Esta publicación todavía no se ha traducido al español. A continuación se muestra la versión en inglés.

← Volver al blog

Who Actually Sees Your Customer List? An Honest Look at Privacy in ToolBerry

The most private app is the one that never has your data in the first place. Here's where ToolBerry pulls that off, and just as honestly, where it doesn't.

Actualizado el 23 de julio de 2026

The most private app is the one that never has your data in the first place. Here's where ToolBerry pulls that off, and just as honestly, where it doesn't.


Imagine you run a two-truck HVAC shop. Over ten years you've built a list of 1,800 customers - names, home addresses, gate codes, which unit is in the crawlspace, who still owes you for the compressor. That list is the business. It's the thing you'd grab first if the office were on fire.

Now ask a simple question about the app you keep it in: who else can see it?

For most field service software, the honest answer is "we can, and so can anyone who breaches us." For ToolBerry, the honest answer is more interesting. We're going to give you all of it, including the parts that aren't flattering.


Why is protecting your data so hard in the first place?

Because the normal way software works is to take your data off your device and keep it on theirs.

Almost every field service app is "cloud-first": you type a customer in, and that record ships to the vendor's servers so their features can work. That's not a bug. It's the whole model. But it means your customer list now lives somewhere you don't control, guarded by a company whose security you can't audit.

And that turns out to be a real risk, not a theoretical one:

  • 15% of all breaches in 2024 involved a third party, a 68% jump in a single year (Verizon 2024 Data Breach Investigations Report). Your data isn't just exposed to your own mistakes anymore; it's exposed to every vendor holding a copy of it.
  • It happens to field service tools specifically. In August 2024, a security researcher found that ServiceBridge, a field-service management provider, had left 31.5 million documents exposed in a database with no password: work orders, invoices, and inspections carrying customer names, addresses, emails, and phone numbers (reported by researcher Jeremiah Fowler; write-up via Bitdefender). That's not a data broker or a bank. That's a tool for running exactly the kind of business you run.

Your customers already sense this. 81% of Americans say the data companies collect will be used in ways they're not comfortable with, and 73% feel they have little or no control over it (Pew Research Center, 2023). And it shows up in dollars: 75% of U.S. consumers say they'd stop buying from a brand after a cyber incident (Vercara, 2023). When the leak has your name on the invoice, it's your customers who walk.


What does ToolBerry do differently?

In its default mode, ToolBerry never takes your data off your phone, so there's nothing on our side to leak.

When you open ToolBerry without signing in, your customers, jobs, sites, and schedules are written to a real database on your device. The part of the app that talks to our servers doesn't even switch on until you sign in and turn on syncing. Until then, there is no account, no password, no server with your customer list on it. If we got breached tomorrow, there'd be nothing of yours to find.

That's the core of it, and a few things follow from it:

  • No trackers. ToolBerry ships no advertising SDKs, no marketing pixels, no cross-site cookies, and no fingerprinting. Not Google Analytics, not the Meta pixel, none of it.
  • No signup wall. Because we don't need a server account to identify you, there's no email, password, or SMS code to hand over just to start.
  • Your backups go to your cloud. When you connect Dropbox, your data lands in a Dropbox "App Folder" that's walled off to ToolBerry only. And if you set an encryption passphrase, it's scrambled on your device first, with a key we never receive and can't recover. We cover the full mechanics in Your Data, Your Dropbox.

This is the same architecture we wrote about in Why ToolBerry Is Offline-First. Privacy isn't a feature we bolted on. It falls out of the decision to make your device the source of truth.


So what does leave your device? (the honest part)

Two things: a small amount of diagnostic data always, and your business data only if you turn on syncing. Here's the precise version.

When you turn on multi-device sync, your business data does go to our servers. This is the tradeoff we won't paper over. The moment you sign in and enable syncing across devices or a team, your customers, contacts, sites, work orders, and invoices are copied to ToolBerry's database so your other devices can pull them down. Job photos and signed PDFs go to our private file storage. That data is protected by strict per-workspace access controls - but we'll be straight with you: it is not end-to-end encrypted on our servers. If you want the version where your data literally never touches us, that's the no-account, single-device mode above. Syncing is a real feature with a real privacy cost, and you should choose it on purpose.

A small amount of diagnostic data goes to one vendor, always, in both modes. To catch crashes and fix bugs, ToolBerry sends error reports, some usage counts, and performance timings to Sentry (a single, well-known monitoring service, with no ad networks involved). We attach a random device ID rather than your name, and error logs aren't meant to contain your business data. Two honest caveats: your workspace rides along as a label, and once, at signup, we record the approximate region and IP your install came from to understand which of our efforts are working. There is no in-app switch to turn this off today - if that matters to you, it's a fair thing to hold us to.

Addresses you search go to Mapbox. When you use address lookup or maps, the address you type is sent to Mapbox to turn it into a location. That's how the map works; it's worth knowing.


How do you get the most private setup?

You're in control of the tradeoff. If privacy is your top priority:

  1. Use ToolBerry without an account to keep everything on-device. This is the most private mode, full stop.
  2. If you need backup or a second device, connect Dropbox and set an encryption passphrase. Write the passphrase down somewhere safe. We can't recover it, which is exactly the point.
  3. Lock your device. Since your data lives on your phone, your passcode and device encryption are the front door. On the free tier, that's the main thing standing between your customer list and whoever finds a lost phone.

The bottom line

ToolBerry's default is genuinely private in a way most field service apps structurally can't be: your customer list stays on your device, and we never hold it. Turn on syncing and you trade some of that privacy for team features and peace-of-mind backup, a fair trade for many businesses, as long as you're making it with eyes open. We'd rather tell you exactly where that line is than pretend it isn't there.

Have a question about any of this? Email us at contact@toolberry.app.


Further reading

Compartir
XLinkedIn