Privacy Policy
Last updated: 4 June 2026
1. Introduction
1.1 This Privacy Policy explains how Drophouse Ltd collects and uses information when you use the Sight Buddy mobile application.
1.2 Drophouse Ltd is the data controller for personal data processed through the App.
2. Contact Details
2.1 Drophouse Ltd
2.2 5 Brayford Square, London E1 0SG
2.3 Company number: 17182597
2.4 Email: contact@drophouse.uk
3. Who this policy applies to
3.1 This policy applies to anyone who downloads or uses Sight Buddy.
3.2 The App is an accessibility aid for people with low or no vision.
3.3 We do not require you to create an account or provide your name or email to use the App.
4. Summary of Data Practices
4.1 We do not use user accounts. We do not show advertisements. We do not use behavioral analytics.
4.2 Camera, microphone, and most vision features (object finding, light/colour scan, on-device text recognition) run on your phone unless you use LLM chat features.
4.3 We provide a setting to turn off LLM chat features if desired.
4.4 If enabled, text, images, and voice-command text may be sent via our servers to OpenAI for AI-assisted answers.
4.5 Feedback you choose to send is anonymous and used only to fix bugs and improve the App.
4.6 App may send crash diagnostics to Firebase Crashlytics. We use these diagnostics only to help us fix stability issues.
4.7 You can delete server-side quota and feedback linked to your device identifier from Settings. LLM chat is blocked for two days after deletion.
4.8 During open beta, Manage plan lets you view tiers and record plan interest (device identifier and tier only). This is not billing and does not charge you.
5. Information we process
5.1 Information processed on your device. The following data stays on your phone unless you use cloud features.
5.2 Camera images are used for finding objects and reading text. Microphone audio is used for voice commands.
5.3 Recognized text is processed locally by Google ML Kit. App settings are stored in your private device storage.
5.4 A record of your terms acceptance is stored only on your device.
5.5 Pseudonymous device identifier. The App uses a technical ID derived from your Android device. This ID is not your name or Google account.
5.6 We use it to manage daily AI limits and link your feedback.
5.7 LLM chat features. LLM chat features are enable by default. When using these features the App sends data to our proxy.
5.8 This proxy forwards it to OpenAI. We use the gpt-4o-mini model. Document chat sends extracted text and your questions.
5.9 Image chat sends a downscaled camera image and your questions. Voice commands send the text of your speech.
5.10 Metadata includes your device ID and timestamps. OpenAI does not use data sent via our API to train their models.
5.11 They delete this data within thirty days for security compliance.
5.12 Feedback. You can submit anonymous feedback through the App. We receive the text you type and your device ID.
5.13 We use this only to fix bugs and improve the service. We do not sell this data.
5.14 Crash and diagnostic data. Production builds use Firebase Crashlytics. This collects crash logs and device models to help us fix errors.
5.15 We do not use this for behavioral tracking.
5.16 Delete data. If you use Delete data in Settings, we receive a request with your device identifier and remove server-side quota records and feedback linked to that identifier. We apply a two-day restriction before LLM chat can be used again. Data stored only on your device is not removed by this action.
5.17 Manage plan (open beta). If you choose a tier in Manage plan, we receive your device identifier and the tier name (for example Lite, Standard, or Pro) to record interest during the open beta. We do not receive payment card or bank details through this feature because payments are not enabled in the open beta.
6. How we use your information
6.1 We process data to provide the App functions.
6.2 We process data to provide cloud AI answers. We process data to enforce daily usage limits.
6.3 We process data to fix bugs through feedback. We process data to maintain stability through crash reports.
6.4 We process delete-data requests to honour your rights and enforce the post-deletion LLM restriction. We process plan-interest selections to understand open-beta demand before paid plans launch.
6.5 Our legal bases are contract and legitimate interests.
7. Third party services
7.1 Supabase hosts our database and proxy functions. OpenAI provides the AI models for cloud features.
7.2 Google provides crash reporting and on device text recognition. Android provides the speech recognition service.
7.3 We do not authorize these providers to use your data for their own marketing.
8. International transfers
8.1 Our providers process data in the UK and the EEA and the USA.
8.2 Content sent to cloud AI features is processed in the USA.
8.3 We use standard contractual clauses to protect your data during these transfers.
9. Retention
9.1 Settings and session data are kept until you uninstall the App.
9.2 Device ID records are deleted after one year of inactivity.
9.3 Feedback submissions are automatically deleted one year after you send them.
9.4 Crashlytics data is kept for up to ninety days by Google.
9.5 Cloud AI content is not stored by us as a persistent history.
9.6 When you use Delete data, we delete or anonymise server-side quota and feedback for your device identifier without waiting for the one-year feedback retention period.
9.7 Open-beta plan interest records are kept until we no longer need them for product planning or until you delete server-side data, whichever comes first.
10. Security
10.1 We use encrypted transport for all data. We use server side API keys so they are not in the App code.
10.2 We limit access to our database. No system is completely secure but we take appropriate steps to protect your data.
11. Your rights
11.1 You have rights under UK and EU GDPR.
11.2 These include the right to access and delete or correct your data.
11.3 You can object to processing or withdraw your consent. You can complain to the Information Commissioner Office in the UK.
11.4 You can also complain to your local data protection authority in the EU.
11.5 We may need your device ID to find your data because we do not use accounts.
11.6 You can use Delete data in Settings to remove server-side quota and feedback without contacting us. You can also contact us at contact@drophouse.uk for other rights requests.
12. Children
12.1 Sight Buddy is not directed at children under thirteen. we do not knowingly collect data from children.
12.2 Contact us if you believe a child has provided data so we can delete it.
13. Permissions
13.1 The App asks for camera and microphone access. It may also ask for internet access and haptic feedback.
13.2 You can turn these off in your device settings. Some features will stop working if you do this.
14. Changes to this policy
14.1 We update this policy from time to time.
14.2 We will post the new version on our website. We will update the date at the top of this page.
14.3 Using the App after changes means you accept the new policy.
15. Other documents
15.1 Use of Sight Buddy is also subject to our Terms of Use.
15.2 This Privacy Policy prevails for all privacy matters.