Last updated: August 20, 2026
This policy explains what information Qatalyst collects, how it's used, and the choices you have. We've tried to write it in plain language rather than dense legal boilerplate — if anything here is unclear, contact us and we'll clarify it.
Account information: when you sign up or are invited to an organization, we collect your name, email address, and a securely hashed password (we never store your password in plain text).
Workspace and business data: information you enter to run your business through Qatalyst — clients, projects, time entries, expenses, mileage logs, invoices, notes, and contact cards.
Usage data: standard technical information like IP address, browser type, device type, and pages visited, collected automatically to keep the service secure and working correctly.
Receipt images: if you use receipt scanning, the image you upload is stored and may be sent to a third-party OCR provider to extract vendor, date, and amount information (see "Third-party service providers" below).
We use the information we collect to operate and improve Qatalyst: authenticating your account, running the features you use (time tracking, invoicing, the client portal, reminders, and so on), securing the service against abuse, and communicating with you about your account or the product.
We do not sell your personal information, and we do not use your business data to train any third-party AI models.
If you use Qatalyst to manage your own clients, you'll enter information about them — names, emails, phone numbers, and billing details. You (or your organization) are the data controller for that information; Qatalyst processes it on your behalf, only to provide the service to you.
When you grant one of your clients access to their portal, they can access invoices, documents, and project status you've chosen to share with them, through a secure, single-use access link — never a shared password.
We rely on a small number of service providers to run Qatalyst: cloud hosting and database infrastructure, and, if your organization enables it, an optical character recognition (OCR) provider used solely to read receipt images you upload. These providers only receive the minimum data needed to perform their function, and are not permitted to use it for their own purposes.
Your data is stored in a securely managed database with access restricted to what each feature actually needs. Connections to Qatalyst are encrypted in transit. No method of storage or transmission is 100% secure, but we design every feature with the assumption that it's handling real business and financial data, and treat it accordingly.
We retain your account and workspace data for as long as your account is active. If you delete a record (a note, a client, an invoice), it's either removed immediately or, where we provide a recovery window (like the Notes trash), permanently deleted after that window closes. If you close your account entirely, we delete your data within a reasonable period, except where we're required to keep certain records for legal or accounting reasons.
Depending on where you live, you may have rights to access, correct, export, or delete your personal information. Most of this you can already do directly inside Qatalyst — editing or deleting a client, exporting your data, or closing your account. For anything you can't do yourself, contact us and we'll take care of it.
Qatalyst is a business tool and isn't directed at children. We don't knowingly collect personal information from anyone under 16.
If we make a material change to this policy, we'll update the date at the top of this page and, where appropriate, let you know directly.
Questions about this policy or your data? Email us at hello@qatalyst.io and we'll get back to you.