Legal

Privacy Policy

Last updated: 2026-09-04

This policy explains what invoiso collects, why we use it, which companies receive it, how long it is kept, and the choices and rights available to you. It covers the public website, the no-account invoice maker, signed-in workspaces and documents sent to signers.

The short version

  • Without an account, thecontents of your invoice stay in your browser. Visiting the site still creates an ordinary hosting request and the limited site measurements described below.
  • With an account, your records are stored on our servers so they work across devices and so the assistant can answer questions about them.
  • Some features send your data to other companies to work at all— reading a document sends it to a model provider, connecting a mailbox lets us read that mailbox, sending an e-invoice sends it across a network. Every one of them is listed below, with what leaves and when.
  • We do not sell workspace data or use it for advertising, and we do not use your invoices or documents to train our own models. We and our service providers process their contents only to provide the features you use, secure the service, meet legal obligations, or help you when you ask for support.

Who is responsible for the data

The controller for that data is Moorio, UAB, a company registered in Lithuania, company number 305786688, registered at Mindaugo 1A-103, Vilnius, Lithuania. You can reach us about anything on this page at privacy@invoiso.com.

invoiso is responsible for the personal data used to operate the site, accounts, billing, security, support and product analytics. When you put personal data about customers, suppliers, employees or signers into a workspace, your business decides why that data is used and is responsible for having a lawful reason to use it. invoiso processes it on your instructions to provide the service. The exact legal labels may differ by jurisdiction, but that division of responsibility does not.

Why we use it

  • To provide the service you request:create, store, sync, send and export records; read documents; answer questions; run connected services; administer accounts and subscriptions; and provide support.
  • To operate and protect invoiso:diagnose failures, measure performance, prevent abuse, enforce usage limits and keep an audit trail where the feature requires one.
  • With your consent:load optional Google Analytics. You can refuse it or withdraw consent without losing the service.
  • To comply with law:respond to valid legal requests, keep records the law requires, and establish or defend legal claims.

Where data-protection law requires a legal basis, these purposes rely as applicable on performing our contract with you, our legitimate interests in operating and securing the service, your consent, and compliance with legal obligations. We do not use workspace content for direct marketing or targeted advertising.

What we collect

What you type and upload

Issuer and customer names, addresses, email addresses, tax identifiers, invoice and credit-note lines, expenses, products, stock movements, notes. Plus the files themselves when you upload one: a receipt, a supplier bill, a bank statement, a PDF to be signed. A bank statement in particular contains your account activity, including counterparties and references.

Without an account this content lives in your browser’s local storage and is not uploaded to the invoiso database. With an account it is stored in our database and scoped to your workspace. It may be processed by the service providers below when a feature needs them.

Your conversations with the assistant

Messages you send and the answers, including the results the assistant’s tools returned from your own records, are stored so a conversation can be reopened. Deleting a conversation removes it.

Signed documents

A document sent for signature records each signer’s name and email address, the time they opened and signed it, andthe IP address the signature came from. Those details are written into a certificate of completion attached to the finished PDF, and into an audit trail you can read on the document. That is the point of the feature — a signature nobody can evidence is not worth much — but it means a signer’s IP address is recorded, and anyone you send the completed PDF to can see it.

Mail you send to your customers, and whether it was opened

When you email an invoice or invoiso sends a payment reminder on your behalf, we keep a record of it against that invoice: the address it went to, any address you copied, the subject, the message as it was sent, the time, and whether the provider accepted it or refused it and why. That record is what lets you answer “did this go out?” months later, and it is visible to you and to nobody else.

Open tracking is off unless you switch it on. When it is on, an invoice email carries a one-pixel image hosted by us, and fetching it tells us the message was displayed. Two things are worth knowing before you turn it on. It puts a request to our servers into a message sent to someone who did not choose that — your customer, not you. And it is a weak signal in both directions: most mail clients block remote images by default, and Gmail fetches them through Google’s cache whether or not a person read anything. So we show “opened” when the pixel fires and we say nothing at all when it does not, because the absence means nothing. We never record that a message was not opened, and you can switch the whole thing off in Settings at any time; existing records keep what they already have.

Account information

Sign-in is handled by Clerk: your email address and the sign-in method you choose. We receive and store the user and organisation identifiers, and the email address on the active session.

What your workspace has spent

Reading documents and asking the assistant cost money per use, so we record, per call: which capability it was, which model, how many tokens, what it cost, and the plan you were on.No message content and no document content is stored in those records— they are counters, and they are what the allowance on your plan is measured against.

Technical logs and analytics

Our hosting provider keeps short-term request logs — URL, status, response time, IP address and browser information — for operations and security. Vercel Web Analytics and Speed Insights also receive cookieless, aggregated page and performance measurements on deployed versions of the site. Google Analytics loads only if you accept it and then collects page and interaction data, approximate location, browser/device information and a pseudonymous cookie identifier. Declining leaves Google Analytics unloaded, and you can change your mind from the footer at any time.

We also keep our own record of activity inside a signed-in workspace. When somebody in your workspace opens a page in the app, we store which workspace, which user, which page and when. Record identifiers are replaced before the page is stored, so we keep /app/income/:id rather than the address of a particular invoice — we can see that invoices were opened, not which ones. Nothing you type is stored: no search terms, no form contents, no customer names. This is not consent-gated the way the analytics above are, because it records activity in an account rather than tracking a visitor, and it is what tells us which parts of the product are worth keeping.

These records outlive your account, without your name on them. We keep your identity against them for 180 days after you were last active. After that — and immediately if you delete your account, or if your workspace is deleted — the identifiers are replaced with a random surrogate and we do not keep any record of what it replaced. That is not encryption and it is not a code we could look up: the link is destroyed, so we cannot turn those rows back into you, and neither could anyone who obtained them. The exact times are rounded to the day at the same moment, so they cannot be lined up against other records to work out who you were.

We keep the rows themselves because they are how we know how many people used the product in a past month, and deleting them would change what we know about a period that has already ended. What survives is that somebody — one person, consistently, across those days — opened these pages. What does not survive is which person.

Who else receives it

Each of these is a company that processes some of your data so a feature can work. Most only apply if you use the feature they belong to.

VercelHosting and content delivery

Every request to the site: the URL, your IP address, and your browser's user agent. Vercel also derives an approximate country from the IP, which the public pages use to decide whether to show country-specific sections.

When: Always, including before you have an account.

NeonThe database

Everything a signed-in workspace saves: invoices and credit notes, contacts, expenses and their line items, products and stock movements, bank statement lines, recurring schedules, documents' metadata, assistant conversations, and your settings.

When: Whenever you are signed in. The guest editor never reaches it.

ClerkSign-in and workspace membership

Your email address, the sign-in method you choose, and session information. We store only the user and organisation identifiers Clerk gives back.

When: Whenever you are signed in.

AnthropicThe model behind document reading and the assistant

The contents of a document when you have it read — the pages themselves, as images or text — and, in the assistant, your messages together with whatever the tools it runs return from your workspace. Which means: if you ask about your invoices, figures from your invoices are in the request.

When: Only when you upload a document to be read, connect a mailbox, ask the assistant, or use autonomous reconciliation. This is the door those requests use by default, and it stays the fallback when a request sent to AWS Bedrock cannot be delivered.

Amazon Web Services (Bedrock)The same models, served by AWS rather than by Anthropic directly

The same content as the row above: the pages of a document you have read, your messages to the assistant, and whatever its tools return from your workspace — when a request is routed to AWS instead of to Anthropic.

When: On the same occasions, and only where the deployment routes model requests to AWS. A request that fails in transit there is retried once with Anthropic.

Amazon Web Services (S3)File storage

The files themselves: receipts, supplier bills and bank statements you upload, PDFs put out for signature, and the completed signed copies.

When: Whenever you upload a document or send one for signature. Absent entirely on a deployment that has not configured it.

Amazon Web Services (SES)Outgoing email

The recipient's address and the message: signature invitations to the people you ask to sign, payment reminders to your customers if you switch reminders on, e-invoicing deadline notices to you, and completion notices.

When: Only when something is actually sent. Absent entirely on a deployment that has not configured it.

StripePayments

Your billing details and what your workspace owes, when you take a paid plan; and the amount and reference of an invoice when you create a payment link for a customer. Card numbers are entered on Stripe's own pages and never reach us.

When: Only on a paid plan, or when you use a payment link. Absent entirely on a deployment that has not configured it.

Google (Gmail API)Reading bills out of a mailbox you connect

Nothing is sent to Google beyond the request itself. What comes back is the part that matters: message metadata and attachments from the mailbox you connect, which are then read exactly as an upload would be — including by the model.

When: Only after you connect a mailbox, and only until you disconnect it. Absent entirely on a deployment that has not configured it.

A Peppol access pointSending and receiving InvoiceNow documents

The invoice or credit note itself — parties, addresses, tax identifiers, lines and totals — because that is the document being delivered to your customer over the network.

When: Only when you transmit or receive an e-invoice. Absent entirely on a deployment that has not configured it.

Xero and QuickBooks OnlineAccounting export

The invoices and expenses you choose to export, with their contacts, tax codes and account codes.

When: Only after you connect one of them, and only for the records you export. Absent entirely on a deployment that has not configured it.

Google AnalyticsCounting page views

Page URLs and interaction data, approximate location, browser and device information, and a pseudonymous cookie identifier. We do not send invoice or document content, workspace data, or account identifiers.

When: Only if you accept analytics on the cookie banner. Declining leaves it unloaded.

Vercel Web Analytics and Speed InsightsAggregated traffic and performance measurement

The page or route visited, referrer, country, browser, device and operating system, plus page performance measurements such as loading speed and visual stability. Vercel says these measurements do not use cookies or retain an IP address or identifier tied to a person.

When: On visits to a deployed version of the site. These measurements do not include invoice, document, workspace or account content.

European Commission (VIES)Checking EU VAT numbers

One VAT number at a time — the number itself and the country that issued it, and nothing else. Not the invoice, not the amount, not your workspace's name. The Commission passes it to that country's own tax administration, which is what answers.

When: When a document you have read prints an EU VAT number, and when you ask for a number to be checked again. Never for a number outside the EU and Northern Ireland — those are not sent at all.

We also fetch data from the following, without sending anything about you: European Central BankPublished daily reference rates, fetched on a schedule. The request contains no information about you or your workspace.

Anthropic states that standard commercial API inputs and outputs are not used to train its generative models by default and are automatically deleted from its backend within 30 days, subject to its stated exceptions for law, safety-policy enforcement or a different agreement. That provider-side period is separate from the conversation or document record you choose to keep in invoiso.

The mailbox connection, specifically

If you connect a Google account, invoiso requests one scope: gmail.readonly. It can read messages and attachments; it cannot send, delete, or modify anything in your mailbox. It looks for supplier documents and files them as expenses, and the documents it finds are read the same way an upload is — which means their contents reach the model provider named above.

invoiso’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use that data only to provide the document-filing feature you connected it for, we do not transfer it except as needed to provide or secure that feature (which includes the model that reads the documents), and we do not use it for advertising. Human access is limited to cases you affirmatively request for support, security or abuse investigation, or a legal obligation.

The refresh token that keeps the connection alive is encrypted before it is stored. You can disconnect the mailbox in Settings at any time, which deletes the token, and you can revoke access independently from your Google account permissions.

Decisions made without a person

invoiso can act on your records unattended, and you decide how far. Each area below has 4 settings, from “prepare it and wait for me” to “act on everything it safely can”. The areas, and what acting means in each, are read from the module that enforces them:

  • Recognising expenses from documents Every document is read and filed either way. This decides which of them are clear enough to count without you checking first. Confirming an expense puts its figures into your reports and its quantities into stock.
  • Reconciling bank transactions Every transaction is matched to the document it most likely settles — money in against an invoice, money out against a supplier's bill. This decides which of those matches are recorded without you. A bill with no reference of its own can only be identified by its supplier and its amount, so those wait for a higher position. Recording a receipt settles the invoice and takes it out of the overdue list; recording a payment out reduces what is owed on the bill. At the top position, transactions judged to settle nothing at all are set aside.
  • Accepting a change to where a supplier is paid Every account a bill prints is read and compared with the supplier's card either way. This decides which of those changes go onto the card without you. A first account is never held — the fraud this guards against is a change, not an arrival — and an account that replaces every one on file waits for a higher position than one that arrives alongside them. Accepting a change moves where a payment file sends this supplier's money. Nothing is dismissed silently: the file names every supplier whose account changed since the last one.

Anything done this way is recorded with the reason it was done and can be undone. Automated processing is a convenience here rather than a judgement about a person: it decides what to file and what to match, not anything about you or your customers. You can turn every area back to its most cautious setting at any time, in Settings.

Where the data lives

The database, the file storage and the hosting are each pinned to one region, chosen when the deployment was set up. Several of the companies above operate globally and may process data outside that region — Clerk, Stripe, Google and the model provider in particular. Where cross-border transfer rules apply, we use the contractual and other safeguards offered by those providers. If the exact region or transfer mechanism matters to your business, contact us before you use the affected feature.

How long we keep it

Workspace records stay while the workspace is active unless you delete them or ask us to delete the workspace. We do not currently expire core business records merely because they are old: an invoice from three years ago remains available because businesses often need it for record-keeping. We retain personal data only while it is needed to provide the service, secure it, meet legal or accounting obligations, or resolve claims.

Deleting a workspace is deliberately not instant. The request cancels your subscription immediately and then waits30 daysbefore anything is destroyed, so an accidental deletion is recoverable by telling us inside that window. Nothing is removed during it.

Two things are worth knowing specifically. A document you delete removes its active record and stored file. Acompleted signed documentis deliberately harder to lose — its certificate exists to be evidence later — so voiding it keeps the signing trail. Service-provider logs, security records and backups may follow separate, limited deletion cycles, and a deletion request may not cover data we must keep by law or for a legal claim. We will explain any exception that applies.

What you can ask for

  • A copy of your data.Invoices download as PDFs and reports export as spreadsheets from inside the app. For everything held about you in one machine-readable file, email us — that one is handled by a person rather than a button.
  • Deletion.Deleting your organisation ends the service and starts a30-day grace period: your subscription is cancelled straight away, nothing is removed yet, and telling us within those 30 days restores everything untouched. After that the workspace is destroyed — its records, its stored files, and the access it granted to any connected accounting package or mailbox. A limited record that the deletion happened is kept, and we may keep more where a legal, security or claims-related reason requires it. If you would rather we did it for you, or you want it done sooner, email us.
  • Correctionof anything wrong — most of it you can edit directly.
  • Withdrawal of Google Analytics consent, from the “Cookie settings” link in the footer.

Depending on where you live and why the data is processed, you may also have rights to restrict or object to processing, receive portable data, withdraw consent, and complain to a data-protection authority. These rights have legal exceptions: for example, deletion is not available for data we must retain by law. Send requests to privacy@invoiso.com. We may need to verify your identity, and we aim to respond without undue delay and normally within 30 days. If applicable law permits or requires a different period, we will tell you.

Cookies, local storage and similar technologies

  • Essential— local storage for your in-progress invoice, your saved invoices and your settings on the guest tier, plus your currency and country preferences on the public pages. The app cannot work without them.
  • Authentication— Clerk’s session cookie, set when you sign in.
  • Analytics— Google Analytics’ cookies, loaded only after you accept. Vercel Web Analytics and Speed Insights measure aggregate traffic and performance without cookies.

Children

invoiso is a business tool and is not directed to children. Do not create an account or use the service on behalf of a business unless you have the legal capacity and authority to do so.

Contact

Questions, rights requests, deletion requests, or anything we have got wrong: privacy@invoiso.com.

Changes

If we change this policy, we will update the “Last updated” date at the top. For a material change, we will provide additional notice where reasonably possible, and ask for consent where the law requires it. See our Terms for the rest.