Skip to content
Quoting Free
InvoiceQuote
TemplatesHistoryClientsSign inAccount
EN EnglishES EspañolFR Français
Menu
TemplatesHistoryClientsSign inAccount
InvoiceQuote

Privacy policy

Effective September 26, 2026

On this page

  1. Who we are
  2. What we collect
  3. How we use and share it
  4. Analytics
  5. Cookies and local storage
  6. Do Not Track and Global Privacy Control
  7. Third-party tracking
  8. Your choices, export and deletion
  9. Retention
  10. Children
  11. Security
  12. Languages
  13. Changes to this policy
  14. Contact

In short

  • You can make and download invoices and quotes without an account. We never store your documents unless you sign in.
  • We measure how the sites are used with PostHog, including a summary of each PDF you download: item names and units as you typed them, but never the names or contact details you enter for your business or your client.
  • We don’t sell your personal information, share it for cross-context behavioral advertising, or show you targeted ads.
  • If your browser sends Do Not Track or Global Privacy Control, analytics never loads, and everything else still works.
  • With an account, you can edit, export and delete your invoices, quotes and clients, and delete your account, at any time.

Who we are

Invoicing Free (invoicingfree.com) and Quoting Free (quotingfree.com) are free invoice and quote tools for trades and small businesses. Augment AI Labs Corporation (“we”, “us”) makes them as part of Crewtron.

This policy covers both sites, in every language. It doesn’t cover crewtron.ai or other sites we link to, which have their own policies.

What we collect

When you visit

Without an account, your document is never stored on our servers. Your browser makes the PDF, and when you upload a PDF to reopen it, your browser reads it without sending it to us.

While you use the sites, our analytics provider, PostHog, collects:

  • Pages: the address of each page you view and of the page that linked you here, with everything after a “?” or “#” removed (except in the cookie fallback described under Cookies and local storage).
  • Campaign tags: tags in the link that brought you here, such as utm_source and utm_campaign. Ad-click identifiers, such as gclid, are masked.
  • Clicks and time on page: clicks on links and buttons (without their text), how long you stay on a page and how far you scroll. Heatmaps show where on a page people click, move the pointer and scroll.
  • Session recordings: a visit may be recorded as a replay of the page’s layout and your pointer movements, clicks and scrolling. All text and every form field are masked, so a recording never shows what you type or what the page says.
  • Actions in the tools: for example, starting a document, adding an item, choosing a type of work, getting a suggested tax rate or changing it, changing the language, downloading or uploading a PDF, and seeing or clicking an ad.
  • Device and browser: your type of device, operating system, browser, screen size, language and time zone.
  • Approximate location: such as your city, region and country. PostHog works this out from your IP address and then discards the IP address, so it isn’t stored with your events.
  • Document summaries: each time you download a PDF, a summary of the document. It has the document’s type, languages, currency, tax rate, discount type, total and number of items; the type of work you chose and the state used for the tax rate (your client’s state, or else yours, unless you pick one); whether it’s paid or was turned from a quote into an invoice; and how long it took to make.

For each item, a document summary includes its name as you typed it (up to 200 characters), its unit, quantity, unit price, type (labor, materials or other) and whether it’s taxable. It never includes business or client names, email addresses, phone numbers or street addresses, notes, logos or an item’s details.

Because item names and units are sent as you type them, please don’t put personal details, such as a client’s name or address, in them.

When you sign in

  • Email address and language: we use them to sign you in with one-time codes and to write to you in your language.
  • What you save: your business profile (name, contact details, address, license number, logo, payment link and default settings), your clients (name, email, phone, address and notes), and your invoices and quotes.
  • Email delivery notices: if an email we send you bounces, is rejected or is marked as spam, our email provider tells us, with your address and the email’s headers, such as its subject. We use this only to fix delivery.

When your client opens a quote link

If you share a quote, your client opens it through a private link, which shows them the quote and your business details as printed on it. We record when they first view it. If they accept it, we record the name they type, the time and the options they choose, and we try to email you that it was accepted.

Your client’s visit is measured by analytics like any other visit, with the private part of the link hidden, except in the cookie fallback described under Cookies and local storage.

What your PDFs carry

Each PDF you download also carries a machine-readable copy of all of the document’s data except your logo and a quote’s private link. That includes your business and client details, every line and the notes. This copy lets you reopen the document by uploading the PDF.

Anyone you send the PDF to can read this data, so send it only to people who should see the whole document.

How we use and share it

We use what we collect to:

  • run the tools: sign you in, save your work, show it on any device and send the emails described below;
  • learn how the tools are used, such as which features, items, types of work and tax rates people use and where they get stuck, so we can improve them;
  • keep the service secure and working, and stop abuse.

We send only two kinds of automatic email: sign-in codes and, if you share quotes, a notice when a client accepts one. We don’t send marketing email, and we otherwise write to you only to answer a message you send us or when the law requires it.

Service providers

These service providers process information on our behalf:

  • Amazon Web Services, Inc. (AWS) stores our database, runs sign-in (Amazon Cognito) and sends our email (Amazon SES) in its US East (N. Virginia) region, and delivers the sites through its worldwide CloudFront network, which also relays analytics to PostHog. See the AWS Privacy Notice.
  • PostHog Inc. runs our analytics on its US Cloud, hosted in the United States. See PostHog’s privacy policy.

No selling, no targeted ads

We don’t sell your personal information, share it for cross-context behavioral advertising, or use it for targeted advertising.

Other disclosures

We may disclose information when the law requires it, or to protect our users, the public or the service from fraud or harm.

If Augment AI Labs Corporation is involved in a merger, sale or reorganization, the sites and the information they hold may pass to the new owner, subject to this policy.

Your clients’ details

Without an account, the names, email addresses, phone numbers and street addresses you enter for your clients never reach us, unless you also type them into an item’s name or unit (see What we collect). They stay with you: in the page you have open, in the PDFs you make, and, if you turn a quote into an invoice, in the link that carries it to Invoicing Free, which your browser may keep in its history.

When you sign in and save clients or documents, we process your clients’ details on your behalf, as your service provider. You decide what to enter, and you must have the right to enter it. If your client has a question or request about their details, they should contact you.

Where information is stored

We store information in the United States. If you use the sites from another country, such as Canada, your information is processed in the US and may be accessible to US courts and authorities under US law.

Analytics

PostHog is the only analytics tool on our sites. Your browser loads PostHog’s code from our sites and sends analytics to our sites, which pass it on to PostHog. Your browser never contacts PostHog directly.

We set PostHog up to collect as little as it can:

  • Text and form fields are masked. Web addresses lose everything after a “?” or “#”, and the private part of a quote link is hidden, except in the cookie fallback described under Cookies and local storage.
  • Page titles are dropped.
  • Recordings leave out the browser console and anything drawn on a canvas.
  • The sign-in page, where you type your email and code, never sends PostHog your email or code, or PostHog’s own records of that page’s clicks, heatmap data or recordings. About that page, PostHog learns only that you visited it, how long you stayed and how far you scrolled, and receives our own events, such as a sign-in starting or finishing or a click on the Crewtron link, and the link to your account’s random ID described below.

Until you sign in, your events are tied only to the random ID in your browser. When you sign in, this browser’s events, earlier ones and document summaries included, are linked to your account’s random ID, never to your email address. When you sign out, your events get a new random ID, but PostHog’s device ID stays in your browser and is sent with later events, so PostHog can still connect them to your account until you clear your browser’s storage.

Cookies and local storage

We use no advertising cookies. Here is what our sites keep in your browser:

  • PostHog’s entry in local storage: random IDs, the site and language, details of your current session, PostHog’s own settings, and the addresses of the first page you visited and of the first page of your current visit, with the pages that linked you to them. These addresses stay in your browser; the events sent to PostHog are cleaned first, as described above.
  • Session storage: PostHog keeps IDs for the current tab, the campaign tags and the address of the page that linked you here, and recording data it hasn’t sent yet. Your browser clears them when you close the tab.
  • A cookie, only as a fallback: if your browser blocks local storage but allows cookies, PostHog keeps the same entry in a cookie on our site instead, for up to a year. If your browser blocks session storage too, the cookie can also hold the campaign tags and the address of the page that linked you here. Your browser sends that cookie with each request to our sites, and our sites pass it on to PostHog with your analytics, so PostHog also receives the addresses the cookie holds, including anything after a “?” and the private part of a quote link.
  • Your sign-in: when you sign in, your browser keeps a sign-in token, your email address and your account’s random ID in local storage, so you stay signed in for up to 30 days. Signing out removes them.
  • A sign-in you’ve started: when you ask for a code, your browser keeps your email address and a reference to that sign-in in local storage, so the link in the email can finish it in another tab. The reference stops working after 15 minutes. Both are removed when you finish signing in; otherwise they may stay until you start another sign-in or clear your browser’s storage.

You can clear all of these in your browser’s settings at any time. The tools keep working; you get a new random ID and are signed out.

Do Not Track and Global Privacy Control

If your browser sends a Do Not Track (DNT) or Global Privacy Control (GPC) signal, our sites never load PostHog. No analytics events, heatmaps, recordings or document summaries are collected, and PostHog stores nothing new in your browser.

We check for these signals each time a page fully loads. If you turn one on while a page is open, reload the page.

Everything else works the same: you can make, download and reopen documents, and sign in. If you sign in, we still keep your account data, because the service needs it.

We don’t sell personal information or share it for cross-context behavioral advertising, so there is nothing else for GPC to opt you out of.

Third-party tracking

Our sites don’t allow any other company to collect information about your activity over time or across websites. Our pages load no advertising networks, social media pixels, embedded videos or third-party fonts. PostHog collects information only for us, as described above.

Our ads are our own ads for Crewtron, built into the page. They’re chosen by site and language, never by who you are. We count when an ad is seen or clicked, as part of our analytics. An ad opens crewtron.ai in a new tab, where Crewtron’s own privacy policy applies.

When you follow a link from our sites to another site, that site learns only which of our sites you came from, not the page you were on (and, from one of our ads, which ad).

Your choices, export and deletion

Everyone can:

  • turn on Do Not Track or Global Privacy Control to stop analytics;
  • clear the browser storage described above to reset PostHog’s random ID;
  • email us at privacy@invoicingfree.com to ask what we hold about you, or to correct or delete it. We answer within 30 days, and we may ask you to confirm the request comes from you.

With an account, you can:

  • review and edit your profile, clients, invoices and quotes at any time;
  • download a CSV export of your invoices, quotes and clients;
  • delete your account.

Deleting your account deletes your profile, clients, invoices and quotes, and your sign-in. The following stay:

  • Analytics events and the account’s analytics profile, in PostHog under your account’s random ID.
  • Copies in our encrypted database backups, for up to 35 days, and AWS’s records of your sign-in requests, for up to 90 days. After that, nothing we keep links your account’s random ID to your email address, though PostHog’s device ID stays in your browser until you clear its storage (see Analytics).
  • Email delivery notices we received about your address, and your address on our email provider’s do-not-send list if an email to it bounced permanently or was marked as spam, as described under Retention.
  • PDFs you’ve downloaded or sent, wherever they are.

If a business that uses our tools holds your details, please contact that business.

These choices are open to everyone, wherever you live.

Retention

  • Account data (your email, language, profile, clients, invoices and quotes, including quote views and acceptances): until you delete it or your account.
  • After account deletion: only a marker holding the account’s random ID, so a device that’s still signed in can’t save to it.
  • Unfinished sign-ins (an email address and language entered without the code): until you ask us to delete them.
  • Database backups: encrypted, and kept up to 35 days.
  • Server logs: 30 days. They record what our services did, not your documents or sign-in codes.
  • Firewall samples: our firewall keeps a small sample of requests, including IP addresses, for 3 hours, to spot attacks.
  • Sign-in request records: AWS keeps a record of each sign-in request, with its IP address, browser, language and your account’s random ID, for 90 days, as a security audit trail.
  • Email delivery notices (bounces, rejections and spam reports, which include your address): in our operations mailbox until we delete them.
  • Addresses our email can’t reach: if an email to your address bounces permanently or is marked as spam, our email provider (Amazon SES) keeps your address on a do-not-send list, so we don’t email it again, until we remove it.
  • Messages you send us, such as privacy requests: in our mailbox until we delete them.
  • Analytics events, including document summaries: 1 year.
  • The analytics profile of a signed-in account (its random ID, with the approximate location, device and browser, first and latest page, referrer and campaign tags PostHog recorded): until we delete it.
  • Session recordings: 30 days.
  • In your browser: as described under Cookies and local storage.

Children

Invoicing Free and Quoting Free are tools for businesses. They aren’t directed to children under 13, and we don’t knowingly collect personal information from them. If we learn that we have, we delete it.

If you believe a child has given us personal information, email privacy@invoicingfree.com.

Security

  • Our sites are served only over HTTPS (TLS): plain HTTP is redirected, and browsers are told to always use HTTPS.
  • Our database and its backups are encrypted at rest.
  • You sign in with one-time codes sent by email, not passwords. Codes are encrypted with a key held in AWS Key Management Service, decrypted only by the service that emails them, and never written to logs.
  • We log as little as we can.

No system is perfectly secure. If a breach affects your personal information, we’ll tell you as the law requires.

Languages

This policy is available in English, Spanish and French. The English version governs; the Spanish and French versions are translations. If they differ, the English version applies.

Changes to this policy

We may change this policy as the tools change. When we do, we post the new version on this page with a new effective date, shown at the top. The new version applies from that date.

Contact

For questions or requests about privacy, email our privacy lead at privacy@invoicingfree.com.

Augment AI Labs Corporation operates Invoicing Free and Quoting Free.

Free invoices and quotes for trades and small businesses. No signup.

Run your whole business with Crewtron

Free tools

  • Invoice generator
  • Quote generator

Company

  • About
  • Privacy
  • Terms

Language

  • English
  • Español
  • Français