Last updated: 2026-09-04
What we collect
- Account data: your email address, authentication provider, and account identifiers used to sign you in. Passwords are stored only as secure hashes.
- Business profile: business name, address, payment instructions you optionally enter.
- Invoices and clients: data you create — client emails, line items, amounts, dates.
- Client email replies: when reply detection is enabled, we store the sender, subject, message text, and receipt time for replies to invoice and reminder emails so they can be associated with the correct invoice.
- Collection responses: payment promises, extension requests, disputes, accounts-payable contacts, installment proposals, and estimate responses or typed signatures submitted through a hosted document.
- Forwarded invoice requests: when you use Forward & Create, we store the forwarded sender, subject, message text, extracted draft fields, and processing status.
- Imported invoice documents: photos, images, and PDFs you choose to analyze are processed in memory and sent to a configured AI provider for field extraction. We do not retain the original uploaded file after the request completes. Confirmed invoice fields are stored only when you choose to import the record.
- Payment records: when online payments are enabled, we store transaction identifiers, amounts, currencies, statuses, and timestamps. Stripe collects and processes payment method and payout-account details; those sensitive financial details do not pass through our servers.
- Subscription records: plan, entitlement, renewal, expiration, and transaction identifiers supplied by Apple and RevenueCat. We do not receive your complete App Store payment-card details.
- Mobile app data: app platform, app version, and operating system version used to identify where an invoice was created and diagnose compatibility problems. Device model information and push-notification tokens are collected only when you opt in to notifications. We do not attach a device identifier to invoices.
- Usage analytics: Vercel Analytics and PostHog collect page views, product events, interactions, referring pages, and basic device or browser information. We use this information to understand feature adoption, diagnose usability problems, and improve conversion funnels. PostHog traffic is routed through our domain and respects your browser's Do Not Track setting.
- Hosted invoice page views: when one of your clients opens an invoice link (/i/<publicId>), we record a timestamp and a one-way hash of their IP and user-agent for dedup purposes. We never store raw IP addresses, and the hash rotates daily so we cannot correlate a viewer across days. This data is shown only to you (the invoice owner) on your dashboard.
How we use it
- To authenticate you using a signed web session or encrypted mobile access token, including Sign in with Apple and Google Sign-In when selected.
- To send invoice and reminder emails to your clients on your behalf.
- To receive replies to invoice and reminder emails, show them in your invoice dashboard, notify you, and pause pending reminders.
- To classify client responses, manage payment promises and plans, and extract invoice drafts from emails you forward to your private intake address.
- To generate AI content and extract fields from invoice documents — your text or selected document is sent to our AI providers (see below).
- To improve the Service via aggregate usage analytics.
- To manage App Store subscriptions, restore purchases, deliver opted-in notifications, prevent fraud, and maintain payment records.
Who we share with
We share data with the following sub-processors strictly to operate the Service:
- Resend — outbound and inbound email delivery
- Anthropic, OpenAI, DeepSeek, and Alibaba Cloud — AI generation and document extraction when a configured provider processes your invoice context or selected invoice document
- Neon — Postgres database hosting
- Vercel — application hosting and aggregate web analytics
- PostHog — product analytics, interaction measurement, and feature experimentation
- Stripe — subscription billing, connected-account onboarding, invoice payment processing, and payouts
- RevenueCat, Apple, and Google — mobile subscriptions, purchase restoration, and authentication
- Expo — mobile application delivery, updates, build infrastructure, aggregate app-launch insights, and opted-in push notifications
- Cloudflare — DNS and email routing
We do not sell your data. We do not share data with advertisers.
Cookies
We use an HMAC-signed session cookie on the web and encrypted device storage for mobile access tokens. Web cookies are httpOnly, sameSite=lax, and secure in production. Analytics services may use first-party cookies or storage to distinguish visits and measure product usage. We do not use cross-site advertising cookies or sell analytics data to advertisers.
Your rights
You can update profile information in Settings, export clients and invoices, and permanently delete your account from Settings → Account on the website or Delete account in the app. Deletion requires a one-time email confirmation code and a subscription safety check. It removes application account data and queued reminders, but cannot recall delivered emails or remove records held independently by payment providers. You may also request access, export, correction, or deletion by emailing [email protected]. You can withdraw optional notification permission in device settings. We respond to verified privacy requests within 30 days.
Data retention
We retain account, invoice, client reply, collection workflow, estimate response, and forwarded request data while your account is active. On account deletion, we delete personal data within 30 days, retaining only minimal records required for legal/financial compliance.
International transfers
Our infrastructure and analytics providers, including Vercel, Neon, PostHog, and Cloudflare, may process data in the United States, Europe, and other regions where they operate. By using the Service, you acknowledge that your data may be processed in those regions.
Contact
For privacy questions, write to [email protected].