Privacy
Last updated July 16, 2026
The plain-language version is the policy.
Your invoices are made in your browser
The free generator runs entirely on your device. When you create an invoice and download it as a PDF, Word, or Excel file, the document is generated locally — the contents are not uploaded to us. Drafts use your browser’s local storage; clearing your browser data clears them, and we can’t see them.
What an account stores
If you create an account, we store what you save: your business profile (name, email, address, logo, invoice defaults) and your invoices and quotes, including the client details you put on them. We also keep the operational records needed to run the service safely, such as send status, document activity, payment state, audit events, and standard server logs.
Client details belong on invoices, so you’re trusting us with someone else’s name and email too. We use them only to render, send, and track your documents on your instruction — never for marketing, never sold, never shared beyond the services below.
The services we rent (and what they see)
- Clerk — sign-in. Holds your login email and credentials.
- Supabase — our database and logo storage. Holds your saved invoices, clients, and settings.
- Resend — email delivery. Sees the invoices, quotes, manual reminders and receipts we send on your instruction, and their recipients.
- Stripe— payments. If you enable online payments, Stripe collects your payout and identity details directly (BillTo does not receive the underlying identity or bank details) and processes your clients’ card payments under Stripe’s own terms and privacy policy.
- Vercel — hosting and aggregate, cookie-free web analytics on public marketing pages. Standard server logs include IP addresses and requests. Analytics receives only the public route without query strings; it is disabled on dashboard, admin, sign-in, sign-up and private invoice/payment pages.
- Sentry — optional production error monitoring. When enabled, it receives software errors and technical context; we strip request headers, cookies, bodies, query strings, account IDs and private payment-link tokens before sending an event. Session replay, user tracking and performance tracing are disabled.
People you bill
Invoice links are long, unguessable URLs — no account is needed to view or pay. The first open marks the document “viewed” for the sender (approximate by nature: inbox link-scanners can trigger it). Card payments happen inside Stripe’s secure fields; card numbers never touch BillTo’s servers.
What we don’t do
No ad trackers, no cross-site profiling, no selling data, and no marketing emails you didn’t ask for. Public-page analytics helps us understand which guides are useful and where people complete or leave the generator; those events use fixed labels such as export format and never include invoice contents, client details, amounts, account IDs, payment-link tokens, account routes, or URL query strings.
Retention and deletion
Your data stays while your account is active. To delete your account, email hello@billto.app from your account email. We process the request within 30 days and erase data that is not needed for security, payment, dispute, tax, fraud-prevention, or other legal obligations. Issued-document, payment, and audit records may be retained in minimized form for the required period; they are not used for marketing. Stripe and Clerk separately retain what their financial and identity rules require under their own policies. You can export your documents anytime — downloads are free.
Questions or requests: hello@billto.app.