QuoteAloud — Privacy Policy
Last updated: 27 September 2026
QuoteAloud turns a voice note about a job into a quote, an invoice and a job report. This policy says what that involves, in plain terms. It is written to be true of the app as built, not as a template — if the app changes, this changes in the same release.
Who we are (data controller)
QuoteAloud is made and run by:
- Name: TODO(owner): legal name
- Address: TODO(owner): postal address, Morocco
- Email: support@quotealoud.com
"We" and "us" in this policy mean the person named above, who is the data controller for the account data described below. Write to the email address above about anything in this policy, including the rights listed further down.
The short version
- Your business data — customers, prices, quotes, invoices, jobs, photos, signatures — is stored on your phone, not on our server. We have no copy.
- A voice note, or text you ask the AI to read, is sent through our server to Cloudflare's AI service only to draft your quote. It is processed in memory and is not stored or logged. Anything you say in it — a customer's name or address, for example — leaves your phone only for those seconds.
- Our server keeps a small record about your account: an account id, your plan, and how many voice quotes you have used each month. If you choose to report a problem with an AI draft, we keep that report for up to 180 days.
- Android may back up your business data to your own Google account. We never receive that backup and cannot read it.
- You can delete your account and its data from inside the app: Settings → Delete account.
- This version of the app has no paid plan and takes no payments. We do not sell anything about you, and we show no advertising.
What stays on your phone
Everything you and your customers would recognise:
- customer names, phone numbers, email addresses, postal addresses and notes;
- your price list, quotes, invoices, payments and expenses;
- the transcript of each voice quote, saved with the quote so you can check it;
- jobs, with their tasks, notes, photos and the customer's signature;
- the payment reminders you schedule;
- your business name, logo, tax details and the PDFs you generate;
- your own payment details — a Stripe payment link, a PayPal handle, bank details — which are printed on your invoices and never sent to us.
This lives in a database and a folder on the device, kept separately for each account that signs in on that phone. We cannot read it. The only way any of it leaves the phone without you sending it is Android's own backup, described below — and that goes to your Google account, not to us.
When you share a PDF or a message with a customer, you choose the app it goes through (WhatsApp, email, SMS and so on), and it goes from your phone to them. It does not pass through us.
What leaves your phone, and why
A voice note, for as long as it takes to draft the quote. When you record a job, the audio is sent over an encrypted connection (HTTPS) to our server, which runs on Cloudflare Workers. Our server passes it to AI models running on Cloudflare Workers AI: Whisper turns the speech into text, and a Llama model reads that text for the services and quantities you mentioned. The audio and the transcript exist only in memory while that request runs. They are not written to storage and not logged: our code logs neither, and Cloudflare's AI Gateway, which the requests pass through, has request logging switched off both in its settings and in every request our server sends. The transcript and the draft come back to your phone. Cloudflare states that it does not use what is sent to Workers AI to train AI models.
Before your first recording, the app shows you a short notice saying this, naming Cloudflare Workers AI, and it explains the microphone before Android asks for it. The recording itself stays on your phone, in temporary storage, only until it has been turned into a draft — so that a failed upload can be retried — and is then deleted.
What the models see is what you said. If you say a customer's name, address or anything else into the microphone, it is in the audio and the transcript for the seconds that request takes. That is the only way customer details leave your phone through us, and none of it is kept. The draft that comes back can include a customer name and address the AI picked out, so that you can check them; they are saved only on your phone, and only if you save the quote.
Text you type, if you ask the AI to read it. The typed-quote screen has two buttons and they are not the same. "Fill from text" sends what you wrote the same way as a transcript — through our server to Cloudflare Workers AI, in memory only, not stored and not logged — and it counts against your monthly voice-quote allowance. The typed-quote screen says so, naming Cloudflare Workers AI, directly above the button, before you use it. "Enter items manually" sends nothing at all, makes no AI request, and is unlimited.
The names of your services, and your language settings. With each voice note or typed text, the app sends the names on your price list, so the AI can match "deep clean" to your own line rather than invent one; the language you speak, if you chose one in Settings; and the language the app is in. Your prices are never sent, and no AI model is ever asked what anything costs: the quote is priced on your phone, from your own price list, by ordinary arithmetic.
Your sign-in. You can sign in with Google, or with an email address and a password, through Firebase Authentication, a Google service. Firebase holds your email address, your name if you gave one (with Google sign-in, the name and profile picture link on your Google account), and an account identifier (a "uid"). We never receive your password. Each request to our server carries a signed token from Firebase; our server checks that it is genuine, takes the uid from it, and does not store your email address or name.
Confirming your email address. If you sign up with an email address and a password, the app opens only once you have shown the address is yours. Our server creates a random 6-digit code and emails it to the address on your account, through Resend, an email delivery service; you type the code into the app, and our server then marks the address as confirmed in Firebase Authentication. To do that, our server reads your email address from your sign-in token — only on these two requests, and without storing it. It keeps a one-way fingerprint (hash) of the code, never the code itself, for at most ten minutes, and deletes it as soon as the code is used or has had five wrong tries. Signing in with Google skips this step, because Google has already confirmed the address.
Crash reports. Release builds send crash reports to Firebase Crashlytics (Google): the error and where in the code it happened, the app version, the device model, the Android version, the device's state at the time (such as free memory), and a Firebase installation ID — a random identifier for this installation of the app. A crash report is not linked to your account id, and the app attaches nothing of its own to it: no audio, no transcript, no customer details and no amounts. Development (debug) builds send nothing.
A problem report about an AI draft — only if you send one. The screen where you review an AI draft has Report a problem with this AI draft (a flag at the top, and a link in the AI notice). If you use it, the app sends: the reason you picked (offensive or inappropriate content, wrong items or quantities, or something else); your comment, if you write one (up to 500 characters); which AI model produced the draft; the app version; the app's language setting and the language of the draft; and — only if you leave Include the lines the AI wrote ticked — the AI's item lines: each line's description, the service name it was matched to, the quantity and the unit. The report screen lists what will and will not be sent, before you send it, and the AI's lines are the ones on the draft as the AI first wrote them — not your edits. A report never includes the recording, the transcript, the customer name or address the AI picked out, your notes, or any price. It is stored on our server linked to your account id, kept for at most 180 days and then deleted automatically, and deleted straight away if you delete your account. We read reports to fix wrong drafts and to catch offensive output. You can send up to 20 reports a day.
What we store on our server
Our server's database (Cloudflare D1) holds, for your account:
- Your account row: the account id (uid), your plan, when the account was first seen, and a trial end date. The trial date belongs to a paid plan we may offer in a later update; in this version there is no paid plan and it grants nothing.
- Monthly usage counters: for each month, how many voice quotes you used, how many seconds of audio were processed, and an estimate of what the AI cost us. They apply your monthly allowance and keep our total AI spending under a fixed cap.
- AI draft problem reports, only if you send any (described above).
That is the complete list. There is no table of customers, quotes, transcripts or audio. We do not store your email address on our server — it stays with Firebase Authentication.
Our server also keeps short-lived request counters under your account id, to stop any one account flooding the service; they expire on their own within two days. While you are confirming your email address, it also keeps the fingerprint of your code, described above, for at most ten minutes.
Each request writes a short technical log line: the account id, how long the audio was, language codes, which model ran, how long it took, how many items came back, and whether it succeeded. Logs never contain audio, transcripts or customer details. Cloudflare keeps these log lines, with basic details of each request (time, address requested, response status), for a few days and then deletes them automatically. Like any network service, Cloudflare sees your phone's IP address in order to deliver each request; we do not store it in our database or use it for anything.
Android backup: your copy, in your own Google account
The app lets Android back up each account's database — customers, price list, quotes, invoices, payments and jobs — with Android's own backup, to your Google account. That backup is run by Google for you, under your Google account. We never receive it and cannot read it.
- On Android 9 and later, the backup is end-to-end encrypted with your phone's screen lock, and the app allows it only when a screen lock is set. On Android 7 and 8, Android cannot apply that encryption: if backup is switched on there, the backup is stored in your Google account without end-to-end encryption.
- When you set up a new phone with the same Google account, Android can restore it. Sign in to QuoteAloud with the same account as before and your data is there.
- Not included in the cloud backup: job photos, signatures, your logo, your sign-in session, the reminder notifications scheduled on the phone, and recordings. After a restore, jobs appear without their photos and signatures, you sign in again, and reminders need setting again.
- A direct phone-to-phone transfer (by cable or Wi-Fi, when you set up a new phone) copies the photos, signatures and logo as well. It goes straight from your old phone to your new one.
- You control the backup: you can switch it off, or delete it, in your phone's backup settings or in Google Drive.
Who else handles data for us
These companies process data on our behalf, only to provide the parts of the app described above:
- Google — Firebase Authentication: your sign-in account.
- Google — Firebase Crashlytics: crash reports, from release builds only.
- Resend: delivers the email carrying your 6-digit confirmation code, if you sign up with an email address and a password. It receives your email address and the code, and nothing else.
- Cloudflare — Workers, Workers AI, D1, KV and AI Gateway: our server, the speech-to-text and item-reading models, our database, a small key-value store (the spending switch, cached sign-in keys and the short-lived request counters), and the gateway that routes AI requests and enforces a spending limit.
Google Play Billing and RevenueCat would handle payments only if and when a paid plan is offered. Neither is active in this version: the app takes no payments and does not start RevenueCat.
Transfers outside your country
Google, Cloudflare and Resend are based in the United States and may process data there and in other countries. Their data processing terms include the European Commission's Standard Contractual Clauses for data leaving the EU and EEA.
Why we are allowed to process it (GDPR)
- To provide the service you signed up for (Article 6(1)(b), performance of a contract): your account, drafting quotes from your voice notes and typed text, the monthly usage counters that apply your allowance, and the AI draft reports you choose to send.
- Our legitimate interests (Article 6(1)(f)): crash reports, to find and fix what breaks, and the usage counters' second job, keeping our AI spending under its cap. Neither involves your business data, and crash reports are not linked to your account.
For users in Morocco, the same processing rests on the equivalent grounds in Law 09-08: it is necessary to perform the service you asked for, or for our legitimate interests.
How long we keep it
| Data | Where | How long |
|---|---|---|
| Account row (uid, plan, dates) | Our server | Until you delete your account |
| Monthly usage counters | Our server | Until you delete your account |
| AI draft problem reports | Our server | At most 180 days, then deleted automatically; at once if you delete your account |
| Short-lived request counters | Our server | Expire on their own within two days |
| Email confirmation code (a fingerprint, not the code) | Our server | At most 10 minutes; deleted once used |
| The confirmation email (your address and the code) | Resend | For Resend's delivery-log retention period |
| Request logs | Cloudflare | A few days, then deleted automatically |
| Sign-in account (email, name, uid) | Firebase Authentication | Until you delete your account |
| Crash reports | Firebase Crashlytics | For Google's Crashlytics retention period, then deleted by Google |
| Audio and transcripts | Our server and Cloudflare | Not kept at all: memory only, for the length of the request |
| Your business data | Your phone, and your own Android backup | Until you delete it, delete your account, or uninstall — and your backup until you delete it |
Your rights
Depending on where you live — under the GDPR in the EU and EEA, and under Law 09-08 in Morocco — you have the right to access your data, to have it corrected, to have it erased, to restrict how it is used, to object to processing based on legitimate interests, and to receive it in a portable format (portability).
Most of your data is already under your control on your phone: you can see, correct, export as PDF and delete it in the app. For what we hold — the account row, the usage counters and any AI draft reports — write to support@quotealoud.com from the email address you sign in with. We will answer within one month. Deleting your account in the app erases everything we hold at once.
If you think we have handled your data wrongly, please tell us first. You can also complain to a data protection authority: in France, the CNIL (cnil.fr); elsewhere in the EU, your own country's authority; in Morocco, the CNDP (cndp.ma), under Law 09-08.
Your customers' data is yours to look after
The customer details you record in the app — names, phone numbers, addresses, notes, photos of their property and their signatures — are your business's records, and you are the controller of that data. You are responsible for having a lawful reason to record it (usually, preparing and carrying out work the customer asked you for), for telling your customers, and for deleting it when you should.
It is stored on your phone. We never receive it, except for the seconds a voice note or typed text you send for drafting is being processed — we process that only to produce your draft, on your behalf, and keep none of it.
Permissions the app asks for
- Microphone — to record the voice note. Recording only happens while the record screen is open. The app explains why before Android asks, and typing a quote works without it.
- Notifications — asked for only when you schedule a payment reminder. Refusing keeps the app working; the reminder just will not appear.
- Internet — to reach our server, Firebase and Crashlytics. Android does not ask you about this one.
- Run at startup — to set your scheduled reminders again after the phone restarts. Android does not ask you about this one either.
The app asks for no camera, photo or storage permission. Job photos are taken with your phone's own camera app or chosen with Android's photo picker, and are kept inside the app on your phone.
The Play Store also lists a few permissions that the app's libraries add and that Android never asks you about: vibration, for reminder notifications; network state, to tell "no connection" from "the server did not answer"; and Google Play's billing permission, which comes with the payment library and is not used in this version.
Deleting your account and your data
In the app: Settings → Delete account. Settings is behind the round account button at the top of every tab. The app asks you to confirm, tells you what goes, and then:
- deletes your account row, every usage counter and every AI draft report from our server;
- erases this account's data on this phone — customers, quotes, invoices, jobs, price list — together with its photos, signatures and logo;
- deletes your Firebase sign-in account.
None of it can be undone. Export any PDFs you still need first.
What account deletion does not reach:
- Your Android backup, which is in your own Google account and under your control. Delete it in your phone's backup settings or in Google Drive if you want it gone too.
- Another phone where you signed in with the same account: its copy stays until you delete the account there or uninstall the app.
- Crash reports, which are not linked to your account and expire on Google's schedule.
If you cannot reach the app — you have lost the phone, or already uninstalled — write to support@quotealoud.com from the email address you signed in with, and we will delete the server data and the sign-in account within 30 days. The same steps are on the account deletion page on our website, https://quotealoud.com/legal/delete-account.
Uninstalling is not the same as deleting. It removes the data on the phone, and leaves your account and its server data until you delete the account or ask us to.
Your choices
- Enter items manually instead of speaking or using "Fill from text". No audio, no text, no AI request at all.
- Refuse the microphone. The app still works; recording is simply unavailable.
- Leave out the line items when you report an AI draft, or do not send a report at all.
- Switch off Android backup for the app in your phone's settings.
- Delete everything, from Settings → Delete account.
Children
QuoteAloud is a tool for running a trade business. It is not directed at anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, write to us and we will delete it.
Changes
This version takes effect on 27 September 2026. If this policy changes in a way that affects what leaves your phone, the change ships with an app update, the date at the top moves, and the change is listed here. If a paid plan is offered in a later update, this policy will be updated before it goes live.
- 27 September 2026 — Named the data controller. Added the 6-digit code that confirms an email/password account's address, and Resend, which delivers it. Added Android backup to your own Google account, the AI draft problem report, the notice shown before the first recording, AI Gateway logging switched off in code, why we may process data, how long we keep it, transfers, your rights and how to complain. Removed paid-plan wording: this version has no paid plan. Removed a photos and camera permission the app does not ask for.
- 21 September 2026 — Previous version.
Contact
support@quotealoud.com