Privacy Policy

Last updated: April 12, 2026

The short version

We do not collect personal information from you. We do not ask for your name, email address, or billing information, because there is no account to create. Your invoices, clients, and settings are stored locally on your device in a private browser storage area — they never reach our servers. We do not use tracking cookies, Google Analytics, Facebook Pixel, or any third-party advertising script. The only analytics we use is a cookieless, aggregate traffic tool that does not identify individual visitors.

What we do not collect

  • We do not collect your name, email, phone number, address, or any other personal identifier.
  • We do not collect your clients' names, addresses, or tax identifiers.
  • We do not collect the contents of your invoices — line items, amounts, notes, or payment terms.
  • We do not set tracking cookies or third-party cookies of any kind.
  • We do not embed Google Analytics, Facebook Pixel, Hotjar, Mixpanel, or any comparable tracking tool.
  • We do not sell data, because we do not have data to sell.

What is stored in your browser

When you create an invoice, the app saves the invoice, any associated clients, and your preferences (theme, default template, etc.) into a private storage area inside your browser profile. This data never leaves your device. You can export it as a JSON backup from Settings, or delete it entirely by clearing your browser data for this site.

We also keep a tiny preferences blob in your browser — specifically, your chosen theme (light/dark) and a small piece of UI state so the app remembers how you left it.

The only time data leaves your browser

When you click "Download PDF", the app sends the invoice payload to a stateless PDF rendering endpoint that produces the PDF and streams the file back to you in a single HTTP response. The endpoint does not write the payload to a database, does not log the contents, and does not retain anything after the response is sent. No invoice data is stored server-side.

Server logs

Like any web service, our hosting provider maintains short-lived operational logs that include HTTP request timing, status codes, and IP addresses for security and abuse prevention. These logs are not used for profiling, are not joined with any other dataset, and are subject to the provider's standard retention policy. They do not contain the contents of your invoices.

Analytics

We use a cookieless, privacy-friendly analytics tool to understand aggregate traffic — how many people visit, which pages get viewed, and what Core Web Vitals look like. It does not set cookies, does not use browser fingerprinting, does not track individual users, and does not build a profile of your browsing.

Children

The app is not directed at children under 13. Because we do not collect personal information from anyone, we do not collect information from children either.

GDPR / CCPA

We are privacy-by-design, which means we do not collect personal data in the first place. There is nothing to consent to, nothing to request access to, nothing to ask us to delete, and nothing to opt out of — because nothing has been collected.

Changes to this policy

If we ever change this policy, the new version will be posted here with an updated "last updated" date. Because the architecture of the app is privacy-first by construction, any future change that reduces privacy would require a fundamental rewrite — which we would announce loudly before shipping.