Privacy Policy
Last updated: July 30, 2026
1. Who We Are
This service (the “Service”) is operated by [OPERATOR]. This policy explains what information the Service collects, why, and what your choices are. You can reach us about anything in this policy at [CONTACT-EMAIL].
2. Information We Collect
Account information. Your email address and a password. The password is stored only as a bcrypt hash — we cannot see or recover your actual password.
Business data you enter. Clients (including any names, addresses, and contact details you record for them), projects, tasks, time entries and their notes, and the invoices generated from them — including the invoice PDF files, which are stored on our server so you can re-download them.
Technical data. A session identifier (see Cookies below) and standard server logs. Rate-limiting counters are held in memory and are not persisted.
We collect nothing else. There is no analytics or tracking script in the Service.
3. How We Use Information
Solely to provide the Service: to authenticate you, store and display your data, generate your invoice PDFs, and send transactional email — password reset links and email-address verification. We send no marketing email. We do not advertise, profile you, or sell or share your data for anyone else's purposes.
4. Cookies and Local Storage
The Service sets exactly one cookie: a strictly necessary
session cookie (connect.sid) that exists solely to keep you logged
in. It is set only when you log in or sign up — visitors who are not
logged in receive no cookie at all. It is httpOnly (not readable
by scripts), restricted to same-site requests, marked Secure in production,
and expires after 24 hours.
The Service also stores two small flags in your browser's
sessionStorage, remembering for the current tab that you dismissed
the setup wizard or the email-verification banner. They never leave your
browser.
There are no analytics cookies, no advertising cookies, and no third-party cookies of any kind — which is why the Service shows no cookie banner.
5. Service Providers
Two providers process data on our behalf, only as needed to run the Service:
- Resend delivers our transactional email and processes your email address for that purpose.
- Railway hosts the Service; the database and your generated PDFs are stored there.
No other third parties receive your data.
6. Data Retention, Export, and Deletion
We keep your data for as long as your account is active. From the Settings page you can, at any time:
- Export your data — download a complete copy of your account data (clients, projects, tasks, time entries, invoices, and settings) as a single JSON file. Generated invoice PDFs are downloadable individually from each invoice.
- Delete your account — permanently remove your account and all associated data, including generated PDF files and active login sessions. Deletion is immediate and cannot be undone.
You may also request a copy of your data, or deletion of your account, by emailing [CONTACT-EMAIL]. We will honor verified requests within 30 days.
7. Security
Passwords are stored only as bcrypt hashes. Password reset, email verification, and email-change confirmation links are single-use and expire after one hour, and only a cryptographic hash of each link's token is stored on the server. In production, all traffic to the Service is encrypted over HTTPS. No system is perfectly secure, but the Service is built so that a copy of its database does not expose passwords or usable login tokens.
8. Children
The Service is a business tool and is not directed at children under 13. We do not knowingly collect personal information from children; if you believe a child has created an account, contact us and we will delete it.
9. Changes to This Policy
We may update this policy from time to time. The “Last updated” date above reflects the current version, and material changes will be noted there.
10. Governing Law & Contact
This policy is governed by the laws of the Commonwealth of Massachusetts, USA. For any privacy question or request: [CONTACT-EMAIL].