Privacy Policy
Last updated: 16-08-2026
Draft — not yet reviewed by a lawyer
This policy was written by the person who wrote the code, so that the facts about what Invoicey does are correct. It is pending the owner's legal review and is not legal advice. Text in [brackets] has not been filled in yet.
Invoicey is run by Invoicey Private Limited (“we”, “us”), based at 123 Business Street, Suite 100, New York, NY 10001, India. This page explains what we collect, why, who else sees it, how long we keep it, and how to make us delete it. It is written to be read, not to be survived.
The short version
You sign in, you type invoices, we store them so you can come back to them. If you use the AI assistant, the draft you are working on is sent to Google to be turned into fields. We do not sell anything, we do not advertise, and we do not share your invoices with anyone except the service providers listed below that we need in order to run the product. You can export everything and delete everything, from inside the app, whenever you want (a few times a day — there is a fair-use cap so one account cannot exhaust the free tier for everyone).
Who is responsible for what
Your invoices contain your clients' names, addresses and email addresses. Those people are not our users and have never heard of us. You decide what goes into an invoice; we just store and process it for you. In data-protection terms you are the one responsible for that information, and we handle it on your instructions. Our job is to keep it secure, not use it for anything else, and delete it when you tell us to.
What we collect
Your account. Email address, display name, profile picture URL, and which sign-in method you used (Google, or email and password). This is held by Firebase Authentication, which is operated by Google. If you use a password, Google holds it — we never see it. We keep a copy of your email, name, picture URL, sign-in methods, account creation date and last sign-in date in our own database.
Your invoices. Everything you type into one: your business name, address, email, phone and logo URL; your client's name, address and email; line items, descriptions and amounts; dates, currency, discount, CGST, SGST, service charge, notes, terms, and the payment details you choose to print on the invoice. The payment-details field is free text — if you type a bank account number, IFSC code or UPI ID there, we store it exactly as typed. We do not verify it, use it, or send anything to it. Invoicey never takes payments and never sends your invoices anywhere; it produces files that you send yourself.
Your business details. If you save a business profile, we store what you put in it: your business name, address, email, phone and logo URL, your GSTIN and PAN, your state code, your LUT ARN, your invoice defaults, your signature name and image URL, and the payment details you save for reuse — bank account name and number, IFSC code, bank name and UPI ID. We store them exactly as typed and use them for one thing: filling in your next invoice and drawing the payment block and UPI QR code printed on it. We never verify them, never send money anywhere, and never share them with anyone. Deleting your account destroys this record outright — export first if you need it.
Feedback. If you send feedback, we store your message, an optional rating, the category and which page you were on.
Technical logs. We record events like sign-ins, invoice creation, exports, errors and AI requests. Each entry can include your user id, your IP address, your browser's user-agent string, and context such as an invoice id, an amount, a currency, or — for errors — a stack trace. Anything that looks like a token, password, key or cookie is stripped out automatically before an entry is written, and each entry is size-capped.
One of those entries is much more detailed than the rest and we would rather say so than let you find out: when you use the AI assistant, we keep our own copy of what was sent — the message you typed and the full draft it was working on, which means your business details, your client's name, email and address, the line items, and the payment/bank note if you have filled one in. It is kept for 30 days and then deleted automatically. It exists so the maintainer can debug a bad AI response. If that is not a trade you want to make, do not use the assistant — the rest of the product does not write these entries.
Cookies and browser storage. We set two cookies (session-token, session-id) and store your display name, user id and basic profile in your browser's local storage, so you stay signed in. Firebase stores its own sign-in session in your browser. Your theme preference is stored locally under invoicey-theme. The invoice you are editing is also saved to your browser's local storage as you type (keys beginning invoicey-draft:), so a closed tab or a dropped connection does not lose your work. That draft holds the same content as the invoice itself — your client's name, address and email, the line items and the amounts — it is unencrypted on your own device, and it is kept for up to seven days before it is discarded. It is stored under your user id, it is deleted when you restore or discard it, and signing out or deleting your account clears it. It never leaves your browser: it is not sent to us and it is not a cookie. On a shared or public computer, sign out when you are done. We do not use advertising or tracking cookies. We also run Vercel Analytics and Vercel Speed Insights on our pages to count page views and measure loading speed; these are cookieless and do not build a profile of you.
The AI assistant sends your draft to Google
This is the part people are most likely to be surprised by, so it gets its own section.
When you use the AI assistant to draft an invoice, the entire draft you are currently working on is sent to Google's Gemini API , along with your message and up to the last ten turns of your conversation with the assistant. The draft is serialised whole, so that includes your business details, your client's name, email address and postal address, every line-item description, and every amount. It has to be — that is what lets the assistant fill in the right fields.
The assistant never writes to your saved invoices. It hands a suggested set of changes back to your browser, you review them, and nothing is stored until you press Save. It is only available while you are creating a new invoice. If you never open the AI panel, nothing is ever sent to Google's AI service.
We currently call Gemini on Google's free tier. Under its terms, the content sent and the responses produced may be used by Google to improve its products and may be read by human reviewers— and that content includes your clients' details as they appear in the draft you send to the assistant. We would rather this were not the case, and moving to a paid key (where prompts are not used for training and are retained only briefly for security and legal compliance) is on the list. Until this paragraph says otherwise, assume the free-tier terms apply.
The assistant can also work from text you paste into it — a client's email, a WhatsApp message, a scope note — and extract the invoice from that. Whatever you paste is sent to Google too, including anything personal about the sender that happens to be in it, such as a signature block, a phone number or an unrelated paragraph further down the thread. Paste the part you need rather than the whole message.
This is the single most important thing on this page, which is why it is not buried: if you do not want your clients' names and addresses reaching Google, do not use the AI assistant. Everything else in Invoicey works without it.
Who else sees your data
These are the service providers we use to run Invoicey. They are the complete list.
| Who | What they get | Where |
|---|---|---|
| Google LLC (Firebase Authentication) | Your email, name, profile picture URL, sign-in method and sign-in activity | Google's global infrastructure, mainly the United States |
| Google LLC (Gemini API) | The invoice draft you send to the AI assistant, and only when you use it | Google's global infrastructure |
| MongoDB, Inc. (Atlas) | Your account record, your business profile, your invoices, your feedback and the technical logs | [ATLAS REGION] |
| Vercel Inc. | Hosting, every HTTP request, server-side execution, runtime logs, and the cookieless analytics described above | [VERCEL REGION] |
| Functional Software, Inc. (Sentry) | Error reports: what broke and where. Request bodies, invoice contents and client details are stripped out before an event leaves our servers, and session replay — which would record an invoice on screen — is switched off | [SENTRY REGION] |
We do not sell personal data, we do not share it for advertising, and we do not give it to anyone else except where the law requires it.
Some of these providers process data outside India, mainly in the United States. Indian law currently permits transfers except to countries the Central Government specifically restricts, and no such restriction has been issued.
Who at Invoicey can see your data
Invoicey is run by one person. That person holds an administrator account which can list users, open any invoice — including ones you have deleted — read feedback, read the technical logs, and export invoice data in bulk. It exists for support, abuse handling and keeping the service running, and it is not used for anything else. Administrator actions are themselves logged, and those audit records are kept for 365 days.
We are telling you this because it is true and you would otherwise have no way of knowing. There is no technical measure that would stop the operator of a database from reading it, and we are not going to imply otherwise.
How long we keep things
- Your account, business profile and invoices: until you ask us to delete them.
- The invoice draft in your browser: up to seven days, then it is discarded on the next visit. It lives on your device, not ours.
- An invoice you delete: deleting an invoice hides it from your dashboard and exports. It is not removed from the database today — it is marked deleted and kept, and the administrator described above can still see it. We are building an automatic purge that removes deleted invoices for good after 30 days; until this page says it has landed, treat a deleted invoice as hidden rather than erased. If you want one actually gone now, ask the Grievance Officer.
- Feedback: kept while the product exists, because it is how we decide what to build. Tell us if you want yours removed.
- Technical logs: on the schedule below. These are enforced automatically by the database expiring each record, not by anyone remembering to do it.
| Kind of log | Deleted after |
|---|---|
| Errors, including stack traces | 365 days |
| Administrator audit records | 365 days |
| Warnings | 90 days |
| Sign-in and invoice activity | 180 days |
| AI-assistant requests and in-browser events | 30 days |
| Everything else | 30 days |
Backups: we do not currently take automated off-site backups of the database. That is a gap we intend to close, and this page will say so when it is closed. In the meantime: export the invoices you cannot afford to lose, and keep the files somewhere you control.
Your rights, and how to actually use them
Indian data-protection law gives you the right to see what we hold about you, correct it, have it erased, complain about how we handled it, and nominate someone to exercise those rights on your behalf. Here is how each one works today.
- See what we hold. Export your account from your account page in the app. You get one file containing your profile, your saved business details (including your GSTIN, PAN and the bank and UPI details you saved for reuse), every invoice with its line items and tax breakdown — including the ones you have deleted — your feedback, and your recent activity records. You can also export any individual invoice as PDF, HTML, CSV or JSON from the editor. If you cannot reach the app, email the Grievance Officer and we will send it to you within 30 days.
- Correct it. Edit any invoice in the app. To change your name or email, change it with whichever sign-in provider you used; it updates here the next time you sign in.
- Delete it. Delete your account from your account page. We ask you to sign in again and type your email address first, because this one is not reversible. It destroys your invoices — including the ones you had already deleted — your saved business details (GSTIN, PAN, bank and UPI details, signature), your feedback and your account record, and removes your sign-in account from Firebase. Your technical log entries are not destroyed; instead everything identifying is emptied out of them — your user id, your IP address, your user-agent, and the message and context fields, which is what removes the stored AI drafts described above. What is left is a bare record that some event happened at some time, and it expires on the schedule above. If you cannot reach the app, email the Grievance Officer from the address on your account and we will do it within 30 days.
- Export before you delete. If you are registered under GST, you are required to keep your records for 72 months. That duty is yours, not ours — Invoicey is not your books of account. Deleting your account here does not excuse it, so take your files first.
- Complain. Contact the Grievance Officer below. If you are not satisfied with how we handle it, you can complain to the Data Protection Board of India.
- Nominate someone. You can nominate a person to exercise these rights for you if you die or become unable to exercise them yourself. We do not have a form for this — email the Grievance Officer and we will record it by hand.
Grievance Officer
If you have a question or a complaint about how we handle your data, this is the person to contact.
Grievance Officer
Faran Mohammad
123 Business Street, Suite 100, New York, NY 10001, India
We respond to privacy grievances within 30 days.
If we need longer, we will tell you why before those 30 days are up.
Security
Reaching any of your data requires a signed-in session, and password accounts have to verify their email address first. Every request is checked against the identity of the signed-in user and scoped to that user's own records. Traffic is served over HTTPS with HSTS, and data is encrypted in transit and at rest by our hosting providers. Secrets are stripped out of log entries before they are written.
We are a small operation and we will not claim more than that. There is no SOC 2 report, no external audit, and no security team. If you find a vulnerability, please email ffaranm15@gmail.com — we would much rather hear it from you.
If something goes wrong
If personal data is breached, we will tell affected users without delay — what happened, what was exposed, and what to do about it — and report it to the Data Protection Board of India as required.
Children
Invoicey is for people running a business and is not intended for anyone under 18. We do not knowingly collect data from children.
Changes
If we change this policy in a way that affects you, we will say so in the app before it takes effect, not quietly edit this page. The date at the top always reflects the current version.