Skip to policy content
NineBrief Free Business Tools Practical documents, made simply.

Privacy Policy

1. Who we are and what this policy covers

This policy applies to the Tools hub, Invoice Generator, Quote & Estimate Generator, Purchase Order Generator and Delivery Note Generator under ninebrief.com/tools/, including visits redirected from the historical Invoice Generator address. These tools are not a separate company. Contact NineBrief Inc. about privacy at legal@ninebrief.com.

This is a service-specific notice for the current no-account tools. Other areas of ninebrief.com, including inquiries, waitlists and any separately offered account, payment or document-processing service, may involve different processing described in the notice for that service. This policy does not replace unrelated company-wide agreements or authorize an automatic transfer of local drafts to another NineBrief service.

2. Your documents and your website visit are different

The current editors process document contents in your browser. Normal editing, selecting supported images, JSON import, preview and document conversion do not upload your document to a NineBrief document database or AI-model service. Working drafts are not saved to a NineBrief account.

What you enter may include business and customer names, addresses, contact and tax identifiers, document numbers, dates, descriptions, quantities, prices, adjustments, payment instructions, delivery details, notes and logos or images. The tools use these locally to display, calculate, save, convert and export your document. Image validation and supported resizing also occur in the browser.

Visiting the tools still creates network requests. Website delivery, font loading and browser security reporting can involve personal information such as an IP address and request details. Browser-local document editing does not mean that no data is processed, that the site works entirely offline, or that every network record stays in Kenya.

Include only information you are entitled to use. A business preparing a document remains responsible for its own handling of customer information. Browser storage is not an encrypted NineBrief vault: another person using your browser profile, relevant extensions, compromised software or code with appropriate same-origin access may access it. The /tools/ path is not a separate browser security origin from the rest of ninebrief.com.

3. Browser drafts, language and temporary transfers

The tools retain one working draft per document family; Quote and Estimate modes share a draft. Drafts can contain your document settings and embedded images as well as text.

Closing an ordinary tab does not normally remove local storage. Browser-data deletion, private-browsing behaviour, storage eviction, profile changes, quota limits or device failures can remove drafts. Session restoration can affect the lifetime of session storage. Monitor the save status and keep an editable JSON backup where appropriate.

An unreadable draft may enter a recovery flow that pauses writes and retains the available original bytes. You can download an explicitly unvalidated recovery copy, retry or request a confirmed reset. Treat recovery files as confidential. NineBrief cannot remotely restore local-only data that your browser no longer holds.

4. Downloads, printing, clipboard and sharing

JSON export creates an editable file on your device; the tools do not encrypt it. PDF output uses the browser's print/PDF workflow. Your browser, operating system, selected printer or file destination, and device-level cloud sync control what happens to that output afterward.

A copy action places text on your device clipboard, which clipboard-history or sync services and other applications may access. The current tools do not automatically email documents or collect payments. Sending an export through email, messaging or shared storage is a separate disclosure you initiate. Clearing a draft does not erase downloads, clipboard history, printed documents or copies already shared.

5. Website delivery, fonts and security reports

Website delivery

Cloudflare delivers and protects the tool routes. Connection and security processing can include IP addresses, request times and URLs, browser/user-agent information, protocol details and related traffic information. Depending on the active service configuration, operational records may be available to NineBrief. This is separate from a cloud document library. Do not put confidential document information in URL query strings.

Fonts

The tools request interface and selected document fonts through Google's font services, including fonts.googleapis.com and fonts.gstatic.com. The provider receives network/request information to supply those resources. The editor does not send your document text as a font-request input. These fonts are not described as self-hosted.

Browser security reporting

A browser may send a report when a resource conflicts with the page's Content Security Policy. The service receives that request before preparing a restricted application log summary. The Worker limits report size and summarized entries. Its summary uses limited directive, disposition, source/blocked URL and status information. URL summarization removes credentials, query strings and fragments and does not retain data/blob contents in that summary. Remaining paths or diagnostic values can still be identifying; sanitization is not a guarantee of anonymity. These endpoints are not for customer-document uploads.

See Cloudflare's privacy information and Google Fonts' information for the providers' own descriptions. Those descriptions do not replace NineBrief's responsibilities for processing it controls.

6. Cookies and similar technologies

The generator's draft and language features use the browser storage described above and do not require an account-session cookie. Cookies applicable to the parent domain or delivery/security features can also affect a tool visit. The absence of cookie-setting code in an editor is not a guarantee that the entire ninebrief.com site has no cookies or analytics.

This notice does not treat visiting a page as consent to optional advertising or tracking. Where an optional feature requires consent, it must be separately explained and accompanied by the required choice before activation. Your browser can block or clear cookies and website storage, although doing so may affect security challenges, appearance, language preferences or draft saving. Contact us for information about a particular request or cookie you observe.

7. Communications, purposes and legal bases

If you email legal@ninebrief.com, we receive the message, sender details and any attachments you choose to send. We use this information to respond and handle the request. A redacted explanation or synthetic example is preferable to an entire invoice or recovery file. Sending a document to us by email is separate from editing it locally.

Under Kenya's Data Protection Act, 2019 and applicable regulations, processing must have an appropriate lawful basis. Necessary website delivery and proportionate security processing serve our legitimate interests in providing a reliable service and preventing misuse, subject to individuals' rights. We process inquiries to respond to the request, using contractual necessity only where a relevant contract or requested pre-contractual step actually applies. Statutory rights requests and required records or disclosures are processed to meet the applicable legal obligation. Consent-based optional processing must have a separate valid consent and withdrawal mechanism.

Authorized personnel and hosting, security, font and communication providers may handle the information needed for these purposes. Information we actually hold may also be disclosed where lawfully required or necessary to protect rights, subject to applicable law. This does not give us remote access to documents held only on your device. Local editing does not grant us permission to sell your documents or use their contents to train an AI model. This tool-specific statement is not a description of every other service on ninebrief.com.

8. Retention and processing outside Kenya

Local drafts remain subject to your browser and device, as described above; there is no NineBrief cloud-retention schedule for documents the editors do not upload. You control your exported copies.

For website and security records, the relevant retention criteria are the delivery/security feature involved and the period needed to operate it, diagnose an incident, address misuse or meet a legal obligation. For correspondence, the criteria are the time needed to resolve the inquiry, undertake necessary follow-up, handle a related dispute and meet applicable record-keeping duties. Rights-request records may be retained as necessary to demonstrate that the request was handled. We do not promise a single fixed deletion period across independent provider systems or infer that disabling one logging feature disables all records. Request category-specific retention information at our contact address.

Website, font and communication providers may process request or correspondence information outside Kenya. Nairobi is our confirmed location, not a data-residency guarantee. Applicable international transfers must meet Kenyan data-protection conditions, including required safeguards and additional conditions for sensitive personal data. This notice does not claim a particular adequacy decision, storage country or transfer agreement that has not been confirmed. You may request information about the providers and safeguards relevant to your information.

9. Your choices and rights

You can use the present editors without signing in, choose what to enter, export a backup, use available clear/reset controls, remove website storage in your browser or stop using the tools. Removing site data can also affect other NineBrief pages.

Subject to the applicable legal conditions, rights include being informed, access, objection, correction and erasure, as well as restriction and portability where provided by law. You may withdraw consent where processing relies on consent, without affecting lawful processing before withdrawal. Send requests to legal@ninebrief.com. We may ask for proportionate verification to protect you and others and will respond within the applicable statutory period, explaining any lawful limitation.

You may complain to Kenya's Office of the Data Protection Commissioner. Contacting NineBrief first is not a condition of that right. Other mandatory protections may apply in your circumstances.

We cannot remotely retrieve or erase a draft held solely in your browser. That limitation does not remove obligations concerning visit information or correspondence we actually hold. A request concerning an invoice issued by another business may also need to be directed to that business.

10. Security, intended use and policy updates

Validation and website security controls reduce risks but do not make a device, browser or website risk-free. The tools are not an encrypted vault or certified archive. Do not enter passwords, card-security codes or unrelated sensitive data. Use an appropriate device and keep necessary backups.

The tools are intended for legitimate business-document work, not child-directed activities. That intended audience does not remove legal duties concerning children's data. Concerns about privacy or security can be reported to legal@ninebrief.com without unnecessary confidential attachments.

Material changes to processing will be explained with the notice or consent required by law. The page will identify its effective date. This policy does not authorize silently uploading existing drafts into future account, AI or marketing services.