Legal

Privacy Policy

Last updated 16 August 2026

Who operates this service

Quote Engine (quoteengine.dev) is operated by Yukesh Dhakal. Questions about this policy or your data can be sent to ukeshdhakal11@gmail.com.

What we collect

Account data you provide directly: name, email address, and a bcrypt-hashed password (if you sign up with email/password rather than Google).

Business data you enter to use the product: business name, jurisdiction, branding (logo, accent colour), terms text, and the quotes, line items, and customer details you create.

If you sign in with Google, we receive your name, email address, and a Google account identifier via Google's ID-token sign-in flow — nothing else, and no password is stored for that account.

Google Gmail access (gmail.send)

If you choose to connect Gmail to send quotes directly from Quote Engine, you'll go through a separate Google consent screen requesting the gmail.send scope only. This is a narrow, "send-only" permission:

  • We can compose and send an email — with your quote PDF attached — from your connected account, only when you click "Send" on a specific quote.
  • We cannot read, search, or view any message already in your mailbox. The gmail.send scope does not grant that access, and we don't request any scope that would.
  • No Quote Engine employee or automated system reads the content of your Gmail account. We only see the message we ourselves composed for that one send.
  • Your Gmail refresh token is encrypted at rest (AES-256-GCM) and is used solely to obtain short-lived access tokens for that send action.
  • You can disconnect Gmail access at any time from within the app, which deletes the stored token; you can also revoke access directly from your Google Account's security settings.

Quote Engine's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, do not sell it, and do not use it for any purpose beyond sending the quote email you explicitly requested.

Where data is stored

Application data (accounts, businesses, quotes) is stored in a managed Postgres database (Supabase). Generated PDF files and uploaded logos are stored on the application server's attached disk. The application server runs on Fly.io; the web app is served by Vercel. These are infrastructure subprocessors, not third parties we share your business data with for their own purposes.

How we use your data

  • To provide the service: creating and rendering your quotes, generating PDFs, and sending them when you ask us to.
  • To authenticate you and keep your business's data isolated from every other business on the platform.
  • To operate and secure the service — e.g. rate limiting and abuse prevention.

We do not sell your data, and we do not use your business or customer data to train any model.

Data retention and deletion

We retain your account and business data for as long as your account is active. To request deletion of your account and associated data, email ukeshdhakal11@gmail.com and we'll action it within a reasonable time, subject to any records we're legally required to retain.

Changes to this policy

If this policy changes materially, we'll update the date at the top of this page. Continued use of Quote Engine after a change constitutes acceptance of the updated policy.