Skip to content

Privacy

Last updated July 29, 2026

The plain-language version is the policy.

Your invoices are made in your browser

The free generator runs entirely on your device. When you create an invoice and download it as a PDF, Word, or Excel file, the document is generated locally — the contents are not uploaded to us. Drafts use your browser’s local storage; clearing your browser data clears them, and we can’t see them.

What an account stores

If you create an account, we store what you save: your business profile (name, email, address, logo, invoice defaults) and your invoices and quotes, including the client details you put on them. We also keep the operational records needed to run the service safely, such as send status, document activity, payment state, audit events, and standard server logs.

Client details belong on invoices, so you’re trusting us with someone else’s name and email too. We use them only to render, send, and track your documents on your instruction — never for marketing, never sold, never shared beyond the services below.

The services we rent (and what they see)

People you bill

Invoice links are long, unguessable bearer URLs — anyone with the link can open the document while the sender’s account is active, without signing in. Links do not yet expire automatically and cannot yet be individually revoked or rotated, so recipients should not forward them. Suspending or placing the sender account on a deletion hold disables all of its hosted links. The first open marks the document “viewed” for the sender (approximate by nature: inbox link-scanners can trigger it). Card payments happen inside Stripe’s secure fields; card numbers never touch BillTo’s servers.

What we don’t do

No ad trackers, no cross-site profiling, no selling data, and no marketing emails you didn’t ask for. Public-page analytics helps us understand which guides are useful and where people complete or leave the generator; those events use fixed labels such as export format and never include invoice contents, client details, amounts, account IDs, payment-link tokens, account routes, or URL query strings.

Retention and deletion

Your data stays while your account is active. To delete your account, email hello@billto.app from your account email. We will respond within 30 days with either confirmation that deletion completed or the status and reason for a required retention hold. A never-connected account with no money history can have its Clerk identity, logo, and BillTo application rows erased. If a connected account, payment, dispute, fraud-prevention, tax, security, or other legal record must be retained, we first suspend the account and disable sending, onboarding, payment collection, and its hosted links. The current hold preserves the saved application record; the future anonymization/minimization workflow is not implemented, so we do not describe a held account as erased. Held data is not used for marketing. Stripe and Clerk separately retain what their financial and identity rules require under their own policies. Before requesting deletion, download any documents you want to keep; exports are free.

Questions or requests: hello@billto.app.