1. Who is responsible for your information
Indate is published by Bitcraftery, a sole trader based in England. Bitcraftery is the data controller for the limited personal data described in this policy. In it, “we”, “us” and “our” mean Bitcraftery.
One inbox handles privacy questions, requests and complaints: [email protected]. Bitcraftery is a sole trader, not a limited company, so there is no company number or registered office. If you need a postal address in order to make a formal request, email us and we will give you one.
This policy covers the Indate iPhone app and this website, indate.bitcraftery.com.
2. What stays on your iPhone
Indate has no account, no login and no server storing your records. Everything you enter is held in the app’s own storage on your iPhone, and that includes:
- your own details — name, date of birth, service address, phone number and email address, or your company details if you let through a company
- each property’s address, the council you pick for it, and its type, size, occupancy and furnished status
- the rent, and how often it is paid
- gas safety records, EICRs and EPCs — inspection dates, deadlines, issuers, reference numbers and notes
- tenant names, whether each tenant is over 18, and the three Right to Rent dates
- deposit amounts, scheme names, protection dates and the date prescribed information was served
- licence types, numbers and conditions
- landlord and property registration numbers once you have them
- documents and photographs you add, including certificate scans
- reminders you set yourself
None of it is sent to us. It is written into the app’s own container, which other apps cannot read, with iOS file protection set so that the files stay encrypted and unreadable whenever your iPhone is locked. It is protected by your device passcode, Face ID or Touch ID in exactly the way the rest of your phone is.
Backups are the one exception worth knowing about. If you back up your iPhone to iCloud or to a computer, Indate’s data may be included in that backup. That backup is between you and Apple, under Apple’s terms and your Apple Account settings. We have no access to it and no way to reach it.
You can export everything you have entered as a file from the app’s Settings, and you can remove all of it by deleting the app.
3. What we never receive
We never receive any of the information listed in section 2. Not in an analytics event, not in a crash report, not in a support email unless you choose to put it in one.
This is worth stating plainly, because it cuts both ways. It is not that we promise not to look: there is nothing for us to look at. We cannot read your records, search them, produce them to anyone who asks, restore them if you lose your phone, or delete them on your behalf. Section 19 explains what that means for your rights.
4. Information about your tenants
If you record a tenant’s name, whether they are over 18, or the dates from a Right to Rent check, that information is personal data about somebody else. You decide what to record and why, so for data protection purposes you are the controller of it. We are not a processor of it either, because it never reaches us — it stays on your iPhone with everything else.
Indate is built to ask for as little as it can: a name, an over-18 flag and three dates, with no facility to store images of immigration documents. Keep what you hold to what you actually need, and tell your tenants what you hold about them. The Information Commissioner’s Office publishes guidance for landlords on both points.
5. Usage analytics
Indate uses Firebase Analytics, a product of Google, to understand how the app is used. Events carry counts and fixed labels only. An event can record:
- that a property was added, and how many properties are now in the app
- which screen was opened
- which rule a reminder came from, by its fixed internal name — gas.annual, for example
- how many reminders the app scheduled on your device
- that the purchase screen was shown, and which plan was selected
- whether the app could reach the configuration file
An event never contains:
- a property address, or any part of one
- a tenant’s name, or anything else about a tenant
- a certificate reference, an issuer’s name or a scan
- a landlord or property registration number
- your name, date of birth, phone number or email address
- a document or photograph you have added
- the iOS advertising identifier — Indate does not use it, does not ask to track you across other apps and websites, and shows no advertising
Alongside those events, the Firebase software records your app version, your device model, your iOS version, the broad region your device is in — worked out from the IP address of the request rather than stored as one — and a random identifier for this installation of the app. That identifier is not linked to your name or your Apple ID, and it ends when you delete the app.
We use this to see which screens are actually used, whether people get through onboarding, and whether the reminder schedule on real devices is running into the limit iOS puts on it. Indate shows no advertising, sells nothing to anyone, and does not share this information with advertising networks.
6. Crash diagnostics
Indate uses Firebase Crashlytics, also from Google, so that we find out when the app stops working. A crash report records:
- what the app was doing at the moment it stopped, as an internal stack trace
- your device model, your iOS version and the version of Indate you were running
- a random identifier Firebase generates for this installation of the app, which is not linked to your name or your Apple ID and ends when you delete the app
- the date and time of the crash
A report can also carry short technical notes that we add ourselves to make a fault easier to trace — which rule was being evaluated, for instance. We never put your records into one.
7. Turning analytics and crash reporting off
The app’s Settings has a switch for analytics and crash reporting. Turn it off and collection stops. Anything already sent is deleted on the timetable in section 16, and you can email us to ask for it to go sooner.
Indate does not use the iOS advertising identifier and does not ask for permission to track you across other apps and websites, so you will not see an App Tracking Transparency prompt from it. If you have turned off “Allow Apps to Request to Track” in iOS Settings → Privacy & Security → Tracking, that setting applies to Indate as it does to every other app.
Deleting the app ends collection entirely and retires the installation identifier.
8. The configuration file the app downloads
The law behind the PRS Database was still in draft when Indate was built, so the app downloads a small configuration file — at most once a day, over an encrypted connection — that lets us correct a fee, a date or a region without waiting for an App Store release.
That request sends nothing about you. No identifier, no address, no records, no account — there is no account. It is the same file for every user, and the app asks for it in the same way your browser asks for a page.
Our hosting provider records standard request information when it serves the file: the IP address the request came from, the date and time, what was requested, and the browser or app user-agent string. We use it to keep the service available and to investigate abuse. It is not used to identify you, build a profile, or work out anything about your properties, and it is not combined with anything else. It is deleted after 30 days.
If the download fails, the app carries on with an identical copy built into it. Indate works fully offline.
9. Purchases and payment
Apple takes every payment, through the App Store. We never see your name, your card details or your Apple ID, and we run no server to check receipts — the app asks iOS whether a purchase is active and gets a yes or a no.
For the transaction itself Apple is an independent controller, handling your information under Apple’s own privacy policy rather than this one. What reaches us is the sales reporting in App Store Connect: totals by day and by country, which identify nobody.
10. When you email us
If you email us we receive your email address, whatever name you sign, and whatever you write. We use it to answer you and to fix whatever you have told us about.
Please do not send tenant details, certificate scans or documents unless they are genuinely needed to resolve the question. If you do send them, we delete them once the matter is closed.
11. The waiting list for Wales, Scotland and Northern Ireland
Indate’s rules cover England. If you tell the app that your property is in Wales, Scotland or Northern Ireland, it says so plainly and offers to take an email address so that we can tell you if and when your nation is supported.
That is optional in the fullest sense: the address is collected only if you type it in, nothing else about you is taken with it, and skipping the step changes nothing about how the app behaves. We use it for that one message. It is not a newsletter, it is not used to market anything else, and it is never shared or sold. Email us at any time and we will remove it.
12. This website
This website sets no cookies, runs no analytics, embeds nothing from a third party, and asks you for nothing. There is no form on it and no tracking on it. The one typeface it uses is served from this site rather than fetched from anyone else, so visiting a page here does not tell any third party that you did.
The hosting logs described in section 8 apply to this site too. The cookies page says the same thing at more length, for anybody who needs it in writing.
13. Our lawful bases for using your information
UK GDPR requires a lawful basis for each thing we do with personal data. Ours are:
| What we do | Lawful basis |
|---|---|
| Finding and fixing crashes and faults | Our legitimate interests — an app that tracks legal deadlines has to keep working, and we cannot fix what we cannot see. |
| Understanding which parts of the app are used | Your consent, given by leaving analytics switched on in Settings. Switching it off withdraws that consent. |
| Storing the analytics and crash identifiers on your device | Your consent, as the Privacy and Electronic Communications Regulations require for anything stored on your device that is not strictly necessary. |
| Serving this website and the configuration file, and keeping both available and secure | Our legitimate interests — running a service that is not knocked over, and being able to investigate if it is. |
| Giving you access to the app you have paid for | Performance of our contract with you — the terms you agreed when you bought Indate. |
| Replying when you email us | Our legitimate interests — answering the person who wrote to us. |
| Telling you when your nation is supported, if you asked to be told | Your consent, given when you typed your email address into that screen. |
Where we rely on legitimate interests, we have weighed them against your interests and rights. The data involved is minimal, does not identify you, and is never about your properties or your tenants — and you can object to any of it with the switch described in section 7, or by emailing us.
14. Who else is involved
We do not sell personal data and we do not share it for advertising. The only parties involved are:
- Google, which provides Firebase Analytics and Crashlytics as our processor, under Google’s data processing terms;
- Apple, which handles your purchase as an independent controller;
- DigitalOcean, which hosts this website and the configuration file and processes the request logs on our behalf;
- the provider that hosts our email, if you write to us.
We would disclose information if the law required it — a court order, for example. For anything in the app, we would have nothing to give, which is the strongest privacy guarantee available to a product of this kind.
15. Where your information is processed
Google processes analytics and crash data outside the United Kingdom, including in the United States. Where that happens, the transfer is covered by the UK International Data Transfer Agreement, or by the UK Addendum to the EU Standard Contractual Clauses, and — where it applies — by the UK Extension to the EU–US Data Privacy Framework. Our hosting and email providers may also process information outside the UK under the same kinds of safeguards.
The records you keep in the app are never transferred anywhere, by us or by anyone else, because they never leave your iPhone.
You can ask us for details of the safeguards that apply to any particular transfer.
16. How long information is kept
| What | How long |
|---|---|
| Everything you enter in the app | On your iPhone until you delete it or delete the app. We hold no copy, so there is nothing for us to keep or erase. |
| Analytics events | Up to 14 months, then deleted by Google. |
| Crash reports | Up to 90 days, then deleted by Google. |
| Website and configuration-file request logs | 30 days, then deleted. |
| Emails you send us | Up to 24 months after the matter is closed, so we can pick up a thread you return to. |
| A waiting-list email address | Until we have written to you about your nation, or you ask us to remove it — and in any case no longer than 24 months. |
| Your purchase | Held by Apple under Apple’s own policy. We see anonymous sales totals in App Store Connect, which do not identify you. |
17. How information is kept safe
The strongest security measure available to us is the one built into the design: we collect almost nothing, so there is almost nothing to lose. There is no account, so there is no password of yours to steal, and no central database of landlords and properties for anyone to breach.
On top of that:
- your records sit in the app’s own sandboxed container, with iOS file protection set so the files are unreadable while the device is locked;
- the configuration request and this website both use encrypted connections;
- analytics and crash data are held by Google under their own security arrangements, and carry no identifying detail from us.
No system is perfectly secure. Keep iOS up to date, use a passcode or Face ID, and do not leave your iPhone unlocked where other people can pick it up.
18. Your rights
Under UK GDPR you have the following rights:
- Access
- Ask for a copy of the personal data we hold about you, and an explanation of what we do with it.
- Rectification
- Ask us to correct anything we hold about you that is wrong or incomplete.
- Erasure
- Ask us to delete personal data we hold about you. For anything in the app, you do this yourself by deleting the app — we have no copy to delete.
- Restriction
- Ask us to stop using your information while a question about its accuracy or our basis for holding it is resolved.
- Portability
- Ask for the information you gave us in a form you can take elsewhere. Inside the app, Settings will export everything you have entered as a JSON file whenever you want it.
- Objection
- Object to anything we do on the basis of our legitimate interests. The analytics switch in Settings is a one-tap way to do exactly that.
- Withdrawing consent
- Withdraw consent at any time, without giving a reason. It does not undo anything done while the consent was in place.
You also have the right to complain to the ICO — see section 23.
19. Using your rights, and what we cannot do for you
Email [email protected] and say what you want. We will respond within one month. If a request is complicated we can extend that by up to two further months, and we will tell you within the first month if we are going to. There is no charge, unless a request is clearly unfounded or repetitive.
What we can do. Deal with anything we actually hold: the emails you have sent us, a waiting-list address, and — where we can identify it — analytics or crash data.
What we cannot do, and why. We cannot access, search, produce, correct, restore or delete the records inside your app, because we never hold them. In practice that means:
- correcting something is you editing the entry in the app;
- getting a copy is the export in the app’s Settings, which gives you everything you have entered in a file you keep;
- erasing everything is deleting the app from your iPhone, which removes the records, the documents and the scans with them. Check any device backup you have made separately.
Analytics and crash records are tied to a random installation identifier rather than to you, so there are cases where we genuinely cannot tell which records are yours. Where that happens we will say so and explain why, as the law allows, rather than collecting more information about you in order to find out.
20. Children
Indate is a tool for landlords. It is not designed for, marketed to, or directed at anyone under 18, and we do not knowingly collect personal data from a child. If you believe a child has given us information, email us and we will delete it.
The app records whether a tenant is over 18 because Right to Rent turns on it. That answer stays on your iPhone and never reaches us.
21. Automated decisions and profiling
We make no automated decisions that produce a legal effect for you or similarly significantly affect you, and we do not profile you.
Indate does work out dates — when a gas safety record runs out, when a regional registration deadline falls — but it does that on your own iPhone, from figures you typed in, and the result is a reminder rather than a decision about you. You are free to ignore it, and the app tells you where each rule comes from so you can check it.
22. Changes to this policy
When this policy changes we will publish the new version here and change the date at the top. If a change is material — a new processor, a new purpose — we will say so in the app or in the release notes. Ask us if you would like a copy of an earlier version.
23. Complaining to the ICO
If you are unhappy with how we have handled your information, please tell us first at [email protected]. You also have the right to complain to the Information Commissioner’s Office, the UK’s data protection regulator:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline 0303 123 1113
ico.org.uk
Complaining to the ICO does not affect any other remedy you have.
Related pages: terms and conditions · cookies · support.