Privacy Policy

Last Updated: June 7, 2026

1. Introduction

Welcome to EgoSales. We are committed to protecting your personal data and your customers' privacy. This Privacy Policy explains how we collect, use, store, and safeguard information when you use our application.

2. Offline-First Architecture & Data Ownership

EgoSales operates on an offline-first basis. The sales ledger, client contact records, and transactions you input are stored locally on your device using IndexedDB (browser-based storage).

You retain full ownership and control of your local data. Wiping your browser cache or deleting the application data will delete this local storage unless synced or backed up.

3. Column-Level Encryption at Rest

To protect Personally Identifiable Information (PII) against unauthorized access:

  • All customer names, phone numbers, and email addresses are encrypted before being synchronized to our cloud databases.
  • We utilize industry-standard AES-256 (via pgcrypto) column-level encryption on PostgreSQL.
  • We generate cryptographic blind indexes (HMAC-SHA256) for search queries, meaning the raw text of your clients' phone numbers or emails is never stored or searchable in plaintext on our cloud storage.

4. Google OAuth and Authentication

When you sign in using Google OAuth, we only request the basic profile details required for authentication (your email address and profile ID). We do not request permission to access your emails, contacts, or other Google services unless explicitly prompted.

5. Data Portability (Backup & Restore)

You can export a complete copy of your local sales ledger database at any time through the Backup & Restore menu in settings. We do not restrict your access to your data or charge fees for data retrieval.

6. Contact Us

If you have questions regarding this Privacy Policy or data security on EgoSales, please email us at support@egosales.com.