Skip to content
StiffProof

Privacy

Privacy policy

Last updated

StiffProof (“we”, “us”) runs stiffproof.com, a free invoice, estimate, quote and receipt generator. This page explains what we collect, why, who else touches it, and how to get it deleted. It is written to be read, not skimmed past.

The short version:

  • Without an account, the documents you make stay in your browser. We never receive them, and your PDFs are built on your own device.
  • No ads, no ad trackers, and no cookies at all unless you sign in. We don’t sell your data or share it for anyone’s marketing.
  • Accounts are optional. If you make one, we keep your email address and a copy of your documents and saved clients so you can reach them later — and you can delete all of it yourself, any time.

Using the generator without an account

Everything you type into an invoice, estimate, quote or receipt is saved in your browser’s own storage (IndexedDB, or localStorage where IndexedDB is unavailable). It is not sent to us. PDFs, CSV and JSON exports are generated in your browser too.

The clients and line items you save are kept in this browser the same way, and are not sent to us.

Photos you add to an estimate or invoice are made smaller and kept in this browser the same way, and are not sent to us. Making them smaller also removes the details cameras store inside a photo, such as where it was taken.

If you install StiffProof or use it on a phone, your browser also keeps a copy of the app’s own pages and code so it opens without a connection. If you’re signed in, that copy includes your name and email as they appear in the page header. It stays on your device, and signing out deletes it. Whether you dismissed the install suggestion is remembered on the device too.

Because we never hold a copy, we can’t recover these documents for you. Clearing your browser’s site data, using a private window, or switching devices will leave them behind — export anything you want to keep.

Analytics

We use PostHog (US-hosted) to count how the site is used, so we can tell whether pages and features are working. It is configured to see as little as possible:

  • Named events only. We record page views and a short, fixed list of events such as “a document was created” or “a PDF export finished”. Automatic click capture, heatmaps and session recording are all switched off.
  • Never your document contents. No event carries anything you typed — no names, addresses, emails, line items, notes, amounts, currencies or document numbers.
  • No cookies and no browser storage. Analytics keeps nothing on your device, so it can’t recognise you from one visit to the next.
  • No IP address. Events are sent with the IP address field blanked, and page addresses are trimmed before sending: document IDs are removed from URLs and query strings are stripped (apart from campaign tags like utm_source).
  • First-party only. Events go through our own domain rather than straight to a third-party server. An ad or tracker blocker that stops them breaks nothing on the site.

Analytics events are never linked to your name, email address or account.

Analytics never runs on the page that shows a document someone shared with you (see If someone sends you a document).

If you create an account

An account is optional. If you sign in, we store:

  • Your email address. If you sign in with Google, also your name and profile picture as Google provides them (see Google user data).
  • A session for each signed-in device: a session cookie, when it expires (30 days after your last visit), your browser’s user-agent string, and a one-way, salted hash of your IP address — never the address itself.
  • Your documents. When you sign in, the documents in that browser are copied into your account, exactly as your browser stores them, and while you stay signed in each document you save is saved to your account too. Signing in on another device brings your account’s documents to that browser. Your browser keeps its own copy of what you made in it; documents that came from your account are removed from a browser when you sign out of it. If the same document is changed on two devices, both versions are kept until you choose one, so nothing is silently overwritten.
  • Your saved clients and items. Your saved clients and items are copied into your account the same way, and follow you to your other devices. A saved client is whatever you saved about them — their name and any email address, phone number, address, tax ID or notes you entered — so it is personal information about your customers, which we hold for you and use only to show it back to you. A saved item is a description and, if you saved one, a price. If the same client or item is changed on two devices, the later edit is kept. Clients and items that came from your account are removed from a browser when you sign out of it, like documents.
  • Your photos. On a free account, your photos stay on the device where you added them. Your account’s copy of a document lists its photos (each one’s size, dimensions, a fingerprint of the file, and any caption you typed) but holds no image. To keep a copy, export from that device.
  • Documents you send by email. If you send a document to a client from your account, we give the document and the client’s email address to our email provider to deliver it, to that one address only — no copies to anyone else. We record on the document whether it was sent, delivered or bounced. We don’t keep the client’s address outside the document itself, and we don’t track whether the email is opened. The email carries one link, to the document’s own page (below). A payment reminder you send for an unpaid invoice is handled the same way: one email to that same address, with the amount still due and the same link, recorded on the invoice’s timeline.
  • Automatic payment reminders. If you turn them on, we store that setting, the days you chose, and any invoice you switched on or off. We then send the same payment reminder on those days, to the same one address, and keep a record of each one — which invoice, which day, and whether it went — so the same reminder is never sent twice. The invoice’s timeline marks these reminders as automatic.
  • Links to your documents. When you copy a client link or send a document by email, we make a private link to that document’s page. Anyone who has the link can see the document and, on an estimate or quote, accept it, decline it or ask for changes — so share it only with your client. You can turn a link off at any time. The link can’t be guessed, and we don’t store it in a form that would open the document. When someone opens it, the date they viewed it is added to your document’s timeline; your own visits while signed in are not.
  • Emails when your client answers. When your client accepts, declines or asks for changes on that page, we email the address you sign in with: their answer, the name they typed to accept, or the note they wrote. This is on unless you turn it off on your account page, and we store that setting. If you mark one of these emails as spam, we turn them off.
  • Receipts and payment notices. When a client pays an invoice online, we make a receipt for that payment and save it with your other documents. Unless you turn it off on your account page, we email it to your client as a PDF, to one address only: the one on the invoice or, for a bank payment with none, the one your client typed into Stripe’s form, which we read from Stripe at that moment only to send it and never keep. We also email the address you sign in with to say you have been paid, unless you turn that off. We store both settings.

There are no passwords. You sign in with Google or with a one-time code we email you. The code expires after 10 minutes and is stored only as a hash.

If someone sends you a document

A business using StiffProof may send you a link to an invoice, estimate or other document they made. The page shows that document exactly as they issued it, and a PDF copy to download. You don’t need an account, and the document’s contents are the sender’s: questions about it go to them.

  • Viewing it. If the page stays open and visible for a couple of seconds, the date and time it was viewed are added to the sender’s copy, at most once a day. Nothing else about you is recorded — not your IP address, device, browser or location.
  • Accepting or declining. On an estimate or quote you can accept or decline. Your answer and its date are added to the sender’s copy, and can’t be changed from the page afterwards. To accept, you type your name: the name, the date and time, and a code identifying the exact version you accepted are added to the sender’s copy and printed on its PDF. We don’t check who typed it.
  • Asking for changes. You can instead send the sender a note asking for changes. The note and its date are added to the sender’s copy, and the document stays open for you to accept or decline.
  • The sender is told. Unless they have turned it off, we email the sender your answer — with the name you typed, or your note — so they don’t have to check. If the document has your email address on it, their reply comes to you directly.
  • Calling or texting. If the sender put a phone number on the document, the page offers Call and Text buttons. They open your phone’s own apps; nothing about the call or message reaches us.
  • Limits. To stop the page being abused, we count requests per link and, for accept and decline, per IP address. The counters hold a salted one-way hash, never the address, and expire within an hour.
  • Nothing else. The page runs no analytics, sets no cookies, is never listed by search engines, and doesn’t pass its address on to other sites.

Records we keep to prevent abuse

  • Sign-in code limits. To stop the sign-in form being used to flood someone’s inbox, we count code requests per email address and per IP address. The counters hold salted one-way hashes, not the address or IP, and expire within 24 hours.
  • Shared document limits. Views, downloads and answers on a shared document’s page are counted per link, and answers also per salted IP hash, in counters that expire within an hour.
  • Email delivery log. For each email we send — sign-in codes, documents and payment reminders you send from your account, the emails telling you a client answered, and receipts and payment notices — we record the delivery status and a salted hash of the recipient’s address, not the address. This log is kept after an account is deleted so we can spot bounces and complaints. If a recipient marks a document email as spam, sending from that account is paused while we review it, because one account’s spam reports affect whether everyone’s documents arrive.
  • Server logs. Like any website, our host receives the technical details every web request carries — IP address, browser user agent and the page requested — and keeps them briefly in its logs to run and secure the service.

Google user data

If you choose “Continue with Google”, we request only Google’s basic sign-in scopes — openid, email and profile. From them we receive your email address, your name, your profile picture and a Google account identifier, along with the sign-in tokens Google issues.

  • How we use it: only to create your account, sign you in, and show you which account you are signed in as — your picture appears in the corner of the site and on your account page. We serve that picture through our own site: your browser asks us for it and we fetch it from Google, so Google is not contacted as you browse. We don’t access your Gmail, Drive, contacts, calendar or any other Google data.
  • Sharing: we don’t sell it, use it for advertising, or share it with anyone except the infrastructure providers listed below that store it on our behalf. We don’t use it to develop, improve or train generalised AI or machine-learning models.
  • Storage and protection: it is stored in our database, encrypted in transit and at rest, with access limited to operating the service.
  • Deletion: deleting your account removes it immediately, including the link to your Google account. You can also revoke StiffProof’s access at any time from your Google Account’s security settings.

StiffProof’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Cookies and browser storage

We set no advertising or analytics cookies. The only cookie we set is the session cookie that keeps you signed in, and only once you sign in — it is strictly necessary for the account to work, which is why there is no cookie banner.

The generator also uses your browser’s storage to hold your documents, the clients and items you’ve saved, the photos you’ve added, a recovery copy of the document you are editing (in case the tab crashes), your preferred document look, and, if you sign in, a note of which documents, clients and items are already in your account and which came from it. None of it is sent to us except the documents and the saved clients and items themselves, and only when you are signed in.

How we use information

  • To run the service: save your documents, sign you in, send sign-in codes, and send the documents and reminders you choose to email — including the automatic reminders you turn on — and the receipt for a payment your client makes online.
  • To keep it secure and stop abuse.
  • To understand, in aggregate, which pages and features are used, so we can improve them.
  • To reply when you contact us.

We don’t sell personal information, share it for cross-context behavioural advertising, or use it to build advertising profiles. There are no ads on StiffProof.

Who else handles it

We use a small set of service providers who process data only on our instructions, to run the parts of StiffProof they are named for:

  • Vercel — hosts the website and its server functions.
  • Neon — the database that holds accounts, their documents, and their saved clients and items.
  • Resend — delivers sign-in codes, the documents and payment reminders you choose to send by email, and the receipts for online payments.
  • Upstash — holds the short-lived, hashed counters behind sign-in limits and the limits on shared document pages.
  • PostHog — the anonymous analytics described above.
  • Sentry — receives a report when something fails on our servers: what went wrong and where in our code, with the ids of the records involved and, at most, an invoice’s number or an amount. Reports never include your IP address, an email address, or the names and lines on your documents, and links to shared documents are removed before they are sent.
  • Google — only if you choose to sign in with Google.

We may also disclose information if the law requires it, to protect StiffProof or its users from fraud or abuse, or as part of a sale or merger of StiffProof — in which case this policy would continue to apply to your information, and we would tell account holders before anything changed.

StiffProof does not process payments today. Online invoice payments through Stripe are being built and are not switched on yet. When they are:

  • If you set up payments, Stripe collects your business, identity and bank details on Stripe’s own pages; they never reach us. We keep your Stripe account’s id, the status words Stripe reports for it (whether it can take card and bank payments, and the names of anything Stripe still needs — never what you entered), its payout schedule, and your settings.
  • For each online payment we keep the amount, the date, card or bank, the card brand or bank name with its last four digits, the fees, its status, Stripe’s reason code if it was declined, and Stripe’s ids for it. We never see or store a card number or a bank account number.
  • If you pay an invoice online, the payment form on the page is Stripe’s: what you type goes to Stripe, and we keep only the amount, date, method and last four digits above. The name and email on the invoice are filled into Stripe’s form for you, and you can change them. Stripe’s script runs only on that payment page, never on the invoice page itself, and Stripe uses it to detect fraud under its own privacy policy. To stop stolen cards being tested on the page, payment tries are counted per link and per salted one-way hash of your IP address — never the address itself — for an hour.
  • Stripe tells us about everything that happens in a connected account, including payments that have nothing to do with StiffProof. We discard those notices unread.

How long we keep it, and deleting it

  • Documents in your browser stay until you delete them in the app or clear your browser’s site data.
  • Saved clients and items in your browser stay until you delete them or clear your browser’s site data.
  • Photos in your browser stay until you remove them, delete the document they’re on, or clear your browser’s site data. A removed photo is cleared from the browser within a week.
  • Your account is kept until you delete it. Deleting it — from your account page, no email needed — immediately removes the account, every session, the Google link, every document and saved client and item it holds, and your reminder settings and their record. Copies may remain in our database provider’s short-term backups until those roll over.
  • A single document deleted from your account is kept as a deleted record (so it can be restored) until the account itself is deleted.
  • A saved client or item you delete from your account keeps only a note that it was deleted, not its details.
  • A document changed on two devices keeps both versions until you choose which to keep on your account page; the version you don’t keep is then removed.
  • A link to a document works until you turn it off, or delete the document or your account. Views and answers recorded through it are part of the document and are kept, and deleted, with it.
  • Sign-in limit counters expire within 24 hours; the hashed email delivery log and anonymous analytics events are kept as long as they are useful for spotting delivery problems and trends.

Your choices and rights

  • Export: download everything as JSON, CSV or PDF, one click, whether or not you have an account. With an account, your account page also downloads everything it holds — including deleted documents, every kept version, and your saved clients and items — as one JSON file.
  • Delete: delete your account yourself at any time, as described above.
  • Access and correction: your account page shows what we hold; for anything else, email us.

Depending on where you live — including the EU, UK and California — you may have rights to access, correct, delete or port your personal information, and to object to or restrict how it is used. Email support@stiffproof.com and we will respond within 30 days. We won’t treat you differently for exercising any of these rights. If you are in the EU or UK, you can also complain to your local data protection authority.

For visitors in the EU and UK, the legal bases we rely on are: performing our agreement with you (running your account), and our legitimate interests in securing the service and understanding aggregate, anonymous usage.

Security

Connections to StiffProof are encrypted, and our providers encrypt stored data. We hold no passwords, store sign-in codes and IP addresses only as one-way hashes, and keep the personal information we collect to the minimum the service needs. No system is perfectly secure; if a breach ever affects your information, we will tell you.

Where your data is processed

StiffProof and its providers operate primarily in the United States. If you use StiffProof from elsewhere, your information is processed in the United States, with the safeguards our providers offer for international transfers.

Children

StiffProof is a business tool and isn’t directed at children. We don’t knowingly collect personal information from anyone under 13 (or under 16 in the EU and UK). If you believe a child has created an account, email us and we will delete it.

Changes to this policy

When this policy changes, the date at the top changes with it. If a change meaningfully affects how we handle information we already hold, we will say so on the site before it takes effect.

Contact

Questions, requests or complaints: support@stiffproof.com. See also our terms of service.