Privacy Policy
BVL - Bright Vision Lab
This policy explains how this application handles information and how to contact us about privacy.
Information we process
Bright Vision Lab stores room plans, project names, fixture positions and settings, saved comparison views, lesson progress, and language, measurement, and appearance preferences on your device. A random installation secret is created on the device and stored in Keychain. When backup is enabled, project data and lesson progress are sent to our server; the server stores a bcrypt hash and SHA-256 fingerprint of the secret for authorization, not the plain secret. The hosting service receives network requests and may process IP addresses, request metadata, and infrastructure logs. We do not ask for an account, password, email address, contacts, location, or payment data.
How we use information
Local data keeps your projects and lessons available offline. The server uses the installation secret to restrict backup and synchronization to this installation and stores project and progress records so changes can synchronize when a connection returns. Request identifiers and operational errors help operate and troubleshoot the service. The app does not use advertising, analytics, or outbound email features.
Service providers and sharing
Railway hosts the application server and PostgreSQL database and processes requests and infrastructure logs as our hosting provider. Network and hosting infrastructure may process connection metadata necessary to deliver the service. We do not sell personal data or send project contents to advertisers, analytics providers, or email services. There are no third-party SDKs in the app beyond Apple system frameworks.
Data retention
Projects, lesson progress, and preferences remain locally until you delete them or remove the app, subject to device backup behavior controlled by Apple. Server project and progress records remain while backup is enabled until you delete the installation's server data. Deleting server data removes active database rows for that installation. Railway may retain backups and infrastructure logs under its own operational policies; we cannot promise immediate removal from those systems or state a fixed period that has not been established. The Keychain secret may remain on the device until the app deletes it through a data-deletion action; the secret uses a device-only Keychain setting and is not intended to transfer to another device.
Deleting your information
In Settings, Delete server data requests deletion of this installation's server records, clears the installation secret, and turns backup off while keeping local projects. Delete all local data removes local projects and lesson progress and requests deletion of the server backup. If offline, the deletion request remains queued on the device and retries when a connection returns; the secret is cleared only after the server confirms deletion. A lost installation secret cannot be recovered to access or delete the associated server records through the app. For privacy requests, contact Thackery890@icloud.com; we may need the installation secret or other information sufficient to identify a record, and we cannot identify an anonymous installation from a name or email alone.
Permissions and your choices
The app does not request location, camera, microphone, contacts, or notification permission. You can stop network backup using Settings and continue working with local projects. You can restrict the app's network access through device settings; queued changes will wait for connectivity while backup remains enabled.
Your privacy rights
You can view, edit, and delete your own project and lesson data in the app. The app does not currently provide a file export feature. You can request information or deletion help by emailing Thackery890@icloud.com. The app has no account or email-based identity, so we may be unable to match a request to server records without the installation secret. Rights available under applicable law may vary by location.
Security
The app sends server requests over HTTPS. It generates a random installation secret with the operating system's secure random source and stores it in the device Keychain. The server checks this secret on each private request, stores a bcrypt hash rather than the plaintext secret, and limits records by installation. Local project files and the offline queue use the device's app storage. No system can guarantee absolute security; protect access to your device and its backups.
Children’s privacy
Bright Vision Lab is designed for adults and is not directed to children. The product does not knowingly request a child's name, contact details, or account information. If you believe a child's data was provided, contact Thackery890@icloud.com so we can review what can be identified and removed.
Changes to this policy
We may update this policy when product features, hosting, or data practices change. The current version and effective date will be published on this page. Questions about the policy can be sent to Thackery890@icloud.com.