Steadybill

Privacy Policy

Last updated: 28 August 2026

Steadybill is an invoicing app for one-person trades businesses. We do not sell your data, we do not show ads, and we do not track you across other apps or websites. This page explains exactly what we hold, why, and how to get it deleted.

1. Who we are

Steadybill is operated by Daigo Fujimoto, a sole trader based in Japan ("we", "us"). We are the data controller for the information described in section 3.

Contact for any privacy question, including requests to access or delete your data: support@steadybill.microforgehq.com. If you use the app, Settings → Contact us reaches the same place and is quicker.

2. Two different kinds of information

This distinction matters, because it decides who is responsible for what.

  • Your information — your sign-in email, your business details, your subscription status. We decide how this is handled, so we are the controller for it.
  • The information you type about your customers — their names, addresses, phone numbers, emails, and the documents you send them. You decide what to put in there and who to send it to. You are the controller for that information; we only store and transmit it on your instructions, as your processor. Section 9 sets out the terms that apply to that role.

3. What we collect

What Why How long
Your email address To sign you in (we send a one-time code — there is no password) and to reach you about your account Until you delete your account
Your business details: business name, address, phone, tax number, invoice settings, and your logo To put them on the documents you create Until you delete your account
Your customers' details and your invoices, estimates, payments and refunds To create your documents and keep them in sync across your devices Until you delete them, or delete your account
Documents you send, and the link the recipient opens To deliver the document by email and let the recipient view and approve it Until you delete the document or your account
The name a recipient types when they approve an estimate, and the time they decided To record the approval on your document. If they decline, we record the decision and the time, but not a name Until you delete the document or your account
The minute a recipient first opened the link you sent So you can see whether your document has been looked at Until you delete the document or your account
A record of each document you send: when, which document, and how you sent it To apply the free plan limit and the fair use limits, and to show you what you have sent Until you delete your account
If a recipient uses "Report a problem" on a document, what they wrote So we can look into misuse of the sending feature Up to 12 months
Your subscription status, and the receipt data Apple gives us for it To know whether your plan is active. It contains no card details Until you delete your account
If you write to us from Settings → Contact us: what you wrote, your email address (so we can reply), and the app version To answer you, and to find the problem you are describing Up to 24 months
Anonymous usage events: which feature was used (for example “a document was sent”), together with your device model, system and app version, and language — under a random ID created on your phone To see which parts of the app are used and where people give up, so we can improve it They are anonymous and cannot be traced back to you

When you delete your account we also write one anonymous line recording that a deletion happened and how many rows it removed. It contains no name, email or document content, and cannot be traced back to you.

Photos you attach to a document are stored on your phone, not on our servers. The one exception is sending: when you email a document, the PDF — including any photos printed on it — passes through our sending service to reach your recipient. We do not keep a copy of it. If you delete the app or lose the phone, the photos themselves are gone with it.

We do not collect: your location, your contacts, your device identifiers for advertising, or crash reports. The app contains no advertising software. The usage events above never include what is in your documents — no customer names, no amounts, no text you typed.

We never receive your card details. Payment is handled entirely by Apple.

4. What allows us to hold it (UK and EU users)

Data protection law says we must have a specific reason — a "lawful basis" — for holding your information. Ours are:

  • To do what you signed up for (GDPR Article 6(1)(b)) — everything needed to run the app for you: signing you in, storing and syncing your documents, sending them, and applying your plan.
  • Because we have a genuine reason and it does not harm you (Article 6(1)(f), "legitimate interests") — for keeping the service secure and stopping the sending feature being used for spam, which is what the limits on our Fair Use page are for. We keep this in proportion by counting how many documents you send, not by reading them. The same basis covers the anonymous usage statistics in section 3 — kept in proportion by never sending anything that identifies you or your customers.
  • Because the law requires it (Article 6(1)(c)) — for records we have to keep, such as tax records of your purchase, which Apple holds rather than us.

Giving us this information is required to use the app — without an email address we cannot sign you in, and without your business and customer details we cannot produce an invoice. We do not make any automated decisions that have a legal or similarly significant effect on you.

5. Who else sees it

We use a small number of service providers. They act on our instructions and are not allowed to use your information for their own purposes.

  • Supabase — stores your account and your synced documents, in the United States (region us-east-1).
  • Resend — sends the emails that carry your documents to the recipients you choose.
  • Cloudflare — serves the page your recipient opens to view and approve a document.
  • PostHog — receives the anonymous usage events described in section 3, in the United States.
  • Apple — handles the purchase and tells us whether your subscription is active. We never see your payment details.

We do not sell or share your information with anyone else, and we do not use it to train machine learning models. We would disclose information if we were legally required to, and we would tell you unless we were forbidden from doing so.

6. Where your information is stored

Our servers are in the United States. If you are in the United Kingdom or the European Economic Area, that means your information leaves your country. Your data protection authority has not ruled that the United States protects it to the same standard automatically, so we cover the gap with a set of legally binding clauses in our contracts with the providers listed above — the Standard Contractual Clauses, and for the United Kingdom the International Data Transfer Addendum. They oblige those providers to protect your information to the standard your own law requires. Ask us at the address in section 1 and we will send you a copy.

7. Your rights

You can ask us to give you a copy of your information, correct it, delete it, restrict or object to how we use it, or send it to another provider in a portable form. To exercise any of these, email the address in section 1. We reply within one month.

Two of these you can do yourself, immediately, without asking us:

  • Export — Settings → Export all data sends you your documents, customers and payments as spreadsheet files.
  • Delete your account — Settings → Delete account removes your account and everything stored for it on our servers. This is immediate and cannot be undone; export first if you want a copy.

If you think we have handled your information badly, please tell us first so we can fix it. You also have the right to complain to your data protection authority: the ICO in the United Kingdom, your national authority in the EEA, the OAIC in Australia, the Privacy Commissioner in New Zealand, or the Privacy Commissioner of Canada.

8. Keeping it safe

Your connection to our servers is encrypted, and information is encrypted at rest by our hosting provider. Your account can only be reached through a one-time code sent to your email address, so there is no password to steal. Access to your documents is restricted at the database level so that one account cannot read another's. A document you send is reachable only through a long random link — anyone holding that link can view that one document, so send it only to the person it is for.

9. When we are only handling it for you

This section covers the customer information you type in (section 2), where you are the one responsible for it and we only handle it on your behalf. It forms part of our Terms of Service. We commit that:

  • we use it only to provide the app to you, and only as you direct;
  • we keep it confidential and protected as described in section 8;
  • we use only the providers listed in section 5 to help us, and we will tell you before we add a new one;
  • if one of your customers asks you what you hold about them, or if there is a security breach, we help you answer;
  • we delete it when you delete it, or when you close your account.

In return, you confirm that you are entitled to give us your customers' details for this purpose.

10. Children

Steadybill is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.

11. Changes

If we change this policy we update the date at the top, and we tell you in the app before any change that materially affects you takes effect.

Terms of Service Fair Use How to cancel