Privacy Policy
InPersonForms (the "App") is developed and published by Sunlit Grace Pty Ltd (ACN 690 111 374). This Privacy Policy explains how we handle information in connection with the App. Sections 1 to 8 are about the App itself. Sections 9 and 10 cover this website, which is a separate thing and works differently.
1. Data Stored on Your Device
The App stores the following data locally on your device. We never receive any of it, and the App never sends it anywhere on its own:
- Client profiles: the name, email address, phone number, and any other profile details you record for each client.
- Form templates: PDF files you import and the field configurations you define on them.
- Signed forms: completed PDF documents containing client signatures and form data.
- Handwriting: ink written with Apple Pencil or a finger, kept alongside the form so it can be reopened and edited later.
- Attachments: photos you take with the camera or pick from your photo library, and files you add from the Files app, saved under the client you attach them to. Depending on what you attach, these can include identity documents, medical records, and other sensitive material.
All of this is stored in the App's own storage on your device. No account, login, or internet connection is required to use the App.
2. The App Does Not Send Your Data Anywhere
We operate no servers, and the App has no server-side component. It makes no network requests other than through Apple's StoreKit, which handles the in-app purchase and restoring it (see section 6). StoreKit carries no client data.
Everything else happens on your device, including PDF rendering, signature capture, and the text recognition used to find fields on an imported PDF.
3. Copies You Export, and Device Backups
The App can produce copies of your data that you then put somewhere yourself:
- Signed PDFs and attachments shared through the system share sheet.
- CSV exports of submission data from the Records tab.
- Backup archives: a single file holding your clients, templates, signed forms, attachments, and the PDFs behind them.
Each of these hands the file to a destination you choose, such as the Files app, iCloud Drive, email, or AirDrop. Once a copy leaves the App that way it is covered by whatever service or device receives it, not by this policy. Backup archives are not encrypted by the App, so keep them somewhere you trust.
Separately, iOS includes app data in device backups. If you use iCloud Backup, a copy of the App's data, client records and attachments included, forms part of that backup and is held by Apple under Apple's Privacy Policy . You can exclude the App from iCloud Backup in the Settings app, or use encrypted local backups instead.
4. No Analytics or Tracking in the App
The App contains no analytics SDKs, crash reporting tools, tracking pixels, or any other form of usage monitoring. We do not know how you use the App, how often you open it, which templates you create, or which clients you have stored.
5. Third-Party Code
The App integrates no advertising networks, analytics services, data brokers, or cloud services. It does build on two open-source libraries, GRDB (the on-device database) and ZIPFoundation (backup archives). Both run entirely on your device and transmit nothing.
6. In-App Purchases
The App offers an optional one-time in-app purchase ("Pro") to unlock additional features. All purchases are processed entirely by Apple via the App Store. We do not collect, process, or have access to any payment information, card details, or Apple ID data.
Please refer to Apple's Privacy Policy for information on how App Store transactions are handled.
7. Your Responsibility for Client Data
The App stores client personal information on your device: names, contact details, signatures, form answers, and any photos or documents you attach. Some of that can be sensitive, such as health information or a photographed identity document. You are responsible for handling it in accordance with the privacy laws that apply to you, including, where relevant, the Australian Privacy Act 1988 (Cth), GDPR, HIPAA, or other local regulations governing the collection of client information.
We recommend securing your device with a passcode or biometric authentication and enabling device encryption to protect stored client data.
8. Data Deletion
You can delete any client, template, signed form, or attachment from within the App at any time. Deleting a client also removes the forms and attachments filed under that client, including the underlying files. Deleting the App from your device permanently removes all locally stored data.
Copies you exported earlier are not affected by any of this. You need to delete those wherever you put them.
9. This Website
Everything above describes the App. This website is separate, and it does load two things from Google.
The first is a Google Ads tag, which measures which ads bring people here. It runs under Google Consent Mode: in the EEA, the UK, and Switzerland it is denied storage by default, so it sets no cookies until you accept. Elsewhere it runs unless you turn it off. On your first visit, wherever you are, you get a dialog with "Accept all" and "Essential only", and the "Cookie settings" link in the footer reopens it on any page if you change your mind. Choosing "Essential only" also expires the cookies the tag had already set. While storage is denied, Google still receives a request carrying no cookie and no persistent identifier, which it uses to estimate conversions in aggregate. We honour a Global Privacy Control signal from your browser as a refusal until you choose for yourself. Your choice is kept in your browser's local storage and is not sent anywhere.
The second is the Inter typeface, loaded from Google Fonts. That request tells Google your IP address and browser. It sets no cookies, and it is not tied to the ads tag.
The site has no accounts, no comments, and no other analytics. We do not sell anything here directly: the App is bought through the App Store.
10. Legal Bases and Your Rights (EEA, UK, and Similar Laws)
The App gives us nothing to hold. It has no accounts and sends us nothing, and the client records you keep in it are under your control, not ours, which makes you the controller of that data and us nobody at all in relation to it. Everything below is about this website.
Why we are allowed to process anything. The Google Ads tag stores and reads cookies only on your consent, which you give in the cookie dialog and can withdraw at any time through "Cookie settings" in the footer. While consent is refused, the tag still sends Google a request with no cookie and no persistent identifier; for that we rely on our legitimate interest in knowing in aggregate whether our advertising works, and you can object to it.
How long anything is kept. We store nothing about visitors ourselves. Your cookie choice sits in your own browser's local storage until you clear it. What the ads tag collects is held by Google under its own policy and retention rules.
Where it goes. Data the tag sends is processed by Google outside the EEA and the UK, under Google's own terms rather than any system we run.
Your rights. You can ask for access to your personal data, and for it to be corrected, deleted, restricted, or given to you in a portable form, and you can object to processing. Because we hold nothing that identifies you, the effective route for anything the ads tag collected is Google's Data & Privacy page . Write to us at hello@sunlitgrace.com and we will answer either way.
Complaints. You can complain to a data protection authority. In the EEA that is the supervisory authority for the country where you live or work; in the UK it is the Information Commissioner's Office.
11. Children's Privacy
The App is not directed at children under the age of 13. It is intended for use by professionals collecting signatures from adult clients. The App itself collects no personal information from any user.
12. Changes to This Policy
We may update this Privacy Policy from time to time, for example if the App adds new features such as cloud sync. Any changes will be published on this page with an updated date at the top. We encourage you to review this page periodically.
13. Contact
If you have any questions about this Privacy Policy or the App's data practices, please reach out:
Sunlit Grace Pty Ltd
ACN 690 111 374
Email: hello@sunlitgrace.com
Website: https://sunlitgrace.com