Privacy Policy
Last updated: October 3, 2026
The Short Version
- ✅ Your data is yours — we never sell it, and we never share or use it for marketing or advertising
- ✅ We do NOT access your bank accounts, credit cards, or financial institutions
- ✅ We do NOT see or store your clients’ personal information beyond what you enter
- ✅ Your data is encrypted and isolated — no other customer account can see it
- ✅ You can export or delete all your data at any time
- ✅ GPS/location features require your explicit consent and can be disabled anytime
- ✅ We use AI to read your receipts — the AI providers we send them to do not train on them
1. What Data We Collect
Account information: Your email address and password (or authentication provider) when you create an account.
Receipt images and data: Photos of receipts you upload, and the data extracted from them (store names, items, prices, dates, payment methods).
Project and expense data: Project names, budgets, labor expenses, and other cost data you enter into the Service.
Invoice data: Client names, email addresses, and invoice details you create within the Service.
Usage data: We track which features you use and how often to improve the Service and enforce plan limits. This includes API call counts and approximate costs.
2. What We Do NOT Collect
We want to be explicitly clear about what we do NOT do:
- We do NOT access your bank accounts — we have no connection to your bank, credit card company, or any financial institution
- We do NOT store credit card numbers — all payment processing is handled by Stripe, a PCI-compliant payment processor. We never see your full card number
- We do NOT collect your Social Security number, tax ID, or government identification
- We do NOT access your phone contacts, camera roll, or other device data beyond what you explicitly share (e.g., taking a receipt photo). Location data is only accessed when you explicitly enable GPS features in Settings
- We do NOT track you across other websites or apps
- We do NOT collect your clients’ personal information beyond what you voluntarily enter into invoices (client name, email, address)
3. How We Use Your Data
Your data is used exclusively to provide and improve the Service:
- Receipt processing: Your receipt images are sent to Google Gemini for data extraction first. If Gemini isn’t available or can’t process the image, it’s sent to Anthropic Claude instead. When Gemini succeeds but can’t tell whether a payment proof is money in or money out, the same image is also sent to Claude for a second opinion. Receipt PDFs go straight to Anthropic Claude. The AI processes the image and returns structured data. Per our AI providers’ API policies, the receipt images we send them are not used to train AI models.
- Cost tracking: Your receipts, expenses, and project data are used to calculate your budgets, margins, and reports
- Service improvement: We use aggregate, anonymized usage statistics to improve the Service. We never use individual financial data for this purpose
4. We Never Sell Your Data
We do not sell, rent, or trade your personal data or financial information. We do not share it with any third party for marketing or advertising.
The service providers that help us run the Service are listed in Section 6.
5. Data Security
We take the security of your data seriously:
- Encryption at rest: All data stored in our database is encrypted
- Encryption in transit: All data transmitted between your device and our servers uses TLS/HTTPS encryption
- Row-Level Security (RLS): Your data is isolated at the database level — our system enforces that each user can only access their own data. No other customer account can see your receipts, projects, or financial information
- Authentication: All API endpoints require authentication. Unauthorized requests are rejected
- Rate limiting: API endpoints are rate-limited to prevent abuse
6. Third-Party Services
We use the following third-party services (sub-processors) to operate and maintain the Service. Each is bound by its own privacy policy. The notes below describe the main ways we use each service.
- Supabase: Database, authentication, and encrypted file storage. Your account, receipts, and uploaded images are stored here.
- Anthropic (Claude AI): Our AI helper for everything except the first read of a receipt photo. We send Claude: what you type in the in-app AI chat and the help chat, and text you dictate by voice; bids and quotes you upload; plans and blueprints; contracts, insurance papers and other job documents; cost sheets; a job’s numbers, receipts and labor lines (including worker names) when you ask for a job briefing or a job completion report; a homeowner’s intake form, including their name and address, when you ask the AI to read a lead; your yearly totals and job names for the summary in the tax package; messages sent to the chat assistant on our website; receipt PDFs; and receipt photos when Gemini is unavailable, fails, or can’t tell which way a payment went. Per Anthropic’s API policy, data sent via the API is not used to train models.
- Google (Gemini API): Our primary receipt-image data extractor. Receipt images are sent to Gemini first. If Gemini isn’t available or fails, the image is sent to Claude instead; if Gemini succeeds but can’t tell whether a payment proof is money in or money out, the same image is also sent to Claude for a second opinion. Per Google’s API policy, data sent via the paid API is not used to train models.
- OpenAI (Codex): A coding assistant we use for software development and debugging. To help us find and fix bugs, it has read-only access to our production database and can read the records stored there, including account, project, crew time and pay, location, and client information. It cannot change or delete data through this connection.
- Vercel: Application hosting and edge delivery. Standard server logs (IP address, request path, user agent) are retained for security and abuse-prevention purposes. Vercel also collects page views and web-vitals performance data from your browser through its Speed Insights and Analytics tools, so we can see which pages are slow or broken.
- Stripe: Payment processing for paid subscriptions. Stripe collects your billing address, payment card details, and tax information. We never see your full card number. Stripe is PCI-DSS Level 1 certified.
- RevenueCat: Subscription management for in-app purchases on iPhone, iPad and Android. RevenueCat receives your account ID and your purchase and subscription events (which plan, when it started, renewed, or lapsed) so we can tell which features your account has. RevenueCat does not receive your email address, your name, your receipts, or any job or financial data.
- Apple (App Store purchases): In-app purchase verification. When you subscribe through the App Store, we send Apple the transaction identifier for that purchase so Apple can confirm it is genuine and still active. Apple does not receive your receipts, job data, or crew information through this.
- Sentry: Error monitoring and crash reporting. Collects stack traces, device/browser metadata, and (when an authenticated request errors) your user ID, so we can fix bugs. We do not send receipt content, project data, or financial figures to Sentry.
- PostHog: Product analytics. Records usage events (page views, feature usage, subscription tier, and aggregate invoice totals) tied to your user ID so we can see which features to improve. Receipt image content and individual receipt line items are not sent to PostHog.
- Resend: Transactional email delivery (welcome emails, password resets, billing receipts, invoice notifications). Resend processes the recipient email address and message content.
- Twilio: SMS delivery. Twilio is our messaging carrier and transmits the mobile phone numbers and message content needed to deliver transactional texts. That message content can include a worker’s pay total and your business name on a pay-stub text, a customer’s name and email address on an owner alert, and a jobsite address on a daily plan text. Twilio does not receive receipt images or uploaded documents, and may not use these numbers for any other purpose.
- Apple (Push Notifications): Push notification delivery to iPhone and iPad. When you have push notifications enabled, we send Apple the notification’s title and body text — which can include a worker’s name and job details — plus your device’s push token, so Apple can deliver the alert to your device.
- Google (Firebase Cloud Messaging): Push notification delivery to Android devices, via Firebase Cloud Messaging. When you have push notifications enabled, we send Google the notification’s title and body text — which can include a worker’s name and job details — plus your device’s push token, so Google can deliver the alert to your device.
- Browser push services: Push notification delivery to a desktop or mobile web browser. When you enable browser notifications, the notification is encrypted on our server before it is sent, so the push service your browser uses (Apple, Google, Mozilla or Microsoft, depending on whether you are on Safari, Chrome, Firefox or Edge) relays it without being able to read it. That service does see your browser’s push endpoint address and the timing of the message.
- Cloudflare (Turnstile): Bot and abuse protection on sign-in and on our public forms. Cloudflare’s check runs in your browser and receives your IP address and browser signals to tell people from bots. We do not send it your account, project, or financial data.
- OpenStreetMap (Overpass API and Nominatim): These public OpenStreetMap services are used three ways: (1) Store detection (Overpass API) — when you have enabled GPS features, the coordinates of a stop are sent to it, with a search radius, to find a nearby supply store. (2) Address-to-map lookup (Nominatim) — when you or an AI-extracted document sets a jobsite or customer address, that address text is sent to it to turn into map coordinates. (3) Bid-builder reverse lookup (Nominatim) — when you tap to use your current location in the bid builder, your device’s coordinates are sent to it to turn into an address. Overpass and Nominatim are separate OpenStreetMap services with their own policies. None of these requests carry your name, email, or account ID. When the lookup runs from your device, the service also sees your IP address.
- Google (Places API): Backup for store detection. If the map service above has no answer, our server sends the same coordinates and search radius to Google to find a nearby store. The request carries no name, email, or account ID.
- Apple and browser speech services (voice entry): Speech-to-text for the voice buttons. In the iPhone app, Apple’s speech service does this — on your phone when it can, on Apple’s servers when it cannot. On the web, your browser’s own speech service does it (for example Google in Chrome, Apple in Safari). We receive only the text, never the audio.
- Apple (Sign in with Apple): If you sign in using Apple, Apple relays a verified email (or a private relay address) and a unique identifier to us. Apple’s own privacy policy governs that relay.
- Google (Sign in with Google): If you sign in using Google, Google provides your verified email and basic profile to us. Google’s own privacy policy governs that exchange.
A current list of sub-processors is maintained on this page. We will update it before adding new sub-processors that materially affect how your data is processed.
7. Location Data
When you enable GPS features, we collect your device’s location to detect store visits and jobsite proximity. Location data is stored locally on your device and on our servers only when you explicitly enable tracking. You can disable this at any time in Settings > Privacy & Data.
Specifically, location data is used for:
- Store visit detection: We identify when you visit a hardware store, supply shop, or other relevant retailer so we can remind you to log receipts
- Jobsite proximity: If you have projects with GPS coordinates, we detect when you arrive at or leave a jobsite to automate clock-in/out
- Mileage tracking: Location data may be used to calculate distances for mileage deduction records
Location data is collected only while the app is active or running in the background with your explicit permission. We do not sell location data or share it with advertisers. You can turn location tracking off at any time in Settings > Privacy & Data, which stops any further collection. Location we have already recorded is removed automatically on a 90-day schedule — see Section 9.
8. Employee Location Tracking
If you use the team management feature, GPS tracking of team members requires their informed consent. Employers are responsible for ensuring all team members are aware of and consent to location monitoring during work hours.
When employee location tracking is enabled:
- Team members’ GPS coordinates are collected only to detect arrival at and departure from designated jobsites
- Location data is used solely for automatic clock-in/out functionality
- Employers can see when team members clocked in/out and at which jobsite, but do not have access to continuous location tracking or location history between jobsites
- Team members receive visible on-screen indicators when GPS tracking is active
- If your phone has a setting that blocks automatic clock-in or clock-out, your employer can see which setting (not your location).
This feature complies with applicable state and federal employment laws. If you are subject to specific state biometric or location privacy laws (such as the Illinois BIPA, Texas CUBI, or California CCPA), you must ensure your own compliance with notice and consent requirements for your employees.
9. Data Retention & Deletion
We retain your data for as long as your account is active. If you cancel your subscription, your data remains accessible (read-only on the free plan). If you request account deletion, all data is permanently removed within 30 days.
Regarding specific data types:
- Receipt images: Stored in encrypted cloud storage (Supabase Storage). Deleted when you delete the receipt or your account
- Location history: Automatically removed after 90 days, whether or not you ask. Raw background-location events are deleted outright. On the records that back your pay — clock-in/out entries, jobsite visits and supply-store visits — the coordinates are erased while the times, hours and pay status are kept, because that is your wage record and you may need it to answer a pay dispute. Anything still held is deleted with your account
- AI processing data: Receipt images are sent to Google Gemini for real-time data extraction first. If Gemini isn’t available or fails, the image is sent to Anthropic Claude instead, and if Gemini succeeds but can’t tell a payment proof’s direction, the image is also sent to Claude for a second opinion. Per our AI providers’ API policies, this data is not used to train AI models and is retained by the provider only briefly, in line with its standard data-retention policy
You can request deletion of all your data at any time by visiting our account deletion page or by emailing chris@jobcostpro.online.
10. Your Rights
You have the right to:
- Access all data we store about you — all your data is visible to you within the app at all times
- Export your data at any time using the built-in export features (CSV, spreadsheets, ZIP)
- Request deletion of your data — you can archive and permanently delete individual receipts, expenses, and projects. To delete your entire account and all associated data, use the Delete Account page at jobcostpro.online/delete-account
- Opt out of non-essential data collection — turn off location tracking in Settings > Privacy & Data. For anything else, email chris@jobcostpro.online
- Disable GPS tracking at any time — go to Settings > Privacy & Data to turn off all location features immediately
- Withdraw your consent — turn off location tracking at any time in Settings > Privacy & Data. To withdraw consent for anything else, email chris@jobcostpro.online or delete your account in Settings.
- Correct your data — you can edit project names, expense details, and other information
11. Cookies
We use essential cookies only — for authentication and session management. We do not use tracking cookies, advertising cookies, or analytics cookies from third parties.
12. Children’s Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect data from minors.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email. The “Last updated” date at the top reflects the most recent revision.
SMS / Text Messaging
When you provide a phone number for yourself, a worker (when you invite a teammate to your jobsite), or a client (when you set up a project), Job Cost Pro may send transactional SMS messages to that number through our messaging carrier (Twilio).
We send SMS for the following purposes only — never for marketing or promotion:
- Worker invites — a one-time message containing a sign-in link when you invite a worker to a jobsite.
- Payment reminders to clients — a text alert when an invoice you have sent becomes overdue, sent only if you have opted into client SMS in Settings → Notifications.
- Account and billing alerts to you — AI-spend threshold alerts, login codes, and other security notices to your account phone number.
SMS data we collect: the mobile phone numbers entered for you, your workers, or your clients, and an opt-in consent record for each number — the exact disclosure text shown at capture, who provided or attested the consent, and when. We retain these consent records as proof of opt-in for as long as we may send SMS to that number and as required by law.
Frequency: Message frequency varies. Transactional messages only — typically fewer than five (5) messages per month per recipient. There are no scheduled or recurring promotional sends.
Opt-in / consent: when you enter a phone number for a worker or a client, you confirm that you have that person’s consent to receive these messages. We do not auto-collect phone numbers from contacts or third-party sources.
Opt-out: every message includes "Reply STOP to opt out." Replying STOP unsubscribes that number permanently from all Job Cost Pro SMS. Replying HELP returns our support contact (chris@jobcostpro.online).
Carrier rates: Message and data rates may apply, charged by your carrier — we do not charge for SMS itself.
Privacy of phone numbers: No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties. Mobile phone numbers and SMS opt-in data will never be sold, rented, or transferred to third parties or lead generators for any purpose. Phone numbers are used only to deliver the message types described above and are stored encrypted at rest in our database.
How consent is captured (Call to Action)
Below is the exact wording shown to an account holder inside Job Cost Pro at every point we collect a phone number. The account holder must check the consent box before the form will save the number — it is impossible to enter a phone number without the explicit attestation. Reviewers and customers can verify this flow in real time by signing up for a free account at jobcostpro.online and visiting Team → Add member, or Projects → New project.
Worker invite (Team → Add member, “Phone” field):
By entering this number, you confirm the worker has agreed to receive a one-time SMS sign-in link from Job Cost Pro. Message frequency: one-time on invite. Msg & data rates may apply. Reply STOP to opt out, HELP for help. SMS Policy and Terms. ☐ (unmarked checkbox by default) I have the worker’s permission to send this SMS.
Client phone (Projects → New project, “Phone” field, and Setup checklist):
By entering this number, you confirm the client has agreed to receive transactional SMS from Job Cost Pro (overdue-invoice reminders, sent only if you toggle them on in Settings → Notifications). Message frequency: typically fewer than 5 messages per month. Msg & data rates may apply. Reply STOP to opt out, HELP for help. SMS Policy and Terms. ☐ (unmarked checkbox by default) I have the client’s permission to send SMS reminders to this number.
Client SMS reminders enable/disable (Settings → Notifications):
“Send SMS reminders to clients” toggle — off by default. Description: “Adds a text version to each overdue-invoice reminder, for clients with a phone number and text consent on file. Nothing goes to a client until you send it from Approvals Inbox → Messages to clients.”
14. Contact & Data Controller
Salvation Home Remodeling LLC, doing business as Job Cost Pro, is the data controller for any personal information you provide. For privacy questions, data access, correction, or deletion requests, contact us at:
To delete your account and all associated data without contacting us first, visit our account deletion page. We respond to verified requests within 30 days.