Privacy Policy
Last updated: September 1, 2026 · Handsome Notes
Handsome Notes (“we”, “the app”) helps field service businesses turn Jobber job notes and photos into clean, structured documentation. This policy describes what we collect, why, and your choices.
What we collect
- Account data: name, email, company, phone, password (stored hashed).
- Jobber data: jobs, visits, notes, and attachments you authorize via OAuth (read/write as configured).
- Voice dictation: audio recordings from the Keel Voice Trigger companion, transcripts, optional GPS coordinates.
- Processed output: structured notes we write back to Jobber and Archive records we store locally.
- Technical data: session cookies, rate-limit logs, webhook delivery logs.
How we use data
- Process and rewrite field notes per your templates and settings.
- Run OCR and image description on photos you attach to jobs.
- Transcribe voice notes and match them to jobs.
- Authenticate you, send account emails, and operate support chat.
- Improve Fair Copy Bias with operator-approved feedback (not automatic retraining on your data without review).
Subprocessors
We use trusted providers to operate the service:
- OpenAI — note rewriting, vision/OCR, Whisper transcription.
- Stripe — subscription billing when you subscribe (customer, invoices, payment method).
- Resend — transactional email (verification, password reset).
- Cloudflare — Turnstile bot protection and tunnel/hosting.
- Slack (optional) — internal support notifications when configured.
We do not sell your personal information.
Retention
- Archive and voice note data are kept while your account is active unless you delete them.
- Dictation audio files are stored on our servers until deleted via account data removal.
- Auth tokens and webhook logs are retained for operations and security; connection tokens are cleared on disconnect.
Your choices
- Disconnect Jobber at any time from Account settings.
- Export your Handsome Notes data (Account → Export data).
- Delete your Handsome Notes data (Account → Delete data). Jobber CRM records are not removed.
- Contact [email protected] for questions or requests.
Security
Passwords are hashed. Jobber tokens are encrypted at rest. Public deployments require HTTPS, Turnstile on auth forms, and webhook signature verification in production.