← Back to quotora.app

Quotora

Quote it. Send it. Get paid.

Last updated: July 25, 2026

Effective date: July 12, 2026

Your privacy matters to us. This policy explains exactly what data Quotora collects, why we collect it, where it's stored, who can access it, and the control and legal rights you have over it. We've written it in plain English — no hidden surprises. This English-language version is the governing version; translations are provided for convenience only, and if there is any conflict the English version controls.

Contents

  1. Who We Are & Our Role in Your Data
  2. What We Collect
  3. Why We Collect It & Our Legal Bases
  4. Where Your Data Lives
  5. Third-Party Services & Sub-Processors
  6. International Data Transfers
  7. Data Security
  8. Your Rights & Choices
  9. Your Rights in Europe, the UK & Switzerland (GDPR)
  10. Your Rights in Brazil (LGPD)
  11. Your California Privacy Rights (CCPA/CPRA)
  12. Data Retention
  13. Children's Privacy
  14. Changes to This Policy
  15. Contact Us

1. Who We Are & Our Role in Your Data

Quotora ("Quotora," "we," "us," or "our") is a mobile invoicing application for freelancers, contractors, tradespeople, and small service businesses. Quotora is operated from Washington State, United States. For all privacy questions, or to exercise any of the rights described in this policy, contact us at support@quotora.app.

There are two different roles to understand, because they determine who is responsible for what:

2. What We Collect

Information you provide directly

When you use Quotora, you enter information to run your business. This includes your account details (your email address and name, provided through email/password sign-up, Sign in with Google, or Sign in with Apple) and your business profile (business name, owner name, business type, address, country, phone number, business email, website, tax identification number, business licence number, and business logo).

It also includes your customers' information that you choose to enter: their names, company names, email addresses, phone numbers, physical addresses, tax-exempt status, and any notes you write about them. You enter and control this information.

To save typing, you can also import a customer's details from your device's contacts. When you use Add from Contacts, Quotora opens your device's built-in contact picker, and the app reads only the single contact you pick — that contact's details simply pre-fill the client form for you to review, edit, and save. Quotora never reads, uploads, or stores your address book. On Android, the Contacts permission is used solely to read the one contact you picked; on iOS, the system picker means no contacts permission is needed at all. Once saved, imported details are handled exactly like any other customer information you enter, as described throughout this policy.

Your invoices, estimates, and receipts contain line-item descriptions, quantities, rates, the tax rate you enter and the tax label on the document, discount details, currency, payment history, notes, terms, and dates. Photos you attach to documents are stored as part of that document.

Calendar events include titles, descriptions, dates, times, locations, reminders, and any linked customers or documents.

Earnings data includes payment amounts, dates, sources, recurring-income entries, and the estimated tax rate used for set-aside figures, which you can adjust.

Payment instructions you add (such as a Zelle ID, Venmo handle, Cash App tag, PayPal address, Pix key, IBAN, or custom text) are stored so they can appear on your invoice PDFs. These are simply text and links that you enter — Quotora does not connect to, integrate with, or move money through any of these services (see Section 5).

Information collected automatically

When you create an account, Firebase Authentication (a Google service) records your email address and a unique user ID. We store your subscription status (Free, trial, or Pro) and trial/renewal dates locally on your device and in the cloud. To confirm that a subscription is genuine and still active, we also store the identifier the App Store or Google Play issues for your purchase — a transaction ID or purchase token — together with a record linking that purchase to your account, so that renewal and cancellation notices from the store are applied to the right account. That link is refreshed while the subscription is active, expires about two years after its last update, and is removed when you delete your account.

Crash and diagnostic reporting

Quotora uses Firebase Crashlytics, a Google service, to report app crashes and errors so we can find and fix problems. When the app crashes or hits an unexpected error, Crashlytics records a crash report (a technical stack trace), your device model, operating-system version, app version, and a Crashlytics installation identifier — a random ID that identifies the app installation, not you personally. This data is used only to diagnose and fix stability problems. It is never used for advertising, marketing, or to track you across other apps or websites.

Apart from this crash and diagnostic data, Quotora does not use third-party analytics services, advertising trackers, or cross-app tracking of any kind. The only other information we hold is what you enter into the app together with your account and subscription details. Any minimal connection metadata logged by Firebase at Google's infrastructure level is used solely for security and service operation.

Push notifications

All push notifications in Quotora (event reminders, invoice reminders) are scheduled locally on your device using your device's built-in notification system. No notification data is sent to our servers or any third party. Notifications are entirely between your device and you.

3. Why We Collect It & Our Legal Bases

We only process personal data where we have a valid legal basis to do so. For users in the European Economic Area, the United Kingdom, Switzerland, and Brazil, the bases we rely on are set out below. In plain terms: we use your data to make the app work for you, to keep it stable and secure, to handle your subscription, and to meet our legal obligations — nothing else.

What we doWhyLegal basis (GDPR / LGPD)
Create your account and provide the core app — invoices, estimates, receipts, clients, calendar, earnings, and cloud sync across your devicesTo deliver the service you signed up forPerformance of a contract (GDPR Art. 6(1)(b); LGPD Art. 7, II/V)
Manage your subscription, trial, and billing statusTo provide Pro features and honor your planPerformance of a contract (GDPR Art. 6(1)(b))
Crash and diagnostic reporting (Crashlytics)To keep the app stable and secureLegitimate interests (GDPR Art. 6(1)(f)); legitimate interests / regular exercise of rights (LGPD)
Security, fraud prevention, and protecting our service and usersTo keep accounts and data safeLegitimate interests (GDPR Art. 6(1)(f))
Responding to your support requests and legal-rights requestsTo help you and to comply with the lawLegitimate interests and legal obligation (GDPR Art. 6(1)(f), (c))
Keeping limited records where required (e.g., tax, accounting, or to establish or defend legal claims)To meet legal requirementsLegal obligation / legitimate interests (GDPR Art. 6(1)(c), (f))

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. You can object to processing based on legitimate interests at any time (see Sections 8–9). We do not use your personal data to make decisions about you by solely automated means, and we do not profile you.

4. Where Your Data Lives

Quotora is an offline-first app. All your data is stored locally on your device first, in a local database (Hive), which is encrypted at rest using AES-256 with a key held in the iOS Keychain or Android Keystore. Files the app keeps outside that database — such as attached photos, your business logo, and the app's offline cloud cache — rely on your device's standard system protections instead. After your first sign-in, the app works entirely without internet — you can create invoices, manage clients, and run your business with no connection at all.

Cloud sync

When internet is available, your data syncs automatically to Firebase Cloud Firestore (Google's cloud database). This includes your invoices, estimates, receipts, clients, calendar events, earnings, settings, templates, and preferences, and it lets your data appear across your own devices. Your business logo and (for Pro/trial users) your document photos sync to Firebase Cloud Storage.

Photos

For Free users, photo attachments on invoices and estimates are stored locally on your device only — they are never uploaded to the cloud. For Pro and trial users, photos are resized to a maximum of 1920 pixels on the longest side and uploaded to Firebase Cloud Storage. If you downgrade from Pro to Free, your existing cloud photos remain accessible but new photos will not be uploaded.

Manual backups

When you use the Import & Export feature to create a backup (JSON) or export customers (CSV), the file is generated locally on your device. It is not uploaded to our servers. Where you save or share that file is up to you, and once it leaves the app it is outside our control.

All cloud data is stored on Google Cloud infrastructure through Firebase, which provides encryption at rest, encryption in transit, and per-user isolation.

5. Third-Party Services & Sub-Processors

We keep the number of third parties to a minimum, and we do not sell or rent your data to anyone. The service providers below process data on our behalf as sub-processors, under contractual data-protection terms:

Google Firebase — Provides authentication (Firebase Authentication), cloud database (Cloud Firestore), cloud file storage (Cloud Storage), crash reporting (Crashlytics), subscription purchase verification (Cloud Functions), and device attestation (App Check). Google acts as our data processor under the Firebase Data Processing and Security Terms. Google's privacy policy applies to data handled on its infrastructure.

Sign in with Apple / Google Sign-In — If you choose these sign-in methods, Apple or Google authenticates you and shares a limited identifier and your email with us. Their respective privacy policies apply to that sign-in.

Apple App Store / Google Play Store — Handle subscription billing and payment processing for Pro subscriptions. Quotora never sees or stores your credit-card or payment-method details — all subscription payment processing is handled entirely by Apple or Google under their own terms and privacy policies. What we do receive from the store is the purchase identifier described in section 2, which is how we confirm your subscription is active.

Your device's own email, SMS, and messaging apps — When you send an invoice, estimate, or receipt, Quotora opens your device's native email client, SMS app, or share sheet (which may include apps like WhatsApp). The document is sent by you, from your account, using your device — Quotora runs no mail server and does not send messages on your behalf from our servers. Once you hand a document to another app to send, that app's own terms and privacy policy govern it.

Your device's maps app (Apple Maps, Google Maps, or another you have installed) — When you tap a client's address in the app, Quotora hands that address to your device's maps app so it can show it. The address leaves the app only at that moment and only because you tapped it; from there that app's own terms and privacy policy govern it.

Payment brands shown on your invoices (PayPal, Zelle, Venmo, Cash App, Pix, bank/IBAN, etc.) — These appear on your invoices only as text and links that you add. Quotora is not integrated with them, does not exchange data with them, and does not process, hold, or move any money. Any payment happens directly between you and your client, outside the app, under those services' own terms.

What we do NOT use

Quotora does not use advertising networks, ad trackers, third-party analytics services, cross-app tracking, or data brokers. The only automated data collection is the Firebase Crashlytics crash and diagnostic reporting described above, used solely to fix bugs and stability problems. Your data is never sold, rented, licensed, or shared with third parties for marketing or advertising purposes. Ever.

6. International Data Transfers

Quotora is operated from the United States, and your data is stored and processed on Google Firebase infrastructure, which may be located in the United States and other countries where Google operates. If you use Quotora from the European Economic Area, the United Kingdom, Switzerland, Brazil, or elsewhere outside the United States, your personal data will be transferred to and processed in the United States.

Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards, including: (a) Google LLC's certification under the EU-US Data Privacy Framework (and the UK Extension and Swiss-US framework); and (b) the European Commission's Standard Contractual Clauses, incorporated into the Firebase Data Processing and Security Terms, as an additional safeguard. For transfers of personal data of individuals in Brazil, we rely on the Standard Contractual Clauses approved by the Brazilian data-protection authority (ANPD) or another mechanism permitted under the LGPD. You may request more information about these safeguards, or a copy of the relevant clauses, by contacting us at support@quotora.app.

7. Data Security

All data transmitted between your device and Firebase is encrypted in transit using HTTPS/TLS. Data stored in Firebase is encrypted at rest. Data in the app's local database (Hive) is encrypted at rest using AES-256, with the encryption key held in your device's secure hardware store (iOS Keychain or Android Keystore); files the app keeps outside that database — such as attached photos, your business logo, and the app's offline cloud cache — are protected by your device's standard system protections instead. Firebase security rules enforce per-user isolation: each user can only access their own data — no user can read, write, or modify another user's invoices, clients, or business information.

Data stored locally on your device is also protected by your device's own security (passcode, Face ID, Touch ID, or biometric lock). We recommend keeping your device locked and your account credentials secure.

If you sign in on a new device, your cloud-synced data will be downloaded to that device. Anyone with access to your account credentials can access your business data, so protect your password and enable two-factor authentication on your email account. No method of transmission or storage is 100% secure, and while we work hard to protect your data, we cannot guarantee absolute security.

If we ever become aware of a personal-data breach that affects you, we will notify you and the relevant authorities where required by law and within the timeframes the law requires.

8. Your Rights & Choices

You have direct, practical control over your data inside the app, regardless of where you live:

A note about subscriptions: deleting your Quotora account does not automatically cancel an active App Store or Google Play subscription. To stop billing, cancel the subscription in your Apple ID or Google Play account settings (see the Terms of Service).

9. Your Rights in Europe, the UK & Switzerland (GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the EU General Data Protection Regulation and the UK GDPR in relation to the personal data for which we are the controller:

You can exercise most of these rights directly in the app (Section 8) or by emailing support@quotora.app. We will respond within one month, as required by the GDPR.

Right to complain: you also have the right to lodge a complaint with your local supervisory authority. In the EEA you can find your authority at edpb.europa.eu/about-edpb/about-edpb/members_en; in the UK, the Information Commissioner's Office at ico.org.uk. We'd appreciate the chance to address your concern first, so please consider contacting us before you do.

Controller and representative: Quotora is the controller of your account data. If you have questions about our EU/UK representative or data-protection contact, email support@quotora.app and we will provide the current details.

10. Your Rights in Brazil (LGPD)

If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD) gives you the right to: confirm that we process your data; access your data; correct incomplete, inaccurate, or outdated data; anonymize, block, or delete unnecessary or excessive data or data processed unlawfully; port your data to another provider on request; delete personal data processed with your consent; obtain information about entities with whom we have shared your data; obtain information about the possibility of refusing consent and the consequences; and withdraw your consent. You can exercise these rights in the app or by emailing support@quotora.app, and you may also contact Brazil's National Data Protection Authority (ANPD). A Portuguese-language version of this policy is available to Brazilian users; the English version governs in the event of any conflict.

11. Your California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA):

Because we do not sell or share personal information, we do not offer a "Do Not Sell or Share My Personal Information" link, but we honor recognized opt-out preference signals (such as Global Privacy Control) where applicable. To exercise your rights, email support@quotora.app or use the Delete Account feature in the app. We will verify your request before acting on it.

12. Data Retention

We keep personal data only as long as we need it for the purposes described in this policy, or as long as the law requires.

13. Children's Privacy

Quotora is a business tool intended solely for users aged 18 and older, as stated in our Terms of Service. It is not directed to children. We do not knowingly collect personal information from anyone under 18 — and, in any event, not from children under 13 (as defined by the U.S. Children's Online Privacy Protection Act) or under the applicable digital-consent age in the user's country under the GDPR. If you believe someone under 18 has provided us with personal information, please contact support@quotora.app and we will delete it.

14. Changes to This Policy

We may update this privacy policy from time to time. If we make material changes, we will ask you to review and accept the updated policy in the app before you continue using it, and we will update the "Last updated" date above. Non-material changes take effect when posted, and continued use of the app constitutes your acceptance of them. If you do not agree with a change, you can delete your account — in the app, or at quotora.app/delete-account. Previous versions are available on request by emailing support@quotora.app.

15. Contact Us

If you have any questions about this privacy policy, your data, or your rights, or to exercise any right described above, contact us at:

support@quotora.app

Quotora is operated from Washington State, United States.