Security & data handling
What happens to a file when you upload it, where your data is stored and which companies process it — in plain language, and specific enough to check.
What happens to your file
The validator, the viewer, the converters and the invoice generator hold your document in memory for the length of the request and then drop it. Nothing writes it to disk or to a database. Two features are exceptions, and both are named below.
Validate, view, convert, generate
- Processed in memory: your XML or PDF is parsed, checked or converted and then discarded when the response is sent
- Never written down: no table in our database holds invoice content, and we operate no file storage
- No account needed: these tools work without signing in, so there is nothing to attach a document to
- Runs on our own servers: the document is not sent to any third party — we build and check the file, and sending it stays in your hands
Exception 1 — AI document scanning
- Your file leaves our servers: this is the one feature where it does. The document is sent to Microsoft Azure Document Intelligence, which extracts the invoice fields
- Only when you ask for it: scanning runs on an explicit upload-and-extract action, never in the background
- We keep the fields, not the file: the extracted values populate the form in your browser; we store neither the document nor the extraction
- No model training: we do not train any model on your documents
Exception 2 — mobile upload by QR code
- Briefly buffered: photographing an invoice with your phone stores the image in our database so your desktop can pick it up
- 15 minutes, maximum: the handover token expires after 15 minutes and a scheduled job deletes expired rows
- Cleared on first pickup: the buffered image is erased as soon as your desktop session retrieves it, which is usually within seconds
- Single use: a token can be claimed once; a lost handover means scanning a fresh QR code
What we do record
- One usage event per request: which feature you used, whether it succeeded, and when — so we can enforce free-tier limits and fix what breaks
- Hashed identity when signed out: anonymous usage is counted against a SHA-256 hash of your IP address, not the address itself
- Error text, not document text: a failure records the error message; it does not record your invoice
- What you deliberately save: templates, customers, suppliers and products are stored against your account until you delete them — or delete the account, which removes them with it
- Your records stay yours: since we hold no copy of the document, keep your own archive for the retention period your tax authority requires
Where your data is
Everything runs inside the EU. Traffic is encrypted in transit with TLS; data at rest is encrypted by the managed platforms below.
Application servers
Fly.io, Frankfurt region. All validation, conversion and PDF rendering happens here.
Database
Supabase (PostgreSQL) in the AWS Ireland region. Holds accounts and what you chose to save — not your documents.
Web apps
Vercel serves this site and the dashboard over HTTPS from its European edge.
In transit
HTTPS everywhere, with HTTP Strict Transport Security set by our hosting platforms.
Who else processes your data
The complete list. You should be able to see the whole chain rather than discover part of it later.
Running the service
- Supabase: database and sign-in (EU region)
- Fly.io: hosts the API (Frankfurt)
- Vercel: hosts this site and the dashboard
- Zoho: sends account and notification email
Specific features only
- Microsoft Azure Document Intelligence: extracts fields during AI document scanning. The only processor that ever receives your document
- Stripe: handles subscription payments. Card details go to Stripe directly and never reach our servers
- Sentry: collects crash reports, with personally identifying data collection switched off and text masked in session recordings
- Company registries and VIES: queried only when you look up a business partner, using the identifier you typed
Accounts and application security
Signing in
- Access token in memory only: it is never placed in local or session storage, so a script injected into the page has nothing to read from disk
- Refresh token in an httpOnly cookie: JavaScript cannot read it, it is scoped to the authentication endpoints, and only our server can exchange it
- Idle timeout: an inactive session is signed out automatically
- Email or social sign-in: authentication is handled by Supabase Auth. If you sign in with Google, X or Facebook, that password is never sent to us
Application hardening
- Rate limiting: per-user and service-wide request limits across the API, so a single client cannot exhaust it
- Browser security headers: framing denied, MIME sniffing blocked, referrers restricted, and camera, microphone and location access refused outright
- Schema changes are versioned: every database migration is reviewed and applied in order, never by hand against production
- Input is validated against official schemas: uploads are parsed with hardened XML settings and checked against the official XSD and Schematron rules for the format
Your data, your rights
What you can do
- Delete your account: available in your profile. It removes the account together with your saved templates, partners and products
- Use the tools signed out: validating, viewing and converting need no account, so most of the service can be used with no personal data at all
- Withdraw cookie consent: reopen the consent banner at any time from the link in the footer
- Ask us anything about your data: access, correction, export and erasure requests all go through the contact form
Our obligations
- GDPR applies to us: we process personal data as a controller for your account, and as a processor for the data you put into an invoice
- Breach notification: a personal data breach is reportable to the supervisory authority within 72 hours, and we will tell you if you are affected
- Data processing agreement: available on request if your organisation needs one on file
- Full detail in the policy: the privacy policy covers lawful bases, retention and supervisory authorities
Found a problem, or need something in writing?
Vulnerability reports, data processing agreements and questions about anything on this page all reach us the same way. We would much rather hear about a weakness from you than not.
Get in touch