Bodhleigh
Privacy Policy — Last updated 14 June 2026
Bodhleigh ("the App") is operated by Leigh Sacha trading as Bodhleigh (ABN 79 705 832 619). This Privacy Policy explains what information we collect, how we use it, and how we protect it.
1. Information We Collect
When you use Bodhleigh, we collect and store the following:
- Account information: email address (verified at sign-up) and an encrypted password
- Business details: business name, ABN, phone number, email, website, and bank account details for invoice generation
- Job and scheduling data: job descriptions, addresses, dates, times, notes, job status
- Client information: client names, phone numbers, email addresses, addresses
- Financial data: quotes, invoices, line items, expense and receipt records, kilometre logs
- Photos: before, after, general job-site photos, and receipt images uploaded by you
- Inbound email content: if you forward or send emails to the App's job intake address, we receive and store those emails — including the sender's email address, subject, and message content — in order to create jobs from them
- Location data: if you use the in-person Tap to Pay feature to accept a card payment, the approximate location (GPS) of your device at the time of the payment is collected by Stripe's payment software to process the in-person payment. This is collected only at the moment of a tap payment and is not used by Bodhleigh for any other purpose (see Section 2).
2. How We Store and Process Your Data
Bodhleigh relies on the following third-party service providers to operate. Each only receives the data needed for its specific function:
- Supabase (supabase.com) — stores your account, business, job, client, and financial data, and manages secure sign-in and email verification. Data is stored on AWS servers in the Asia-Pacific region.
- Cloudinary (cloudinary.com) — stores photos and receipt images you upload. These are accessible only via unique URLs generated by the App.
- Stripe (stripe.com) — processes card payments from your customers. Card and payment details are handled directly by Stripe and are not stored by Bodhleigh. Payments are routed to your own connected Stripe account. If you use the in-person Tap to Pay feature, Stripe's payment software also collects the approximate location (GPS) of the device at the time of the tap, as required by Stripe to process in-person card-present payments. This location data is collected and used by Stripe for payment processing and fraud prevention and is not stored by Bodhleigh.
- RevenueCat (revenuecat.com) — manages your Bodhleigh subscription. RevenueCat receives purchase and subscription information (such as your subscription status, purchase and renewal events, and an anonymous user identifier) to validate your subscription and grant access to the App. It does not receive your card details.
- Apple App Store and Google Play — when you subscribe to Bodhleigh, your subscription is purchased and billed through the Apple App Store or Google Play, depending on your device. Your payment details are handled by Apple or Google under their own terms and privacy policies and are not received or stored by Bodhleigh.
- Resend (resend.com) — sends emails on your behalf, including account verification emails and the quotes, invoices, and approval links you send to your customers.
- Mailgun (mailgun.com) — receives inbound emails sent to the App's job intake address so they can be turned into jobs.
- Anthropic (anthropic.com) — provides the AI features. When you use AI Photo Scan or Receipt Scan, the relevant image or email text is sent to Anthropic to extract details (such as job notes, vendor, total, or job information). Anthropic processes this content to return a result and does not use it to train its models.
All data is transmitted over HTTPS encrypted connections.
3. How We Use Your Data
Your data is used solely to operate the Bodhleigh application and provide you with its features. Specifically:
- To display your schedule, jobs, quotes, invoices, and financial summaries
- To generate PDF quotes, invoices, and financial reports
- To send account verification and notification emails to you
- To send quotes, invoices, and approval links to your customers on your behalf
- To turn emails forwarded to the App into jobs automatically
- To read photos and receipts you choose to scan and pre-fill job or expense details
- To display job-site photo galleries to your customers via approval links
- To restore your data if you reinstall the App or switch devices
4. We Do Not Sell Your Data
We do not sell, rent, trade, or share your personal information or your clients' information with any third parties for marketing or commercial purposes. The third-party providers listed in Section 2 act only as processors to deliver the App's features. Your data belongs to you.
5. Photos of Private Properties
Photos uploaded through Bodhleigh may include images of private residential and commercial properties. These photos are stored securely on Cloudinary and are accessible only via unique URLs that you control. Where you use AI Photo Scan, the image is also sent to Anthropic for analysis as described in Section 2. You are responsible for obtaining any necessary permissions before photographing private properties.
6. Client Data
When you enter client information into Bodhleigh (names, phone numbers, addresses, emails), you are responsible for ensuring you have their consent to store that information in a cloud-based application. We store this data solely to provide the App's functionality to you.
7. Financial Data
Bodhleigh generates financial summaries, GST/BAS estimates, and income reports based on the data you enter. This information is stored securely and used only to provide these features to you. Bodhleigh is an organisational and estimating tool only and does not constitute financial advice. Always consult a registered tax agent or accountant for your tax obligations.
8. Data Retention & Deletion
Your data is retained for as long as your account is active. You may request deletion of your account and all associated data by contacting us at accounts@bodhleigh.com.au.
Please note that some records may be retained after a deletion request where we are required to keep them to comply with legal obligations — for example, financial and receipt records that must be kept for tax record-keeping purposes. Where this applies, we keep only what is required for as long as the law requires, and delete the rest.
9. Security
We take reasonable steps to protect your data, including encrypted transmission (HTTPS), password hashing and email verification via Supabase Auth, and access controls ensuring each user can only access their own data. However, no system is completely secure and we cannot guarantee absolute security.
10. Children's Privacy
Bodhleigh is designed for use by adult tradespeople and business operators. We do not knowingly collect information from anyone under 18 years of age.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of significant changes via the App. Continued use of the App after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions about this Privacy Policy or how your data is handled, please contact us: