Privacy Policy
Think Team Sdn Bhd is the data controller for GOTCHA. This policy explains what the app collects, what never leaves your device in readable form, and who can see what. It is written to the Malaysian Personal Data Protection Act 2010 (PDPA).
The short version: your photos are encrypted on your phone with a key held in your phone’s keystore, before anything is uploaded. We hold ciphertext we cannot read. Nothing is written to your device gallery, and nothing is shared with anyone unless you share it.
01What we collect
- Account details — email address, display name and (if you sign in with Google) your Google profile photo, handled by Firebase Authentication.
- Captures — the photo itself, encrypted with AES-256 on your device before upload. We store the ciphertext; the key stays in your device keystore.
- Capture metadata — GPS coordinates and the address they resolve to, the capture time, the file’s SHA-256 hash, and basic device information. This is what makes a capture verifiable.
- Evidence anchors — the hash plus a server timestamp, written once and never editable, including by you. That immutability is the point.
- Guardian Circle — the circle you belong to, its members, and anything you choose to share into it.
- GOTCHA-CAM — the camera’s ID and your ownership claim. The pairing key from the QR sticker is stored in your device keystore, not on our servers.
- Subscription — the purchase token or transaction ID from Google Play or the App Store, and the resulting status and expiry date. We never see your card details.
02What we do not do
We do not run advertising SDKs, we do not sell or rent personal data, we do not build advertising profiles, and we do not save your captures to your device’s photo gallery. We cannot decrypt your photos.
03Why we hold it
- To run the service you signed up for — capturing, sealing, syncing and restoring your own evidence (performance of our contract with you).
- To make captures verifiable — location, time and hash are the evidentiary value of the product, and are collected only when you capture.
- To keep accounts and payments correct — verifying subscriptions with Google and Apple, and preventing one receipt being used to unlock several accounts.
- To keep the service secure and to meet legal obligations.
04Who it is shared with
Only these, and only for the purposes above:
- Google (Firebase / Google Cloud) — authentication, database and hosting infrastructure.
- Google Play and Apple — subscription billing and the receipt checks that confirm you paid.
- Your Guardian Circle — the people you added, limited to what you share.
- Authorities — only where we are legally required to, and only what we actually hold. For your photos, that is ciphertext we cannot open.
05Location
Location is read at the moment of capture, to stamp the photo. You can refuse or revoke the permission in your phone’s settings; GOTCHA keeps working, and captures are stamped “Location Unavailable”. We do not track you in the background.
06Storage and retention
Encrypted captures and their metadata stay until you delete them or delete your account. Account records are kept while your account exists; subscription records are kept as long as tax and accounting law requires. Deleting a capture removes it and its stored bytes; the evidence anchor (a hash and a timestamp, which identify nothing on their own) may remain.
07Your rights
Under the PDPA you may ask us to give you a copy of the personal data we hold about you, correct it, limit how we use it, or delete it, and you may withdraw consent for optional processing. Write to the address below and we will respond within 21 days.
Exporting your own captures from the app is free and always available — that is deliberate: your evidence should never be held hostage by a subscription.
08Security
AES-256 encryption applied on-device, keys held in the Android Keystore / iOS Keychain, transport secured with TLS, per-account access rules on the database, and optional biometric lock on the app. No system is perfect: if a breach ever affects your data, we will tell you and the relevant authority.
09Children
GOTCHA is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has an account, contact us and we will remove it.
10International transfers
Our infrastructure runs on Google Cloud, which may process data outside Malaysia. Those transfers are covered by Google’s data protection terms and appropriate safeguards.
11Changes
If this policy changes materially, we will notify you in the app or by email before the change takes effect.
12Contact
Think Team Sdn Bhd, Malaysia — info@thinkteam.biz
See also the Terms of Service.