Privacy Policy
Last updated: 19 August 2026
Who we are
SimplInvoice (“we”, “us”) is an automated invoice-capture and VAT-classification service, operated by EXCYTECH LIMITED, Unit 13F, Maynooth Business Campus, Maynooth, Co. Kildare, W23 Y5N7, Ireland. This policy explains what personal data we process, why, and how you can exercise your rights. If you have any questions, contact us at support@simplinvoice.com.
What we store
- Account details: your name, email address, and role within your organisation.
- Company details you enter, including a structured registered address when you provide one.
- Invoice data you upload, import, or that we retrieve from a mailbox you connect — including supplier names, VAT numbers, amounts, and the source document. When you use your own AI keys, documents are sent to those providers on your account. When platform-provisioned AI runs (trial, Enterprise, or the Platform AI add-on, after your own keys fail), invoice images may be sent to SimplInvoice’s configured LLM vendors to extract fields. SimplInvoice is the processor for that path; those vendors are subprocessors used only for field extraction, not model training. You can opt out or disable fallback when you have your own keys under Settings → AI.
- Mailbox credentials for any mailbox you connect. Passwords and OAuth tokens are stored encrypted at rest.
- Billing details are held by Stripe, our payment processor. We store only a customer reference, the card brand, and the last four digits.
Connected mailboxes
If you connect a mailbox (Gmail, Microsoft 365, Yahoo, Zoho, iCloud, or any IMAP account), SimplInvoice signs in to it on your behalf to collect invoices. This section describes exactly what that access is used for.
What we access
- Only the folders you nominate — INBOX by default.
- Only unread messages from the last 30 days, each time a scan runs.
- Within those messages, only PDF attachments.
What we keep — and what we do not
- We keep the PDF attachments we collect, and the invoice fields extracted from them (supplier, VAT number, dates, amounts).
- We do not store the body, subject, or recipients of your emails. Messages are read in transit to find attachments and are not retained.
- We never send email from your account, never modify or delete messages, and never access folders you have not nominated.
Limited use of Google user data
SimplInvoice's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically: we use this data only to provide and improve the invoice-capture features you asked for; we do not transfer it to others except as necessary to provide those features, for security purposes, or to comply with applicable law; we do not use it for advertising; and we do not allow humans to read it, except with your explicit consent for a specific support request, where required for security, or to comply with applicable law.
Withdrawing access
You can disconnect a mailbox at any time from its page in SimplInvoice — this deletes the stored credentials immediately and stops all scanning. You can additionally revoke access from your provider's own account settings (for Google, at myaccount.google.com/permissions). Invoices already captured are kept as part of your accounting records unless you ask us to delete them.
Why we process your data
- To provide the service you signed up for (contract) — storing your invoices, extracting their details, classifying them, and producing reports and exports.
- To comply with legal obligations — retaining accounting and tax records, and responding to lawful requests from authorities.
- For our legitimate interests — keeping the service secure, preventing abuse and fraud, and improving reliability. When you add a company address we may use your IP address only to guess country and town on the form; that guess is not stored as the company address unless you keep it in the fields.
- With your consent where applicable — for example, connecting a mailbox or choosing an AI extraction provider. You can withdraw consent at any time by changing the relevant setting or disconnecting the mailbox.
How long we keep data
- Account data — while your account is active, and as long as needed afterwards to meet legal or record-keeping obligations.
- Invoices and extracted data — for as long as your accounting and tax record-keeping obligations require, and for as long as you keep your account.
- Mailbox credentials — until you disconnect the mailbox, at which point they are deleted immediately.
- Operational logs (scan activity, AI-settings activity, VIES lookups, extraction attempts, audit trails) — pruned automatically: the activity trail is retained for 90 days and audit trails for 365 days, keeping recent history per record.
Third parties that process your data
- AI extraction providers — invoice text or images are sent to the provider your organisation selects (OpenAI, Anthropic, Google, Mistral, NVIDIA, Cloudflare, GitHub Models, Hugging Face, or OpenRouter) to extract structured fields. This can be disabled in Settings. When OpenRouter is used, requests ask it to route only to endpoints that do not retain or train on your documents (a setting you can change under Settings → AI). You can also switch on masking (under Settings → Features), which replaces IBANs, card numbers and phone numbers in document text with a placeholder before it is sent; scanned pages sent as pictures cannot be masked.
- VIES — the European Commission's VAT validation service, used to check supplier VAT numbers.
- IP geolocation — a lookup of your IP (Cloudflare country header and/or ipwho.is, with ip-api.com as a fallback) to pre-fill country and town on the company address form. We do not store the lookup itself as your address.
- Stripe — subscription billing and payment processing.
- Your email provider — we read messages from the folders you nominate in order to collect invoice attachments.
International transfers
Depending on which AI provider your organisation selects, invoice content may be processed by a provider located outside the EEA. You choose the provider in Settings → AI extraction, and you can disable AI extraction entirely. Where data is transferred outside the EEA, we rely on appropriate safeguards (such as the provider's standard contractual clauses) and on your control over the provider choice. The VIES service is operated by the European Commission.
Security
- Mailbox credentials (passwords and OAuth tokens) are encrypted at rest.
- All traffic to the service is encrypted in transit (TLS).
- Access to production data is restricted to personnel who need it to operate and secure the service.
Cookies
SimplInvoice uses only the functional cookies required to keep you signed in and protect forms — a session cookie and a CSRF-token cookie. We do not use advertising, tracking, or analytics cookies. You can clear cookies in your browser at any time; doing so will sign you out.
Your rights
Under GDPR you can request access to, correction of, or deletion of your personal data. See our GDPR page for how to make a request, or contact us.
Changes to this policy
We may update this policy as the service or the law changes. Material changes will be announced in the application and the updated policy will be posted on this page with a new “Last updated” date. Continued use of the service after a change takes effect constitutes acceptance of the updated policy.
← Back to home