PAT Logbook

PAT Logbook — privacy policy

Last updated: 1 September 2026

The short version

PAT Logbook keeps your clients, sites, appliances and test records on your own phone. There is no PAT Logbook account, no sign-in and no PAT Logbook server that holds your records. Nobody — including us — can see them. Optional PostHog product analytics and AppsFlyer advertising attribution have separate choices and are each off unless you choose to allow them.

What PAT Logbook stores, and where

Everything you enter into your PAT records — clients, sites, appliances, test sessions and test records, your business profile, logo and signature — stays in the app's own storage on your device and is not sent for analytics or attribution. App settings are also stored locally. If you enable either optional measurement choice, PAT Logbook sends only the pseudonymous events and consent state described below, never your PAT-record content.

Backups: your iCloud Drive, not ours

PAT Logbook can automatically back up your data as timestamped snapshot files. Those backups go to your own iCloud Drive, in your own Apple account — visible in the Files app under iCloud Drive → PAT Logbook. This is a one-way backup, not a sync service: PAT Logbook has no server of its own, and nothing passes through our infrastructure or anyone else's. You can turn automatic backups off at any time, and you can also create a backup file and restore from one manually, whenever you choose.

What PAT Logbook never sends for analytics or attribution

Product measurement never includes your name, email address, phone number or other personal contact details. It never includes your clients, sites, appliances, domains, test records or readings, photos, signatures, certificate PDFs, CSV exports, backup files or iCloud Drive contents. Your records remain local to your device and, where you choose, your own iCloud Drive.

Optional PostHog product analytics

If you allow Share product usage data, PAT Logbook sends a small, manually allow-listed set of feature-use and purchase-flow events to our EU-hosted PostHog project. These events use a random identifier generated for this installation of PAT Logbook, together with basic app and device information such as app version and build. The identifier is not an account, a name or an Apple identifier, and PAT Logbook never sends it to AppsFlyer.

PAT Logbook disables PostHog screen and element autocapture, session replay, person profiles, surveys, feature flags, automatic lifecycle events and error/crash autocapture. Every PAT Logbook event disables PostHog’s GeoIP enrichment, and the PostHog project is configured to discard client IP addresses. PostHog therefore does not retain a city, postcode, coordinates or IP address from these events.

Optional AppsFlyer advertising attribution

If you separately allow Measure advertising results, PAT Logbook starts AppsFlyer Strict 7 so we can measure whether advertising results in an install and later app activity. AppsFlyer creates its own pseudonymous appsflyer_id for the installation and sends its standard install and foreground-session attribution events, together with basic app and device information. This is a different identifier and data stream from PostHog.

PAT Logbook additionally sends AppsFlyer only three conversion events: a certificate was issued, the paywall was viewed, or a purchase completed. The events contain only fixed app-state labels, such as how the paywall was opened or whether the certificate allowance was available. They do not contain PAT record fields. PAT Logbook uses AppsFlyer’s Strict binary, disables IDFA and IDFV collection, never supplies an account or customer user identifier, and does not request App Tracking Transparency permission. AppsFlyer still processes its own pseudonymous installation identifier and attribution information. PAT Logbook does not enable AppsFlyer’s optional anonymizeUser setting: AppsFlyer documents that setting as removing or hashing standard identifiers and IP data while some install and event measurement may continue. Instead, PAT Logbook controls whether the SDK starts and collects events through your separate choice. The AppsFlyer app is also configured with Aggregated Advanced Privacy and IP masking enabled, and probabilistic view-through attribution disabled.

Coarse location. When advertising measurement is enabled, AppsFlyer may retain country- or city-level location fields associated with its pseudonymous install identifier. IP masking means the source IP address is not shown in raw reports or partner postbacks, although AppsFlyer documents that country and city fields can remain. PAT Logbook does not request or send precise GPS location.

For every AppsFlyer session, regardless of the App Store country or the user’s location, PAT Logbook tells AppsFlyer that GDPR applies. Enabling this choice gives consent for the limited advertising-measurement data use and device storage described above; advertising personalisation is always reported as not allowed. PAT Logbook sends this consent state before each AppsFlyer start and again if the choice changes.

PostHog is the product-analytics service; AppsFlyer is used only for advertising attribution. Turning on one does not turn on the other.

Your choice and control

PostHog product analytics and AppsFlyer attribution are both off by default, with a separate choice for each. You can allow, decline or withdraw either permission later under Settings → Analytics & privacy. Declining either choice leaves the full offline product working and does not change the other choice.

Turning PostHog off stops collection, closes the SDK and removes any unsent PostHog event queue from this phone so queued events cannot be uploaded later. Turning AppsFlyer off stops AppsFlyer event collection and reports data-use, advertising-personalisation and ad-storage consent as withdrawn. AppsFlyer documents one narrow exception: an SDK already initialised in the current app process may still fetch privacy-preserving SKAdNetwork configuration. That fetch contains no PAT Logbook event or app identifier; after the app process ends, a later launch with the choice still off does not initialise AppsFlyer. PAT Logbook keeps the provider-generated AppsFlyer identifier locally after withdrawal so you can still make an access or deletion request. Withdrawal does not by itself delete data that a provider has already processed.

Retention and deletion of optional measurement data

Our PostHog project is hosted in the EU and is currently on PostHog’s pay-as-you-go tier, which retains product-analytics events for seven years. PostHog accepts deletion requests for a pseudonymous identifier; deleting a subject can also queue all corresponding events for removal. The project discards client IP data, and PAT Logbook disables GeoIP enrichment before every event is sent.

AppsFlyer retention varies by advertising source and data type. PAT Logbook’s App Store record now exists, but AppsFlyer attribution is not enabled in a public release. Before enabling it, we will record the app-specific retention settings and complete an OpenDSR access-and-deletion test. This pre-release policy describes the intended consent-gated data flow; it does not claim that production AppsFlyer measurement is already active.

To ask about, access or delete optional measurement data:

We use the supplied pseudonymous identifier only to locate the matching provider data, coordinate the request with PostHog or AppsFlyer, and confirm the outcome. Please do not send us client details, PAT records, readings, photos, signatures, certificates or backup files. Because PAT Logbook has no account and does not connect these identifiers to your identity, we cannot locate optional measurement data without the relevant identifier.

Purchases

The one-off unlock is handled entirely by Apple through StoreKit. PAT Logbook asks the App Store for product information and to purchase, verify or restore your unlock; Apple processes that under Apple's own terms and privacy policy. We never see your payment details, and no purchase information is sent to any PAT Logbook server.

Exports and sharing

When you export a certificate, an asset register, a CSV file or a full backup, PAT Logbook writes it to your device and, if you choose to email or share it, hands it to the iOS share sheet. Where it goes after that is your choice — PAT Logbook does not upload it, keep a copy, or see where you sent it.

Camera and photos

PAT Logbook uses the camera, when you choose to use it, to scan appliance barcodes and photograph appliances for your own records. Photos you take or import are stored with the appliance record on your device, in the same way as everything else.

Notifications

The optional weekly reminder digest is generated on your phone from your own data and scheduled as a local notification. Nothing about it is sent to a server.

App Store information

Apple provides developers with aggregate statistics about App Store downloads and crashes through App Store Connect. That is Apple’s measurement of the App Store, not access to your PAT Logbook records.

The PostHog software package bundled with PAT Logbook also carries an Apple privacy manifest that declares unlinked Crash Data and Other Diagnostic Data. PAT Logbook disables PostHog error and crash autocapture and does not intentionally send those diagnostic events. The App Store privacy answers will nevertheless be reconciled against the final shipped archive and observed provider traffic, rather than inferred from this runtime setting alone.

Children

PAT Logbook is a professional tool for people who test portable electrical appliances. It is not directed at children. Its optional measurement does not include personal contact details or PAT Logbook records.

Your rights

We do not hold your PAT Logbook records. You can export them as CSV or a full backup file at any time from Settings, and delete them from your device whenever you choose. For optional measurement data, use the deletion route above.

Changes

If a future version changes what PAT Logbook sends, this policy and the App Store privacy answers will be updated before that version ships.

Contact

Tom Murton — support@weevolve.app


PAT testing is one way of evidencing the maintenance of electrical equipment that UK law requires — it is not itself a legal requirement. PAT Logbook is a records tool, not legal advice.