Legal

Privacy Policy

Pruuf · The ScoutsOn Watch Company · Last updated 12 August 2026

Who we are

Pruuf is published by The ScoutsOn Watch Company. “We” and “us” below mean that company.

The short version

Pruuf stores your first name, the time of day you’ve chosen to check in, and a list of who is connected to you. It does not read your messages or show you advertising. There are no accounts and no passwords.

Pruuf does not track you. If the person checking in chooses to, Pruuf records where they were at the moment they tapped — once, then it stops looking — so their family can find them if they ever ask for help. It is off in two taps, it is never on in the background, and every location is deleted after 24 hours.

What we collect

A first name. Whatever you type when you set up. It can be a nickname. It is shown to the family members connected to you so they know whose check-in they’re seeing.

Your check-in time and time zone. So we know when a missed check-in should trigger an alert.

A record of your check-ins. The date and time you tapped the button.

A record of help requests. If you tap “I need help”, we store the time you tapped it and whether it was sent or cancelled, so the app knows whether your loved ones still need to be alerted.

An anonymous account identifier. Created automatically when you first open the app. It is a random identifier. It is not linked to your email, phone number, Apple ID, or any advertising identifier.

A push notification token, if you allow notifications. This is what lets Apple deliver a notification to your device. We store it so we know where to send alerts. One token is stored per device, so an alert reaches your iPhone, your iPad and your Apple Watch rather than only the last one you set up.

A record of each device you use Pruuf on. When you add a second device we store, for that device: a random identifier, whether it is an iPhone, iPad, Apple Watch or Mac, the device name iOS reports for it, and the date it was added. This is what the “My devices” screen shows you, and it is what lets you sign a device out.

The device name comes from Apple and, for apps like ours, is the model name — “iPad Pro 13-inch”, not “Margaret’s iPad”. We do not request the entitlement that would reveal your personal device name, and we collect no hardware identifier, serial number, IMEI, or advertising identifier.

A pairing secret, stored in your own iCloud. So a new iPhone or iPad signed in to the same Apple ID can join your existing account without you typing anything, Pruuf saves one random string to Apple’s iCloud key-value storage. That storage belongs to you and your Apple ID; we cannot read it, and nothing else is ever put there. If you have iCloud turned off, nothing is stored and you add devices with a six-character code instead.

Who is connected to whom. The link between a person checking in and the people receiving their check-ins.

If you write to us through this website: the name, email address and message you type into the contact form, so that we can reply. We also store a one-way hash of your IP address — not the address itself — purely so that one source cannot flood the form. The form posts to our own servers; it is not a third-party form service, and nothing you write is passed to anyone else. We delete these messages once the conversation they belong to is finished, and you can ask us to delete yours sooner.

What we do not collect

  • Your location, unless you switch it on. This is the one thing on this page that changed, so it is spelled out rather than softened. If the person checking in chooses to share it, Pruuf records a single position at the instant they tap I’M OK or I NEED HELP — whichever they chose — and nothing between those moments. There is no background location, no history of where anybody goes, and no way for us or anyone else to ask the app where somebody is now. Only the people they have added can see it, and every position is deleted after 24 hours. The switch is in Settings under “Share My Location”, it is explained during setup before an account exists, and turning it off changes nothing else about how Pruuf works.
  • Your contacts. When you add a family member, the app opens Apple’s contact picker and uses the name and number you select to pre-fill a text message and to offer a call button. That information is never sent to us. It is stored on your device and synced through your own iCloud account — so if you use Pruuf on an iPhone and an iPad you only add it once — which means it is covered by Apple’s encryption and your Apple ID, and never by us. We have no way to read it.
  • Your email address or phone number — unless you give us an email address by writing to us.
  • Any health, fitness, or medical data.
  • Analytics, advertising identifiers, or behavioural data. There are no third-party advertising or analytics SDKs in this app, and none on this website either — no cookies are set by it, no fonts or scripts are loaded from anybody else’s servers, and there is nothing here that would need a cookie banner.

How we use it

Only to make the app work:

  1. To send a notification to your loved ones when you check in.
  2. To send an alert to them if you have not checked in by your chosen time.
  3. To send an alert if you tap the help button.
  4. To show you and them the current status.

We do not sell your data. We do not share it with advertisers, data brokers, or any third party for their own purposes.

Where it’s stored

Data is stored on servers operated by Supabase, which hosts our database in the United States. Push notifications are delivered through Apple’s Push Notification service. Both process this data on our behalf in order to provide the service.

How long we keep it

We keep your information for as long as you use the app. Check-in records are kept so the app can show whether you’ve checked in today.

Deleting your data

In the app: open Settings (the gear in the top corner) and choose Delete my account. This immediately and permanently removes your profile, your check-in history, your help requests, every connection between you and your loved ones, and the record of every device you had signed in. It cannot be undone, and it takes effect for all your devices at once, not just the one you did it on.

Removing a single device: Settings → My devices → the ⊖ next to it. That device stops receiving alerts and is forgotten; your account and everyone connected to you are unaffected.

You can also email wesleymwilliams@gmail.com and we’ll do it for you within 30 days.

Note that deleting the app from your phone does not by itself remove your data from our servers, because the account is anonymous and tied to the app installation. Use Delete my account first if you want it gone.

Children

Pruuf is not directed at children and we do not knowingly collect information from anyone under 13.

Security

There are no passwords. Pruuf has no accounts, usernames or password resets, so there is no credential of yours to leak, phish, or reuse against you on another site. Two people are connected by a six-character code that grants nothing else.

Check-ins are signed on the device that makes them. Each install holds a private key created inside Apple’s Secure Enclave, which cannot be exported, copied to another device or recovered from a backup. We verify the signature before recording a check-in as verified — so a verified check-in could not have been produced by anybody not holding that unlocked device, ourselves included. Where signing is unavailable the check-in is still recorded, unsigned; being told about a missed day matters more than being able to prove one.

Access is restricted by row-level security inside the database itself, keyed to the account making the request, so one person’s data is not returned to another — a rule the database enforces rather than one our application code has to remember.

Traffic between the app and our servers is encrypted with TLS, and stored data is encrypted at rest.

We do not offer end-to-end encryption, and we will say why. Our servers must be able to see that a check-in did not arrive, or they could not alert anyone — which is the entire purpose of Pruuf. Anybody offering both server-side alerting and end-to-end encryption is describing something that cannot work.

No system is perfectly secure, and we cannot guarantee absolute security. A fuller description of how this works is at thepruuf.com/security.

An important limitation

Pruuf is not a medical alert device. The help button notifies the people you have added — nobody else is told, and nothing is dispatched.

Notification delivery depends on Apple’s service, on internet connectivity, and on the recipient’s phone and notification settings — none of which we control. Do not rely on Pruuf as the only way of knowing whether someone is safe.

Changes

If this policy changes we’ll update the date at the top of this page.

Contact

The ScoutsOn Watch Company · wesleymwilliams@gmail.com · write to us