Legal

Privacy Policy

Last updated: 11 August 2026

Closed beta. Invoister is in active development. We may update this document as the product evolves; the "Last updated" date above always reflects the current version, and we will notify you of material changes.

This Policy explains what personal data Invoister collects, why, and your rights under the EU General Data Protection Regulation (GDPR). We aim to keep it short and clear.

1. Who is responsible

The data controller is Mykyta Ryzhov ("Invoister"). For any privacy question or to exercise your rights, contact [email protected].

2. What we collect and why

We collect only what we need to run the Service. The table below sets out each category, why we use it, and the legal basis under GDPR Article 6.

DataPurposeLegal basis
Account data (email, name)Create and secure your accountPerformance of a contract
Business profile, clients, invoicesProvide the core invoicing featuresPerformance of a contract
AI assistant content you send, including PDFs you uploadAnswer your requests and read documents you attachPerformance of a contract
Anthropic API key, if you choose to provide oneRun the AI assistant on your own account instead of oursPerformance of a contract
Anonymous page-view analytics (Vercel, cookieless)Understand roughly how the product is usedLegitimate interest
Essential cookiesKeep you signed in, remember settingsNecessary for the Service
Payment detailsBilling — handled by our Merchant of Record; we never store card dataPerformance of a contract
Support emailsRespond to your enquiriesLegitimate interest

3. How we use your data

We use your data to provide and secure the Service, to bill you (via our Merchant of Record), to improve the product (using anonymous, cookieless page-view analytics under our legitimate interest), and to comply with our legal obligations. We do not sell your personal data.

4. Who we share it with

We share data only with the processors that help us run the Service, each under a data-processing agreement. See the current list on our Subprocessors page.

5. International transfers

We host data in the EU where possible (our database runs in an EU region). Where a processor is outside the EU/EEA, the transfer is covered by appropriate safeguards such as the European Commission's Standard Contractual Clauses.

6. How long we keep it

We retain invoice and tax-related records for a minimum of 4 years, as required by Spanish tax law (Ley General Tributaria, Art. 66). Other account and personal data is deleted within 30 days of a deletion request, and removed from backups within 90 days. Page-view analytics are anonymous and aggregated, so they contain nothing that identifies you.

7. Your rights

Under GDPR (Articles 15–22) you have the right to access, rectify, erase, restrict, port and object to the processing of your personal data, and to withdraw consent at any time. You can export your data and request deletion directly from Settings → Privacy, or email [email protected].

You also have the right to lodge a complaint with your data-protection authority. In Spain this is the AEPD (aepd.es).

8. Cookies

We only use cookies that are strictly necessary to run the Service — no advertising, tracking or analytics cookies. See our Cookie Policy for the full list.

9. Security

Data is encrypted in transit and at rest, access is restricted, and our database enforces row-level security so each account can only access its own data. No system is perfectly secure, but we apply industry-standard measures.

10. Children

The Service is not directed at people under 18, and we do not knowingly collect their data.

11. Changes to this Policy

We may update this Policy. We will notify you of material changes by email or in-app.

12. Contact

Privacy questions: [email protected].