Legal
Privacy Policy
Effective 29 September 2026. Voucht is a small product and this policy is written to match what the code actually does, not to sound reassuring.
What we store
Your account: your email address, display name and the profile fields you fill in (username/handle, headline, bio, location, links, avatar).
Your work records: project titles and descriptions, milestone titles, deadlines and amounts, the client name and client email address you enter for each milestone, delivery submissions and the timestamps of each client confirmation.
Billing: your plan, the payment provider, the subscription status and the period end date. Card and crypto payment details are handled by the payment providers; Voucht does not receive or store card numbers.
Proof page visits: when someone opens your public page we record a view with the referrer domain. We do not store visitor IP addresses: each visit is matched to a one-way hash of the IP plus that day, so we can count roughly one view per person per day and nothing more.
What a public proof page shows
Public pages are built from database views that expose a fixed column list: your name, handle, headline, bio, location, website and LinkedIn links, your calculated Trust Score, your tier, project and milestone titles, delivery dates, whether each delivery was on time, when a client confirmed it, and a masked client label such as “S***a J.”.
Public pages never show client email addresses, verification tokens, contract text, amounts, credentials or anything you did not type as a project or milestone title. Client emails exist so the confirmation link can reach the right inbox.
Verification links
When you ask for a delivery to be verified we create a random, unguessable token and email a link containing it to the client email address you provided. The link opens without a Voucht account, shows only that one delivery (project title, milestone title, deadline, your name), and stops working as soon as the client confirms it, disputes it, or the link expires. A disputed delivery is never counted in the Trust Score.
Who else processes data
- Supabase hosts the Postgres database and authentication.
- Vercel hosts and serves the application.
- Resend sends verification, reminder and billing emails.
- CREEM is the merchant of record for card subscriptions and NOWPayments for crypto subscriptions. They process payment data and their own privacy policies apply to that processing.
- Google Gemini is called only when you press “generate contract draft”, using the project and milestone details of that draft as the prompt.
We do not run advertising trackers or sell or rent personal data.
Cookies
Voucht sets first-party session cookies used by Supabase Auth to keep you signed in. There are no advertising or cross-site tracking cookies. Your browser’s sessionStorage also remembers that it already counted one view of a proof page, so refreshing the page does not double count it.
How long we keep it, and deleting your data
Work records stay as long as your account exists, because the Trust Score is calculated from them. Deleting a project removes its milestones, deliveries and the client emails attached to them, and the score recalculates.
There is no self-service delete button in the product yet. Email hello@voucht.tech from the address on the account and we will remove a project, a client record, or the whole account including its auth user, then confirm to you. We also honour requests to see or correct what we hold.
Security
Every table enforcing row-level security means an account can only read and write its own rows; server code that needs broader access uses separate service-role credentials that never reach the browser. Traffic is encrypted in transit and the database is encrypted at rest by the provider. No system is perfectly secure, so keep your password and your verification links private.
Children and regions
Voucht is a work-reputation tool for adults and is not directed at children under 16. Data is stored on the provider’s infrastructure; depending on your plan the region may change, so treat the addresses above as the place to ask where your rows live today.
Changes to this policy
If this policy changes materially we will update the effective date on this page and, where we have a working email channel, tell account holders.
Questions: hello@voucht.tech. See also the Terms of Service.