Last updated September 10, 2026
CPL Proof privacy
CPL Proof is designed to inspect cinema package metadata locally without creating an account or sending package content to the developer.
Data collection
CPL Proof does not collect, transmit, sell, rent, or share personal data. The app contains no analytics SDK, advertising SDK, tracking technology, account system, subscription, in-app purchase, or developer-operated cloud service.
Package folder access
CPL Proof accesses a folder only after you choose it with Apple's document picker. Security-scoped access is used to read package XML and files for the requested scan. The developer does not receive the folder, filenames, cinema content, hashes, KDM metadata, or scan results.
KDM metadata
If you choose a KDM XML file, CPL Proof reads descriptive metadata such as composition identifiers, validity times, device labels, certificate thumbprints, and encrypted-key counts. CPL Proof does not extract private keys, decrypt cinema content, verify certificate chains, or upload KDM data.
Local records
Package revisions, dependency findings, screening plans, audit history, operator fields, venue fields, drive labels, and notes are stored in the app's local container. Deleting the app removes its local container through the operating system. CPL Proof does not synchronize records through a developer service.
Exports
PDF, CSV, JSON, and TXT evidence files are created locally. CPL Proof shares an export only when you invoke the Apple share sheet or choose a destination. The privacy terms of the destination you choose apply after export.
Permissions
CPL Proof does not request camera, microphone, photo library, location, contacts, health, Bluetooth, or tracking permission. The system document picker and share sheet are used only after an explicit action.
Children
CPL Proof is a specialist cinema operations utility and is not directed to children. Because the app does not collect data, it does not knowingly collect personal information from children.
Policy changes
If the app's data practices change, this page will be revised before the changed behavior is released. The last-updated date above identifies the current policy.
Contact
Privacy questions can be sent to the developer. Do not attach confidential DCP, KDM, or venue files.
Email CPL Proof privacyPreserved cases
An unreadable current or legacy case file remains in the app container. You may explicitly share that file for recovery. Deleting the app removes the local copy; previously exported copies remain at their chosen destinations.