Privacy Policy
Effective date: April 27, 2026 · Last updated: September 23, 2026
1. Information we collect
Data you enter into the app
RepairNode is an offline-first mobile app. All data you enter — customers (names, phone numbers, email addresses, physical addresses), repairs, parts orders, quotes, technicians, and shop settings — is stored in a SQLite database on your device by default. Core shop records are not transmitted to RepairNode services unless you enable an optional feature that requires the limited data described below. Data may also leave your device when you complete a paid subscription flow or intentionally share/export content through your device's email, messaging, printing, or share tools.
Photos and signatures
Repair photos (before, during, after) and customer drop-off/pickup signatures are stored as files on your device's local storage. They are not transmitted to any server unless you have Google Drive photo backup enabled.
Device passcodes
If you record a device unlock PIN, password, or pattern for a repair job, it is stored in encrypted form in the local database using at-rest encryption.
Subscription information
RevenueCat checks subscription availability and rights, including for non-purchasers. It processes anonymous app identifiers and relevant store purchase information, also used in dashboard reporting. RepairNode sends no shop records or payment card details to RevenueCat. RevenueCat Privacy Policy.
Public tracking data
If you enable public tracking, RepairNode syncs a minimal repair or order status record tied to a random 32-character access key so your customer can open a single tracking page at tracking.repairnode.app. The public page may include your shop name, business phone number, business email address, and business address so customers can contact the shop. Customer names, customer contact details, payment data, internal notes, signatures, photos, and order supplier details are not included in that public record.
Optional diagnostic reports
If you enable diagnostic reports in the app, RepairNode may send crash reports and technical error details to help us fix stability problems. These reports are designed to exclude customer records, phone numbers, email addresses, device identifiers, tracking links, backup secrets, file paths, photos, signatures, and document contents.
2. How we use information
We use the information you enter solely to power the app's features:
- Displaying and managing your customers, repairs, orders, quotes, and reports
- Generating PDF invoices, receipts, and quote documents
- Printing documents to connected label or thermal printers over your local Wi-Fi network
- Handing off calls, emails, messages, PDFs, or shared files to the native apps or share targets you explicitly choose to use
- Creating encrypted cloud backups in your personal Google Drive when you enable that feature
- Sharing a repair or order status page with your customers when you enable public tracking
- Checking your subscription status through RevenueCat
- Diagnosing crashes and technical failures if you enable optional diagnostic reports
We do not use your data for advertising, analytics profiling, or any purpose unrelated to the features listed above.
3. Data storage & security
On-device storage
Your primary data store is a SQLite database on your device. Sensitive fields — customer contact details, technician contact details, and device passcodes — are encrypted at rest using AES-256-GCM before being written to the database. Older app versions used AES-CBC, and those legacy records remain readable for compatibility.
Backup encryption
When you create a Google Drive backup, the database is encrypted using AES-256-GCM with a key derived from your backup passphrase or recovery phrase via PBKDF2-HMAC-SHA256 (600,000 iterations). The encrypted file is stored in the private appDataFolder of your own Google Drive account — it is not accessible to other people or to RepairNode.
Backup secret storage
Your backup passphrase or recovery phrase is stored using platform secure credential storage such as Android Keystore or iOS Keychain protections. It is never transmitted over the network as plain text.
App access protection
RepairNode can optionally require device authentication through your operating system's biometric or device-credential prompt. The current app no longer uses a separate in-app PIN or security-question system.
Diagnostics redaction
When optional diagnostic reports are enabled, RepairNode sanitises crash and error reports before upload. Reports are intended to contain technical context such as stack traces, app version, platform, locale, and coarse workflow tags, while redacting customer records, contact details, tracking keys, backup secrets, file paths, document content, and similar sensitive values.
4. Third-party services
RepairNode integrates with the following third-party services or platforms. Some are entirely optional, while Apple / Google store providers are only involved if you install, purchase, or restore through their ecosystems. These providers process information under their own privacy policies and service terms. Where a provider processes data on behalf of RepairNode, we require it to protect that data consistently with this policy and applicable data-protection requirements.
Used for app distribution, store billing, subscription renewal, purchase restore, and refund handling on the relevant platform. Apple or Google may process account, device, transaction, and receipt information under their own policies. Governed by Apple's Privacy Policy and Google's Privacy Policy.
Used for encrypted cloud backup and restore. You must explicitly sign in with Google and enable backup. Data is stored in your own Google account's hidden app folder. RepairNode cannot access other Google Drive files. Governed by Google's Privacy Policy.
Optional public tracking stores a guest account and status records in Supabase. Anyone with the link can read device/item details, issue descriptions, status, dates and shop contacts. Customer contact fields, payments, private notes, photos, signatures and supplier details are excluded. Never enter personal information or secrets in public descriptions. Records expire after three months without updates. RepairNode does not log individual lookups in its diagnostic table. Cleanup diagnostics contain no user identifiers or tracking keys and are retained for up to 90 days. Supabase Privacy Policy.
RevenueCat checks subscription availability and rights, including for non-purchasers. It processes anonymous app identifiers and relevant store purchase information, also used in dashboard reporting. RepairNode sends no shop records or payment card details to RevenueCat. RevenueCat Privacy Policy.
Used solely to authenticate with your Google account for Google Drive backup access. We request only the minimum scopes required (Drive appDataFolder access) and do not read other Drive files. RepairNode stores the connected account's email address, display name, and profile-photo URL locally in secure device storage so the app can display and manage the backup connection. This profile information is not sent to RepairNode servers or used for advertising, analytics, or marketing. Governed by Google's Privacy Policy.
Used only if diagnostic reports are available in your build of the app and you explicitly enable them. Sentry receives crash reports, technical error details, stack traces, app version, platform, locale, and coarse workflow tags so we can fix stability problems. RepairNode redacts customer data and does not enable session replay, screenshots, advertising analytics, user profiling, or performance tracing by default. Governed by Sentry's Privacy Policy.
Used when you submit the RepairNode website contact form. Formspree may process your name, email address, subject, message, IP address, browser metadata, and submission time as needed to deliver, secure, and manage your support request. Do not include customer records, passwords, recovery phrases, photos, signatures, or other unnecessary sensitive data. See Formspree Security and Privacy.
Used only if you configure QZ Tray mode for thermal printing. QZ Tray runs on your own computer and receives print payloads from RepairNode over your local network so it can forward them to a locally connected USB printer. RepairNode does not route those print jobs through its own servers. Governed by QZ Tray's Privacy Policy.
5. Device permissions
| Permission | Purpose |
|---|---|
| Camera | QR code scanning to look up repairs and orders. Also used to capture repair photos if you choose to add them. |
| Photo Library | Selecting images for repair photo attachments and shop logo upload. Only accessed when you tap the relevant action. |
| Local Network | Communicating with label printers and thermal printers on your local Wi-Fi network. No data is sent to the internet. |
| Internet | Required only for Google Drive backup, public tracking sync (when enabled), subscription verification, and optional diagnostic reports. All offline features work without internet access. |
| Notifications | Optional local reminders for overdue repairs and awaiting-pickup alerts. All notifications are generated locally — no push service is used. |
6. Your rights & control
Because your data is stored on your own device, you have full control at all times:
- Access: Your data is visible directly within the app and can also be exported when you choose.
- Correction: Edit any customer, repair, order, or quote record directly within the app at any time.
- Deletion: Delete individual records from their detail screens, or delete all data at once (see Section 7).
- Portability: Export a full local backup as JSON or export selected business tables as CSV from the app at any time.
- Backup control: Enable or disable Google Drive backup at any time and remove cloud backups from within the app.
- Tracking control: Enable or disable public repair/order tracking globally. Deletion requests remove the corresponding remote tracking records when confirmed online; incomplete cleanup remains pending. Records expire under the retention policy measured from their last update.
- Diagnostics control: Optional diagnostic reports can be turned on or off from the app's privacy settings whenever that feature is available in your build.
7. Data deletion
Delete All Data removes local business records and requests deletion of the guest account and published tracking records. Drive cleanup is optional. Offline or failed remote cleanup stays pending with status and Retry; minimal progress and necessary credentials remain until completion. Uninstalling prevents app-managed retries. Deletion does not cancel store subscriptions. App-owned temporary copies are cleaned up. Provider diagnostic and purchase records follow their retention policies and legal obligations. JSON and CSV exports are not encrypted and include sensitive information. Share and store them securely. Copies saved or shared outside this app must be deleted separately.
8. Children's privacy
RepairNode is designed for use by repair shop owners and employees, who are expected to be adults. The app is not directed at children under 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has used the app to enter personal data, you may delete all data using the method described in Section 7.
9. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page and, for material changes, include a notice in the app's release notes. Your continued use of RepairNode after a change takes effect constitutes acceptance of the revised policy.
10. Contact
If you have questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:
Product: RepairNode
Website: repairnode.app
Contact: repairnode.app/contact
Email: support [at] repairnode.app