Legal
Privacy
Last updated 17 July 2026
QuoteStudio is run by stillidea. This page describes what we actually store and why — not what a template says we might.
What we collect
If you have an account
- Your email and password. The password is hashed (PBKDF2); we cannot read it and neither can anyone who obtains the database.
- Your studio details — name, logo, brand colours, currency, timezone, working schedule, default terms, payment methods. You enter these; they appear on documents you send.
- Your work — quotes, projects, milestones, tasks, invoices, and the client names and email addresses you add to them.
- A session cookie, so you stay logged in. It is not used for tracking.
- Sign-in timestamps, so we can tell an account is in use.
If a client opens a link you sent
Nothing about them is stored beyond what you already entered, plus what they choose to submit — an approval, a requested change, or an issue raised on an invoice. Clients never create accounts and are never asked to. No tracking pixels are placed in the documents you send.
If you visit the website
We use Cloudflare Web Analytics, which is cookie-free and does not fingerprint or track individuals across sites. It tells us how many people visited a page — not who they are.
What we never do
- We do not sell your data, or your clients' data. There is no version of this business where that happens.
- We do not use your data to train anything.
- We do not place advertising or third-party trackers in the app or in your documents.
- We do not email your clients except when you tell us to send a quote or an invoice.
Who else touches it
- Cloudflare — hosting and database. Your data lives in Cloudflare D1.
- Resend — sends the emails you trigger. They process the recipient address and message.
That is the entire list. No analytics suites, no CRMs, no data brokers.
How long we keep it
For as long as your account exists. Delete your account and everything goes — quotes, projects, invoices, clients, files, the account itself. It is a hard delete, not a flag, and it cannot be undone. Any client links you shared stop working immediately. Email us to request it.
Your rights
Ask us and we will export everything we hold about you, correct it, or delete it. You do not need a legal basis and we will not ask for one. Contact us.
Security, honestly stated
Passwords are hashed, every query is scoped to the account that owns the row, and client-facing links use long unguessable tokens. Anyone holding a link can view that document — that is the point of them, so share them the way you'd share any document link. No system is perfectly secure, and we won't claim otherwise.
Changes
If this page changes in a way that matters, we will email account holders rather than quietly updating the date.
Questions: get in touch.