Invoice Atelier

Public legal and trust materials for the AI-assisted invoicing platform.

Privacy
Last updated [EFFECTIVE DATE]

Privacy Policy

How the platform collects, uses, stores, safeguards, and discloses account, client, invoice, communication, analytics, and integration data.

These pages are written to be plain-English and liability-conscious. Final review by a licensed lawyer is recommended before production launch.

1. Information we collect

We collect account information, client and contact records, invoice data, uploaded files and notes, communication logs, device and usage analytics, support messages, and integration metadata needed to operate the service.

  • account profile and authentication information
  • client and recipient names, emails, phone numbers, and addresses
  • invoice details, line items, notes, payment terms, and status history
  • uploaded receipts, files, prompts, summaries, and draft content
  • communication logs, audit logs, support requests, and usage analytics

2. Why we use data and legal bases

We use information to provide the service, secure accounts, maintain records, support AI-assisted drafting, process user-authorized sends, monitor product health, investigate abuse, improve reliability, and meet legal obligations.

Depending on context and jurisdiction, we rely on consent, contractual necessity, legitimate interests, and legal obligation as legal bases for processing. Where consent is required, you may withdraw it subject to lawful and operational limits.

3. Google and Gmail integration disclosures

If you connect Google or Gmail, we may access Google user data necessary to support the requested feature, such as sender identity, authorized send capability, and limited connection metadata. We use this data only to provide the integration, support user-authorized sends, secure the integration, troubleshoot issues, document audit trails, and comply with law.

We do not sell Google user data. We do not use Google user data for advertising. Users can revoke access through Google account settings or by disconnecting the integration, and they may request deletion of retained connection data subject to lawful retention requirements.

4. Sharing, transfers, retention, rights, and security

We may share information with subprocessors that provide hosting, analytics, email, AI, security, and support services. Data may be processed across borders where those providers operate. We retain data as long as reasonably necessary to provide the service, maintain records, preserve audit trails, resolve disputes, enforce agreements, and comply with legal obligations.

Where applicable, users may request access, correction, deletion, restriction, or export of certain data. We use administrative, technical, and organizational safeguards designed to protect information, but no system is perfectly secure. We do not sell personal information.

5. Privacy contacts

Privacy requests and complaints: [PRIVACY EMAIL]. General support: [SUPPORT EMAIL]. Mailing address: [COMPANY ADDRESS]. Final lawyer review is strongly recommended before launch.