Data Policy and AI Processing Notice
This page is the operational data policy for Zone Zero Navigator. It is written for homeowners, app-store reviewers, and implementation partners who need a plain-language view of how the product handles property photos, AI analysis, report records, and premium purchases.
Data map
| Data | Purpose | Processors | Retention |
|---|---|---|---|
| Property photos | Wildfire screening, visual annotations, and report evidence. | Anthropic for analysis; browser session; Supabase only when saved. | Session-only unless saved in report history. |
| Address and jurisdiction | Localize the report and select the appropriate California/San Diego context. | Anthropic and Supabase when saved. | Stored with saved reports; otherwise session-only. |
| AI report content | Display findings, confidence, scope limitations, annotations, and action plans. | Supabase when report backup/history is enabled. | Stored while report history remains active or until deletion request is processed. |
| Email backup | Recover accountless reports and associate report history with an email address. | Supabase authentication and Resend email delivery. | Until removed, replaced, or deleted through account/report support. |
| Premium purchase records | Validate consumable premium report credits and prevent duplicate claims. | Stripe for web checkout; Apple App Store or Google Play for receipt verification; Supabase ledger. | Retained as needed for fraud prevention, store compliance, refunds, and support. |
| Operational logs | Security, rate limiting, troubleshooting, and service reliability. | Vercel hosting and Upstash rate-limiting infrastructure. | Limited operational retention; logs should avoid raw photos and full addresses. |
Safeguards
- Photos are resized and re-encoded before AI analysis to reduce payload size and strip common metadata.
- Server events should use request IDs and redacted addresses rather than raw photos or complete addresses.
- Premium purchase credit grants require server-side validation and service-role database access.
- Camera/photo access is requested only for the scanner feature and should not be used for advertising or profiling.
- The app is calibrated as a screening assistant and does not make official inspection, insurance, permit, or emergency-response decisions.
App-store disclosure baseline
Apple and Google disclosures should reflect that the app may collect user-provided photos, optional email, purchase history, user-generated report content, diagnostics, and identifiers needed for accountless session recovery and purchase verification. Web checkout uses Stripe. Camera and photo access are used for the scanner feature only.