Privacy Policy

Codegrain Reports · reports.codegrain.dev

Last updated: 29 September 2026

1. Who we are

Codegrain Reports is run by CODEGRAIN S.R.L., a company registered in Romania (European Union).

  • Registered office: Str. Izvorului 46, Camera 3, Ap. 24, Constanța, Romania
  • Company ID (CUI): 54921110 · Trade Register No. J2026039341004
  • Privacy contact: andrey@mail.codegrain.dev
  • We have not appointed a data protection officer, because the law does not require one for the kind of processing we do. Please send any privacy question to the address above.

Codegrain Reports reads data from your Jobber account and turns it into reports. We are an independent company. We are not affiliated with Jobber.

2. The short version

  • We only read from Jobber. Our app can't create, change or delete anything in your Jobber account. The only thing it can do there is disconnect itself when you ask.
  • From Jobber we keep only what the reports need: names, numbers, amounts, dates and statuses. We don't take your clients' or your team's email addresses, phone numbers, street addresses, notes or attachments.
  • Your data is stored on our server in Frankfurt, Germany.
  • When you disconnect, we delete your data within 24 hours (details and exceptions in section 6). Our encrypted backups are overwritten within 7 more days.
  • We don't sell data, we don't show ads, and we don't use analytics or tracking cookies.

3. Our two roles

(a) Your Jobber data: we work for you. When you connect Jobber, we copy data about your clients, your team and your work. You decide why this data is used. Under the EU GDPR you are the controller and we are your processor. Where California law (CCPA/CPRA) applies to you, you are the business and we are your service provider. We use this data only to provide Codegrain Reports to you, as described in our Terms of Service, section 12.

If you are a customer of a contractor who uses Codegrain Reports and you want to see, fix or delete your data, please contact that contractor. If you write to us instead, we will pass your request to the contractor and help them answer it.

(b) Our own customers and contacts: we decide. For your account with us, billing, emails with us, visits to our website and business contacts we email, CODEGRAIN S.R.L. is the controller.

4. What data we have, where it comes from and why

4.1 Data from your Jobber account (we are your processor)

What we keep Where it comes from in Jobber Why we need it
Your company's name and Jobber account ID; your time zone, which you tell us at setup Account (the time zone comes from you, not from Jobber) To know which account is yours and to show dates correctly
Your clients' names; whether a client is a company; whether it is archived Clients Unpaid invoices report and the daily summary
Your team members' full names Users Reports by salesperson (commissions)
Quotes, jobs, visits, invoices and payments: numbers, statuses, dates, amounts, taxes and line items (item name, quantity, unit price, total), and the links between them Quotes, jobs, visits, invoices, payments All reports and Excel exports
Your list of products and services: name and type (product, service or labour) Products and services Revenue by category
One custom field that you choose for revenue categories (optional) Custom fields Revenue split by your own categories

How far back we go: all of your quotes, jobs, invoices, payments and clients; visits from the past 12 months and up to about 4 months ahead (for the forecast).

What we don't keep: email addresses, phone numbers, street addresses, notes, attachments, or full copies of what Jobber sends us. Jobber's permissions are broad. For example, permission to read clients also covers phone numbers and addresses. We don't ask Jobber for those fields and we don't store them.

If a record is deleted in Jobber, we keep it marked as deleted, so that the reports stop counting it (for example, a cancelled visit). Everything is removed when you disconnect (see section 6).

4.2 Data about you as our customer (we are the controller)

What Why Legal basis (GDPR)
Sign-in. Your Jobber account ID and company name, plus one sign-in cookie To sign you in. You sign in through Jobber, so we have no passwords Performing our contract with you
Billing. Name, email, billing address, what you bought, payment status. Stripe collects this when you pay. Card numbers stay with Stripe and we never see them To charge you, issue invoices and keep accounting records Contract; legal obligation (accounting and tax law)
Emails with us. Your name, email address and what you write Setup, support and questions Contract; our legitimate interest in answering you
Server logs. IP address, time, page requested, browser type Security and fixing problems Our legitimate interest in keeping the service secure

Gmail API. We use the Gmail API only for our own mailbox: to send our emails and to read the replies. We don't ask for access to anyone else's Google account. We don't sell data from our mailbox and don't use it for advertising. Our AI assistant (Anthropic, section 7) reads and drafts these emails for our founder.

4.3 Businesses we email (we are the controller)

We send short one-to-one emails to home-service businesses that might need our reports. For this we use business contact details that the company has published (such as a company name, a contact name, a business email address and the company website), plus public information about the business, for example a public review that we mention in the email. Legal basis: our legitimate interest in offering our service to businesses. You can say "stop" at any time: reply to our email. We then put your address on a do-not-contact list and don't email you again.

4.4 Cookies

We use one essential cookie, __Host-cr_sid, to keep you signed in for up to 30 days. We don't use analytics, advertising or third-party cookies, and our pages load no third-party scripts. Our home page sets no cookies.

5. Where your data is stored

Everything the service stores (your Jobber data, the encrypted Jobber access keys and the encrypted backups) is on our server, rented from DigitalOcean in its Frankfurt, Germany data center. We don't send your Jobber data to Google Sheets or to any other tool. Excel files are created when you click "Download", and we don't keep copies of them.

6. How long we keep data

Data How long
Your Jobber data while you are connected As long as you stay connected
After you disconnect (in our dashboard, or in Jobber, which then notifies us) Your Jobber data, access keys and sessions are deleted within 24 hours. Encrypted backup copies are overwritten within 7 more days. If Jobber's notice doesn't reach us, the next row applies
If our connection stops working and you don't reconnect (for example, your Jobber subscription ends, your Jobber plan changes, or the admin who connected us is removed) Access keys are deleted right away. Your Jobber data is deleted after 14 days, and backup copies are gone 7 days after that
After you cancel your subscription We disconnect and delete your data within 7 days after your last paid period ends
If you take the setup fee refund in the 14 free days after setup We disconnect and delete your data within 7 days after the service ends
If we don't finish your setup within 30 days after you pay (we then refund the setup fee in full) The service ends. We disconnect and delete your data within 7 days after it ends
If you don't pay for your subscription within 14 days after we send the payment link (we send it on the 15th day after setup) The service ends. We disconnect and delete your data within 7 days after it ends
If we end the service We disconnect and delete your data within 7 days after the service ends
Deletion record After a deletion we keep a short record: a one-way hash of your Jobber account ID, the date, and how many rows were deleted. It contains no names. We keep it for 3 years, as proof that the deletion happened
Technical sync records (no names) 90 days
Change notices from Jobber (record IDs only) 30 days
Server logs (IP address) Up to 15 days
Sign-in cookie Up to 30 days
Billing records As long as Romanian accounting and tax law requires
Emails with us Up to 3 years after our last contact
Do-not-contact list For as long as we send emails, so that we keep honoring your request

7. Service providers we use (subprocessors)

Provider What they do for us What data they handle Where
DigitalOcean, LLC Hosts our server and database Everything the service stores (section 5) Data center in Frankfurt, Germany (company based in the USA)
Stripe (Stripe Payments Europe, Ltd.) Payments and subscriptions. Stripe also uses some billing data for its own purposes, such as fraud prevention and legal checks, under its own privacy policy Billing data Ireland (EU); Stripe may also process data in the USA
Google (Gmail) Our email inbox Emails with us USA and other countries
Cloudflare, Inc. DNS for our domain; forwards email sent to @mail.codegrain.dev to our inbox Emails in transit. Cloudflare does not see traffic to reports.codegrain.dev USA and other countries
Anthropic, PBC AI assistant our founder uses to read and draft emails and to help run and fix the service Emails with us. When we fix a problem, it can also see service data, such as logs and database records, which may include your Jobber data USA

Your synced Jobber data is stored only at DigitalOcean. Google and Cloudflare see Jobber data only if it is put in an email, for example a screenshot you send us for support. Please don't email us your clients' personal data. If you do, the email stays in our Gmail inbox (Google) and we keep it as described in section 6 ("Emails with us").

Anthropic does not store a copy of your synced Jobber data. Its AI assistant sees parts of it only when our founder uses the assistant to find and fix a problem, for example by reading a log or a database record. Anthropic handles what the assistant sees under its own terms.

We will use an uptime monitor (Healthchecks.io) once the service runs. It will receive only "the service is running" signals and no customer data.

Jobber is not our subprocessor: Jobber is where the data comes from, and your use of Jobber is covered by Jobber's own terms and privacy policy.

We will update this list before adding a provider. If a new provider would store your Jobber data, we will email you at least 14 days before the change.

8. Transfers outside the EU

Your data is stored in the EU (Germany). DigitalOcean, Stripe and Cloudflare are US companies or part of US groups, and they may access data from the USA. Their data processing agreements form part of our contracts with them. For transfers to the USA these agreements rely on the EU–US Data Privacy Framework and on the EU Standard Contractual Clauses. Our email inbox is Gmail, so Google stores emails with us in the USA and other countries under its own terms for Gmail. Anthropic is a US company. Emails with us, and any service data its AI assistant sees while we fix a problem, are processed in the USA under Anthropic's own terms.

9. How we protect data

  • All connections use HTTPS.
  • Jobber access keys are encrypted in our database. The encryption key is stored separately and is not in backups.
  • Each customer's data is separated inside the database, so one account can't see another account's data.
  • There are no passwords to steal: you sign in through Jobber. The sign-in cookie can't be read by scripts and is sent only over HTTPS.
  • Backups are encrypted. Only our founder holds the key to decrypt them.
  • The server accepts only key-based administrator logins. Password login is turned off.
  • Our logs don't contain Jobber access keys or your clients' names.
  • Only our founder has administrator access to the server and the database. Our founder's AI assistant (Anthropic, section 7) works through this access when it helps fix a problem, and can then see logs and database records.

If a security incident affects your data, we will tell you without undue delay and help you meet any duty you have to notify others.

10. Your rights

Under the GDPR (it applies to us because we are an EU company), you can ask us to:

  • give you a copy of your personal data;
  • correct it;
  • delete it;
  • limit how we use it, or stop using it where we rely on legitimate interest;
  • give it to you in a common format (portability).

Write to andrey@mail.codegrain.dev. We reply within one month. You can also complain to a data protection authority: in Romania this is ANSPDCP (www.dataprotection.ro), or you can use the authority in the country where you live or work.

We don't make decisions about people by purely automated means, and we don't build profiles of people.

For Jobber data we hold for a contractor, we help the contractor answer requests from their customers and team. The contractor can export the data (Excel), and it can ask us to delete specific records. We do that within 30 days.

California (CCPA/CPRA). When we process Jobber data for a contractor, we act as that contractor's service provider. We use the data only to provide our service, we don't sell or share it, we don't use it for advertising, we don't combine it with other data, and we delete it when the service ends. For the data we collect as a controller: we don't sell or share personal information, and we don't do cross-context behavioral advertising. California residents can ask to know, correct or delete their personal information, and we won't treat you differently for asking.

11. Children

Codegrain Reports is a service for businesses. It is not meant for anyone under 18, and we don't knowingly collect data about children.

12. Changes to this policy

When we change this policy, we post the new version here with a new date. If a change is important, we also email our customers at least 14 days before it takes effect.

13. Contact

CODEGRAIN S.R.L., Str. Izvorului 46, Camera 3, Ap. 24, Constanța, Romania

Email: andrey@mail.codegrain.dev

Jobber is a trademark of Octopusapp Inc. Codegrain Reports is not affiliated with, endorsed by or sponsored by Jobber.