Privacy Policy
At BenDevsPro, we take the privacy and security of your community data seriously. This policy explains how the Community Events Records Monitor (CERM) app handles and protects your information.
1. Zero knowledge & data minimization
We do not collect personal data of members of your community. The CERM app is built on a Zero Knowledge architecture coupled with strong encryption. This means BenDevsPro has absolutely no ability to read, view, or access the identities, activities, or performance records of your members.
2. Data storage & encryption
Your primary data is stored locally on your device using encrypted SQLCipher databases. When you choose to use our Cloud Sync feature:
- Backup files (.cerm) are strictly locked to your specific user identity via Firebase Authentication UID.
- Files are secured in transit using AES-256-GCM encryption.
- Our Firebase Storage rules prohibit any user from reading or writing to folders outside of their own authenticated ID.
3. Third-party services
To provide our services, we use industry-standard third-party providers:
- Google Firebase: Used for secure user authentication and cloud backup storage.
- RevenueCat: Used strictly to validate subscription status across Android and Desktop platforms (see our Pricing page). RevenueCat does not have access to your community ledger data.
4. Local access
The app requests local biometric authentication (fingerprint/face unlock) to protect access to the app on your device. This biometric data is processed entirely by your device's operating system and is never transmitted to our servers.
5. Your choices
Cloud Sync is optional — you can use CERM entirely offline if you prefer to keep all data local to your device. You can review billing and cancellation terms on our Terms of Service page.
6. Account and data deletion
You have the right to request the complete deletion of your account and all associated cloud backup data. To request account deletion:
- Send an email to bendevspro@gmail.com from the email address associated with your account.
- Use the subject line "Account Deletion Request".
- We will permanently delete your Firebase Authentication record and all associated .cerm backup files within 7 days.
Note: Because primary ledger data is stored locally on your device, you must also uninstall the application to clear local storage.