QuickBill Pro — App Privacy Policy

Applies to the QuickBill Pro app, Android package com.suryaai.quickbillpro and iOS bundle com.suryaai.quickbillpro.
Version 1.1.0-beta · Last updated 20 August 2026 · Effective 20 August 2026

This app is in closed beta. Anything the app syncs is sent to our sandbox environment, not to a production service. There is no production QuickBill Pro backend yet. The sandbox is a test environment: it is not covered by a service level agreement, it may be reset, and you should not rely on it as your only copy of your business records. Keep your own backups.

This page covers the app. The company-wide policy for our websites and accounts is at quickbillpro.co.in/privacy.html. Where the two differ for the app, this page governs.

1. Who we are

QuickBill Pro is published by Surya AI Technologies Pvt Ltd (CIN U62099KA2026PTC220007), Bengaluru, Karnataka, India.

Under India's Digital Personal Data Protection Act, 2023, we are the Data Fiduciary for the account data of the shop owners and staff who use the app — the people who sign in and run a store with it. For the customer records a shopkeeper enters, the shopkeeper is the Data Fiduciary and we process that data on their behalf (§10). That distinction decides who a person exercises their rights against — see §9, which now says which is which — so it is worth being exact about rather than claiming both roles at once.

Privacy and data-deletion requests: [email protected]
Data Protection Officer: Kishore Rajendra, [email protected]

2. QuickBill Pro is offline-first — most of your data stays on your device

The app keeps a full local database on the device (an SQLite file named quickbill.db in the app's private storage). Billing works with no network connection at all. The local database holds everything you enter in the app, including:

The app does not add its own encryption to this local database. It is protected by your device's own storage encryption and app sandboxing. Your login token is stored separately in the platform's secure store — the Android Keystore / encrypted shared preferences on Android, and the Keychain on iOS.

Usage events are recorded in that same local database. This build has no upload path for them — they stay on your device.

The app also keeps local backups of that database — a daily automatic one and any you make yourself. They are gzip-compressed copies written into the app's own private storage. They are compressed, not encrypted: like the database itself, they are protected by your device's storage encryption and app sandboxing, and by nothing the app adds.

Settings → Backup & Restore also lets you export a backup through your phone's share sheet — to WhatsApp, email, a cloud drive, anywhere. That is there deliberately, so an accidental uninstall or a lost tablet does not wipe your bills. Please be aware of what you are sending when you use it: that file is your entire database, including every customer name and phone number you have saved, and it is not encrypted. Once you have shared it, it is subject to whatever the receiving service does with it, and we have no visibility into that.

"Save PDF" on a bill is different, on Android. It writes the invoice — customer name, line items and totals — into your device's public Downloads folder, not into the app's private storage. That means any other app with permission to read your storage can open it, and uninstalling QuickBill Pro does not remove it. Saved invoices you no longer want must be deleted from Downloads yourself, with your file manager.

Uninstalling the app deletes its private storage, and with it the local database and any local backups still held there. Other copies are not affected, and uninstalling does not reach them — see §8, which covers the ones we know of, including copies Android's own backup service may have made without you doing anything, and anything you sent out of the app yourself.

"Backup" means four different things in this app, and they behave differently. Where this page says "backup" it names which one:

3. What leaves your device, and when

This section covers sync to our own servers. It is not the only thing that leaves the device, and it is not the largest: a compressed copy of your entire database goes to your Google Drive daily, on by default, once a Google account is connected — that is described in §4.3, and it is worth reading before this one.

3.1 Sync to our servers

If you sign in and sync is enabled, the app sends records over HTTPS to https://sbx.quickbillpro.co.in. Our server accepts, and therefore may store, the record types the app syncs — including categories, products, product variants, inventory, inventory adjustments, customers, loyalty points, discounts, tax configurations, staff, bills, bill items, payments, settings, printer configurations, store details and the business templates a store starts from.

Those servers are Amazon Web Services instances in the Asia Pacific (Hyderabad) region — ap-south-2, in India. Traffic to our domains is proxied by Cloudflare, Inc., which terminates TLS at an edge location and therefore sees request metadata, including your IP address, in transit.

3.2 How your data is protected on our servers

DataHow it is stored
Customer name, customer phone numberEncrypted in the database column using PostgreSQL pgcrypto symmetric encryption
Staff phone number and emailEncrypted in the database column, same mechanism
Supplier / vendor phone number and email⚠️ This build never sends supplier records to us at all. Our database has encrypted columns ready for them, but suppliers are not among the record types §3.1 lists, so the only copy is the one on your device. See §2 — and note that means we hold no backup of your supplier contacts
Payment reference numbersEncrypted in the database column, same mechanism
Staff login PINStored only as a bcrypt hash — never in a recoverable form
Customer email, GSTIN, address and your notesNot separately encrypted — stored as ordinary database columns
Customer date of birth, gender and tagsColumns exist in our database but this build cannot collect them — the app has no field for them and never sends them. Listed only so the table matches what our database actually contains
Bills, line items, amounts, product and stock dataNot separately encrypted — stored as ordinary database columns

The encryption key is supplied to the server at startup from its environment. The server refuses to start if that key is missing, shorter than 32 characters, or one of a blocklist of placeholder values. All traffic between the app and our servers is over TLS.

4. Third parties in this build

These are the third parties your data can reach through the app. Each section below says when that party is contacted and what reaches it — some only when you choose to send something, some by the app on its own without asking, and some only in certain builds. Please do not assume which is which: the section says. There is no advertising SDK, no attribution or install-tracking SDK, and no third-party analytics SDK in the build.

4.1 Razorpay — card and UPI payments

Razorpay Software Private Limited handles two kinds of payment in the app: your own QuickBill Pro subscription, and — if you choose Razorpay as the payment method on a customer's bill — that customer's payment.

Whoever is paying, their card, UPI or wallet credentials are entered into Razorpay's own checkout and go to Razorpay. They are never sent to us and we never store them. We receive an order identifier, a payment identifier and the success or failure result.

When you take a customer's payment this way, that customer's phone number and email address — where you have saved them — are sent to Razorpay to pre-fill the checkout, and are also recorded against the order on our own servers. If you would rather not pass a customer's contact details to Razorpay, take the payment by another method. Razorpay's own privacy policy governs what it does with all of this.

4.2 Google LLC — fonts fetched when you print or export a PDF

When you print a receipt or export a PDF report, the app downloads the Noto Sans typeface from Google's font service (fonts.gstatic.com) and caches it. That request discloses your device's IP address and user-agent to Google. It carries none of your business data — no bill, customer or product information is included. If the download fails, the app falls back to a built-in font and printing still works.

4.3 Google LLC — Google Drive backup

Read this one carefully — backups are not encrypted, and the upload is automatic.

QuickBill Pro can copy your database to your own Google Drive. How this actually behaves in the current build:

What is true regardless: the file goes to your Google account, not ours. We ask Google only for permission to manage the files this app itself creates in your Drive — we cannot see the rest of it. We do not receive a copy of your backup.

If you would rather not have this: turn off automatic backup in Settings → Backup & Restore, or do not connect a Google account. You can delete existing backups from the QuickBillPro Backups folder in your own Google Drive at any time. We are fixing the encryption gap; when that change ships, this section will be updated to describe it, and not before.

4.4 Sentry — crash reports

Crash reporting uses Sentry, and it is switched on only in builds where a Sentry endpoint has been configured when the app was compiled. In a build where it has not been, no crash data is collected or transmitted at all, and §4.5 does not apply either. In a build where it has, you can switch it off at Settings → About → "Share anonymous crash reports".

A crash report contains the error message, the stack trace, an anonymous identifier, and device and OS details. Sentry also receives performance samples from a fraction of your sessions — timings for how long parts of the app took, carrying no bill or customer data. Before a report is sent, the app rewrites the error message text, the attached breadcrumb messages and the user field to redact email addresses, Indian phone numbers, GSTINs and long digit sequences such as account numbers. That redaction covers those fields and not every field an error report can carry, so we do not claim a crash report can never contain a fragment of your data. Bills, customer records, invoices and product data are never deliberately attached to a crash report.

4.5 Feedback you choose to send us

If you use Settings → Send Feedback, the text you write, together with your app version and a description of your device, goes to each of these:

Three honest caveats about the current build. First, the redaction described in §4.4 is not applied to feedback — whatever you type is what we receive. Second, the "Share anonymous crash reports" switch does not stop feedback being sent. Third, the email is composed whether or not crash reporting is on. Please do not paste a customer's phone number, name or a full invoice into the feedback box. We have recorded the first two as defects to fix.

4.6 WhatsApp / Meta — when you send a bill or a reminder

QuickBill Pro can send things to your customers over WhatsApp — to one customer, or to many at once. What is handed on depends on whether you are sending a message or a file, so the two are described separately below.

Sending a message

Wherever the app offers to send something over WhatsApp as a message — the "Text WhatsApp" button on a bill, a payment reminder, a low-stock alert, or a bulk send to several customers at once — all of the following hold, whatever the feature is called and however your device is set up:

We do not set out the exact technical route here. It varies with your device, with whether WhatsApp is installed and with whether a number is saved, and a description detailed enough to be worth reading would be long and would go out of date. The points above are true of every WhatsApp message the app can send; if any of them stops being true, this page changes.

Sending a file

This covers "PDF WhatsApp" and "Image WhatsApp" on a bill. The app writes the invoice out as a PDF, or renders a picture of the receipt card as a PNG, and hands over that file along with the message text. An image of a receipt carries the same customer name, items and totals as the PDF does — it is not a lesser disclosure for being a picture. Here the platforms differ:

When the share sheet is used, the file goes wherever you choose to send it — WhatsApp, email, a cloud drive, any app on your device. This policy cannot describe that recipient, because we do not know it. Whatever you pick handles the file under its own privacy policy from that point.

This is the feature working as intended, and it is your decision each time. It does mean that from the moment you send, the customer's phone number and the contents of that bill are handled by WhatsApp (Meta) under Meta's own privacy policy, or by whichever app you picked from the share sheet — not by us. We have no control over and no visibility into what happens to the message after it leaves the app.

4.7 Cloudflare, Inc.

Our domains sit behind Cloudflare, which proxies requests and terminates TLS. Cloudflare processes connection metadata, including your IP address, in order to route and protect the traffic.

4.8 Your device's speech service — voice billing

Voice input uses your device's built-in speech recognition, not a service of ours. Depending on your device, its settings and its Android or iOS version, that recognition may run on the device or may be performed by the operating system's speech provider (Google on Android, Apple on iOS). QuickBill Pro receives only the resulting text. We do not record, store or transmit audio.

4.9 Text recognition from photos runs on your device

Scanning a printed menu or price list to create products uses Google ML Kit text recognition, which runs entirely on your device. The photograph is not uploaded to Google or to us. The same is true of barcode and QR scanning.

5. What we never do

6. Device permissions and why the app asks

PermissionWhy
CameraScanning barcodes and QR codes, and photographing products or a printed menu
Microphone / speech recognitionVoice billing and voice product search — only while you hold the voice control
Photo library (iOS)Choosing an existing photo for a product, and saving images you export. Android needs no storage permission for this; note that a saved invoice PDF still goes to the public Downloads folder there — see §2
Bluetooth (scan and connect)Finding and printing to a thermal receipt printer
Location (Android)Required by Android to permit Bluetooth device scanning on older OS versions. Not used to determine where you are.
InternetSync, card and UPI checkout, Drive backup, sending over WhatsApp, and emailing feedback
Local network (iOS)Discovering printers on your shop's network, and syncing data

7. Retention

Deleting a record inside the app hides it and stops it syncing, but the row itself remains in the local database — see §10. What does remove data from the device: Settings → Clear transactional history, which erases your customers, bills, payments, held carts, returns and loyalty history for the store you are in while keeping your products, categories and settings; and uninstalling the app, which removes everything in its private storage. Neither reaches copies that live outside the app — §8 covers those, and they include one Android makes on its own.

For data on our sandbox servers during the closed beta, we are being deliberately plain: we have not yet automated retention limits. Records we hold are kept until you ask us to delete them, or until the closed beta ends and the sandbox environment is torn down, whichever comes first. When automated retention takes effect for the production service, this page will be updated before it does.

Where we are required to retain invoice and tax records under Indian law, we keep the financial record and remove the personal details attached to it.

8. Deleting your data

During the closed beta, deletion is handled by us, by hand, on request. There is no self-service delete button in this build, and we would rather tell you that than point you at one that does not exist.

To delete data held on our servers:

To delete data on your device, these are the options that actually work. Deleting individual records inside the app is not one of them — that hides a record without removing it (§10).

Neither one empties the pending-changes queue. "Clear transactional history" does not touch it, so entries already queued for sync — which can carry customer names and phone numbers — remain on the device until the app is uninstalled. If your aim is to leave nothing behind, uninstall.

And neither is a per-customer delete. There is still no way to remove one person's record while keeping the rest (§10).

Uninstalling is not the end of it. These copies live outside the app and survive it — check each one that applies to you:

9. Your rights

Under the Digital Personal Data Protection Act, 2023 you may ask for a summary of the personal data held about you and how it is processed; ask for it to be corrected or completed; ask for it to be erased; nominate someone to exercise these rights on your behalf; and complain about how it is handled.

Who you exercise those rights against depends on whose data it is (§1):

Either way, if the response does not satisfy you, you may complain to the Data Protection Board of India.

10. Data about other people that you enter

When you save a customer's name and phone number, you are the one deciding to collect it — we process it on your behalf so that the app can show it back to you. Please only enter details you are entitled to hold, and tell people if they ask. The same applies to the staff and supplier contacts you enter: you decide to collect them, they are subject to the same soft delete described below, and for suppliers there is no server copy at all (§3.2) — so the device copy is the only one.

If a customer asks you to erase their details, deleting the record in the app is not enough, and we would rather tell you than let you believe otherwise.

Deleting a customer in the app hides the record and stops it syncing. It does not remove it: the name, phone number and anything else you saved stay in the app's database on your device, and a copy also sits in the app's pending-changes queue. Only uninstalling QuickBill Pro clears them from the device.

Email [email protected] with the person's name or number and your store name, and we will erase our server copy and confirm when it is done. That part we can do.

The copy on your device is the part we cannot fix for you today, and we are not going to pretend otherwise. There is no way in this build to remove one person's record from your phone while keeping the rest. What exists is all-or-nothing: Settings → Clear transactional history erases every customer, bill and payment for the store you are in — keeping your products and settings, so it is far less drastic than uninstalling, but it also removes every other customer's record along with the one you were asked about. It does not empty the pending-changes queue either, so queued entries carrying names and numbers stay until you uninstall (§8). Note it does not touch staff or supplier contacts — those stay until uninstall.

So the honest position is: we can erase our copy; you can erase all of your customer records or none of them; and a per-customer delete does not yet exist. We have recorded that as a defect to fix. If you are asked to account for it, say exactly that — it is better than a claim that does not hold. Deleting the record in the app on its own does not satisfy an erasure request under the Digital Personal Data Protection Act.

11. Children

QuickBill Pro is business software for shop and restaurant owners and their staff. It is not directed at children and we do not knowingly collect personal data from anyone under 18. If you believe we have, write to [email protected] and we will delete it.

12. Changes to this policy

We will update this page when what the app does changes. The changes we already expect are: the beta moving off the sandbox onto a production backend; crash reporting being switched on for the beta build (§4.4, §4.5); encryption of backups (§2, §4.3); bringing feedback under the crash-report switch and its redaction (§4.5); bundling the printing fonts into the app, which removes the Google font download described in §4.2 entirely; an in-app way to delete your data (§8); a delete inside the app that actually removes a record from the device rather than hiding it (§10); automated retention limits (§7); stopping the WhatsApp message text from reaching Meta before you confirm, on a device without WhatsApp installed (§4.6); and correcting how saved phone numbers are converted, so a message can no longer open addressed to the wrong number (§4.6). Each will be described here when it ships, not before — we would rather this page lag reality by a day than describe something the app you are running does not do. The "last updated" date at the top always reflects the current version.

13. Contact

Surya AI Technologies Pvt Ltd
CIN U62099KA2026PTC220007
Bengaluru, Karnataka, India
Support and deletion requests: [email protected]
Data Protection Officer: Kishore Rajendra — [email protected]