Privacy Policy
Last updated 8 October 2026
This policy explains what personal data Invoita collects, why, who we share it with, and the rights you have. It covers https://invoita.com and the Invoita application.
1. Two different roles
We are the controller of data about you as an Invoita user — your name, email, password hash and account settings.
For the data you put into Invoita about your own clients, you are the controller and we are your processor. We only handle that data to run the service for you, and we do not sell it, mine it, or use it to build any profile.
2. What we collect
- Account data — name, email address and a hashed password. If you sign in with Google we receive your name, email and profile picture from Google.
- Business data — your business name, address, tax number, logo and invoice settings.
- Client and document data — the clients, invoices, quotes, contracts, expenses and time entries you create, including any personal data about your clients that you enter.
- Connected mailbox — if you connect an email account to send your invoices from, its address and the credential that lets Invoita send through it. Section 5 explains exactly what that covers.
- Technical data — IP address, browser type and timestamps in server logs, plus error reports, used for security, debugging and abuse prevention.
- View data — whether a shared invoice, quote or contract link has been opened, so you can see if a client has seen it. For invoice links we also log the time, IP address and browser type of each visit.
The free invoice generator.Your invoice is built and turned into a PDF in your browser. We never receive what you type — only an anonymous count that a PDF was made (currency, language, page size, number of lines, whether a logo or signature was used). If you save it to a free account, it is uploaded then. The count also records whether the document was an invoice, receipt, estimate or bill, which Invoita page you arrived from, and a code that changes every day, made by hashing your IP address and browser; the IP address itself is not stored with it. Your unsaved draft stays in your browser's local storage on that device. Invoices you save in an account are stored as described above.
We do not process payments, so your clients never enter card details on Invoita. We do not run advertising trackers, and we do not sell personal data to anyone.
3. Why we use it, and our legal basis
- To provide the service — creating and storing your documents, generating PDFs, serving the share links you create, sending the emails you ask us to send from your connected mailbox, and keeping your account working. Basis: performance of a contract.
- To keep the service safe — rate limiting, sending limits, fraud and abuse prevention, error monitoring and backups. Basis: our legitimate interest in a secure service, and in protecting the people who receive email sent through Invoita.
- To contact you — service notices such as verification, password reset and important changes. Basis: performance of a contract. Marketing email, if we ever send any, would be on consent you can withdraw.
- To meet legal duties — keeping the records the law requires and answering lawful requests. Basis: legal obligation.
4. Who we share it with
We share data only with providers that help us run Invoita, and only as far as each needs. Several are optional and receive nothing unless you use them.
| Provider | Purpose |
|---|---|
| Optional sign-in with your Google account, and optional sending from your own Gmail (Gmail API) | |
| Microsoft | Optional sending from your own Outlook or Microsoft 365 mailbox (Microsoft Graph) |
| OpenAI | Optional AI drafting of invoices and reading of expense receipts |
| Xero and QuickBooks | Optional accounting synchronisation |
| Sentry | Application error monitoring |
| Cloudflare | DNS, CDN, denial-of-service protection, and delivery of account emails |
| OVHcloud | Server hosting and database storage |
We may also disclose data where the law requires it, or to establish or defend legal claims. If Invoita is ever sold or merged, data may transfer to the acquirer under this policy.
5. Sending from your own mailbox
You can connect one email account to each business — Gmail, Outlook or Microsoft 365, or any other provider by SMTP — so that Invoita can send your invoices, quotes and payment reminders from your own address. Connecting is optional. Invoita never emails your clients from its own address.
- What we store — the address you connected and the credential that lets us send through it: for Gmail and Outlook an OAuth refresh token; for SMTP the server name, port, username, the sender name you chose, and your password or app password. Tokens and passwords are encrypted at rest and never sent to your browser, your team or anyone else.
- What we use it for — only to send the emails you ask us to send, at the moment you click Send: the message you see in the send window, to the recipients you entered, with the PDF attached. Invoita never sends anything from your mailbox on its own.
- What we never do — read, search, list, change or delete your email. For Gmail we ask only for permission to send email (the gmail.send scope), which cannot read your mailbox. For Outlook we ask only to send email as you (Mail.Send) and to read your own address from your profile (User.Read).
- What we keep about each email — the recipient addresses, the time, which kind of mailbox sent it and whether it went, so we can enforce sending limits and investigate abuse. We do not keep a copy of the message; your email provider may keep one in your Sent folder.
- Disconnecting — Disconnect in Settings › Email deletes the stored address and credential straight away, and for Gmail also revokes Invoita's access at Google. Connecting a different mailbox, or deleting the business or your account, deletes it too. You can also remove Invoita's access at any time in your Google or Microsoft account settings.
Google user data. Invoita's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. The only Google user data we receive for sending is your Gmail address and the permission to send as you. We use it only to send the emails you ask us to send, a feature you see and control in Invoita. We do not transfer it to anyone except as needed to provide that feature, to comply with the law, or as part of a merger or acquisition; we do not use it for advertising and never sell it; we do not use it to develop, improve or train AI or machine-learning models; and no person at Invoita reads it unless you ask us to for a specific message, it is needed for security such as investigating abuse, or the law requires it.
Microsoft user data. The same rules apply to what we receive from Microsoft. Through Microsoft Graph we receive only your mailbox address and the permission to send as you, and we use them only to send the emails you ask us to send, in line with the Microsoft APIs Terms of Use. We never read your mail, never use the data for advertising or to train AI models, never sell it, and share it with no one except as needed to provide that feature or to comply with the law.
Other providers (SMTP).If you connect by SMTP, your emails go through your own provider's mail server, under your agreement with that provider. Use an app password where your provider offers one, so you can revoke it there without changing your main password.
6. AI features
If you use AI drafting or receipt reading, what you supply — the text you type, or the receipt image you upload — is sent to OpenAI to produce a draft or read the receipt, and the result is returned to you. We do not permit that content to be used to train third-party models. AI output can be wrong — always check it before you rely on it or send a document to a client.
7. International transfers
Some providers listed above operate outside the EEA. Where data leaves the EEA we rely on an adequacy decision or on Standard Contractual Clauses with appropriate safeguards.
8. How long we keep it
- Account and document data: for as long as your account is open.
- Connected mailbox: until you disconnect it, connect a different one, or delete the business or your account.
- Send log (the recipients and time of each email sent through Invoita): for as long as it is needed to enforce sending limits and investigate abuse reports, including after the account that sent it has been closed.
- After deletion: removed or irreversibly anonymised within a reasonable period, except where we must retain records by law.
- Server logs: retained for a short rolling window for security and debugging.
9. Security
Passwords are hashed with bcrypt and never stored in readable form. Stored third-party credentials, including mailbox tokens and passwords, are encrypted at rest. Traffic is served over TLS, and optional two-factor authentication is available on your account. No system is perfectly secure, but we work to protect your data and will tell you and the relevant regulator about a qualifying breach without undue delay.
10. Your rights
Depending on where you live you may have the right to access, correct, delete, restrict or object to our use of your personal data, to receive it in a portable format, and to withdraw consent. You can exercise most of these directly in your account settings, or by emailing [email protected]. You also have the right to complain to your data-protection authority — in Spain that is the Agencia Española de Protección de Datos (AEPD).
If your data is in Invoita because one of our customers invoiced you or emailed you through Invoita, please contact that business first — they control that record. If you received an email sent through Invoita that you think is spam or phishing, tell us at [email protected] and we will investigate.
11. Children
Invoita is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
12. Cookies
We use a small number of strictly necessary cookies. See our Cookie Policy.
13. Changes
We will post any update here and change the date at the top. If a change is material we will notify you by email or in the product.
Questions about this policy? Email [email protected].