Privacy
Draft for owner review. The facts below describe how the software behaves today. Legal entity, jurisdiction, contact channels and retention commitments must be confirmed by the business owner before this page is considered final.
What the application stores
- Invoices you create: your business details, the customer details you enter, line items, notes, and lifecycle events (issued, viewed, paid, cancelled).
- Accounts: name, email address, a password hash (or a Google account link when Google sign-in is enabled), and session records.
- Saved business defaults, customers and service items for registered users.
- Guest sessions: a random identifier in an HttpOnly cookie (180 days) that links guest invoices to the browser that created them. Only a hash of the cookie value is stored.
- Abuse controls: a hashed client identifier and failure counts for password attempts on protected invoices.
What stays in your browser
While you edit a new invoice, the form is saved in your browser's local storage so a refresh does not lose your work. Passwords are never stored there. Use “Discard” in the editor to remove it.
Invoices are only emailed when you press Send and an email provider is configured. Each attempt and its result are recorded with the invoice.
Analytics
The public pages load Google Analytics (gtag). Owner to confirm: whether this remains enabled, and the consent mechanism for the launch market.
Retention, deletion and your rights
Owner to specify: retention periods for issued invoices, the deletion process, the legal entity responsible for this service, the applicable jurisdiction, and how to exercise access or deletion rights.
Contact
See the contact page.