Legal
Privacy Notice
Last updated: July 14, 2026
One Person exists to run your business, not to mine it. This notice explains what we collect, why, who touches it, and the controls you have. No legalese where plain words will do.
1. What we collect
Account data — your name, email, and password (stored as a salted hash; we can't read it). If you sign in with Google, we receive your name and email from Google instead.
Business data — what you put into the product to run your business: your business profile, branding (logo, colors, templates), customer records, invoices, and documents. This is your data; we process it only to provide the service.
Payment data — if you subscribe, our payment processor handles your card. We never see or store full card numbers; we receive only what's needed to manage your subscription (plan, status, billing events).
Technical basics — standard server logs (IP address, browser type, timestamps) used for security and keeping the service running.
2. What we use it for
- Providing the product: storing your records, rendering documents, sending the invoices you ask us to send.
- Keeping your account secure: sessions, sign-in, fraud and abuse prevention.
- Transactional email: welcome messages, receipts, and invoice delivery on your behalf.
- Improving the product from aggregate, de-identified usage.
We do not sell your personal data, and we do not use your business data (or your clients' data) for advertising.
3. Your clients' data
The customer records and invoice details you store belong to your business — you're the controller of that information, and we process it on your instructions. When you email an invoice or share a link, we deliver it to the recipients you chose and nothing more.
4. Who we share with (processors)
We use a small set of infrastructure providers to run One Person:
- Database hosting — encrypted storage of your account and business data.
- Resend — delivers transactional and invoice emails you trigger.
- Dodo Payments — processes subscriptions and card payments.
- Google — only if you choose “Sign in with Google.”
Each provider receives only what it needs for its job. Beyond these, we disclose data only if the law requires it, or to protect the service and its users.
5. Cookies
We use two essential, httpOnly cookies to keep you signed in — and today, that's it. No advertising cookies, no cross-site trackers. Details and preferences live on the Cookie Settings page.
6. Public share links
Invoice share links use long, unguessable tokens and show a read-only view. Anyone with a link can see that invoice — so share links the way you'd share the document itself. Deleting an invoice disables its link.
7. Security
Data is encrypted in transit (TLS) and at rest with our hosting providers. Passwords are hashed with bcrypt. Sessions use short-lived tokens in httpOnly cookies. Access to production systems is limited and audited. No system is perfect — if we ever discover a breach affecting your data, we'll notify you without undue delay.
8. Retention
We keep your data while your account is active. Delete your account and we delete your business data from production systems, with residual copies in encrypted backups expiring on their rotation schedule. Billing records are kept as long as tax and accounting law requires.
9. Your controls
- Export — download your clients, activity, and business profile anytime from Account → Export.
- Correct — edit your profile, business, and records directly in the product.
- Delete — remove your account and its data from Account → Delete.
- Ask — for access, correction, deletion, or portability requests the product doesn't cover, email us and we'll handle it.
Depending on where you live (for example the EU/EEA, UK, or California), these controls are also legal rights — we honor them regardless of geography.
10. Children
One Person is a business tool for adults. It isn't directed at children under 16, and we don't knowingly collect their data.
11. Changes to this notice
If we change how we handle your data in a meaningful way, we'll update the date above and tell you in the product or by email before the change applies.
12. Contact
Privacy questions or requests: privacy@oneperson.app.