Tradoc

Privacy policy

Tradoc is local-first: your business records live on your device and the app works offline without an account. This page describes exactly what leaves your device, which services handle it, and the choices you have.

Information on your device

Quotes, invoices, customers, line items, payment history, reminders, reusable work, business profile details, job photos and app settings are stored locally on your device, in Tradoc’s own database. Reminders are scheduled by your phone. Signing in does not by itself upload or sync those records.

If you choose to add a customer from your contacts, Tradoc asks for permission to read your contacts, shows your address book on the device so you can pick one person, and saves only the details you pick into that customer. Your address book is not uploaded and no contact identifier is kept.

Your account (optional)

An account is needed only to send documents to customers, use online payments, use Tradoc Pro or back up to the cloud. Supabase, Tradoc’s backend, holds your account: your email address, or your Google identity if you use Google Sign-In, plus authentication and security records. Tradoc also records on its server which account has used its one free customer send and a copy of your subscription status.

Optional account backup

Automatic cloud backup is off until the account that owns this device’s work turns it on. When it is on, Tradoc uploads a full copy of your Tradoc data to Supabase after changes: customers, quotes, invoices, line items, manual payment records, reusable work, business profile information and related settings. Job photos, logo files and subscription records are not included. It is sent over encrypted connections (HTTPS).

Backup is disaster recovery, not sync: it is not a live multi-device collaboration system, and restoring replaces the data on a device. Which account owns this device’s work does not depend on backup — turning backup off does not change it. You can create a backup file yourself instead and decide where to keep it.

Customer links

When you share a quote or invoice as a link, Tradoc publishes a copy of that document — your business details and logo, and the customer name, work and prices it shows — so your customer can open it at mytradoc.com without an account. Anyone holding the link can open it; these pages are kept out of search engines and are not stored by shared caches.

When your customer accepts a quote or asks for changes, Tradoc stores the name they type and any note they add (up to 500 characters). It records when a page was first and last opened and how many times — not who opened it, their IP address or their device.

Messaging and social apps may fetch a shared link to show a preview (your business name, the document number, and your logo) and can keep that preview independently of Tradoc. Tradoc cannot remove previews those apps have already stored.

Online payments (Stripe)

If you accept online payments, you set up a Stripe account through Stripe Connect. Stripe collects the identity, business and bank details it needs to verify you and pay you out, directly and under its own privacy policy; Tradoc does not receive them. Tradoc stores the Stripe account’s identifier, status and country, and labels the Stripe account with your Tradoc account identifier so the two stay linked. You are the merchant for your customers’ payments.

Card and bank details your customer enters on an invoice page go straight to Stripe and never reach Tradoc. Tradoc records what Stripe reports about each payment — amount, status, refunds, disputes and Stripe’s identifiers — to show what has been paid. Stripe keeps its own records of those payments.

Subscriptions (RevenueCat, Google Play)

Tradoc Pro is sold through Google Play on Android and through RevenueCat’s web checkout on the web. RevenueCat receives your Tradoc account identifier and email address to link a subscription to your account; RevenueCat and Google Play process purchase, renewal and entitlement records needed to provide and restore Tradoc Pro.

Notifications

If you allow notifications and are signed in, Tradoc stores your phone’s push token (Firebase Cloud Messaging) with your account so it can tell you when a customer answers a quote or pays. The notification says what happened, not the customer’s details. Signing out asks the server to remove that phone’s token (when the phone is online), and every token is deleted with your account.

Analytics and technical data

Firebase Analytics receives bounded app events — a screen or workflow category, a result, a plan or billing period — plus Firebase’s automatic events (such as first open and session start) and an app-instance identifier. Tradoc’s events exclude customer names, contact details, document IDs, document text, notes, exact prices and account identifiers. Advertising ID collection is off.

Analytics are on by default. You can turn them off in the app under Help & quick start, Share usage analytics; that stops future analytics from that device but does not delete what Firebase already received. Tradoc does not send crash reports to a crash-reporting service; Google Play may collect crash and performance data under Google’s terms.

Websites and hosting

mytradoc.com and customer pages are served by Cloudflare, which processes each request (including IP address and browser details) to deliver it. The web version of the app loads its rendering engine from Google’s content network.

Sharing and retention

When you deliberately share a PDF, export, backup file, or message, the destination app and recipient process that content. Tradoc’s own server data — your account, cloud backup, customer pages and responses, push tokens, and payment records — is kept while your account exists and deleted with it. Stripe, RevenueCat, Google Play, Firebase and Cloudflare keep their own records under their own policies and legal obligations. After an account-deletion request, Tradoc may retain only minimal request/completion evidence and billing records required for security, fraud prevention, legal, tax, or store-accounting obligations.

Your choices

  • Use the core local app without an account or cloud backup.
  • Turn automatic cloud backup on or off from Account & cloud backup.
  • Turn analytics off in Help & quick start.
  • Create a portable local backup file and control where you save or share it.
  • Remove local records in the app or by uninstalling and clearing app data.
  • Request account deletion through the account deletion page.
  • Manage or cancel a Tradoc subscription through Google Play, or from Tradoc Pro in the app for a web subscription.

Policy updates

This policy is prepared for Tradoc 2.2 and was last updated September 30, 2026. Material changes will be published on this page.