Effective 19 September 2026
Privacy Policy
This is the whole policy, written to be read. It describes what InvoiceCraft (invoicecraft.net) actually does with data, not what a template says a website might do.
- The free generator does not need an account. The invoice you build is sent to our server only to render the PDF and is not stored.
- We keep basic usage records about free PDFs (country, total, item count, which template) for 90 days, including the IP address, to stop abuse. Never the invoice contents.
- If you make an account, we store what you put in it: your business details, clients, invoices, expenses, and photos. Your data is never sold and is never used for advertising.
- Three outside services do work for us: Cloudflare (hosting), Resend (sending email), and OpenRouter/Anthropic (the AI features). Google serves our fonts.
- We count visits anonymously: a number per page per day, with no cookie and nothing that identifies you (details under Counting visits).
- No third-party analytics scripts and no trackers for normal visits. One cookie, only when you are signed in. The single exception: if you arrive by clicking one of our ads, that advertiser's conversion tag loads for that visit so we can tell whether the ad led to a download or a signup. We advertise on Google and on Facebook, and only the one you clicked is ever loaded (details below).
- You can delete every invoice from Settings, and you can ask us to delete your whole account.
The free generator (no account)
What stays in your browser
Your business name, address, phone, email, logo, accent color, and currency are saved in your browser's local storage so you do not have to retype them. Client details, line items, and dates are not saved anywhere between visits. Your theme choice (light or dark) is also stored locally. None of this is sent to us until you download or email an invoice.
What is sent to our server, and what we keep
When you download a PDF, the invoice is sent to our server, rendered, returned to you, and discarded. We do not store the invoice contents. We do keep one usage record per PDF for 90 days: the date, which template or tool it came from, the country, the currency, the total, the number of line items, whether it had a logo, whether the AI helper was used, a random per-tab identifier (so we can tell that an AI draft led to a download), and the IP address. The IP address is there to rate-limit and to investigate abuse. A separate aggregate counter (with no IP address) keeps overall totals by template and country.
If the PDF endpoint is unreachable, the PDF is generated inside your browser instead and nothing is sent at all.
The AI Invoice Helper
The job description you type is sent to OpenRouter, which forwards it to Anthropic's Claude model to draft line items. We send the description and the trade (for example "plumber"); we do not send your business name, client, or any other invoice fields with it. We log the request for 90 days (date, trade, length of the description, outcome, token counts, IP address), not the text itself. OpenRouter and Anthropic process the text to produce the response under their own terms; we do not use it to train anything.
Before the request is made, Cloudflare Turnstile runs a bot check in your browser. Turnstile is operated by Cloudflare under Cloudflare's privacy policy.
"Email it to me"
If you ask us to email you the PDF, we send it through Resend to the address you give and do not keep the PDF. We store the address, the date, and which template it came from. We send exactly one follow-up email the next day. Every such email has a one-click unsubscribe link; once you use it we keep the address only as a do-not-email record so it is never emailed again, even if it is entered a second time. Each address can be sent at most three PDFs a day, and this feature also runs a Turnstile bot check.
Saving an invoice to an account
If you choose "Save it to my account" after downloading, the invoice you made (everything in the form except your logo) is sent with your sign-up or sign-in request and kept with that link until you use it. When you open the link it becomes a draft in your account, and any business details your account does not have yet are filled from it. If you never open the link, the invoice is deleted with the sign-up request after at most 30 days.
The live demo
The demo at invoicecraft.net/demo creates a temporary account filled with made-up sample data. You do not give an email address to use it. Whatever you type into the demo is stored in that temporary account and is deleted, with the account, 24 hours after you started it, or sooner if you press Reset. The demo sets the same sign-in cookie as a real account, for that period. Nothing sent from a demo account is emailed to anyone, and its AI drafting is limited. If you sign a sample proposal or change order as the pretend customer, the approval record (typed name, time, IP address, browser) is deleted with the demo. If you choose Keep this account and confirm your email, the demo becomes an ordinary account and everything below applies from then on; records you signed before that point are then kept like any other approval.
Accounts (Pro and Team)
Signing in
There are no passwords. You sign in with a one-time link we email you through Resend. That link is valid for 15 minutes, or 24 hours when it creates a new account. If you ask for a sign-up link and do not use it, we keep your address and send one reminder with a fresh link about an hour later; the address is deleted when you sign up, or after 30 days if you never do. Signing in sets one cookie, ic_sess, which keeps you signed in for 30 days and is used for nothing else. Signing out removes it.
What we store
- Your email address and when the account was created. During a trial in which nothing has been created yet, we send up to two short tips (around day 2 and day 7), each with a one-click opt-out, and a notice the day before the trial ends.
- Your business profile: name, address, phone, email, logo, accent color, currency, invoice numbering, default tax rate, payment link, review link, and your settings (reminders, late fees, review requests, AI suggestions).
- Your clients, invoices, estimates, recurring schedules, and expenses, exactly as you enter them, plus their status history (sent, viewed, paid, approved) and timestamps.
- The payments you record against invoices (amount, date, how it was paid, and your note), and the ways to pay you that you save in Settings, which are printed on your invoices.
- When a customer taps "I've paid" on an online invoice: the time, how they say they paid, and their note. It is shown to you and marks nothing as paid until you confirm it.
- Change orders on accepted proposals and, like proposal acceptances, a permanent record of each approval: the typed name, the time, the IP address and browser, the agreed content and totals, and the consent wording.
- Job photos you attach to invoices, and your logo, in Cloudflare R2 storage.
- A count of each AI feature you use (tokens and timing, not the content), so we can see what the product costs to run.
On a Team plan, everyone you invite sees the same clients, invoices, and reports. Billing and team management stay with the account owner. When a teammate is removed, their sign-in stops working immediately and the documents they created stay with the account.
Bank statements and imports
To match bank deposits to invoices you upload a CSV export from your bank. We never connect to your bank and never ask for bank credentials. The file is read on our server for that request and is not stored. We keep only the statement lines you act on (the date, description, amount, and whether you matched it to an invoice, made it an expense, or ignored it), so the same line is not offered twice if you upload the statement again. Importing customers, a price list, or unpaid invoices works the same way: the file is read, you choose the rows, and only those rows are saved. Importing never emails anyone.
Email we send on your behalf
When you send an invoice or estimate, request a review, or have automatic reminders turned on, we email your client through Resend. Those emails go out from an InvoiceCraft address with your business email set as the reply-to, so replies come to you. They contain the document, the amounts, and a link to the online copy. Reminders are opt-in, at most one a week per invoice and four in total.
Email we send to you
A welcome email when you sign up, a notice about two days before a free trial ends, and a notice after it ends. These are about your account, not marketing lists, and we do not send newsletters.
AI features for accounts
Each AI feature sends only what it needs to OpenRouter (and on to Anthropic's Claude), and nothing is stored on the AI side by us:
- Receipt capture sends the photo you upload so the amount, date, vendor, and category can be read. The photo itself is not kept; only the expense you confirm is.
- Estimate drafting and the invoice helper send your job description.
- Follow-up drafts for overdue invoices send the invoice number, amount, due date, client name, and your business name.
- Price sanity-check, which is off unless you turn it on in Settings, sends a line item's description, quantity, and rate as you finish typing it.
- Bank statement categories: money-out lines that our own keyword rules cannot place are sent as the description and amount only (at most 60 lines per upload) so a bookkeeping category can be suggested. Money-in lines, your customers, and your invoices are not sent. Bank descriptions are whatever your bank printed, which can include a merchant name and the last digits of a card.
- Old invoice photo on the import page sends the photo you upload so its customer, dates, and line items can be read into a draft. The photo is not kept.
- Insights on the Reports page, which is off unless you turn it on in Settings, sends aggregated figures for your last 24 months: totals by month and quarter, counts, percentages, how quickly invoices get paid, proposal win rates, expense totals by category, the names of the items you bill, and the 5-digit ZIP codes taken from your customer addresses. Your customers are replaced by labels ("Client A", "Client B") before anything is sent, and the list of which label is which customer stays on our side and is only ever sent back to your own browser. No invoice, no document, no customer name, address, email, or phone number is included.
Client portal and statement links
Every sent invoice or estimate has an online copy at a link that contains a long random token. Anyone with the link can view that one document, the same way a shared document link works, so treat the link as you would the invoice itself. Opening it marks the document as viewed. If your client approves an estimate, we store the name they typed and the time. Client statements work the same way.
Payments
InvoiceCraft does not process payments and never sees card numbers. If you add a payment link (for example a Stripe Payment Link, PayPal.me, or Venmo), it is placed on your invoices as a button and QR code and your clients pay you directly through that provider under its terms.
If you subscribe to a paid plan, the subscription itself is handled by Stripe. Stripe collects and stores your card details; we store only a Stripe customer reference so we know which account is paid.
Counting visits
To see which pages people read and where they stop before signing up, the site counts a few moments: a page being viewed, a Start free trial or live demo click, the homepage email box, and the save-to-account box after a free download. Each count is one number for that page, that day, and whether the visit came from one of our ads or not. Nothing else is recorded: no cookie, no IP address, no browser or device details, no email, and nothing that links one count to another or to you. Automated browsers are not counted.
Cookies and local storage
One cookie, ic_sess, set only when you sign in. No social media pixels and no third-party analytics scripts. Local storage holds the business details and theme described above, on your device only.
If you arrive from one of our ads (the link carries a click ID from the platform you clicked on), we load that platform's conversion tag for that visit and for return visits from the same browser within 30 days. From Google that is the Google Ads tag (gtag.js); from Facebook or Instagram it is the Meta pixel. The tag sets that platform's advertising cookies and reports back to it when you download a PDF, request a sign-in link, create an account, or subscribe, so we can tell which ads work. The ad link also carries the ids of the campaign, the ad group or ad set, and the keyword or ad the click came from; if you then create an account, those ids are kept on it so we know which ads bring customers. They identify the ad, not you.
If you arrive from one of our postcards (the QR code or the web address printed on it, which open invoicecraft.net/mail), no advertising tag of any kind is loaded. Your browser remembers for 30 days that the visit came from a postcard, along with the mailing batch and trade printed in the QR code, and if you create an account those two labels are kept on it so we know which mailing worked. They identify the mailing, not you. We got your business address from the public Johnson County contractor licensing roster or from your public Google business listing; tell us and we will take you off the list.
Only the platform you actually clicked is ever loaded: a Google click never loads Meta's pixel and a Facebook click never loads Google's tag. Neither is loaded for visits that did not start with an ad click. Google describes its handling of this data in its advertising policy, and Meta describes its own in its privacy policy.
Who else handles your data
| Service | What it does for us | What it sees |
|---|---|---|
| Cloudflare | Hosts the site and the API, stores account data (D1 database, KV, R2), runs the Turnstile bot check, and keeps the aggregate usage counter | All traffic to the site and everything stored in an account |
| Resend | Delivers every email we send | Recipient addresses and the email contents, including PDF attachments in transit |
| OpenRouter and Anthropic | Run the AI features | Only the inputs listed above, per request |
| Google Fonts | Serves the typefaces | Your IP address and browser details when the font files load |
| Google Ads | Conversion measurement, only for visits that began with a click on one of our Google ads | Google's click ID and cookies, and which of our pages a download, signup, or subscription happened on. We keep the campaign, ad group, and keyword ids of the click on an account created from it |
| Meta (Facebook and Instagram) | Conversion measurement, only for visits that began with a click on one of our Facebook or Instagram ads | Meta's click ID and cookies, and which of our pages a download, signup, or subscription happened on. We keep the campaign, ad set, and ad ids of the click on an account created from it |
| Stripe | Subscription billing for paid plans | Your card and billing details, held by Stripe, not by us |
These providers process data to deliver the service, under their own privacy policies. We do not sell data to anyone, and we do not share it with advertisers or data brokers.
How long we keep things
- Free-generator usage records and AI helper logs: 90 days.
- Error logs (which may include an API path and a message, not invoice contents): 30 days.
- Captured email addresses: until you unsubscribe, after which only the do-not-email record remains.
- Unused sign-up requests, including an invoice being saved to the account: until you sign up, or 30 days.
- Anonymous visit counts: kept, since they identify no one.
- Account data: for as long as the account exists. If a trial ends without upgrading, the data becomes read-only and is kept so it is there if you come back.
- Backups: nightly copies of the database and stored files are kept for 30 days, so deleted data can persist in a backup for up to 30 days after deletion.
Deleting your data
Invoices and estimates: Settings has a "Delete all invoices" action that permanently removes every document and its photos. Individual documents can be deleted from the invoice list.
Your account: send a message through the support form from the email address on the account and we will delete the account, its clients, documents, expenses, files, and settings, and confirm by email. The team member or removed-teammate rules above apply to Team accounts.
Captured email address: use the unsubscribe link in the email, or ask through the support form.
You can also ask what we hold about you or ask us to correct it, through the same form.
Security
Everything is served over HTTPS. Sign-in links, portal links, and unsubscribe links are long random tokens that expire or can be revoked. Account data lives in Cloudflare's infrastructure, and the app is a small codebase we review ourselves. No system is perfectly secure; if you find a problem, please tell us through the support form and we will act on it.
Children
InvoiceCraft is a business tool and is not directed at children under 16. We do not knowingly collect their data.
Changes to this policy
If how we handle data changes, this page changes and the date at the top moves. Significant changes to what we collect will also be mentioned in the app.
Contact
Questions, requests, and deletions: the support form. A person reads every message.