Privacy Policy
This policy explains what data the Invoice Box mobile app (iOS and Android, “the app”) handles, why, who else is involved, and the choices you have. We have tried to write it in plain language and to describe what the app actually does.
1. Who we are
The app is published by KLOE LLC, a limited liability company in the United States (“KLOE”, “we”, “us”).
KLOE LLC (a Wyoming limited liability company)
30 N Gould St Ste R, Sheridan, WY 82801, United States
Email: [email protected]
2. The short version
- There is no sign-up. The app creates an anonymous account for your device the first time it opens.
- What you type in the app (your business profile, customers, items, invoices, quotes and payments) is stored on our servers so it is backed up and synced, and kept on your device so the app works offline.
- For the business data you enter about your customers, you decide what goes in and we process it only on your behalf.
- We use privacy-friendly usage analytics (PostHog, hosted in the EU) tied to a random ID. Analytics events never contain names, emails, amounts or customer data.
- Subscriptions are paid through Apple or Google. We never see your card details.
- No ads. We do not sell your data, and we do not track you across other apps or websites.
3. Data we process
3.1 Your anonymous account
On first launch the app creates a random secret and keeps it in your device’s secure storage (iOS Keychain or Android Keystore). Our server stores only a one-way hash of that secret, which lets your device sign back in. We also create:
- a random user ID and a random company (workspace) ID;
- a session record for your device: a hash of the session token (never the token itself), creation, last-use and expiry times, and the app’s technical “user agent” string (app and operating-system version information).
We do not ask for your name, email or phone number to create an account.
3.2 Content you enter
Everything below is optional except where the app needs it to make a document (for example, a customer name on an invoice):
- Business profile: business name, email, phone, address, tax ID, logo image, currency, tax name, document numbering, default notes and terms, and your invoice design (template and colors).
- Customers: name, contact person, email, phone, address, tax ID and notes.
- Items (articles): names, descriptions, prices and tax rates.
- Invoices and quotes: numbers, dates, lines, totals, discounts, notes, terms, status, and a copy (“snapshot”) of the customer and business details at the time the document was made, so old documents never change.
- Payments: amount, date, method (for example cash or bank transfer), reference and note. These are records you type; the app does not process payments.
Your logo is stored in a private Cloudflare R2 storage bucket. It is only reachable through short-lived signed links that our server creates for your account. When you choose a logo, the app reads only the single image you pick from your photo library, resizes it on the device and uploads it.
3.3 Server logs
Like most online services, our servers record technical request logs: IP address, date and time, the requested address, response status and user agent. We use them to keep the service secure (for example rate limiting and abuse prevention) and to fix problems.
3.4 Usage analytics
We use PostHog (PostHog EU cloud, hosted in the European Union) to understand how the app is used, mainly the first-launch steps and the subscription screen. Events are tied only to our random user ID. They include things like “app opened”, which onboarding step was viewed, completed, skipped or left, whether the subscription screen was shown, which plan was selected, and whether a purchase or restore succeeded, failed (with a technical error code) or was cancelled. PostHog also records standard technical information sent by its app library, such as operating system, app version, device type, and an approximate location derived from the IP address.
Our rule is that analytics events never contain names, emails, phone numbers, addresses, business or customer data, amounts, document numbers or anything you type. We also use PostHog feature flags to decide which version of the subscription screen to show (for example, with or without a free trial).
3.5 Purchases and subscriptions
Subscriptions are sold and charged by the Apple App Store or Google Play under your Apple or Google account; their own privacy policies apply to that. We use RevenueCat to check whether your subscription is active. RevenueCat receives your anonymous company ID, purchase and subscription information from the store (product, dates, status, transaction identifiers, store country and price) and basic device and app information. Neither we nor RevenueCat receive your card number or billing address.
3.6 Data that stays on your device
- A cached copy of your data and any changes made while offline (kept up to 30 days so they can sync later).
- Small preferences: app language, the last currency and tax rate you used, and your last known subscription status.
- PDF files generated for sharing or printing. PDFs are created on your device; we do not generate or store them on our servers.
When you email, share or print a document, the app hands the PDF to your phone’s mail app, share sheet or print dialog. We do not send emails for you and we do not see what you send or to whom.
3.7 What we do not collect
We do not access your contacts, precise location, camera, microphone or advertising identifier, and we do not collect payment card details.
4. Your customers’ data: you are in charge
When you enter information about your customers (names, emails, addresses, tax IDs and so on), you are the “controller” of that data: you decide why and how it is used. KLOE acts as your “processor” (service provider): we store and process it only to provide the app to you, following your instructions as expressed through the app, and never for our own purposes such as marketing, analytics or selling. You are responsible for having a valid reason to store your customers’ data and for informing them where the law requires it. Our commitments as a processor are set out in our Terms of Use.
5. Why we use data, and our legal bases
If you are in the European Economic Area, the United Kingdom or another place with similar laws, we rely on these legal bases:
| Purpose | Legal basis |
|---|---|
| Creating your anonymous account, storing and syncing your data, generating documents, providing the subscription you bought | Performance of our contract with you (the Terms of Use) |
| Security, abuse prevention, server logs and fixing errors | Our legitimate interest in keeping the service safe and working |
| Anonymous usage analytics and testing versions of the subscription screen | Our legitimate interest in understanding and improving the app, balanced by the measures above (random ID, no personal content). You can object at any time (see section 9) |
| Keeping records of purchases, and answering legal requests | Compliance with legal obligations |
| Your customers’ data | We process it on your behalf; you choose the legal basis as controller |
We do not use your data for automated decisions that have legal or similarly significant effects on you.
6. Who we share data with
We share data only with the service providers we need to run the app, and only for that purpose:
| Provider | What for | Where |
|---|---|---|
| Our servers (operated by KLOE) | The app’s database (MongoDB) and backend: account, content and logs | Operated by us |
| Cloudflare, Inc. | Private storage of logo images (R2) and network delivery and protection (CDN) | Global network; United States company |
| PostHog, Inc. | Usage analytics and feature flags | European Union (PostHog EU cloud) |
| RevenueCat, Inc. | Subscription status | United States |
| Apple Inc. / Google LLC | App distribution, payment for subscriptions, and the device platform | United States and worldwide |
We may also disclose data if required by law or a valid legal request, to protect our rights or users’ safety, or to a successor if KLOE’s business is sold or merged (this policy would continue to protect your data). We do not sell personal data, we do not share it for cross-context behavioral advertising, and we show no ads.
7. International transfers
KLOE is a United States company, and some of our providers are in the United States. If you use the app from outside the United States, your data may be transferred to and processed in the United States and other countries whose laws may differ from yours. Analytics data is hosted by PostHog in the EU. Where the law requires it, we rely on appropriate safeguards for these transfers, such as the European Commission’s Standard Contractual Clauses or the provider’s certification under the EU-U.S. Data Privacy Framework, where available.
8. How long we keep data
- Your content is kept for as long as your account exists, so it stays backed up and available.
- Deleting inside the app: when you delete a customer, item, invoice, quote or payment, it disappears from the app, but our database keeps the record marked as deleted. We do this on purpose: invoices are business records that many countries require to be kept for several years, and it protects you from accidental loss. Logo images are likewise kept, so that old documents keep their logo.
- Full erasure: you can ask us to permanently erase your account and all its content at any time by email (see section 9). We will do so within 30 days, except for information we must keep by law (for example, purchase records), which we keep only as long as required. Keep in mind that you may have your own legal duty to keep copies of your invoices, so export or share them first.
- Sessions stop working after 180 days without use; the expired records are kept with your account and erased with it.
- Server logs are kept for a limited period for security and troubleshooting, then deleted.
- Analytics data is kept as long as it is useful for improving the app, and is deleted on request together with your account.
- On your device, data stays until you uninstall the app. Uninstalling removes the app’s local data; the secure-storage secret may survive a reinstall on some iPhones.
9. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you and get a copy;
- rectify inaccurate data (most of it you can edit directly in the app);
- erase your data;
- receive your data in a portable format (we will send it in a common machine-readable format such as JSON);
- object to processing based on legitimate interests, including analytics, or ask us to restrict processing;
- withdraw any consent you gave, without affecting earlier processing;
- complain to your data protection authority (in the EU/EEA, the authority of your country; in the UK, the ICO; in Brazil, the ANPD).
To exercise any right, email [email protected]. Because accounts are anonymous, please write from the email address saved in your business profile if you have one, and include your business name as it appears in the app; we may ask for more details (for example, a screenshot of the app) to confirm the account is yours before acting. We answer within 30 days (45 days where California law applies). We will not treat you differently for exercising your rights.
If you are a customer of one of our users (your data was entered by a business that invoices you), please contact that business first: it controls your data. We will help it respond.
California and other U.S. states
Under the California Consumer Privacy Act as amended by the CPRA, and similar state laws, you have the right to know what personal information we collect, use and disclose; to delete it; to correct it; and to opt out of its “sale” or “sharing”. We do not sell or share personal information (as those words are defined in those laws), and we do not use or disclose sensitive personal information for purposes that would require offering a right to limit. In the last 12 months we collected the categories described in section 3: identifiers (random IDs, IP address), commercial information (subscription status), internet or network activity (app usage events, server logs), approximate location derived from IP address, and the business content you enter. We collected it from you and your device, and disclosed it only to the service providers listed in section 6 for business purposes. You may use an authorized agent to make a request; we may ask the agent for proof of authorization.
Brazil, Mexico and other Latin American countries
If you are in Brazil (LGPD), Mexico (Ley Federal de Protección de Datos Personales en Posesión de los Particulares), Argentina, Colombia, Chile, Peru or another country with a data protection law, you have the rights your law grants, including access, rectification, cancellation or deletion, opposition (ARCO rights) and portability where applicable. Write to the address above to exercise them.
10. Security
We use reasonable technical and organizational measures to protect data: connections between the app and our servers are encrypted (HTTPS); your device secret and session tokens are stored on our side only as one-way hashes; each account can only reach its own data; logo images are in private storage reachable only through short-lived signed links; and your device keeps its credentials in the operating system’s secure storage. No system is perfectly secure; if a breach affects your personal data, we will notify you and the authorities where the law requires.
11. Children
Invoice Box is a business tool. It is not directed to children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has given us data, contact us and we will delete it.
12. Changes to this policy
We may update this policy when the app or the law changes. We will change the effective date above and, for important changes, tell you in the app or on this page before they take effect.
13. Contact
KLOE LLC (a Wyoming limited liability company)
30 N Gould St Ste R, Sheridan, WY 82801, United States
Email: [email protected]