Privacy
Last updated 11 August 2026
BuildShot has no account, no server and no upload. Your photos, spoken notes, to-dos and job sites are written to your iPhone and stay there. Nobody at BuildShot can see them, because there is nowhere for them to be seen.
The short version: your photos, notes and jobs never leave the phone. Four things do go out over the network — a request asking public web servers what the time is, the coordinates sent to Apple to turn into a street name, whether a purchase is live, and, if the app crashes, a report about the crash. All four are described below, and the last one can be switched off.
What stays on your phone
- Photos, and the date and place burned into them
- Spoken notes and their transcripts
- To-dos and job sites, including their names, clients and addresses
- Your business details and logo, used on the reports you generate
- Reports, until you choose to share them
All of it lives inside the app's own storage on the device. It is included in an encrypted iPhone backup if you make one, and it is removed when you delete the app.
Permissions, and what each is for
- Camera — to take the photos. Images are saved inside the app.
- Location — to work out which job site you are standing on, and to write the place onto the photo. Working out the site happens entirely on the device; turning the coordinates into a street name does not, and is described below. If you refuse Location, the app keeps working; it asks you which site to file a photo under instead of knowing.
- Microphone and speech recognition — to record spoken notes and turn them into text. Transcription runs on the device; the audio is not sent to Apple or to anyone else.
- Photo library — only if you choose an existing image or set a logo.
What leaves the phone, and why
Four things, and nothing else. No photo, no spoken note, no report and no job record is ever transmitted.
The time
BuildShot dates your photos against an outside time source, so that the date on a photo does not
depend on your phone's clock, which anybody can change in Settings. To do that the app sends a
HEAD request to three public websites — apple.com, cloudflare.com and one.one.one.one
— and reads the standard Date header their servers return.
These requests contain no photo, no location, no identifier and no information about you or your work. As with any web request, the servers involved can see your IP address. No response is stored beyond the time reading itself.
If your phone has no network, the app carries on and marks the photos as carrying device time rather than verified time.
The street name
To print a street under the stamp rather than a pair of numbers, the app asks Apple's geocoder to turn the coordinates into an address. That means the coordinates are sent to Apple, handled under Apple's own privacy terms, and the name that comes back is stored on your phone with the photo. It happens only when a photo or a job site needs a name.
If you refuse Location, neither of these happens and the app keeps working — it asks you which site a photo belongs to instead of knowing.
Whether you have paid
Reports are a paid feature. Payment itself is handled entirely by Apple — BuildShot never sees your name, your card or your Apple ID. To know whether a purchase is live, the app uses RevenueCat, which receives a randomly generated identifier for this install, the country your App Store account is in, and the state of the purchase itself. It receives nothing about your jobs, your photos or where you have been, and the identifier is not linked to you.
If you never buy anything, this still runs — the app has to ask what is on offer in order to show a price. And if it cannot reach the network at all, the app assumes in your favour and lets you carry on.
Crashes, and how the app is used
When the app crashes, a report is sent to Sentry, hosted in the European Union. It contains what the code was doing when it failed, the iPhone model and the iOS version. It carries no photo, no job, no address and no location, and the record of which screens you opened is deliberately switched off — on this app that list would spell out which customers' addresses you visited.
You can turn crash reports off, in the app: Profile, then the gear, then Privacy. Off means off.
A handful of counts also go to TelemetryDeck so we know whether a feature is used at all: a job was created, a photo was taken, a report was made, the price screen was seen. Four counts, and nothing about the job, the photo or the place.
Those counts carry an identifier for this installation, so that one person opening the app twice is not counted as two. It is derived on the device, it is not your name or your Apple ID, and it does not follow you into any other app or website — but it exists, and saying otherwise would be untrue.
Neither of these is advertising, and neither of them tracks you.
Sharing
A report leaves your phone only when you send it, using the iOS share sheet, to a recipient you choose. BuildShot does not see the report, the recipient or the message.
Children
BuildShot is a tool for tradespeople and is not directed at children.
Your rights
Your work — the photos, the notes, the jobs, the reports — is held only on your phone, so there is nothing on our side to hand over or delete. Deleting the app removes all of it.
The four things described above are the only exceptions, and none of them is tied to your name: crash reports can be switched off in the app, and the feature counts and purchase state carry no identifier that would let us find you in order to delete anything. If you want any of this explained, or want us to check something for you, write and a human will answer.
Changes
If a future version ever collects anything, this page will say so plainly before that version ships, and the change will be described here rather than buried.