Privacy Policy
Last updated: April 2026
This is a plain-English privacy policy. We've tried to say what we actually do without hiding behind legalese. If anything here is unclear, email support@qspilot.app and we'll explain.
Who we are
QS Pilot is a mobile app for builders and subcontractors. It helps you price jobs, track costs, and
send branded PDF quotes from your phone. This policy covers the QS Pilot app and this
website (qspilot.app).
The Service is operated by QS Pilot Ltd ("we", "us", "our"). We are the data controller for the information described in this policy. Our UK registered address is 73 Sandylands Road, Kendal, England, LA9 6JG.
What we collect, and why
Your account
When you sign up we collect your name, email address and (optionally) phone number and business address. The business address, your company name and logo are used on the PDF quotes we generate for you — the same way a letterhead works.
We also store an internal user ID from Supabase (our auth provider) so we know which data belongs to which account.
Your jobs, quotes and costs
Everything you put into QS Pilot — projects, quotes, rates, costs, notes — is stored against your account so it syncs across your devices and survives if your phone is lost. This is your data. We don't look at it, sell it, or use it to train AI.
Data is written to a local database on your device and synced to the cloud when you have signal, so your projects, quotes and notes survive a flat battery or a dropped connection.
Your customers' contact details
When you add a client name or client email to a job, that information stays in your account (Supabase, EU region) and on your device. It is never sent to any AI provider. Our AI features see your project scope, line item descriptions, photos, and uploaded documents — but not your customer contact records.
Two things worth knowing:
- If you upload a customer's email or a PDF that contains their details, the contents of that document are sent to the AI provider as part of reading the file. Any names or addresses inside the document travel with it.
- The project scope text you type is sent to the AI to help generate the quote. Don't include anything in the scope you wouldn't want the AI to see.
Photos and documents
When you take a photo of a site, an invoice, or a spec sheet, the image is sent to our AI provider (Anthropic's Claude) so we can read the text and numbers and turn them into structured data for your quote or cost record.
Photos you attach to a project are stored in your account (Supabase Storage). Photos sent to the AI for one-off OCR are processed and returned — we don't keep a separate long-term copy tied to your identity on AI providers' systems (see "Who we share with" below).
Payment information
If you subscribe, billing is handled by Stripe (on web and Android) or Apple (in-app purchase on iOS). We never see or store your card details. We receive a confirmation that your subscription is active and when it expires.
What we don't collect
- No ad networks, no advertising IDs.
- No third-party analytics or tracking SDKs.
- No location tracking in the background.
- No access to your contacts, microphone or camera unless you tap the feature that needs it.
Our legal basis (UK GDPR)
Under UK GDPR we have to tell you why we're allowed to process your data. For QS Pilot that falls into three buckets:
- Contract. If you're on a paid plan or free trial, we process your account and job data because we have to in order to deliver the service you've signed up for.
- Legitimate interest. We process a minimal amount of diagnostic data (crash logs, error messages) to keep the app running. You can object to this at any time.
- Legal obligation. We keep basic billing records for as long as UK tax law requires (typically six years).
Who we share with
We use a small number of trusted providers ("processors") to run the service. We only share what they need to do their job.
- Supabase — database, authentication and file storage. Your data is stored in the EU region (Ireland).
- Anthropic (Claude) — reads your photos and documents to extract text and numbers, and powers the heavier reasoning that turns a site survey into a structured quote. Servers in the US. Anthropic may retain inputs and outputs for up to 30 days for safety and abuse monitoring, after which they are deleted. Anthropic does not use your data to train their models.
- Google (Gemini) — handles lighter text-only AI tasks like parsing project descriptions, classifying inputs, narrowing rate-book searches and generating scope summaries and exclusions. Servers in the US. Google does not use paid Gemini API inputs or outputs to train their models.
- SambaNova (Llama) — powers the in-app pricing chat ("why is this priced like this?") because it can reply faster than the other providers. Servers in the US. Only line item descriptions, rates, quantities, your saved day-rate names and your typed chat messages reach this provider — your customer names, project names and site addresses are never sent.
- Stripe — subscription billing on web and Android. UK/US.
- Apple — in-app purchase billing on iOS, if you subscribe through the App Store.
Transfers to the US are covered by the UK International Data Transfer Addendum and our providers' standard contractual clauses. We don't sell your data. We don't share it with advertisers. We don't let AI providers train on it.
How long we keep it
Your data stays in your account for as long as your account is open. If you delete your account from inside the app, we wipe your personal data and job data from our systems within 30 days. Billing records may be retained longer where UK law requires.
Your rights
Under UK GDPR you have the right to:
- See what we hold about you.
- Correct anything that's wrong.
- Delete your account and everything in it — there's a one-tap button in Settings. No email required.
- Take your data with you. You can export any Final Account as a PDF or CSV straight from the app.
- Object to or restrict certain kinds of processing.
- Withdraw consent at any time.
To exercise any of these, email support@qspilot.app or use the tools in the app Settings. We'll respond within one month.
Complaints
If you're not happy with how we've handled your data, please tell us first so we can fix it. If we can't, you have the right to complain to the UK's Information Commissioner's Office (ICO) at ico.org.uk.
Security
Data is encrypted in transit (TLS) and at rest on Supabase. Row-level security rules mean one user can't read another user's data. We use Apple and Google sign-in where available so passwords don't have to be stored in our systems.
Nothing is 100% secure. If we become aware of a personal data breach, we will notify the ICO within 72 hours as required by UK GDPR, and we will notify affected users without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
Children
QS Pilot is a tool for running a building business. It's not designed for, or directed at, anyone under 18. We don't knowingly collect data from children.
Cookies
This website uses essential cookies only — there's no advertising, no tracking and no analytics SDK. The mobile app doesn't use cookies.
Changes
If we change this policy in a way that affects you materially — including adding a new sub-processor to the "Who we share with" list — we'll update the "Last updated" date and tell you in the app or by email before the change takes effect. If you're not happy with a change, you can cancel your subscription and delete your account.
Contact
Questions, data requests, anything at all:
Email: support@qspilot.app
Company: QS Pilot Ltd