Your information
Privacy policy
Effective and last updated: September 10, 2026
This policy explains how JobUp handles personal data across our website, web app, mobile apps, and related services.
We use your information to provide JobUp, keep accounts secure, and support your work. Google Sign-In shares basic identity information. Cloud sync and optional AI features process the information needed for those features. We do not sell your personal data.
1. Who we are
JobUp is operated by Heliapps SL (“we”, “us”, or “our”). For questions or privacy requests, contact [email protected] and mention JobUp.
We are responsible for the personal data we use to operate accounts, secure the service, and manage our relationship with you. When a business uses JobUp to manage its clients, workers, invoices, or other records, that business decides why the information is used and we process it to provide the service. If you are a client or worker of that business, you can also contact it about your data.
2. Information we handle
- Account information: your name, email address, profile image when supplied by a sign-in provider, provider account identifier, authentication records, and workspace memberships.
- Business records: business and client contact details, addresses, tax identifiers, estimates, invoices, items, prices, receipts, expenses, notes, images, signatures, attachments, and payment status that you or your workspace provide.
- Feature inputs: audio, transcripts, text, images, or documents you submit for voice capture, AI assistance, or document and receipt recognition.
- Transactions: subscription and entitlement status, payment-provider references, amounts, and payment events when payment features are used. Payment providers handle card details and payment credentials in their own payment interfaces.
- Technical and support information: IP address, browser or device information, app version, timestamps, session and installation identifiers, error reports, performance measurements, and information you send when requesting help.
We receive this information from you, your authorized workspace users, sign-in and payment providers, and interactions with the service. A business may provide your details when it creates an invoice or adds you as a client or team member.
3. Google Sign-In
If you choose Google Sign-In, we request basic identity access (openid, email, and profile). Google provides an account identifier, your name, email address and its verification status, and a profile picture when available. Authentication tokens allow us to verify the sign-in and establish your JobUp session. We do not receive your Google password.
We use this information to create or identify your JobUp account, display your profile, provide access to your workspaces, and protect account access. This sign-in does not request permission to read your Gmail messages, Google Drive files, contacts, or Google Calendar. We do not sell Google user data or use it for advertising.
JobUp’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements where applicable.
You can remove JobUp’s access in your Google Account connections. Disconnecting Google does not automatically delete your JobUp account, its business records, or an existing JobUp session. Sign out of JobUp to end the session on that device, and contact us to request account or data deletion.
4. Why we use information
We use personal data to authenticate you, provide and synchronize workspaces, create and deliver the documents you request, run optional features, manage payments and subscriptions, answer support requests, prevent abuse, troubleshoot failures, and meet legal obligations.
Where European data-protection law applies, we rely on performance of our contract with you for the service you request; legitimate interests in operating, securing, and improving a reliable service and responding to inquiries; legal obligations for required records and valid legal requests; and consent where it is required, such as for optional device permissions. You can withdraw consent without affecting processing that was lawful before withdrawal.
Account details needed to authenticate you and content needed to carry out a request are necessary for those features. Optional voice capture, imports, and uploads can be left unused. JobUp does not make solely automated decisions about you that produce legal or similarly significant effects.
5. Voice, AI, and device permissions
When you use voice or AI features, the relevant audio, transcript, text, images, document content, and business context may be sent to speech-recognition and AI service providers. An edit may include the current document so that unchanged details can be preserved. These features can involve cloud processing even when the original file or recording is on your device.
Our integrations include Soniox for speech recognition, Vercel AI Gateway and the model providers fulfilling a request, and OpenRouter as a configured fallback. Supported on-device recognition may also be used. Processing and retention at these providers depend on the service and its applicable terms; this policy does not promise that all provider processing is instantaneous or leaves no retained copy.
JobUp uses these inputs to produce the output you request. We do not train our own general-purpose AI models using your business records. You remain responsible for reviewing generated text, amounts, and documents before using or sending them.
Microphone, camera, photo, contact, and notification access is used for the feature you choose when that permission is available and granted. You can manage permissions in your device settings. Declining a permission can prevent its related feature from working.
7. Storage, diagnostics, and international processing
The apps may keep preferences, draft records, and cached data on your device. Signed-in features also store records on our servers and file-storage services. Signing out does not necessarily erase cached business records from the device.
Essential cookies and similar storage support authentication and preferences. Web sessions are configured for up to 180 days; mobile sessions use a rolling expiry of up to 365 days. Activity can renew a session. Browser or device controls can clear local storage, but doing so does not delete server records.
Web diagnostics can include sampled session replay with text and inputs masked and media blocked. Diagnostic collection depends on platform and configuration; changing notification settings does not switch diagnostics on or off.
Our hosting and service providers may process data outside your country, including in the United States. Where European law requires a transfer safeguard, transfers must be covered by an applicable adequacy decision or appropriate safeguards such as standard contractual clauses. Contact us for information about the safeguards applicable to your data.
We use measures including HTTPS, authentication, role-based access, and restricted access to service credentials. No system can guarantee absolute security.
8. How long information is kept
We keep account and workspace information while it is needed to provide the service and preserve the records the workspace uses. Retention depends on the record’s purpose, account and workspace status, deletion requests, the business’s instructions, and applicable legal requirements. An invoice retained by a business may need to remain even when an individual leaves its workspace.
We may retain limited information after account closure when necessary for tax or accounting obligations, dispute resolution, fraud prevention, and legal claims. Backup copies and provider logs can have a separate lifecycle; deletion from the live service may not immediately remove every backup copy. We can explain the applicable retention and any exceptions when handling your request.
Voice recordings are used for transcription and retry handling. The asynchronous transcription integration requests deletion of its uploaded Soniox file and transcription after processing. That cleanup is not a guarantee of deletion from every provider system. Content you save into an invoice, estimate, or other record follows the retention of that record.
9. Your choices and privacy rights
Depending on the law that applies, you can request access to your personal data, correction, deletion, restriction, or a portable copy; object to processing based on legitimate interests; and withdraw consent. Contact [email protected] to make a request, including account deletion. We may need to verify your identity and workspace authority before acting.
Some requests are subject to legal exceptions or the rights of other people in a workspace. For records managed by a business using JobUp, we may refer the request to that business or help it respond. You can also complain to your local data-protection authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD).
10. Business use and children
JobUp is intended for professional and business use, not for children. If you believe a child has provided personal data to us, contact us so we can investigate and take appropriate action.
11. Changes to this policy
We may update this policy as the service or our practices change. We will update the date on this page and provide additional notice or request consent when required for a material change.