Privacy
Last updated July 29, 2026
The plain-language version is the policy.
Your invoices are made in your browser
The free generator runs entirely on your device. When you create an invoice and download it as a PDF, Word, or Excel file, the document is generated locally — the contents are not uploaded to us. Drafts use your browser’s local storage; clearing your browser data clears them, and we can’t see them.
What an account stores
If you create an account, we store what you save: your business profile (name, email, address, logo, invoice defaults) and your invoices and quotes, including the client details you put on them. We also keep the operational records needed to run the service safely, such as send status, document activity, payment state, audit events, and standard server logs.
Client details belong on invoices, so you’re trusting us with someone else’s name and email too. We use them only to render, send, and track your documents on your instruction — never for marketing, never sold, never shared beyond the services below.
The services we rent (and what they see)
- Clerk — sign-in. Holds your login email and credentials.
- Supabase— our database and logo storage. Holds your saved invoices, clients, and settings. Our production database connections use Supabase’s database CA certificate to verify the server and its hostname.
- Resend — email delivery. Sees the invoices, quotes, manual reminders and receipts we send on your instruction, and their recipients.
- Stripe— payments. If you enable online payments, Stripe collects your payout and identity details directly (BillTo does not receive the underlying identity or bank details) and processes your clients’ card payments under Stripe’s own terms and privacy policy.
- Vercel — hosting and aggregate, cookie-free web analytics on public marketing pages. Standard server logs include IP addresses and requests. Analytics receives only the public route without query strings; it is disabled on dashboard, admin, sign-in, sign-up and private invoice/payment pages.
- Sentry — production error monitoring. It receives software errors and technical context; we strip request headers, cookies, bodies, query strings, account IDs and private payment-link tokens before sending an event. Session replay, user tracking and performance tracing are disabled.
People you bill
Invoice links are long, unguessable bearer URLs — anyone with the link can open the document while the sender’s account is active, without signing in. Links do not yet expire automatically and cannot yet be individually revoked or rotated, so recipients should not forward them. Suspending or placing the sender account on a deletion hold disables all of its hosted links. The first open marks the document “viewed” for the sender (approximate by nature: inbox link-scanners can trigger it). Card payments happen inside Stripe’s secure fields; card numbers never touch BillTo’s servers.
What we don’t do
No ad trackers, no cross-site profiling, no selling data, and no marketing emails you didn’t ask for. Public-page analytics helps us understand which guides are useful and where people complete or leave the generator; those events use fixed labels such as export format and never include invoice contents, client details, amounts, account IDs, payment-link tokens, account routes, or URL query strings.
Retention and deletion
Your data stays while your account is active. To delete your account, email hello@billto.app from your account email. We will respond within 30 days with either confirmation that deletion completed or the status and reason for a required retention hold. A never-connected account with no money history can have its Clerk identity, logo, and BillTo application rows erased. If a connected account, payment, dispute, fraud-prevention, tax, security, or other legal record must be retained, we first suspend the account and disable sending, onboarding, payment collection, and its hosted links. The current hold preserves the saved application record; the future anonymization/minimization workflow is not implemented, so we do not describe a held account as erased. Held data is not used for marketing. Stripe and Clerk separately retain what their financial and identity rules require under their own policies. Before requesting deletion, download any documents you want to keep; exports are free.
Questions or requests: hello@billto.app.