JobWrapUp Privacy Policy

Effective date: September 3, 2026

This policy explains what JobWrapUp collects, what we do with it, who else touches it, and how long we keep it. It is written to describe how the product actually works today — not how we hope it will work later.

JobWrapUp is operated by Alex Quintero, a sole proprietor doing business as JobWrapUp ("JobWrapUp", "we", "us"), based in Orange County, California. Questions about anything here: support@jobwrapup.com.

So you know who you are dealing with: JobWrapUp is a sole proprietorship — one person, not an LLC or a corporation. "We" and "us" throughout this policy mean that business.


The short version

  • You can record yourself describing a job or use Scan Notes to photograph handwritten job notes. We turn that evidence into written job documentation.
  • Your recording is sent to Deepgram to be transcribed. Scan Notes images are sent to Anthropic to extract the writing. The transcript or extracted note text is then sent to Anthropic to write the documentation. Both companies are contractors processing data on our behalf.
  • The original recording is automatically deleted about 30 days after the job. It is not deleted immediately. During that period it sits in encrypted, private storage.
  • Original Scan Notes images are normally deleted about 7 days after their text is successfully extracted. If extraction never succeeds, an image is deleted once it is about 30 days old. Those timers are for jobs you keep — if you delete the job first, the images go then instead.
  • Job photos are different from Scan Notes. Photos you add to document the work — a panel, equipment, damage, a finished installation — are kept with the job for as long as you keep the job. They are not sent to Anthropic and are not read or analysed by AI.
  • Deleting a job deletes its pictures. Using Delete Job deletes both the photos you added to that job and the original Scan Notes images, from our storage, before the job leaves your history.
  • Transcripts, extracted note text and generated job records are retained indefinitely until you ask us to permanently delete them. Using Delete Job removes the job from your JobWrapUp history; it does not erase that underlying text.
  • We do not sell your data, we do not advertise, and we do not use third-party tracking or advertising cookies.
  • Your data is stored in Canada. Our database and file storage are hosted in Supabase's Canadian region. Other providers process data elsewhere. See Where your data is stored.
  • JobWrapUp is an early-stage product run by one person. We hold no security certifications. See Security.

1. What we collect

Your account. Your email address.

Signing in normally means we email you a link or a code, and most accounts never have a password at all. The app also offers an optional Sign in with a password option, for accounts where a password has been set — for example a sign-in that cannot receive our email.

If a password is used, it is checked by Supabase Auth, the authentication service described in Section 3. Supabase stores it hashed rather than as readable text. We do not keep a copy of it in our own database, and we cannot look up what you typed. There is no way to create, change or reset a password inside the app.

Your business details. Whatever you enter about your company: business name, contractor name, phone, email, license number, and a logo if you upload one.

People you invite. If you invite someone in your office to your company, we keep the email address you typed, who invited them and when, until the invitation is used, cancelled or expires. Before they accept, that address is the only thing we hold about them. Once they accept, they have an account like yours.

Your job recordings. The audio you record in the app.

Your Scan Notes images. Photographs of handwritten job notes that you choose to upload. These images may contain whatever is written on the page, including customer or job information.

Your job photos. Photographs you add to a job to document the work — panels, equipment, model or serial plates, damaged components, site conditions and finished installations. These are pictures of the property you were working at and may show the inside of somebody's home or business.

These are a different thing from Scan Notes images, and we handle them differently. A Scan Notes image is a page of writing we read and then throw away. A job photo is part of the job's documentation: nothing reads it, no AI processes it, and it stays with the job until you delete the job.

Extracted note text. The text and uncertainty notes produced when we read your Scan Notes images.

Transcripts and generated documentation. The text Deepgram produces from your audio, and the job documentation generated from your transcript or extracted note text — including any edits you make.

What you type about a job. Customer name, job address, job title.

Basic usage records. Timestamps, counts and status values — when a wrap-up was created, how long the audio was, whether generation succeeded, whether you regenerated a section, whether you opened your phone's Messages or Mail app with a draft. These are counts, durations and IDs. We do not put transcript text, customer names or addresses into this data.

Error logs. When something breaks we record what broke and where. Our logging deliberately strips transcript text, customer names, addresses, email addresses and phone numbers before writing a log entry.

Problem reports. If you use Report a problem in the app, we keep the category you picked and whatever you typed, along with which job you reported it from, which screen you were on and your app version. We do not attach your recording, your transcript, your photos or your customer's details — not even when you tell us the write-up was wrong. If we need to look at the job itself, we open the job.

Whatever you type is up to you, so please do not put a customer's details in that box. We keep problem reports while we are still working on what they describe, and you can ask us to delete yours.

We do not store your IP address in our own database. Our hosting and database providers keep standard server logs, which include IP addresses, as part of running the service.


2. About the people you talk about

This is the part worth reading twice.

When you describe a job out loud, you will usually say a customer's name, their address, and details about their home or business. You decide what goes into a recording. We process whatever you say.

You are responsible for having the right to record and to share that information — including complying with any recording-consent laws that apply where you work. See the Terms of Service for more.

We treat that content as confidential customer information. We do not use it to advertise to anyone, we do not sell it, and we do not use it to train AI models.

Anyone you add to your company can see it. If you invite an office user, they can read your finished jobs — including customer names, addresses and job photos — and print them. They cannot delete jobs and they cannot invite anyone else. Deciding who to add is your decision, and it is a decision about your customers' information as well as your own.


3. Who we share data with

We use a small number of outside companies to run JobWrapUp. They may only process your data to provide their service to us. We do not sell data to anyone, and we do not share it with advertisers or data brokers.

Deepgram — speech-to-text

What we send: your audio recording.

Deepgram converts it to text and returns the transcript.

JobWrapUp sends every transcription request with the parameter mip_opt_out=true. Deepgram's documentation describes this as excluding the request from Deepgram's Model Improvement Program, and states that "data from opted-out requests is retained only for the duration necessary to process the request."

That is Deepgram's published statement about their own systems, not a guarantee we can independently enforce. What we can tell you is what we control: we send the flag on every request, we have a test in our codebase that fails if the flag is ever removed, and we have confirmed it appears as mip_opt_out: true in Deepgram's request logs for our account.

Deepgram's policies: https://deepgram.com/privacy

Anthropic — generating your documentation

What we send: for a recorded job, your transcript plus the job context you entered (such as customer name and job address, where you provided them). For Scan Notes, we first send the note images to Anthropic so the writing can be extracted. We then use the extracted note text, together with the job context you entered, to generate the written sections you see.

The Scan Notes images are sent as image data, not as a public or signed storage URL.

We do not send your job photos to Anthropic. Photos you add to document the work are stored with the job and are never included in what we send for transcription, extraction or generation. No AI reads them, describes them or draws conclusions from them.

Anthropic states that, by default, it does not use inputs or outputs from its commercial products — including the Anthropic API, which is what we use — to train its models. Anthropic retains API data for a limited period under its own policies.

Anthropic's policies: https://www.anthropic.com/legal/privacy

Supabase — database, sign-in and file storage

What they hold: everything above. Your account, your job records, your transcripts, and your audio files.

Our Supabase project is hosted in Canada (Supabase's ca-central-1 region). Your account details, job records, transcripts, generated documentation and audio files are stored on servers in Canada, not in the United States.

Supabase also handles sign-in. That covers the one-time links and codes we email you and, for any account that has one, the password — which Supabase stores hashed rather than in a form we or they can read back as text.

Audio is kept in a private storage bucket that is not publicly readable. Database access is restricted per-account at the database level, so one account cannot read another account's rows.

Supabase's policies: https://supabase.com/privacy

Vercel — hosting

What they hold: the application itself, plus standard server request logs (including IP addresses).

Vercel's policies: https://vercel.com/legal/privacy-policy

Resend — sign-in emails and invitations

What we send: your email address and your sign-in code.

And, if you invite someone: the address you typed and a link to the invitation. We do not send them your company's name, your name, or anything about your jobs — an invitation email says only that somebody has invited them to a company on JobWrapUp.

Resend's policies: https://resend.com/legal/privacy-policy

Other disclosures

We may disclose information if we are legally required to, or where we reasonably need to in order to protect JobWrapUp, our users, or someone's safety. If JobWrapUp is ever sold or transferred to someone else — including if it is later moved into a company that gets formed — your data may transfer as part of that, and this policy would follow it.


4. How long we keep things

Audio: automatically deleted after about 30 days

Your original recording is deleted from our storage roughly 30 days after the job was created. A scheduled job runs once a day and deletes every recording past that mark, so in practice a file is removed on the first daily run after it turns 30 days old — not at the exact minute it crosses the line.

Recordings are not deleted immediately after you finish a wrap-up. They stay in private storage for those 30 days so that we can retry a failed transcription and investigate problems.

If you need a recording gone sooner than that, email us.

Scan Notes images: about 7 days after extraction, 30-day backstop

Once text has been successfully extracted from your Scan Notes images, the original note images are automatically deleted about 7 days after extraction. A scheduled job runs once a day, so deletion happens on the first eligible daily run rather than at an exact minute.

If extraction fails or never happens, the original image is still deleted once it is about 30 days old. This prevents an abandoned or unreadable image from remaining in storage indefinitely.

Those two timers are for jobs you keep. If you use Delete Job first, the original note images are deleted as part of that, without waiting for either one. See the section below.

Deleting the original image does not delete the extracted text or extraction notes — whether the image went on a timer or because you deleted the job. That extracted text is retained with the job record under the rule below.

Job photos: kept with the job, deleted when you delete the job

*(Delete Job also takes the Scan Notes images with it — see the end of this section.)*

Photos you add to a job stay in private storage for as long as that job is in your history. There is no timer on them. That is deliberate: a photo of a panel or a finished installation is part of the record of the work, and it is still the answer to a question that might be asked months later.

When you use Delete Job, we delete that job's photos, and its original Scan Notes images, from our storage. Both sets of pictures are removed before the job is taken out of your history — the note images first — so if the deletion cannot be completed the job stays where it is and you can try again.

For Scan Notes images this is sooner than the 7-day and 30-day timers above, not in addition to them: deleting the job is what removes them, and no timer has to run first.

This is a stronger commitment than the one below about text. The pictures do not survive Delete Job. The written record of a job does — including the text extracted from your note pages, which is kept even though the pages themselves are gone.

Transcripts, extracted note text and job records: retained until permanent deletion

Transcripts, extracted note text, generated documentation, your edits, customer names, addresses and job titles are retained indefinitely unless and until you ask us to permanently delete the applicable data.

Using Delete Job in the app removes that job from your JobWrapUp history and cannot currently be undone from the app. It does not erase the underlying data. Permanent data deletion is handled separately as described below.

Everything else

  • Account and business details: kept while your account is open.
  • Usage records and error logs: kept while we need them to run and debug the service. They contain IDs, counts and codes, not job content.

5. Deleting your data

The app has a Delete Job control. It does two different things:

  • It deletes that job's pictures from our storage — both the photos you added and the original Scan Notes images.
  • It removes the job from your JobWrapUp history. The underlying text — the transcript, the text extracted from your note pages, the generated documentation and your edits — is not erased by that action.

So Delete Job is enough if what you want removed is the pictures. If you want the written record gone as well, read on.

Deleting your account

The app has a Delete account control, in Settings. It deletes your sign-in, your name and your email address, and it takes effect immediately.

What happens to job records depends on whether anyone else is in your company, because those records belong to the company rather than to you individually:

  • If you are the last person in your company, the company is deleted with your account — every job, photo, note page and recording in it, from both the database and file storage.
  • If other people are still in your company, its jobs stay with them and your name comes off the ones you recorded.
  • If you are that company's only owner, we will not delete your account until another owner exists. We do not pick a successor for you: being in a company the longest is not the same as agreeing to run it. The app lists the companies that need a new owner and lets you choose one, and you stay an owner until the deletion itself succeeds.

We say this plainly because the alternative would be misleading: deleting your account does not, on its own, erase a working company's job history. If you need that erased as well, delete those jobs first, or ask us.

If you want us to permanently erase anything the controls above do not cover, email support@jobwrapup.com from the address on your account and tell us what you want removed:

  • the underlying data for a specific job,
  • all of your job data, or
  • your whole account and its associated data.

We will confirm when the permanent deletion request is complete. We aim to handle these requests within 30 days.

Some records may survive a deletion request where we are legally required to keep them, and backups roll off on their own schedule rather than being edited in place.

You can also ask us for a copy of the data we hold about you, or to correct something that is wrong. Depending on where you live, you may have additional rights under state privacy laws — including in California. Ask us and we will help regardless of where you live.


6. Cookies and tracking

We use cookies for one thing: keeping you signed in. They are required for the app to work.

We do not use third-party analytics, advertising networks, session replay, or cross-site tracking. Our product analytics are counts stored in our own database, described in Section 1.


7. Security

What we do:

  • Traffic is encrypted in transit (HTTPS).
  • Audio lives in a private storage bucket, not a public URL.
  • Every database read is restricted per-account at the database level, so an account can only reach its own rows.
  • Sign-in normally uses a one-time emailed link or code. The app also offers an optional password sign-in. Passwords are handled by Supabase Auth, which stores them hashed — we do not keep passwords in our own database and we cannot read the original text of one.
  • Our logs are built to exclude transcripts, customer names, addresses, phone numbers and email addresses.

What we are not claiming:

  • We do not hold SOC 2, ISO 27001, HIPAA, PCI, or any other certification or audit. We are an early-stage product and we have not been through those processes. If you need a certified vendor, we are not one yet.
  • No system is perfectly secure. We cannot guarantee that a breach will never happen. If one affects your data, we will tell you.

8. Where your data is stored

JobWrapUp is operated from the United States and intended for use in the United States. Your data is not stored only in the United States.

Your main data store is in Canada. Our Supabase project — which holds your account, your job records, your transcripts, your generated documentation and your audio files — is hosted in Supabase's ca-central-1 region, on servers located in Canada.

Our other providers process data in their own locations, which may be in the United States or elsewhere, under their own terms and their own transfer mechanisms:

  • Deepgram states that it stores data on servers in the U.S.
  • Anthropic, Vercel and Resend each operate infrastructure in multiple countries and may process data outside the United States. See the policies linked in Section 3.

By using JobWrapUp you understand that your data will be stored and processed outside the United States, including in Canada. If that is a problem for your business or your customers, tell us before you sign up — we would rather know.


9. Children

JobWrapUp is a tool for working tradespeople. It is not intended for anyone under 18, and we do not knowingly collect information from children.


10. Changes to this policy

If we change how we handle data, we will update this page and change the effective date. For anything significant — a new subprocessor, a change to retention — we will email account holders rather than quietly editing the page.


11. Contact

support@jobwrapup.com

Tell us what you need. A real person reads it.