All legal pages

Privacy policy

What stays on your device, what we store if you create an account, who else handles it, and for how long.

In short

  • Qufy is run by GRW Lab. The tools work without an account; an account keeps your workspace on our server in Germany.
  • We do not sell your data, show ads, or run third-party analytics.
  • Text you send to the assistant is not used to train models, under OpenRouter’s and the providers’ terms.
  • Logs are deleted after 90 days, waitlist entries after 12 months, and backups age out after about 6 months.
  • You can download your data and delete your account in Settings. Accounts are for people aged 18 or older.

Last updated: 8 October 2026

Who we are

Qufy is run by GRW Lab. You can reach us at hello@qufy.app or through https://grwlab.net.

Qufy is your freelance office, in English and Arabic: rates, quotes, invoices, contracts, and time tracking, on the web and in a Mac app. The tools work without an account. An optional account keeps a workspace on our server. Qufy is in a closed beta: accounts are by personal invite.

What stays on your device

You can calculate a rate, download a PDF invoice or contract, and use the ZATCA checklist without signing up. Drafts, language, and the rate → invoice → contract handoff use this browser’s localStorage or sessionStorage. We do not receive that content unless you later save it to an account, paste it into the assistant, or send a client link.

Optional account

If you create an account we store: your name, username, email, language, and a hashed password (never the password itself); the profile and business details you enter (business name, address, tax ID, default rate, currency, payment details, logo); your clients, projects, quotes, invoices, contracts and their earlier versions, time entries, reminders, and notifications; comments and responses your clients leave on your links; and, for each signed-in device, the browser or device name and when it was last used.

Account data is stored in a PostgreSQL database on our server, a Hetzner Cloud server in Nuremberg, Germany. Logos and signature images are stored as files on the same server. We do not sell this data and do not use it for advertising.

Every day we back up the database and stored files. A copy stays on the same server for 14 days. An encrypted copy goes to a Hetzner Storage Box in Helsinki, Finland, where we keep 14 daily, 8 weekly, and 6 monthly copies. Data you delete can therefore stay in backups for up to about 6 months, until those copies are replaced.

Qufy does not process payments. Payment details you add appear only on the invoices where you choose to show them. A client can tap “I’ve paid” on an invoice link; that only tells you they say they paid. The invoice is marked paid only when you confirm it.

Quote requests from a public profile

When someone sends a quote request from a freelancer’s public profile, we store their name, email, WhatsApp number and company if they give them, the service, budget, and timeline they pick, and their message, and show them to that freelancer so they can reply. GRW Lab keeps the request for the freelancer; the freelancer decides how to answer it. We also email the sender a confirmation and, if the freelancer declines with a reply, that reply.

The freelancer can delete a request at any time. Requests are deleted with the freelancer’s account, and a declined request is deleted 12 months after it was declined. To protect profiles from spam we keep a fingerprint (hash) of the sender’s IP address with the request, never the address itself.

When people at Qufy look at your account

People who run Qufy can open a member’s account and workspace in an admin view. They do so only to give support you asked for, to keep the service secure, or when the law requires it. Every time a member’s workspace is opened from the admin, the access is logged. The admin never shows your clients’ share links.

Invites and account emails

Invites are personal. An invite link works once, only for the email it was sent to, and only until the end date in the email. We store only a fingerprint (hash) of the link, not the link itself. Signing up through it confirms your email address.

When you sign up without an invite, we email a link to confirm your address (valid 24 hours). Password-reset links work once, for 30 minutes. We also email you about activity on your documents (for example a signed contract) and send the reminders you set up to your clients. All email goes through Resend, an email delivery service.

The Mac app signs in after you confirm a code on the /device page. Its session is stored in the Mac’s keychain and appears in Settings under signed-in devices, with the device name.

Cookies

We use only cookies needed to run the site; none are for advertising, and there is no third-party login. qufy_session keeps you signed in (30 days; httpOnly, SameSite=Lax, Secure on HTTPS). During the beta, qufy_member lets a member or an invited person past the beta gate (30 days, or until the invite ends), and qufy_invite keeps the invite you opened until sign-up is finished or the invite ends. qufy_locale remembers your language and qufy_tz your time-zone offset (1 year each). qufy_start_hidden remembers that you hid the getting-started card (1 year), qufy_office_hidden that you put off “Finish setting up your office” on Home (30 days), and qufy_insights_hidden which insights from your account you hid (30 days).

Client links and signatures

When you share a quote, invoice, or contract, anyone with the link can open it and respond: accept or decline a quote or invoice, sign a contract, leave a comment, or say an invoice is paid. A link stops working after 14 days, or earlier if you turn it off. Comments are saved with the document.

When a client signs, we record the name they typed, the time, and their IP address as evidence of the signature, together with the signature drawing and their browser’s user agent. This evidence stays with the document for as long as the document exists. Signing on a Qufy link is an electronic acceptance; see the terms for what it is and is not.

If you send a link by email, Qufy sends it through Resend to the address you entered. This is available only after you confirm your own email address. Reminder emails to clients include a link that stops further reminders for that invoice. WhatsApp sharing opens wa.me; we do not operate WhatsApp.

Waitlists

If you join a waitlist (on qufy.app or the ZATCA page), we store your email, the list you joined, for the launch list your language, and where you came from (campaign tags in the link and the referring site) in a file on our server. We get an email notice of each new sign-up. We use the launch list only to send your beta invite, and the ZATCA list only to tell you when that feature exists. We delete an entry after 12 months, or earlier on request.

Assistant

Text you give the assistant (a brief, a chat paste, or contract clauses) is sent through OpenRouter, an AI routing service, to a model provider (currently OpenAI or Google) to produce the answer. Every request asks OpenRouter to use only providers that do not collect the text (“data_collection: deny”). Text sent to the assistant is not used to train models, under OpenRouter’s and the providers’ terms.

We keep a log of each call with the model name, token counts, and cost, but not your text. Do not paste secrets, bank details, or other people’s private data.

Analytics

We do not use Plausible or any other third-party analytics. Blog pages count views on our own server. qufy.app is served through Cloudflare, which processes visitors’ IP addresses to deliver and protect the site.

Rate index (opt-in)

If you turn on “Help build the Qufy rate index: share my rates anonymously” in Settings under Business, each quote you send and each hourly rate you save adds one anonymous row: your profession, country, currency, pricing model, the rate or total, and the month. It never includes your name, email, account, clients, document titles, or anything you typed, and it is stored apart from your account with no link back to it. It is off by default. Turning it off stops new rows at once; rows already shared cannot be traced back to you, so they cannot be found or removed for one person. No rate from the index is shown to anyone until there are enough rows for each country and profession.

Service providers

Hetzner (server and backups; Germany and Finland), OpenRouter and the model provider (assistant), Resend (email), Cloudflare (qufy.app only). Market data refreshes from public sources (U.S. BLS, World Bank PPP, ExchangeRate-API, egytech.fyi); those requests carry none of your data.

Companies in the United States

Your workspace is stored in the EU (Germany, with backups in Finland). Five of the companies above are based in the United States, and each receives only what it needs:

OpenRouter: the text you send to the assistant and the model chosen. OpenAI and Google: the same text, passed on by OpenRouter to produce the answer. Resend: each email we send for you or to you (the recipient’s address, the subject, and the message with its link). Cloudflare: the IP address and request details of visitors to qufy.app, including what is typed into its waitlist form.

How long we keep data

Account and workspace data stay until you delete them or delete your account. A cleanup job runs every day and deletes: operational logs (assistant usage, email records, error and security reports, feedback, and admin activity) after 90 days; expired sign-ins 30 days after they expire; invite records 90 days after the invite is used, cancelled, or expires; declined quote requests 12 months after they were declined; and waitlist entries after 12 months. Qufy’s own server logs are kept for 30 days.

Signature evidence (the name, time, and IP address) stays with its document for as long as the document exists. A share link stops working after 14 days, but its record stays with the document until you delete the document or the account. Backups can hold deleted data for up to about 6 months, until they are replaced. Browser drafts stay until you clear this site’s data.

Your choices

You can use the tools without an account. In Settings you can download your data as a JSON file (profile, clients, projects, documents, links, signatures, time entries, reminders, notifications, and signed-in devices) and delete your account. In Settings you can also sign out one device or all others. You can clear this site’s storage in your browser. For anything else, write to hello@qufy.app from the account’s email.

Deleting the account needs your email and password and removes, at once, your documents, share links, signatures, logo, time entries, and everything else in the workspace, as well as your feedback, your invite records, and any waitlist entry with the same email. Copies in backups age out within about 6 months.

Minimum age

Accounts are for people aged 18 or older. If you believe someone under 18 has an account, write to us and we will delete it.

Changes

If how we handle data changes in a material way, we will update this page and the date at the top, and email account holders before the change applies.

Contact

Questions about privacy, an account, or these pages — write to the address below. We need the email on the account if you want data deleted.

Qufy is run by GRW Lab.

hello@qufy.appgrwlab.net