Local and connected use
Catalogi stores business details, client contacts, products, prices, drafts, issued invoices, PDFs and recorded payment information on your iPad. You can keep a business local. Its workspace is not uploaded until you explicitly connect it or join a shared business.
Versions with Account & sync include Clerk for authentication. The authentication SDK may contact Clerk when the app starts, even if your business remains local. Authentication requests include installation and device identifiers, device model, operating-system and app versions, and app identity. When you sign in, Clerk also processes the account and sign-in information you provide.
The app does not create accounts. During the private beta, we set up a sign-in for each invited person with the email address that person gives us. Clerk keeps that email address and the records of each sign-in.
Connecting a business sends its shared records to the Catalogi service, hosted using Supabase. Authorized people and devices in that business can receive its catalog, clients, drafts, invoices, PDFs and recorded payments. The service keeps operation and deletion records to apply changes safely and prevent deleted invoices or used numbers from returning.
These versions do not include advertising, cross-app tracking or product analytics. Clerk development telemetry is disabled; that does not disable the authentication requests described above. Recording a payment does not charge a card or transfer funds.
Joining a business
Opening a business invitation does not join the business automatically. You sign in, review the invitation and choose whether to join. A link can be used once and expires after seven days; a replacement retires the previous link.
Initial business data is downloaded separately before the app switches to it. Work saved on this iPad must be preserved or presented for review. Your account and business remain separate from the private installation process.
Protection and device backups
Catalogi uses complete iOS Data Protection for its workspace and app-owned temporary PDFs. Keep an iPad passcode enabled and iPadOS current. This does not provide end-to-end encryption of the shared business: the authorized service processes the records.
iPadOS may include app data in iCloud, Finder, Apple Devices or organization-managed backups. Apple, your organization and device settings control those copies and their retention.
Portable backups, sharing and printing
An exported Catalogi backup is readable JSON and may include client contact details and issued invoice PDFs. Its checksum detects accidental corruption; Catalogi does not separately encrypt or password-protect the export.
You may export a backup of a connected business, but you cannot restore an old backup into that shared business. A backup of the current local view is not a guarantee that every pending change or unknown server outcome has been preserved. Local-only businesses retain their separate backup restore options.
Files providers, Share destinations and AirPrint systems receive the copies you send them. Their practices apply to those copies. Catalogi removes its own temporary share files after completion, cancellation or failure, but cannot erase a recipient’s copy or a printed document. Sharing and printing do not automatically mark an invoice as Sent or Paid.
Deletion, sign-out and access removal
An invoice deleted from a connected business remains deleted when other devices reconnect; its number remains used. Pending deletion is shown separately from confirmed deletion. Service operation records and backup copies have a separate retention boundary, so deletion from the app is not a promise that every historical backup copy has already been erased.
Signing out does not delete the shared business. The app must protect pending and uncertain work before leaving. An owner can remove a member’s access; an offline iPad cannot be erased or notified immediately. Once removal is confirmed, only that person’s attributable unsent work may be exported for recovery, without the business’s shared directory or original invoice PDFs.
In local-only use, deleting a client removes its related drafts and invoices. Deleting a local business removes its drafts and invoices while preserving unrelated catalog and client records. Restoring an old local backup may bring back earlier records while preserving used invoice numbers.
Erasing local app data does not erase server records, external backups, shared PDFs, printed documents or recipients’ copies. It is logical deletion, not a forensic storage-erasure guarantee.
Asking us to delete your sign-in or business
In this beta, the app cannot delete a sign-in or a shared business, and it cannot move a business to another owner. To ask for one of these, open Settings in Catalogi, then About & support, then Privacy & Data, and tap “Contact privacy support”. This starts an email to our support address; send it from the email address you sign in with. The About & support page also shows the address. Tell us what to delete: your sign-in, or the whole shared business. Only the owner can ask us to delete a business.
We reply to confirm who you are and what will be removed. We then remove it by hand from Clerk and from the Catalogi service, and we tell you when it is done. We do not state a deadline during this beta. Deleting a member’s sign-in does not delete the business or the records that member entered in it. The name the owner entered for that member also stays in the business until the business is deleted.
If you are the owner, we cannot delete your sign-in and keep the business, because a business cannot change owners in this beta. We delete both together, after you confirm.
Backup copies and provider logs made before the deletion follow the providers’ own retention. Copies outside the service are not removed: exported backups, shared PDFs, printed documents and device backups.
Loss, recovery and support
Use Apple Find My or your organization’s device-management service to lock or erase a lost iPad. An authorized account can download server-accepted business data on another supported installation. Changes that existed only on the lost iPad may not be recoverable; local-only work requires a usable backup.
For support or other data requests during the private beta, contact us the same way. Do not send invitation links, passwords or full client data in an ordinary support message.
About this revision
This revision describes builds with Account & sync. Earlier local-only builds do not include Clerk accounts or shared business uploads. We update these disclosures when the app’s data practices change.