Privacy
This page covers the Proof website and the Proof phone app (iOS and Android). It says what we hold, who can see it, and how to delete it.
What we collect
Sign-in. On the phone: Google, Apple, or LinkedIn. We receive an email address and a display name. If you hide your email with Apple, we only see the relay address Apple gives us. On the website you can also sign in with a phone number; we store that number to send a one-time code and to keep you signed in.
What you write. Logs, replies, and reactions. This is the product.
Photos you attach to a log, if you take one or pick one from your library. The file is stored so the log can show it. A public log's photo can be seen by anyone who can see that log.
A profile photo, if the sign-in provider gives us one, or if you upload one on the website. For a provider photo we store the link they gave us. For an upload we store the file.
How the app is used. Which screens open, how long a post took to write, whether a post succeeded or failed. Not the text of what you wrote. The phone app sends product analytics (PostHog): your account id, your name, and which screens you open. Not log text. We do not sell this. The store build always sends it; there is no switch in the app to turn it off.
A device session token, so the app keeps you signed in. Only a one-way hash of it is stored, so the stored value cannot be used to sign in as you. Drafts you have not posted yet stay on that phone.
What we never collect
Audio. When you use voice on the phone, speech is turned into text on the device. The recording is never uploaded. We only receive the text you then edit and choose to post.
No location. No contacts. No ad network.
We do not sell your data
Nothing is sold. Nothing is shared with data brokers or ad networks. We do not use what you write to train a model of our own.
Public log text (not your name or handle) may be sent to a language-model provider so we can suggest which logs to feature. A person at Proof still decides. Private logs are not sent.
Private logs
A log marked Only me is encrypted before it is stored and is never stamped public, so it cannot appear in any feed, cannot be reacted to, and mentions nobody. Its date and verb stay readable — those are metadata, not what you wrote.
Notifications
The phone reminder is one you set yourself. Your phone schedules it and your phone fires it. We hold no push token for it. Separately, you may be told when another person responds to something you posted. There is no marketing push today.
Who can see what you write
A public log can be read by anyone, including founders hiring through Proof — that is the point of it. A private log can be read by nobody but you. You choose per log. On the website you can go Quiet from You or Settings. Quiet hides you from the founder pool; founders you already replied to can still read you. That switch is not in the phone app.
Children
Proof is not directed at children under 13, and we do not knowingly create accounts for them. Published standards against child sexual abuse and exploitation (CSAE) are on Child safety.
Deleting your account
You can delete your account from inside the phone app — You → Delete my account — or on the web from Settings. Deleting signs out every device immediately and removes your account, your logs, and your reactions. It cannot be undone.
If you would rather ask a person, write to rk@candorandinnovation.com and it will be done.
Changes
If what we collect changes, this page changes with it, in the same release. The date at the top is when it last did.
Contact
Candor and Innovation · rk@candorandinnovation.com