Skip to content

Safety Meeting: Toolbox TalksiPhone, iOS 17+

Privacy Policy

The short version: nothing you enter into ToolboxLog reaches us or anybody else. There is no account and no server holding your records. The app and this website do count how they are used, anonymously, on a server we run ourselves - and the app's switch for that is in Settings.

Document
Privacy policy for the ToolboxLog iOS app and this website
Applies to
Safety Meeting: Toolbox Talks · com.kuberstar.toolboxlog
Updated
5 August 2026

1. Who this is from

ToolboxLog is developed and published by Kuberstar ( “we”, “us”). This policy covers the iOS app Safety Meeting: Toolbox Talks (bundle identifier com.kuberstar.toolboxlog) and the pages on https://toolboxlog.com. Questions about it go to support@kuberstar.com.

2. What we collect

Nothing you write. The app has no sign-up, no login and no server of ours holding your work. It contains no third-party analytics SDK, no crash reporting SDK and no advertising SDK. It does not read your contacts, your location, your calendar or your photo library except for a photo you explicitly attach to a record, which is then stored with that record on the device.

One thing is sent: an anonymous count of how the app is used. So that we can see which parts of the app confuse people - how many meetings that get started are actually signed, how many people who open the subscription screen ever buy - the app sends small named events to https://analytics.kuberstar.com/api/event. That address is a Plausible Community Edition server Kuberstar hosts itself, not a third-party analytics company, and the events go nowhere else.

An event carries the name of the action (for example a meeting was signed, the subscription screen was shown), your platform and app version, and coarse labels: which screen opened the subscription page, how many people were on the roster in bands rather than exactly, which subscription identifier was bought or restored, whether a record was verified successfully. It never carries a name, a signature, a job site, a company, a photo, the text of a talk, any part of a report, or a device or advertising identifier.

Plausible is cookieless. It derives a daily-rotating, non-reversible hash from your IP address to count a visit and does not store the IP itself, so nothing links today’s events to yesterday’s, to another app, or to you. Events are queued on your device when you are offline and deleted from it once the server accepts them. To stop it, turn off “Share usage analytics” in the app’s Settings. Nothing is sent while that switch is off, and anything still queued on the device is deleted.

The app’s privacy manifest declares this as Product Interaction and Purchase History usage data, collected for analytics, not linked to your identity and not used for tracking; it declares that the app does not track, which is what “no advertising identifier, no linkage to other companies’ data” means in Apple’s vocabulary. Those declarations agree with the behaviour described here.

3. What the app stores on your device

Everything the app creates is written to the app’s own storage on your iPhone or iPad, and stays there:

  • meetings, including the topic text as it was read out, the date, the time, the job site and the language;
  • attendance: each attendee’s printed name and the signature they drew on screen;
  • your crew roster, their trades, and any training records you keep against them;
  • your saved job sites and the state whose rule each is held to;
  • your company name, address and logo, as they are printed on the report;
  • walk-around inspections, incident and near-miss reports, and job hazard analyses;
  • talks you write or edit yourself;
  • the rendered PDF of each record, cached in the app’s own documents folder.

Two system APIs are used for reasons Apple requires be declared: UserDefaults, to remember how many reports you have shared, which version last asked you for a review, and whether you have switched usage analytics off, and file timestamps, to manage the cached PDFs the app itself wrote and the small file that holds usage events waiting to be sent. Both are declared in the app’s privacy manifest with the corresponding reason codes.

4. The names and signatures of your crew

A signed attendance record contains personal data about the people who signed it. That data is collected by you, as their employer or their contractor, for your own record-keeping obligations. We never receive it, never see it and never process it, so we are neither its controller nor its processor. Whatever duties you have towards your crew under the law that applies to you, including telling them what the record is for and keeping it no longer than you need to, remain yours. The app helps by showing the retention period the state you selected actually sets, and by naming the section it comes from.

5. Apple’s part

ToolboxLog Pro is sold as an auto-renewing subscription through the App Store. Apple processes the purchase; we never see your payment details, your Apple Account or your name. The app asks Apple whether an entitlement is active and receives yes or no. Together with the anonymous usage events in section 2, that is the whole of the app’s network traffic: nothing on any screen waits on a network call, and the app is fully usable with no signal at all.

If you have turned on the iOS setting that shares analytics with app developers, Apple may make aggregated, non-identifying usage and crash statistics available to us through App Store Connect. Those are produced and controlled by Apple, contain nothing that identifies you, and never contain anything from your records. Your device backup, if you use iCloud, is likewise Apple’s service, governed by Apple’s privacy policy rather than by this one.

6. Copies you choose to make

The app can export every signed report as one zip file, and can keep a rolling backup in an iCloud Drive folder that you pick. Both are copies made by your device to a destination you chose. Once a file is in iCloud Drive it is subject to Apple’s terms and to your own iCloud settings. If you email, message or AirDrop a report, it goes wherever you send it, and we have no part in that either.

7. This website

https://toolboxlog.com sets no cookies and embeds no third-party trackers, no advertising pixels and no third-party fonts. Fonts and images are served from the same origin as the page.

It does load one script, from the same self-hosted Plausible instance the app reports to (analytics.kuberstar.com), which counts page views and a handful of interactions: how far down a page you scrolled, which sections came into view, which question you opened in the FAQ, which link or App Store badge you clicked, and any address that returned a 404 so we can find broken links. It records the page URL, the referring site, and a country, browser, operating system and device type derived from your IP address and user agent; the IP address itself is not stored, no cookie is set and no identifier persists between visits, so no cookie banner is needed and nothing here can follow you to another website. You can stop it by blocking analytics.kuberstar.com in any content blocker - the site works exactly the same without it.

As with any website, the server that hosts it processes ordinary request logs, such as IP address and user agent, for the purpose of delivering the page and keeping it available. We do not use those logs to build a profile of you and do not combine them with anything else.

8. Children

ToolboxLog is a tool for construction crews and is rated 4+ because it contains nothing objectionable, not because it is aimed at children. It is not directed at children, has no accounts and collects no data from anybody.

9. Deleting your data

Because we hold nothing that identifies you, there is nothing for you to request from us, correct or ask us to erase - the usage counts described in section 2 are anonymous, so there is no profile on the server that could be traced back to a person and deleted. What you can do at any time is stop them: the “Share usage analytics” switch in the app’s Settings. Deleting a record inside the app removes it from the device. Deleting the app removes everything it stored, subject to any device backup you have made. Before a record is deleted the app shows you the retention period the selected state sets, so that you do not destroy a document you are still required to be able to produce.

10. Changes

If this policy changes, the updated version is published on this page and the date at the top changes with it. Material changes will also be noted in the app’s release notes. The policy in force is the one you can read here.

11. Contact

Write to support@kuberstar.com. Every message is read and answered. See also the Terms of Use and the support page.

Kuberstar · 5 August 2026