← Back to aniprotech

Privacy Policy

Last updated 5 September 2026

aniprotech is business software for invoicing, HR, payroll and attendance. This policy explains what it stores, why, who else sees it, and how to have it removed. It covers the aniprotech website and the application at aniprotech.com.

The service is operated by Ani Protech. You can reach us at info@aniprotech.co.uk or +44 7480 422277.

1. Who this policy is about

Two different groups use aniprotech, and the distinction matters:

2. What we store

When a business signs up

What a business puts in

Automatically, as the software runs

There is no advertising, tracking or analytics on this site. aniprotech loads no analytics script, no advertising pixel and no third-party tracker on any page. We do not build profiles, we do not track people across other websites, and we do not sell or rent personal data to anybody, ever.

3. Cookies

One cookie: a signed session cookie set when you sign in, so the application knows it is still you between requests. It is marked SameSite=Lax, sent only over HTTPS, and expires after 24 hours by default. It holds a reference to your session and no personal information.

The application also uses your browser's own local storage to remember small conveniences, such as a collapsed panel or a dismissed message. That never leaves your device.

There are no advertising or analytics cookies, so there is nothing to consent to.

4. Google account data

A business may connect a Google account so its invoices and payslips are sent from its own address rather than ours. This is optional, and the software works without it.

When connected, we request these permissions and no others:

PermissionWhat we do with it
openid, email, profile Identify the account being connected, and show its address on the settings screen so you can see which one is in use.
gmail.send Send the invoices, quotes and payslips that you choose to send, from your own address. Nothing else.

We cannot read your email. The gmail.send permission only allows sending. We do not request, and could not use, any permission that reads, searches, modifies or deletes messages in your mailbox.

Google issues a token that lets the software keep sending on your behalf. It is stored on our server, is never shown in any web page, and is deleted immediately when you press Disconnect on the settings screen or delete your account.

Limited Use. aniprotech's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: data obtained through Google APIs is used only to provide the sending feature described above. It is not transferred to anyone else except as needed to provide that feature, to comply with law, or as part of a merger or acquisition. It is not used for advertising, is not sold, and is not read by any person except where you have specifically asked us to investigate a problem or where the law requires it. No Google user data is used to train any machine learning or AI model.

5. Who else sees the data

Only these, and only for the part of the job each one does. None of them is permitted to use the data for their own purposes.

WhoWhat reaches themWhy
Railway Everything, as our hosting and database provider Running the application and storing its database
Google The message being sent, when a business has connected Google Delivering that email from the business's own address
Your own mail server The message being sent, if SMTP is configured instead Delivering that email
Stripe, Razorpay, GoCardless, PayPal The amount, currency and invoice reference. Card and bank details are entered on the provider's own page and never reach us. Taking payment for an invoice, or topping up a wallet
Groq Only the text you submit to an AI feature — for example the invoice wording you ask it to draft Generating that text. Not used where no AI feature is used.
Meta (WhatsApp Business API) The message and the recipient's number, only if a business chooses to send an invoice by WhatsApp Delivering that message

We do not sell personal data, we do not share it for advertising, and we do not give it to anyone else unless the law requires it.

6. Where it is kept and for how long

Data is held on Railway's cloud infrastructure, in a managed PostgreSQL database.

While an account is open, data is kept for as long as the business needs it — invoices and payroll records usually have to be retained for tax purposes, and that period is set by the law where the business operates, not by us.

When an account is closed, its data is deleted within 30 days. Sign-in records and email delivery records are kept for up to 12 months so that security questions can be answered, then removed.

7. How it is protected

No system is perfectly secure. If a breach affects your data we will tell you and, where the law requires it, the relevant authority.

8. Your rights

Depending on where you live you may have the right to ask for a copy of your data, to correct it, to have it deleted, to restrict or object to how it is used, and to receive it in a portable form. To exercise any of these, write to the address below. We will respond within 30 days.

If you are an employee or a customer of a business using aniprotech, that business controls your record. Please contact them first; if you cannot reach them, contact us and we will help.

You can also ask us to delete your account at any time, and you can disconnect a Google account yourself at any time from the settings screen. You can revoke our access directly from your Google account permissions page.

9. Children

aniprotech is business software and is not intended for anybody under 16. We do not knowingly collect data from children.

10. Changes

If this policy changes we will update the date at the top and, for anything significant, tell account holders by email.

11. Contact

Ani Protech
Email info@aniprotech.co.uk
Telephone +44 7480 422277