Privacy Policy
Last updated: May 12, 2026
Quotafly ("we", "our", or "us") is built for field service contractors. This policy explains what data we collect, why we collect it, and how we keep it safe. We keep it plain — no legal maze.
1. What We Collect
Account Information
Your name, email address, and password when you create an account. If you sign in with Apple, we receive only your name and email from Apple.
Business Profile
Your business name, phone number, logo, and payment terms — entered during onboarding or in Settings.
Voice Recordings & Transcripts
Audio you record in the app, along with the AI-generated transcript and extracted quote data (client name, services, prices). Recordings are processed by our AI and then stored securely in your account.
Quotes, Invoices & Payments
All documents you create — quotes, invoices, receipts — and payment records (amounts, methods, dates). We do not store full credit card numbers. Card processing is handled entirely by Stripe.
Client Data
Contact names, email addresses, and phone numbers you add to your CRM. This data belongs to you — we store it on your behalf to power the app.
Usage Data
Basic app usage information such as feature interactions and error logs, used to improve the product. We do not sell this data.
2. How We Use Your Data
- To provide and operate the Quotafly app and web dashboard
- To process your voice recordings and generate AI-powered quotes
- To send quotes, invoices, and receipts to your clients on your behalf
- To process subscription payments and manage your billing
- To show you your pipeline, client history, and business stats
- To send you transactional emails (account confirmation, password reset, trial reminders)
- To improve the product and fix bugs
We do not use your data for advertising. We do not sell your data to third parties.
3. Third-Party Services
Quotafly uses the following services to operate. Each has its own privacy policy.
Supabase
Stores all your account data, contacts, documents, and voice notes in a secure PostgreSQL database. Also handles authentication.
supabase.com/privacyStripe
Processes all subscription and client payments. Stripe handles card data directly — Quotafly never sees or stores full card numbers.
stripe.com/privacyBrevo (Sendinblue)
Delivers transactional emails — quotes, invoices, and receipts sent to your clients, and account emails sent to you.
brevo.com/legal/privacypolicyAnthropic (Claude AI)
When you use the voice recording feature, your recording is transcribed on-device and the transcript is sent to Anthropic's Claude AI to extract client name, services, and pricing to generate your quote. The iOS app asks for your consent before the first recording. Transcript data is not used to train Anthropic's models. You can revoke consent at any time in the app under Settings → Preferences → AI voice processing.
anthropic.com/privacy4. Data Retention
Your data is retained for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or financial compliance purposes (such as payment records).
5. Your Rights
You have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Request deletion of your account and data
- Export your data (contacts, documents)
To exercise any of these rights, email us at support@quotafly.com.
6. Security
All data is transmitted over HTTPS. Authentication tokens are stored in the iOS Keychain. Your data is stored in Supabase with row-level security — you can only access your own data. We follow industry-standard practices to protect your information.
7. Children's Privacy
Quotafly is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with their information, please contact us and we will delete it.
8. Changes to This Policy
We may update this policy as the product evolves. When we do, we will update the "Last updated" date at the top of this page. Continued use of Quotafly after changes means you accept the updated policy.