Privacy Policy

Last updated August 4, 2026

This page covers redovix.com — the marketing site, your account, and the license activation flow — operated by Fara Technology AB (“we”, “us”). It does not cover your bookkeeping data, which is a deliberately separate story explained below.

This is a good-faith, plain-language description of what we actually collect and why, written to match the code as it exists today rather than adapted from a generic template. It is not legal advice. If you need this policy to satisfy a specific regulatory regime (GDPR, CCPA, or otherwise) for your own compliance purposes, have it reviewed by counsel first.

The desktop app is not covered by this policy, on purpose

The Redovix desktop application — the actual bookkeeping software, where your ledger, invoices, and customer records live — stores everything in an encrypted database on your own computer. It does not upload your books to us, ever, and it works fully offline for everyday use. There is nothing for a privacy policy to disclose about data we never receive, because we never receive it. See our FAQ and How it works pages for the mechanics (hash-chained entries, local storage, what the one-time activation call actually sends).

Everything below is about the much smaller surface where redovix.com itself, as a website and an account system, does talk to a server.

Information we collect

Account information. Creating an account (Sign up) collects a name, email address, and password — the password is handled entirely by Firebase Authentication and we never see or store it in plain text. If you sign up with Google or GitHub instead, we receive the name, email, and profile photo your OAuth provider shares with us, and nothing else from that account.

Activation and license information. Activating a license (from the desktop app or this site) sends a machine identifier, your chosen tier, and — for the free tier’s signup — a name and phone number, to a server we operate so we can issue and verify your license key. This is the only data point that ever crosses from the desktop app to us, and it’s limited to exactly what’s needed to activate a device.

Payment information. For paid tiers billed outside Ethiopia, card payment is handled entirely by Stripe on Stripe’s own checkout page — we receive your email and subscription status, never your card number. Ethiopia-region billing (Telebirr / M-Pesa) is handled by those providers directly under the same principle: we see that a payment happened, not your financial account details.

Analytics. We use Firebase Analytics (built on Google Analytics) to understand which pages get used and roughly how many visitors we get. This includes standard web analytics data: pages viewed, approximate location derived from IP address (not the IP address itself, retained), device and browser type, and referral source. It is not tied to your account identity unless you are signed in and we explicitly choose to make that link in the future — we do not currently do so.

Bot protection. We use Firebase App Check with Google reCAPTCHA v3 to distinguish real visitors from automated scripts on account-creation and sign-in flows. reCAPTCHA runs an invisible risk assessment in your browser and does not require you to solve a puzzle. Use of reCAPTCHA is subject to Google’s Privacy Policy and Terms of Service.

Cookies and local storage. Firebase Authentication uses local storage to keep you signed in between visits. Firebase Analytics sets standard analytics cookies to distinguish sessions and visitors. We don’t use advertising or cross-site tracking cookies.

How we use this information

  • To create and secure your account, and let you sign back in.
  • To issue, verify, and let you manage your license (see it, move it to a new device, deactivate it).
  • To process payment for paid tiers, via Stripe or the regional payment provider.
  • To understand product usage in aggregate and improve the site and product.
  • To detect and block automated abuse of signup and sign-in.
  • To email you about your account or a purchase — never marketing email you didn’t ask for.

Who we share it with

We don’t sell personal information, to anyone, ever. What we share is limited to the service providers this site is genuinely built on: Google/Firebase (authentication, hosting, functions, analytics, bot protection), Stripe (payment processing for international billing), and the regional payment providers used for Ethiopia billing. Each processes data under their own privacy policy and only for the purpose we use them for.

Data retention

Account and activation records are kept for as long as your account is active, plus a reasonable period afterward for support, fraud-prevention, and legal/accounting record-keeping purposes. Analytics data is retained under Firebase Analytics’ standard retention window before it is aggregated or deleted.

AI features & third-party processing

Redovix offers AI-powered features that can run in two modes:

  • On-device AI (default, all tiers): A local AI model runs entirely on your computer. Nothing leaves your device. Your ledger data, invoices, and customer records are never transmitted to any server or third party.
  • Redovix Cloud AI (opt-in, Pro & Business only): If you choose to enable cloud-based AI, your chat messages and questions are forwarded to a third-party AI provider for processing. This is strictly opt-in — you must explicitly consent before it is enabled, and you can switch back to on-device AI at any time under Settings > AI.

What is transmitted to the cloud AI provider

When cloud AI is enabled, only the text of your questions and the conversation context needed to answer them are sent. Raw ledger data, account balances, company files, customer records, and transaction details are never transmitted. When the AI needs to query your books to answer a question (e.g., “What is my cash balance?”), that query runs locally on your computer — the AI model requests the data, the Redovix app fetches it from your local database, and only the specific result (e.g., “245,000 ETB”) is included in the conversation.

Query caching

To reduce costs and improve response speed, Redovix caches anonymized query patterns on our servers. The cache stores the structure of common accounting questions (e.g., “what account for office rent”) but never stores company names, personal data, financial amounts, or any information that could identify you or your business. Each cached entry is a hash of the normalized question text paired with the AI’s response. Cached entries automatically expire after 30 days.

Your control

Cloud AI is disabled by default. When you select it for the first time, you must explicitly acknowledge and accept the third-party processing disclosure. You can disable it at any time and return to fully on-device AI with no data retention on our servers. Your consent preference is stored locally on your device.

Your rights

You can see and edit your account details from the Account page at any time. To request a full export or deletion of your account data, email us — see Contact below — and we’ll handle it directly; we’re small enough that this doesn’t need to be self-service yet. Deleting your account does not touch any bookkeeping data in the desktop app, since we never had it to begin with.

Children’s privacy

Redovix is business software. It isn’t directed at children, and we don’t knowingly collect information from anyone under 18.

Changes to this policy

If this changes in a way that matters — a new data use, a new third party — we’ll update the date at the top of this page. Material changes affecting existing account holders will be emailed, not just posted quietly.

Contact

Fara Technology AB — hello@redovix.com. This is a real inbox a real person reads, for privacy questions same as any other.