Last updated: 28 August 2026
Steadybill is an invoicing app for one-person trades businesses. We do not sell your data, we do not show ads, and we do not track you across other apps or websites. This page explains exactly what we hold, why, and how to get it deleted.
Steadybill is operated by Daigo Fujimoto, a sole trader based in Japan ("we", "us"). We are the data controller for the information described in section 3.
Contact for any privacy question, including requests to access or delete your data: support@steadybill.microforgehq.com. If you use the app, Settings → Contact us reaches the same place and is quicker.
This distinction matters, because it decides who is responsible for what.
| What | Why | How long |
|---|---|---|
| Your email address | To sign you in (we send a one-time code — there is no password) and to reach you about your account | Until you delete your account |
| Your business details: business name, address, phone, tax number, invoice settings, and your logo | To put them on the documents you create | Until you delete your account |
| Your customers' details and your invoices, estimates, payments and refunds | To create your documents and keep them in sync across your devices | Until you delete them, or delete your account |
| Documents you send, and the link the recipient opens | To deliver the document by email and let the recipient view and approve it | Until you delete the document or your account |
| The name a recipient types when they approve an estimate, and the time they decided | To record the approval on your document. If they decline, we record the decision and the time, but not a name | Until you delete the document or your account |
| The minute a recipient first opened the link you sent | So you can see whether your document has been looked at | Until you delete the document or your account |
| A record of each document you send: when, which document, and how you sent it | To apply the free plan limit and the fair use limits, and to show you what you have sent | Until you delete your account |
| If a recipient uses "Report a problem" on a document, what they wrote | So we can look into misuse of the sending feature | Up to 12 months |
| Your subscription status, and the receipt data Apple gives us for it | To know whether your plan is active. It contains no card details | Until you delete your account |
| If you write to us from Settings → Contact us: what you wrote, your email address (so we can reply), and the app version | To answer you, and to find the problem you are describing | Up to 24 months |
| Anonymous usage events: which feature was used (for example “a document was sent”), together with your device model, system and app version, and language — under a random ID created on your phone | To see which parts of the app are used and where people give up, so we can improve it | They are anonymous and cannot be traced back to you |
When you delete your account we also write one anonymous line recording that a deletion happened and how many rows it removed. It contains no name, email or document content, and cannot be traced back to you.
Photos you attach to a document are stored on your phone, not on our servers. The one exception is sending: when you email a document, the PDF — including any photos printed on it — passes through our sending service to reach your recipient. We do not keep a copy of it. If you delete the app or lose the phone, the photos themselves are gone with it.
We do not collect: your location, your contacts, your device identifiers for advertising, or crash reports. The app contains no advertising software. The usage events above never include what is in your documents — no customer names, no amounts, no text you typed.
We never receive your card details. Payment is handled entirely by Apple.
Data protection law says we must have a specific reason — a "lawful basis" — for holding your information. Ours are:
Giving us this information is required to use the app — without an email address we cannot sign you in, and without your business and customer details we cannot produce an invoice. We do not make any automated decisions that have a legal or similarly significant effect on you.
We use a small number of service providers. They act on our instructions and are not allowed to use your information for their own purposes.
We do not sell or share your information with anyone else, and we do not use it to train machine learning models. We would disclose information if we were legally required to, and we would tell you unless we were forbidden from doing so.
Our servers are in the United States. If you are in the United Kingdom or the European Economic Area, that means your information leaves your country. Your data protection authority has not ruled that the United States protects it to the same standard automatically, so we cover the gap with a set of legally binding clauses in our contracts with the providers listed above — the Standard Contractual Clauses, and for the United Kingdom the International Data Transfer Addendum. They oblige those providers to protect your information to the standard your own law requires. Ask us at the address in section 1 and we will send you a copy.
You can ask us to give you a copy of your information, correct it, delete it, restrict or object to how we use it, or send it to another provider in a portable form. To exercise any of these, email the address in section 1. We reply within one month.
Two of these you can do yourself, immediately, without asking us:
If you think we have handled your information badly, please tell us first so we can fix it. You also have the right to complain to your data protection authority: the ICO in the United Kingdom, your national authority in the EEA, the OAIC in Australia, the Privacy Commissioner in New Zealand, or the Privacy Commissioner of Canada.
Your connection to our servers is encrypted, and information is encrypted at rest by our hosting provider. Your account can only be reached through a one-time code sent to your email address, so there is no password to steal. Access to your documents is restricted at the database level so that one account cannot read another's. A document you send is reachable only through a long random link — anyone holding that link can view that one document, so send it only to the person it is for.
This section covers the customer information you type in (section 2), where you are the one responsible for it and we only handle it on your behalf. It forms part of our Terms of Service. We commit that:
In return, you confirm that you are entitled to give us your customers' details for this purpose.
Steadybill is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, contact us and we will delete it.
If we change this policy we update the date at the top, and we tell you in the app before any change that materially affects you takes effect.