Privacy Policy
Last updated: 11 September 2026
1. Introduction
1.1 This Privacy Policy explains how Drophouse Ltd handles information when you use the Sight Buddy mobile application (the “App”).
1.2 The short version: Sight Buddy has no backend of ours. We do not collect, store, or receive your images, audio, text, or usage data. The only information that reaches us is an anonymous crash report if the App crashes — and you can turn that off.
1.3 Drophouse Ltd is the data controller for the crash diagnostics described in section 9. Section 12 sets out our role, and yours, in more detail.
2. Contact details
2.1 Drophouse Ltd
2.2 5 Brayford Square, London E1 0SG, United Kingdom
2.3 Company number: 17182597
2.4 Email: contact@drophouse.uk
3. Who this policy applies to
3.1 This policy applies to anyone who downloads or uses Sight Buddy.
3.2 The App is an accessibility aid for people with low or no vision.
3.3 There is no sign-up. We do not ask for your name, your email address, or any other identifier, and the App does not create an account for you.
4. Summary of data practices
4.1 No accounts, no sign-up, no advertising, no analytics, and no behavioural tracking.
4.2 Object detection, printed-text reading (OCR), colour detection, light detection, and speech recognition all run on your device, unless you turn on optional OpenAI voice transcription (off by default — see 7.10).
4.3 We receive no images, no audio, no recognised text, and no usage data.
4.4 AI features are optional and require your own OpenAI API key. When you use them, your request goes directly from your device to OpenAI — it does not pass through us. This includes optional voice transcription, which sends recorded audio to OpenAI and is off by default (see 7.10).
4.5 If the App crashes, an anonymous crash report is sent to Google Firebase Crashlytics. You can turn this off at any time in Settings → Privacy → “Send crash reports”.
4.6 If you agree to the prompt, the App can download open-source speech-recognition model files from GitHub once.
4.7 Earlier beta versions (v1.x) used a cloud AI service routed through our own server. That service has been shut down and all data it held has been permanently deleted (see section 11).
5. No accounts, no servers of ours
5.1 Sight Buddy has no backend operated by Drophouse Ltd. There is no database of ours, no user account, no login, and no server-side profile of you.
5.2 We do not collect, store, or receive your images, audio, text, or usage data.
5.3 Because we hold no account and no identifier for you, we are not able to link activity in the App to you as an individual.
6. On-device processing
6.1 The following features run entirely on your device: finding objects, reading printed text (OCR), detecting colour, measuring light level, and speech recognition — the last of these unless you turn on optional OpenAI voice transcription (see 7.10).
6.2 Camera images and microphone audio are processed in memory on your device and are never uploaded by us. If you turn on optional voice transcription, your device sends that recorded audio directly to OpenAI; it still does not pass through any server of ours.
6.3 Your App settings, and the record that you accepted the Terms of Use, are stored in your device's private storage. They are removed when you uninstall the App.
7. Optional AI features use your own OpenAI key (BYOK)
7.1 AI features are optional. They work only if you choose to add your own OpenAI API key in Settings.
7.2 Your key is stored encrypted on your device only, using a non-exportable key held in the Android Keystore. It is never transmitted to us, and never to any third party other than OpenAI.
7.3 With no key saved, the App makes no AI requests at all.
7.4 When a key is saved, what can be sent directly from your device to OpenAI is photographs, extracted text, and, if you enable it, voice recordings — and each is sent only at the moment you ask for it:
- Image chat — the captured photo and your question.
- Text chat — the text extracted from the capture (not the image itself) and your question.
- Find objects — the phrase you spoke, and only when the App cannot match it to a known object on your device. No image is sent.
- Voice transcription — the audio you record with the Ask button, and only if you have turned on OpenAI speech recognition in Settings. This is off by default; see 7.10.
7.5 Everything else — object detection, reading text aloud, colour, and light — runs on your device and sends nothing. Speech recognition also runs on your device once the voice models are present, unless you turn on optional OpenAI voice transcription (see 7.10).
7.6 These requests are initiated by you, sent directly from your device to OpenAI, billed to your own OpenAI account, and governed by OpenAI's privacy policy and terms. Drophouse Ltd neither receives nor stores their content. See OpenAI's privacy policy.
7.7 Please be aware: while using the AI features, do not point the camera at information you do not wish to send to OpenAI.
7.8 You can remove your key at any time in Settings. Removing it disables all AI features.
7.9 Removing the key from Sight Buddy — or uninstalling the App — deletes only the copy stored on your device. The key itself belongs to your OpenAI account and stays active there until you revoke it yourself at platform.openai.com/api-keys. We never receive your key, so we cannot deactivate it for you.
7.10. Voice transcription (optional)
If you turn on OpenAI speech recognition in Settings, audio you record with the Ask button is sent to OpenAI for transcription using your own API key. This setting is off by default and is never enabled without your explicit consent. When it is off, speech is processed by your device's built-in recogniser or by the optional on-device voice models, and no audio leaves your phone. OpenAI processes API audio under its API data usage policy: it is not used to train models, and is retained for up to 30 days for abuse monitoring before deletion. This is OpenAI's current policy and may change in the future. You can turn this off at any time in Settings, and doing so stops any further audio being sent.
8. One-time voice model download
8.1 On first use, and only if you accept the prompt, the App can download open-source speech-recognition model files (about 154 MB) from GitHub.
8.2 This is a plain file download. We receive nothing from it. That connection is governed by GitHub's privacy statement.
8.3 The download is never automatic, and the App works without it — speech recognition falls back to your device's built-in recogniser until the files are present.
8.4 These voice models recognise English speech only. This section therefore applies if you use the App in English; in other languages the download is not offered, and speech recognition uses your device's built-in recogniser, or OpenAI transcription if you turn it on (see 7.10).
9. Crash diagnostics (Firebase Crashlytics)
9.1 If the App crashes, an anonymous crash report is sent to Google Firebase Crashlytics so that we can find and fix the fault.
9.2 A report contains a stack trace, your device model, your operating system version, and the App version. It does not contain your name, your email address, your images, your audio, or your text.
9.3 No advertising ID, no analytics, and no behavioural tracking. The App does not use Google Analytics, and advertising-ID permissions are stripped from the App at build time.
9.4 You can turn crash reporting off at any time in Settings → Privacy → “Send crash reports”.
9.5 Crash reports are processed by Google. See Google's privacy policy and Firebase's privacy information.
10. Google Play
10.1 Google provides us with aggregate install and performance statistics as the operator of the Play Store, in accordance with the Google Play terms.
10.2 These statistics are aggregated and do not identify you to us.
11. Historic data from earlier beta versions
11.1 Earlier beta versions (v1.x) used a cloud AI service routed through a server of ours, together with a pseudonymous device identifier, daily usage quotas, and an anonymous feedback channel.
11.2 That service has been shut down, and all data it held has been permanently deleted.
11.3 The current version of the App sends no data to any server operated by us.
12. UK GDPR and EU GDPR
Sections 12.1 to 12.8 set out how UK and EU data-protection law applies. Section 12.9 covers users in other countries.
12.1. Who the controller is
Drophouse Ltd (UK) is the controller for the crash diagnostics described in section 9.
For AI requests, you are effectively in control: you supply your own OpenAI API key, you trigger each request, and the data goes to OpenAI under your own OpenAI account and OpenAI's terms. Drophouse Ltd neither receives nor stores that content.
12.2. Lawful basis
Crash diagnostics are processed under legitimate interests (Article 6(1)(f)) — keeping the App stable and safe for the people who depend on it — and are limited to anonymous, pseudonymous technical data.
No special-category data is processed. No advertising or analytics processing takes place, so no consent banner is required.
12.3. What we hold
Essentially nothing: no accounts, no contact details, no images, no audio, and no usage profiles. Crash reports are pseudonymous and are retained by Firebase Crashlytics in line with Google's retention period, typically 90 days.
12.4. Your rights
You have the right of access, rectification, erasure, restriction of processing, objection, and data portability, and the right to complain to a supervisory authority — the Information Commissioner's Office (ICO) in the United Kingdom, or your national data protection authority in the European Union.
We should be straightforward about one practical limit: because we hold no account and no identifier linking a person to a crash report, we may be unable to locate data relating to a specific individual. You can stop all crash reporting by turning it off in Settings, or by uninstalling the App. Any data held by OpenAI in connection with your own API key can be deleted through your own OpenAI account.
12.5. International transfers
Crash diagnostics are processed by Google (Firebase), and the AI requests you initiate are processed by OpenAI. Both may process data outside the United Kingdom and the EEA under their own safeguards, such as standard contractual clauses or adequacy decisions.
See Google's privacy policy and OpenAI's privacy policy.
12.6. Right to object and opt out
You can turn crash reporting off at any time in the App: Settings → Privacy → “Send crash reports”. This is available in version 2.1.0 and later.
Because the App carries out no advertising, analytics, or behavioural tracking, there is nothing further to opt out of. AI features send nothing unless you have added your own key and asked for an answer.
12.7. Contact
Privacy enquiries: contact@drophouse.uk.
12.8. EU representative
Drophouse Ltd relies on the Article 27 exemption for occasional, low-risk processing and has not appointed an EU representative.
12.9. Users in other countries
Sight Buddy is available worldwide. Drophouse Ltd is based in the United Kingdom, and we apply the standards in this policy — written around UK and EU GDPR — to everyone as a baseline, wherever you use the App.
Because we operate no backend and hold essentially no personal data (only the anonymous, optional crash reports described in section 9), there is very little for any national data-protection law to reach. We do not sell or share personal data, we do not use it for advertising, and we hold no account or identifier that links a person to a crash report.
Depending on where you live, you may have additional rights under your own local law — for example the CCPA/CPRA in California and other US state privacy laws, the DPDP Act in India, or the KVKK in Türkiye. In practice the same controls apply to everyone: turn crash reporting off in Settings → Privacy → “Send crash reports”, uninstall the App to stop it entirely, and manage any data held by OpenAI through your own OpenAI account. The international-transfer safeguards in 12.5 apply to all users.
13. Retention
13.1 Your App settings and your acceptance record remain on your device until you uninstall the App.
13.2 Your OpenAI API key remains encrypted on your device until you remove it in Settings or uninstall the App.
13.3 Crash reports are retained by Firebase Crashlytics in line with Google's retention period, typically 90 days.
13.4 We hold no other data, so there is nothing else for us to retain or delete.
13.5 Content you send to OpenAI is handled under OpenAI's own retention policy and the settings of your OpenAI account.
13.6 Voice recordings sent for optional transcription are not stored by Sight Buddy at all. OpenAI retains API audio for up to 30 days for abuse monitoring before deleting it, and does not use it to train its models. This is OpenAI's current policy and may change in the future.
14. Security
14.1 Your OpenAI API key is encrypted at rest using AES-GCM with a non-exportable key held in the Android Keystore, hardware-backed where your device supports it.
14.2 All network connections made by the App use encrypted transport (HTTPS/TLS).
14.3 The App is open source, so its handling of your data can be independently inspected: github.com/DrophouseLtd/SightBuddy.
14.4 No system is completely secure, but we take appropriate steps to protect your data — the most effective of which is not collecting it.
15. Children
15.1 Sight Buddy is not directed at children under 13, and we do not knowingly collect data from children.
15.2 Because we operate no servers and hold no accounts, we do not hold personal data about any user, including children. If you have a concern, contact us at contact@drophouse.uk.
16. Permissions
16.1 The App asks for camera and microphone access, and uses internet access and vibration (haptic feedback).
16.2 You can turn these off in your device settings. Some features will stop working if you do.
16.3 The App does not request location, contacts, or an advertising ID.
17. Changes to this policy
17.1 We update this policy from time to time.
17.2 We will post the new version on our website and update the “Last updated” date at the top of this page.
17.3 Using the App after changes take effect means you accept the updated policy.
18. Other documents
18.1 Use of Sight Buddy is also subject to our Terms of Use.
18.2 This Privacy Policy prevails for all privacy matters.