Privacy Policy

SUPLOAD LLC

Version 2.1.1 · Published: July 31, 2026 · Effective Date: July 31, 2026 · Last Updated: July 31, 2026

1. Introduction

Supload (“we,” “us,” “our”) is a camera app for work, developed by Supload LLC, a Pennsylvania limited liability company. Supload replaces the multi-app juggle (Camera, Photos, cloud storage) with a single workflow: capture, organize into groups, and upload directly to your cloud storage.

This Privacy Policy explains how we collect, use, store, share, and protect your information when you use the Supload mobile application (“the App”), the Supload customer portal (“the Portal,” a separate service for managing subscriptions, user allocation, and billing), and the Supload marketing website at sup-load.com (“the Website”).

Our core privacy principle: your photos and videos go directly from your device to your own cloud storage account (Google Drive, Dropbox, or Microsoft OneDrive). We never store, access, or process your media files on our servers. We collect only the minimum data necessary to provide the service.

By creating a Supload account, you agree to the practices described in this policy. If you do not agree, do not create an account or use the App.

2. Privacy at a Glance

Question Answer
What do you collect? Account basics (email, display name, user ID, installation ID) plus the limited technical data described in Section 3. Your photos and videos upload directly to your own cloud, never to our servers.
What don’t you collect? Ad identifiers, browsing history, contacts, health data, full payment card numbers
Where do my photos go? Directly from your device to YOUR cloud storage (Google Drive, Dropbox, or OneDrive). Never sent to our servers.
Third-party trackers? None. Zero third-party analytics or advertising SDKs.
Analytics? Opt-in only, first-party, stripped of personal details, tied to your account ID so we can delete it, auto-deleted after 28 days
Do you train AI on my data? Never. We do not use your content or personal data to train AI or machine learning models, and we do not let anyone else do so.
How do I delete everything? Profile, then Profile (under the Account heading), then Delete Account. Permanent, anytime. A few narrow legal records are retained (Section 7).

3. Information We Collect

3.1 Account Information

When you sign in, we collect the following from your authentication provider (Google, Apple, or your organization’s single sign-on):

Data Purpose Source
Email address Authentication, account identification, profile display Auth provider (Google Sign-In, Sign in with Apple, or organization SSO via Microsoft Entra ID)
Display name Profile display within the app Auth provider
User ID Unique account identifier (Supabase UUID) Generated at sign-up
Installation ID Per-device identifier for session management Generated on first launch
Terms acceptance record Terms of Service version, Privacy Policy version, timestamp of acceptance, and account email Recorded at account creation and sign-in

The acceptance record does not include your IP address or device user agent. We also keep a log of the legal-document change notices we send you (the document, version, delivery channel, and date), so we can show which notices you received.

When you link a cloud storage provider (Google Drive, Dropbox, or OneDrive), we receive the account identifier and email address associated with your cloud account through the OAuth authorization flow. This may be different from the email you used to sign in. We use this information solely to establish and manage the connection to your cloud storage.

3.2 Photos and Videos

Supload captures photos and videos using your device’s camera. These files are:

  • Stored locally on your device within your local install of the iOS Supload app as temporary groups until you upload or delete them
  • Uploaded directly to your linked cloud storage (Google Drive, Dropbox, or OneDrive) when you initiate an upload, running in the background with checkpoint-based resume
  • Deleted from your device only after your cloud provider confirms the complete file was received and stored, never on a partial or interrupted transfer
  • Never sent to, stored on, or processed by Supload’s servers

We do not access, view, analyze, scan, or use the content of your photos or videos for any purpose other than facilitating their upload to your chosen cloud storage provider. Our backend stores metadata necessary to operate the service (such as upload status and group structure), but never the content of your media files.

When you use offline mode, Supload caches your cloud storage folder structure (folder names and hierarchy) locally on your device so you can queue uploads without an internet connection. This cached data is stored locally on your device within the App’s private storage and is never sent to Supload’s servers. It is deleted when you unlink the cloud provider or delete your account. When you turn off offline mode, the App asks whether to keep or clear your saved folders, and the cache is deleted if you choose “Clear saved folders.” This cache may be refreshed in the background when offline mode is enabled, using iOS background processing to keep your folder structure current.

Supload LLC is not responsible for any loss, corruption, or inaccessibility of content stored locally on your device prior to upload completion. Until an upload is confirmed complete, your content exists only on your device and is solely your responsibility. For more information, see our Terms of Service, Section 5.4.

3.3 Location Data (Optional, You Control This)

If you enable “Content location” in the App’s privacy settings (Profile, then Permissions), Supload records the GPS coordinates where a photo or video is captured and stores them in a private file on your device, within the App’s sandboxed storage. These coordinates power the in-app map, which shows your capture locations, useful for job sites, inspections, and field documentation.

These coordinates are not written into your photo or video files (they are not added to the photo’s EXIF metadata), are not uploaded with your media to your cloud storage, and are never sent to Supload’s servers or included in analytics. They stay on your device and are not shared with anyone unless you choose to share them: if you use the share feature to send a group of photos, Supload includes a short, readable location summary (for example, a street or city derived from those coordinates) in the message you send, so the people you share with can see where the photos were taken. That summary goes only to the recipients you choose, never to Supload.

The App requests “While Using the App” location authorization only (never “Always”). When you disable Content location, the App stops recording new capture locations immediately.

3.4 Usage Analytics (Opt-In Only, You Control This)

If you opt in, we collect usage analytics to improve the App, such as feature usage patterns, app performance metrics, and error rates. Analytics events are recorded with your account identifier, which is what lets us delete them when you delete your account. Personal details are stripped from event content before storage, as described below.

Analytics are off by default. You must opt in to share analytics data. You can change this at any time in Profile, then Permissions, then “Share usage analytics.”

How we protect your analytics data when you opt in:

  • First-party only. Analytics go exclusively to our own backend (Supabase). We never share them with third-party analytics services.
  • Personal details stripped before storage. Every analytics event passes through a sanitization filter that blocks an extensive set of personal-data key patterns (including email, display name, GPS coordinates, IP address, device identifiers, file paths, folder paths, group names, tokens, and secrets) and scans all string values for email patterns, redacting matches automatically.
  • Consent is checked before every event. If you have not opted in, no analytics events are sent. No restart required, and opting out stops transmission immediately, including queued events.
  • Short-lived. Auto-purged after 28 days.

We do not use any third-party analytics SDKs.

3.5 Crash Reports

Crash reporting is automatic and helps us keep the App stable. Crash reports include error type and stack trace, app version and build number, device model and iOS version, and error context. We scrub known personal-data patterns from crash reports using an email filter and a keyword blocklist before they are stored, though rare fragments may remain. Crash reports are stored for up to 90 days and then automatically deleted. On account deletion, local crash log files are also deleted from your device.

3.6 Customer Portal and Website

The Supload marketing website (sup-load.com) provides product information, pricing, FAQ, and legal documents. The customer portal (hosted on Cloudflare Pages) uses strictly necessary first-party cookies for authentication and session management. These cookies are required for the portal to function. We do not use advertising or cross-site tracking cookies on the portal or the website, and we do not use advertising networks or data brokers.

To understand how our marketing website is used, we use Cloudflare Web Analytics, a privacy-preserving analytics tool. It measures aggregate website usage, such as page views, referring sites, and coarse country and device/browser type derived from the request, without setting any cookies, without fingerprinting your device, and without building a cross-site or cross-app profile of you. Because it uses no cookies and no device identifiers, it does not track you across other sites or apps. Cloudflare also processes your IP address transiently to route and secure your connection. Cloudflare Web Analytics does not use your IP address to identify you, and Supload receives only aggregate measurements, not your IP address, from it. We also use Google Search Console to see how our site appears in Google Search. It relies on Google’s own search data and places no script or cookie on your visit to our website.

3.7 Device and Technical Information

We access certain device capabilities for core functionality. Each permission requires your explicit approval through an iOS system prompt before Supload can access it:

Permission Purpose Required?
Camera Capture photos and videos Yes, core functionality
Microphone Record audio with video Yes, for video capture
Photos (Limited or Full Access) Import existing photos and videos into Supload for organization and upload. With Limited Access, Supload sees only the photos you select. With Full Access, Supload can browse your library to let you import photos and, at your direction, remove the imported originals from your Camera Roll to free up space. Before each import, the App asks with a “Remove from Camera Roll?” dialog that includes a Keep option. Your choice applies to everything in that import, and nothing is removed unless you choose Remove. Supload keeps its own copy of imported media until your upload to cloud storage completes (see Terms of Service, Section 4.5). Supload only accesses or modifies photos you explicitly select or act on. We do not scan, index, or analyze your broader library. Optional, only if you import from your existing library
Location (While Using the App) Record capture location for the in-app map (stored on your device only, see Section 3.3) Optional, controlled in the App (Profile, then Permissions, then Content location) and in iOS Settings
Notifications Receive upload completion alerts and account notifications. Notifications are a convenience, and declining them does not disable uploading or any core function. Optional
Cellular Data Upload content over cellular networks. The App also offers an “Upload only on WiFi” setting (off by default). Optional, controlled in iOS Settings

You can change or revoke any permission at any time in iOS Settings under Supload. Revoking a required permission may limit the App’s functionality. We do not request “Always” location access. “Allow Tracking” is not requested because Supload does not track you (see Section 9).

Security and account-activity log. When you take certain security-sensitive or billing-sensitive actions on your account, for example signing in through the web, linking or unlinking a cloud provider, or making a change to your subscription, our backend records an entry in a server-side audit log. Each entry includes the action taken, the account identifier of the user who took it, the date and time, and, for security and fraud-prevention purposes, the IP address and the device or browser user agent associated with the request. We use this log to secure accounts, investigate suspicious activity, support billing and compliance, and meet our legal obligations. These entries are retained for up to one year (see Section 7.1). This log is separate from your Terms acceptance record, which does not include your IP address or user agent (see Section 3.1).

3.8 Information We Do NOT Collect

We do not collect advertising identifiers (IDFA), browsing history, contacts, health or fitness data, biometric data, call logs or SMS messages, or data from other apps. Stripe processes your payment and shares limited billing metadata with us. For card-based payments this includes the card brand and the last four digits, which we retain in our billing audit records for up to one year. Depending on the payment method you choose, for example a card, Apple Pay, Link, Cash App Pay, Klarna, or Amazon Pay, the exact metadata may differ, but we never receive or store your full card number, bank account details, wallet login credentials, or other payment credentials. Stripe processes those directly.

3.9 In-App Feedback and Diagnostic Logs (Optional, You Control This)

If you submit feedback through Profile, then Send Feedback, we collect your message, category (bug, feature request, or general), app version, device model, and iOS version. You may optionally include your email address for follow-up.

If you enable “Include Diagnostic Logs” when submitting feedback, Supload attaches on-device logs from your current app session using Apple’s OSLogStore framework. These logs help us diagnose the issue you are reporting. Diagnostic logs may include app state transitions, network request metadata, timestamps, and context messages written by the App. They do not include the contents of your photos or videos, your cloud storage credentials, or your cloud file contents.

Diagnostic logs are truncated to 100 KB before submission. You can also export logs to a file via Profile, then Send Feedback, then Export Logs, which generates a .log file you control. Supload does not receive a copy of exported files unless you choose to include them in a feedback submission.

Feedback submissions are accessible to Supload LLC staff for support and product improvement purposes. Feedback submitted without the diagnostic logs toggle enabled is stored without any device logs. If you do not wish to share diagnostic logs, do not enable the toggle. Feedback is retained for up to 90 days and then deleted automatically. Your feedback is included when you download your data. When you delete your account, the message text, contact email, and diagnostic logs you submitted are erased, and only a de-identified record may be kept to improve the service (see Section 7).

3.10 Information Collected Before Account Creation

You may use the App’s camera, local photo organization, and on-device features before creating an account. Data collected locally during pre-account use includes a device-generated installation ID for session management, crash reports (captured automatically and stored on your device until you sign in), and iOS permission grants (stored by iOS, not by us). Crash reports are uploaded to our servers only after you create an account or sign in, and locally stored records may then be associated with your new account. Until account creation, no personal information is transmitted to Supload’s servers.

4. How We Use Your Information

Information Purpose Legal Basis
Email and Name Authentication, profile display Contract performance
User ID and Installation ID Account management, session handling Contract performance
Cloud provider account details Cloud storage connection management Contract performance
Terms acceptance record and notice log Version tracking, compliance Legitimate interest
Photos/Videos Local staging and upload to your cloud Contract performance
Location (optional) In-app map (stored on your device) Consent
Usage Analytics (opt-in) App improvement Consent
Crash Reports Bug fixing, stability Legitimate interest
Feedback and diagnostic logs (optional) Support and product improvement Consent
Billing metadata (card brand, last four digits) Billing records and fraud prevention Legitimate interest
Device Info Core functionality Contract performance

We do not use your information for advertising, profiling, automated decision-making, selling to third parties, or cross-app tracking. We do not use your content or your personal data to train artificial intelligence or machine learning models, and we do not permit anyone else to do so. We do not make any automated decisions that produce legal effects or similarly significant effects on you.

We conduct data protection assessments as required by applicable law.

5. Third-Party Services and Subprocessors

A complete list of subprocessors is published at sup-load.com/subprocessors. For Enterprise customers, we provide at least 30 days’ notice of material changes to our subprocessor list by updating the published list and, where we have the Enterprise administrator’s email on file, by email. Individual users can check the published list at any time.

5.1 Cloud Storage Providers

Provider Purpose Data Shared
Google Drive Photo/video upload destination Your media files (directly from your device to your Google account)
Dropbox Photo/video upload destination Your media files (directly from your device to your Dropbox account)
Microsoft OneDrive Photo/video upload destination Your media files (directly from your device to your OneDrive account)

Supload requests only the permissions needed to let you choose a destination folder and upload to it. For Google Drive, this means reading the names and structure of your folders, so you can choose where to upload and use that folder structure offline, and creating new files and folders. If an upload to Google Drive is interrupted and later resumed, the App may also read the names of the files in that upload’s destination folder, and nothing else, to avoid uploading the same file twice. Supload does not read, download, or modify the contents of your existing files. Depending on the provider, the permission you grant on the authorization screen may technically allow broader access than the App uses, and the App limits itself to the operations described here. The specific permissions requested are shown on each cloud provider’s authorization screen. If future versions require additional permissions, we will disclose the changes before requesting them. Each provider’s handling of the files you upload is governed by its own privacy policy: the Google Privacy Policy, the Dropbox Privacy Policy, and the Microsoft Privacy Statement.

Google API Services User Data Policy. Supload’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5.2 Authentication Providers

Google Sign-In, Sign in with Apple, and your organization’s single sign-on. Supload uses Microsoft’s MSAL library both for Enterprise single sign-on (via Microsoft Entra ID) and to connect consumer Microsoft OneDrive accounts for cloud storage. For Enterprise customers using directory sync (SCIM 2.0), your identity provider shares user provisioning data (email, display name, group membership, active status) with Supload to manage organization membership. Supload does not share data back to the identity provider beyond deprovisioning confirmations. See the Google Privacy Policy, the Apple Privacy Policy, and the Microsoft Privacy Statement.

5.3 Payment Processing

Stripe handles billing for Pro and Enterprise subscriptions, processed through a secure web checkout that supports cards and common wallets and pay-over-time options (such as Apple Pay, Link, Cash App Pay, Klarna, and Amazon Pay). We receive subscription status, billing email, and limited billing metadata (for card-based payments, the card brand and last four digits). We never receive full card numbers, bank account details, or wallet credentials. Supload does not sell subscriptions through Apple In-App Purchase, and Apple does not process Supload subscription payments. See the Stripe Privacy Policy.

5.4 Backend and Infrastructure

Supabase (hosted on AWS US West) provides authentication, database, crash reporting, analytics, and session management. See the Supabase Privacy Policy. When you link a cloud provider, Supload sends a device identifier to our backend to record which device owns that connection, used for security and to manage your cloud integrations. Cloudflare Pages hosts the customer portal and website. See the Cloudflare Privacy Policy.

5.5 Email Delivery

Resend provides transactional email delivery (notifications, usage digests). Resend processes user email addresses to deliver messages. See the Resend Privacy Policy.

5.6 SDK Privacy Manifests

Where a third-party SDK we bundle provides an Apple Privacy Manifest (PrivacyInfo.xcprivacy), we review it before adding or updating that SDK. SDKs that access or transmit user data are supabase-swift (backend, including its bundled Auth component for authentication), GoogleSignIn-iOS (Google sign-in), GTMAppAuth (Google OAuth authorization state), AppAuth-iOS (OAuth flows), google-api-objectivec-client-for-rest (Google Drive API), gtm-session-fetcher (Google HTTP transport), SwiftyDropbox (Dropbox API), MSAL (Microsoft sign-in and OneDrive), and KeychainAccess (secure local storage). We also use swift-crypto for cryptographic operations, and SDWebImage with SDWebImageSwiftUI to load and cache images such as profile photos and cloud folder thumbnails. Additional utility libraries, including swift-concurrency-extras, are listed in the App under Profile, then Terms & Policies, then Open Source Licenses. We update this list before adding new SDKs.

6. Data Storage and Security

6.1 On Your Device

Data Storage Protection
Cloud OAuth tokens (Google / Dropbox / OneDrive) iOS Keychain (kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly, not synchronized to other devices) Hardware-encrypted, never sent to Supload’s servers
App preferences UserDefaults (no personal data) Sandboxed
Photos/videos App Documents directory (temporary, deleted after confirmed upload) Sandboxed in the App’s private storage. To let uploads finish in the background while your device is locked, staged media uses a Data Protection class that keeps it accessible after your device’s first unlock (rather than the strictest class, which would lock it whenever the screen locks)
Upload history and file links App’s private storage (local only) Sandboxed. After a successful upload, the App keeps the resulting cloud file link on your device so you can open your file. Links are never stored on Supload’s servers, and this history is removed when you clear it in the App or delete your account
Cloud folder cache (offline mode) App’s private storage (local only) Sandboxed. Deleted when the cloud provider is unlinked or the account is deleted, and when you turn off offline mode and choose “Clear saved folders”
Capture locations (optional) Private on-device file Sandboxed, never uploaded (see Section 3.3)

6.2 On Our Backend (Supabase / AWS US West)

Data Protection Retention
Account info Row Level Security (RLS), encrypted at rest Until account deletion
Usage analytics RLS, personal details stripped, encrypted at rest 28 days (auto-purged)
Crash reports RLS, encrypted at rest 90 days (auto-purged)
Feedback (message, optional email, optional logs) RLS, encrypted at rest Up to 90 days (auto-purged)
Billing audit records (payment-method metadata such as card brand and last four digits for card payments) RLS, encrypted at rest Up to 1 year
Security and account-activity log (includes IP address and device/browser user agent) RLS, encrypted at rest Up to 1 year (auto-purged)
Session tokens Encrypted, Supabase Auth managed Session duration

Row Level Security policies are applied to tables containing user data. The iOS app uses only the Supabase anon key (not service_role), so RLS cannot be bypassed from the client.

6.3 Security Measures

All network communication uses HTTPS/TLS (ATS fully enabled, no exceptions). Cloud OAuth tokens are stored in the iOS Keychain with hardware encryption and afterFirstUnlockThisDeviceOnly access control, are not synchronized to other devices, and are never stored on Supload’s servers. Personal-data sanitization is applied to all analytics. Secrets are managed through secure build processes and are never stored in source code.

Supload staff may access account information (email, organization membership, audit logs) for support, compliance, and operational purposes. Staff access is role-based and limited to organization-level data. Staff do not access your photos, videos, or cloud provider credentials, and our internal analytics tools do not surface your individual usage activity. Authorized staff can access crash diagnostics, including crash reports and aggregated crash dashboards, as required to operate and stabilize the service. We scrub known personal-data patterns from crash reports using an email filter and a keyword blocklist before they are stored, though rare fragments may remain.

Supload LLC implements commercially reasonable security measures but does not guarantee absolute security. No method of electronic transmission or storage is completely secure. You are responsible for maintaining the security of your device, authentication credentials, and cloud storage accounts. Supload LLC is not responsible for unauthorized access resulting from compromised device security, weak or reused passwords on third-party services, or security incidents at your cloud storage provider.

7. Data Retention and Deletion

7.1 Retention Schedule

Data Retention Deletion
Account info Until account deletion Cascades to all tables
Terms acceptance record and notice log 4 years after account deletion Retained for legal claims defense, then deleted automatically
Usage analytics 28 days Automatic purge
Crash reports 90 days Automatic purge
Feedback submissions Up to 90 days Automatic purge. On account deletion, message text, contact email, and diagnostic logs are erased immediately, and only a de-identified record may remain
Billing audit records (payment-method metadata such as card brand and last four digits for card payments) Up to 1 year Retained in the billing audit log, then purged
Audit trail Up to 1 year Purged automatically after 1 year. Entries record security-sensitive and billing-sensitive actions taken under your account and retain the acting user’s identifier, the IP address, and the device or browser user agent associated with the action as part of our security and compliance records. They are not anonymized on account deletion (see Section 7.2)
Local photos/videos Until uploaded or manually deleted Auto-deleted after confirmed upload, manual deletion in-app
Cloud uploads Managed by you Via your cloud provider
Cloud OAuth tokens Session duration Cleared on sign-out or deletion
Local crash logs Until account deletion Deleted from the App’s storage
Inactive Free accounts 12 months of inactivity Subject to deletion with reasonable email notice (see Terms of Service, Section 18.3)

Account information is kept only while your account exists. Everything else follows the fixed schedules above or stays under your direct control.

7.2 Account Deletion

Profile, then Profile (under the Account heading), then Delete Account (double confirmation).

Server-side: an Edge Function cascades deletion to your user data tables, including analytics, crash reports, upload history, group metadata, and session records. The Terms acceptance record (Terms version, Privacy Policy version, timestamp, and email) and the log of legal notices we sent you are retained for four (4) years for legal claims defense, then permanently deleted. Feedback is handled as described in Section 3.9: the message text, contact email, and diagnostic logs are erased, and only a de-identified record may be kept. Audit trail entries that record actions taken under your account retain the acting user’s identifier (they are not anonymized) and are kept as part of our security and compliance records until the organization is deleted or the 1-year audit-trail retention period expires, whichever comes first. We rely on our legitimate interest in security, fraud prevention, and maintaining accurate compliance records as the basis for this limited, time-bound retention. All other account data is permanently deleted. If any table deletion fails due to a technical error, we will identify and remove the residual data promptly upon detection.

We also clear the App’s cloud tokens on your device and make a best-effort request to your providers to revoke the App’s access where the provider supports remote revocation. You can always revoke Supload’s access directly from your provider’s own permissions page (your Google Account permissions, your Dropbox connected apps page, or your Microsoft account consent settings).

Device-side: all files from Documents and Caches cleared, all app-specific UserDefaults keys removed, all Keychain items deleted, local crash logs deleted.

Not affected: files already in your cloud storage. You manage those directly.

8. Your Privacy Rights

8.1 All Users

  • See your data. Photos are in your cloud. Account info is in your profile.
  • Download your data. Profile, then Download My Data (under the About heading). You will receive a copy of all account information Supload stores about you, including your profile, organization memberships, cloud service connections, terms acceptance records, usage analytics (if opted in), crash reports, feedback submissions, and audit trail entries associated with your actions. OAuth tokens and information privileged for another party (such as another organization member’s data) are excluded for security.
  • Delete everything. Profile, then Profile (under the Account heading), then Delete Account.
  • Turn analytics on or off. Profile, then Permissions, then “Share usage analytics.” Immediate.
  • Control location. Profile, then Permissions, then “Content location.” Immediate.
  • Unlink cloud services. Profile, then Cloud Services. You can also revoke Supload’s access from your provider’s own permissions page (Google Account permissions, Dropbox connected apps, or Microsoft account consent settings).

8.2 United States Residents

If you live in a US state with a comprehensive privacy law, including but not limited to California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, you have rights to access, delete, correct, and port your data, and to opt out of sale or targeted advertising.

We do not sell your personal data. We do not share your personal data for targeted advertising. We do not share your personal data with data brokers, ad networks, or any third party for commercial purposes. There is no sale or sharing to opt out of. For details on our tracking practices, see Section 9.

Universal Opt-Out Mechanisms. We recognize Global Privacy Control (GPC) and similar opt-out preference signals as valid requests to opt out of sale or sharing. Because we do not sell or share personal data for targeted advertising, there is no sale or sharing to opt out of, regardless of whether you use GPC.

For CCPA/CPRA: categories collected are identifiers, internet activity (opt-in usage analytics, and the IP address and device or browser user agent recorded in our security and account-activity log), geolocation (optional, stored on your device only), and audio/visual information (on your device and cloud only). We do not sell personal information or share it for cross-context behavioral advertising. In the twelve months preceding the effective date of this Privacy Policy, Supload LLC has not sold or shared any personal information.

Sensitive Personal Information. Under CCPA/CPRA, “sensitive personal information” includes categories such as precise geolocation and biometric data. Supload records precise geolocation only if you enable Content location, and only in a private file on your device that powers the in-app map. It is not written into your photos, not uploaded with your media, and not transmitted to or stored by Supload. We do not use sensitive personal information to infer characteristics about you.

California Shine the Light Law. California residents may request information about our disclosure of personal information to third parties for those third parties’ direct marketing purposes. Supload does not share personal information with third parties for their direct marketing purposes.

Right to Appeal. If we deny a privacy rights request, we will explain why and provide instructions for how to appeal the decision. You may submit an appeal by emailing [email protected] with the subject line “Privacy Rights Appeal.” We will respond to appeals within the timeframe required by applicable state law.

8.3 European Economic Area and United Kingdom (GDPR and UK GDPR)

You have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), objection to processing (Article 21), withdrawal of consent through App settings, the right not to be subject to automated decision-making (Article 22), and the right to lodge a complaint with your local supervisory authority (Article 77), or with the UK Information Commissioner’s Office if you are in the UK.

We do not make any automated decisions that produce legal effects or similarly significant effects on you.

Data Controller: Supload LLC, 502 W 7th ST, STE 100, Erie, PA 16502, United States · Privacy Contact: [email protected] · Legal Bases: contract performance, consent, legitimate interest, legal obligation.

The App is not currently offered in the European Economic Area or the United Kingdom, so we have not appointed a representative under Article 27 of the GDPR or the UK GDPR. If we make the App available in those regions, we will appoint the required representatives and update this policy before we do. If you are located in the EEA or the UK and have questions about this policy, contact [email protected].

8.4 Canadian Residents (PIPEDA)

Access, correction, and consent withdrawal. Contact [email protected].

8.5 Exercising Your Rights

Contact [email protected]. Response within 30 days. No fee. We may verify your identity before fulfilling a privacy rights request by matching the information you provide with the account information we have on file. We will not fulfill requests that we cannot reasonably verify. You may designate an authorized agent to submit a privacy request on your behalf. We may require the agent to provide written authorization from you and may verify your identity directly.

9. Tracking and Advertising

Supload does not track you across other apps or websites. No IDFA, no ads, no ad networks, no data brokers, no third-party cross-app analytics, no cross-context behavioral advertising, no device fingerprinting, no SKAdNetwork. NSPrivacyTracking = false. No App Tracking Transparency prompt because there is no tracking.

We also honor Do Not Track (DNT) browser signals. Because we do not track users across websites or apps, DNT signals do not change our data practices.

10. Age Requirement

Supload is designed for working professionals. You must be at least 18 years old to create an account. During account creation and sign-in, you must check a box confirming you are at least 18, as stated in our Terms of Service. Supload relies on this self-attestation. We do not collect a birth date, and we do not currently use a platform age-verification signal. The App’s App Store age rating is 18 plus.

We do not knowingly collect personal information from anyone under 18. If we learn that a user is under 18, including through information provided by Apple or an App Store age-rating system, we will promptly delete their account and all associated data and restrict account creation consistent with applicable law. If you believe a user under 18 has created an account, contact [email protected].

Several states have enacted App Store age-verification and parental-consent laws with varying effective dates and ongoing legal challenges. These laws place their primary obligations on app store operators. Supload’s 18-plus rating and 18-plus account requirement are designed to keep the App outside the scope of minor-directed obligations under those laws.

11. Enterprise and Organization Accounts

Your administrator may manage cloud policies, require SSO, and access aggregated analytics (not individual photos). Organizations own the organizational data (group structures, team configurations, aggregated analytics). Individual users’ photos remain their own, uploaded to their personal cloud storage (Google Drive, Dropbox, or OneDrive) and not accessible to administrators through the App.

Each organization’s data is logically separated through Row Level Security policies. No organization can access another organization’s data through the App or customer portal.

11.1 Data Processing Agreements

A standard Data Processing Agreement (DPA) is available for Enterprise customers upon request. The DPA documents the roles, responsibilities, and obligations of each party regarding the processing of personal data. To request a DPA, contact [email protected].

12. On-Device Processing and AI Features

All processing happens on your device: capture (AVFoundation), encoding, thumbnail generation, night mode, red-eye reduction, QR code scanning, text recognition, document detection, and caching. Version 1.0 includes on-device features powered by Apple system frameworks (AVFoundation, Vision). These process data entirely on your device and never send content to external servers.

We do not use your content or personal data to train artificial intelligence or machine learning models, and we do not permit anyone else to do so. Future on-device intelligence features (scene detection, OCR enhancements, document scanning improvements) will use Apple’s Core ML and Vision frameworks exclusively, process entirely on-device, never train on your content, and be disclosed before release with at least 30 days’ notice.

13. International Data Transfers

Supload LLC is based in the United States, and the account data described in this policy (account information, crash reports, analytics, feedback, and billing metadata) is processed in the United States on Supabase (AWS US West). When you use the App from the EEA, the UK, or Switzerland, you provide your account information directly to us in the United States.

Our subprocessors commit to Standard Contractual Clauses and equivalent safeguards in their data processing agreements where their own transfers require them. We protect all personal data with the security measures described in Section 6, including encryption in transit and at rest. We have assessed the risks of processing personal data in the United States and determined that these combined safeguards provide adequate protection. Transfer impact documentation is available to Enterprise customers upon request.

Photos and videos transfer directly from your device to your own cloud provider and never pass through Supload.

14. Data Breach Notification

14.1 Definition

A “security breach” means an incident in which account data (email, display name, user ID, or other personal information) is accessed, acquired, or disclosed by an unauthorized party.

14.2 Notification to Users

We will notify affected users as soon as practicable after discovering a security breach, and no later than any deadline required by applicable state breach notification law. Where GDPR applies, we will notify affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms.

Notification will be sent to the email address associated with your account and, when feasible, through an in-app notification.

Supload LLC’s notification obligations apply only to data that Supload LLC stores on its servers (account information, analytics, crash reports, feedback, and billing metadata). Because Supload does not store, access, or process your photos or videos, Supload LLC has no obligation to notify you of security incidents at your cloud storage provider (Google Drive, Dropbox, or OneDrive) or authentication provider (Google, Apple, Microsoft). You should monitor security notifications from those providers directly.

14.3 Notification to Authorities

Where GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of a breach, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. We will comply with all applicable state breach notification laws, including any requirements to notify state attorneys general, consumer reporting agencies, or affected individuals, and any requirements to provide credit monitoring services.

14.4 What We Provide

Breach notifications will include: a description of the nature of the breach, the types of data involved, the likely consequences, the measures taken or proposed to address the breach, and contact information for questions.

15. Business Transfers

If Supload LLC is acquired by or merged with another company, or if we sell substantially all of our assets, your account data may be transferred to the successor entity as part of that transaction. We will use commercially reasonable efforts to notify users of any such transfer and of any material changes to this Privacy Policy that result. Until a new privacy policy takes effect, the successor entity will be bound by the commitments in this Privacy Policy. You may delete your account at any time. In the event of bankruptcy or receivership, we will use reasonable efforts to ensure any successor entity adheres to the commitments in this Privacy Policy.

16. Law Enforcement Requests

Supload LLC discloses account data to law enforcement only where we reasonably believe we are legally required to do so. We evaluate each request for legal validity, scope, and jurisdiction, including compliance with the Stored Communications Act (18 U.S.C. Section 2701 and following) and other applicable law. We may challenge overbroad or legally deficient requests. Our policy is to notify affected users before disclosure unless we are prohibited from doing so by law or we reasonably believe notice would create a risk of harm. We produce only the minimum data responsive to a valid request. Contact [email protected] for questions.

17. Marketing Communications

You may opt out of marketing at any time via the unsubscribe link or by contacting us. We process opt-outs within 10 business days. We never send marketing to users who have not opted in or who have opted out.

18. Changes to This Policy

We use a two-tier process, matching our Terms of Service.

Routine changes. We update the “Last Updated” date, notify account holders by email, show an in-app notice with the effective date, and note what changed in the Version History.

Material changes (changes that expand what we collect, how we use it, or who we share it with): we provide notice at least 30 days before the change takes effect and require your affirmative re-acceptance in the App before the changed policy applies to you. Material changes apply prospectively only.

We keep a record of the change notices we send, as described in Section 3.1.

19. App Store Privacy Label

Category Details
Data Used to Track You None. Supload does not track you across apps or websites and uses no advertising identifiers.
Data Linked to You Email, Name, and User ID, for account creation and authentication. Photos or Videos, captured or imported in the App and uploaded directly to your own cloud storage, never sent to, stored on, or accessed by Supload’s servers (see Section 3.2). Precise Location, only if you turn on Content location, stored in a private on-device file for the in-app map, and included as a readable summary in a group’s share text if you choose to share it, never written into your photos and never sent to Supload’s servers (see Section 3.3). Product Interaction, opt-in usage analytics, recorded with your account identifier (see Section 3.4). Crash Data, automatic crash diagnostics (see Section 3.5). Performance Data, opt-in performance diagnostics (see Section 3.4). Device ID, a device identifier used to verify which device owns a cloud connection (see Section 5.4). Other Diagnostic Data, logs you optionally attach to in-app feedback (see Section 3.9).
Data Not Linked to You None.
Data Not Collected Advertising identifiers (IDFA), browsing history, contacts, health or fitness data, biometric data, call logs or SMS messages, and data from other apps (see Section 3.8).

How to read this label. Apple’s App Store privacy label uses a broad definition of “collect” that counts transmitting data off your device, including to your own cloud storage, even when Supload never receives or stores it. Because the App’s privacy manifest declares the types listed above, they appear here as Data Linked to You, and never as data used to track you. Your photos and videos and your precise location are still never sent to, stored on, or accessed by Supload’s servers, as described in Sections 3.2 and 3.3. This label reflects Apple’s off-device definition, not any storage by Supload.

20. Contact

Privacy: [email protected] · General: [email protected] · Legal / Law Enforcement / DPA Requests: [email protected] · Website: https://sup-load.com · Mail: Supload LLC, 502 W 7th ST, STE 100, Erie, PA 16502, United States

Join Waitlist