Privacy Policy
Effective 2026-08-08
This Privacy Policy explains what SealMove collects, why, and what control you have over it.
1. What we collect
- Walkthrough content: photos, video, condition notes, room names, and property details (address, city, state, ZIP) you enter — stored on your device, and additionally on our servers only if you choose to share or back up a report.
- Signatures and verification data: device-generated cryptographic signatures and hashes over your captures — not biometric data itself, which never leaves your device's Secure Enclave.
- Account identity (Move-Out only): if you sign in with Apple to unlock Move-Out, we store Apple's stable, app-scoped identifier for your account plus your free-allowance and purchase-credit counters. We do not request or store your name or email address, regardless of what you choose to share with Apple during sign-in.
- Purchase records: StoreKit transaction identifiers, to credit purchases and support restoring an interrupted purchase.
- Link acknowledgment records: when someone acknowledges a shared report, we store the name they typed, the acknowledgment time, a one-way hash of their browser's user-agent string, and a coarse country code — not the raw user-agent string and not their IP address.
- Device attestation material: data used by Apple's App Attest to confirm requests come from a genuine copy of the app — this does not identify you personally.
2. What we don't collect
We don't request your real name or email through Sign in with Apple, don't collect precise location beyond what you choose to attach to a walkthrough, don't store raw IP addresses or user-agent strings for link acknowledgments, and don't use third-party advertising trackers.
3. Data about people who aren't SealMove users
If you enter information about another person — most commonly a landlord or tenant's name or a property address — that information is stored as part of your report. That person may not be a SealMove user and may not know their information was entered. If you are that person and want information about you removed from a report you're not the account holder for, contact us at the address below and we will evaluate the request.
4. How we use data
To operate the app's core features: rendering and comparing your walkthroughs, generating reports, hosting shared links, verifying purchases, and preventing abuse of the free-allowance and attestation systems. We do not sell your data.
5. Who we share data with
We use Apple (Sign in with Apple, StoreKit purchase verification, App Attest) and Cloudflare (hosting, storage, and database infrastructure for shared reports) as service providers. They process data on our behalf under their own privacy and security commitments; we don't share your data with anyone else, and never for advertising purposes.
6. Retention and deletion
- On-device data (your own captures and reports) stays on your device until you delete the app. There is currently no in-app way to delete a single finished walkthrough — see the callout below.
- Hosted reports are retained for up to 36 months from upload, then automatically deleted, regardless of acknowledgment status.
- Before a shared report is acknowledged, its owner can delete or revoke it at any time.
- After acknowledgment, a report cannot be deleted early through the app — see "Evidence is not retractable" in the Terms of Use for why. If you believe your data should be removed despite this — for example because you're a non-user third party, or because of a legal requirement that applies to you — contact us at the address below and we will evaluate the request individually.
docs/legal-privacy-review-packet.md for the open questions.7. Security
Captures are signed using a key held in your device's Secure Enclave. Requests to our backend are protected by Apple's App Attest where applicable. Hosted report access uses a separate, revocable viewer token rather than exposing a predictable report identifier as a bearer secret. No system is perfectly secure, and we can't guarantee absolute security.
8. Children's privacy
SealMove is not directed at children and is not intended for use by anyone not eligible to enter a rental agreement or its equivalent.
9. Your choices
You can decline to share a report, decline to sign in (Move-In stays fully usable without an account), revoke or rotate a shared link's access token at any time before acknowledgment, and delete the app to remove all on-device data. For anything else — access, correction, or deletion requests — contact us below.
10. Changes to this policy
We may update this policy as the product changes. Material changes will require re-acceptance in the app.
11. Contact
Privacy questions or requests: contact@sealmove.com.