Vouch is an app for short-term-rental hosts and the people who clean for them. A host sets up their properties and a cleaning checklist; a cleaner photographs each item before and after, notes what supplies are running low, and reports any damage; the host gets a report.
This policy describes what the app collects, why, and who else sees it. It is written against what the app actually does — if you find something here that does not match the app's behaviour, the app is wrong and we want to hear about it.
- Responsible
- Melih Dikmen, sole developer, acting as an individual
- Contact
- melihdeveloper06@gmail.com
What we collect
If you are a host
- Email and password
- To sign you in. The password is stored as a hash and is never readable by us.
- Display name
- To show who you are to the cleaners you invite.
- Interface language
- So the app opens in the language you chose, on any device.
- Properties
- Names and addresses. These are what the app is for. An address is optional — the app works without it.
- Checklists and supply lists
- The templates each turnover is built from.
- Turnovers
- Which property, which cleaner, which date, and how it ended.
- Subscription status
- Whether you have a paid plan, when it expires, and which store it came from.
If you are a cleaner
- Display name
- So your host can tell your work apart from another cleaner's.
- Phone number
- Your host needs a way to reach you about a job. Visible to the hosts you work for, and to nobody else.
- Interface language
- So the app opens in your language.
- Email and password
- Only if you choose to secure your account. You can join and work with an invite code alone. Adding an email is what lets you sign in again on a new phone.
- Photos you take
- The before-and-after record of the work.
- Damage notes
- What you saw, in your words, sent to the host.
- Your work record
- Which turnovers you completed, and when.
Photos
Photos are the heart of the app, so it is worth being exact about them.
- They are taken in the app, with the camera. Vouch does not read your photo library.
- They are stored in a private bucket. There is no public link to any photo; viewing one produces a short-lived signed link that expires.
- They are visible to the cleaner who took them and the host who owns that property. Not to other cleaners, not to other hosts, not to anyone browsing the internet.
- They are held on your phone first and uploaded when there is a connection, so a cleaner with no signal can still finish a job. Once uploaded, the local copy is dropped.
- A host can export a turnover as a PDF containing those photos. What happens to that PDF after they share it is outside the app's control, and outside this policy.
On your phone
Your sign-in session, any turnover still waiting to be uploaded, and small preferences such as your chosen language are kept in an encrypted store whose key lives in the device keychain. It stays on the device; deleting the app deletes it.
What we never collect
No location. No contacts. No photo library. No microphone or audio — the camera takes stills only, and the app does not ask for microphone permission. No advertising identifier, and no advertising of any kind.
Analytics and crash reports
We use Google Firebase for three narrow purposes.
- Analytics — to learn whether the product works, which for us means one question: does someone who finished one turnover ever finish another. The app records a small fixed set of events — a property created, a checklist saved, an invite made or accepted, a turnover created, started, finished or abandoned, damage reported, a supply flagged, a PDF made or shared, and a queue of offline photos finishing its upload — along with counts and durations, and which screen was open.
- Crashlytics — so a crash gets fixed. Collected from released versions only, never from development builds.
- Remote Config — to adjust settings such as photo quality or plan limits without shipping a new version. This only sends settings to your phone.
The only identifier we attach is your account id — a random value with no meaning outside our database — plus whether you are using the app as a host or as a cleaner. Names, phone numbers, email addresses, property addresses, photos and damage notes are never sent to Firebase. A cleaner's identity is not ours to hand to an analytics provider.
Firebase collects some technical information of its own, such as device model, operating system version, and approximate region derived from IP address. See Google's privacy policy.
Payments
Vouch offers an optional paid plan. We never see your card. The purchase happens entirely inside Apple's or Google's payment system.
We use RevenueCat to check with the store whether a subscription is valid. RevenueCat receives your account id — the same meaningless identifier — along with what you bought and when it renews or expires. It receives no name, email, phone number or content. See RevenueCat's privacy policy.
We store only the result: which plan, whether it is active, and when it ends.
Who can see your data
Within the app, access is enforced by the database itself, not by the app asking politely.
- A host sees their own properties, their own turnovers, and the cleaners who accepted their invite.
- A cleaner sees only the turnovers assigned to them, and only the properties they are assigned to.
- One host can never see another host's data. One cleaner can never see another cleaner's.
- A cleaner working for two hosts keeps those two jobs separate.
Outside the app
We do not sell your data. We do not share it with advertisers. We do not use it to train machine-learning models. If we are ever legally compelled to hand something over, we will say so publicly unless the law forbids it.
How long we keep it
As long as your account exists.
You can delete your account from inside the app, under Settings. It is immediate and it cannot be undone.
- If you are a host, everything goes with it: your properties, checklists, turnovers, damage reports and every photo in storage. Your cleaners stop seeing your places.
- If you are a cleaner, your account and phone number go. The turnovers you finished stay with your hosts as their record that the work was done — with your name removed. Those photos are of their property, not of you, and they are the host's evidence.
- Either way, your customer record at RevenueCat — the account id and any purchase history under it — is deleted in the same step, so the identifier does not outlive the account at a processor.
The app also clears its own cache on the phone when you sign out or delete, so nothing of yours lingers for the next person to use the device. If you cannot get into the app, write to us instead and we will do the same by hand.
Analytics events in Firebase expire on Google's own schedule, and are not tied to anything that identifies you once your account is gone.
Your rights
Wherever you are, you can ask us to:
- See everything we hold about you.
- Correct anything wrong.
- Delete your account and its data — from Settings in the app, or by email.
- Export your data in a portable form.
If you are in the UK or the EU, the UK GDPR and the GDPR give you these as legal rights, along with the right to object to processing and the right to complain to your national data protection authority. Our legal basis is performance of a contract for the data the app needs in order to work at all, and legitimate interests for the analytics and crash reporting that keep it working — a small, identifier-only set that you can object to.
To exercise any of these, write to us. We will answer within 30 days.
Children
Vouch is a tool for work and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, write to us and we will remove it.
Changes
If this policy changes in a way that affects you, we will say so in the app before the change takes effect — not quietly, and not only by updating the date at the top.