Privacy Policy
Last updated: 6 September 2026
This policy explains what Finick does with your information. Finick is a punch list and closeout app for building contractors, published by UKGADGETS LTD ("we", "us"). We are the data controller for the information described here.
The short version. Finick is an offline-first app. Your jobs, items, photos and contacts are stored on your phone. There is no analytics SDK, no advertising, and no tracking of any kind in this app. Information leaves your phone only when you do something that requires it, such as creating a share link for a sub, signing in so your work is backed up, or when the app crashes.
1. What Finick stores on your phone
Everything you create in Finick is written to a database on the device itself:
- Jobs and projects, including the name, address and client details you enter
- Punch list items, their status, trade, priority, notes and due dates
- Photos you take or attach, including any markup you draw on them
- Your contacts list of subcontractors, with the names and contact details you enter
- Your company name and logo for reports
- Your settings and preferences
This data stays on the device. It is not uploaded anywhere by default, and the app works fully with no signal.
2. What leaves your phone, and when
| What | When it happens | Who receives it |
|---|---|---|
| Share link contents | Only when you create a link for a sub or a client | Google Firebase (hosting the link) |
| Cloud backup of your jobs, items, photos and contacts | Automatically once you have Pro and have signed in, when you leave the app | Google Firebase |
| Crash diagnostics | Only when the app crashes | Firebase Crashlytics |
| Subscription status | Every time you open Finick, and each time you return to it, so the app knows whether Pro is active, and when you buy, restore or renew | RevenueCat and your app store |
| Push notification token | If you allow notifications | Firebase Cloud Messaging |
| App integrity check | On launch, to verify the app is genuine | Firebase App Check |
Share links deserve a longer explanation
When you send a subcontractor or a client a link, Finick uploads what that link needs to show, so it can open in an ordinary web browser with no app and no login. That upload contains:
- The job name and your company name
- The first name of the person the link is for
- Only the items included in that link, with their titles, notes, status and photos
It does not contain your client's contact details, your other jobs, or another sub's items. A link for one sub shows that sub's work only.
Anyone holding the link can open it. A share link is a long unguessable web address, and it is not password protected, by design, because the point is that a sub does not have to install anything. Treat it like any other link you send: whoever you forward it to can see it. You can revoke a link at any time from inside the app, and revoking takes effect immediately: the refusal is enforced on our servers, not just in the app. Every link also expires by itself 30 days after it is created. That is automatic and you cannot extend it; to keep a sub working past 30 days, send a fresh link.
If you gave a link permission to accept updates, the sub can also upload a photo of the completed fix through it. That photo goes to the same place and appears on your item.
Cloud backup
Backup is a Pro feature, and you should know that it is automatic rather than something you switch on. Once you hold a Pro subscription and have signed in with a durable account, Finick copies your jobs, items, photos and your subcontractor contacts list, including their names, trades, phone numbers and email addresses, to storage tied to that account. It runs by itself, without you pressing anything: when you leave the app, and again when you come back to it. It will not repeat more often than once every 30 minutes, except while photos are still waiting to upload, when it retries as often as every couple of minutes until they are up. There is no on/off toggle. If you do not want your work copied off the device, do not sign in: the whole punch-list workflow runs on the anonymous device profile without it. Other Finick users cannot read your backup, which is enforced by a server-side rule tying every stored file to your own account id.
Crash diagnostics
If Finick crashes, Firebase Crashlytics receives a report so we can fix the fault. A report contains the device model, the operating system version, the app version and a technical stack trace. It does not contain your jobs, items, photos or contacts.
3. Your account
Finick signs you in anonymously by default. That means the app holds an identifier for your device so your data can be tied to a backup or a share link, and it does not ask you for a name or an email address.
You can optionally create a durable account so that your Pro subscription and your backup follow you to a new phone. Two routes exist, and which you see depends on the phone:
- An email address and password, on both iOS and Android. We never see or set the password; it is held by Google Firebase, which also sends the reset email if you forget it.
- Sign in with Google, on Android only. We receive the account identifier and the email address Google gives us.
Finick does not offer Sign in with Apple. Nothing in the app asks for your Apple ID.
4. Permissions and what each one is for
- Camera. To photograph punch list items and proof-of-fix shots.
- Photo library. To attach jobsite photos you already have, to pick your company logo, and to save a report or an annotated photo back to your library.
- Face ID, Touch ID or device biometrics. To lock the app so client details and reports stay private on a shared work phone. The check is performed by the operating system. Finick never receives your fingerprint or face data, only a yes or no.
- Notifications. To remind you about due items. You can decline and the app still works.
5. What we do not do
- Photo location data is stripped. A phone camera writes GPS coordinates into a photo file. Every photo that leaves the device, whether in a report, an export or a backup, is re-encoded with that EXIF GPS removed
- No microphone access. The camera component Finick bundles would request one for video recording. The app strips that permission from its manifest, so no microphone permission is asked for or shown, and Finick contains no recording feature
- No location access of any kind. Finick does not ask for it, the app carries no location permission, and it contains no mapping or geolocation code
- No analytics or usage tracking SDK is present in the app
- No advertising and no ad identifiers
- No selling or sharing of personal information with data brokers
- No profiling and no automated decision making
- We do not read your jobs, items, photos or contacts
6. Payments
Finick Pro is sold through the Apple App Store and Google Play. Those stores take the payment and we never see your card number, bank details or billing address. We use RevenueCat to tell the app whether your subscription is active. RevenueCat receives a purchase identifier and your anonymous app user identifier, not your payment details.
7. Third parties we use
- Google Firebase (Firestore, Storage, Authentication, Cloud Messaging, Remote Config, App Check, Crashlytics), for share links, optional backup, sign in, notifications and crash reporting. See Firebase privacy.
- RevenueCat, for subscription status. See RevenueCat privacy.
- Apple App Store and Google Play, for distribution and payment.
8. Where your data is held
Data on your phone stays in your country, with you. Anything that leaves the device is processed on Google and RevenueCat infrastructure, which may be located in the United States or elsewhere. Where information is transferred out of the UK or the European Economic Area, it is covered by the standard contractual clauses those providers operate under.
9. How long we keep things
- On your phone: until you delete the app, or use Delete everything. Deleting a single item or job hides it and stops it counting against your limits, but its record stays in the on-device database until one of those two happens.
- Share links: revoking, expiry and deleting the job all cut off access immediately and permanently. Be aware that they switch the link off rather than erase what was already mirrored for it; that copy is removed when you use Delete everything.
- Cloud backup: for as long as you hold Pro and stay signed in. Signing out stops new copies being made; deleting your data removes what is already there.
- Crash reports: retained by Firebase Crashlytics on its standard schedule, currently 90 days.
- Purchase records: kept while the subscription is active and afterwards where we are required to for tax and accounting.
10. Your rights
If you are in the UK or the European Economic Area, the UK GDPR and the GDPR give you the right to access your data, correct it, delete it, restrict or object to how it is processed, and to receive a portable copy. If you are in California, the CCPA gives you the right to know, to delete, and to opt out of sale. We do not sell personal information, so there is nothing to opt out of.
Finick lets you exercise the two that matter most without contacting anyone:
- Export. Settings has an export that saves a spreadsheet of your jobs and items plus every photo, wherever you choose. It is free and it works on the free tier.
- Delete everything. Settings has a delete that erases every job, item, contact, photo and report from the phone, and everything held for you on our servers: your backup and every share link you have issued. It needs a connection, because it has to reach our servers as well as your phone; with no signal it deletes nothing and tells you so. It cannot be undone, and the share links you have sent stop working. One exception: a link you issued before you last signed out or switched accounts is stamped with that earlier sign-in and can no longer be deleted or switched off from the app, so it keeps working until it expires, 30 days after it was created. Email [email protected] with the link and we will delete it for you. We suggest exporting a copy first.
You can also write to us at the address below and we will act on your request. Our lawful basis for the processing described here is performance of the contract with you (running the app and your subscription) and our legitimate interest in keeping the app working and secure (crash reporting and app integrity).
11. Photos of people
Jobsite photos sometimes catch a person in the frame. If you photograph an identifiable individual and share it, you are responsible for having a proper reason to do so under data protection law. Finick has no face recognition and does not analyse the content of your photos.
12. Children
Finick is a tool for working contractors. It is not directed at children and it is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has provided us with information, contact us and we will delete it.
13. Security
Data on the device is protected by the operating system's own app sandbox and, if you enable it, by a biometric lock. Traffic between the app and our providers uses TLS. Access to share links and backups is controlled by server-side security rules, and the app verifies its own integrity with Firebase App Check so that a tampered copy cannot reach our data. No system is perfect, and we cannot guarantee absolute security.
14. Changes to this policy
If we change this policy we will update the date at the top of this page. If a change materially affects what we do with your information, we will tell you in the app before it takes effect.
15. Contact us
Questions, requests or complaints:
UKGADGETS LTD
International House, 12 Constance Street
London, E16 2DQ, United Kingdom
Company Reg: 11571746 | VAT: GB307226723
[email protected]
If you are in the UK and you are not happy with our response, you can complain to the Information Commissioner's Office at ico.org.uk.