Legal
Last updated: July 2026
This Privacy Policy describes how Quotes ("we", "our", "the app") handles information when you use the Quotes invoicing application, available on Android, iOS, macOS, Windows, Linux, and Web.
Because Quotes is a local-first application, the vast majority of your data never leaves your device. Please read this policy to understand exactly what is and is not transmitted.
The following data is stored exclusively on your device and is never transmitted to our servers unless you enable Cloud Sync (Pro) — see Section 3:
This data is encrypted on-device using AES-256-CBC before being written to disk. The encryption key is derived from your Firebase account identifier (UID) and is never transmitted anywhere.
Quotes uses Firebase, a Google service, for authentication and, if you enable it, cross-device sync and error reporting. The following data is shared with Firebase:
Firebase's handling of this data is governed by Google's Privacy Policy.
If you enable Cloud Sync to keep your documents up to date across multiple devices, the following is transmitted:
The encryption key is derived deterministically from your account identifier. This means the server itself cannot read your document content, but it is not a "zero-knowledge" design in the strict cryptographic sense: anyone who had access to both our Firebase project and your account identifier could in theory derive the same key. We do not access, inspect, or share this content. Cloud Sync is currently unavailable on Linux desktop.
When you use the digital signature feature, the following additional data is written to Firebase Firestore:
This data is stored in Firestore and is accessible only to your authenticated account. Signature data is retained until you delete the associated document.
As with any web request, your client's browser and device necessarily transmit their IP address to Firebase's infrastructure when they open the signing link, as an inherent part of how web requests work. We do not record, store, or use this IP address for tracking or location purposes.
Quotes uses Firebase Crashlytics to help us detect and fix bugs. When the app or our sync engine encounters an unexpected error, we receive a technical error report containing the type of error, a stack trace, and which internal operation failed. These reports never include your document content, client data, or any business information — only anonymous technical details needed to diagnose the issue. Crash reporting is disabled on the Web version of the app.
Quotes does not use any third-party advertising SDKs, behavioral analytics, or usage-tracking tools. We do not track how you use the app, and we do not profile you based on your business data.
The Backup & Restore feature exports a ZIP archive of your locally stored encrypted files. This archive is saved to a location you choose (your device's file system, cloud storage, etc.). We do not receive, store, or have access to your backup files.
Local data persists until you uninstall the app or use the "Empty Trash" / permanent delete function. Deleted documents are soft-deleted first (recoverable for 30 days) then permanently removed.
You can delete your account yourself at any time from within the app (Settings → Account → Delete Account). This immediately removes your authentication record and your associated Firestore and Cloud Sync data. If you are unable to access the app, you may instead contact us at the email below and we will delete your account and associated server-side data within 30 days.
Quotes is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it promptly.
We may update this Privacy Policy from time to time. Material changes will be communicated through an in-app notice. Continued use of the app after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or your data, contact us at: [email protected]