Quill.

Privacy policy

This page is not finished. The business details it depends on have not been filled in yet (name, address, privacyEmail, supportEmail, icoRegistration), and a solicitor has not reviewed the wording. It is published so the routes and structure exist, and must be completed before taking payment from anyone.

Last updated 2026-08-16. This explains what Quill does with personal data — yours, and your customers'. It is written to be read rather than to be impressive, so if anything here is unclear, ask and it will be fixed.

Who is responsible for your data

Quill is operated by [legal business name — not yet filled in], of [registered address — not yet filled in]. For questions about this notice or to exercise any of the rights below, contact [privacy email address — not yet filled in]. ICO registration: [ICO registration number — not yet filled in].

Two different relationships, which matter

Quill holds two kinds of personal data and its legal role differs for each. For your own account — your name, email, business details and billing — Quill is the data controller and this notice explains what it does.

For the details you enter about your customers — their names, addresses, phone numbers, email addresses, site notes and photographs — you are the controller and Quill is your processor. Quill acts on your instructions, does not decide what to collect, and does not use your customer list for its own purposes. The processing terms required by Article 28 of the UK GDPR are in the terms of service.

What is collected, and why

Only what the app needs to do its job. There is no advertising, no profiling, no data sold or shared for marketing, and no third-party analytics or tracking of any kind on this site or in the app.

Your account

  • Your name, email address and a hashed password. The password itself is never stored and cannot be recovered, only reset.
  • Your business details as you enter them: trading name, address, phone, VAT number, and scheme registrations such as NICEIC or NAPIT. These print on your invoices because your customers and their insurers look for them.
  • Your bank account name, sort code and account number, if you choose to enter them. These are shown to your customers on your invoices so they can pay you — that is their only use.
  • If you sign in with Google, Apple or Microsoft, the identifier and email address that provider returns. Quill never receives your password for those accounts.

Your customers and your work

  • Customer records you create: name, address, email, phone, and any notes or photographs you attach.
  • Invoices, estimates, credit notes, expenses, time entries and payment records.
  • Delivery outcomes for emails you send through Quill, so you can see whether an invoice actually arrived.

Bank feed, if you connect one

Connecting your bank is optional. If you do, Quill receives read-only access to your account balance and transaction list so it can match incoming payments to invoices. Access tokens are encrypted before storage. Quill cannot move money, and the connection can be withdrawn at any time from your bank or from Quill.

Technical data

  • A single session cookie, described below.
  • Server error records, kept so faults can be diagnosed and fixed.
  • Your IP address, used transiently to rate-limit abuse of sign-in and other endpoints.

The lawful basis for each use

  • Contract — running your account, storing your work, generating documents, sending the emails you ask Quill to send, and taking your subscription payment.
  • Legitimate interests — keeping the service secure, preventing abuse, diagnosing faults, and contacting you about service problems or changes.
  • Legal obligation — keeping the records tax and company law require.
  • Consent — connecting a bank account, and using the optional AI features. Both are off unless you choose them, and either can be withdrawn without affecting anything else.

Who else processes it

Quill uses a small number of suppliers to run the service. Each is a processor acting under contract, and each receives only what its job requires.

  • Railway — hosting the application.
  • Neon — the PostgreSQL database where your data is stored.
  • Stripe — subscription payments, and card payments your customers make. Stripe receives billing details and card data directly; Quill never sees or stores a card number.
  • Resend — sending the invoice and estimate emails you choose to send, and the reminders you schedule. Receives the recipient address and the message.
  • TrueLayer — the open banking provider, only if you connect a bank account.
  • OpenAI — only if the optional AI features are used, and only for the text you submit to them.
  • Google, Apple or Microsoft — only if you choose to sign in with one of them.

The AI features, specifically

Quill's AI extras are optional and clearly labelled. When you use one — describing a job in plain English, improving wording, or reading a works order — the text or document you submit is sent to OpenAI to produce the result. That text may include a customer's name or address if you put one in it.

Nothing is sent automatically and nothing is sent in the background: creating, saving, emailing and generating a PDF of an invoice never involve AI. If you would rather no data went to OpenAI at all, do not use those buttons and nothing will.

Transfers outside the UK

Some suppliers process data outside the UK, including in the United States. Where that happens it relies on the safeguards UK data protection law requires, such as the International Data Transfer Agreement or the UK extension to the EU–US Data Privacy Framework.

Cookies

Quill sets one cookie, named quill.sid. It keeps you signed in, lasts up to 30 days, is marked http-only and secure so scripts cannot read it, and is not readable by other sites. It is strictly necessary for the service to work, which is why there is no cookie banner asking you to accept it.

There are no analytics, advertising or tracking cookies, because there is no analytics, advertising or tracking. Stripe sets its own cookies on its checkout pages, which are covered by Stripe's privacy policy.

How long it is kept

Your data is kept while your account is open. Deleting an invoice or estimate moves it to a recoverable state for 30 days — so a mistake can be undone — after which it is permanently removed.

Close your account and your data is deleted. Export anything you need first: UK tax records generally have to be kept for six years, and that obligation is yours, not Quill's. Quill may keep the minimum needed for its own legal and accounting duties, such as a record that a payment was made.

Security, honestly stated

Traffic is encrypted in transit. Passwords are hashed. Bank access tokens are encrypted before they are stored. Each account's data is separated, and access is checked on every request rather than assumed from a link.

No service can promise it will never suffer a breach. If one happens and it puts your rights at risk, you will be told, and the ICO will be notified within 72 hours where the law requires it.

Your rights

Under UK data protection law you can ask for a copy of your data, ask for it to be corrected or deleted, ask to receive it in a portable form, object to or restrict certain processing, and withdraw consent where consent is the basis. There is no charge and a response is due within one month.

Write to [privacy email address — not yet filled in]. If you are unhappy with the response you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113. Complaining to the ICO is free and does not require going through Quill first.

If you are one of our customers' customers

If you received an invoice or estimate made with Quill and want to know what is held about you, or want it corrected or erased, ask the tradesperson who invoiced you. They control that record; Quill only stores it for them. Quill will pass on any request that comes to it directly, but cannot act on it alone.

Changes to this notice

If this notice changes in a way that affects you, you will be told in the app or by email before it takes effect. The date at the top always reflects the current version.