Quotebolt

Privacy Policy

Last updated: 26 August 2026

Quotebolt turns a voice note about a job into a priced quote you can send. Your quotes, your customers and your price list live on your iPhone. This page explains the few things that do leave it, why, and how to get rid of them.

Who we are

Quotebolt is run by a sole trader based in Ireland. For data protection law, we are the data controller for the information described here.

Email: allenjoshsamson99@gmail.com

Written requests can go to the same address, and we will reply from it.

What stays on your phone

Most of Quotebolt never talks to a server at all. The following is written to a file inside the app's own storage on your device and is not uploaded anywhere by us:

If you delete the app, that file goes with it. iCloud or iTunes device backups are handled by Apple under Apple's terms, not ours.

Voice recordings

When you tap record, Quotebolt saves an audio file to the app's temporary folder on your phone. Recordings are capped at three minutes and recorded in mono at speech quality, because a longer file costs more to transcribe and never contains more information.

Turning speech into text

There are two ways this can happen, depending on your version of the app:

We do not store your audio. It exists for the length of that one request and is never written to our database. The only thing recorded is how many bytes were transcribed, so we can measure cost and enforce the monthly free allowance.

Building the quote

When the Quotebolt service is used, the transcript of what you said (or what you typed) is sent to our server along with your trade, currency, day rate, VAT rate, whether you charge VAT, and up to forty rates from your price list. Our server passes that to Anthropic, which returns a structured, priced quote. Your customer's name and address, if you mentioned them out loud, are part of the transcript.

We do not store the transcript or the quote it produced. We keep only counts: how many characters the transcript was, how many line items came back, and the model's token usage. Those are used for cost control and the free-tier ceiling.

Some versions of the app do this work entirely on the phone with a built-in pricing engine and never contact us at all.

Sending a quote by link

This is the one feature that genuinely stores your data on our servers, and it only happens when you choose to publish a quote as a link. It is a Pro feature.

When you publish, we store a copy of that quote: your business name, phone, email and brand colour, your customer's name and email address, the job title, quote reference, currency, line items, notes, terms, discount, VAT and totals.

What your customer sees

The link is a page on our server with a long, random, unguessable address. It is marked so search engines do not index it, and there is no login — anyone you give the link to can open the quote, so treat it like an email attachment. We record when it was first opened and how many times, so your app can show you "viewed" or "accepted".

Emails we send on your behalf

If your customer's email address is on the quote, our server will email them twice unless they respond first: a gentle follow-up three days after you send it, and a warning shortly before the quote expires. When they accept or decline, we email you. These are sent through Resend. Both chases are cancelled the moment the customer decides.

If you use this feature, you are responsible for the customer details you put in. You decide whose name and email address go into a quote; we store and send it because you asked us to. Only enter a customer's email address if it is reasonable for them to hear from you about the job they asked you to price.

Deleting it

Deleting a quote in the app revokes the link, so the customer's page stops working. Settings › Erase everything deletes every published quote and your usage counters from our servers as well as wiping the app. If you want your anonymous install record removed too, email us.

The install identifier

Every install generates a random UUID, stored in your device's Keychain. It is sent with each request to the Quotebolt service. It exists for one reason: to count how many quotes an install has used this month, so the free allowance can be enforced and so a runaway script cannot spend our AI budget.

It is not linked to your name, email, Apple ID or advertising identifier, and it is not shared across your devices. We also record the two-letter country code Cloudflare derives from the connection, so we know roughly where the app is being used. We do not store IP addresses in our database.

Analytics

Quotebolt contains no advertising SDK, no third-party analytics SDK, no tracking pixel and no cross-app tracking. We do not use the advertising identifier (IDFA) and we do not ask for tracking permission.

When the Quotebolt service is used, our own server writes a plain event log: an event name (for example quote_built), the install identifier, a timestamp, and a few numbers such as item counts, character counts, quote totals and error status codes. It never contains anything you typed or said, and never a customer's name or email.

Payments

Subscriptions are bought and managed entirely through Apple's In-App Purchase. We never see your card details, billing address or Apple ID. Your app checks Apple's signed receipt to work out whether you are on a paid plan.

Where a subscription-management service (RevenueCat) is connected to validate receipts, it receives your install identifier and Apple's purchase events, and tells our server whether the install is entitled to Pro. Nothing about your quotes is sent to it.

Who processes data for us

CompanyWhat they handle
AppleApp distribution, in-app purchases, and speech recognition where your device cannot do it offline.
CloudflareHosts our server and database, and serves the customer-facing quote pages. Data is held in Cloudflare's D1 database.
OpenAITranscribes your voice note. Receives the audio for that request only.
AnthropicTurns the transcript into a structured, priced quote. Receives the transcript for that request only.
ResendSends the follow-up and accept/decline emails.
RevenueCatValidates App Store receipts and tells us whether an install is on a paid plan.

Several of these are based in the United States, so some data is transferred outside the EEA. Those transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

We do not sell your data, and we do not use anything you send through Quotebolt to train AI models.

Why we are allowed to hold it (lawful basis)

We do not rely on consent for any of the above, so there is no cookie banner. The quote pages we serve to your customers set no cookies and run no scripts.

How long we keep things

DataKept for
Voice recordings and transcriptsNot stored. The length of one request.
Photos of a jobNot uploaded. They stay on your phone.
Published quotesUntil you delete the quote, erase everything, or ask us to remove it.
Usage countersUntil you erase everything or ask us to remove them.
Install record and event logUntil you ask us to remove them.

If you want everything gone, the fastest route is Settings › Erase everything in the app, then one email to us to remove the install record and event log.

Your rights

Under the GDPR you can ask us to:

Email allenjoshsamson99@gmail.com and we will answer within one month. Because our records are keyed to an anonymous install identifier rather than a name, we will normally ask you to send the request from the app or to include the identifier so we can find the right rows — we would rather ask than delete a stranger's data.

If you are unhappy with how we have handled it, you can complain to the Irish Data Protection Commission.

Children

Quotebolt is a business tool for tradespeople and is not directed at children. We do not knowingly collect data from anyone under 16.

Security

Everything between the app and our server travels over HTTPS. API keys live on the server, never in the app. Quote links use a 96-bit random token, accept and decline are protected against being triggered from another website, and the admin dashboard is behind a password. No system is perfect, but there is deliberately very little here worth stealing.

Changes to this policy

If we change what we do with data, we will update this page and change the date at the top. Material changes will also be mentioned in the app's release notes.

Contact

Questions, deletion requests, or anything on this page that does not match what you have seen the app do — please tell us.

allenjoshsamson99@gmail.com