THE DETAILS · INVOICEQUO

Privacy notice

This notice describes how the current InvoiceQuo application uses information to provide invoice and quotation tools.

Information you provide

Account information includes your name, email address and a password stored as a hash. Company, customer and document information may include business names, contact details, addresses, tax identifiers, logos, descriptions, prices, taxes, dates, notes and terms. Only enter information you are authorized to use, and avoid unnecessary sensitive information.

How information is used

InvoiceQuo uses this information to authenticate accounts, manage customers, create and display documents, generate PDFs, apply plan limits, and protect the service. Creation and AI usage events support monthly allowances. Operational error logs and temporary rate-limit records support reliability and abuse prevention.

AI Quick Create

When you choose AI Quick Create, your prompt and extraction instructions are sent to OpenAI to generate structured draft data. Your prompt may contain customer or project information, so include only what is needed. The app does not send your full customer list or account credentials. OpenAI processes requests under its applicable service terms and data policies; this notice does not promise zero provider retention. The resulting draft requires your review before saving.

Hosting and storage providers

Application hosting and PostgreSQL store and process account and document information. Cloudflare R2 stores company logos. Uploaded logo URLs are publicly accessible to anyone with the URL and are not suitable for confidential images. AI requests use OpenAI. The operator must publish the selected hosting/database providers, processing regions and any applicable transfer arrangements before commercial launch.

Cookies and browser storage

InvoiceQuo uses an essential session cookie to keep you signed in. It is inaccessible to JavaScript and expires after seven days unless cleared earlier. Logging out clears the cookie. AI drafts use account-scoped session storage in your browser tab, with a one-hour application expiry; closing the tab clears this temporary storage. The current marketing site does not add advertising trackers or analytics cookies.

Security and access

The application uses hashed passwords, signed sessions, authenticated account-scoped access, input validation and request limits. These controls reduce risk but cannot guarantee absolute security. Keep your account credentials private. PDFs you download and share are outside the application's access controls.

Retention and historical documents

Saved documents contain snapshots of seller and customer details. Updating a company or customer does not automatically erase historical snapshots. Logos referenced by historical documents may be retained. Deleting a document does not remove its plan-usage event. The operator must publish an operational retention schedule covering accounts, backups, logs and provider-held data; no specific deletion deadline is promised by this MVP notice.

Your choices and requests

You can edit company/customer details and manage documents through the available account tools. Depending on applicable law, you may have rights concerning access, correction, deletion, restriction, objection or portability, and the ability to complain to an appropriate supervisory authority. Requests require a working contact route, which is marked as pending below. A self-service account deletion or bulk data export feature is not currently offered.

Updates to this notice

This notice should be updated when processing practices or providers change. The operator must complete the missing identity, contact, retention and jurisdiction-specific information and review the applicable legal requirements before launch.

Contact

Legal operator: [To be provided]
Privacy and support email: [To be provided]
Business address and jurisdiction: [To be provided]