Privacy policy
What the Groundtruth app collects, what stays on your phone, what our server stores, and who else touches your data — in plain language. We are based in New Zealand, and we handle personal information under the New Zealand Privacy Act 2020 and its thirteen information privacy principles.
The short version
- Your test data — depths, blow counts, GPS test locations, calibration, reports — lives on your device. We do not upload it to our server.
- The microphone is used to detect hammer blows. Audio is analysed in real time, in memory, on the device. It is never recorded to a file and never transmitted anywhere.
- Our server stores your account: email address, and the name and company you optionally add for your reports, plus sign-in session records.
- Account data is held in a managed PostgreSQL database in Google Cloud's Sydney, Australia region.
- We use a small number of service providers (listed below). We do not sell your data, we do not run ads, and we do not use advertising or cross-app tracking identifiers.
Who we are
Groundtruth is a field-testing app for geotechnical engineers, made by Groundtruth Technology Limited (NZBN 9429053791115), a New Zealand company registered at 61 Cornford Street, Karori, Wellington 6012, New Zealand. For anything in this policy, email info@getgroundtruth.app.
What stays on your phone
The app works offline, and everything you produce with it is stored locally on the device:
- DCP tests and projects — depths, blow counts, timestamps, test settings, and the estimated CBR configuration.
- Test-site locations — GPS coordinates and accuracy stamped onto a test, if you grant location permission (or a position you set manually on the map).
- Your blow calibration — the loudness and ring profile of your hammer, captured during calibration.
- Reports — the CSV files and PDF reports you generate, until you delete them.
- Preferences — units, increments, sensitivity, onboarding state, and the operator name and company you put on reports.
None of this is sent to our server. It leaves the device only when you export or share it (for example emailing a CSV or PDF), or in the two narrow cases described under Location and Service providers below. Deleting a test, a project, or the app deletes the local copy.
The microphone
Groundtruth listens for hammer blows during a live test and during calibration. The audio stream is processed sample-by-sample, in memory, on the device: the app filters the signal and derives per-blow numbers (a timestamp, a peak level, and how long the strike rang). Those derived numbers are all that is kept. Raw audio is never saved to a file, never stored, and never transmitted off the device — there is no recording to access or delete. Listening runs only while a test or calibration screen is active.
Location
If you grant location permission, the app takes a GPS fix to stamp a test site. The coordinates are stored with the test on your device. They are transmitted in exactly two cases, both driven by you:
- When you generate a PDF report with a satellite site map, the test coordinates are sent to Mapbox to render the map image.
- When you open the interactive test-location map, the map tiles are fetched from Mapbox, which sees the map viewport (and usage telemetry from its SDK on Android).
Location is optional — you can decline the permission and run every test without a geotag. We never track your location in the background, and coordinates are never associated with your account on our server.
What our server stores
Signing in is how the app knows who you are, and it is the only thing our server is for today. Sign-in is passwordless: you give us your email address, we email you a six-digit code, and you type it in. The server stores:
- Your account — your email address, an account identifier we generate, a link to the sign-in provider record, and the name and company you optionally add to your profile (they appear on your reports).
- Sign-in sessions — when each session was created and last used, whether it has been signed out, and a short device summary (like “Chrome on macOS”) so sessions are recognisable.
- Session tokens — stored only as cryptographic hashes, never the tokens themselves.
- Sign-in requests — the email address a code was sent to, a hash of the code (never the code itself), how many attempts were made, and when it was used. These records are kept to rate-limit sign-in attempts.
That is the complete list. Your tests, locations, calibration, and reports are not on our server.
Where your data is held
Account and session data lives in a managed PostgreSQL database (Google Cloud SQL) in the australia-southeast1 (Sydney) region, alongside the server that uses it. Because some of our service providers are global services, some data crosses borders — the table below says which. Under privacy principle 12 we only disclose personal information overseas to providers who are subject to comparable safeguards, and each provider below acts as our agent: it processes your data to provide its service to us, not for its own purposes.
Service providers
Every third party that receives any user data, and what it receives:
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Google — Firebase Identity Platform | Verifies you own your email address during passwordless sign-in. | Your email address; its own sign-in metadata (account creation and last-sign-in times, and the device IP address of each sign-in). | Global Google service; not region-pinned. |
| Google — Firebase Crashlytics | Collects crash reports so failures in the field are diagnosable. | Crash stack traces, screen names leading up to the crash, app state flags, and device metadata (model, OS version, locale, memory) keyed to an installation identifier — not to you. Nothing you typed, measured, or located is included. | Global Google service; not region-pinned. |
| Google — Play services (fused location) | Supplies GPS fixes on Android. | Nothing from Groundtruth — it is an on-device API. Google's network-assisted positioning is in the path of the device's own location. | Not applicable — no Groundtruth data transmitted. |
| Mapbox | Renders the interactive test-location map and the satellite map in PDF reports. | Test-site coordinates (as map pins), the map viewport, and SDK usage telemetry. | Mapbox-operated infrastructure; no region choice. |
| Resend | Delivers the sign-in code emails. | Your email address and the six-digit sign-in code (which expires after 10 minutes). | Resend-operated infrastructure; no region choice. |
That is every third party the app sends data to. We do not use analytics services, advertising networks, or data brokers.
This website
getgroundtruth.app itself sets no analytics cookies and runs no trackers. The one exception to "no third parties" here is the early-access signup form, which is provided by MailerLite: if you submit it, the email address you enter goes to MailerLite, which manages our early-access mailing list on our behalf. Every email we send through it includes an unsubscribe link, and you can ask us to remove you from the list at any time.
How long we keep it
- On your device — until you delete the test, project, or report, or uninstall the app. We hold no copy.
- Your account and sessions — for as long as you have an account. Deleting the account also deletes its sessions, token history, entitlements, and export-usage records.
- Sign-in requests — completed requests are retained separately from the account because they are how we rate-limit sign-in abuse. Deleting an account does not reset that history.
- Crash reports — expire on Firebase's own retention schedule; they are keyed to an installation identifier, not to your account.
- Provider logs — Mapbox and Resend retain request and delivery logs under their own policies.
Your rights
Under privacy principles 6 and 7 of the Privacy Act 2020 you can ask for a copy of the personal information we hold about you, and ask us to correct it. You can also delete your server account and the data that goes with it directly in the app: open Profile, choose Delete account, and confirm the permanent deletion. This deletes the account held by us and our sign-in provider; it does not delete tests, projects, reports, or other field records stored only on your device. You control those records on the device separately. You can also email info@getgroundtruth.app from the address on the account with an access, correction, or deletion request; we will confirm it is you and respond within 20 working days, as the Act requires.
If you think we have mishandled your information and we have not put it right, you can complain to the Office of the New Zealand Privacy Commissioner at privacy.org.nz.
How the Privacy Act shapes this
The Act's thirteen information privacy principles are the frame we work within: we collect only what the app needs and collect it from you directly (principles 1–4); we keep it secure — sign-in codes and session tokens are stored only as hashes, and connections are encrypted in transit (principle 5); you can access and correct it (principles 6–7); we use and disclose it only for what it was collected for (principles 9–11); overseas disclosure is limited to the providers above (principle 12); and the account identifier we assign you is our own, used for nothing else (principle 13).
Changes to this policy
When the app grows — team sync is on the roadmap, and it would change what our server stores — this policy will change with it. We will update this page and the date at the top, and for material changes we will tell you in the app or by email before they take effect.
Contact
Groundtruth Technology Limited (NZBN 9429053791115)
61 Cornford Street, Karori, Wellington 6012, New Zealand
info@getgroundtruth.app