Browse the manual

Customer data and privacy

Export customer data, understand retained records, and control optional external processing.

On this page

For: business owners responding to customer data requests. Covers: customer data export and data retention.

Customer data export

You need data.export and access to the records. Owners, admins and accountants have export access by default. Custom roles can include it.

  1. Open Customers.
  2. Click Export.

Made with Pepper downloads a CSV with customer fields only.

Made with Pepper has no per-customer export of documents, payments or messages, and no anonymization action. To answer a data request, open the customer's page and the documents linked to it, and export the reports you need.

Data retention

Made with Pepper does not automatically delete finalized invoices. You remain responsible for the retention rules that apply to your business.

Soft-deleted customers and documents remain in the database with a deleted_at timestamp. There is no maintenance command for permanent removal.

Optional external processing

Made with Pepper includes owner controls for an optional TypeSafe provider. It is disabled by default.

The current connection test sends a fixed synthetic sentence, with no customer or invoice data. Customer-data features await independent evaluation and remain inactive.

Made with Pepper encrypts the saved API credential. Saving provider settings clears optional decision history. Daily maintenance removes optional metadata older than 30 days. Financial documents keep their existing retention behavior.

The provider’s own terms govern received data. Disabling cannot retract an earlier disclosure. Made with Pepper makes no zero-retention or data-residency promise.

See Configure optional suggestions for access, consent, limits, deletion and connection-test instructions.

External client connections

Made with Pepper provides owner-granted MCP and HTTP access. Both interfaces use the same permissions. Access starts off. The owner chooses an active staff delegate, permitted access and expiry. Guests cannot hold connections. Clients use a pasted credential or OAuth browser sign-in.

A client receives only the fields its tools and delegated user permit. Customer reads return active permitted IDs and names. Document reads include public lines, notes, exact totals and references. Internal notes, customer addresses and bank details stay outside those document responses.

People tools can disclose work email, job title, skills, teams, manager, time zone and weekly working hours. They exclude guests, private contact details, rates, time-off records and sign-in settings.

A client can prepare invoice drafts. Issuing needs the delegated person’s approval of each invoice, followed by client execution within 10 minutes from preparation. These tools send no email, record no payment and export no files.

The client can retain received records or send them to another service under its own settings and terms. Revocation stops later access. It cannot retract earlier copies.

Your server keeps connection metadata, credential hashes, draft attribution, request receipts, approval summaries, decisions and results. These records have no automatic deletion or pruning. A pasted credential appears once. Made with Pepper keeps its hash, without plaintext in stored connection or audit data. OAuth clients manage access and refresh tokens.

See Connect an external client for grants, expiry, limits, review and revocation.

Need help with the product?

Contact support