Legal

Privacy Policy

Effective date: 9 July 2026  ·  Last updated: 11 September 2026

This policy explains how PicAnchor handles personal data. Because PicAnchor is used by businesses to document their own field teams, parts of this policy distinguish between data we control and data our business customers control. Please read Section 3 carefully.

1. Who we are

PicAnchor ("PicAnchor", "we", "us") is a field-documentation application and web dashboard that lets organisations capture photos stamped with a verified time and location, and manage those photos across a team. This policy is published by Baturlabs Ltd, a company registered in England and Wales ("the Operator"), contactable at admin@baturlabs.com.

This policy applies to the PicAnchor mobile app, the PicAnchor web dashboard, and the picanchor.com website (together, the "Service").

Not every feature this policy describes is available on every platform or in every version of the Service. Where a feature - such as accounts, company sync, or paid plans - is not offered on the platform or version you are using, the sections describing that feature simply do not apply to you.

2. The data we collect

We collect only what the Service needs to function. What is collected depends on how you use it.

CategoryWhat it includesWhen
Admin accountEmail address and password (stored encrypted), company name you enter.When an admin signs up for the dashboard.
Worker identityThe display name your admin registers for you and a join code. Workers do not provide an email or password; sign-in is anonymous and linked only to a worker entry your admin created.When a worker joins a company by name + code.
Photos & their stampThe photos you capture, and the information stamped on them: date and time, GPS coordinates, a reverse-geocoded address, and any note you type.Each time a photo is captured and synced.
Proof registrationA fingerprint of the photo file, its verification code, the capture time and whether that time came from the network or the device clock. Never the image (Section 12).Each time a photo is captured, with or without an account.
LocationDevice GPS location, used to stamp photos and detect falsified ("mock") location. Location is used at the moment of capture; we do not continuously track device location in the background.While capturing a photo, with your permission.
Technical dataBasic information needed to operate and secure the Service, such as whether a photo has been synced and the time zone it was captured in. We use no analytics or crash-reporting services and collect no hardware identifier - no IMEI and no advertising ID; a worker's device is linked to their account only by a random, app-generated identifier that keeps one worker account bound to one device.During normal use.

The PicAnchor app works locally without an account. If you never sign in as an admin and never join a company as a worker, photos stay on your device and are not sent to our servers. A fingerprint and the capture time are registered so your photo can be verified later (Section 12); your location and the photo itself never leave your device unless you use an account.

3. Who controls your data (controller and processor)

This is important for understanding your rights.

4. How we use data

We do not sell personal data. We do not use your photos or location to build advertising profiles, and the Service does not display third-party advertising.

5. Legal basis and consent

We process personal data where you (or the business you work for) have given consent, where it is necessary to provide a service you have requested, and where we have a legitimate interest in operating and securing the Service. For workers, the lawful basis for processing field documentation generally rests with the employing company that registers you and instructs the documentation. The Operator is established in the United Kingdom, and we handle personal data under the UK General Data Protection Regulation (UK GDPR).

6. Sharing and third-party services

We share data only with service providers that help us run the Service, and only as needed:

7. Storage, location, and retention

Synced photos and records are stored in private cloud storage provided by Supabase, hosted in Tokyo, Japan (AWS ap-northeast-1). Supabase provides that storage on Amazon Web Services infrastructure, which acts as our sub-processor. Data is retained according to your plan: photos synced by a free-plan company are kept for 30 days, and photos synced by a paid-plan company for 365 days, after which they are automatically deleted from storage. A free-plan company may store up to 100 synced photos at a time; once that limit is reached, further photos remain on the worker's device and are not uploaded until space is freed or the plan is upgraded. Businesses that control their data may also delete workers and photos at any time from the dashboard. Photos deleted from the dashboard are held in Recently Deleted for 30 days, where an admin can restore them, and are then removed from storage; photos kept after a worker is removed retain only the worker's name as recorded at the time of capture, so the documentation remains intact.

Verification registry entries are kept indefinitely, and that is deliberate: a verification code printed on a photo or a report must still work years later, for someone who was never our customer. You can ask us to erase an entry (Section 9). A photo synced to a company is deleted from company storage on the schedule above; its registry entry is not, so a photo can be gone from a company's dashboard while its verification code still answers.

8. Security

We protect data with measures including isolated per-company access controls (so one company cannot see another's data), private storage that is not publicly accessible, encrypted transmission, and tamper-resistance features built into the stamp (network-derived time, mock-location detection, and a digital fingerprint on each photo). No system is perfectly secure, but we work to protect your data in line with industry practice.

9. Your rights

Subject to applicable law, you may request to access, correct, or delete your personal data, and to object to or restrict certain processing. Because much of the data is controlled by the business that uses PicAnchor (see Section 3), workers should usually direct these requests to their employer/the company that registered them. For data the Operator controls, or if you are unsure who to contact, write to admin@baturlabs.com and we will help route your request.

You can also ask us to erase a verification registry entry (Section 12) by writing to admin@baturlabs.com; there is no in-app control for this today. The entry then answers only "revoked" to anyone who looks it up: the capture time and the time source are removed and cannot be recovered. We keep the fingerprint itself, the verification code and the time we first received them, because releasing the fingerprint would let someone else register the same file later and claim an earlier date for it. We also keep a count of how many times the same file was submitted and when it was last seen. Erasure cannot be undone.

10. Children

PicAnchor is a tool for workplaces and is not directed to children. We do not knowingly collect personal data from anyone under the age of majority in their jurisdiction. If you believe a minor has provided data, contact us and we will remove it.

11. Changes to this policy

We may update this policy as the Service evolves or as the law requires. We will revise the "Last updated" date above and, for significant changes, provide a more prominent notice.

12. Photo verification registry

The registry holds no pictures. Nothing in this section involves the photo itself leaving your device; photos are uploaded only when you sync them to a company (Sections 2 and 7).

When you take a photo, the app sends four things to our verification registry:

Nothing else is sent. No location, no names, no account details, no device identifiers. The registry itself records the moment it received them, from our own clock, and, if the same file is submitted again, how many times and when it was last seen. The registry cannot tell where a photo was taken or who took it.

Registration happens for every photo you take and cannot currently be switched off in the app. If you do not want photos registered, contact us (Section 13).

This exists so that a photo can be verified later: anyone with the photo, or its verification code, can check at verify.picanchor.com when the file was registered and whether it has changed since. Because verification depends on the record being durable, fingerprint and capture-time entries are retained indefinitely.

To stop the registry being flooded, we limit how many registrations can come from one network address in a given period. To do that we store a scrambled, one-way form of that address for up to two hours. We do not store the address itself, and we create no permanent identifier for your device or installation - registrations from the same device are not linked to each other.

13. Contact

Questions about this policy or your data: admin@baturlabs.com.
Operator: Baturlabs Ltd, a company registered in England and Wales, registered address Unit 20 Yarrow Business Centre, Chorley PR6 0LP, United Kingdom.