What FluxPay stores
An account record: your email address, the display name and profile fields you entered, and your sign-in provider. Everything else is work you brought to the app:
- clients and their contact details;
- invoices, their line items, and the payments recorded against them;
- quotes and proposals, including revisions and client responses;
- projects, milestones and budgets;
- vendor payables and expenses;
- time logs and the rates they were billed at;
- recurring retainer templates and the drafts they generate;
- work chains, which group those records around a client and project;
- share tokens, their expiry dates and their revocation dates;
- an activity log of edits, and the log of emails FluxPay sent for you.
What the data is used for
To operate the product: to total your invoices, to generate PDFs, to send the emails you ask FluxPay to send, to enforce access rules, and to keep the service reliable. Your ledger is not used to build an advertising profile, it is not sold, and it is not shared with third parties for their own purposes.
Where it is stored
In Firebase services — Firestore for records, Storage for uploaded files such as logos, and Firebase Authentication for sign-in. Records are scoped to your authenticated user ID and the Firestore and Storage rules restrict reads and writes to your own account.
Share links, and who can open one
Creating a share link issues a token URL. Anyone who holds that URL can open the invoice it points at, with no account and no sign-in. The payload is sanitised server-side: bank name, IBAN and SWIFT are deliberately excluded, and so are activity logs, before the public view is served.
A link is live while it has a token, has not been revoked, and its expiry has not passed. You set the expiry, including “never expires”, and you can revoke a link at any time; a revoked link stops opening immediately. Anyone with a revoked link’s URL can still see the invoice text if they kept a copy, so treat the URL as the secret.
A payment reported from a public invoice view — a name, an email address, an amount, a method and an optional reference — is written to a pending queue for you to confirm. It is not a payment until you confirm it, and no card details are collected on that page.
Your choices
You can export invoice and expense data from Settings, delete individual records from the dashboard, and revoke any share link. Those exports are CSV summaries of the invoice and expense ledgers; they are not a full copy of your workspace, so they should not be treated as a backup of everything FluxPay holds.
Account-level deletion is arranged out of band during the beta rather than through a form, because there is no support desk yet. Deleting individual records from the dashboard deletes them; deleting the account is a separate, manual process.
Beta status
FluxPay is in public beta. The privacy statement above describes the software as it is built today and will be revised when the paid tiers and the support desk arrive.
The other public document