ProofHaven

Your information

Privacy policy

Effective September 23, 2026

This policy explains what ProofHaven processes, the choices you have, and the limits of our current deletion and retention processes.

Who operates ProofHaven

ProofHaven is operated by Chengdu Kaxinuo Interactive Co,Ltd. Contact us at support@juyougame.club for support or privacy questions.

Information you provide

ProofHaven helps you organize receipts, product labels, warranties, asset documents, reminders, and repair notes. Guest receipt images, extracted fields, and records stay on your device; SDK operational metrics are described below. For signed-in accounts, we process your email address, optional display name, authentication identifiers, password hash for email/password sign-in, session records, and account and household identifiers. Cloud records include the images, documents, extracted text, product details, purchase information, dates, notes, and other content you choose to save. Household records may be accessible to other members of that household.

On-device recognition and SDK metrics

ProofHaven uses Google ML Kit for on-device text recognition. Google states that input images/text and recognition outputs stay on-device, while ML Kit sends operational metrics to Google. This can occur during guest capture. See Google ML Kit privacy terms.

These metrics include device/OS and app information, installation identifiers, latency, image configuration, feature events, and error codes, used for diagnostics and usage analytics. See Google’s iOS SDK data disclosure. Declining ProofHaven cloud capture does not disable this separate SDK behavior. Our extraction-diagnostic cleanup and account deletion do not control Google’s SDK metrics retention; we have not verified a deletion deadline for those metrics.

Cloud capture and your choice

Before each signed-in capture is processed or uploaded, the app asks whether you allow cloud sharing and processing. If you agree, the selected receipt or product-label image is uploaded to private Cloudflare R2 storage, and extracted text and fields are sent to our service. Where additional extraction is needed, the image and extracted text may be sent to Alibaba Cloud Qwen in Beijing, China. This may involve processing outside your country. The app lets you review and edit extracted fields before saving. Cancel stops that capture upload; manual entry and local guest capture remain available. Consent applies to that document, including retries of its extraction. It does not automatically approve your next capture.

Why we process information

We use this information to provide account access, store and synchronize your cloud records, identify receipt and product fields, display warranty and return dates, support reminders you choose to create, handle support requests, and operate and protect the service. Extraction records also contain provider and model details, usage counts, estimated cost, timestamps, and fixed failure codes used to operate extraction and its retries.

Service providers and email

Our application server runs on Oracle Cloud in Seoul, South Korea. Supabase PostgreSQL in the US West (Oregon) region stores cloud account and record data, including extracted text and document references. Images and document files are stored separately in private Cloudflare R2 storage. These services may process information outside your country. Alibaba Cloud Qwen processes consented extraction requests in Beijing, China. The operator uses Resend to send and receive email at juyougame.club. The support console reads messages from Resend without a separate email archive; Resend retains email content for 30 days under its standard retention policy. If you email support, your address, message, and attachments are processed through the email services involved. Send only the information needed to explain your request. We do not sell your personal information. These public pages include no advertising trackers, analytics scripts, or third-party fonts.

How long records are kept

Cloud records remain until you delete them or the account deletion process removes them, subject to the shared-household rule below. For completed or failed extraction jobs, temporary diagnostics become eligible for cleanup after 30 days. Cleanup runs hourly in limited batches, so removal may occur later when there is a backlog or a service interruption. It removes separate cloud extraction output, confidence data, fallback reasons, and provider latency; legacy error text is replaced with fixed failure codes. Local extraction is removed at this stage only for confirmed jobs. Unconfirmed local drafts, merged review results (which can include extracted text), and provider, usage, cost, timestamp, and retry metadata remain until the associated document or account records are deleted. Guest records remain on the device until you clear them or remove the app, subject to your device backup settings.

Deleting documents and your account

You can delete individual documents in the app. Their database records are removed and private-object deletion is queued. Signed-in users can request account deletion from Account > Privacy > Request account deletion. A pending deletion request blocks authenticated access. The background process deletes the user account, linked sign-in identities, saved session tokens, subscriptions and associated store events, memberships, and the deletion request itself. A household owned solely by the departing user, with no other members, is deleted with its dependent assets, documents, extraction jobs, reminders, and repair records. Shared households and their records remain for the remaining members; ownership transfers to a remaining member when necessary. Removing your account therefore does not remove all shared household content.

Private-object deletion and remaining limits

Private-object deletion is delayed by at least 16 minutes to allow previously issued upload links to expire. Failed storage deletions are retried; database deletion does not mean the private object has already been erased. The deletion queue retains the object reference and retry information until deletion succeeds. This is not a promise of immediate or complete erasure from every system. Automated daily database backups created from September 14, 2026 are encrypted and become eligible for deletion after seven days; cleanup runs after a successful daily backup and may be delayed by interruptions. Fixed retention periods for older or manually retained infrastructure backups, operational logs, and previously retained support correspondence have not yet been established, and device-backup behavior has not been fully verified. Contact us for the current status or to raise a deletion request concerning support correspondence. We do not promise an unverified backup-erasure deadline.

Your choices and contact

You can use guest capture, enter details manually, decline a cloud capture, review extracted information, and delete documents or request account deletion. Contact support@juyougame.club to ask about your information, request corrections, or raise a privacy concern. Do not send passwords, session tokens, or unnecessary receipt images. ProofHaven is not intended for children under 13. We will update this page when our practices change, with the effective date shown above.