informational site: we put no cookies, no analytics, and no tracking on it, and it has no sign-in or data-entry forms, so the site itself collects nothing about you, by design. It is hosted by Cloudflare, whose infrastructure logs visitor IP addresses and standard browser error reports in the ordinary course of serving any website (for security and delivery), as every web host does. We use Cloudflare only to serve the site and do not use those logs to identify visitors. Cloudflare acts as our processor for the site; its privacy policy is at cloudflare.com/privacypolicy. Why this is allowed (GDPR legal basis): legitimate interest (Article 6(1)(f)): securely delivering the site, the same routine logging every web host performs. These logs are kept by Cloudflare under its own short retention schedule for security operations; we never receive, store, or use them ourselves.
Security
Today, there is no JobRig server, no user database, and no account system. The little that can travel (the crash reports and, only with your consent, the usage events) is encrypted in transit (HTTPS/TLS), minimized by design, and handled by reputable processors under data-processing agreements. No system is perfectly secure, but there is very little here to attack. If a security incident ever affected the limited data described here, we would act promptly to contain it, tell the relevant authorities where the law requires, and, where the law requires telling you, tell you the same way we announce a change to this policy (see Changes to this policy), and on our store listings.
If you believe you have found a security problem in the app or on the website, please tell us at support@jobrig.app and we will look into it.
Who processes data for us
- Sentry receives and stores the crash reports (EU data residency).
- PostHog receives and stores the usage events, only if you consented (EU cloud hosting).
- Cloudflare hosts the jobrig.app website, including the supported-versions file the app downloads when it opens (a global network, with standard infrastructure logs), and forwards mail sent to support@jobrig.app.
Each is bound by a written agreement that requires it to handle the data only on our documented instructions, to keep it confidential and to protect it with appropriate security measures, and not to use it for its own marketing or advertising. PostHog's agreement also bars PostHog and the companies it uses from using the data to train or develop AI models.
No one else, apart from the providers that carry email to us, and except where the law compels us to disclose something. If this list ever grows, this policy changes first (see Changes).
If JobRig is ever taken over by someone else, or moves into a company, the data described here would move with the app so it keeps working. That is a change of who runs JobRig, not a sale of your data: we do not sell it now and a handover is not a way around that. You would be told through this policy first, on the same terms as any other material change (see Changes).
Changes to this policy
If anything material changes (what data is handled, why, or by whom), this policy will be updated with a new effective date before the change ships, and the store privacy declarations will be updated to match. The published page at jobrig.app/privacy carries that new date, and that date is the notice; where a change is significant enough to need saying out loud, the app also shows you a notice the next time you open it after the update that carries it. Minor clarifications that do not change substance may be made at any time.
Who is responsible for your data
The data controller for JobRig and jobrig.app is Raz Sharabi, an individual developer based in Israel, who is also the person responsible for protecting personal data here and can be reached at support@jobrig.app.
Contact
Questions or requests about this policy: support@jobrig.app
