RN
RepairNode
Back to home
Legal

Privacy Policy

Effective date: April 27, 2026  ·  Last updated: May 27, 2026

Short version: RepairNode keeps your shop records on your device unless you explicitly enable encrypted Google Drive backup, public repair/order tracking, optional privacy-safe diagnostic reports, or intentionally share/export content through external apps. Subscription purchases and entitlement checks are handled through Apple, Google, and RevenueCat. We do not run advertising analytics, profile your customers, or sell your data.

1. Information we collect

Data you enter into the app

RepairNode is an offline-first mobile app. All data you enter — customers (names, phone numbers, email addresses, physical addresses), repairs, parts orders, quotes, technicians, and shop settings — is stored exclusively in a SQLite database on your device. RepairNode does not send that business data to its own servers. It only leaves your device when you use optional cloud features described below, complete a paid subscription flow, or intentionally share/export content through your device's email, messaging, printing, or share tools.

Photos and signatures

Repair photos (before, during, after) and customer drop-off/pickup signatures are stored as files on your device's local storage. They are not transmitted to any server unless you have Google Drive photo backup enabled.

Device passcodes

If you record a device unlock PIN, password, or pattern for a repair job, it is stored in encrypted form in the local database using at-rest encryption.

Subscription information

If you purchase RepairNode Pro, billing is handled by the Apple App Store or Google Play Store, with entitlement verification managed through RevenueCat. Available packages may vary by store, region, platform, or current offering. We do not receive your payment card details or direct billing credentials.

Public tracking data

If you enable public tracking, RepairNode syncs a minimal repair or order status record tied to a random 32-character access key so your customer can open a single tracking page at tracking.repairnode.app. Customer names, customer contact details, payment data, notes, signatures, photos, and order supplier details are not included in that public record.

Optional diagnostic reports

If you enable diagnostic reports in the app, RepairNode may send crash reports and technical error details to help us fix stability problems. These reports are designed to exclude customer records, phone numbers, email addresses, device identifiers, tracking links, backup secrets, file paths, photos, signatures, and document contents.

2. How we use information

We use the information you enter solely to power the app's features:

  • Displaying and managing your customers, repairs, orders, quotes, and reports
  • Generating PDF invoices, receipts, and quote documents
  • Printing documents to connected label or thermal printers over your local Wi-Fi network
  • Handing off calls, emails, messages, PDFs, or shared files to the native apps or share targets you explicitly choose to use
  • Creating encrypted cloud backups in your personal Google Drive when you enable that feature
  • Sharing a repair or order status page with your customers when you enable public tracking
  • Checking your subscription status through RevenueCat
  • Diagnosing crashes and technical failures if you enable optional diagnostic reports

We do not use your data for advertising, analytics profiling, or any purpose unrelated to the features listed above.

3. Data storage & security

On-device storage

Your primary data store is a SQLite database on your device. Sensitive fields — customer contact details, technician contact details, and device passcodes — are encrypted at rest using AES-256-GCM before being written to the database. Older app versions used AES-CBC, and those legacy records remain readable for compatibility.

Backup encryption

When you create a Google Drive backup, the database is encrypted using AES-256-GCM with a key derived from your backup passphrase or recovery phrase via PBKDF2-HMAC-SHA256 (600,000 iterations). The encrypted file is stored in the private appDataFolder of your own Google Drive account — it is not accessible to other people or to RepairNode.

Backup secret storage

Your backup passphrase or recovery phrase is stored using platform secure credential storage such as Android Keystore or iOS Keychain protections. It is never transmitted over the network as plain text.

App access protection

RepairNode can optionally require device authentication through your operating system's biometric or device-credential prompt. The current app no longer uses a separate in-app PIN or security-question system.

Diagnostics redaction

When optional diagnostic reports are enabled, RepairNode sanitises crash and error reports before upload. Reports are intended to contain technical context such as stack traces, app version, platform, locale, and coarse workflow tags, while redacting customer records, contact details, tracking keys, backup secrets, file paths, document content, and similar sensitive values.

4. Third-party services

RepairNode integrates with the following third-party services or platforms. Some are entirely optional, while Apple / Google store providers are only involved if you install, purchase, or restore through their ecosystems.

Apple App Store / Google Play (platform-dependent) Distribution & billing

Used for app distribution, store billing, subscription renewal, purchase restore, and refund handling on the relevant platform. Apple or Google may process account, device, transaction, and receipt information under their own policies. Governed by Apple's Privacy Policy and Google's Privacy Policy.

Google Drive (optional) User-controlled

Used for encrypted cloud backup and restore. You must explicitly sign in with Google and enable backup. Data is stored in your own Google account's hidden app folder. RepairNode cannot access other Google Drive files. Governed by Google's Privacy Policy.

Supabase (optional) User-controlled

Used only when you enable public repair or order tracking. When enabled, a minimal repair or order status record is synced to an anonymous Supabase session and exposed through a bearer-style tracking link on tracking.repairnode.app. Customer names, customer contact details, payment details, and order supplier data are not included. Tracking records are automatically deleted after 3 months and can also be removed earlier when you delete the related record or purge tracking data. Governed by Supabase's Privacy Policy.

RevenueCat (Pro subscribers only) Subscription management

Used to verify and manage Pro subscription entitlements. RevenueCat receives an anonymous app user identifier, store purchase receipt data, and entitlement status from the App Store or Play Store. No customer records, repair data, or billing card details you enter into RepairNode are shared with RevenueCat. Governed by RevenueCat's Privacy Policy.

Google Sign-In (optional) User-controlled

Used solely to authenticate with your Google account for Google Drive backup access. We request only the minimum scopes required (Drive appDataFolder access). We do not read, store, or use your Google profile information beyond establishing the Drive connection. Governed by Google's Privacy Policy.

Sentry (optional) Diagnostics only

Used only if diagnostic reports are available in your build of the app and you explicitly enable them. Sentry receives crash reports, technical error details, stack traces, app version, platform, locale, and coarse workflow tags so we can fix stability problems. RepairNode redacts customer data and does not enable session replay, screenshots, advertising analytics, user profiling, or performance tracing by default. Governed by Sentry's Privacy Policy.

QZ Tray (optional) Local print bridge

Used only if you configure QZ Tray mode for thermal printing. QZ Tray runs on your own computer and receives print payloads from RepairNode over your local network so it can forward them to a locally connected USB printer. RepairNode does not route those print jobs through its own servers. Governed by QZ Tray's Privacy Policy.

5. Device permissions

Permission Purpose
Camera QR code scanning to look up repairs and orders. Also used to capture repair photos if you choose to add them.
Photo Library Selecting images for repair photo attachments and shop logo upload. Only accessed when you tap the relevant action.
Local Network Communicating with label printers and thermal printers on your local Wi-Fi network. No data is sent to the internet.
Internet Required only for Google Drive backup, public tracking sync (when enabled), subscription verification, and optional diagnostic reports. All offline features work without internet access.
Notifications Optional local reminders for overdue repairs and awaiting-pickup alerts. All notifications are generated locally — no push service is used.

6. Your rights & control

Because your data is stored on your own device, you have full control at all times:

  • Access: Your data is visible directly within the app and can also be exported when you choose.
  • Correction: Edit any customer, repair, order, or quote record directly within the app at any time.
  • Deletion: Delete individual records from their detail screens, or delete all data at once (see Section 7).
  • Portability: Export a full local backup as JSON or export selected business tables as CSV from the app at any time.
  • Backup control: Enable or disable Google Drive backup at any time and remove cloud backups from within the app.
  • Tracking control: Enable or disable public repair/order tracking globally. Deleting individual repairs/orders or using Delete All Data removes the corresponding remote tracking records; disabled tracking records also expire automatically under the retention policy.
  • Diagnostics control: Optional diagnostic reports can be turned on or off from the app's privacy settings whenever that feature is available in your build.

7. Data deletion

You can delete all your data at any time. No account cancellation or email required.

In the app: Use the Delete All Data action in Settings. This removes all customers, repairs, orders, quotes, technicians, photos, signatures, and settings from your device in a single irreversible action. If Google Drive backup or public tracking was enabled, the corresponding cloud data is also purged.

Uninstalling the app from your device also removes the local SQLite database and any files stored by RepairNode. Any Google Drive backups you created will remain in your Google Drive until you delete them manually or use the in-app cloud-cleanup actions before uninstalling. Files you previously exported or documents you already shared outside the app remain wherever you stored or sent them.

8. Children's privacy

RepairNode is designed for use by repair shop owners and employees, who are expected to be adults. The app is not directed at children under 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has used the app to enter personal data, you may delete all data using the method described in Section 7.

9. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for material changes, include a notice in the app's release notes. Your continued use of RepairNode after a change takes effect constitutes acceptance of the revised policy.

10. Contact

If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:

Product: RepairNode

Website: repairnode.app

Contact: repairnode.app/contact