Privacy Policy
Rapid Box Layout
This policy explains how this application handles information and how to contact us about privacy.
Information we process
Rapid Box Layout stores the spaces you name, their dimensions and types, item names, categories, dimensions, weights, fragile flags, positions and unload order, and your load scenarios on your device using SwiftData. Your language, unit preference and selected space are stored in device preferences. If backup is enabled, the app sends scenario data and associated space details to its server. A random installation secret is stored in the device Keychain; the server stores a lookup digest and bcrypt hash of that secret, an installation identifier and creation time, and scenario identifiers, JSON payloads and update times. The server necessarily receives network requests and related connection metadata. No account, email address, location, contacts or payment data is requested by the app.
How we use information
Local data is used to draw loading plans, calculate fit, weight distribution, unload order and scenario comparisons while offline. The optional server backup stores and retrieves scenarios for this installation and checks the installation secret before returning or changing private data. Device preferences control language and measurement units. Request metadata is used by the hosting infrastructure to operate and protect the service.
Service providers and sharing
Backup data is hosted in PostgreSQL on Railway, which provides the application service and infrastructure and may process connection metadata and infrastructure logs. The app has no analytics, advertising, email delivery or social sign-in provider. We do not sell plan data. Application error logs contain request ID, method, path and error code, not the authorization secret or request body.
Data retention
Local plans remain on the device until you delete a space or the app data. Server scenarios and the installation record remain until the installation is deleted through Settings or the service is discontinued; no fixed automatic expiry is implemented. Deleting server data removes the active installation and its scenario rows and invalidates its secret. Railway may retain infrastructure logs or managed backups under its own operational policies; this app does not control or promise immediate erasure of those copies and does not implement a separate application backup archive.
Deleting your information
You can delete a space locally in the app. In Settings, Delete server data sends an authorized deletion request that removes this installation and its scenarios from the live database and invalidates the secret while leaving local plans on the device. To erase local app data, delete the spaces in the app or remove the app and its data using iOS controls. A later manual backup creates a new installation secret. Loss of the secret prevents restoration of its server data; there is no account recovery.
Permissions and your choices
The app does not request location, camera, microphone, photos, contacts or notification permission. Network access is used for optional backup and for opening this policy. You can stop using backup in Settings by deleting server data; the core planner continues to work offline. You can withdraw any system permission through iOS Settings if a future version requests one, and this policy will be updated first.
Your privacy rights
You can view, change and remove local plan data in the app, reveal your installation secret in Settings, and delete server data there. For privacy questions or requests about data under our control, contact YewhurstYarrowby223@icloud.com. We may need the installation secret or other reasonable proof of control to identify a server record because no account identity is collected. Applicable legal rights depend on your location.
Security
Private scenario endpoints require a high-entropy installation secret sent over HTTPS. The server stores a digest for lookup and a bcrypt hash for verification rather than the plaintext secret. The device stores the secret in Keychain. Access is scoped to the matching installation; the application does not log secrets or scenario bodies. You should keep the displayed secret private. No system can guarantee absolute security.
Children’s privacy
Rapid Box Layout is a practical loading planner for a general audience and is not designed specifically for children. It does not ask for a birth date or knowingly collect a child's identity. A child using the app would create the same local plan and optional installation backup data described here.
Changes to this policy
We may update this policy when app behavior, hosting or data practices change. The current version and effective date will appear on this public page. Material changes will be reflected in a revised policy before the changed processing is introduced. Contact YewhurstYarrowby223@icloud.com with questions.