Privacy Policy
Last updated: 21 July 2026
1. Introduction
1.1 This Privacy Policy explains how Drophouse Ltd handles information when you use the Sight Buddy mobile application (the “App”).
1.2 The short version: Sight Buddy has no backend of ours. We do not collect, store, or receive your images, audio, text, or usage data. The only information that reaches us is an anonymous crash report if the App crashes — and you can turn that off.
1.3 Drophouse Ltd is the data controller for the crash diagnostics described in section 9. Section 12 sets out our role, and yours, in more detail.
2. Contact details
2.1 Drophouse Ltd
2.2 5 Brayford Square, London E1 0SG, United Kingdom
2.3 Company number: 17182597
2.4 Email: contact@drophouse.uk
3. Who this policy applies to
3.1 This policy applies to anyone who downloads or uses Sight Buddy.
3.2 The App is an accessibility aid for people with low or no vision.
3.3 There is no sign-up. We do not ask for your name, your email address, or any other identifier, and the App does not create an account for you.
4. Summary of data practices
4.1 No accounts, no sign-up, no advertising, no analytics, and no behavioural tracking.
4.2 Object detection, printed-text reading (OCR), colour detection, light detection, and speech recognition all run on your device.
4.3 We receive no images, no audio, no recognised text, and no usage data.
4.4 AI features are optional and require your own OpenAI API key. When you use them, your request goes directly from your device to OpenAI — it does not pass through us.
4.5 If the App crashes, an anonymous crash report is sent to Google Firebase Crashlytics. You can turn this off at any time in Settings → Privacy → “Send crash reports”.
4.6 If you agree to the prompt, the App can download open-source speech-recognition model files from GitHub once.
4.7 Earlier beta versions (v1.x) used a cloud AI service routed through our own server. That service has been shut down and all data it held has been permanently deleted (see section 11).
5. No accounts, no servers of ours
5.1 Sight Buddy has no backend operated by Drophouse Ltd. There is no database of ours, no user account, no login, and no server-side profile of you.
5.2 We do not collect, store, or receive your images, audio, text, or usage data.
5.3 Because we hold no account and no identifier for you, we are not able to link activity in the App to you as an individual.
6. On-device processing
6.1 The following features run entirely on your device: finding objects, reading printed text (OCR), detecting colour, measuring light level, and speech recognition.
6.2 Camera images and microphone audio are processed in memory on your device and are never uploaded by us.
6.3 Your App settings, and the record that you accepted the Terms of Use, are stored in your device's private storage. They are removed when you uninstall the App.
7. Optional AI features use your own OpenAI key (BYOK)
7.1 AI features are optional. They work only if you choose to add your own OpenAI API key in Settings.
7.2 Your key is stored encrypted on your device only, using a non-exportable key held in the Android Keystore. It is never transmitted to us, and never to any third party other than OpenAI.
7.3 With no key saved, the App makes no AI requests at all.
7.4 When a key is saved, exactly three things can be sent directly from your device to OpenAI, and each is sent only at the moment you ask for it:
- Image chat — the captured photo and your question.
- Text chat — the text extracted from the capture (not the image itself) and your question.
- Find objects — the phrase you spoke, and only when the App cannot match it to a known object on your device. No image is sent.
7.5 Everything else — object detection, reading text aloud, colour, light, and speech recognition once the voice models are on your device — runs on your device and sends nothing.
7.6 These requests are initiated by you, sent directly from your device to OpenAI, billed to your own OpenAI account, and governed by OpenAI's privacy policy and terms. Drophouse Ltd neither receives nor stores their content. See OpenAI's privacy policy.
7.7 Please be aware: do not point the camera at information you do not wish to send to OpenAI.
7.8 You can remove your key at any time in Settings. Removing it disables all AI features.
7.9 Removing the key from Sight Buddy — or uninstalling the App — deletes only the copy stored on your device. The key itself belongs to your OpenAI account and stays active there until you revoke it yourself at platform.openai.com/api-keys. We never receive your key, so we cannot deactivate it for you.
8. One-time voice model download
8.1 On first use, and only if you accept the prompt, the App can download open-source speech-recognition model files (about 154 MB) from GitHub.
8.2 This is a plain file download. We receive nothing from it. That connection is governed by GitHub's privacy statement.
8.3 The download is never automatic, and the App works without it — speech recognition falls back to your device's built-in recogniser until the files are present.
9. Crash diagnostics (Firebase Crashlytics)
9.1 If the App crashes, an anonymous crash report is sent to Google Firebase Crashlytics so that we can find and fix the fault.
9.2 A report contains a stack trace, your device model, your operating system version, and the App version. It does not contain your name, your email address, your images, your audio, or your text.
9.3 No advertising ID, no analytics, and no behavioural tracking. The App does not use Google Analytics, and advertising-ID permissions are stripped from the App at build time.
9.4 You can turn crash reporting off at any time in Settings → Privacy → “Send crash reports”.
9.5 Crash reports are processed by Google. See Google's privacy policy and Firebase's privacy information.
10. Google Play
10.1 Google provides us with aggregate install and performance statistics as the operator of the Play Store, in accordance with the Google Play terms.
10.2 These statistics are aggregated and do not identify you to us.
11. Historic data from earlier beta versions
11.1 Earlier beta versions (v1.x) used a cloud AI service routed through a server of ours, together with a pseudonymous device identifier, daily usage quotas, and an anonymous feedback channel.
11.2 That service has been shut down, and all data it held has been permanently deleted.
11.3 The current version of the App sends no data to any server operated by us.
12. UK GDPR and EU GDPR
This section applies to users in the United Kingdom and the European Union.
12.1. Who the controller is
Drophouse Ltd (UK) is the controller for the crash diagnostics described in section 9.
For AI requests, you are effectively in control: you supply your own OpenAI API key, you trigger each request, and the data goes to OpenAI under your own OpenAI account and OpenAI's terms. Drophouse Ltd neither receives nor stores that content.
12.2. Lawful basis
Crash diagnostics are processed under legitimate interests (Article 6(1)(f)) — keeping the App stable and safe for the people who depend on it — and are limited to anonymous, pseudonymous technical data.
No special-category data is processed. No advertising or analytics processing takes place, so no consent banner is required.
12.3. What we hold
Essentially nothing: no accounts, no contact details, no images, no audio, and no usage profiles. Crash reports are pseudonymous and are retained by Firebase Crashlytics in line with Google's retention period, typically 90 days.
12.4. Your rights
You have the right of access, rectification, erasure, restriction of processing, objection, and data portability, and the right to complain to a supervisory authority — the Information Commissioner's Office (ICO) in the United Kingdom, or your national data protection authority in the European Union.
We should be straightforward about one practical limit: because we hold no account and no identifier linking a person to a crash report, we may be unable to locate data relating to a specific individual. You can stop all crash reporting by turning it off in Settings, or by uninstalling the App. Any data held by OpenAI in connection with your own API key can be deleted through your own OpenAI account.
12.5. International transfers
Crash diagnostics are processed by Google (Firebase), and the AI requests you initiate are processed by OpenAI. Both may process data outside the United Kingdom and the EEA under their own safeguards, such as standard contractual clauses or adequacy decisions.
See Google's privacy policy and OpenAI's privacy policy.
12.6. Right to object and opt out
You can turn crash reporting off at any time in the App: Settings → Privacy → “Send crash reports”. This is available in version 2.1.0 and later.
Because the App carries out no advertising, analytics, or behavioural tracking, there is nothing further to opt out of. AI features send nothing unless you have added your own key and asked for an answer.
12.7. Contact
Privacy enquiries: contact@drophouse.uk.
12.8. EU representative
Drophouse Ltd relies on the Article 27 exemption for occasional, low-risk processing and has not appointed an EU representative.
13. Retention
13.1 Your App settings and your acceptance record remain on your device until you uninstall the App.
13.2 Your OpenAI API key remains encrypted on your device until you remove it in Settings or uninstall the App.
13.3 Crash reports are retained by Firebase Crashlytics in line with Google's retention period, typically 90 days.
13.4 We hold no other data, so there is nothing else for us to retain or delete.
13.5 Content you send to OpenAI is handled under OpenAI's own retention policy and the settings of your OpenAI account.
14. Security
14.1 Your OpenAI API key is encrypted at rest using AES-256-GCM with a non-exportable key held in the Android Keystore, hardware-backed where your device supports it.
14.2 All network connections made by the App use encrypted transport (HTTPS/TLS).
14.3 The App is open source, so its handling of your data can be independently inspected: github.com/DrophouseLtd/SightBuddy.
14.4 No system is completely secure, but we take appropriate steps to protect your data — the most effective of which is not collecting it.
15. Children
15.1 Sight Buddy is not directed at children under 13, and we do not knowingly collect data from children.
15.2 Because we operate no servers and hold no accounts, we do not hold personal data about any user, including children. If you have a concern, contact us at contact@drophouse.uk.
16. Permissions
16.1 The App asks for camera and microphone access, and uses internet access and vibration (haptic feedback).
16.2 You can turn these off in your device settings. Some features will stop working if you do.
16.3 The App does not request location, contacts, or an advertising ID.
17. Changes to this policy
17.1 We update this policy from time to time.
17.2 We will post the new version on our website and update the “Last updated” date at the top of this page.
17.3 Using the App after changes take effect means you accept the updated policy.
18. Other documents
18.1 Use of Sight Buddy is also subject to our Terms of Use.
18.2 This Privacy Policy prevails for all privacy matters.