GigFee — Privacy Policy

Last updated: 8 August 2026

GigFee keeps your work on your phone. Nothing is sent anywhere unless you turn on cloud backup, which is optional and part of the Premium subscription. If you do turn it on, one copy of your data is stored in GigFee's Firebase project in Sydney, reachable only by the account you signed in with.

This policy explains what stays on your device, what leaves it if you ask it to, and how to get rid of everything.

What we collect

With cloud backup off — nothing. There is no account, no analytics, no advertising and no crash reporting in GigFee. Turn the app on, use it for years, never sign in, and we receive nothing about you at all.

With cloud backup on, two things reach us:

What is in a backup

Everything the app holds, which is what makes it worth restoring:

Generated invoice PDFs are not included — they are rebuilt from the invoice when you open it, so nothing is lost by leaving them out.

Some of this is other people's personal information: your clients' details, and anything imported from your phone's contacts or calendar. Once it is in GigFee it is part of your data and is included in a backup like everything else.

Where it is stored, and who can read it

Backups are held in Google Cloud Storage, in a Firebase project we operate, in Google's australia-southeast1 (Sydney) region. Your backup file does not leave Australia.

Access is enforced by server-side security rules that allow a file to be read or written only by the account that owns it. That check runs on Google's servers on every request, not in the app, so it cannot be bypassed by a modified copy of GigFee. No other GigFee user can reach your backup.

We will be straight with you about the limit of that: as the operators of the project we hold administrative access to the storage bucket, in the same way any company hosting your data does. We do not open, read, analyse or share the contents of anyone's backup, and there is no feature, tool or process in GigFee that does. But "we cannot" would be too strong a word, and we would rather say so than imply otherwise.

Your account record — email address, display name and user ID — is held by Firebase Authentication, which Google does not run on a region-specific basis. That means it may be stored or processed outside Australia. Your backup file is not.

Data is encrypted in transit using HTTPS, and encrypted at rest by Google Cloud Storage.

Deleting your data and your account

You can delete everything we hold, at any time, from inside the app:

  1. Open GigFee.
  2. Go to Settings → Backup & restore.
  3. Under Automatic cloud backup, tap Disconnect.
  4. Choose Delete everything.

That removes the backup file and closes your GigFee account in the same step. It happens immediately, and it cannot be undone.

If you no longer have the app — a lost phone, an uninstall — email us at the address at the bottom of this page from the Google account you signed in with, and ask for your GigFee data to be deleted. We will delete the backup file and the account and confirm when it is done, within 30 days and usually much sooner. We may ask you to confirm the request from that email address; that is the only check we can make that you are who you say you are.

What is deleted: the backup file, and the account record holding your email address, display name and user ID. Everything.

What is kept: nothing. We hold no separate archive, no analytics profile and no record of the contents of anyone's backup. Google's own infrastructure may retain a deleted file briefly as part of normal storage operation, after which it is gone.

What is not affected: the copy on your phone. Deleting your cloud data never touches your local records, and disconnecting is not the same as deleting — you can stop syncing and keep the cloud copy for your next phone if you prefer.

Uninstalling GigFee deletes everything held on the device. If you had cloud backup on, use one of the routes above as well, or the cloud copy will remain.

Choosing not to use cloud backup

Cloud backup is off until you turn it on, and every other part of GigFee works without it. Manual backup — a file you save and keep yourself — is available on every plan, including the free trial and a lapsed subscription. These are tax records you are required to keep, and being unable to pay should never mean being unable to get them out.

Contacts (optional)

If you use "Import from contacts", GigFee reads your device address book so you can pick clients to add. The reading happens entirely on your device, and only the entries you explicitly select are saved into the app. Those saved clients are then part of your GigFee data, and are included in a cloud backup if you have one turned on. You can decline this permission and use every other part of GigFee normally.

Calendar (optional)

The gig importer reads the calendars already on your phone so you can pick events to bring in. It is read-only — it never changes or adds an event — and the reading happens on your device. As with contacts, the gigs you choose to import become part of your GigFee data and are included in a backup.

Photos (optional)

Adding a logo, or photographing a bill, uses your device's photo picker or camera, which gives GigFee access only to the images you select or take. They are copied into the app's private storage, and are included in a cloud backup if you have one.

Reading a bill

When you attach a bill somebody sent you, GigFee can read the text off it to fill in the form. That recognition runs entirely on your phone, using a model bundled with the app. The document is not sent to an online text-recognition service — somebody else's invoice, with their name, ABN and bank details on it, never leaves your device for that purpose.

Purchases

Purchases are processed by Google Play. We never see or receive your payment card details, billing address or any other payment information — Google handles the transaction and tells GigFee only whether a purchase is active.

Your purchase is tied to your Google account, which is what lets it be restored if you reinstall the app or move to a new phone.

Notifications

GigFee can remind you when an invoice is due. Reminders are scheduled and shown by your device. Nothing is sent through a notification server, and no information leaves your phone to produce them.

Sharing and exporting

When you send an invoice, export a spreadsheet or share a backup file, your device's share sheet or email app sends it to the destination you choose. Once it leaves GigFee, it is handled by that app or service under their terms, not ours.

Analytics, advertising and tracking

There are none. GigFee contains no analytics SDK, no advertising, no crash-reporting service and no tracking of any kind. We do not know how many invoices you have made, which screens you visit, or whether you opened the app today.

Children

GigFee is a business tool intended for adults. It is not directed at children and we do not knowingly collect information from them.

Security

On your phone, your data sits in Android's app-private storage, which other apps cannot read. In the cloud, it is isolated per account by server-side rules, encrypted in transit and encrypted at rest.

We would encourage you to protect your phone with a screen lock, and to keep your own backups as well — GigFee's manual backup exists for exactly that reason.

Your rights

Australian privacy law, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles, gives you rights to access and correct personal information an organisation holds about you. If you have used cloud backup, you can exercise those rights by contacting us at the address below; in practice your own copy in the app is the same data, kept current.

You remain responsible for the personal information you enter about your own clients, and for meeting any obligations you have to them.

Changes to this policy

This policy changed on 8 August 2026, when optional cloud backup was added. Before that release GigFee had no accounts and sent nothing off the device. If what we collect changes again, this page will say so and the app will tell you rather than relying on you re-reading it.

Contact

Questions about this policy, or a request to delete your data:
admin@tones-au.com