LUMBER iOS APP
Mobile privacy policy
Effective date:
Lumber is operated by Burningpony Corp. This policy explains how information is handled when you use the Lumber iOS app and the Lumber service it connects to at app.lumber.io. Lumber helps organizations manage orders, inventory, documents, notes, and production work. For the website and browser-based service, see the web privacy policy.
Your organization manages your workspace and determines which business records you may access. If you use Lumber through an employer or another organization, its own policies also apply to the information it adds to Lumber.
Information we handle
- Account information. Your account identifier, name, email address, profile image when available, workspace memberships, and permissions are used to identify you and provide access to your workspace. Password sign-in sends your credentials to Lumber. When spam protection is enabled, a verification sheet loads from the selected Lumber server and uses Cloudflare Turnstile. The sheet sends request and device information, including your IP address, to Cloudflare to check for automated abuse. Your email and password are submitted to Lumber, not to the verification sheet. A short-lived verification token is sent to Lumber with your password sign-in request. Google sign-in uses Google’s authentication service and sends an identity token to Lumber to verify your account; an approved account may be created on first sign-in.
- Workspace content. Orders, customer and business contact details, documents, photos, files, notes, task assignments, and production updates entered or uploaded by you or your organization are stored by the Lumber service. Your contributions can be associated with your account, workspace, and the time of the action.
- Technical information. Requests from the app to the service expose information such as IP address, device information, requested URLs, and request times to hosting infrastructure. The service also processes request logs and error diagnostics to operate, secure, and troubleshoot Lumber. Diagnostics can include account information, request context, and information involved in an error.
- Support communications. If you contact us for help or make a privacy request, we use the information you provide to respond and handle the request. Requests submitted through the website contact form are also covered by the web privacy policy.
Camera, photos, and local storage
The iOS app requests camera access to scan order QR codes. Scanning happens on your device; the scanner does not upload its camera video. The scanned code is used to find the corresponding order in Lumber.
You choose photos through Apple’s system photo picker and choose files to upload. Selected items are sent to the Lumber service and become part of your workspace records. The app can use Apple’s on-device image analysis to suggest a photo filename.
The app stores its session token in the device Keychain. Account and workspace context and selection preferences are stored locally to restore your session. Signing out removes the local session token and cached account context. Signing out or removing the app does not delete your server account or workspace records.
How information is used
We use information to authenticate users, enforce workspace permissions, deliver Lumber’s business workflows, store and display records and uploads, respond to support requests, and maintain the service’s reliability and security.
The iOS app does not implement advertising tracking. The iOS app uses Sentry in production and development builds to report crashes and errors and help us maintain reliability. Reports can include stack traces, app version and build, device and operating-system details, timestamps, and session health information. Diagnostic requests expose the connection’s IP address to Sentry’s infrastructure. The app does not explicitly attach your Lumber account identifier or email, and automatic personal-information collection is disabled. Screenshots, view hierarchies, breadcrumbs, failed-request capture, performance tracing, and profiling are disabled. The Lumber server can still collect request logs and send error diagnostics to Sentry when you use the app.
Who can receive information
Workspace records and uploads are available to people with access through your organization’s workspace. Your organization’s administrators manage access. Take care when entering personal information into shared business records.
Lumber uses service providers for infrastructure, storage, authentication, and diagnostics. These include:
- Amazon Web Services: storage of uploaded files and documents.
- Cloudflare: Turnstile verification for password sign-in when enabled. Cloudflare processes request and device information for abuse prevention. See Cloudflare’s privacy policy.
- Google: authentication when you choose Google sign-in and delivery of Google-hosted profile images when used.
- Sentry: crash and error diagnostics for production and development builds of the iOS app, as described above, and error diagnostics for the connected Lumber server. Server diagnostics may contain account and request information. See Sentry’s privacy policy.
Information may also be disclosed when required by law or necessary to investigate misuse and protect the service and its users. When you follow a link to a third-party service, that service’s privacy policy applies to your use of it.
Retention and deletion
Account information is retained while it is needed to provide and administer your access to Lumber. Workspace records and uploads are retained to support your organization’s ongoing business use. Removing a user’s access does not automatically remove organization-owned orders, documents, notes, or production history.
Retention depends on the type of information, your organization’s instructions, operational needs, and applicable legal requirements. Support communications are retained as needed to respond and maintain the support relationship. Logs and diagnostics serve troubleshooting and security needs; backup copies can remain after information is removed from the active service until those backups are replaced or expire.
You may request access to, correction of, or deletion of your personal information or account using the contact instructions below. We may need to verify your identity and coordinate with your organization. We will explain any information that must be retained for legal obligations or organization-owned business records when handling your request.
Your choices
You can disable camera permission in your device’s Settings, choose which photos and files to upload, and sign out from the app’s Account screen. Disabling camera access prevents QR scanning; you can still access orders through the app’s other navigation. You can stop future uploads by choosing not to upload content. These choices do not erase information already sent to the service.
Your privacy rights depend on where you live and the circumstances in which your information is used. Contact us to request access, correction, deletion, or to raise a concern about the use of your information.
Privacy questions and requests
For privacy questions or requests to Burningpony Corp., including requests to delete your account or personal information, use the website contact form and begin your message with “Privacy request.” Include your account email and workspace name so we can identify the relevant records; do not send your password. You can also contact us through your organization’s existing Lumber support channel.
For questions about workspace access or organization-owned records, contact your organization’s Lumber administrator. If the website form is unavailable, ask your administrator to raise your request through your organization’s Lumber support channel.
Changes to this policy
We will update this page when our practices change and revise the effective date above. Please review it for the current description of how Lumber handles information.