Privacy Policy
Last updated: 26 July 2026 · Effective date: 26 July 2026
1. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account | Email, display name, user ID; if you sign in with Google/Apple, the basic profile they return | You / Firebase Authentication |
| Your work records | Jobs (title, amount, dates, notes), clients (name, WhatsApp number you enter), categories, currency | You enter in the app |
| Voice input | Short audio clips you record to add a job | You (processed, not stored — see §3) |
| Portfolio / profile content | Images you upload, public profile text and slug you create | You (may be public if you choose — see §4) |
| Subscription | Purchase status, plan, trial state (no card numbers) | Apple / Google / RevenueCat / Stripe |
| Calendar sync | A private feed token that lets your calendar app read your jobs | Generated for you |
| Device / usage | App diagnostics, push notification token, approximate technical data | Automatically |
We do not collect payment card numbers — payments are handled by Apple, Google, or Stripe.
2. How we use it
- Provide the core service: record jobs, track unpaid amounts, calendar sync.
- Send payment reminders on your behalf via WhatsApp (only when you enable it, using the client number you enter).
- Provide AI features you trigger (voice-to-job, portfolio/CV/post generation).
- Manage your subscription and entitlements.
- Send you notifications you opt into; maintain security and prevent abuse.
We do not sell your personal data, and we do not show third-party advertising.
3. Voice and AI processing (important)
When you use voice input or AI generation, the relevant content (audio, or the job/profile text) is sent to Google (Vertex AI / Gemini) to produce the result. Audio is not stored by us — it is processed transiently and discarded. AI-generated text is stored only as part of your own records. This processing may occur on Google servers outside Hong Kong (e.g. the United States); see §6.
4. Public content you choose to share
If you build a public profile / portfolio, the content you mark public (including images and text) becomes accessible to anyone with the link (/p/<your-slug>). Do not mark content public if it contains information you or your clients (including images of people or minors) do not want disclosed. You can unpublish or change visibility at any time.
5. Who we share data with (processors)
We use trusted service providers that process data on our behalf:
- Google / Firebase — authentication, database, hosting, cloud functions.
- Google Vertex AI (Gemini) — voice and AI features (§3).
- RevenueCat — subscription management (App Store / Play).
- Stripe — website subscription payments.
- Apple / Google Play — in-app purchases.
- Meta / WhatsApp (Cloud API) — delivering reminders you enable.
Each processes data under its own terms and only as needed to provide its function.
6. International transfer
Some providers (notably Google Vertex AI, RevenueCat, Stripe, Meta) process data outside Hong Kong, including in the United States. By using features that rely on them, you understand your data may be transferred and processed abroad, subject to those providers’ safeguards.
7. Deleting your account & retention
We keep your account and work records while your account is active. When you delete a client or job in the app, we remove or redact the associated records.
Deleting your whole account. You can delete your account yourself at any time from within the app (Settings → Delete account). Deletion works as a soft-delete with a 30-day grace period:
- As soon as you request deletion, your account is deactivated: your public pages (profile / portfolio, payment and review links, calendar feed) go offline, and payment reminders and daily digests stop.
- If you sign back in within 30 days, your account and data are fully restored.
- After 30 days your account and data are permanently deleted and cannot be recovered — including your work records (jobs, clients, categories), uploaded images and portfolio content, public pages, the subscription and AI-usage records we hold, and your sign-in credentials.
Deleting your account does not automatically cancel a paid subscription bought through the App Store, Google Play, or Stripe — cancel those separately in the relevant store or billing settings. Some data may be retained after deletion where required for legal, tax, or fraud-prevention reasons.
8. Security
We use industry-standard measures (encrypted transport, access-controlled infrastructure, server-enforced authorization). No method of transmission or storage is 100% secure.
9. Your rights
Under the PDPO you may request access to, or correction of, your personal data, and ask us to stop using it. In the app you can edit or delete jobs and clients, unpublish public content, and delete your entire account (Settings → Delete account; see §7). To exercise other rights, contact us (§11).
10. Children
Freelantant is intended for professional/business use by adults and is not directed at children. We do not knowingly collect data from children.
11. Contact
Questions or requests: cs@chothy.com.hk.
12. Changes
We may update this policy; material changes will be posted here with a new "Last updated" date.