Local when you choose local. Clear when work goes to the cloud.
ShotOps is operated by IT Envy Technology Solutions LLC under the Envy Forge developer brand. Contact Support@itenvy.com with privacy questions.
Release modes
Free local use
No account is required to capture, organize, review, or export work photos and videos. The local app does not include ads, an advertising identifier, behavioral analytics, or an advertising SDK.
Optional Personal Pro beta
Invited testers may sign in and enable a personal job source for hosted metadata sync, web management, and encrypted media backup. Signing in does not automatically back up every local job. Personal Pro is not currently represented as a generally available public purchase.
Data handled on your device
- User-captured or imported photos and videos, including audio from user-initiated video.
- Capture time, media type, local file reference, Job assignment, Projects, phases, tags, archive/export state, markup, reports, and before/after links.
- Optional coordinates, address labels, job-site boundaries, and location consent when enabled.
- Local app, connected destination, and sync preferences.
Media is saved in the visible Pictures/ShotOps album. Organization data is stored in local SQLite, and supported Android versions may also receive a recovery manifest under Documents/ShotOps.
Data processed for Personal Pro
- Identity and session information provided through Clerk.
- Installation identifier, trusted-device public key, selected job-source links, sync health, and bounded security/error state.
- Selected job and source metadata needed for synchronization and web management.
- Encrypted originals, previews, and thumbnails when backup is enabled and the configured provider is operational.
Job and source metadata is protected in transit but is not end-to-end encrypted. It must be processed by ShotOps to synchronize and manage backed-up jobs.
Media encryption and recovery
Personal Pro media is encrypted on the device before upload. Encrypted bytes are stored through the configured private object-storage provider. The job-source backup key is not sent to Clerk, Convex, or the storage bucket.
The current user-held recovery mode requires a recovery kit stored outside the phone. Envy Forge cannot recreate a lost user-held recovery kit.
Permissions
- Camera for photos, video, documents, and code capture.
- Microphone during user-initiated video recording.
- Photos and videos for ShotOps gallery management—not to back up unrelated personal media.
- Foreground location for approved geotags and job-site tools. ShotOps does not request background location.
- Network for sign-in, selected Pro sync, maps/geocoding, and provider activity.
Sharing and service providers
You control sharing and export. Connected Android document providers own their sign-in; ShotOps stores a folder reference and Android access grant, not Google or Microsoft passwords.
- Clerk for identity and sessions.
- Convex for application data and synchronization.
- Railway for the web portal and storage gateway.
- Private object storage for encrypted beta media.
- Google Maps Platform or device geocoding for user-initiated maps, search, or address features.
Retention and deletion
Local media remains until you delete it through ShotOps or Android photo/file tools. Uninstalling can remove app-private metadata; the visible ShotOps album and recovery manifest may remain.
Personal Pro deletion revokes devices, deletes hosted media bytes before associated records, removes related hosted data, and minimizes the retained account tombstone. Local files and copies already sent elsewhere are not deleted.