Last updated: 2026-08-05 Product: Semper DIC Android app and optional cloud sync backend Contact: support mailbox configured as SUPPORT_EMAIL for the deployment
This policy describes personal data processed by Semper when you use the app and, if enabled, the Semper cloud backend. Analysis itself runs on-device; the cloud path is optional and only active when the app is built with an API base URL.
| Role | Who |
|---|---|
| App operator / controller | The organization that distributes your build and operates the GCP/Firebase project |
| Subprocessors (typical) | Google (Firebase Auth, Firestore, Google Drive, Firebase Crashlytics, Cloud Logging / Cloud Run), Resend (transactional email for access-request notifications) |
No large-language-model or generative-AI provider is integrated.
.dat / CSV) stored in a company Shared Drive under the Cloud Run service account — bytes are uploaded by the device directly to Drive, not through Cloud Run.audit_logs in Firestore record security-relevant actions (auth denials, approvals, deletes, exports). They intentionally retain the fact of actions after account erasure and do not store analysis content.| Purpose | Examples | Basis (typical) |
|---|---|---|
| Provide the product | Sign-in, sync, restore, quotas | Contract / legitimate interest |
| Access control | Pending approval, admin approve/revoke | Legitimate interest / compliance |
| Security | Device attestation, rate limits, audit | Legitimate interest |
| Reliability (server) | Cloud Logging, readiness probes | Legitimate interest |
| Reliability (app diagnostics) | Crashlytics / Analytics crash reports | Consent — opt-in, withdrawable in Settings |
| Support onboarding | Resend access-request mail | Legitimate interest |
Exact legal bases depend on your jurisdiction and the deploying organization’s policies; replace this section with counsel-approved language before public launch if required.
| Data | Retention |
|---|---|
| Firebase Auth account | Until you delete the account or an admin removes it |
| Firestore profile, devices, sessions, file docs | Until account/session erasure via the app/API |
| Drive artifacts | Deleted with session or account erasure (Shared Drive trash may retain per Workspace policy) |
| Crashlytics | Per Firebase project retention settings (UNKNOWN until verified in console) |
| Cloud Logging | Per GCP log retention (UNKNOWN until verified; default often 30 days) |
| Resend message content | Per Resend retention (UNKNOWN until verified) |
| Audit logs | Retained after erasure for security/compliance; not included in user export of analysis content |
Scheduled Firestore exports / PITR, where enabled, follow FIRESTORE_DATA_PROTECTION.md.
GET /v1/me/export, which returns profile, devices, and complete session manifests — complete: true is written last, so a truncated download is detectable.) Binary artifacts are downloaded via GET /v1/files/{id}/content (or the app Restore flow).DELETE /v1/sessions/{id} removes Drive folder + Firestore metadata for that analysis.DELETE /v1/me removes the Drive user subtree and Firestore user/session/device/file docs. Audit logs remain.Data is shared with subprocessors above to operate the service. It is not sold. Admin operators of your deployment can approve users and view operational logs according to project IAM.
TLS in transit (Cloud Run / Gateway), deny-all client Firestore rules (server SDK only), device attestation for high-consequence mutations, rate limits, security headers, and opaque client error bodies on Cloud Run. See CLOUD_ARCHITECTURE_GCP.md.
Semper is intended for professional / research use, not for children under 16 (or the applicable age of digital consent).
Material changes will update the “Last updated” date. Significant changes to cloud processing should be reflected in-app or in release notes.
Use the in-app support / help action or the configured support email for privacy requests (export, deletion, access questions).