Skip to content
CrackLog CrackLog
Home Privacy Terms Get the App
Home Privacy Policy Terms of Service Get the App

Privacy Policy

Effective date: August 26, 2026 · Last updated: August 26, 2026

Contents

  1. Introduction
  2. Data We Collect
  3. Organizations & Shared Access
  4. How We Use Your Data
  5. AI Processing
  6. Third-Party Services
  7. Data Storage & Security
  8. Data Retention
  9. Your Rights & Choices
  10. Children's Privacy
  11. International Transfers
  12. Changes to This Policy
  13. Contact Us

1. Introduction

CrackLog ("we," "us," or "our") operates the CrackLog mobile application (package name com.cracklog.monityl) and the website at https://crack-log.com (collectively, the "Service").

CrackLog is a professional tool for engineering firms and inspectors documenting structural cracks during building inspections. This Privacy Policy explains what information we collect, how we use it, with whom we share it, and the choices you have. By using the Service, you agree to the collection and use of information as described here.

What changed in this version: CrackLog now works around organizations. Inspection data belongs to an organization rather than to an individual account, and every member of an organization can see that organization's projects, cracks, scans, and reports. If your firm added you to its organization, please read Section 3 — it describes what your colleagues and administrators can see, and what happens when you join or leave.

Important: CrackLog provides AI-assisted crack measurements and assessments. It is not a substitute for professional structural engineering judgment, inspection, or legal advice.

2. Data We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address and password (for email sign-up)
  • Display name
  • Firebase user ID (UID)
  • Google profile information if you sign in with Google (name, email, profile photo URL)
  • The organization your account belongs to, and your role within it (administrator or inspector)

2.2 Inspection Content

When you use CrackLog, you or your colleagues may provide:

  • Project records — building name, street address, certificate of occupancy year, jurisdiction, and inspection type for each building being inspected
  • Crack records — labels, structural component tags (for example load-bearing wall, foundation, column), and free-text location descriptions within the building (for example "NW stairwell, 3rd floor")
  • Photographs of structural cracks, captured via camera or selected from your gallery
  • Measurement data (width, length, uncertainty, confidence) generated on your device
  • AI-generated analysis — crack classification, severity assessment, explanations, and recommendations
  • Engineer verifications — when you override an AI measurement, we permanently record the corrected values together with your name, your user ID, the date and time, and any note you write. See Section 8 for why these records cannot be edited or deleted
  • PDF reports generated within the app
  • Firm logo, if an administrator uploads one for report covers (paid plans)

Note on building addresses: project addresses identify third-party properties that your organization inspects. The organization is responsible for ensuring it is entitled to record that information in CrackLog.

2.3 Subscription & Billing Data

Subscriptions apply to an organization, not to an individual account. Payment through the app is processed entirely by Google Play; some plans are invoiced directly by us instead. We receive and store:

  • Plan tier and, for Google Play subscriptions, the product ID, purchase token, and expiry date
  • For invoiced plans, an internal entitlement record containing the plan tier, expiry date, and an invoice or customer reference
  • Monthly usage counters (scans, reports, and summaries used), which are shared across the whole organization

We do not collect or store credit card numbers or other payment instrument details.

2.4 Device & Technical Data

We automatically collect:

  • Device type, operating system version, and app version
  • Firebase installation identifiers and App Check attestation tokens
  • Automatic app-interaction events via Firebase Analytics (we do not record custom analytics events)
  • Crash and stability diagnostics via Firebase Crashlytics, which may include device state and stack traces at the time of a crash

2.5 Data We Do Not Collect

CrackLog does not collect:

  • Precise geographic location from your device (we request no GPS or location permission). Building addresses and in-building locations exist only because a user typed them in — they describe the inspected property, not your device's whereabouts
  • Contacts, microphone audio, SMS, or call logs
  • Advertising identifiers for ad targeting (we do not show ads and do not use advertising SDKs)

2.6 Local Device Data

The app stores an offline copy of your organization's data on your device using a Room database and DataStore preferences, including cached projects, cracks, scans, verification history, reports, and your theme, language, and reminder preferences. If you are removed from an organization, the app clears that organization's local copy the next time it refreshes your account. Local data may be included in Android system backups depending on your device settings.

3. Organizations & Shared Access

Every CrackLog account belongs to exactly one organization. When you sign up, we automatically create a private, single-member organization for you and make you its administrator. If you work for a firm, an administrator there may add you to the firm's organization instead.

3.1 What other members can see

All members of an organization — administrators and inspectors alike — can view all of that organization's data:

  • Every project, crack, photograph, measurement, and report in the organization, regardless of who created it
  • Your display name and email address in the organization's member list
  • Your name and the date on any measurement you verified, and on the "last edited" record of any crack you changed

CrackLog does not provide per-project or per-member access restrictions within an organization. If you do not want colleagues to see a piece of work, do not record it in a shared organization.

3.2 What administrators can additionally do

  • Add another CrackLog user to the organization by email address, and remove members
  • Change a member's role between administrator and inspector
  • Delete projects, cracks, and reports
  • Purchase or manage the organization's subscription and upload the firm logo

3.3 Joining an organization

An administrator can only add you if you already have a CrackLog account. When you are added, your own private workspace is absorbed into that organization and is deleted, and from then on your work is visible to the organization's members. This is only possible automatically when your private workspace contains no projects; if it does contain projects, the transfer requires a support request so that you and your firm can agree on what happens to that data.

3.4 Leaving or being removed

If an administrator removes you, you immediately lose access to the organization's data, the app clears its local copy from your device, and a new private workspace is created for you on your next sign-in. Work you contributed stays with the organization — including projects, scans, and the verification records bearing your name.

3.5 Roles and responsibilities

Where an organization is operated by a firm, that firm decides what inspection data is recorded in CrackLog, who may join, and how long the data is kept; we process that data on the organization's behalf in order to provide the Service. If you are a member of a firm's organization and want a copy of, correction to, or deletion of the organization's inspection records, contact your administrator first — and see Section 9 for the rights that apply to you directly. Firms subject to data protection laws such as the GDPR may need a data processing agreement with us; contact [email protected].

4. How We Use Your Data

We use collected information to:

  • Provide, maintain, and improve the CrackLog service
  • Authenticate your account, resolve your organization membership, and sync data across devices and between members
  • Process crack images through on-device computer vision and cloud AI analysis
  • Generate growth trend summaries and consolidated project PDF reports
  • Maintain the verification audit trail that makes inspection records defensible
  • Manage subscription entitlements and usage limits at the organization level
  • Send local reminder notifications you configure (processed on-device; we do not send push notifications from our servers)
  • Protect against fraud, abuse, and unauthorized access
  • Respond to support requests
  • Comply with legal obligations

5. AI Processing

CrackLog uses Google Gemini AI to analyze crack photographs and generate text summaries. When you request AI analysis:

  • Your crack photograph is sent as a JPEG image to our secure Firebase Cloud Functions
  • Our servers forward the image and associated measurement metadata to Google's Generative Language API (Gemini). The API key is held only on our servers and is never present in the app
  • For growth summaries, only historical measurement dates and widths are sent — not photographs
  • Project addresses, member names, and email addresses are not sent to the AI provider
  • AI responses are stored in your organization's records and displayed in the app

AI analysis requires an authenticated account and is subject to your organization's plan limits. Google's use of data sent to the Gemini API is governed by Google's Privacy Policy and applicable API terms.

AI-generated measurements are estimates. An engineer may override them, and CrackLog keeps both values — see Section 8.

6. Third-Party Services

We use the following third-party services that may process your data:

  • Google Firebase — Authentication, Cloud Firestore database, Cloud Storage, Cloud Functions, App Check, Analytics, and Crashlytics (Firebase Privacy)
  • Google Gemini — AI image analysis and text generation (Gemini API Terms)
  • Google Play — In-app subscription billing and purchase verification (Google Privacy Policy)
  • Google Sign-In — Optional authentication (Google Privacy Policy)
  • OpenCV — On-device computer vision processing (runs locally; no data sent to OpenCV)

We do not sell your personal information to third parties. We do not use your data for third-party advertising.

7. Data Storage & Security

Your cloud data is stored in Google Firebase infrastructure, primarily in the United States (us-central1 region for Cloud Functions). Data is organized per organization:

  • Your profile and organization membership: users/{your-uid}
  • Organization profile, plan, and usage: organizations/{org-id}
  • Projects: organizations/{org-id}/projects/{project-id}
  • Cracks: organizations/{org-id}/projects/{project-id}/cracks/{crack-id}
  • Scans and measurements: .../cracks/{crack-id}/scans/{scan-id}
  • Verification audit trail: .../scans/{scan-id}/verifications/{entry-id}
  • Reports: organizations/{org-id}/projects/{project-id}/reports/{report-id}
  • Photos and PDFs: orgs/{org-id}/projects/...; firm logo: orgs/{org-id}/branding/

Access to cloud data is restricted by Firebase Security Rules so that only authenticated members of an organization can read or write that organization's data. Plan, usage, subscription, and membership fields can only be written by our server-side functions, never by the app. All network communication uses HTTPS/TLS encryption, and Firebase App Check is used to help prevent unauthorized API access.

While we implement industry-standard safeguards, no method of transmission or storage is 100% secure. You are responsible for keeping your account credentials confidential, and administrators are responsible for who they add to their organization.

8. Data Retention

We retain data for as long as the organization it belongs to is active, or as needed to provide the Service:

  • Inspection data (projects, cracks, scans, photographs, reports) is kept until deleted by an administrator, or until the organization itself is deleted
  • When the last remaining member of an organization deletes their account, the organization's entire record set and stored files are permanently deleted
  • Removing a member does not delete the organization's data, and does not remove that member's name from records they created or verified
  • Subscription and invoicing records are retained as required for billing reconciliation and legal compliance
  • Usage counters reset monthly
  • Local device data persists until you uninstall the app, clear app data, or are removed from the organization

Verification records are immutable. Because inspection findings may be relied upon in regulatory filings, insurance matters, or legal proceedings, CrackLog is designed so that the original AI estimate and every engineer verification — including the verifier's name and timestamp — can never be altered or deleted by anyone, including us and including the person who created the entry. A later verification is added alongside earlier ones rather than replacing them. We retain these records on the basis of our and our customers' legitimate interest in maintaining a defensible inspection record and for the establishment, exercise, or defence of legal claims. They are removed only when the entire organization is deleted.

An administrator who is the only administrator of an organization with other members cannot delete their account until another member is promoted, so that a firm's records are never orphaned.

To request deletion of data beyond what the app allows, contact us at [email protected]. We will process verified requests within 30 days, subject to the immutability of verification records described above.

9. Your Rights & Choices

Depending on your location, you may have the following rights:

  • Access — View your organization's data within the app; view your own account details in Account settings
  • Correction — Edit project details, crack labels, component tags, and locations in the app. AI measurements are corrected by adding an engineer verification rather than by overwriting them
  • Deletion — Delete your account in Account settings. Deleting projects, cracks, and reports requires an administrator role; verification audit entries cannot be deleted while the organization exists
  • Portability — Export project PDF reports from the app; contact us for additional data export requests
  • Opt-out of marketing — We do not send marketing emails
  • Withdraw consent — Stop using the Service and delete your account

If you are a member of a firm's organization: you can always delete your own account, but the organization's inspection records — including work you contributed — remain with the organization. Requests relating to that data should be directed to your administrator, who controls it. We will assist administrators in fulfilling such requests.

California residents (CCPA): We do not sell personal information. You may request disclosure or deletion by contacting us.

EEA/UK residents (GDPR): Our legal bases for processing include contract performance (providing the Service), legitimate interests (security, service improvement, and maintaining a defensible inspection audit trail), and consent (where applicable). Where we process inspection data on behalf of a firm, that firm is the controller and we act as processor. You may lodge a complaint with your local data protection authority.

Camera & photo permissions: You can deny camera or gallery access, but crack scanning features will not function. You can revoke permissions in your device settings at any time.

Notifications: Reminder notifications are local only. You can disable them in the app or device settings.

10. Children's Privacy

CrackLog is a professional tool intended for business use and is not directed at children under 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.

11. International Transfers

CrackLog is operated from the United States. If you access the Service from outside the US, your data may be transferred to and processed in the United States and other countries where our service providers operate. By using the Service, you consent to such transfers. We rely on standard contractual clauses and provider safeguards where required by law.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page with an updated effective date. For material changes, we may notify you through the app or by email. Continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us:

  • Email: [email protected]
  • Website: https://crack-log.com
CrackLog

AI-assisted structural crack documentation for engineering firms and inspectors, with engineer-verified measurements and consolidated project reports.

Product

  • Features
  • How it works
  • Plans
  • Google Play

Legal

  • Privacy Policy
  • Terms of Service
  • Contact
© 2026 CrackLog. All rights reserved. crack-log.com