Legal
Privacy Policy
Effective 28 August 2026 · Last updated 28 August 2026
Fiber Color Code is a field tool for fiber optic technicians. This policy describes exactly what the app collects, why, who it is shared with, and how long it is kept. It is written against what the software actually does, not from a template.
The app is operated by Fiber Education, a sole proprietorship based in Kentucky, United States ("we", "us", "our"). Contact us at privacy@fibercolorcode.app.
1. Who this policy covers
Fiber Color Code is sold to contracting companies and used by their crews. That means two kinds of people use it:
- Account holders — the person or company that buys a workspace.
- Crew members — technicians invited into an organization or team by their employer.
If your employer invited you, they control the workspace, decide what work data is entered, and can see the records described below — including your check-in and check-out locations. We process that data on their behalf. Questions about your employer's use of the app should go to them first; we will still honor the rights described in section 7.
2. What we collect
Account and profile
- Name, email address, phone number, company name, and profile photo, as you enter them.
- Authentication credentials handled by Firebase Authentication. If you sign in with Google, we receive your Google account's email address and basic profile — never your Google password.
- A push notification token, so we can notify you when work is assigned to you.
Work content you create
- Splice plans: the location name you type, cable configurations, fiber counts, case types, and the generated splice assignments.
- GPS coordinates attached to a splice plan, when you use the GPS button or pick a point on the map.
- Photos you attach to a plan.
- Handwritten signatures captured on-device when you sign off a plan, stored as an image alongside a SHA-256 hash used to detect later alteration.
- An activity log recording who created, edited, exported, shared, or attached photos to each plan, with timestamps and the acting user's email address.
- Organization records: customers, work orders (including PO numbers, scheduled dates, and notes), and materials with unit costs.
Time and location records
See section 3 — this category gets its own treatment.
Technical and diagnostic
- Crash reports and diagnostics via Firebase Crashlytics on iOS and Android: stack traces, device model, and OS version. Crashlytics is not used on the web version.
- Abuse-prevention signals via Firebase App Check. On the web this uses Google reCAPTCHA v3, which assesses whether a request comes from a real browser.
- Daily counters of invitations sent and photos uploaded per user, used only to enforce rate limits.
Stored on your device
The app keeps a local copy of your workspace so it works without signal: a SQLite database on iOS and Android, browser storage on the web, plus small preferences such as your last selected workspace. Signing out clears this local copy.
3. Location data and workforce tracking
Read this section if you are a crew member. The app records your physical location at specific moments, and your organization's administrators can see it.
Location is captured in three distinct ways, and they are not the same:
Check-in and check-out coordinates — stored, and visible to your employer
When you check in or out of a work order, the app records your GPS coordinates and the timestamp against that time entry. These are retained as part of your employer's records and can be viewed by organization owners and administrators, including in daily production reports. If location permission is denied or times out, check-in still succeeds without coordinates.
Splice plan coordinates — stored, tied to the job, not to you
Using the GPS button or the map picker attaches coordinates to that splice plan so the site can be found again. These describe a location in the field, not your movements. The app does not use these coordinates to rename or relabel a plan you have named.
Live map position — shown to you, never stored
While the Map screen is open, the app follows your device location to draw the blue "you are here" dot. This is used only to render the map on your own screen. It is not written to our servers and no one else can see it.
The app never tracks your location in the background or when it is closed. You can revoke location permission at any time in your device settings; the app continues to work, and check-ins simply record no coordinates.
Notice to employers: some U.S. states require that you give employees written notice before tracking their location. Using this feature is your decision and your legal responsibility. We provide this section so your crews can be told plainly what is collected.
4. Why we use it
| Purpose | Data used |
|---|---|
| Provide the app and sync your work across devices | Account, work content, local cache |
| Control who can see what | Account, team and organization membership |
| Produce as-built PDFs, CSV exports, and daily reports | Work content, signatures, photos, time entries |
| Notify you when work is assigned | Push token, assignment records |
| Bill for paid plans | Account, subscription status |
| Keep the service stable and prevent abuse | Crash diagnostics, App Check, rate-limit counters |
We do not sell your data, share it with advertisers, use it for behavioral advertising, or use your splice plans, photos, or customer records to train machine learning models.
5. Who we share it with
We use the following service providers. Each receives only what it needs.
| Provider | Purpose | What it receives |
|---|---|---|
| Google (Firebase) | Authentication, database, file storage, server functions, crash reporting, push notifications | Account, work content, photos, signatures, diagnostics |
| Google reCAPTCHA | Abuse prevention on the web | Browser and request signals, IP address |
| Mapbox | Map tiles and imagery | IP address and the map area being viewed |
| Stripe | Subscription payments on the web | Billing contact and payment details, entered directly with Stripe |
| RevenueCat | Validating in-app purchases | Purchase receipts, account identifier |
| Apple, Google Play | Processing mobile purchases | Payment details, under their own policies |
| Resend | Sending invitation and notification emails | Recipient email address and message contents |
We never see or store your full card number. Card details are handled entirely by Stripe, Apple, or Google.
We may also disclose data if legally required, or as part of a business transfer — in which case we will say so before your data moves.
6. How long we keep it
- Active data is kept while your workspace exists.
- Deleted items (plans, templates, teams, organizations, and user profiles) are soft-deleted first and recoverable for 30 days, then permanently erased by an automated daily job, including associated photos and signature files.
- Backups. Organizations receive a nightly backup and we keep the most recent 14. Deleted content can therefore persist in a backup for up to 14 days after deletion, even once removed from the live database.
- Crash diagnostics are retained under Google's Crashlytics retention schedule.
7. Your rights and choices
- Access and portability — Profile → Export My Data produces a JSON file containing your profile and every workspace's plans and templates. Individual plans export as PDF or CSV.
- Correction — edit your profile in the app at any time.
- Deletion — Profile → Delete Account, or see our deletion page. If you cannot sign in, email us.
- Notifications — turn off push notifications in your device settings.
- Location — revoke the permission in your device settings.
Depending on where you live you may have additional rights, including to object to or restrict processing. Email privacy@fibercolorcode.app and we will respond within 30 days. We will not discriminate against you for exercising a right.
If your employer administers your workspace, some requests may need to be directed to them, and we will tell you if that is the case.
8. Security
Data is encrypted in transit. Access is enforced server-side by security rules evaluated on every read and write, so membership in a team or organization determines what you can reach — it is not enforced only in the app. Signature images are write-once and carry a content hash. Uploads are attributed to the uploading account and rate-limited. Administrative operations such as account restoration run through verified server functions rather than trusting the client.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your data, we will notify you as required by law.
9. International users
We operate in the United States and our providers store data there. If you use the app from outside the U.S., you understand your data is transferred to and processed in the U.S., which may have different data protection laws than your country.
10. Children
Fiber Color Code is a professional tool and is not directed to children. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, email us and we will delete it.
11. Changes
If we change this policy we will update the date above. For material changes affecting how we use data you have already given us, we will give notice in the app or by email before the change takes effect.
12. Contact
Privacy questions and requests:
privacy@fibercolorcode.app
General support: support@fibercolorcode.app