Privacy Policy for TrustLogger

Last Updated: August 15, 2026

Who this policy covers

This policy applies to TrustLogger's Android app, progressive web app (PWA), website features and related support services. TrustLogger is operated by MidPulse Labs in the United Kingdom. MidPulse Labs is the controller of the personal information described in this policy.

Information we collect

Account and profile information

When you create an account, we process your email address, authentication identifier, username and any profile display information you provide. Authentication credentials are handled by our authentication provider; we do not store readable passwords in the TrustLogger application database.

Visits, social features and user content

We process the visits you log, including site, date, optional notes, favourites and related timestamps. If you use social features, we process friend requests, friendships and visit-participant tags. Tagged people can see the visit details shared with them, including the site, date and any notes attached to that visit.

Photos and user content

When you upload a photo, we process the image, a resized version and thumbnail, and associated information such as the relevant site or visit, your account identifier, storage reference, dimensions and upload time. Photos can identify people and may reveal where someone was. Please do not upload a photo of another person unless you have their permission, and do not upload content that is unlawful or infringes someone else's rights.

Photos are private to the account that uploaded them. You can view and delete your own photos in TrustLogger. If a photo concerns you or you believe it should be removed, email privacy@midpulselabs.com with enough detail for us to find it.

Location, device and technical information

If you choose to enable location access, TrustLogger uses your device location to provide map and nearby-site features. The Android app may request the permissions needed for the optional features you choose, such as location or notifications. You can withdraw these permissions in your device settings. We also process limited technical information needed to run and secure the service, such as session information, browser or device context, network status and error information.

Web cookies and local storage

The PWA uses essential authentication cookies to keep you signed in, and browser local or session storage for features such as preferences and short-lived app state. These are necessary to provide the service and are not used for behavioural advertising. The Android app uses its own on-device storage rather than browser cookies.

Why we use information and our lawful bases

Under UK data protection law, we process account, visit, photo and social-feature information where necessary to provide the service you request and perform our contract with you. We use legitimate interests where necessary to secure, maintain and improve TrustLogger, prevent misuse and respond to support requests, having considered your rights and interests. We rely on consent where it is appropriate for optional device permissions or features; you can withdraw that consent through device settings or by stopping use of the feature. We may also process information where necessary to comply with a legal obligation or establish, exercise or defend legal claims.

How we share information

We share information with people you choose to involve through TrustLogger's friend and visit-tag features, as described above. We use service providers to operate TrustLogger, including Supabase for authentication, database and private file storage; Google services where you choose Google sign-in or mapping features; and mobile notification-delivery providers where notifications are enabled. These providers process information on our instructions where they act as processors. We may also disclose information where required by law or to protect the rights, safety and security of users, MidPulse Labs or others.

International transfers

Some of our providers may process personal information outside the UK. Where this is a restricted transfer, we use a transfer mechanism permitted by UK data-protection law, such as UK adequacy regulations or appropriate safeguards, and take account of the security of the transfer. You can contact us for further information about the safeguards relevant to your information.

Retention and deletion

We retain account information and content while your account is active, unless you delete the relevant content sooner. You can delete individual photos and visits where the feature provides that option, or request account deletion in Profile. When an account is deleted, we remove or anonymise associated active-service data within 30 days unless we need to retain limited information for legal, security or fraud-prevention reasons. Secure backup copies may remain until they are replaced under our backup cycle and are not used for normal service activity.

Your rights

If UK data-protection law applies to you, you may have the right to request access, correction, erasure, restriction, objection and data portability. Where we rely on consent, you may withdraw it at any time. To exercise a right or ask for a copy of your information, contact privacy@midpulselabs.com. We may need to verify your identity before acting on a request.

You can also complain to the UK Information Commissioner's Office (ICO). Details are available at ico.org.uk/make-a-complaint. If you are in the EEA, you may also have rights under applicable EU data-protection law.

Security

We use measures designed to protect information, including encrypted connections, authentication controls, private storage, signed access links and database access controls. No internet service can guarantee absolute security. If we become aware of a personal-data breach, we will assess it and take the steps required by applicable law, including notifying regulators and affected people where required.

Children

TrustLogger is not intended for children under 13. If you believe a child has provided personal information to us, please contact us so we can investigate and take appropriate action.

Changes to this policy

We may update this policy as TrustLogger changes or legal requirements develop. We will publish the updated version on this page and update the date above. Where a change is material, we will take appropriate steps to bring it to users' attention.

Contact us

For privacy questions, rights requests or photo-removal requests, contact MidPulse Labs at privacy@midpulselabs.com.