Asset Assistant: Privacy Policy


1. Summary

Asset Assistant is an Android app for recording your movable assets. Your asset records and photos are stored only on the register owner's device: on a Solo plan or as a team owner, that is your own device; a team field device sends its captures, end-to-end encrypted, to the owner's device (see section 7A). We do not host your records or keep a readable copy on our servers. Some optional features send your photos to an AI service for processing and return a result; we do not retain those images. We keep usage statistics: including the asset category, and (only with your separate consent) invoice vendor names, to run, cost and improve the service. We have no user accounts, so this is not linked to you. Like almost every online service, our servers also keep technical request logs, including the IP address a request came from, for 90 days, to keep the service secure and to trace faults and abuse (section 4A).

2. What stays on your device (we never receive it)

We have no user accounts and no database of your data. We cannot see, retrieve, or restore your records.

Two things leave your device only when you ask: photos and documents sent for AI processing (section 3), and asset records sent to an accounting system you connect (section 7B). Neither is stored by us.

In team mode, "your device" above means the organization owner's device: field devices capture and then hand their captures to the owner, end-to-end encrypted in transit through a relay that cannot read them (section 7A).

3. What we process when you use AI features

When you use Identify with AI, Read Invoice with AI, or Estimate Market Value, the app sends the relevant photo(s) or document and a few text hints (e.g. category, site name, notes you entered) to our AI service. Our service forwards them to our AI provider (OpenAI) to generate the result, which is returned to your device. - We do not store these images/documents, our own service (hosted in South Africa) processes them in transit only. - Photographs are sent inline with the request and are never stored as files at the AI provider. PDF invoices are technically different: to be read they must be uploaded to the AI provider's file storage. We set those uploads to expire automatically one hour after upload, which is far longer than the few minutes a job takes. - Our AI provider (OpenAI) may retain them for up to 30 days for abuse monitoring and to operate the service, after which they are deleted, unless OpenAI is legally required to keep them longer. Content that is flagged by automated safety checks (for example, suspected illegal content) may be reviewed by a person at the AI provider. OpenAI encrypts this data at rest and in transit. We do not keep a copy. - OpenAI processes this data under its API terms with us, which bind it not to use your content to train its models and to hold it only as described above. Its commitments are published at https://openai.com/enterprise-privacy/ and its privacy policy at https://openai.com/policies/privacy-policy/. You are not a party to those terms; we are, and we are responsible to you for the transfer. - Cross-border transfer: our AI provider processes data outside South Africa (in the United States). The transfer is made because it is necessary to provide the AI feature you asked for, and under OpenAI's API terms with us, which bind it to the protections described above (POPIA section 72). Our own service and its logs run inside South Africa. The only other transfer is the purchase and app-verification checks with Google Play (section 6), which Google handles under its own terms. See the POPIA Notice for your rights.

4. Usage data we keep

For each AI request, our service records a single log entry to operate, bill, and improve the service and to understand which kinds of assets the service is used for. We have no user accounts, so these entries are not linked to you or to any account or device. An entry contains: - timestamp, operation type (identify / invoice / value), AI model, request status - token usage (for cost), a confidence score, currency, country (ZA) - which kinds of fields were present (e.g. a flag that an amount was provided, never the amount itself) - the asset category (e.g. "tractor"), using both your own description and a standardised category code, for product analytics.

We do not log your photos, asset make/model, serial/registration numbers, purchase amounts or values, GPS coordinates, site names, or free-text notes.

Vendor name: only with your consent

When you use Read Invoice with AI, we can additionally retain the vendor / supplier name read from the invoice, for analytics. This happens only if you have given consent in the app's Terms & Privacy screen (Settings → Terms & Privacy), it is off by default. A vendor name can in some cases identify a business or person, so we treat it as sensitive: you can withdraw this consent at any time, which stops vendor names being logged going forward (it does not delete entries already logged, see §9).

If you report an AI result

Every AI result has a Report this result action. A report sends a reference to that AI request, the reason you selected, and any note you type - and nothing else. Your photos, asset details and values are not sent. We use it to look up what went wrong; the reference lets us find the request in our usage log and, within the AI provider's retention window, the response itself.

4A. Technical request logs

Every time the app (or a browser) contacts our service, for any purpose (AI requests, purchase checks, team relay, service notices, or opening these legal pages), Google Cloud automatically records a technical log entry. It contains the time, the address requested (for team relay requests this includes the team's random organisation code, not a name), the response status and size, the IP address the request came from, and the app or browser identifier (user agent). Our service also uses the IP address, in memory only, to apply rate limits. - Why: to keep the service secure, to detect and stop abuse (for example excessive or automated requests, or attempts to bypass credit limits), and to trace a fault or a misuse to the requests involved. - Lawful basis: our legitimate interest in running a secure, working service (POPIA section 11(1)(f)). - Personal information: an IP address can in some cases be linked to a person, so we treat these logs as personal information. We do not combine them with other data to identify people, except where needed to investigate abuse or a security incident, or where the law requires. - Where and how long: stored in a dedicated log store in South Africa and deleted automatically after 90 days.

5. Permissions

6. Payments and subscription checks

Subscriptions and AI credit packs are sold and processed by Google Play Billing. We do not receive or store your card, bank or payment details, Google handles those, under Google's privacy policy.

We do check that a purchase is genuine. When you buy or renew, Google Play issues your device an opaque purchase token. The app sends that token to our service, which asks Google's Play Developer API whether the token is valid and when the subscription expires, and returns the answer. This is what stops someone unlocking paid features without paying. - The purchase token identifies a transaction, not a person: it carries no name, email, card number or device identifier. - We send it only to Google, which issued it and already knows about the purchase. Nothing about your purchase is sent to any other third party. - Your device keeps the answer so the app works offline.

6A. Refunds of credit packs

If a credit-pack purchase is refunded or charged back, the app asks our service which of its own purchase tokens Google has voided, and deducts those credits on the device (Terms 5.6). Again only opaque tokens are involved, no personal data.

6B. App verification (Google Play Integrity)

To protect the AI service from abuse, we confirm with Google Play that AI requests come from the genuine app on a device that passes Android's integrity checks. This involves Google only, tells us nothing about who you are, and we store nothing from it. What Google processes for this check is covered by Google's own privacy policy.

6C. Support reports (only if you send one)

If you contact support, we may ask you to share a support report. It is created on your device, at your request, and shown to you as a file that you send (for example by email), the app never transmits it by itself. It contains your app version and device model, subscription and free-allowance state, credit balance and the app's own log of credit changes, and your purchase/refund tokens, and deliberately no photos, no asset details, no location, and no register content. We use it to resolve your issue, and we keep it as part of our support records for as long as reasonably necessary for the matter and for proper business records, including the establishment or defence of legal claims, after which it is deleted.

6D. Service notices

From time to time we may need to tell users something: a problem affecting a particular app version, a security incident affecting team relay data, or a change to the service. The app fetches a short public list of notices from our service when you open it, and shows any that apply to your device. The request carries no identifier: every device receives the same list, and the app decides on the device which notices apply, by app version, by whether it is used on its own or in a team, and, for a notice about a specific team, by comparing a one-way code derived from its team identifier that we publish instead of the identifier itself. Dismissing a notice is recorded on your device only.

7. Backups

Encrypted backups are created by you, encrypted with a passphrase you choose, and stored where you choose (your device or your own cloud). We never receive, hold, or have access to your backup or passphrase. If you lose the passphrase, the backup cannot be recovered.

7A. Team mode (organizations)

If an organization owner invites team devices, captures made by field devices travel to the owner's device through our sync relay. Everything the relay carries is end-to-end encrypted on the devices: we relay ciphertext we cannot read or decrypt, and relay content is deleted automatically (at most 60 days; typically as soon as delivered). There are still no user accounts: team devices are identified by pseudonymous tokens and a device label the owner typed, no names, emails, or phone numbers are collected. Encryption keys travel only inside the invite QR code, device-to-device, never through our service. - The organization owner controls the team: invites and revokes devices and can delete the organization's relay data at any time in-app (Team → Delete Organization). - A field device keeps a local capture journal (what was captured and delivered, with the owner's response). It remains on that device as the worker's own record, including after access is revoked. Asset photos and details are removed from the field device once delivered, and the organization's assets and photos are erased from the device entirely if the worker leaves the team or the owner revokes it: the register belongs to the organization, not to the worker's phone. - The register itself lives on the owner's device, not with us.

7B. Accounting system connection (Xero)

If you connect your accounting system (currently Xero) on the Export screen, the app links directly from your device to that provider. You sign in on the provider's own login page; the app receives access tokens which it stores on your device only and refreshes itself. Our service is not involved beyond a static page that returns you to the app after sign-in; it does not receive, store or forward your tokens or your data.

When you tap Sync, the app sends the asset records you have marked for sending: asset number, name, serial number, description, cost, purchase date, asset type and depreciation settings. It also reads your fixed-asset list to match assets and show their status. For a registered asset it may, on your explicit confirmation, update the name, serial number and description. Nothing else is sent, and no photographs, GPS positions or invoices are sent.

Cross-border transfer: your accounting provider may host your organisation's data outside South Africa under its own privacy policy (Xero: https://www.xero.com/legal/privacy/). This transfer happens at your instruction, from your device to your own accounting organisation; we are not a party to it. Disconnecting in the app revokes the app's access; records already sent stay in your accounting system, where you control them.

8. Children

The app is a business tool and is not designed for or directed at children. Buying a subscription or credit pack requires the legal capacity to contract (in South Africa, generally 18 or older). A team member using a device seat provided by their employer buys nothing and may use the app from 16 years of age, at that employer's responsibility. See Terms 2.1.

9. Data retention

10. Security & service providers (sub-processors)

11. Your rights & contact

Because we hold no account and no personal information that directly identifies you (the closest are the IP addresses in our technical request logs, §4A), most data-subject requests relate to your on-device data (which you control directly, edit it in-app, or uninstall to erase all local data). For questions or requests, including deletion, contact info@vitalpursuit.co.za. See the POPIA Notice for South African data-protection rights and our Information Officer details.

12. Changes

We may update this policy; the effective date above will change and material updates will be notified in-app or on the listing.

See also: Terms & Conditions · POPIA Notice · Data Deletion · PAIA Manual