Privacy Policy

Last updated: September 3, 2026

Introduction

Welcome to GigBook. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, store, and protect your information when you use our app.

Information We Collect

Account Information

When you create an account, we collect:

  • An account identifier assigned when you sign in
  • Email address
  • Display name
  • Legal business name (optional)
  • Phone number (optional)
  • Business address (optional)
  • VAT number (optional)

Business Data and User Content

To provide our services, we collect or process:

  • Gig information (dates, venues, fees, payment status)
  • Company and client contacts
  • Invoice data and line items
  • Payment methods including bank account details and IBAN (stored encrypted)
  • Expenses
  • App preferences and settings
  • Content you enter, select, record or upload to optional AI features, including Assistant prompts, gig-edit instructions, typed gig requests, import files, screenshots, receipt images and voice recordings

Purchase and AI-Credit Records

When you obtain or use managed AI credits, we receive or create:

  • Purchase history, including product, transaction and payment-provider identifiers, verified amount, currency, state and refund facts
  • Your AI-credit balance and append-only credit ledger
  • Limited product-interaction records for managed AI requests, such as the feature used, operation status, provider/model identifiers and metered usage

Apple, Google or Stripe processes payment details, depending on your platform and the checkout offered to you. GigBook does not retain raw payment-card details, raw store receipts or signed webhook bodies.

Automatically Collected Information

  • Device type and operating system
  • App version
  • Account-scoped device and delivery tokens when you register for push notifications or Live Activities
  • Scrubbed crash, error and performance diagnostics

How We Collect Information

We collect information directly when you create an account, enter or select data, record audio, upload or import content, make a purchase, or submit an AI request. Clerk provides the authentication and account identifiers used to sign you in. Apple, Google or Stripe sends us verified purchase identifiers and status facts after a purchase or refund event. The app automatically sends device/delivery tokens when you register notification features and sends scrubbed diagnostics when an error or sampled performance event occurs. GigBook also creates account-scoped sync, Assistant-history, managed-AI operation and credit-ledger records as you use those features.

Voice Input (Optional)

If you use managed voice gig entry, GigBook accesses your microphone only while you are actively recording. Granting AI permission does not upload a recording. After you explicitly start the managed voice action, the completed recording is sent through GigBook to the managed transcription provider when recording stops. That request also includes the bounded spelling and language hints described below. The returned transcript is shown for review before it is used to propose structured gig details.

How We Use Your Information

We use your information to:

  • Provide and maintain the GigBook service
  • Authenticate your account and keep it secure
  • Generate invoices and manage your gigs
  • Send or schedule invoice emails and record their delivery status when you ask us to
  • Sync your data across devices
  • Process the optional AI request you explicitly start and return its transcript, extraction, answer, plan or edit proposal
  • Keep Assistant conversation history and the account data you choose to save
  • Look up and save an address for a known venue when you ask the Assistant where it is
  • Route requested reminders and Live Activity updates to your device
  • Verify purchases, maintain your AI-credit balance, settle usage, support refunds and disputes, and prevent duplicate or fraudulent transactions
  • Diagnose crashes, errors and performance issues, protect the service, and fix bugs
  • Comply with legal obligations

We do NOT: Sell your data, share it for advertising, or use it for marketing purposes.

AI Features and Third-Party AI Providers

GigBook offers optional AI-assisted features: Ask GigBook Assistant, editing a selected gig from an instruction, importing gig history from files, creating gigs by voice or typed description, parsing gigs from screenshots, and extracting expenses from receipt photos or PDFs. These features only run when you actively use them, and only after you have given explicit permission inside the app (revocable at any time in Settings → AI). Granting permission alone does not start a provider request; each send follows a separate, explicit start or submit action in the relevant feature.

What is sent:

  • Ask GigBook Assistant: your prompt and recent conversation history, including compact summaries of records shown in prior Assistant results, so a follow-up can refer to those results, plus your saved timezone and current date/time context used to interpret scheduling requests
  • AI gig editing: your edit instruction and the selected gig's relevant details, including date and time, venue, company, fees, performers, notes, payment and invoice status, tax/coverage/skipped status, tips, deposit and timezone
  • Imports: the file, image or pasted text you submit, in bounded sections where necessary, plus your answers to import clarification questions
  • Gig and expense extraction: the typed gig request, gig screenshot, or receipt photo/PDF you explicitly submit
  • Managed voice transcription: the completed recording plus spelling hints drawn from up to 30 saved venue names, 30 saved musician names, 15 saved vendor names, and venue, company and performer names from your 30 most recent gigs. The final voice-hint list is de-duplicated and capped at 60 unique names; your saved app language/locale is included when it is a valid language code

The voice hints are used to preserve the spelling of names that are actually spoken. GigBook does not initiate new AI work from them in the background.

Who it is sent to and why: GigBook's server relays the disclosed content to OpenAI, GigBook's current managed AI service provider, using GigBook's provider account. GigBook sends it to fulfill the user-requested transcription, extraction, Assistant planning or gig-edit operation. OpenAI processes the content under its applicable service terms and data controls. Under the applicable OpenAI business/API agreement and data-protection terms, GigBook requires OpenAI to use it only to provide and secure the requested service or meet legal obligations, and to provide the same or equal protection described in this policy and required by applicable law. GigBook may retain an encrypted provider result and limited operation records needed for safe replay, billing and audit. GigBook stores Assistant conversations in your account history so you can reopen them, and an action you approve may save the resulting gig or expense to your account. Proposed gigs, edits and expenses are shown for review before you choose to save or apply them. Personal provider keys are retired and are never used for new AI work.

Managed AI: before work starts, GigBook reserves a server-calculated maximum from your non-expiring AI-credit balance, then settles verified usage or releases the reservation. The exact debit varies with the content you send and the managed model that runs; Credit history records the completed-task debit. Provider credentials, payment evidence and wallet data are never included in model prompts.

Purchases: Apple, Google or Stripe processes payment details. GigBook retains provider identifiers, cryptographic hashes, verified amount/state facts and an append-only credit ledger for security, refunds and accounting. We do not retain raw receipts, card details or signed webhook bodies.

Trial promotions: if GigBook issues one-time trial credits, we retain the campaign and economic-policy version, retail value, credit amount and pseudonymous wallet ledger proof needed to enforce the global budget and prevent a second grant. We do not add email matching or device fingerprinting for this purpose.

Your control: granting AI permission does not itself send data; every provider request follows an explicit start or submit action. A managed voice recording is sent when recording stops. Withdrawing consent in Settings → AI blocks new AI requests but does not cancel a request already started or delete saved account data, purchase records or credit history. Account deletion is a separate control in Settings → Profile.

Data Storage and Security

Where Your Data is Stored

  • Database: Neon PostgreSQL (cloud-hosted, encrypted at rest)
  • Authentication: Clerk (industry-standard authentication service)
  • Hosting: Vercel (serverless infrastructure)

Security Measures

  • All data transmitted over HTTPS (encrypted in transit)
  • Database encryption at rest (Neon)
  • Field-level encryption for sensitive financial data (IBAN, bank account details) using AES-256-GCM
  • Secure authentication via Clerk (OAuth supported)
  • Strict user data isolation — no user can access another user's data
  • Regular security updates and patches

Third-Party Services

We use the following third-party services. Where a company acts as GigBook's processor under applicable contracts and data-protection terms, GigBook requires purpose-limited processing, appropriate security, and the same or equal protection of personal data described in this policy and required by applicable law. A service identified below as an independent controller handles the limited information it receives under its own published terms and privacy policy rather than GigBook's processor instructions.

OpenAI (Managed AI Processing)

Receives the specific content described in the AI section above to provide the managed AI operation you request. OpenAI's business/API processing is governed by its applicable Services Agreement and Data Processing Addendum; its API data controls explain API storage and retention controls.

Resend (Invoice Email Delivery)

When you send or schedule an invoice email, GigBook sends Resend the recipient, sender, BCC and reply-to addresses used for that delivery, the subject and message body, and the completed invoice PDF, including the business, client, line-item, payment and bank details displayed in it. Resend delivers the message and returns identifiers and delivery status used to operate and troubleshoot the feature. Resend acts under its applicable service and data-processing terms; see also its privacy policy.

OpenStreetMap Foundation / Nominatim (Venue Lookup)

If a known venue has no saved address and you ask the Assistant where it is, GigBook's server may send the venue name and an optional city hint derived from your saved timezone to the public Nominatim search service operated by the OpenStreetMap Foundation. A confident result may be saved to that venue for future answers. The Foundation receives normal request metadata from GigBook's server and acts as an independent controller, not as GigBook's contracted processor. See its privacy policy and Nominatim usage policy.

Clerk (Authentication)

Handles user authentication and account security. Read their privacy policy: clerk.com/privacy

Neon (Database)

Stores your app data securely. Read their privacy policy: neon.tech/privacy-policy

Vercel (Hosting)

Hosts the app infrastructure. Read their privacy policy: vercel.com/legal/privacy-policy

Sentry (Diagnostics)

Receives scrubbed crash, error and sampled performance events when diagnostics are configured. GigBook disables session replay and default personal-information capture, and removes raw messages, user/request context, breadcrumbs and attachments before sending diagnostic events. Read their privacy policy: sentry.io/privacy

Apple Push Notification Service

Receives device or Live Activity delivery tokens and the notification payload needed to deliver reminders and Live Activity updates you enable.

Apple, Google and Stripe (Purchases)

Process payment details and return verified transaction, purchase-state and refund facts to GigBook for purchases available on your platform.

Data Retention

  • Your data is stored as long as your account is active
  • When you delete your account, ordinary account content is removed from the active account; the wallet is closed and detached so it cannot be reused
  • Any unused purchased or promotional AI credits become unavailable when the account is deleted. Account deletion does not automatically request or issue a refund
  • To make deletion permanent, we retain a one-way cryptographic digest (SHA-256) of your deleted account identifier indefinitely. It contains no name, email, or reversible identifier; its only purpose is to prevent delayed system events, backup restores, or imports from ever recreating a deleted account. Your raw account identifier itself is removed or replaced with this digest across our records at deletion
  • References to files pending deletion from storage are kept until that deletion verifiably completes, then removed. Where automatic deletion cannot safely complete (for example an ambiguous or interrupted storage operation), the reference is retained as the durable record of the still-pending deletion until our operators complete it manually — retaining it is what guarantees the file is not forgotten
  • Administrative and security audit records (for example a record that an administrator adjusted a billing wallet) are append-only by design. New records identify actors only by a separate one-way digest that is not linkable to the deletion digest above; a small number of older records created before this change may retain an administrative account identifier and are kept under our legitimate interest in security and financial auditability
  • Minimal pseudonymous purchase, refund and append-only ledger facts may be retained for legal, accounting, fraud-prevention and dispute obligations
  • Database backups are retained for up to 90 days for disaster recovery, then permanently deleted
  • We retain minimal logs for security purposes (90 days)

Your Rights

Under GDPR and other privacy laws, you have the right to:

  • Access: Request a copy of your data
  • Correction: Update or correct your information in Settings
  • Deletion: Close your account and remove ordinary account content from active GigBook systems directly from Settings → Profile → Delete Account. The limited retention described above still applies
  • Export: Download your data as JSON or CSV from Settings → Data → Export data
  • Object: Object to certain data processing activities
  • Withdraw AI Consent: Block new AI requests at any time in Settings → AI without deleting your account

To exercise any of these rights or for questions, contact us at privacy@gigbook.xyz

Children's Privacy

GigBook is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.

International Users

Your data may be processed in countries outside your own. We ensure adequate safeguards are in place to protect your data in compliance with GDPR and other applicable privacy laws.

Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any significant changes by email or through the app. Your continued use of GigBook after changes means you accept the updated policy.

Contact Us

If you have questions about this privacy policy or your data, contact us:

This privacy policy applies to the GigBook mobile app and web application. By using GigBook, you agree to the collection and use of information in accordance with this policy.