Privacy Policy

Your Data, Your Control

Simple, honest privacy policy. No legal jargon, no hidden surprises.

Effective Date: January 22, 2026 | Last Updated: January 23, 2026

1. The Basics: What We Collect & Why

Invoice Forge is a productivity tool that helps you create invoices. To make that work, we need to collect some data. Here's the simple breakdown:

Your Account Info

What: Email address, name (if you provide it), profile photo (from Google/GitHub)

Why: So you can log in and we can identify your account

Source: You (via OAuth login)

Your Business Data

What:

  • Sender profiles (your company name, address, tax ID, bank account)
  • Customer database (client names, emails, addresses, tax IDs)
  • Product catalog (names, prices, descriptions)

Why: So Invoice Forge can generate invoices with the right information

Invoice Data & Snapshots

What: Invoice details (number, date, currency, totals) + Snapshots – frozen copies of sender + customer data at the time you finalize an invoice

Why Snapshots?

Imagine you update your client's address in your database. Without snapshots, your old invoices would show the new address (confusing!). Snapshots keep historical invoices accurate.

Retention: Invoices (including snapshots) are kept as long as you use the service. When you delete your account, everything is permanently removed within 30 days.

2. Age Restriction

Invoice Forge is strictly for users 18 years of age or older. We do not knowingly collect or process personal data from anyone under 18.

If you believe a minor has created an account, please contact us immediately at Invoice Forge <support@invoiceforge.hopko.dev>, and we will delete their data within 72 hours.

3. Cookies & Tracking

Invoice Forge uses one strictly necessary session cookie for authentication purposes only.

Authentication Cookie Details

  • Cookie Name: next-auth.session-token (or __Secure-next-auth.session-token on HTTPS)
  • Purpose: Keep you logged in and manage your session
  • Technology: Auth.js (NextAuth.js)
  • Duration: Session-based (expires when you log out or after 30 days of inactivity)
  • Type: First-party cookie (no third-party tracking)

By using Invoice Forge, you consent to the use of this strictly necessary cookie. Without it, the Service cannot function.

What We DON'T Use

  • Advertising cookies
  • Analytics cookies (e.g., Google Analytics)
  • Social media tracking pixels
  • Cross-site tracking

4. How We Use Your Data

Core Functions

  • Generate invoices (obviously)
  • Store your customer/product catalog for easy reuse
  • Authenticate your login (via Auth.js/NextAuth with Google or GitHub)

We Do NOT:

  • Sell your data to third parties
  • Train AI models on your invoices
  • Send marketing emails (unless you opt in)
  • Share your data with tax authorities (you're responsible for that)

5. Third-Party Processors (Sub-processors)

To run Invoice Forge, we rely on trusted infrastructure providers. Here's a transparent list of who processes your data:

ServiceWhat They DoWhat They SeeLocation
VercelHosting and serverless functionsEncrypted application data, server logsUSA (with EU edge caching)
NeonDatabase storage (PostgreSQL)All user data (encrypted at rest)USA
Auth.js OAuth ProvidersAuthentication via Google/GitHubYour email, name, profile photo (authentication only)USA (Google/GitHub servers)

All providers comply with GDPR through Standard Contractual Clauses (SCCs) approved by the European Commission.

Your data is private – no one else can see your invoices or customer lists. These processors only handle the technical infrastructure.

6. Your Rights (GDPR & Ukrainian Law)

Under EU law (GDPR) and Ukrainian data protection law, you have the right to:

Access Your Data

Request a copy of everything we store about you.

Correct Your Data

Fix mistakes in your customer database, sender profiles, etc.

Delete Your Account

Close your account anytime via Settings → Privacy → Delete Account.

What gets deleted: Everything – your account, invoices, customer database, product catalog. All gone within 30 days.

Export Your Data (Data Portability)

You can export all your data in JSON format at any time:

Method 1: Go to Settings → Privacy → Export My Data

Method 2: Contact us at Invoice Forge <support@invoiceforge.hopko.dev> and we'll send you a complete data export within 72 hours

Your export will include: customer lists, product catalog, invoices, sender profiles, and all associated metadata.

Restrict Processing

Ask us to stop using your data (account will be suspended).

Object to Processing

You may object to certain types of data processing by contacting Invoice Forge <support@invoiceforge.hopko.dev>. We will cease processing unless we have compelling legitimate grounds.

Response Time: We will respond to all data requests within 30 days (may be extended by 2 months for complex requests, with notification).

7. Data Retention & Deletion Schedule

Here's exactly how long we keep your data:

Data TypeRetention Period
User account & profileDeleted 30 days after you close your account
Invoices & snapshotsDeleted with your account (30 days after closure)
Customer/product catalogsDeleted with your account (or sooner if you delete them manually)
System logs90 days (for security and debugging)true
Database backupsOverwritten every 7 days (rolling backups)true
Deleted account dataFully purged from all systems within 30 days (including backups)true
Authentication sessionExpires after 30 days of inactivity or when you log out

No long-term storage: We don't keep your data after you leave. Export what you need before deleting your account.

8. Security: How We Protect Your Data

What We Do

  • Encryption: Data is encrypted in transit (TLS/SSL) and at rest (database encryption)
  • OAuth Only: No passwords stored – we use Google/GitHub authentication
  • Access Controls: Only authorized team members can access infrastructure

What We DON'T Promise

  • 100% hack-proof (no system is)
  • Zero downtime (we're in beta)

If a breach happens: We'll notify you within 72 hours via email (GDPR requirement). We'll also inform relevant supervisory authorities if required by law.

9. Governing Law

This Privacy Policy is governed by the laws of Ukraine and complies with:

  • GDPR (EU Regulation 2016/679)
  • Ukrainian Law on Personal Data Protection
  • ePrivacy Directive (2002/58/EC)

10. Contact & Data Protection Officer

For privacy questions, data requests, or concerns:

  • Email: Invoice Forge <support@invoiceforge.hopko.dev>

EU Supervisory Authority: If you're unhappy with how we handle your data, you can file a complaint with your national data protection authority: List of EU DPAs

Ukrainian Supervisory Authority: Ukrainian Parliament Commissioner for Human Rights

11. Final Note: We're Not Tax Advisors

Invoice Forge is a productivity tool, not a tax compliance platform. You are responsible for:

Entering accurate data
Complying with local tax laws
Ensuring invoices meet legal requirements

We store your data to help you work faster, not to audit you or file your taxes.

By using Invoice Forge, you confirm:

You've read this Privacy Policy
You are 18 years of age or older
You understand how we handle your data
You consent to the use of strictly necessary cookies
You know you can delete everything anytime

Last Updated: January 23, 2026

This policy complies with GDPR (EU) 2016/679, Ukrainian Law on Personal Data Protection, ePrivacy Directive, and EU consumer protection laws.