Pipefitter Academy Pro

Privacy Policy

Last updated: 17 July 2026  ·  Version 1.2

This policy explains what data Pipefitter Academy Pro collects, why, how long it is kept, and your rights. We collect only what is strictly necessary to provide the service.

1. Controller

The data controller is Artur Moniz, operating Pipefitter Academy Pro as an individual developer.
Contact: suporte@pipefitteracademy.com

For EU/EEA users: the processing described in this policy has its legal basis in Article 6(1)(b) GDPR (performance of a contract), Article 6(1)(a) GDPR (consent — for product analytics and optional product-update emails), and Article 6(1)(f) GDPR (legitimate interests — for crash/error monitoring and security) where indicated.

2. Data We Collect

2.1 Account data (Google Sign-In)

When you sign in with Google, we receive:

We do not receive or store your Google password.

2.2 Subscription & billing data

On the web and iOS, payments are processed by Stripe (Stripe Payments Europe, Ltd.), where we are the seller of record. In the Android app, purchases and subscriptions are processed through Google Play Billing (via RevenueCat), where Google is the merchant of record. In every case the payment processor handles all card data and card processing; we never see or store card numbers, bank details, or full billing card data. We receive only: subscription status, plan type, and transaction IDs.

2.3 App data you create

This data is stored in your personal Firestore document, access-controlled to your account only.

2.4 ISO Assistant uploads

When you use the ISO Assistant, photos or files you upload are sent to our Cloud Function, which forwards them to the Anthropic Claude API for analysis. Images are not stored on our servers after the response is returned. The Anthropic API processes them under Anthropic's Privacy Policy.

2.5 Usage analytics & error monitoring

Product analytics (PostHog). With your consent, we use PostHog (PostHog Inc., processed on EU infrastructure) to collect usage events such as "calculator opened" or "PDF exported", to understand which features are used and improve the app. Analytics only run after you accept the consent banner; if you decline, no analytics events are sent and PostHog is kept opted out. You can withdraw consent at any time, after which tracking stops and the associated identifiers are reset.

Error & crash monitoring (Sentry). We use Sentry (Functional Software, Inc.) to detect crashes and errors so we can keep the app stable and secure. Before any error is sent, we strip personal data: we do not send your email, IP address, user name, or session replays, and we scrub identifiers from error payloads. This processing relies on our legitimate interest in the security and reliability of the service; you can object at any time by contacting us.

2.6 Push notifications (optional)

If you enable notifications, we store a push-notification token (a device identifier issued by Firebase Cloud Messaging) linked to your account, used solely to send you service and re-engagement notifications. You can disable notifications at any time in your device settings; deleting your account removes the token.

2.7 Country (approximate region)

We store a two-letter country code derived from your browser's language setting and time zone, used for usage statistics and regional pricing. We do not use your IP address, GPS or any geolocation service to determine it, and we do not store your IP address for this purpose. This relies on our legitimate interest in understanding where the product is used; you can correct or remove it by contacting us.

2.8 What we do NOT collect

3. How We Use Your Data

Purpose Data used Legal basis
Authenticate your account Google UID, email Contract
Deliver Pro features after payment Subscription status from Stripe Contract
Save your projects & progress Projects, quiz scores, preferences Contract
Provide AI-assisted ISO reading Uploaded images (transient) Contract
Understand feature usage (analytics) Usage events (PostHog) Consent (opt-in only)
Keep the app stable & secure (crash/error monitoring) Error reports with personal data stripped (Sentry) Legitimate interest
Send service emails (receipts, subscription notices, enrolment confirmations) Email address Contract
Send product news and offers about Pipefitter Academy Pro Email address Soft opt-in (Art. 13(2) ePrivacy Directive; Art. 13.º-A(2) of Portuguese Law 41/2004) — we email our own similar products to people who already hold an account with us. Every such email carries a one-click unsubscribe link, and you may object at any time. We do not email people who have no account with us without their prior consent.

Unsubscribing stops all product news and offers, including our onboarding and trial email sequences. Service emails continue, because they are part of the service you signed up for.

4. Third-Party Services

Service Purpose Privacy policy
Google Firebase (Auth, Firestore, Hosting) Authentication, database, hosting firebase.google.com/support/privacy
Stripe Payment processing, subscription management (web & iOS) stripe.com/privacy
RevenueCat / Google Play Billing Purchase & subscription processing in the Android app revenuecat.com/privacy
Anthropic (Claude API) AI analysis of ISO drawings (ISO Assistant) anthropic.com/legal/privacy
PostHog (EU) Product usage analytics (only with consent) posthog.com/privacy
Sentry Crash & error monitoring (personal data stripped) sentry.io/privacy

No data is sold to, or shared with, any third party for advertising or profiling purposes.

5. Data Retention

6. Your Rights

EU / EEA users (GDPR)

You have the right to:

To exercise any right, email suporte@pipefitteracademy.com. We will respond within 30 days.

You may also lodge a complaint with your national supervisory authority (e.g. CNPD in Portugal, ICO in the UK, BfDI in Germany).

California users (CCPA / CPRA)

California residents have the right to know what personal information is collected, request deletion, and opt out of sale. We do not sell personal information. To exercise your rights, contact us at the email above.

Delete your account

You can delete your account from the Profile tab inside the app, or by emailing us. Account deletion removes all your data from Firestore within 30 days.

7. Security

All data is transmitted over HTTPS. Firestore access is protected by server-side security rules that restrict each user to their own documents. API keys and secrets are stored exclusively in Google Cloud Secret Manager and are never exposed in the client-side app bundle.

8. Children

Pipefitter Academy Pro is intended for professional tradespeople and vocational students aged 13 and over (16 in the EU/EEA). We do not knowingly collect data from children under these ages. If you believe a child has provided us with personal data, contact us immediately.

9. Changes to This Policy

If we make material changes, we will notify you via the app or by email at least 7 days before the change takes effect. The "last updated" date at the top of this page reflects the current version.

10. Contact

Artur Moniz
suporte@pipefitteracademy.com