Last updated: 20 August 2026 Rigbill is an invoicing app for tradespeople. This policy explains what it collects, why, where it lives, and how to get rid of it. It is written to match docs/privacy-manifest.md, which is the machine-checked source of truth for our App Store privacy label and Play Data Safety form. A build gate (npm run verify:privacy) derives what the app actually collects from the code and fails if this and the code ever disagree — in either direction, so we cannot quietly collect more than we say, nor claim to collect more than we do. If something here is wrong, that is a bug, and it is one we test for.
Your name and email address, from whichever sign-in method you use, plus a user ID we generate. If you sign in with Apple or Google, we also receive the profile image URL they supply.
Business name, trade, licence number, phone, address, your logo, your payment instructions and default terms. This exists to be printed on your invoices — that is the whole point of it.
Names, email addresses, phone numbers, postal addresses, and any notes you write about the people you invoice. This is the part we take most seriously, because your customers never installed this app and never agreed to anything. We treat their details as yours to control: they are never used to market anything to anyone, never sold, and never shared beyond delivering the document you asked us to deliver. When you delete your account, they go with it.
If — and only if — you tap Import from Contacts and grant permission, Rigbill reads your device address book so you can pick people to add as clients. Two things worth being precise about:
You can refuse, and the rest of the app works normally. You can revoke it later in iOS Settings → Privacy & Security → Contacts. This is the only permission Rigbill asks for in this release.
Invoices, estimates, line items, prices, your price book, payments, and expenses — including photographs of receipts. This is the content of the product.
When voice-to-invoice is available, audio you record is uploaded, transcribed, and the recording is then deleted from our storage. What we keep is the transcript, the structured result, and any corrections you make — those are what your invoice is built from, and what makes the feature better. This is a deliberate design decision. It is enforced in code and covered by tests, not just promised here.
A device identifier used to keep your session and to rate-limit abuse. Crash reporting and product analytics are not currently active in Rigbill. If that changes, this policy and our store disclosures change first.
No location data of any kind. No health or fitness data. No browsing history. No contacts beyond the ones you explicitly import. No advertising identifiers.
Everything above is collected to run the app: to create and send your documents, to get you paid, to keep your account secure, and to keep your data available. We do not profile you, and we do not use your data — or your customers' — for advertising.
That is the complete list. We do not share your data with anyone else, and we do not sell it to anyone, ever.
As long as your account exists. When you delete your account, we delete your data — every row and every file, not a flag marking it hidden. Voice recordings are the exception in the other direction: they are deleted as soon as they are transcribed, long before you ask. Backups may persist for a short period as part of ordinary infrastructure operation.
In the app: Settings → Delete account. You do not need to email us, wait for a reply, or explain yourself. You will be offered a copy of your data first. Deletion removes your sign-in account, every record belonging to it across every table, and every file you uploaded. It cannot be undone.
Depending on where you live, you may have the right to access, correct, export, or delete your data, and to object to certain processing. The delete and export paths above are built into the app so you can exercise the two that matter most without going through us at all. For anything else, contact us.
Rigbill is a tool for running a trade business and is not directed at children. We do not knowingly collect data from anyone under 13.
If this policy changes materially, we will update the date at the top and, where the change affects what we collect, update our App Store and Play disclosures at the same time — our build gate requires that they agree.
Questions about this policy, or about your data: support@rigbill.dev