01The short version
measurd is local-first. Your projects, photos, measurements, layouts, notes and reports are stored in the app on your phone. Without Pro cover we do not have a copy of them, and nothing leaves your device unless you send it somewhere — by exporting, sharing, or uploading to a system you connected. Once you are covered by Pro — your own subscription, or a team plan that includes you — the projects you sync and the reports you publish are stored on our servers for you, as described below.
What we do process: the account details needed to sign you in (through Firebase Authentication with Sign in with Apple or Google), your subscription status (through Apple and RevenueCat), for Pro subscribers the content you sync or publish, the email you give us on the website if you ask to be notified, and ordinary technical logs. Unless you switch it off in the App, the App also sends us crash reports and pseudonymous usage events so we can keep it working.
Team workspaces are shared. If your company is on a team plan, everything in the team workspace is visible to — and editable by — every member of that team. Your personal workspace is not.
What we don’t do: we do not sell your personal information, we do not run advertising or ad-tracking, and we do not read or mine your measurement data.
This policy explains, in more detail, what information Leicht Queens (“measurd”, “we”, “us”) collects when you use the measurd app for iOS (the “App”) and the website at measurd.pro (the “Site”), how we use it, whom we share it with, and the choices you have. Capitalised terms not defined here have the meaning given in the Terms of Service.
02Data stored on your device
The App keeps your work in its own on-device database. This includes projects, rooms, photographs you take or import, the measurements and annotations you draw, wall layouts and elevations, notes, generated reports, your settings (such as units, app language and report language), and, if you connect one, the details of the third-party destination you send reports to.
- On the free plan we do not receive this data. It is not uploaded to servers we control as part of normal use. (Pro cloud sync, which does store it for you, is described in its own section below.)
- Files you import are processed on the device. If you import a project file — for example a PDF exported from another measuring app — the App reads it and extracts photos and measurements entirely on your phone; the file is not sent to us.
- Deleting the App deletes it. So does resetting or losing the device, unless you have a copy — for example an export you saved, or a device backup you maintain through iOS. Device backups are controlled by you and Apple, not by us.
- Photos may contain personal information — a customer’s home, people, addresses on paperwork. You are responsible for what you photograph and whom you share it with.
03Account information (sign-in)
When you sign in, the App uses Firebase Authentication (a Google service) with Sign in with Apple or a Google account. Through it we receive and store:
- a unique user identifier created by Firebase for your account;
- your email address — or, if you use Apple’s Hide My Email, the relay address Apple provides;
- your display name if the provider shares one, and the sign-in provider used;
- authentication tokens and time stamps needed to keep you signed in.
We use this to identify you, to determine which plan applies to your account, to keep your session working, to respond to support requests, and to protect the Service from abuse. Google processes this information as our service provider under the Firebase privacy terms.
04Subscriptions and purchases
measurd Pro is purchased through Apple’s In-App Purchase. Apple processes the payment and holds your billing details; we never see your card number. To recognise that your account is entitled to Pro, the App uses RevenueCat, which receives an app-specific user identifier, the App Store transaction receipt, and the resulting subscription status (product, start and renewal dates, trial status, cancellation). We use this only to unlock Pro features, to handle restores and support, and to understand subscription metrics in aggregate.
Apple’s handling of your purchase is described in Apple’s Privacy Policy; RevenueCat’s in RevenueCat’s Privacy Policy.
05Data you choose to send somewhere
The App can move data off your device only when you tell it to:
- Export and share — annotated images, report files, or room packages you save or share through the iOS share sheet go wherever you send them (Messages, Mail, Files, another app). We do not receive a copy.
- Sending to a system you connected — for example a CRM or project system that you configure in the App with a workspace address and key. When you upload a room, the package (photos, measurements, layout, notes, values) is sent directly from your device to that system. That system’s operator — which may be your employer or a vendor you chose — is responsible for the data there, under their own privacy terms.
06Cloud sync, teams and published reports (Pro)
Cloud sync and backup
Pro includes cloud sync and backup, so your projects follow your account between devices and survive a lost phone. Sync runs automatically while you are signed in and covered by Pro — through your own subscription, or through an active team plan that includes you. Without that cover nothing is synced and your data never reaches our servers.
- What is synced: your projects and their contents — rooms, photos, measurements, wall layouts and elevations, notes and related settings — held in your own personal workspace, or in a shared team workspace if you belong to one, as described under Team workspaces below.
- Where it lives: on infrastructure operated for us by reputable cloud providers — currently our sync service runs on Vercel, project data is stored in a Neon-hosted database, and photo and image files are stored in private Cloudflare storage, accessible only through short-lived signed URLs. Everything is transmitted over encrypted connections.
- We do not read or mine it. Synced content is processed only to provide sync, backup and the features you use, subject to a storage allowance shown in the App's settings.
- You can remove it. Deleting a project (after your devices sync) removes it from the sync service, with stored files cleared by our routine cleanup within about 30 days; deleting your account removes all of it, as described under Your choices and rights. If your subscription lapses, syncing stops; your data stays on your devices.
Team workspaces
A company can be put on a team plan — a package of seats, five by default, that we provision for the buying owner. A team does not change your personal workspace; it adds a second, shared one beside it.
- Everything in the team workspace is shared. Every member can see and edit all of its projects, rooms, photos, measurements, notes and reports. There is no per-project or view-only permission — membership is access to the whole workspace — so treat anything you put there as visible to your colleagues, including photographs of a customer's home.
- Your personal workspace stays private. Belonging to a team gives nobody — the owner included — any access to your own projects, and joining does not move your existing work into the team.
- Members can see one another. The team screen lists the members by the account email address recorded when they joined, so joining a team discloses your email address to the other members.
- The owner controls membership — inviting, revoking invitations, and removing members, who lose access immediately. You can also leave a team yourself at any time. Either way the workspace's projects stay with the team; they were never a copy of your personal data.
- If the team's period ends, syncing to that workspace stops and its contents stay as they are; each member falls back to whatever their own plan allows.
Published report links
Pro can also publish a project's measurement report to a web link you send to your client, instead of a file. When you publish:
- the report page and its images are stored on our servers and served at a link containing a long, unguessable token — anyone who has the link can open it, so share it only with people who should see the report;
- re-publishing replaces the page, and you can revoke a link at any time from the App — the page stops being served immediately, and the stored copy is removed by our routine cleanup and on account deletion;
- the page contains no advertising or tracking; requests to it appear in our hosting logs like any web page.
07Team workspaces and invitations
Joining a team workspace is consequential — it is shared working space, as described under Cloud sync, teams and published reports — so it is worth being exact about how people get in and what we collect along the way.
Inviting someone
The owner invites people with an invitation code, valid for 7 days and revocable at any time. A code you pass on yourself — by whatever means you like — belongs to the workspace rather than to a person, and tells us nothing at all about whoever you gave it to.
Having the App email the invitation works differently: it issues a single-use code for that one person, and we keep their address for as long as the invitation is outstanding.
- What we store. The address is recorded against that one invitation, with the time it was sent, so the invitation can appear in your team's pending list and you can resend or cancel it. To deliver the message it is passed to our email provider, Resend, which records the message it sent — including the address — in its own sending log, under its retention.
- Who can see it. The team owner, and nobody else: it is not shown to the other members. We use it for that invitation alone — no contact list, no marketing, no profile of the recipient.
- When it goes. The record is deleted when the invitation is accepted, cancelled, or expires — we do not keep the address of an invitation that was never taken up.
- What the email says. It identifies the inviter by their account email address, alongside the workspace name and a join link, so emailing an invitation reveals your address to the recipient. It says nothing about the projects inside the workspace.
Joining one
Joining requires a measurd account; someone who does not have one creates a free account first, as described under Account information. The invitation itself creates no account. When someone joins a workspace:
- their account email address is stored as part of their membership, and is shown to the other members on the team screen. We use it for that members list only — never to sign anyone in. It is removed when they leave, are removed by the owner, or delete their account.
- they gain full access to everything in that workspace — every project, room, photo, measurement and report in it, with the ability to edit them. Add people on that basis; there is no view-only invitation.
- their own workspace stays private. Joining a team gives nobody — the owner included — any access to a member's personal projects, in either direction.
You can leave a team at any time from the App, which ends your membership and removes your address from its members list. Questions about a team you were added to can go to privacy@measurd.pro.
08Device permissions: camera, photos and Bluetooth
- Camera and photo library — used to photograph rooms and to import existing photos into a project. Images stay in the App on your device unless you export or send them.
- Bluetooth — used only to connect to your laser measure and receive readings. Readings are stored with the measurement you assign them to, on your device. We do not use Bluetooth to track your location or to detect other devices.
You can change these permissions at any time in iOS Settings; some features will not work without them.
09The website (measurd.pro)
- Notify-me form. If you enter your email to be notified about launch or TestFlight, we store that address, whether you asked for a TestFlight build, and the time and page of the request. We use it only to contact you about measurd’s availability, and we delete it when the launch communication is done or when you ask, whichever comes first. Every email we send includes a way to opt out.
- Hosting and logs. The Site is hosted on Vercel. Like most hosts, Vercel’s infrastructure records technical request logs (IP address, user agent, requested page, time) for security and reliability, retained for a limited period.
- Cookies and analytics. The Site sets no advertising or tracking cookies. If we add analytics, we will use a privacy-respecting, cookieless tool and update this policy.
10Diagnostics and usage analytics
To find crashes before you have to report them, and to see which features are actually used, the App sends a small amount of diagnostic and usage data to two service providers:
- Sentry (Functional Software, Inc.) receives crash and error reports: the stack trace, your device model, OS and app version and build, and the last few screens and actions before the problem as breadcrumbs — with URLs and element labels stripped. The App removes the IP-address field before sending. Stored in Sentry’s US region and kept for 90 days.
- PostHog (PostHog, Inc.) receives usage analytics — only explicit product events such as “app opened”, “laser connected” or “export completed”, with counts and category values. No session replay, no automatic capture of what you tap or type, no advertising or cross-app tracking. Stored in PostHog’s US cloud and kept for 12 months. Like any network request, events reach PostHog with your IP address in transit, but we have configured PostHog to discard it rather than store it; we do not use it to identify you.
Both are keyed by a pseudonymous identifier derived from your account — never your name, email or user id — and events never contain your measurements, photos, project or room names, or email addresses.
You can switch this off in the App under Settings → Help & support → “Share diagnostics & usage data”. Turning it off applies immediately; turning it back on takes effect at the next launch. The switch is a device setting, so it survives signing out and even deleting your account.
Separately, if you have chosen in iOS Settings to share analytics with app developers, Apple may send us anonymised crash logs and usage statistics through App Store Connect; we use them to fix bugs. You can turn this off in iOS Settings → Privacy & Security → Analytics & Improvements. If you email us for support, we keep that correspondence to help you.
11How we use information, and our legal bases
| Purpose | Information | Legal basis (where required) |
|---|---|---|
| Providing the App and signing you in | Account information | Performance of our contract with you |
| Managing Pro subscriptions and trials | Subscription status from Apple / RevenueCat | Performance of contract |
| Emailing a team invitation at your request, and letting you manage it | The recipient's email address and the time it was sent, supplied by you | Legitimate interests — in letting you build your crew and track an outstanding invitation |
| Running team workspaces | Members' account emails and the workspace content they share | Performance of contract |
| Cloud sync, backup and published reports (Pro) | The content you sync or publish | Performance of contract |
| Support, security, preventing abuse | Account information, correspondence, technical logs | Legitimate interests |
| Telling you about launch or TestFlight | Email from the notify-me form | Consent (withdraw any time) |
| Keeping the App working (diagnostics and usage analytics) | Crash reports and pseudonymous usage events (Sentry, PostHog) | Legitimate interests — opt out any time with the in-app switch |
| Complying with law | As required | Legal obligation |
13How long we keep information
- On-device data — until you delete it or the App. We never had it.
- Account information — while your account exists, and for a short period afterwards to handle deletion, disputes and legal obligations.
- Team invitations and membership — invitation codes expire after 7 days, or sooner if used up or revoked by the owner. Where an invitation was emailed, the recipient's address is kept only while that invitation is outstanding, and is deleted when it is accepted, cancelled or expires. A member's account email held on their membership is removed when the membership ends. A team workspace's own content is retained like any other synced content, above.
- Synced content and published reports (Pro) — while your account exists. Deleted projects and revoked report links are cleared by our routine cleanup (stored files within about 30 days); deleting your account removes everything, per the deletion section, leaving only the minimal deletion record described there.
- Subscription records — for as long as needed to honour your subscription and to meet accounting and tax obligations.
- Diagnostics and usage data — crash reports are kept by Sentry for 90 days; usage events by PostHog for 12 months.
- Notify-me emails — until launch communications are complete or you opt out.
- Website logs — for the limited period our hosting provider retains them.
14Your choices and rights
- Access, correct, export. Your measurement data is already on your device and can be exported from the App. For account information we hold, email us and we will provide a copy.
- Delete your account. In the App, go to Settings → Account → Delete account (or email privacy@measurd.pro). This permanently deletes your synced projects and published reports from our servers, your sign-in identity with Firebase, and your subscriber record with RevenueCat, and — if you signed in with Apple — revokes the Sign in with Apple connection. The App then removes the account's data from that device and signs you out. What deletion does and does not reach is detailed in What happens when you delete your account. Deleting your account does not cancel an Apple subscription — cancel in your Apple ID settings, ideally first.
- Turn off diagnostics & usage data. In the App: Settings → Help & support → “Share diagnostics & usage data”. Off applies immediately; back on takes effect at the next launch.
- Opt out of emails. Use the link in any email or contact us.
- Permissions. Manage camera, photo and Bluetooth access in iOS Settings.
Depending on where you live, you may have legal rights to access, correct, delete, restrict or object to our processing of your personal information, to data portability, and to withdraw consent. Residents of the European Economic Area, the UK and Switzerland can exercise these rights by contacting us and may lodge a complaint with their local supervisory authority. Residents of California and other US states with privacy laws have the right to know, delete, and correct, and the right not to be discriminated against for exercising those rights; we do not sell or share personal information as those laws define it. To exercise any right, email privacy@measurd.pro. We will verify your request through the account you signed in with.
15What happens when you delete your account
Account deletion is immediate and permanent: our server removes your synced project data and published reports, records the deletion so the account cannot be silently re-created by a later subscription event, and deletes your Firebase identity and RevenueCat subscriber record. For completeness, here is what deletion does not instantly erase:
- Stored photo and report files are removed by our routine cleanup — fully cleared within 30 days of the deletion.
- Copies on your own devices. Data on other phones you were signed in on stays on those phones; they lose access to the account within about an hour and their local copy can be erased from the App's settings. The same applies to device backups you keep through iOS.
- Data you already sent elsewhere. Reports shared by file, email, or uploaded to a CRM or other system you connected belong to that recipient — we never held them and cannot delete them there.
- Work you put in a team workspace. Deleting your account ends every team membership you hold and removes your email from those members lists, but the team workspace and its projects belong to the team and stay with it. If you were the owner, deleting your account dissolves the team — its memberships and outstanding invitation codes go with it, and the workspace's content is removed as your synced data.
- A minimal deletion record (your account identifier and deletion timestamps) is kept so that later subscription events cannot recreate the deleted account, and to evidence that the deletion happened.
- Server logs and encrypted database backups retained by our hosting providers for a limited period expire on their schedules.
Usage analytics and crash reports are keyed by a pseudonymous identifier derived from your account, never by your name or email. After deletion nothing maps that identifier back to you; the events already recorded expire on the providers’ retention schedules (PostHog per the project’s retention setting, Sentry after 90 days) and are not deleted individually.
Signing in again afterwards — even with the same Apple or Google identity — creates a brand-new, empty account.
16Security
We use reasonable technical and organisational measures to protect the information we process, including encrypted connections to our providers and access controls on our accounts with them. Data on your device is protected by your device’s own security (passcode, Face ID, encryption). No system is perfectly secure; if we learn of a breach affecting your information we will notify you as the law requires.
17Children
The Service is intended for professionals and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.
18International transfers
We are based in the United States and our service providers operate there and elsewhere. If you use the Service from another country, the limited information we process — chiefly account and subscription data — will be transferred to and processed in the United States. Where required, we rely on appropriate safeguards such as our providers’ standard contractual clauses.
19Changes to this policy
We may update this policy as the Service evolves — for example when a new Pro feature stores data for you. We will post the new version here with a new “Effective” date and, for material changes, notify you in the App or by email before they take effect.
20Contact
Privacy questions and requests: privacy@measurd.pro. General contact: hello@measurd.pro. Leicht Queens, operator of measurd.