Proof — Privacy Policy
Last updated: July 10, 2026
Proof (“Proof,” the “App”) is operated by Madmar Labs LLC (“we,” “us,” or “our”). Proof is a mobile application (iOS and Android) that helps independent home bakers running cottage food businesses manage custom cake and baked-goods orders.
This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices available to you. It applies to your use of the App.
Two kinds of people are described in this policy. Most of this policy is about you, the baker who installs Proof and creates an account. But bakers also enter information into Proof about their own customers — people who never install Proof, never create an account, and never interact with us directly. Section 4 explains how that customer information is handled and what it means for both bakers and their customers.
1. Information We Collect
1.1 Baker account and profile information
When you create and use a Proof account, we collect:
- Email address and a password (your password is hashed and managed by our authentication provider, Supabase — we never see or store your password in readable form).
- Your name.
- Business name (optional).
- Phone number.
- Pickup address.
- State, which is used to provide cottage-food compliance information (see Section 8).
- Business logo (optional).
- Payment handles — your Venmo, PayPal.Me, and/or Cash App handles (all optional), used to help you request payment from your own customers.
- Notification preferences.
1.2 Billing information
Subscription billing is handled by Stripe, Inc. Stripe processes and stores all payment and card information directly. Proof never receives or stores your card number or full payment details. We store only a Stripe customer identifier and your subscription tier so we can provide the features associated with your plan.
1.3 Information you enter about your own customers
As part of managing your orders, you may enter information into Proof about your customers, including:
- Customer name, phone number, email address, Instagram handle, and free-text notes;
- Order details, event and pickup dates, and delivery address;
- Allergy information associated with an order; and
- Photos — order reference/inspiration images and finished-product photos.
This information is entered by you, the baker, about individuals who do not themselves install or use Proof. See Section 4 for how this affects responsibilities and consent.
1.4 Customer-facing links (no customer account required)
Proof provides two optional customer-facing web surfaces, each accessed through a private, single-purpose link (a “bearer-token” URL). Neither requires the customer to log in or create an account, and neither collects information beyond what is needed for that one transaction:
- Intake link — a customer can submit an order request.
- Signature link — a customer can review and sign a document or contract.
1.5 Device permissions
The App requests the following device permissions, each only for the stated purpose:
- Photo library and camera — to add your business logo, attach order photos, and capture photos of expense receipts.
- Notifications — to deliver local, on-device reminders only. Proof does not operate a push-notification service and does not send your reminders through an external server.
- File access — to import customer lists via CSV and to upload documents.
You can grant or deny each permission through your device settings; denying a permission may limit the related feature.
2. How We Use Information
We use the information described above to:
- Provide, operate, and maintain the App and its order-management features;
- Authenticate your account and keep it secure;
- Provide subscription features according to your tier;
- Provide cottage-food compliance information based on your state (see Section 8);
- Provide the optional AI features described in Section 3, when you choose to use them;
- Generate documents, labels, invoices, and receipts that you create;
- Deliver on-device reminders you have enabled; and
- Respond to your support requests.
We do not sell your information, and we do not use it for advertising. See Section 6.
3. Artificial Intelligence (AI) Features
Proof includes two separate and optional AI features. They are described individually below because they send different kinds of information to a third-party AI provider, OpenAI.
3.1 Message / DM parsing — important disclosure about customer information, including allergy information
Proof offers a feature that lets you paste a customer's message or direct-message (DM) text into the App so that an AI tool can extract order details for you (for example, the requested item, dates, and other details mentioned in the message).
When you use this feature, the full text you paste is transmitted to OpenAI (model: gpt-4o-mini) for processing. That text may include anything the customer wrote — including the customer's name, phone number, and any allergy information they mentioned. In other words, a customer's message, including potentially sensitive allergy information, may be transmitted to a third-party AI service as a necessary part of this feature.
This feature is optional. If you do not want a customer's message sent to OpenAI, do not use the message-parsing feature; you can enter order details manually instead.
3.2 Cake design mockup generation
Proof offers a separate feature that generates cake design mockup images using OpenAI (model: gpt-image-1). This feature sends only design details — such as flavor, color, and style. It does not send the customer's name, contact information, or allergy data.
OpenAI processes information it receives under its own terms and retention practices. See Sections 5 and 7.
4. Your Customers' Information and Consent
Much of the customer information in Proof (Section 1.3) is entered by you, the baker, about people who never install Proof, never create an account, and never agree to our terms themselves. Because those individuals do not interact with us, you are responsible for having any notice or consent required to enter their information into Proof and to use features that transmit it — including, in particular, the message-parsing feature described in Section 3.1, which may send a customer's message (including allergy information) to OpenAI.
We handle the customer information you enter only to provide the App's features to you.
5. How We Share Information — Service Providers
We share information only with the following service providers (“sub-processors”), each for the limited purposes described:
| Provider | What is shared | Purpose |
|---|---|---|
| Stripe, Inc. | Your (the baker's) billing information only | Subscription payment processing. Stripe stores card/payment data directly under its own terms; Proof stores only a customer ID and tier. |
| OpenAI | (a) The full message text you paste into the message-parsing feature, which may include a customer's name, phone, and allergy information (gpt-4o-mini); and (b) cake design details only, never customer identity or allergy data (gpt-image-1) |
The two AI features described in Section 3. |
| Supabase | All data stored by the App | Supabase is our underlying infrastructure, database, authentication, and file-storage host — our primary sub-processor. Data you and the App store is held on Supabase's infrastructure. |
Each of these providers processes data under its own privacy terms and, where applicable, data-processing terms. We may also disclose information if required by law or to protect our rights, and we may transfer information in connection with a business transfer (e.g., merger or acquisition).
We do not sell personal information and do not share it with advertising networks or data brokers.
6. No Analytics, Tracking, or Advertising
Proof uses no analytics SDK, no tracking technology, no advertising identifier, and no crash-reporting SDK of any kind. We do not build advertising profiles, and we do not track you across other apps or websites. The only third parties that receive data are the service providers listed in Section 5, and only for the purposes stated there.
7. Data Retention and Deletion
7.1 Self-service deletion
You can delete your account at any time from within the App. When you do, the App:
- Cancels any active Stripe subscription first;
- Deletes all of your user-owned data across our database and file storage; and
- Deletes your account itself.
7.2 Data that may persist outside our control
Even after you delete your account, some data may persist with our service providers under their own independent policies, which we do not control:
- Stripe retains its own transaction records as required by its own legal and retention obligations, even after your account is deleted.
- Supabase infrastructure-level backups may retain data for a period of time before those backups age out on their normal cycle.
- Any text already sent to OpenAI (for example, through the message-parsing feature) is subject to OpenAI's own independent retention policy, separate from your account deletion.
8. Cottage Food Compliance Information
Proof provides cottage food legal compliance information (such as revenue caps and product-category rules) as an informational tool, based on our best-effort research into publicly available state law. This information is offered as a convenience within the App.
This information is provided for informational purposes only and is not legal advice. Cottage food laws vary by state, change over time, and may be interpreted or enforced differently across jurisdictions. You are solely responsible for verifying your own compliance obligations directly with your state's relevant regulatory agency, and we recommend consulting a licensed attorney for guidance specific to your situation.
9. Children's Privacy
Proof is not directed at or intended for use by children. We do not knowingly collect personal information from children. If you believe a child has provided information through the App, please contact us (Section 12) and we will take appropriate steps to delete it.
10. Your Rights and Choices
You can access and delete the information associated with your account using the App's in-app self-service account-deletion tool (Section 7.1), which removes your user-owned data as described. If you need help exercising these choices, contact us at the address in Section 12.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Your continued use of the App after an update takes effect constitutes your acceptance of the revised policy.
12. Contact Us
If you have questions about this Privacy Policy or your information, contact:
Madmar Labs LLC
support@proofbaker.app