任
Ataru
ProductsPricingAboutContact
Sign In Sign Up

Privacy Policy

Last updated: May 2026

Ataru LLC ("Ataru", "we", "us", or "our") operates the Ataru Cesium application and the ataru.io website (collectively, the "Service"). This Privacy Policy explains how we collect, use, and safeguard your information when you use the Service.

1. Information We Collect

Account Information

When you create an account, we collect your name and email address. If you sign in with Google, we receive your name, email, and profile photo from Google.

Business Data

The Service stores business data you provide, including time entries, client and project details, invoices, expenses, tax configurations, and estimated tax payments. This data is yours. We store it solely to provide the Service to you.

Contact Form Submissions

When you submit the contact form, we collect your name, email address, and message content. We also record your IP address for spam prevention.

Usage Data

We may collect basic usage metrics (pages visited, features used) to improve the Service. We do not use third-party analytics trackers.

2. How We Use Your Information

  • To provide and maintain the Service
  • To send transactional emails (invoices, account notifications, contact form confirmations, subscription lifecycle reminders)
  • To respond to your contact form submissions
  • To enforce rate limits and prevent abuse

We do not sell, rent, or share your personal information with third parties for marketing purposes.

3. Data Storage and Security

Your data is stored in Google Cloud Firestore and served via Google Cloud Run. We use Firebase Authentication for account management with support for multi-factor authentication. All data is transmitted over HTTPS.

We take reasonable measures to protect your data but cannot guarantee absolute security. No method of electronic storage is 100% secure.

4. Third-Party Services

We use the following third-party services to operate:

  • Google Cloud Platform - Infrastructure and authentication
  • Stripe - Payment processing and subscription management. Stripe processes credit card information and tax compliance data; we do not store your full card number on our systems
  • Resend - Transactional email delivery

Each service has its own privacy policy governing how they process data.

5. Data Retention

Active Accounts

Your business data is retained for as long as your account is active and your subscription is current.

Cancelled or Expired Subscriptions

When your subscription ends (whether by cancellation, payment failure, or expiry), we retain your data for 90 days from the end-of-access date. During this period:

  • You can log in to download your data via the export feature
  • You can resubscribe at any time and your data will be fully restored
  • You will receive a warning email at Day 60 with 30 days notice before deletion
  • At Day 90, all your data is permanently deleted from our systems and cannot be recovered

Immediate Deletion

You may request immediate permanent deletion at any time via the account settings page or by contacting us. This is irreversible.

Tax Records

Cesium is a tool, not a system-of-record for your tax compliance. You are responsible for retaining your own business records as required by your jurisdiction. Use the export feature to keep your own copies for as long as your jurisdiction requires.

Email Logs

We retain logs of transactional emails sent (sender, recipient, type, timestamp) for the lifetime of your account plus a reasonable period thereafter for audit purposes.

Stripe Webhook Logs

We retain Stripe webhook event identifiers in a stripe_events collection for idempotency. This collection contains no personal data, only Stripe event IDs and types.

6. Your Rights

You may request access to, correction of, or deletion of your personal data by contacting us. You may delete your account at any time through the application settings.

If you are in the European Economic Area (EEA) or United Kingdom, you have additional rights under GDPR including:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure / "right to be forgotten" (Article 17)
  • Right to restrict processing (Article 18)
  • Right to data portability (Article 20)

The data export feature satisfies the right to data portability. The "delete my account permanently" feature satisfies the right to erasure.

If you are in California, you have rights under CCPA including the right to know, delete, and opt out of sale (we do not sell your data).

7. Cookies

We use a session cookie (__session) for authentication and a timezone cookie (tz) for date display. We do not use advertising or tracking cookies.

8. Children's Privacy

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect information from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "last updated" date. Your continued use of the Service after changes constitutes acceptance of the revised policy.

10. Contact

For questions about this Privacy Policy, please use the contact form.

任
Ataru

Business tools for freelancers. Track time, manage invoicing, and keep your finances organized.

Product

  • Products
  • Pricing
  • About
  • Contact

Legal

  • Privacy Policy
  • Terms of Service

© 2026 Ataru LLC. All rights reserved.