Effective date: May 7, 2026 Last updated: May 7, 2026

This Privacy Policy describes how Carleton Energy Consulting, LLC (“CEC”, “we”, “us”) collects, uses, and protects information when you use the CEC Audit iOS application (the “App”). The App is provided to CEC personnel and authorized contractors for the purpose of conducting energy audits and related fieldwork.

This policy applies only to information collected through the App. CEC’s website, customer portal, and other services have their own data practices and are not covered here.

1. Information we collect

When you use the App, we collect:

  • Account information — your email address and password used to sign in.
  • Audit content — information you create as part of an energy audit, including written notes, equipment lists, building characteristics, measurements, photos, videos, audio recordings, and 3D room scans captured using your device’s camera, microphone, and ARKit/RoomPlan sensors. We only capture this content with the permissions you grant through iOS.
  • Diagnostic data — crash logs, performance metrics, app version, iOS version, and device model. We collect this through Google Firebase Crashlytics to identify and fix issues.
  • Usage data — anonymized information about how features in the App are used (such as which screens are visited and how often), collected through Google Firebase Analytics.

We do not collect: location data, advertising identifiers (IDFA), contacts, calendars, health or financial data, or browsing history.

2. How we use information

We use the information we collect to:

  • Provide the App’s core functionality (creating, syncing, and reviewing energy audits).
  • Authenticate your account and protect against unauthorized access.
  • Diagnose and fix technical issues, monitor reliability, and improve the App.
  • Comply with our legal obligations.

We do not sell personal information and we do not use the information collected through the App for advertising.

3. How information is stored and shared

Audit content and account information are transmitted over HTTPS and stored on infrastructure operated by CEC.

We share information with the following service providers, who process information on our behalf under contractual obligations to protect it:

  • Google Firebase (Analytics and Crashlytics) — diagnostic and usage data only. Google’s privacy practices are described at https://policies.google.com/privacy.
  • Cloud infrastructure providers that host CEC’s backend systems.

We do not share your information with any other third parties except (a) when required by law, (b) to protect our rights or the rights of others, or (c) in connection with a corporate transaction (such as a merger or asset sale), in which case the recipient will be bound by terms consistent with this policy.

4. Data retention

We retain audit content and account information for as long as needed to support the legitimate business purposes for which it was collected, including ongoing project work and contractual or regulatory obligations.

You may request deletion of your account and associated data by contacting us at the address below. Some information may be retained as required by law or for legitimate business purposes after account deletion. Diagnostic and usage data is retained according to Firebase’s default retention policies.

5. Security

We use commercially reasonable technical and organizational measures to protect information collected through the App, including:

  • HTTPS-encrypted transport between the App and our servers.
  • Password hashing using industry-standard algorithms.
  • iOS Data Protection (file encryption tied to device unlock).
  • iOS Keychain storage for authentication credentials.
  • Optional biometric (Face ID / Touch ID) authentication.

No system is perfectly secure. We cannot guarantee that information transmitted through the App will not be subject to unauthorized access.

6. Your rights

Depending on where you reside, you may have rights regarding your personal information. To the extent applicable law grants such rights, you may:

  • Request access to the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion of your information.
  • Opt out of analytics and diagnostic data collection (contact us to do so).

California residents. Under the California Consumer Privacy Act (CCPA), California residents have the rights described above and the right to non-discrimination for exercising those rights. We do not “sell” personal information as defined by the CCPA.

To exercise any of these rights, contact us at [email protected].

7. Children

The App is intended for use by CEC personnel and authorized contractors and is not directed to children under 13. We do not knowingly collect personal information from children under 13.

8. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above.

9. Contact

Questions about this Privacy Policy or the App’s data practices:

Carleton Energy Consulting, LLC [email protected]