Wattle Office
Privacy Policy
Wattle Office is built for Australian sole traders and small businesses. This policy explains what information the app uses, how it is stored, and what choices you have.
Last updated: 16 August 2026
Who We Are
Wattle Office is a mobile app for simple business administration, including customers, jobs, quotes, invoices, expenses, receipts, reports, GST estimates, BAS summaries and subscription access.
For privacy questions, contact us at admin@encryptionjwegames.com.
Information You Enter In The App
Wattle Office lets you enter business information such as customer names, business names, phone numbers, email addresses, job details, addresses, ABNs, licence numbers, invoice and quote details, expense records, receipt images, notes, payment records and business profile details. If you choose to add bank details such as a BSB and account number, those details are saved so they can appear on invoices or quotes you create.
This business data is stored locally on your device first. Wattle Office does not store your customers, jobs, invoices, quotes, expenses, bank details, receipts, job photos or business logo on a Wattle Office or developer-controlled server. Data leaves the device only when you choose a cloud folder, export or share it. For example, data may leave your device if you select Google Drive, OneDrive, Dropbox or another storage provider for sync, send an invoice or quote to a client, or share a PDF, CSV or backup file. Technical diagnostics on Windows are also kept locally and leave the device only when you explicitly choose Export diagnostics and send the file yourself.
An earlier app version could create a protected legacy
office_data record in Firebase for an affected
account. Current versions do not use that record for sync and do
not write new business data there. Any remaining legacy record is
being handled through an audited deletion process; account deletion
will remove it where present before the account itself is deleted.
Google Sign-In
Wattle Office uses Google Sign-In so access to the app can be tied to your Google account. The app may receive your Google account name, email address and basic profile identifier from Google. This information is used to identify your account and manage app access. Free-trial eligibility is managed by Google Play. Your Google account identifier is also used to keep each local or user-managed cloud workspace separate.
Google Play Subscriptions
Wattle Office uses Google Play Billing for subscriptions. Purchases, renewals, cancellations and payment handling are processed by Google Play. Eligible new customers can receive one month free. After the free month, the subscription automatically renews at $19.99 AUD per month unless it is cancelled before the next billing date. You can cancel at any time through Google Play and there is no lock-in contract. Google Play displays the final price and confirms trial eligibility before purchase.
Wattle Office receives subscription status information needed to unlock access. App versions before 1.0.42 used a protected Firebase backend record containing the subscription product, expiry and a one-way hash of the Play purchase token. Wattle Office 1.0.42 and later use the Cloudflare service described below. The raw purchase token is used for server-side verification and is not placed in your business records or cloud backup. We do not receive or store your full payment card details.
Cloudflare backend: in Wattle Office 1.0.42 and later, subscription and account-access requests are processed by a Cloudflare Worker while Firebase Authentication continues to identify the signed-in account. The Worker will receive a Firebase sign-in token and, on supported devices, an App Check token so it can authenticate the request; it may also read the verified account email to apply an owner or app reviewer access rule. These tokens and the email are not stored in D1. A private Cloudflare D1 database will store the Firebase account ID, subscription product, status, expiry, verification time and a one-way purchase-token hash. It will also retain the Play purchase token encrypted with a separate server-side key so the Worker can periodically re-check the subscription with Google Play. Cloudflare will therefore process this limited account and subscription data, along with normal request metadata, under its service policies. After account deletion, a one-way hash of the deleted Firebase account ID may remain only to stop a still-valid sign-in token from recreating subscription data. It stops being used after 48 hours and is scheduled for removal by the next daily cleanup. If that cleanup is delayed, the marker remains inactive and is removed by the next successful run; the raw account ID is not kept in it. Deleting these records removes them from the live D1 database. Cloudflare D1's always-on recovery history may still make an earlier database state recoverable for up to seven days on the Free plan. Wattle Office does not use that recovery history for routine subscription or account processing. Cloudflare controls its removal under the applicable recovery-history retention period. The selected D1 region is a placement preference and does not guarantee that this data is stored only in Australia. Automatic backend tracing is disabled and application logs are restricted so purchase tokens, sign-in tokens, App Check tokens and full Google Play request addresses are not intentionally logged. This change does not put customers, jobs, invoices, quotes, expenses, receipts, bank details or sync packages in Cloudflare. Earlier app versions may continue to use the legacy Firebase backend until they are updated.
App Usage And Crash Diagnostics
On Android release builds, Wattle Office uses Firebase Analytics and Firebase Crashlytics to understand whether important setup steps are completed and to diagnose crashes. Product events use general names such as onboarding completed, first invoice created or help opened. They do not include customer names, invoice text, receipt contents, bank details or other business-record contents. Advertising ID collection and advertising personalization signals are disabled in the Android app.
Crash reports may include technical information such as the app version, device model, operating system, time of the crash and a technical stack trace. This information is used only to understand app reliability and improve Wattle Office.
Photos, Receipts And Files
If you attach receipt photos, business logos or other files, those files are used to provide app features such as receipt records and invoice or quote PDF branding. These files are stored on your device unless you choose to export, share or place them in a cloud folder you control. Cloud sync packages are encrypted with the sync passphrase you choose before they are written to that folder. Wattle Office does not receive or retain that passphrase.
Exports And Sharing
Wattle Office can create PDFs, CSV files and backup exports. When you choose to share or export a file, the destination you select may receive that information. For example, if you email an invoice PDF, your email provider and the recipient will receive that file. If your business profile includes a licence number or bank details, those details may be included in exported invoices or quotes.
Third-Party Services
Wattle Office may use these third-party services:
- Google Sign-In, to let you sign in with your Google account.
- Google Play Billing, to manage monthly subscriptions.
- Firebase Authentication, to support account-based Google sign-in.
- Firebase Analytics and Crashlytics on Android release builds, to measure general workflow completion and diagnose app crashes.
- Cloudflare Workers and D1, for Wattle Office 1.0.42 and later, to verify account access and store the limited encrypted subscription information described above.
- Device operating system services, such as file picking, camera access, photo access and share sheets when you choose to use those features.
How We Use Information
Information is used to:
- Provide the app's business admin features.
- Save your customers, jobs, invoices, quotes and expenses.
- Create reports, PDFs, CSV files and BAS estimate summaries.
- Manage your free trial and subscription access.
- Sync records through a cloud folder you explicitly choose.
- Let you export, import or share records when you choose.
- Maintain app reliability and security.
- Understand general onboarding and feature completion without collecting business-record contents.
Data Storage And Security
Wattle Office is designed as a local-first app. Your business records are stored on your device first. If you enable sync, the app reads and writes a Wattle Office package in the folder you selected. The package is encrypted before it is written. Access, transmission, retention and provider security for that folder are controlled by your chosen provider and your account with that provider. To use the records on another device, you must connect that device to the same provider, select the same folder and enter the same sync passphrase. Wattle Office cannot recover a lost sync passphrase. You are responsible for protecting your device, cloud account, sync passphrase and exported backup files.
No app can guarantee absolute security. We use reasonable steps to keep the app trustworthy and limit data collection to what is needed for the app to work.
Data Retention And Deletion
Records you create in Wattle Office remain on your device until you edit, delete, export, import, uninstall the app or clear app data. You can delete records inside the app where delete actions are provided. A cloud sync package remains in the storage provider and folder you selected until you delete it there. Wattle Office and the developer do not control or retain that package. You can also remove the app from your device.
Entitlement metadata held for Wattle Office access is deleted when
the in-app account deletion completes. Any remaining legacy
Firebase office_data and entitlement records are handled
first, including a purchase-token ownership index only when it is
confirmed to belong to that Firebase account. In Wattle Office
1.0.42 and later, deletion then removes the matching D1
entitlement, purchase-token hash and encrypted purchase token before
deleting Firebase Authentication access. A one-way
account-ID hash may remain for the short replay-protection period
described above, then is purged. Deleted D1 rows can remain
recoverable in Cloudflare's point-in-time history for up to seven
days as described above. Subscription and purchase records managed
by Google Play remain controlled through your Google account and
Google Play subscription settings.
Children's Privacy
Wattle Office is intended for business use and is not directed to children. We do not knowingly collect personal information from children.
Australian Tax And BAS Notes
Wattle Office can estimate GST and BAS summary figures from the records you enter. These summaries are estimates only and should be checked with your accountant or the Australian Taxation Office.
Changes To This Policy
We may update this policy as Wattle Office changes. When we do, we will update the date at the top of this page.