FiberScan

Legal

Privacy policy

Last updated — 2026-08-15

FiberScan (“the app”) is a professional asbestos survey and reporting tool published by Ingenio Productions LLC (“we”, “us”). This policy explains what data the app handles, why, and your choices. We collect the minimum needed to run the app and never sell your data.

1. Using the app without an account

FiberScan is offline-first. You can create surveys, capture photos, score findings, and generate reports entirely on your device without an account. Your survey data — sites, findings, photos, floor plans and any GPS coordinates you attach — stays in local storage on your device. We never receive it unless you have a Professional subscription and are signed in (section 2), or you share a report yourself.

We do not send diagnostics unless you switch them on. Neither crash reports nor usage analytics are reported to us unless you enable Share usage & crash reports. We ask you once, on the last screen of first-time setup, with a plain Not now alongside it — declining takes you into the app exactly as accepting does, and nothing about the app behaves differently afterwards. Skipping setup altogether counts as declining. The same switch lives in Settings → Theme thereafter; it is off until you turn it on, switching it back off takes effect immediately, and it sits outside the account section on purpose so it is reachable whether or not you have an account.

There is one exception, at the moment the app starts. Firebase Crashlytics begins collecting as soon as the app process launches — before the app has read your preference — and we deliberately do not suppress it at that point, because a crash during startup on a real phone is precisely the fault we would otherwise never see. If the app fails in that window a report can be created. Once startup finishes and your preference is applied, we switch collection off and delete anything still waiting to be sent, and it stays off from then on.

Once you have turned it on, two channels can send, and you can control them individually in Settings → About → Diagnostics:

  • Crash reports — included as soon as you opt in. If the app crashes, Firebase Crashlytics sends the stack trace, your device model and OS version, and an identifier for this installation of the app. It is not linked to your account or to your name, and it never contains survey content, photos, client names or site addresses. It is the only way we find faults that happen on a phone on a site and never in testing. Turn it off — either switch will do it — and we also delete any reports still waiting to be sent.
  • Usage analytics — still off until you also enable it. Firebase Analytics can count app opens and which screens get used. It stays off even after you grant the master consent, until you switch it on in Settings → About → Diagnostics; turning it back off resets the analytics identifier as well as stopping collection.

Neither channel is anonymous, and we would rather say so: both are keyed to a device-scoped Firebase app-instance identifier. That identifier is why they are opt-in rather than on by default.

Separately, Firebase’s messaging SDK registers a push token for this installation of the app when the app starts, before you are asked about notifications and whether or not you have an account. The token identifies the app installation, not you. We only store it against an account if you are signed in, and it is removed when you sign out or delete your account.

2. Data we process when you sign in or subscribe

Data When Why Where
Your email address and an account identifier. A name only if you sign in with Apple or Google and that provider gives us one — we never ask you for a name, and signing up with an email and password does not collect one. Firebase Authentication also records whether your email is verified, which sign-in methods you have used, and when you created the account and last signed in. If you sign up with a password, Firebase holds it in hashed form and we never see it. If you create an account / sign in (email & password, Sign in with Apple, or Google) Authenticate you and follow your Professional subscription across devices Firebase Authentication (Google LLC)
Surveys and findings, including the site address of the building you surveyed, photos, floor plans and any GPS coordinates you attached While you have a Professional subscription and are signed in Sync your work between your devices and back it up Cloud Firestore & Firebase Storage, scoped to users/{your-id}/…
Your professional profile: inspector name, certification or licence number and its expiry date, company name, company address, phone number, email, accreditation body, laboratory name and address, report disclaimer, and your company logo image While you have a Professional subscription and are signed in Restore your report letterhead and your report defaults — region and regulatory framework, survey type, units, sample numbering, laboratory turnaround and accreditation, custom materials and accent colour — on your other devices Cloud Firestore, scoped to users/{your-id}/…
Push notification token and platform Only if you enable reinspection reminders Deliver reinspection reminder notifications to this app install Cloud Firestore & Firebase Cloud Messaging
Purchase / subscription entitlement, keyed to your account identifier If you buy a Professional subscription Unlock and verify paid features across your devices RevenueCat, Inc. and the Apple App Store
Crash reports and usage analytics, linked to a device-scoped identifier (the Firebase app-instance ID) rather than to your account Only if you switch on “Share usage & crash reports” in Settings → Theme — off by default. See section 1 Diagnose faults; understand which parts of the app earn their place. Never includes survey data, photos, client names or site addresses Firebase Crashlytics & Analytics

There is no separate “cloud sync” switch, and signing out is the off switch. While you are signed in with an active Professional subscription your surveys and profile sync; sign out and nothing further leaves the device. If your subscription lapses, syncing stops, but anything already backed up stays until you delete your account (section 9).

Each survey keeps its own change log, and every entry records who made the change. That is your name if we have one, otherwise your email address, otherwise the inspector name set in the app. It is stored inside the survey, so it travels with that survey wherever you export, share or sync it.

If you used an earlier version that registered your devices, your account may still hold legacy device records — a device identifier, device name and platform. Nothing writes them any more. They are included in the copy of your data you can ask for, and they are erased when you delete your account. Where such a record was revoked, it is swept 12 months after revocation.

Some of what you upload is other people’s data — most obviously the address of the building you surveyed and photographs of its interior. You are responsible for having a basis to collect it; we hold it for you and act on your instructions. If you need a data processing agreement for your clients, ask us.

Two different things are described above, and they are ours in different ways. The account we issue you — sign-in details, subscription entitlement, diagnostics — exists so that we can run the service, so we decide what is needed and we answer for it. The survey content you capture is not ours in that sense: you decide what goes into it and why, and we store, sync and delete it on your instructions and for no purpose of our own. We do not read your surveys, mine them, use them to improve the app, or train anything on them.

This matters for one practical reason. If a client asks who is accountable for the photographs and addresses in a survey you carried out, the answer is you — we are holding them for you. Ask us and we will put that in writing as a data processing agreement you can give them.

3. Camera, photos, location, and room scanning

The app requests camera access to photograph suspected materials and to measure runs and areas in AR; photo library access to pick a company logo, import floor-plan images, and save generated reports; and location to attach GPS coordinates to surveyed areas. Each is used only for the stated purpose, only when you trigger it, and you can decline or revoke any in iOS Settings.

On supported iPhones and iPads the app can also scan a room to produce a to-scale floor plan. What this captures is dimensioned interior geometry of the building you are in — the positions and lengths of walls, doors and windows, in metres. No 3D mesh, no textured model, and no camera imagery from the scan is stored or leaves the app: only those measurements become part of the floor plan, which is then treated exactly like the rest of the survey (on-device unless you are a signed-in subscriber).

4. Why we are allowed to process it

If you are in the UK or the EEA, the UK GDPR / GDPR requires us to tell you our lawful basis for each purpose.

Purpose Lawful basis Your control
Running your account, syncing and backing up your surveys and profile Performance of a contract (Art. 6(1)(b)) Sign out, or delete your account
Verifying your subscription entitlement Performance of a contract (Art. 6(1)(b)) Cancel through the App Store
Keeping legacy device records until they are swept Legitimate interests (Art. 6(1)(f)) — protecting a paid service from abuse Object using the contact below, or delete your account
Reinspection reminders Performance of a contract (Art. 6(1)(b)); permission to send notifications is separately consented in iOS Turn reminders off in the app, or revoke notifications in iOS Settings
Crash reporting Consent (Art. 6(1)(a)) — keeping the app working on real devices Not reported unless you turn it on, subject to the launch-window exception in section 1; withdraw at any time with either the master switch in Settings → Theme or the channel switch in Settings → About → Diagnostics
Usage analytics Consent (Art. 6(1)(a)) Off unless you turn it on; withdraw at any time in Settings → About → Diagnostics, with no effect on anything else
Security, abuse prevention and service logs Legitimate interests (Art. 6(1)(f)) — keeping the service secure and available Object using the contact below

Crash reporting and the push token both involve storing an identifier on your device, so UK and EU rules on terminal equipment apply to them as well. The switch described in section 1 is how you object, and it costs nothing and changes nothing else about the app.

5. Who else processes your data, and sharing

Provider Role Where processed
Google LLC (Firebase Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, Crashlytics, Analytics) Hosting your account, synced surveys, photos, push notifications and diagnostics United States
RevenueCat, Inc. Subscription entitlement — receives your account identifier and your purchase history United States
Apple Inc. App Store delivery, payment processing, Sign in with Apple United States and Apple’s regional infrastructure

We do not sell your data and we do not share it for advertising. We share it only with the processors listed above — Google/Firebase, RevenueCat and Apple — to provide the service, and where the law requires it. Each of these providers is bound by its agreement with us to protect your data to at least the same standard this policy describes. Reports you generate are shared only by you, via the destinations you choose (email, AirDrop, and so on).

6. International transfers

Your data is processed in the United States. Firebase Authentication operates globally; our Cloud Firestore data and Cloud Functions are hosted in the United States (us-central1). We do not offer UK or EU data residency, and we would rather say so than imply otherwise: moving one database would not move authentication, diagnostics or subscription processing. Where your data is transferred outside the UK/EEA it is protected by the transfer terms in each provider’s published data processing addendum — the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, entered into with Google LLC and RevenueCat, Inc. Contact us for a copy of the relevant safeguards.

7. Payments

Subscriptions are processed by Apple. We never see or store your payment card details. Subscription status is managed through RevenueCat and Apple. Deleting your FiberScan account does not cancel an App Store subscription — cancel that through the App Store.

8. How long we keep it

  • On your device: until you delete it in the app, use Delete App Data, or remove the app.
  • In the cloud: for as long as your account exists. Deleting your account erases it, and it rolls out of our providers’ backups within 30 days. We do not currently delete inactive accounts automatically. If we introduce a retention period for dormant accounts we will publish it here and give notice before anything is deleted.
  • Deletion markers (the record that a survey was deleted, kept so another of your devices cannot restore it): 12 months. Any legacy device record left by the retired device registry is swept 12 months after it was revoked, and in every case when you delete your account.
  • Push tokens: 90 days after last use, or immediately when you sign out or delete your account.
  • Crash reports: held by Crashlytics for up to 90 days.
  • Usage analytics: held by Firebase Analytics for up to 14 months. Switching the toggle off stops further collection.
  • Service logs, including the IP addresses seen by Firebase Authentication and Cloud Functions: up to 30 days.

The diagnostics and service-log periods above are our providers’ retention periods. We do not extend them, and because those records are keyed to a device-scoped identifier rather than to your account, we cannot single yours out of them.

8A. How we protect your data

We would rather state this precisely than reassuringly, so this section says what is actually true of the app as built.

  • In transit. Everything the app sends to us travels over HTTPS/TLS. There is no unencrypted network path.
  • At rest, on our side. Data held in Firestore, Cloud Storage and Firebase Authentication is encrypted at rest by Google using its own key management.
  • Access control. Firestore and Storage security rules scope every record to the account that owns it, so one account cannot read another’s surveys, photographs or floor plans. Those rules are tested on every release.
  • On your device. Surveys and photographs are held in the app’s own storage, protected by iOS device encryption and your passcode. We do not add a second layer of encryption on top of that, and we do not want to imply we do.
  • Archives you export are not encrypted. A survey archive you export and share is a plain file containing surveys, photographs and floor plans. Anyone who receives it can open it. How you send it, and to whom, is your decision.
  • Payment details never reach us. Apple processes payment; we never see or store card details.

No system is immune from every attack, and we will not claim otherwise. If a breach affects your personal data we will notify the relevant supervisory authority and, where the law requires it, you — without undue delay and within the time limits the UK and EU GDPR set.

9. Your rights and how to use them

Depending on where you are (for example under the UK/EU GDPR) you may have rights to access, correct, export, restrict, object to, or erase your data, to data portability, and to withdraw consent at any time — withdrawal does not affect processing already carried out.

  • Delete your account. Settings → Account → Delete Account. This erases your account and everything stored for it — surveys, photos, floor plans, profile, device records and your record with RevenueCat — before the app confirms it is done. Surveys on your device are not affected; use Delete App Data for those. It does not cancel an App Store subscription.
  • Get a copy of your data. Use Settings → Account → Download my data in the app, or email us and we will do it for you. Either way you get everything the account holds: your account record, profile, surveys (including deletion markers), any legacy device records, push tokens, your subscription record, and time-limited download links for your photos and floor plans. The links expire one hour after the copy is prepared, because anyone holding one can open the file. This is free, and available on every plan.
  • Export your surveys from the app. Export / Share, from the survey list — an archive or CSV of the surveys on that device, at any time, free and on every plan.
  • Diagnostics. Settings → About → Diagnostics — see section 1.
  • Anything else — correction, restriction, objection, or a complaint: contact us below. In the UK you may also complain to the Information Commissioner’s Office (ico.org.uk); in the EEA, to your local supervisory authority.

California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use it for cross-context behavioural advertising. We do not respond to Do Not Track signals, as there is no common standard for them.

10. Children

FiberScan is a professional tool not directed at children under 16.

11. This website

fiberscan.app sets no cookies and runs no analytics or tracking scripts.

12. Changes to this policy

We update the “last updated” date above when this policy changes. Material changes that affect how we use your data will additionally be notified in the app before they take effect.

13. Who we are, and how to contact us

The controller of the personal data described in this policy is Ingenio Productions LLC, a limited liability company organised under the laws of the Commonwealth of Pennsylvania, United States. You can reach us at [email protected].

We are established in the United States, not in the United Kingdom or the European Economic Area. Because we offer the app to people in the UK and the EEA, the UK GDPR and the EU GDPR apply to us directly under Article 3(2) of each.

Questions, requests, or to exercise any right above: [email protected].