Back to Privacy Hub

AdHocKit: Check-In & Equipment Privacy Policy

Last Updated: September 25, 2026

Quick Summary

AdHocKit is a local-first Android operations utility with optional Pro Shared Sync. Local workspaces stay in app-private storage by default; when a Pro organizer deliberately enables Shared Sync, selected workspace data is sent to AdHocKit's Supabase backend for authorized collaboration. Google Play handles lifetime Pro, while configured builds also include RevenueCat, Google Mobile Ads, and Google UMP for an optional user-initiated rewarded temporary-Pro path.

App-Specific Details

Specific data handling practices for AdHocKit: Check-In & Equipment.

  • Stores workspace, person/display-name, attendance, equipment/custody, claim, counter, operation, import, and locally decoded QR/CODE_128 data in app-private local storage.
  • Camera frames used for QR/CODE_128 scanning are processed locally and are not intentionally retained or uploaded.
  • When a Pro organizer enables Shared Sync, selected workspace data can be transmitted to Supabase for authentication, authorized collaboration, synchronization, realtime invalidation, server functions, and account deletion.
  • Organizer cloud sign-in uses email verification; staff may join with a temporary anonymous Supabase identity. Authorized invited staff can see workspace data deliberately shared into that workspace.
  • Google Play processes the one-time adhockit_pro purchase. For production Shared Sync authorization, a purchase token is verified by an authenticated server function; the raw token is processed transiently while bounded verification/fraud-prevention metadata is retained as described below.
  • The production dependency set includes RevenueCat, Google Mobile Ads, and Google UMP for an optional rewarded temporary-Pro path. AdHocKit does not intentionally include a behavioral analytics SDK or third-party crash-reporting SDK.
  • Android CAMERA is requested only for deliberate scanning and INTERNET is used for Billing, Shared Sync/Supabase, and the optional monetization services. AdHocKit does not request app-owned location, contacts, microphone, SMS, call-log, broad storage, accessibility, or foreground-service permissions for these features.
  • Operational Room data, local Pro state, and persisted auth/session preferences are excluded from Android cloud backup and device-to-device transfer. Cloud-account deletion and local-workspace deletion are separate controls.

Detailed Official Policy

Full technical and legal disclosure for AdHocKit: Check-In & Equipment.

# AdHocKit Privacy Policy Last updated: September 25, 2026 AdHocKit is a local-first Android utility for temporary real-world operations such as check-in, equipment custody, coat or bag claims, and counting. Core local workflows can be used without an AdHocKit cloud account or AdHocKit Pro. Optional **AdHocKit Pro** is a one-time Google Play purchase that unlocks **Shared Sync** for collaboration across authorized devices/users. ## Local data Depending on the tools you use, AdHocKit can store in Android app-private Room storage: - workspace names, descriptions, lifecycle state, and retention settings; - person/display names, attendance state, and timestamps; - item names, labels, descriptions, and external/operational identifiers; - equipment custody, assignments, controlled-checkout state, coat/bag claim records, and return history; - counters, sequence/claim numbers, operational events, corrections, and operation receipts; - data you explicitly import from CSV; and - locally decoded QR/CODE_128 lookup values. Camera frames used for QR/CODE_128 scanning are processed locally with bundled barcode recognition and are not intentionally retained or uploaded. CSV import/export uses Android system document APIs. Exported files are outside AdHocKit's deletion/retention boundary once written to a destination you choose. ## Optional Shared Sync data When a Pro user deliberately enables Shared Sync for a workspace, selected operational data is transmitted to AdHocKit's Supabase backend so authorized members can collaborate. Depending on the workspace, transmitted/stored data can include: - organizer email address for email-OTP authentication; - Supabase user/account identifiers and a random app-generated device UUID; - workspace names/descriptions and lifecycle/retention state; - person/display names; - attendance state and timestamps; - equipment/item identifiers, descriptions, custody, assignment, and controlled-checkout records; - coat/bag claim records; - counters, sequence/claim state, operation history, operation receipts, and corrections; - workspace membership/invite state; and - synchronization revisions, conflicts, retry/error state, and other protocol metadata. Organizer sign-in uses an email verification code. Staff may join through a temporary anonymous Supabase Auth identity and do not need to provide an email address for that flow. Shared Sync uses HTTPS/WSS and Supabase Auth/RLS/scoped RPC authorization. Room remains the local operational working copy; Realtime is used as an invalidation hint rather than as canonical state. Workspace data deliberately shared by an organizer can be visible to authorized invited staff in that workspace. Supabase acts as AdHocKit's application-service provider for authentication, storage, synchronization, realtime delivery, server functions, and account deletion. ## AdHocKit Pro and Google Play purchase verification Product ID `adhockit_pro` is a one-time non-consumable Google Play product. Google Play processes payment credentials and the commercial transaction under Google's terms. AdHocKit does not receive card/bank credentials. For production Shared Sync authorization, the Android app sends the Google Play purchase token to an authenticated AdHocKit server function. The server verifies the purchase with the Google Play Developer API before granting a time-bounded cloud Pro lease. The raw purchase token is processed transiently and is not stored in the AdHocKit database. AdHocKit stores: - a SHA-256 fingerprint of the purchase token; - the associated organizer cloud user ID while the account exists; - fixed package/product identifiers; - Google Play order ID when returned by Play while the account exists; and - first/last verification, lease-expiry, revocation, and anonymization timestamps/state. This data is used for entitlement verification, acknowledgement/recovery, fraud/anti-replay protection, and preventing one purchase token from being simultaneously bound to unrelated cloud accounts. A recent locally verified Play entitlement can be cached for up to 72 hours to make temporary Billing/network outages tolerable; the cache is not permanent purchase authority. A definitive Play ownership query that no longer reports the purchase removes local Pro access. Cloud authorization also expires unless refreshed by server verification. A refund/revocation does **not** delete local operational records. It disables new Pro-only cloud actions after reconciliation/lease expiry. Existing cloud records remain subject to workspace retention/account-deletion behavior instead of being destructively erased merely because billing changed. ## Account deletion AdHocKit provides cloud-account deletion in the app. A public organizer deletion resource is also available at: `https://efspxwixortusvrsdohv.supabase.co/functions/v1/adhockit-account-deletion` Deleting a cloud account removes the Supabase Auth identity and the account-linked Shared Sync data handled by the deletion service, including owned cloud workspaces, staff memberships, registered devices, and outstanding invites. Local Room workspaces on Android devices are deliberately **not** remotely deleted; they can be managed/deleted separately in the app. Exported files are also unaffected. For a Pro organizer, account deletion also removes the organizer user binding and Google Play order ID from AdHocKit's billing record. For fraud/anti-replay protection, AdHocKit may retain an **inactive SHA-256 purchase-token fingerprint**, fixed package/product identifiers, and non-account verification/revocation/anonymization timestamps. The raw purchase token, organizer email, organizer user ID, and order ID are not retained in that anonymized record. A legitimate owned purchase may be verified and linked again after a future organizer sign-in. Temporary anonymous staff identities can be deleted in-app from Shared Sync > Cloud account > Delete cloud account. Because those temporary identities have no email credential, the external email-verification page cannot identify them after the session is lost. ## Retention and deletion Local workspaces support manual retention or timed retention after close. Eligible timed-retention workspaces move to Recently Deleted and receive a recovery grace period before permanent local purge. Users can explicitly permanently delete eligible local workspaces after confirmation. Shared Sync cloud data follows the workspace lifecycle/retention and account-deletion mechanisms implemented by the service. Staff membership and invite expiry/revocation are enforced independently of local Room retention. Users should not place data in AdHocKit that they are not authorized to process/share. ## Android backup and device transfer AdHocKit excludes its operational Room database, local Pro entitlement cache, and persisted shared-preference/auth session state from Android cloud backup and device-to-device transfer. Reinstall/device replacement restores Pro only when Google Play reports the purchase again; Shared Sync cloud access additionally requires an authenticated organizer verification when needed. ## Permissions and SDKs The app-owned production manifest declares: - `CAMERA` — requested only when the user starts QR/CODE_128 scanning; manual workflows remain available without it. - `INTERNET` — required for Google Play Billing connectivity and optional Shared Sync/Supabase networking. AdHocKit does not request app-owned location, contacts, microphone, SMS, call-log, broad storage, nearby-device, notification, exact-alarm, accessibility-service, or foreground-service permissions for these features. The final merged AAB is reviewed before release for library-contributed permissions. The production dependency set includes Google Play Billing Library 9.1.0 and Supabase Auth/Functions/PostgREST/Realtime plus Ktor for the optional cloud feature. It also includes RevenueCat Purchases and its AdMob adapter, Google Mobile Ads, and Google UMP for the optional user-initiated rewarded temporary-Pro path. AdHocKit does not intentionally include a behavioral analytics SDK or third-party crash-reporting SDK. The rewarded-ad callback is not permanent purchase authority; temporary access is accepted only after server-side reward verification and backend lease confirmation, and failures in the rewarded stack do not revoke valid permanent Google Play ownership. ## Security Operational data is stored in Android app-private storage. Cleartext traffic is disabled. Shared Sync uses encrypted transport, authenticated server functions, Row Level Security and scoped database RPCs. Production cloud writes are protected independently from the Android UI by a recent server-verified Google Play Pro entitlement for the workspace organizer. No system can guarantee absolute security. Enter only the information reasonably necessary for the temporary operation and follow applicable privacy/legal obligations. ## Children and sensitive use AdHocKit is an organizer-facing utility and is not designed or marketed specifically to children. It is not intended to be a medical-record system, law-enforcement evidence system, financial-credential store, government-ID archive, or other regulated safety-critical record system. ## Contact For privacy questions, contact Quazmoz@vivaldi.net.

General Privacy Terms

These terms apply across all our applications.

Questions or privacy requests? Contact us at Quazmoz@vivaldi.net