Your invoices live on your device
Invobis is built so that your business records stay yours. This page lists every path data can take off your device — each one starts with an action you choose to take.
Everything you create in Invobis — invoices, estimates, credit notes, clients, payments, your business profile, logo and signature — is stored in a local database on your device. Nothing leaves it unless you act: turning on iCloud backup, publishing an invoice link, emailing an invoice, signing in, or subscribing. We run no ads and never use your clients’ data for anything except the feature you invoked. We do measure how the app itself is used — which screens people reach, whether a purchase succeeded, how often an invoice is sent — and that measurement never includes what is on your invoices.
The controller for the processing described here is Rashem Pandit, trading as Invobis, Vorbergstrasse 10A, 10823 Berlin, Germany — hello@invobis.com. Full identity in the legal notice / Impressum.
The app’s database is local. We cannot read it, and it is not sent to our servers. That includes documents you only ever export as PDFs through the share sheet — those go through your own apps, not through us.
If device backup is on, the app syncs its database to the private CloudKit database of your own iCloud account, operated by Apple under your Apple ID. We have no access to it and run no server of our own for it. Turning backup off stops the sync; Apple’s handling is described in Apple’s own privacy terms.
Sharing an invoice as a link uploads a snapshot of that document to our hosting backend (Supabase) so the page at invobis.com can show it to your client. The snapshot contains what the document itself contains: your business details as printed, your client’s name and the details you put on the invoice, line items, amounts, tax, dates, payment details — and, optionally, the PDF rendered on your device.
If you send an invoice by email from the app, we pass the recipient address, your message, the link and the PDF to our email delivery provider solely to deliver that email. The reply-to is your address, so answers go to you. Client email addresses are used for nothing else — no marketing, no lists. Sending through the share sheet instead uses your own mail app and never touches our servers.
Card payments on a hosted invoice run through Stripe Checkout on your own connected Stripe account — funds move directly from your client to you; we never hold them. Card details are entered on Stripe’s pages and processed by Stripe under Stripe’s privacy policy; we never see card numbers. We receive the confirmation that an invoice was paid, which updates its status for you and your client.
Signing in is optional and exists so hosted documents can be owned by you (required for online payment). Via Supabase Auth we receive the identifier Apple issues and the email you choose to share — which may be Apple’s private relay address. It is used only to know which published documents are yours.
Payment for Invobis Pro is handled entirely by Apple through your App Store account; we never see your payment details. To know whether a subscription is active the app uses RevenueCat, which receives an anonymous app-generated identifier and your App Store transaction data (product, purchase and expiry dates) under RevenueCat’s privacy policy.
invobis.com — this site and the hosted invoice pages — sets no advertising or analytics cookies. Hosting infrastructure keeps short-lived technical logs (such as requests and errors) needed to run and secure the service.
Where the GDPR applies: hosting the pages you publish, delivering the emails you send, sign-in and operating your subscription are performance of our contract with you (Art. 6(1)(b)). View timestamps and abuse prevention rest on our legitimate interest in running the service securely and giving you the read-receipt the product promises (Art. 6(1)(f)). Data on your device and in your iCloud stays under your control and is not processed on our servers. For personal data inside the invoices you publish (your clients’ details), you are the controller of that content; we process it for you as part of the service.
Product analytics is processed inside the EU (PostHog, Ireland). Our hosting backend (Supabase), email delivery, Stripe and RevenueCat may process data on servers outside the EEA, including in the United States. Where that happens, transfers rely on the safeguards those providers offer under the GDPR — EU standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.
You can export your data from the app at any time (Settings → Your data). For anything we hold server-side — published documents and the sign-in that owns them — you can ask for access, correction or deletion at hello@invobis.com. Under the GDPR you also have the rights to restriction, portability and objection, and to complain to a supervisory authority. You can delete the Invobis account directly in the app (Settings → Account → Delete account) — that permanently removes your published documents, their PDFs, view events and your sign-in. It does not cancel Apple billing.
To learn where the app confuses people and what to fix next, Invobis records a small, fixed list of things that happen inside it: which onboarding step you reached, whether you moved back a step, whether a subscription purchase completed or was cancelled, that you signed in, and that a document was started, created, sent, converted from an estimate, or marked paid. Each of these carries only the fact that it happened plus a coarse label — the kind of document, the plan you chose, the country you told us your business is in.
Two of those labels deserve spelling out. When a document goes out, we record how: by email, by link, through the share sheet, or only marked as sent. For the share sheet we keep a broad category — saved to files, mail, messages, a chat app, print — and never the name of the app you picked. And when a new draft is closed without being created, we record how far it had got: whether a client had been chosen, whether any line had been added, whether you had previewed it. Not which client, and not what the lines said.
What these records never contain: invoice or estimate amounts, totals, currency figures, client names, client email addresses, your business name, line-item descriptions, notes, logos or signatures. The contents of your documents are not part of this and never leave your device except by the routes described above.
The processor is PostHog, on their EU infrastructure (Ireland), acting under a data processing agreement. IP addresses are discarded on arrival rather than stored. We do not use an advertising identifier, do not record your screen, and do not build advertising profiles. Records are held for up to 24 months and are tied to a random identifier generated on your install — never your name, email or Apple ID. That same random identifier is shared with our subscription provider so a renewal or cancellation can be matched to the app it came from. Deleting your account deletes them; see Your rights. The legal basis is our legitimate interest in understanding and improving our own product (Art. 6(1)(f) GDPR), and you may object at any time by writing to us.
If we change what the app actually does with data, this page and its date change before the new behaviour ships. Material changes are called out in the app.
Rashem Pandit, trading as Invobis
Vorbergstrasse 10A
10823 Berlin
Germany
hello@invobis.com
Legal notice / Impressum