Skip to main content

Privacy Policy

Last updated: 31 July 2026

This Privacy Policy explains how we collect, use, and protect your information when you use our platform, website, and related services (collectively, the "Service").

Who we are: The Service is operated by Orleyton Ltd, trading as Tibr ("TIBR", "we", "us"), a company registered in England & Wales (Company No. 12577916). Registered office: The Old Plough, Bagstone Road, Bagstone, Wotton-under-Edge, GL12 8BD, United Kingdom. For the personal data of our account holders and website visitors, Orleyton Ltd is the data controller. Where you use the Service to store information about your own clients (for example names and site addresses inside your quotes), you are the controller of that data and we act as your data processor.

You can contact us about anything in this policy at privacy@tibr.ai.

1. Information We Collect

We collect the following types of information when you use the Service:

  • Account Information: Your name, email address, and billing details.
  • Usage Data: Log files, IP address, browser type, device information, and interactions with the platform.
  • Content Data: Information you upload or create through the Service (e.g., project data, quote templates, estimates, documents, and photos). This may include personal data about your own clients, such as names, addresses, and contact details.

2. How We Use Information

We use your information to:

  • Provide, operate, and improve the Service.
  • Process payments and manage subscriptions.
  • Respond to your inquiries and provide support.
  • Send service updates and communications (including marketing, if you’ve opted in).
  • Ensure platform security, detect fraud, and enforce our Terms of Service.

AI model training: We do not use your Content Data (your quotes, project data, documents, or your clients' personal data) to train, develop, or improve any AI or machine-learning models, whether our own or a third party's, and our contracts with our AI providers (see section 3A) prohibit them from doing so.

2A. Legal Basis for Processing (UK/EU Users)

We process your personal data under the UK GDPR (and, where applicable, the EU GDPR) on the following legal bases:

  • Contractual necessity – to provide and operate the Service.
  • Legitimate interests – to improve the platform, prevent fraud, and maintain security.
  • Consent – for marketing communications, non-essential cookies, or optional features.
  • Legal obligation – when required by applicable laws, regulators, or court orders.

3. Sharing & Disclosure

We do not sell your personal data.

We share information with trusted third-party service providers (sub-processors) that help us operate the Service. These providers are bound by data protection agreements and only process your data as necessary to deliver their service to us. Our current sub-processors are:

  • Amazon Web Services (AWS) – cloud hosting and infrastructure.
  • Paddle – payment processing. Paddle acts as our merchant of record: when you buy a subscription or top-up, your payment and billing details are collected and processed by Paddle under Paddle's privacy policy.
  • Postmark and Amazon SES – transactional email delivery. Postmark also delivers our product news and tips emails (sent from the news.tibr.ai subdomain). Links in those news and tips emails use link tracking — they redirect briefly through Postmark so we can tell which content is useful. You can stop receiving these emails at any time via the unsubscribe or email-preferences link included in every one.
  • MailerLite – marketing email (only if you have opted in).
  • AI providers – see section 3A below.
  • Analytics – Google Analytics, Hotjar, and Meta Pixel on our website, only where you have consented via our cookie banner (see section 9).

We may also disclose your information:

  • To comply with legal obligations, law enforcement, or government requests;
  • To protect our rights, users, or the public from harm or fraud.

3A. AI Providers

Tibr's core features are powered by large language models ("AI"). When you use an AI feature (for example asking Tibr to build a quote, analyse a drawing or site photo, transcribe a voice note, or draft a document), the content needed for that request — which may include project details, client names and site addresses you have entered, documents and spreadsheets you upload, photos you attach, and audio you record for transcription — is sent to one or more of the following AI providers to generate the response:

  • Anthropic (Claude models)
  • OpenAI (GPT models, and Whisper for voice transcription)
  • Fireworks AI (hosted open-weight AI models)
  • Google (Gemini models)
  • Microsoft Azure (hosted AI services)
  • Tavily and Brave Search (web search used to ground AI answers; search queries only, not your stored content)

We access these providers on business/API terms under which your data is not used to train their models. Data is sent only when you use an AI feature, and only the content relevant to that request. The Tibr apps ask for your explicit consent to this AI data sharing before any of your content is sent; because Tibr's core features are delivered through these providers, the Service cannot be used without that consent, and you can withdraw it at any time by contacting us or deleting your account. A full, maintained list of our sub-processors (including these AI providers) is published at tibr.ai/subprocessors. We update it before adding or replacing a sub-processor.

4. Data Storage & Security

  • All data is hosted on Amazon Web Services (AWS) in secure data centers.
  • We use encryption in transit (TLS 1.2+) and at rest (AES-256) to protect your data.
  • Access to systems is restricted through role-based access controls and monitored for suspicious activity.
  • Regular backups and disaster recovery procedures are in place.

4A. Google Calendar, Google Drive, Google Photos & Google User Data

TIBR offers optional integrations with Google Calendar (so tradespeople can schedule won jobs around their existing diary), Google Drive (so they can pull their own project files into a quote, and save finished quote and RAMS PDFs back to a job folder in their Drive), and Google Photos (so they can attach site photos to a job). This section explains exactly what Google user data we access and how we handle it. All of these integrations are entirely optional: TIBR's scheduling, file, and photo features work without them.

What we access

If you choose to connect your Google Calendar (via Google's sign-in and consent screen), TIBR requests the https://www.googleapis.com/auth/calendar.events scope ("View and edit events on all your calendars"), plus your basic profile email address so we can show you which Google account is connected. We use this access only to:

  • Read events and free/busy information from your primary calendar, so that when you schedule a job we can suggest available dates and show you what you already have on around those dates.
  • Create, update, and delete a calendar event for a job you book through TIBR. The event contains the job details you can see in TIBR (client name, address, phone, quote reference, value, and a link back to the job). Re-booking updates that same event; removing the booking deletes it.

Google Drive (file import and "Save to Drive")

If you choose to add Google Drive access, TIBR requests the https://www.googleapis.com/auth/drive.file scope ("See, edit, create and delete only the specific Google Drive files that you use with this app"). This is Google's narrowest per-file Drive scope: TIBR can only access the individual files you hand-pick in the Google file picker (or files and folders TIBR itself created). TIBR cannot list, browse, search, or scan your Drive. When you pick files, TIBR downloads those files and stores them in your TIBR file library, exactly as if you had uploaded them directly (Google Docs, Sheets and Slides are converted to PDF/Excel on the way in). Imported files are then governed by this privacy policy like any other file you upload.

The same scope also powers the optional Save to Drive feature: when you click "Save to Drive" on a quote or RAMS document, TIBR creates a TibrAI folder in your Drive (with a sub-folder per job) and writes the PDF there. Saving the same document again updates that same file. These folders and files belong to you, live in your Drive under your control, and are the only things in your Drive TIBR can see.

Google Photos (site photos)

If you choose to add Google Photos access, TIBR requests the https://www.googleapis.com/auth/photospicker.mediaitems.readonly scope ("See selected photos and videos from Google Photos"), the Google Photos Picker scope. You pick photos in a Google-hosted picker window; TIBR can only ever access the specific photos you selected in that picker session and cannot list, browse, or scan your photo library. Picked photos are downloaded and stored against your job in TIBR (as job evidence, e.g. before/after photos), exactly like photos you upload directly, and are then governed by this privacy policy like any other file.

Beyond the specific access described above, we do not access your Gmail, contacts, or any other Google data, and we do not change your calendar settings or sharing.

How we use and store it

  • Google user data (Calendar, Drive, and Photos alike) is used solely to provide the in-app features described above to you, the signed-in user. It is never used for advertising, never sold, and never shared with third parties.
  • Google user data is not used to train, develop, or improve any AI or machine-learning models, whether generalised or otherwise.
  • Your calendar events are displayed to you transiently and are not copied into our database. The only things we store are your encrypted connection tokens, the job dates you choose, and the identifier of calendar events that TIBR itself created (so re-booking can move the right event).
  • OAuth access and refresh tokens are stored encrypted at rest, per individual user, and are never exposed in logs or to other users, including other members of your own team.
  • No human at TIBR reads your Google Calendar data except with your explicit permission (e.g., a support request), where necessary for security or abuse investigation, or where required by law.

Retention, disconnection, and revocation

  • You can disconnect at any time in Settings → Calendar → Disconnect inside TIBR: this immediately deletes your stored Google tokens (one Google connection powers Calendar, Drive, and Photos, so disconnecting removes all of them). Files and photos you already imported remain in your TIBR library; delete them from the Files page like any upload.
  • You can also revoke TIBR's access from your Google Account permissions page; TIBR detects the revocation and clears the stored connection.
  • Deleting your TIBR account deletes your stored tokens along with your other account data.
  • Calendar events TIBR created remain in your Google Calendar under your control unless you remove the booking in TIBR or delete them yourself.

Limited Use disclosure

TIBR's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. International Data Transfers

We are a UK company and the Service is operated from the United Kingdom. Some of our sub-processors (including AWS, Paddle, and the AI providers listed in section 3A) may process data in the United States or other countries outside the UK/EEA. Where personal data is transferred outside the UK or EEA, we rely on lawful safeguards, including:

  • UK adequacy regulations (including the UK–US Data Bridge, where the recipient is certified);
  • The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses;
  • EU Standard Contractual Clauses, where the EU GDPR applies.

6. Your Rights

Under the UK GDPR (and, where applicable, the EU GDPR), you have the right to:

  • Access or request a copy of your personal data.
  • Correct or update inaccurate information.
  • Delete your data or restrict its processing.
  • Object to certain uses (such as marketing).
  • Request data portability.
  • Withdraw consent at any time (where consent was the legal basis).

To exercise your rights, please contact us at privacy@tibr.ai. We will respond within one month.

You also have the right to lodge a complaint with the UK supervisory authority, the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint, or by phone on 0303 123 1113. We would appreciate the chance to address your concerns first, so please consider contacting us before approaching the ICO.

7. Data Retention

We retain personal data as follows:

  • Account and Content Data: for as long as your account remains active. If you delete your account (or ask us to), your account and content data are deleted from our live systems within 30 days, and from encrypted backups within a further 35 days as backups expire on rotation.
  • Billing records: retained for 6 years after the tax year they relate to, as required by UK tax law.
  • Server logs and usage data: retained for up to 12 months for security and diagnostics.
  • Marketing data: until you unsubscribe or withdraw consent.

You may request deletion of your account and associated data at any time by contacting us.

8. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or via email. The current version will always be available at tibr.ai/privacy. Continued use of the Service after changes take effect constitutes your acceptance of the updated policy.

9. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Maintain session state and login functionality (essential, always on);
  • Analyze traffic and usage patterns (Google Analytics, Hotjar), only with your consent;
  • Measure marketing campaigns (Meta Pixel), only with your consent.

Non-essential cookies are only set after you consent via the cookie banner, and you can change your choices at any time via "Manage cookies" in the footer. See our Cookie Policy for details.

10. Children’s Privacy

The Service is not intended for use by children under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately at privacy@tibr.ai.

11. Contact

If you have questions or concerns about this Privacy Policy or how we handle your data, you may contact us at:

Orleyton Ltd, trading as Tibr
Company No. 12577916 (England & Wales)
ICO registration reference: ZC204688
The Old Plough, Bagstone Road, Bagstone, Wotton-under-Edge, GL12 8BD, United Kingdom

Email: privacy@tibr.ai

We use essential cookies to make our site work. With your consent, we also use analytics and marketing cookies to improve your experience. You can manage your choices any time.