RestoCam

Privacy Policy

Last updated August 15, 2026

RestoCam is a job-site documentation service for restoration contractors, operated by bizi.us ("RestoCam", "we", "us"). This policy explains what information the RestoCam web app and iOS app collect, how it's used, and what happens to it. We've tried to keep it in plain language, because the honest answer is short: we collect what the product needs to work, we send it only to the services that make it work, and we don't sell or share it with anyone else.

What we collect

Everything RestoCam stores is something you or your team put into it:

  • Account details — your name, email address, and password. Passwords are stored only as one-way cryptographic hashes; we cannot read them.
  • Company details — your company's name, logo, and time zone.
  • Project details — job-site street addresses and, when you use GPS quick capture, the location coordinates used to match you to the project you're standing in.
  • Job documentation — the photos you take, the notes you dictate or type, photo captions, tags, annotations, and comment threads.
  • Vendor and contact details — names, emails, and phone numbers of the contractors and property owners you keep on file for invites and share links.
  • Billing status — your subscription state and seat count. Payment card details go directly to Stripe (see below) and never touch our servers.

Voice dictation stays on your phone

When you narrate while shooting in the iOS app, your speech is transcribed on the device itself, using Apple's on-device speech recognition. The audio recording never leaves your phone and is never uploaded to us or anyone else. Only the resulting text transcript is sent to RestoCam, where it becomes your captions and report narrative.

How we use your information

We use your data for exactly one purpose: providing RestoCam to your company. That means storing your photos and notes, generating your reports, matching captures to projects, sending the emails you trigger (invites, share links, comment notifications), and running billing. We do not use your data for advertising, we do not build profiles of you, and we do not sell or rent it to anyone.

Your company owns its content. The photos, notes, and reports your team creates belong to your company. RestoCam processes them only to provide the service.

Service providers we share with

RestoCam is built on a small set of processors, each receiving only what its job requires:

  • Anthropic — powers the AI features. When you finalize a session or request AI photo descriptions, downscaled copies of your photos, your dictated transcripts, and your session notes are sent to Anthropic's API to produce captions, narratives, and searchable descriptions.
  • Mapbox — receives project street addresses to convert them into map coordinates (geocoding).
  • Stripe — handles all payment processing. Stripe receives your company name and the account owner's email address; your card details are entered directly with Stripe and never pass through RestoCam.
  • Resend — delivers our transactional email: invites, share-link emails, comment notifications, and billing reminders. Emails you send to outside recipients (like a homeowner's report link, or a comment reply) necessarily include that content.
  • AppSignal — receives error reports when something breaks, with sensitive parameters filtered out and records referenced by ID only, so we can fix problems.

That's the complete list. No analytics trackers, no ad networks, no data brokers.

Sharing you control

Report share links and homeowner/contractor access links exist only when someone on your team creates them, and each one expires automatically 90 days after it's created. You can revoke any link early, and archiving a project revokes all of its outside links at once.

Cookies

RestoCam uses session cookies only — the kind that keep you signed in. There are no advertising cookies, no tracking cookies, and no third-party analytics on the site.

How long we keep your data

  • Active accounts — your photos, transcripts, reports, and comments are kept indefinitely, for as long as your company's account is open. We don't expire them with age. Archiving a project hides it; it never deletes data.
  • Deleted companies — once a company account closure takes effect (that is, after the 30-day grace period has run out), everything it created — photos, transcripts, reports, comments — is permanently deleted 90 days later. Billing and transaction records — including the business name, address, and contact details attached to them — are retained after deletion for financial and legal purposes. They are not accessible in the app. Aside from those records, the 90 days are the only window; after that the data is gone and we cannot recover it.
  • Removed user accounts — removing a user account is a separate thing from deleting the company, and it is done by a company admin from the company's Team page. Removal takes effect immediately: the person is signed out, loses access, comes off the roster, and their seat frees for someone else. The account itself is kept, deactivated, for 90 days, and is then permanently deleted. If the company invites the same email address back within that window, the account is reactivated with its history intact. Separately, the company keeps a permanent record of the person's name, email address, and the dates they joined and left, so that the work they documented stays attributable to them; that record is not accessible as an account, and it is deleted only when the whole company account is deleted. The job documentation they created — photos, transcripts, captions, comments — stays with the company, which owns it, and follows the company timeline above. An admin who is the company's only admin can't remove themselves without first making someone else an admin, or closing the company account instead.
  • Deleted photos — recoverable from the project trash for 30 days, then permanently purged.
  • Unpaid accounts — if a subscription payment fails and isn't resolved, the account becomes read-only, then locked, and 90 days after the first failed payment the account and all of its data are permanently deleted. We email reminders with the deletion date before that happens.
  • Share and access links — expire 90 days after creation.
  • Abandoned uploads — photo uploads that never attach to a session are purged within a few days.

Security

All traffic between your devices and RestoCam is encrypted in transit (HTTPS). Passwords are hashed, never stored in readable form. Each company's data is isolated — users can only ever see their own company's projects, and outside visitors see only what a link explicitly grants.

Your choices and contact

You can update your account details in the app, and company admins control seats, vendors, and outside links. Removing a user account is done by a company admin from the company's Team page; it takes effect immediately, and the account is permanently deleted 90 days later unless the company invites the same address back before then. Closing a whole company account is started from that same page, and only by the company's last remaining admin: we email a confirmation link, and once it's confirmed there's a 30-day grace period during which the closure can still be canceled. To ask a question about your data, request a copy of it, or request removal of your account, email us at support@resto.cam. We'll respond as quickly as we can.

Changes to this policy

If we change this policy, we'll update the date at the top of this page. If a change meaningfully affects how your data is handled, we'll email account owners before it takes effect.

See also our Terms of Service.