Effective Date: April 2026 · Last Updated: April 28, 2026
InvoiceGenie ("we," "us," or "our") is operated by Ali Munir, based in Germany. We operate the InvoiceGenie platform, an AI-powered invoicing service. This Privacy Policy explains how we collect, use, store, and protect your information when you use our service.
This policy applies to users in all jurisdictions where InvoiceGenie operates, including Germany, the United Arab Emirates, and the United States.
Summary: We collect the information you provide to create and send invoices. We do not sell your data. We do not use your data for advertising. AI processing is used only for prompt-to-invoice parsing and your data is not used to train AI models.
When you register for InvoiceGenie, we collect:
Information you add to your workspace for invoice generation:
Payment processing is handled entirely by Stripe. We do not store credit card numbers, CVVs, or bank account details on our servers. We store only your Stripe customer ID and subscription status.
We collect aggregate platform usage data such as the number of invoices created, PDFs generated, and emails sent. This data is used for quota enforcement and service improvement and is not shared externally.
We collect IP addresses during account registration for security purposes. We do not use tracking cookies, analytics services, or third-party advertising pixels.
We use your information exclusively to:
We never:
We use the following third-party services to operate InvoiceGenie. Each is bound by their own privacy policy and data processing terms:
| Service | Purpose | Data Shared | Location |
|---|---|---|---|
| Supabase | Database hosting and authentication | All application data (encrypted at rest via AES-256 and in transit via TLS) | United States (AWS) |
| OpenAI (GPT-4o-mini) | AI invoice prompt parsing | Text prompt input only (processed in real-time, not used for model training per OpenAI's API data usage policy) | United States |
| Stripe | Payment processing | Email, payment method details (handled by Stripe) | United States |
| DigitalOcean Spaces | PDF invoice storage | Generated PDF files (encrypted at rest) | Germany (Frankfurt, FRA1) |
| DigitalOcean VPS | Workflow processing (n8n automation server) | Invoice data in transit during PDF generation and email sending | Germany (Frankfurt, FRA1) |
| Gotenberg | HTML-to-PDF conversion | Invoice HTML templates (processed locally on our DigitalOcean VPS, no external transmission) | Germany (Frankfurt, FRA1) |
| Resend | Transactional email delivery | Recipient email addresses, email subject and body content, PDF attachments | United States |
| Vercel | Frontend hosting and CDN | Static assets and server-side rendering | Global (edge network) |
We will notify customers at least 14 days before engaging any new sub-processor that handles personal data. If you have concerns about a new sub-processor, contact us at privacy@invoicegenie.ai.
Account information is retained for the duration of your subscription. If you request account deletion, your data is permanently deleted within 30 days. If you cancel your subscription without requesting deletion, your account data is retained for 90 days (to allow reactivation), after which it is permanently deleted.
Invoice records (metadata, line items, client information) are retained in the database while your account is active.
Generated PDF invoices are stored in DigitalOcean Spaces (Frankfurt). Retention periods depend on your plan:
| Plan | PDF Retention |
|---|---|
| Free | 90 days |
| Basic ($9.99/month) | 2 years |
| Pro ($29.99/month) | 5 years |
Text prompts sent to OpenAI for invoice parsing are processed in real-time and are not stored by InvoiceGenie after the structured data is extracted. OpenAI's API data usage policy states that API inputs and outputs are not used to train their models.
We implement the following security measures:
About our frontend code: The Supabase anonymous key visible in our frontend code is designed to be public — it only allows operations permitted by our Row-Level Security policies. All secret keys (API keys, service credentials) are stored securely on our backend servers and are never exposed in client-side code.
If you are located in the European Union or European Economic Area, the EU General Data Protection Regulation (Regulation 2016/679) applies to our processing of your personal data. In addition to the rights listed above, you have the right to:
Legal basis for processing: (a) Contractual necessity — providing the service you subscribed to (Article 6(1)(b)); (b) Legitimate interest — improving service quality and security (Article 6(1)(f)); (c) Consent — where applicable, such as for optional features (Article 6(1)(a)).
Data transfers: Where your data is transferred outside the EEA (to services hosted in the United States), we rely on Standard Contractual Clauses (SCCs) as adopted by the European Commission (Decision 2021/914) and, where applicable, the EU-US Data Privacy Framework.
In addition to EU GDPR rights, the German Federal Data Protection Act (Bundesdatenschutzgesetz, "BDSG") applies. The Federal Commissioner for Data Protection and Freedom of Information (BfDI) and the relevant state data protection authorities serve as supervisory authorities.
If you are located in the United Arab Emirates, the Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, "PDPL") applies.
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act provides you with specific rights:
InvoiceGenie's privacy controls — including data minimization, configurable retention, and the right to deletion — satisfy the requirements of current US state privacy laws.
In the event of a data breach that affects your personal data:
InvoiceGenie processes data across multiple locations. Here is exactly where your data flows:
| Processing Activity | Service | Location |
|---|---|---|
| Workflow processing (n8n server) | DigitalOcean VPS | Frankfurt, Germany (FRA1) |
| PDF generation (Gotenberg) | DigitalOcean VPS | Frankfurt, Germany (FRA1) |
| PDF storage | DigitalOcean Spaces | Frankfurt, Germany (FRA1) |
| Database storage | Supabase (AWS) | United States |
| AI prompt parsing | OpenAI API | United States (transient — not stored) |
| Payment processing | Stripe | United States |
| Email delivery | Resend | United States |
| Frontend hosting | Vercel | Global (edge network) |
For transfers from the EU/EEA to the United States, we rely on Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework. For UAE transfers, we rely on contractual safeguards and your explicit consent.
InvoiceGenie uses artificial intelligence (OpenAI's GPT-4o-mini) to parse natural language prompts into structured invoice data. This processing is a convenience feature only — it does not produce automated decisions with legal effects. You are responsible for reviewing all invoice details before sending.
OpenAI's API operates under their data usage policy: API inputs and outputs are not used to train their models. Your prompt text is processed in real-time and is not stored by InvoiceGenie after the structured data is extracted.
The AI feature is optional. You can create invoices entirely through manual form input without using AI parsing.
InvoiceGenie is a business service and is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors.
We may update this Privacy Policy from time to time. We will notify you of material changes via email at least 14 days before they take effect. Continued use of the service after changes take effect constitutes acceptance of the updated policy.
For privacy-related inquiries, data access requests, or concerns: