Pruph

Privacy Policy

EFFECTIVE 28 JULY 2026

This Privacy Policy describes how Pruph ("Pruph," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the Pruph mobile application (the "App").

Pruph organises tickets, reservations, bookings, and event confirmations so that they are available when you need them. This includes concert and event tickets, flights, trains and buses, hotel bookings, restaurant reservations, museum and attraction passes, conference passes, parking passes, and event invitations.

By using the App, you agree to the collection and use of information in accordance with this Policy. If you do not agree, please do not use the App.

1. Information We Collect

1.1 Information you provide directly

When you add or edit an event manually, we collect the information you enter, including event names, dates, times, venues, addresses, confirmation numbers, and seating details.

1.2 Photo library information

With your permission, the App accesses screenshots stored in your device's photo library in order to identify tickets, reservations, and confirmations.

Each screenshot is analysed locally on your device before any transmission occurs. The App evaluates whether the image contains characteristics consistent with a ticket or reservation, including a barcode or machine-readable code, a confirmation or booking reference, a future date and time, and a venue or location. Images that do not meet these criteria are discarded on the device and are not transmitted to us or to any third party.

The App does not access photographs created before you grant permission unless you expressly request that it do so. This setting may be changed at any time within the App.

1.3 Gmail message information

If you elect to connect a Google account, the App requests read-only access to your Gmail messages using the https://www.googleapis.com/auth/gmail.readonly scope.

The App does not download or index the contents of your mailbox. It issues targeted queries limited to messages likely to constitute booking or reservation confirmations, identified by sender domain and by subject-line characteristics. Personal correspondence, professional correspondence, and promotional messages outside these criteria are not retrieved.

1.4 Location information

If you grant location permission, the App uses your device's location to display a relevant ticket when you approach an associated venue. Location data is processed entirely on your device and is not transmitted to us or to any third party.

1.5 Account information

An account is optional for the core features of the App. You may identify, organise, search, edit, and access your events offline without signing in.

An account is required for features that depend on our systems, namely connecting a Gmail account, backing up your events, and synchronising them across devices.

You may create an account using Sign in with Apple or Sign in with Google. In either case, authentication is handled by the respective provider, and we do not receive or store your password.

From these providers we receive a unique identifier and an email address. If you use Sign in with Apple and elect to hide your email address, Apple provides an anonymised relay address rather than your actual address, and we receive only the relay address.

Sign in with Google is used solely to establish an account and is distinct from the Gmail access described in Section 1.3. Establishing an account does not by itself grant the App access to your email; Gmail access requires a separate and explicit authorisation, which you may decline or revoke at any time without affecting your account.

1.6 Backup and synchronisation data

If you create an account, your event records and associated images may be stored on our systems in order to restore them to a new device or to synchronise them across your devices. This is described further in Section 5.

1.7 Information we do not collect

We do not collect passwords, payment card details, contacts, device identifiers used for advertising, or analytics regarding your use of the App.

2. How We Use Information

We use the information described above solely to:

(a) identify tickets, reservations, and confirmations among your screenshots and email messages;

(b) extract event details, including event name, date, time, venue, address, confirmation number, and seating information;

(c) organise those events chronologically and make them available offline on your device;

(d) notify you in advance of an upcoming event, and display the relevant ticket when you approach the associated venue;

(e) where you have created an account, authenticate you, back up your events, and restore or synchronise them across your devices;

(f) where you have separately and affirmatively opted in, send you occasional messages regarding the App. Signing in does not by itself constitute consent to receive such messages, and you may withdraw consent at any time.

We do not use your information for advertising, profiling, or any purpose unrelated to the functionality described in this Policy.

3. Disclosure of Information

3.1 Service providers

To extract event details from a ticket image or confirmation email, the relevant content is transmitted to Anthropic, PBC ("Anthropic"), which processes it and returns structured event information. Transmission occurs through infrastructure operated by Cloudflare, Inc. ("Cloudflare"), which routes the request and does not retain its contents.

Content is transmitted only after an image has satisfied the on-device evaluation described in Section 1.2, or where an email message has been identified as a confirmation under Section 1.3. Anthropic does not use content submitted through its commercial API to train its models.

Where you create an account, authentication is performed by Apple Inc. or Google LLC, as applicable. These providers process your credentials under their own privacy policies, and we do not receive your password.

3.2 No sale or sharing of personal information

We do not sell your personal information, and we do not share it with third parties for cross-context behavioural advertising or any similar purpose. We do not disclose your information to advertisers, data brokers, or analytics providers.

3.3 Legal disclosure

We may disclose information where required to do so by law, regulation, legal process, or enforceable governmental request. Because we do not retain email message content, and retain event data only where you have created an account, the information available for such disclosure is limited.

4. Limited Use of Google User Data

The App's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

(a) Google user data is used only to provide and improve the user-facing features described in this Policy;

(b) Google user data is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior notice to affected users;

(c) Google user data is not used for advertising purposes;

(d) no human reads Google user data except with your affirmative agreement for specific messages, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymised.

5. Data Retention and Storage

Event records, associated images, barcodes, and confirmation numbers are stored locally on your device. Your device is the authoritative repository for your event data.

Without an account, this is the sole repository. We do not retain your tickets, reservations, email content, or photographs on any system. Content transmitted for extraction under Section 3.1 is not retained following processing.

With an account, event records and associated images are additionally stored on our systems in encrypted form for the purpose of backup and synchronisation. This data is retained while your account remains active and is deleted when you delete your account, as described in Section 6.

Email message content is never retained on our systems, whether or not you have an account.

Access tokens are stored in the iOS Keychain on your device, encrypted by the operating system, and are not transmitted to us.

6. Your Rights and Choices

Access and permissions. You may grant or revoke photo library, location, and notification permissions at any time in iOS Settings.

Disconnecting Google. You may disconnect your Google account at any time within the App, which revokes the App's access token. You may also revoke access directly at myaccount.google.com/permissions.

Communications. If you have opted in to receive messages about the App, you may withdraw consent at any time within the App or by using the unsubscribe link in any message. Withdrawing consent does not affect service messages necessary to operate your account.

Deletion. Deleting an event within the App removes that event and its associated images from your device, and from our systems where you have an account. Deleting the App removes all local event data, images, and settings.

Account deletion. You may delete your account at any time in Settings. Doing so permanently removes your account record, your email address, and any backed-up event data from our systems. This action cannot be reversed.

If you do not have an account, your data is stored on your device alone, and requests for access, correction, portability, or deletion are satisfied through the App itself, as we hold no copy to retrieve or erase on your behalf.

Residents of certain jurisdictions, including the European Economic Area, the United Kingdom, and the State of California, may have additional rights regarding personal information. Given that we do not retain personal information, these rights are ordinarily exercised directly through the App. Enquiries may be directed to the address in Section 10.

7. Security

We employ measures designed to protect information in transit and at rest, including transport-layer encryption for all network requests, storage of credentials in the iOS Keychain, and on-device evaluation that limits what is transmitted.

No method of transmission or storage is entirely secure, and we cannot guarantee absolute security.

8. Children's Privacy

The App is not directed at children under the age of 13, and we do not knowingly collect personal information from children under 13. If we become aware that we have inadvertently collected such information, we will take steps to delete it.

9. Changes to This Policy

We may update this Policy from time to time. Where changes are material, we will provide notice within the App prior to the change taking effect. The effective date at the top of this Policy indicates when it was last revised. Continued use of the App following the effective date constitutes acceptance of the revised Policy.

10. Contact

Questions, concerns, or requests regarding this Policy may be directed to:

[email protected]