Data & security
What we do to protect your inspection data, described plainly. Last updated 5 September 2026.
Your data is stored in Australia
Accounts, customer records, inspection data and images are held in a Supabase project in the Sydney region (ap-southeast-2), and backups are kept in Australian-hosted storage. Four specific features send data overseas, all only in the circumstances the Privacy policy describes: AI drafting (the capture's images and readings go to Anthropic in the United States, whether triggered on the camera or requested on the web); every email you send to support@switchreport.app, whose content is also sent to Anthropic in the United States to help us triage and draft a reply — this applies automatically to every message, not just ones you opt into; a manually submitted problem report, which is emailed to our support mailbox through Google in the United States; and card payments on paid plans (processed by Stripe). Nothing else is moved offshore for processing.
Encrypted in transit
All traffic to switchreport.app uses HTTPS. Plain HTTP requests are redirected, and the
.app domain is on browsers' HTTPS-only preload list, so mainstream browsers
will not attempt an unencrypted connection.
One account cannot see another's data
Separation between accounts is enforced in the database using row-level security, not only in the application. Every record carries its owner, and the database refuses to return or accept rows belonging to anyone else. Stored images are similarly partitioned per account. Because the check is in the database, a fault in the website or camera app cannot on its own expose another customer's records. A small number of our own server-side operations run with elevated access (seat invitations, support alerts, AI usage metering, account deletion); we limit and review those.
Accounts
Accounts are created by us rather than by public sign-up. Passwords are stored hashed by our authentication provider and are never visible to us. Sign-in attempts are rate limited, and authentication events are logged so misuse can be investigated.
On the camera
The app stores its working data in the device's protected app storage, which other apps cannot read. Saved sign-in credentials are encrypted using the device's hardware-backed keystore. Builds we release are hardened so the app's data cannot be extracted over a USB cable.
Signing out erases the app's data from the camera, and warns you first if anything has not yet been uploaded. Copies saved into the device's own picture gallery are deliberately left in place as your own backup — see the Privacy policy for what that means if a camera is shared or passed on.
Backups
The database holding your account, customer, site and inspection records is backed up daily. Thermal and visual images are additionally backed up weekly to Australian-hosted storage, filed under system identifiers; the backup also holds generated report PDFs, which name the site and customer as the report does.
No third-party code on our pages
Everything the website loads — fonts, scripts, styles — is served from our own site. The typefaces are self-hosted, and the database library is a pinned, exact-version copy kept in our own tree with its checksum recorded, rather than a live download from a third-party CDN. Loading a page sends nothing to anyone except us and the service providers named in the Privacy policy, and no third-party CDN can change the code that runs on the page holding your session.
AI drafting
SwitchReport can draft the condition observation, the board description and the wording for an absolute-maximum reading. On the camera, turning AI on for an inspection sends every capture in it for drafting once the inspection reaches the web; on the web, you can request a draft for one capture or for a whole inspection, and requesting one may prepare the next captures in your queue ahead of time. A request carries that capture's thermal image, visual photo, the panel name you typed and the readings, not your customer records. Every request is logged against your account, and what the assistant drafted (and what you did with it) is recorded so reports stay auditable. The details, including the overseas processing involved, are in the Privacy policy.
What we do not do
- We do not sell, rent or trade your data, or your customers' data.
- We do not use advertising or tracking pixels on the signed-in application.
- We do not use your inspection images for any purpose other than producing your reports.
- We do not store payment card numbers — card payments are processed by Stripe.
If something goes wrong
If a data breach occurs that is likely to result in serious harm, we will assess it promptly — within 30 days of suspecting an eligible breach — and notify the Office of the Australian Information Commissioner and the people affected as soon as practicable, under the Notifiable Data Breaches scheme. The commitment is made formally in the Privacy policy.
Reporting a security problem
If you believe you have found a security issue in SwitchReport, please tell us at support@switchreport.app before disclosing it publicly. We will acknowledge you promptly and keep you informed while we fix it. We will not pursue anyone who reports a genuine issue to us in good faith.