Privacy Policy
Last updated: September 14, 2026
KeyProof is a stay-record platform for property managers. It supports two products from the same codebase: Tenancies for long-term rentals (move-in, tenant response, move-out, tenant response) and Bookings for short-term rentals such as Airbnb, VRBO, or direct-booking properties (an immutable property baseline pinned to each booking, a 24-hour guest flag window at check-in, and a targeted damage capture at checkout). Property managers pick which product a property uses. This policy covers the web app at keyproof.app and the KeyProof iOS app.
KeyProof is published by Cedarline Technologies LLC. Questions: contact@keyproof.app.
1. The short version
- To capture a move-in or move-out layer, photos, videos, voice notes, and the sealed record itself are uploaded to Cedarline-controlled infrastructure (Supabase, hosted in the United States).
- Access is scoped: property managers see the tenancies belonging to their organization; a tenant sees only their own tenancy through a permanent email link.
- Sign-in happens via emailed magic link (property managers on the web) or Apple Sign In (iOS app). Tenants authenticate through a permanent link sent to the email address the PM invited. We do not store passwords.
- Nothing is sold. No third-party advertising SDKs. No behavioral tracking across the web.
2. What we collect and store
Tenancy records (long-term rentals)
Each tenancy accumulates up to four layers: PM move-in checklist, tenant response, PM move-out checklist, tenant response. When a PM captures a layer, we store: the room list, every photo and video, voice notes and their captions, per-item condition and damage flags, the timestamped hash seal on the closed layer, and the property and tenancy the layer belongs to.
Bookings (short-term rentals)
Short-term properties carry an immutable baseline — a captured record of the unit that the PM maintains once, versioned as it changes. When a booking is created, we store: the guest's display label (which can be a first name only — no full legal name required), a guest contact for the check-in link (email or phone), booking dates, and the baseline version pinned to that booking at check-in.
During the guest's 24-hour check-in window, we store any flag the guest raises: the flagged item, the guest's note, and photos or video they upload. At checkout, we store the PM's targeted damage flags: item, condition change, notes, and photos or video. The baseline itself — the room list, per-item photos, videos, voice notes, condition, and every immutable version — is stored the same way tenancy records are.
Account data
Email address, display name, organization membership, and — for property managers — organization details (name, plan, teammates). For tenants: the email address the PM used to invite you, which authenticates your permanent link to the tenancy. For guests: the label and contact the PM entered when opening the booking; the check-in link is derived from that record.
Tenant and guest responses
Each time a tenant reviews a move-in or move-out layer, we store the per-item verdict (accept or dispute), any dispute note, the responding tenant's identity, and the timestamp. The tenant's per-item verdict is their electronic acknowledgement of the record and creates a binding electronic signature under the US ESIGN Act.
For bookings, we store each guest flag (item, note, media, timestamp) submitted through the check-in link. If the 24-hour window elapses with no flag, we record the elapsed window itself — the fact that the guest had access and raised nothing — as timestamped evidence. Both the flag submissions and the documented silence are treated as electronic acknowledgements under the US ESIGN Act.
Support requests
When you submit an invoice request or contact support, we store the details you send (name, organization, email, message).
Technical logs
Standard web-server access logs (IP, user agent, request path, timestamps) retained for up to 30 days for security and operations.
3. Who sees what
- Property manager side: members of the organization the tenancy or booking belongs to. Role-based access; owners and admins see everything, teammates see what their role permits.
- Tenant side: a tenant sees only their own tenancy — every layer of it, side by side — through the permanent link sent to the email address the PM invited. Tenants can email themselves a copy of the record from that view any time.
- Guest side (short-term rentals): a guest sees only their own booking — the baseline version pinned to it and any flags they themselves raised — through the permanent check-in link. Guests do not see other guests, other bookings, the property's booking history, or the PM dashboard. Guests can email themselves a copy of their booking record from that view any time.
- Cedarline personnel: access is restricted to those operating the service and is logged.
Guest data minimization
The guest label a PM enters can be a first name only — a full legal name is not required, and KeyProof performs no ID verification on guests. The guest contact (email or phone) is used only to deliver the check-in link and to let the guest email themselves a copy of their booking record. Guest data is retained on the booking record so the evidence pack stays intact; if you want a booking's guest record purged, ask your PM to delete the booking from their organization.
4. Sub-processors
We use the following vendors to run KeyProof. All are under written data-processing terms.
- Supabase (US) — database, authentication, file storage.
- Cloudflare (US) — hosting for keyproof.app and content delivery.
- Stripe (US) — payment processing for property manager subscriptions.
- Photon (Komoot / OpenStreetMap) — address autocomplete when adding a property. We send the partial text you type; nothing is stored by Photon beyond standard access logs.
- Apple (US) — Sign in with Apple, when used from the iOS app.
5. iOS app
The KeyProof iOS app requests the following permissions on demand — never on launch — and each prompt appears the first time you trigger the feature that needs it:
- Camera — the first time you tap Add photo or Add video while capturing a move-in or move-out layer.
- Microphone — the first time you record a video clip or a voice note.
- Speech Recognition — on the first voice note. Transcription runs on-device; the transcript stays on your phone until you close the layer.
- Photo Library — only when you tap Attach from library, and only for the picker you interact with.
- Precise Location — used to geo-stamp captures as part of the tamper-evident record. Read only while you are actively capturing.
- Notifications — never asked in v1.0. May be added in future versions with your explicit opt-in.
To support crash diagnostics, the iOS app also collects standard crash logs from Apple. Crash logs are not linked to your account.
The types of personal data collected in the iOS app — as declared on the App Store product page — are: name, email address, precise location, photos or videos, audio data, user ID, and crash data. All are used for App Functionality; none are used for tracking; none are shared with third-party advertising networks or data brokers.
6. What we do not collect
- No selling or sharing of user data with third parties for marketing.
- No advertising SDKs. No IDFA, no ad fingerprinting.
- No behavioral tracking across other sites.
- No contacts, no browsing history, no data from other apps or tabs.
7. PDFs and evidence packs you generate
Tenancy record PDFs are generated server-side (web) or on the device (iOS app). Property managers can export a full tenancy — every layer of the record — from the dashboard. Tenants can email themselves a copy of their tenancy from the permanent-link view.
For short-term bookings, PMs can export a booking-specific evidence pack: the pinned baseline version, any guest flags or the documented silence during the 24-hour check-in window, the checkout damage capture, and every timestamp. The evidence pack is intended for upload to a resolution centre (Airbnb, VRBO, or your own platform). Sharing the PDF or evidence pack onwards — email, cloud storage, resolution-centre upload, printout — is your choice.
8. Deleting your data
Property managers: Settings → Delete organization removes the organization, its properties, units, tenancies, bookings, baselines (and every immutable version), and every layer of record attached to them.
Tenants and guests: the tenancy or booking record is owned by the property manager who created it. Email support@keyproof.app with questions about a specific record, or ask your PM to delete the tenancy or booking from their organization.
For deletion requests that can't be completed in-app, email support@keyproof.app — we respond within one business day.
9. Children
KeyProof is not directed at children under 13. The App Store age rating is 4+, but the actual use case (documenting a rental or purchase) is intended for legal adults.
10. Changes to this policy
Material changes will bump the "Last updated" date at the top of this page. Continued use of KeyProof after a change signifies that you accept the updated policy.
11. Contact
Email: contact@keyproof.app
Company: Cedarline Technologies LLC
This policy is governed by the laws of the State of Florida, United States.