← Back to home

App Privacy Policy

Version 1.0 · Effective 26 August 2026

This policy explains how Patrol 6, LLC ("Patrol 6", "we", "us"), an Arizona limited liability company operating Report 6, collects, uses, shares, and retains information in the Report 6 mobile app and the services behind it.

Report 6 works in two modes, and who is responsible for your data depends on which one you are using. Personal mode is you, reporting for yourself. Enterprise mode is you, reporting into the workspace of a company that has invited you. Section 2 sets out the split, and the rest of this policy flags anywhere the two differ.

For the report6.ai website, see the website Privacy Policy. Your use of the app is also governed by the App Terms of Use.

1. Who we are

Report 6 is operated by Patrol 6, LLC, an Arizona limited liability company based in Phoenix, Arizona, United States.

  • Postal address: Patrol 6, LLC, 2843 E Robin Ln, Phoenix, AZ 85050, United States
  • Privacy Officer: Privacy Officer, Patrol 6, LLC, at the address above
  • Privacy contact: support@patrol6.com

2. Personal vs Enterprise — who is responsible

The legal terms below ("controller", "business", "processor", "service provider") come from privacy laws in the US, UK, Canada, and Australia. In plain terms: the controller decides why data is collected and what happens to it; the processor only handles it on the controller's instructions.

WhatPersonal modeEnterprise mode
Report content
audio, photos, location, transcript, findings
Patrol 6 is the controller / business. The company is the controller. Patrol 6 processes report content on that company's instructions.
Account & security data
sign-in, device identifiers, diagnostics, service administration
Patrol 6 is the controller. Patrol 6 remains the controller for authentication, security, diagnostics, and administering the Service.
Shared reports
links and emailed copies
You decide who receives the report and why. The company decides who receives the report and why.
Retention Set by Patrol 6 and enforced automatically — see section 8. Set by the company in its own system. Patrol 6's consumer windows do not apply.
Where to send a data request Patrol 6 — see section 12. Your employer or the company first. We will route misdirected requests.

How Enterprise access works. A company running Patrol 6 Frontline adds you by invitation: it associates your work email address with its account and invites you to create your Report 6 account online. When you sign in to the app with that account, the company's workspace appears alongside your personal one, and what you can see and create there — report templates, sites, and capture settings — is determined by the company. Reports you create in a company workspace upload into that company's own cloud tenant, under its retention and access rules — not into your personal Report 6 account. Your Personal workspace stays available and separate. The company's administrators control membership and can remove your access at any time; if they do, the company workspace and its reports are removed from the app automatically. You can also sign out of a company account in the app at any time.

Enterprise customers sign a Data Processing Addendum with us covering retention, deletion, subprocessors, breach notification, international transfers, and administrator responsibilities. Where the Addendum and this policy differ for enterprise report content, the Addendum governs. Companies can request a copy at support@patrol6.com.

If you use Report 6 for work, your employer can see what you submit to it. Enterprise reports, including narration, photos, and location, are visible to that company's administrators and to anyone it assigns the report to.

3. What we collect

You give us

  • Account information — name and email address, taken from Apple or Google sign-in or entered by you.
  • Recipient email addresses you type in to share a report.
  • Report text you write or edit — findings, annotations, corrections to the AI's draft, template selections, and site or property details.
  • Support correspondence — what you send us when you ask for help.

The app captures while you record

  • Audio. Continuous microphone narration for the duration of a capture.
  • Photos and video frames. The camera captures automatically — roughly one frame per second in Personal mode, and in bursts of up to 20 seconds in Enterprise mode — plus any image you add yourself.
  • Precise location. Your GPS position and route, collected only while the capture screen is active, used to place findings on the report map and to derive a street address for the report header.

We generate or observe

  • Transcripts and AI output — the text of your narration, and the detected issues, summaries, media associations, and recommendations drafted from it.
  • Identifiers — a Report 6 account ID, a Firebase user ID, an app installation ID, and, in Enterprise mode, the tenant, site, and template identifiers for the company workspace.
  • Usage events — which screens and controls you use, and upload statistics such as queue depth, transfer size, and success or failure.
  • Diagnostics and performance data — battery, thermal state, memory, storage, and network conditions, plus crash and error records. This is written to a log on your device and is only uploaded if you or our support team start a diagnostics upload. Uploaded diagnostics are redacted of report content before they reach us.

What Report 6 does not do. No advertising. No advertising identifier. No tracking of you across other companies' apps or websites, and no sale or sharing of your personal information for cross-context behavioral advertising. We do not read your device address book. We do not collect data in the background when you are not capturing a report.

4. Camera, microphone, and location

Camera and microphone are active only during a capture you started, and the app shows a recording indicator for the whole session alongside the system camera and microphone indicators. On supported devices a capture continues while the screen is off or the app is in the background so a walk is not interrupted; the recording indicator stays visible throughout. You start and stop every capture yourself.

Precise location is collected only while the capture screen is active and stops when the capture stops. It is used for the report map, the derived street address, and evidence context. Where your device or configuration allows it, you can capture a report without granting location — the report is produced without map placement. You can change camera, microphone, and location permissions at any time in your device settings; the app cannot capture without camera and microphone access.

5. How we use your information

PurposeData usedUK/EU legal basis
Create your account and sign you inEmail, identifiersPerformance of a contract
Capture, transcribe, and generate reportsAudio, photos, location, transcript, report textPerformance of a contract; in Enterprise mode, the company's legitimate interests as controller
Build the report map and derive the addressLocationPerformance of a contract
Deliver shared reports to recipientsReport content, recipient emailPerformance of a contract
Synchronize reports to a company workspaceReport content, tenant/site identifiersPerformance of a contract; company's legitimate interests
Support and troubleshootingSupport correspondence, redacted diagnosticsLegitimate interests in a working product
Security, abuse prevention, and service integrityIdentifiers, security logs, usage eventsLegitimate interests in protecting the Service; legal obligation
Improve reliability and performanceAggregated usage, performance, and diagnostic dataLegitimate interests in improving the Service
Billing and subscription management, if paid subscriptions are introducedAccount identifiers, purchase records held by the app storePerformance of a contract; legal obligation
Meet legal and regulatory obligationsAs requiredLegal obligation

We do not use your report content for advertising or profiling, and we do not sell it.

6. AI processing

Report 6 uses automated systems to turn a walk into a document. Specifically, AI:

  • transcribes your narration into text;
  • identifies issues and findings described in that narration;
  • associates captured photos with the findings they illustrate;
  • drafts summaries, descriptions, and recommended actions; and
  • may propose a category, severity, or assignee for a finding.

AI output is a draft you are responsible for. Every report is presented for your review before it is finalized, and you can edit or delete anything the AI produced. Transcription and issue detection can be wrong — they mishear, miss things, and occasionally invent detail.

No automated decisions about people. Report 6 does not use AI output to make decisions that produce legal or similarly significant effects about any individual, and it is not designed for, and must not be used for, evaluating individual workers, scoring people, or determining anyone's access to employment, housing, credit, insurance, or benefits.

Our AI and transcription providers process your content solely to return a result to us, under contract. Your content is not used to train their models.

7. Sharing and recipients

  • People you send a report to. When you share a report by link or email, the recipient receives the report content — narration transcript, photos, location, and findings.
  • The company, in Enterprise mode. Its administrators, the users it grants access, and any vendor or contractor it assigns to a finding.
  • Service providers. The processors listed in section 10, under written data-processing agreements, only to deliver the Service.
  • Legal disclosures. Where we are legally required to, or where disclosure is necessary to investigate suspected fraud, abuse, or a threat to someone's safety. Where we are permitted to notify you, we will.
  • Business transfers. If Patrol 6 is involved in a merger, acquisition, or sale of assets, data may transfer to the successor, which remains bound by this policy or gives notice before changing it materially.

Anyone holding a valid report link can open the report. Share links are unauthenticated by design so a recipient does not need a Report 6 account. Treat a link like the report itself: anyone it is forwarded to can read the contents until it expires — and until the report is locked, the link also lets the recipient edit the draft; that is how emailed review works. Links expire automatically after 7 days. If a link gets out, delete the report — which disables its link immediately — or contact us.

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under US state privacy laws.

8. Storage and retention

Personal Personal mode

DataKept for
Finished reports on your deviceUntil you delete them. The device copy is the primary copy.
Source media in the cloud — audio, captured frames, location traceLocked and deleted automatically within 72 hours of the report being finalized. Media not referenced by a finished report is removed in the same cleanup.
Reports abandoned before finalizingDeleted within 30 days of the last activity on the draft.
Shared links7 days from creation, then the link expires and stops working. Deleting the report disables its link immediately.
Account record — email, identifiers, settingsUntil you delete your account.
Uploaded diagnostics30 days from upload.
Security and access logs12 months.
Billing and tax records, if any7 years, as required by US tax law.
Encrypted backups35 days on a rolling cycle. Deleted data persists in backups until the cycle passes it, and is not restored into the live service.

Enterprise Enterprise mode

Reports you submit to a company workspace are stored in that company's cloud tenant under that company's retention policy, which is typically far longer than the consumer windows above — field reports are often kept for years as evidence. The consumer windows in the table do not apply to them, and deleting your personal Report 6 account does not delete them. Retention, legal holds, and deletion for enterprise report content are set in the company's Data Processing Addendum and administered by the company. To ask about or request deletion of company reports, contact the company.

Patrol 6's own retention for account, authentication, security, and diagnostic data is the same in both modes, per the table above.

9. Deletion and account closure

  • Delete a single report. Delete it in the app. This removes the device copy and any cloud copy Patrol 6 holds, and disables any live share link for it.
  • Delete your account. In the app, go to Settings → Delete Account & Personal Data. You can start account deletion from inside the app, without contacting us. We delete your account record, personal reports, cloud media, and share links within 30 days, subject to the backup cycle and to records we must keep by law (billing and tax). See Delete your account for the step-by-step.
  • Leave a company workspace. Sign out of the company account in the app to stop reporting into its workspace; a company administrator can also remove your access at any time, which removes the workspace and its reports from your app. Neither deletes reports already submitted — those belong to the company.
  • Enterprise deletion. When a company deletes a report or removes a user in its own system, that deletion propagates to the copies Patrol 6 processes on its behalf. Company-side deletion requests go to the company's administrator.

10. Service providers and international transfers

We use a small set of providers to run Report 6. Each is bound by a written data-processing agreement, may use your data only to provide its service to us, and may not use it for its own purposes or to train its models.

ProviderWhat it doesDataProcessing location
Google Cloud Platform / FirebaseAuthentication, database, file storage, backend functions, crash reportingAccount data, report content, media, diagnosticsUnited States
DeepgramSpeech-to-text transcriptionAudio narrationUnited States
Mapping and geocoding services (cloud)Convert report GPS coordinates into the report's street addressLocation coordinatesUnited States
AI report-generation provider (cloud AI service)Issue detection, media association, summaries and recommendationsTranscript, photos, report metadataUnited States
ResendTransactional email — verification, share noticesEmail address, report linkUnited States
AppleApp Store distribution; MapKit map renderingApp Store account and download records held by Apple; map tiles are fetched by your device under Apple's own policyUnited States

A current subprocessor list is available at support@patrol6.com, and enterprise customers receive advance notice of changes under their Data Processing Addendum.

International transfers

Patrol 6 is based in the United States and processes data there. If you use Report 6 from the United Kingdom, the European Economic Area, Canada, or Australia, your information is transferred to the United States. For UK and EEA transfers we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the Standard Contractual Clauses, together with a transfer risk assessment and technical measures including encryption in transit and at rest. Copies of the transfer mechanism are available on request.

11. Security and incidents

  • All traffic between the app and our services is encrypted in transit with TLS, and stored data is encrypted at rest.
  • Access to production data is limited to personnel who need it, is authenticated and logged, and is reviewed periodically.
  • Enterprise tenants are logically separated, so one company cannot reach another's reports.
  • Share links expire automatically after 7 days.
  • Diagnostics are redacted of report content before upload.
  • Backups are encrypted and access-controlled.
  • We maintain an incident response process. Where a breach is likely to result in a risk to your rights, we will notify you and the relevant regulator within the timeframes the applicable law requires — including 72 hours to the ICO under UK GDPR and, in Australia, assessment and notification under the Notifiable Data Breaches scheme. For enterprise report content we notify the company as controller, without undue delay, per the Data Processing Addendum.

No system is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your device and sign-in credentials secure, and for who you send reports to.

12. Your rights and how to complain

Depending on where you live, you may have the right to access your personal information, correct it, delete it, receive a portable copy, object to or restrict certain processing, withdraw consent, and not be discriminated against for exercising these rights. Section 16 sets out what applies in your region.

  • How to ask. Email support@patrol6.com from the address on your account, or write to the Privacy Officer at the address in section 1. Tell us what you want and which mode the data relates to.
  • Verification. We verify your identity before acting — normally by confirming control of the account email, and for higher-risk requests by asking for detail only the account holder would know. We collect the minimum needed and do not keep it afterwards.
  • Timing. We acknowledge within 10 business days and respond within 30 days, or one month where UK GDPR applies, extendable by two further months for complex requests with an explanation. Requests are free unless manifestly unfounded or excessive.
  • An authorized agent may submit a request on your behalf with written proof of authority.
  • Appeals. If we refuse, we tell you why, and where the law provides an appeal you can reply to the same address with "Appeal" in the subject.
  • Enterprise mode. For report content held by a company whose workspace you report into, contact that company first — it is the controller. If you send the request to us, we will route it to the company and tell you we have done so.

13. People captured in reports

Continuous capture in public, commercial, or workplace settings will pick up other people, vehicles, faces, plates, and background conversation. Automatic deletion of unreferenced cloud media (section 8) is intended in part to limit how long incidental capture is retained.

You are responsible for recording lawfully. Recording, wiretap, one- and two-party consent, workplace monitoring, and CCTV laws differ by country, state, and province, and some require notice or consent from people being recorded. Before you capture, make sure you have the right to record that place, those people, and that audio.

If you appear in a report and want it addressed, contact the person or company that created it. If you cannot identify them, email support@patrol6.com with what you know and we will route your request to the controller and assist where we can.

14. Children and restricted use

Report 6 is a workplace tool for adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 13. You must be at least 16 to hold an account and 18 or older to use Report 6 in a workplace setting. If we learn that we hold information from a child in breach of this, we delete it. A parent or guardian who believes a child has given us information should email support@patrol6.com.

Report 6 is not designed or cleared for medical, clinical, social-work, child-welfare, or school-safeguarding workflows, and must not be used to capture health information, information about identified children, or other special-category data without a separate written agreement with us.

15. Changes to this policy

We will update this policy as Report 6 changes. The version number and effective date at the top tell you which version you are reading. For material changes — new categories of data, new purposes, new recipients, or shorter protections — we will give notice in the app and by email to account holders at least 14 days before the change takes effect, and enterprise customers get notice under their Data Processing Addendum. Prior versions are available on request.

VersionDateChange
1.026 August 2026First published app privacy policy, covering Personal and Enterprise modes.

16. Regional addenda

These sections add to, and where they conflict override, the rest of this policy for people in the regions named.

United States

Notice at collection. The categories we collect, why, and for how long are set out in sections 3, 5, and 8. In the language of US state privacy laws we collect identifiers; personal information under Cal. Civ. Code §1798.80; commercial information (subscription records, if any); internet and app activity; precise geolocation; audio, electronic, and visual information; and inferences drawn from report content. Sources are you, your device, and — in Enterprise mode — the company whose workspace you report into.

Sensitive personal information. Precise geolocation is sensitive personal information under California law. We use it only to provide the Service — placing findings on the map and deriving the report address — and for the security and integrity of the Service. We do not use or disclose it to infer characteristics about you, and California residents therefore have no further right to limit its use beyond what we already do.

No sale, no sharing. We do not sell personal information and do not share it for cross-context behavioral advertising, and we have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of anyone under 16.

Your rights. Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws may request to know, access, correct, delete, and obtain a portable copy of their personal information, opt out of targeted advertising, sale, and profiling with legal effects (none of which we do), and appeal a refusal. We will not discriminate against you for exercising any of these rights — no denial of service, different pricing, or reduced quality. Submit requests as described in section 12. California residents may also contact the California Privacy Protection Agency or the Attorney General; other states, their Attorney General.

Recording consent. Federal and state wiretap and eavesdropping laws are separate from privacy law. Some states require all parties to a conversation to consent to audio recording. Whether and how you may record is your responsibility — see section 13 and the App Terms of Use.

United Kingdom

For UK users, Patrol 6, LLC is the controller for the data described in section 2 and processes personal data under UK GDPR and the Data Protection Act 2018.

  • Lawful basis. Purpose by purpose, in the table in section 5 — chiefly Article 6(1)(b) performance of a contract, Article 6(1)(f) legitimate interests for security, support, and service improvement, and Article 6(1)(c) legal obligation. Where we rely on legitimate interests we have balanced them against your rights, and you may object at any time.
  • Retention. The periods in section 8 are the retention schedule; we do not rely on open-ended "as long as necessary" wording.
  • Your rights. Access, rectification, erasure, restriction, portability, objection, and the right not to be subject to solely automated decisions with legal or similarly significant effects — which Report 6 does not make (section 6). Where processing relies on consent, you may withdraw it without affecting prior processing.
  • Complaints. You may complain to the Information Commissioner's Office — ico.org.uk, helpline 0303 123 1113 — though we would like the chance to resolve it first.
  • Transfers. See section 10. We rely on the UK International Data Transfer Addendum to the EU SCCs, plus a transfer risk assessment.
  • Employers. A UK company using Enterprise mode is the controller for the reports its workers submit. Because Report 6 captures audio and precise location during working time, that company is responsible for its own transparency notice to workers, for identifying a lawful basis for monitoring, and — where the processing is likely to result in high risk — for carrying out a Data Protection Impact Assessment before deployment. We will provide the information needed to complete one.

Canada

For Canadian users we handle personal information under PIPEDA and applicable provincial laws, on these principles:

  • Accountability. Our designated Privacy Officer is reachable at support@patrol6.com or the address in section 1.
  • Identified purposes and meaningful consent. The purposes are in section 5. We obtain consent at the point of collection — app store disclosure, in-app permission prompts, and this policy — and you may withdraw consent, subject to legal or contractual limits, by deleting your account or contacting us.
  • Limiting collection, use, and retention. We collect only what the report requires and delete on the schedule in section 8.
  • Access and correction, safeguards, and challenging compliance as described in sections 11 and 12.
  • Cross-border. Your information is processed in the United States and is subject to lawful access by US authorities (section 10).
  • Provincial. Alberta PIPA, British Columbia PIPA, and Quebec Law 25 apply where relevant, including Quebec's rights to de-indexing and data portability and its requirement to notify you of transfers outside Quebec. A French-language version of this policy is available for Quebec users on request; where Report 6 is distributed in Quebec, French is offered on equal terms.
  • Complaints. Contact us first, then the Office of the Privacy Commissioner of Canada, or your provincial commissioner in Alberta, British Columbia, or Quebec.

Australia

For Australian users we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

  • Collection notice. What we collect and why is in sections 3 and 5. We collect only what is reasonably necessary for our functions. Where practical you may deal with us anonymously or by pseudonym for general enquiries; you cannot use the Service anonymously, because a report has to be attributable to its author.
  • Sensitive information. We do not solicit sensitive information. Report 6 is not to be used to capture health or other sensitive information (section 14).
  • Access and correction. Under APP 12 and 13, as described in section 12. If we refuse access we give written reasons and the complaint mechanism.
  • Overseas recipients. Under APP 8, your information is disclosed to recipients in the United States — the providers in section 10.
  • Direct marketing. We do not use report content for direct marketing. Product emails carry an unsubscribe link.
  • Data breaches. We assess eligible data breaches and notify affected individuals and the OAIC as the Notifiable Data Breaches scheme requires.
  • Complaints. Email us and we will respond within 30 days. If you are not satisfied you may complain to the Office of the Australian Information Commissioner — oaic.gov.au.
  • Surveillance devices. State and territory surveillance devices and listening devices laws govern recording of conversations and workplaces and are separate from the Privacy Act. Complying with them is your responsibility.

17. Contact

Questions, requests, or complaints about this policy or your data:

Privacy Officer
Patrol 6, LLC, an Arizona limited liability company
2843 E Robin Ln, Phoenix, AZ 85050, United States
support@patrol6.com

See also the App Terms of Use, the website Privacy Policy, and Delete your account.