Legal

Privacy policy

Last updated 12 September 2026 · Applies to In & Out version 1.3.1 for Android

At a glance

  • Choose Company or Personal mode at first launch. In Company mode, your employer keeps attendance records through the Digital Pages service. Personal mode keeps your own time record encrypted on your device and makes no API or network requests.
  • Precise location is recorded only at the moment you check in or out, start or end a break, or submit or cancel a leave request. There is no background or continuous location.
  • No advertising, no advertising identifier, no third-party analytics or tracking, and no sale or sharing of your data with advertisers or data brokers.
  • The app never receives your salary or bank details, and your fingerprint or face never leaves your device.
  • Questions, access or deletion: app@digital-pages.dev

1. Who is responsible for your data

In & Out (“the app”) is published and operated by Digital Pages (“we”, “us”).

In Company mode, you reach the service through your employer. Your employer decides that attendance will be recorded, who is invited, and what happens to the records afterwards, so your employer is the controller of that information. We provide and run the app and the service behind it on your employer's behalf. Where Digital Pages is itself the employer, we are both.

If you want to know why your company records attendance or reviews a particular entry, ask your employer first. If you want to know what the app technically stores, this page answers that, and you can always write to app@digital-pages.dev.

Personal mode: your device, your record

Other / Personal mode does not connect to payroll or create a server account. You keep your own attendance, breaks and leave on your device; neither Digital Pages nor an employer receives those records from the app. Personal leave is Recorded or Cancelled, without management review. You control any CSV files you export, which may contain precise location and personal notes.

There is no online backup. If Android cannot use the encryption key, the app reports a storage error and does not automatically erase the existing encrypted records. We cannot recover the key or restore those records from a server. Clearing app storage or uninstalling removes local records; exported files must be managed separately.

2. How a Company account comes to exist

There is no public sign-up for Company mode. An administrator at your company grants your work email address mobile access from the payroll system and sends you an invitation. Sign-in then uses that email address and a six-digit one-time code; there is no password to create. An invitation is required for Company access. Other / Personal mode requires no account, email, invitation or code.

3. What the app collects

3.1 Company identity, from your employer's payroll system

When you sign in, the service reads a narrow, read-only view of your employer's payroll records: your name, work email address, employee identifier, company identifier and the status fields that decide whether you are eligible to use the app. That view cannot be written to and contains no salary, bank, contract or other payroll detail. The service also stores your email in code and session records, and an employee-name snapshot in leave requests; those identity fields are not kept solely in payroll.

3.2 Company sign-in and session data

  • Your email address, so that a code can be sent to it.
  • The one-time code, stored only as a keyed hash, valid for ten minutes, with a limit of five attempts. Codes are limited to one per minute and five per hour per address.
  • A session token, stored on the server only as a hash and valid for seven days. On your device it is held in Android's encrypted storage.
  • Short-lived rate-limiting counters keyed to a hash of the network address a request came from, used to slow down abuse.

3.3 Attendance and breaks

Check-in and check-out times, the working day they belong to, break start and end times, total break time, the reason you chose for each break and any note you added.

3.4 Leave requests

Both modes record leave type, dates or times, reason and status. Company requests additionally include your payroll name and, after review, the reviewer, review time and review note. Personal leave is Recorded or Cancelled locally and is not submitted for management approval.

3.5 Location, at the moment of an action

Latitude, longitude, accuracy in metres, the original time of the fix and whether it is fresh or last-known, attached to each attendance action and each leave submission or cancellation. Section 4 describes this in full.

3.6 Company device and connection details

The network address the request came from, the agent string the app sends, whether your device reported Wi-Fi or mobile data, and a short device description reported by your device. These accompany the attendance entry so that your employer's administrators can see the circumstances in which it was made. They are reported by the device itself and are not treated as proof of identity.

Company actions additionally use Android hardware key attestation. The service checks the app package, signing certificate, app version and verified boot state, then keeps a session-bound public key that is valid for up to six hours and short-lived request nonces to prevent replay. The private signing key stays in Android Keystore. The server checks Google’s public certificate revocation list; no attendance or location is sent to Google by this service. Personal mode does not enroll keys or make attestation requests.

3.7 Kept only on your device

Your language and appearance choice, biometric-lock settings and, in Company mode, the encrypted session token. Personal attendance, breaks, leave, GPS stamps and notes are kept in encrypted on-device storage and are not uploaded. There is no online backup. A Personal CSV export contains records, GPS and notes in the file destination you choose; that file is outside the app’s encrypted storage and remains under your control. Release builds of the app disable debugging, disable system backups of app data, and block screenshots and app-preview capture.

4. Location, in detail

Location is the most sensitive thing the app records, so here is exactly how it behaves.

  • A fix is captured only when you check in, check out, start or end a break, or submit or cancel a leave request. Nothing is captured while you browse other screens, while the app is in the background, or when the app is closed.
  • The app requests a new fix after confirmation. If that attempt fails while GPS remains enabled, it uses the latest known real location. The original timestamp and accuracy are preserved and the source is marked LAST_KNOWN in records and exports. Mock locations are refused. Without any usable real fix, the action cannot be recorded.
  • Fresh fixes require valid coordinates, accuracy of 250 metres or better and age of no more than 120 seconds. A LAST_KNOWN fallback may be older or less accurate; its actual time and accuracy remain visible in the record. It is not proof of the user’s current position.
  • Precise location permission and enabled location services are required to reach the employee screens. If either is missing, the app says so and offers to open Android settings. Without them you cannot record attendance from the app.
  • The app holds no “allow all the time” background location permission, defines no office geofence, and does not judge whether a position is inside or outside a permitted area. It produces a stamp attached to your action. Company stamps are sent for employer review; Personal stamps stay on your device unless you export them.

5. What the app does not collect

No advertising identifier and no advertising or marketing profiling. No third-party analytics, crash-reporting or tracking SDK. No contacts, photos, messages, call history or microphone access. A Personal CSV export writes only the file you choose through Android’s file picker; it does not scan other files. No continuous or background location. No salary or bank information. No biometric data: biometric unlocking is performed by Android, and the app only learns whether it succeeded. We do not sell your data and we do not share it with advertisers or data brokers.

6. Why Company data is used

DataPurpose
Identity and eligibilityConfirming that you are an employee entitled to use the app, and attaching records to the right person and company
Email and one-time codeSigning you in without a password, and preventing abuse of the code system
Attendance, breaks and leaveProducing the attendance record your employer uses for time-keeping, leave management and payroll
Location, device and connection detailsShowing your employer's authorised administrators the circumstances in which each entry was made
Security counters and service logsProtecting the service against abuse and keeping it running

Where data-protection law applies, this processing rests on your employment relationship, your employer's legitimate interest in accurate attendance records, and any legal obligation your employer has to keep employment records. Your data is not processed for advertising or for any purpose unrelated to attendance.

7. Who can see Company data

  • Your employer. Authorised payroll administrators at your company review your attendance, its location stamps and your leave requests from the payroll application. That is the purpose of the app.
  • Digital Pages staff who operate the service, strictly where needed to run, support, back up or repair it.
  • The infrastructure used to run the service: the provider hosting the server, and the mail service that delivers your one-time codes and invitations.
  • Authorities, only where we or your employer are legally required to disclose.

There is no third-party SDK inside the app that receives your data.

8. Where data is kept

Company attendance data is stored in a dedicated database on a server operated by Digital Pages, separate from the main payroll database and reachable only through this service's own restricted account. Traffic between the app and the service uses HTTPS; connections between the service and the database use TLS.

9. How long Company data is kept

DataRetention
One-time code challengesThe code hash is cleared on successful use; a code becomes invalid after 10 minutes. Later code requests remove other challenge rows whose last send time is over 24 hours old.
Sign-in sessionsInvalid after 7 days. Expired rows are deleted during a later successful sign-in; signing out deletes that session.
Rate-limiting countersEntries older than 2 hours are removed during later code requests.
Attendance, breaks and leave requests, with their location stampsKept as your employer's employment record, for as long as your employer requires and the law allows
Database backupsRetained on a rolling 14-day basis, then destroyed

Authentication cleanup is triggered by these later requests, not by a guaranteed deletion schedule. How long Company attendance records are kept after employment ends is your employer’s decision. Personal records stay on your device until app storage is cleared or the app is uninstalled; exported CSV files remain separately under your control.

10. How data is protected

  • HTTPS with a valid certificate for all traffic between the app and the service.
  • One-time codes and session tokens stored only as hashes, never in readable form.
  • The session token held in Android's encrypted storage on your device.
  • Debugging, system backup of app data, and screenshot or app-preview capture disabled in release builds.
  • Database accounts limited to exactly the tables and columns they need, with no access to salary data.
  • The service running in a hardened container with a read-only filesystem and no extra privileges.
  • Request size limits, rate limits, and your eligibility re-checked on every authenticated request.

No system is perfectly secure, but the app is built so that a problem in one part does not expose payroll data.

11. Your choices

  • Location permission can be withdrawn at any time in Android settings. The app will then be unable to record attendance, because a fix is required for those actions.
  • Biometric lock is optional and can be switched on or off in the app's settings.
  • Language and appearance are your choice and are stored on your device.
  • Signing out in Company mode removes the session from your device and invalidates it on the server.
  • Uninstalling removes the app and its on-device data. Company entries already sent remain in your employer’s record. Personal records are removed, while exported CSV files remain outside app storage.

12. Your rights

Depending on where you live, you may have the right to ask for a copy of your data, to have it corrected or deleted, to restrict or object to its use, and to complain to a data-protection authority.

For Company employment records, the fastest route for most requests is the HR or payroll administrator at your company, who can review your entries and handle a correction request. You can also write to us at app@digital-pages.dev and we will help, working with your employer where the records belong to them. For deletion specifically, see Delete my data. We answer requests within 30 days.

13. Children

In & Out is a time-keeping tool for adults and is not directed at children. Company access is limited to invited, eligible employees.

14. Changes to this policy

If this policy changes, we will update this page and the date at the top. Changes that materially affect Company data use will also be communicated through your employer.

15. Contact

Digital Pages — In & Out
app@digital-pages.dev

Appendix: Android permissions

PermissionWhy the app asks
Precise and approximate locationThe single fix attached to each attendance action and leave submission or cancellation. Used only while you are using the app; no background location.
Internet and network stateCompany mode: reaching the attendance service and reporting Wi-Fi or mobile data for an action. Personal mode makes no API or network requests.
Biometrics / fingerprintThe optional app lock. Verification is performed by Android; the app only learns the result.
NotificationsIf granted, only for messages the app itself raises on your device. The app does not receive remote push messages.