Privacy Policy

1. Who We Are

This service (the “Service”) is operated by [OPERATOR]. This policy explains what information the Service collects, why, and what your choices are. You can reach us about anything in this policy at [CONTACT-EMAIL].

2. Information We Collect

Account information. Your email address and a password. The password is stored only as a bcrypt hash — we cannot see or recover your actual password.

Business data you enter. Clients (including any names, addresses, and contact details you record for them), projects, tasks, time entries and their notes, and the invoices generated from them — including the invoice PDF files, which are stored on our server so you can re-download them.

Technical data. A session identifier (see Cookies below) and standard server logs. Rate-limiting counters are held in memory and are not persisted.

We collect nothing else. There is no analytics or tracking script in the Service.

3. How We Use Information

Solely to provide the Service: to authenticate you, store and display your data, generate your invoice PDFs, and send transactional email — password reset links and email-address verification. We send no marketing email. We do not advertise, profile you, or sell or share your data for anyone else's purposes.

4. Cookies and Local Storage

The Service sets exactly one cookie: a strictly necessary session cookie (connect.sid) that exists solely to keep you logged in. It is set only when you log in or sign up — visitors who are not logged in receive no cookie at all. It is httpOnly (not readable by scripts), restricted to same-site requests, marked Secure in production, and expires after 24 hours.

The Service also stores two small flags in your browser's sessionStorage, remembering for the current tab that you dismissed the setup wizard or the email-verification banner. They never leave your browser.

There are no analytics cookies, no advertising cookies, and no third-party cookies of any kind — which is why the Service shows no cookie banner.

5. Service Providers

Two providers process data on our behalf, only as needed to run the Service:

No other third parties receive your data.

6. Data Retention, Export, and Deletion

We keep your data for as long as your account is active. From the Settings page you can, at any time:

You may also request a copy of your data, or deletion of your account, by emailing [CONTACT-EMAIL]. We will honor verified requests within 30 days.

7. Security

Passwords are stored only as bcrypt hashes. Password reset, email verification, and email-change confirmation links are single-use and expire after one hour, and only a cryptographic hash of each link's token is stored on the server. In production, all traffic to the Service is encrypted over HTTPS. No system is perfectly secure, but the Service is built so that a copy of its database does not expose passwords or usable login tokens.

8. Children

The Service is a business tool and is not directed at children under 13. We do not knowingly collect personal information from children; if you believe a child has created an account, contact us and we will delete it.

9. Changes to This Policy

We may update this policy from time to time. The “Last updated” date above reflects the current version, and material changes will be noted there.

10. Governing Law & Contact

This policy is governed by the laws of the Commonwealth of Massachusetts, USA. For any privacy question or request: [CONTACT-EMAIL].