This Privacy Policy explains what information Agent Invoice collects, how we use it, and the choices you have. It applies to agent-invoice.com and app.agent-invoice.com.
1. Information We Collect
Account information
Name, email address, password (stored as a salted hash, never in plain text), and business details you provide (business name, address, logo, contact info).
Client data you enter
Names, emails, addresses, and phone numbers of your clients, and the invoices, estimates, line items, and notes you create for them.
Payment metadata
Invoice amounts, statuses, and payment confirmations. We do not receive or store full payment card numbers - those are handled directly by Stripe and/or PayPal.
Usage & log data
IP address, browser type, pages visited, and timestamps, collected automatically to operate and secure the Service.
Communications
Messages you send us through the contact form, support email, or newsletter sign-up.
2. How We Use Information
- To provide, maintain, and improve the Service (generating invoices, sending emails, calculating totals, processing payments);
- To communicate with you about your account, billing, and - if you opt in - product updates;
- To detect, prevent, and address fraud, abuse, and security issues;
- To comply with legal obligations.
We do not sell your personal information or your clients' information.
3. If You're a Client Whose Data Was Entered by a Business
If one of our users has entered your contact information to send you an invoice or estimate, that business is the data controller for the information they've entered - we process it on their behalf. To access, correct, or delete that information, please contact the business that invoiced you directly. If that isn't possible, contact us and we'll do our best to help.
4. Data Storage & Security
Data is stored with Supabase (PostgreSQL) and served via Vercel. Connections to the Service use TLS (HTTPS) encryption in transit, and stored data is encrypted at rest. We restrict internal access to production data to what's necessary to operate and support the Service. See our PCI Compliance & Security page for more detail on payment-specific safeguards.
5. Third-Party Service Providers
We share information with the following categories of service providers, only as needed to operate the Service:
- Stripe & PayPal - payment processing, at your direction, when you connect a gateway;
- Supabase - database hosting and authentication;
- Vercel - application hosting;
- Email delivery providers - sending invoice, reminder, and transactional emails;
- USPS / mail delivery partners - only if you use the physical-mail feature, and only for the recipient address on that mailing.
These providers are authorized to use your information only as necessary to provide services to us.
6. Connected Mailboxes (Google & Microsoft)
You may optionally connect your Gmail or Outlook account so that invoices and reminders are sent from your own address rather than ours. Connecting a mailbox is entirely optional, and the Service works without it.
When you connect a mailbox, we request the narrowest permission that makes the feature work - send-only access (gmail.send for Google, Mail.Send for Microsoft). This permission does not allow reading, searching, modifying, or deleting your email, and we do not request any scope that would.
- What we do with it: send the specific invoice, estimate, and reminder messages that you or your configured automations trigger. Nothing else.
- What we store: the OAuth access and refresh tokens needed to keep sending, plus the email address of the connected mailbox. We do not store the contents of your mailbox, because we cannot read it.
- How we protect it: tokens are held in our database, which is encrypted at rest, and travel only over TLS. They are readable only by your own account and by the Agent Invoice backend that sends on your behalf, never by another customer. They are used solely to send the messages you trigger, and are deleted when you disconnect the mailbox.
- What we never do: we do not use mailbox access for advertising, we do not sell or transfer this data, we do not use it to train machine-learning or AI models, and no human at Agent Invoice reads it.
- Disconnecting: you can disconnect at any time from Settings, which deletes the stored tokens. You can also revoke access directly from your Google Account permissions or Microsoft account security settings.
- AI features and your mailbox: Agent Invoice has optional AI features that draft invoice line items and suggest brand colours. They are powered by a third-party provider, OpenRouter. Google Workspace data is never sent to them, and cannot be: the only Google permission we hold is send-only, so there is no mailbox content for us to pass on. The AI features receive the text you type into them and the names of your own clients, nothing more. Every request we make carries a flag instructing the provider not to route it to any service that retains prompts for model training.
Agent Invoice's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
7. Cookies
We use essential cookies to keep you signed in and remember basic preferences. We do not use third-party advertising trackers. Invoice emails may include a small tracking pixel so you can see when a client has opened an emailed invoice - this is a feature of your account, not third-party ad tracking.
8. Data Retention
We retain account and invoicing data for as long as your account is active, and for a reasonable period afterward to comply with legal, tax, and accounting obligations. You can request deletion of your account and associated data at any time by contacting us; some information may be retained where required by law (for example, financial records).
9. Your Rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, or to object to certain processing. To exercise these rights, email support@agent-invoice.com. We'll respond within a reasonable timeframe.
10. Children's Privacy
The Service is intended for business use by adults and is not directed at children under 16. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced by email or in-app notice before they take effect.
12. Contact
Questions about this policy or your data? Email support@agent-invoice.com.