Privacy Policy
Last updated: August 7, 2026
This policy explains what Involoop stores, why, and what you can ask us to delete. It covers the product as it works today.
What we store
Account data: your email, the name you type, and an authentication record held by Supabase, our database and auth provider.
Invoice data: the client name, description, amount, currency, and due date you enter, plus the public link generated for each invoice.
Usage data: how many times an invoice link was opened, whether the referral invitation on it was clicked, and the credit movements in your ledger.
A language cookie (involoop_lang) and, if you arrived through someone's invoice, a referral cookie (ref_invoice) that expires after 7 days.
What we never store
Card numbers, CVCs, and bank credentials. Payment details are entered on PayPal's own checkout page and never reach our servers.
Who else processes your data
Supabase (database, authentication), PayPal (payments), Vercel (hosting and request logs), and an AI provider that receives only the billing sentence you type when you ask it to compose an invoice.
The sentence you send to the AI step is used to produce that invoice and is not used to train models by us.
Invoices are public by design
Anyone holding an invoice link can see its contents without logging in. That is what makes the link shareable, so treat the link like the invoice itself and only send it to the client it belongs to.
Deletion and questions
Email hello@involoop.vercel.app to request a copy of your data or the deletion of your account and invoices. We aim to respond within 30 days.