Privacy policy
Effective October 10, 2026
The short version: Doorbook stores visitor information on the tablet it was entered on. The Doorbook developer never receives it. If you turn on cloud sync, the tablet sends check-ins straight to the Google or Microsoft account you connect, which you control. We don’t run ads, we don’t sell data, and the app has no analytics or tracking.
1. Who we are
“Doorbook”, “we” and “us” mean the developer of the Doorbook app and this website. You can reach us at support@getdoorbook.com.
2. Who controls visitor information
Doorbook is a tool that an organization (a business, school, church, club or event host, called the organization here) installs on its own tablet. The organization decides what to ask visitors, how long to keep their answers, and whether to copy them to its own cloud storage. The organization is responsible for that information and for telling visitors how it is used. Visitors with questions about their information should contact the organization that ran the kiosk.
We do not receive, see or store visitor information, so we cannot look up, correct or delete it for anyone. Organizations can do all of that themselves in the app.
3. What the app stores on the tablet
Everything below is kept in the app’s private storage on the tablet and is not sent to us.
| Information | Why |
|---|---|
| Visitors’ answers to the sign-in questions the organization sets up (for example name, email, phone, company), the time of check-in, and whether they ticked the privacy-notice box | The sign-in list itself |
| Visitor photos, only if the organization turns photos on | Shown in the admin visitor list and included in exports |
| Settings, a station name for the tablet, and a monthly check-in count | Running the app and the free-plan limit |
| The admin PIN, stored only as a salted PBKDF2 hash, and a one-time recovery code, also hashed | Protecting the admin screens |
| Sign-in tokens for Google or Microsoft, only if cloud sync is connected | Letting the tablet write to the organization’s own cloud account |
Android cloud backup is turned off for Doorbook, so this information is not copied into a device-wide Google backup.
4. Optional cloud sync (Pro)
An admin can connect the tablet to a Google Drive, Microsoft OneDrive or SharePoint account that the organization owns. When connected, the tablet sends each check-in (the visitor’s answers, check-in time, station name, consent answer and, if enabled, the photo) directly from the tablet to that account over an encrypted connection. It does not pass through any Doorbook server. Once there, the information is held by Google or Microsoft under the organization’s own agreement with them.
Disconnecting sync on the tablet deletes the stored sign-in tokens from the tablet. Files already in the organization’s cloud account stay there until the organization deletes them.
5. Google user data
When an admin connects Google Drive, Doorbook asks Google for these permissions:
drive.file: create and update only the files and folders Doorbook itself creates (the “Doorbook – Organization” folder, its check-ins Sheet and Photos folder). Doorbook cannot see or open any other files in the account.emailandopenid: show which Google account is connected (“Connected as name@example.com”).
This information is used only on the tablet to provide the sync feature the admin turned on. It is not sent to us, not sold, not used for advertising, and not used to train AI or machine-learning models. No person at Doorbook can read it.
Doorbook’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can remove Doorbook’s access at any time at myaccount.google.com/permissions, or by tapping Disconnect in the app.
6. Microsoft user data
When an admin connects OneDrive or SharePoint, Doorbook asks Microsoft for:
Files.ReadWrite(OneDrive) orSites.ReadWrite.All(SharePoint): create the Doorbook folder, workbook (or CSV file) and Photos folder, and add check-ins to them. For SharePoint, the app also lists sites and document libraries so the admin can choose where to save.User.Read: show which account is connected.offline_access: keep syncing without signing in again each hour.
Doorbook only writes to the Doorbook folder it creates and does not read other files. As with Google, this information stays between the tablet and Microsoft and is never sent to us. You can remove access at myapps.microsoft.com (work or school accounts) or account.live.com/consent/Manage (personal accounts).
7. Purchases and subscriptions
Pro subscriptions are sold through the Amazon Appstore or Google Play, which handle payment. We never see card details. To check whether a tablet has an active subscription, the app uses RevenueCat, a subscription service. RevenueCat receives a random app user ID that is not tied to your name, the purchase receipt from the store, and basic app and device details (such as app version and country). It never receives visitor information. We can see subscription records in RevenueCat to provide support and refunds where the store allows.
8. Device permissions
- Camera: only used if the organization turns on visitor photos. Photos are taken inside the app and saved on the tablet.
- Internet: used only for optional cloud sync, sign-in to Google or Microsoft, and subscription checks.
- Kiosk lock: when an admin turns it on, Doorbook pins itself to the screen using Android’s screen pinning or, on tablets set up for it, Android’s lock-task mode. It does not read anything from other apps.
9. This website
getdoorbook.com uses no cookies, no analytics and no advertising. It is hosted by Cloudflare, which processes standard request information (such as IP address and browser type) to deliver and protect the site. If you email us, we use your message and address only to reply and keep a record of the conversation.
10. Keeping and deleting data
- Check-ins stay on the tablet until an admin deletes them, one at a time or all at once, from the admin screens. Uninstalling the app deletes everything it stored on the tablet.
- Photos can be set to delete automatically after 30, 90 or 365 days.
- Copies in the organization’s Google or Microsoft account are kept and deleted by the organization.
- Support emails are kept as long as needed to help you and then deleted.
11. Security
Admin screens are protected by a PIN, stored only as a salted hash, with lockouts after repeated wrong tries. All cloud sync uses encrypted HTTPS connections and the narrowest permissions that make the feature work. Spreadsheet exports and synced sheets are written so that nothing a visitor types can run as a formula. No system is perfectly secure, so organizations should also protect the tablet itself with a screen lock and keep it in a supervised place.
12. Children
Doorbook is a tool for organizations and is not directed at children. If an organization uses it where children sign in, the organization is responsible for getting any consent its local laws require. We do not knowingly collect personal information from children, and in practice we receive no visitor information at all.
13. Your choices and rights
Depending on where you live, you may have rights to access, correct or delete personal information. Because visitor information is held by the organization that ran the kiosk (on its tablet or in its own cloud account), please contact that organization. For anything we hold, such as support emails or subscription records, email support@getdoorbook.com and we will respond within 30 days. We do not sell or share personal information for advertising.
14. Changes and contact
If we change this policy we will update the date at the top. Material changes will also be noted in the app’s release notes. Questions: support@getdoorbook.com.