Privacy Policy

Last updated October 10, 2026

Gigsworth is operated by Berrywine LLC ("we", "us"). This policy describes what Gigsworth stores about you, where it is held, who can reach it, and how to get rid of it. It is written to be specific rather than broad — if something is not described here, Gigsworth does not do it.

1. What we collect

Gigsworth collects only what the product needs to work.

Your account. Your email address and your name, both of which are required to create an account, and a time zone, which defaults to US Eastern and which you can change at any time. Your password is handled entirely by our authentication provider and stored as a hash — we never see it, and we cannot recover it for you.

What you enter. The records you create: gigs (a name, a date, an amount, hours worked, and any notes you add), expenses, mileage, tags, and income goals.

People you paid. If you record a contractor payment, Gigsworth stores the name you give that person, and their email address and phone number if you enter them. This is information about someone other than you. Only enter it if you are entitled to, and enter no more of it than you need — Gigsworth does not ask for, and has no field for, a Social Security number or a taxpayer identification number.

Feedback you send.If you use the in-app feedback form, we store your message, the contact email you supply, the page you were on, your browser’s user-agent string, and the version of Gigsworth you were running.

We do not collect Social Security or taxpayer identification numbers, bank account credentials, card numbers, home addresses, or copies of tax forms. Gigsworth has no advertising, no analytics or tracking pixels, and no third-party cookies. The only cookies it sets are the ones that keep you signed in.

2. Where it lives

Your records are stored in a Postgres database hosted by Supabase in the us-west-2 (Oregon, United States) region. Gigsworth is a United States product and your data is processed in the United States.

Every table holding your records is protected by row-level security, which means the database itself enforces that one signed-in user cannot read another user’s rows — the rule does not depend on the application getting it right.

3. Who can see it

You can. Anyone else who signs into your account can too, so keep your password to yourself.

We can. People operating Gigsworth hold administrative access to the underlying database and can read what you have entered. We use that access only to run, maintain, debug, secure and support the product, to answer your support requests, and where the law requires it. We do not read your records for any other reason.

Our service providers can, to the extent their service requires. They are listed in the next section. None of them is permitted to use your information for their own purposes.

We do not sell your personal or financial information, we do not share it with advertisers, and we do not use it to train machine-learning models.

4. Service providers

Gigsworth runs on infrastructure operated by other companies:

  • Supabase — database, authentication, and the account emails Gigsworth sends (sign-in confirmation, password resets, invitations).
  • Vercel — application hosting. Vercel processes the ordinary server logs that serving a website produces, including IP addresses, and holds the diagnostic records described in section 5.
  • Resend — delivery of those account emails. Resend handles your email address and the contents of the message sent to you.
  • Proton Mail — the mailbox that receives anything you send to support@gigsy.app.

We choose providers we reasonably believe maintain appropriate safeguards, and we may change providers. If we do, this list changes with them — it is the list as of the date at the top of this page, not a general statement of intent.

5. When something goes wrong

Gigsworth uses no third-party error-monitoring service. When an operation fails, the app writes a diagnostic record to its own server logs, which are held by our hosting provider and retained for a limited period set by that provider.

The records Gigsworth writes are stripped before they are written: gig and contractor names, amounts and email addresses are removed, and you are identified only by the opaque account identifier the authentication system assigns you. The intent is that a diagnostic record tells us what broke without telling us what you earned or who you played with.

If something fails while a page is drawing in your browser, the details are written to your own browser’s console and are not transmitted to us at all.

If we later add an error-monitoring service, it will be named in the list above and this section will describe what it receives, before it starts receiving anything.

6. How long we keep it

We keep your records for as long as your account exists, because they are the product — a gig you logged in January is meant to still be there in December.

You can delete your account yourself at any time from your settings page. Deleting your account is immediate and permanent: it removes your login and, with it, every gig, expense, contractor, contractor payment, mileage log, tag, income goal, feedback submission and profile record attached to it. There is no undo, no grace period, and no way for us to restore it for you afterwards.

Two things survive a deletion for a limited period, and we would rather say so than imply otherwise: routine encrypted database backups taken by our database provider, which age out on that provider’s own schedule, and the server logs described in section 5, which are retained for a limited window and hold the redacted diagnostic records rather than your own records. Neither is reachable from the product, and neither is used for anything but disaster recovery and debugging.

If you would rather keep a copy before you go, export your data from the export page first — once the account is gone we cannot produce one for you.

7. Security

Gigsworth is served over HTTPS, passwords are stored hashed by the authentication provider, access to your rows is enforced by the database rather than only by the application, and the keys that could bypass those rules are held on the server and never sent to your browser.

None of that is a guarantee. No system of electronic storage or transmission is completely secure, and Gigsworth is early software. Keep your password to yourself, tell us promptly at support@gigsy.app if you think someone else has reached your account, and keep your own records of anything you cannot afford to lose.

8. Children

Gigsworth is not intended for anyone under 13, and we do not knowingly collect information from children. If you believe a child has created an account, write to support@gigsy.app and we will delete it.

9. Your choices

You can correct your name and time zone, change your password, export everything you have entered, and delete your account outright — all from inside the product, without asking us. If you want something we have not built a button for, write to support@gigsy.app and we will do what we reasonably can.

10. Changes to this policy

If we change this policy we will update the date at the top of this page. If a change materially affects what we do with your information, we will tell you before it takes effect rather than expecting you to re-read the page.

11. Contact

Questions about this policy, or about anything Gigsworth holds for you, go to support@gigsy.app. A person reads that mailbox.

This policy sits alongside the Terms of Service, which cover what Gigsworth does, what it does not promise, and how either of us ends the agreement.