I Hate Invoicing

Privacy Policy

Effective Date: July 13, 2026

Last Updated: July 13, 2026

Document Version: 2026-07-13

Introduction

At I Hate Invoicing ("we," "our," or "us"), we respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services (collectively, the "Services").

Information We Collect

Information You Provide to Us

Account Information

  • Name and email address
  • Business name and contact information
  • Password credentials are managed by Supabase Auth; we do not receive or store your plaintext password

Invoice Information

  • Client names and email addresses
  • Invoice amounts and descriptions
  • Invoice payment status and Stripe payment identifiers; Stripe handles payment-card details

Payment Processing Information

  • Stripe connected-account identifier and connection status
  • Bank account information is collected and stored by Stripe, not by us

Communications

  • Messages you send to our support team
  • Feedback and feature requests

Information Collected Automatically

Usage Information

  • Request and security information such as IP address, user agent, timestamps, route, and audit events where recorded by the Service or its hosting providers
  • Product records such as invoice activity, payment status, and feature configuration

Push Notification Data

  • Web-push subscription details (browser endpoint and keys) used to send payment and reminder notifications

Cookies and Similar Technologies

We use cookies and local browser storage primarily to:

  • Keep you logged in
  • Remember limited app preferences, such as whether a PWA prompt was dismissed
  • Support product analytics; PostHog stores an analytics identifier linked to your account

You can control cookies through your browser settings.

How We Use Your Information

We use your information to:

Provide Services

  • Create and manage your account
  • Process and store invoices
  • Facilitate payments through Stripe
  • Send invoice emails to your clients

Improve Services

  • Monitor reliability, prevent abuse, fix bugs, and improve the Service

Communicate with You

  • Send service updates and notifications
  • Respond to your inquiries
  • Send payment confirmations
  • Send payment and reminder push notifications
  • Provide customer support

How We Share Your Information

We do not sell your personal information. We share information only in these limited circumstances:

With Your Clients

  • Invoice information you choose to send
  • Your business name and contact details (as shown on invoices)

With Service Providers

  • Stripe - Payment processing (covered by Stripe's privacy policy)
  • Supabase - Database and authentication
  • DeepSeek - AI-assisted invoice drafting and structuring from information you submit; the product does not intentionally include payment-card fields in model requests, and you must not enter card details into chat
  • Emailit - Transactional invoice, notification, and account emails
  • PostHog - Product analytics; pageviews and feature events are linked to your account ID, and a code-enforced property whitelist keeps events free of invoice amounts, client names, and client emails
  • Sentry - Error monitoring, including session replay that masks text on the page
  • Google - Only if you connect Gmail to send from your own address
  • Connected tools such as Claude or ChatGPT - only when you enable MCP access, using the account data authorized through OAuth
  • Vercel and related hosting, logging, and monitoring providers used to operate the Service

Each provider processes information under its own terms and privacy documentation and our applicable agreements with that provider.

When you use AI-assisted features, relevant conversation and invoice details may be transmitted to DeepSeek to generate a response. Do not submit information you are not authorized to share or information that requires a separate regulated-data agreement. Our AI telemetry records provider, model, operation, token counts, latency, cost, and outcome; it is linked to your account ID, may include error type and a truncated error message, and is designed not to store prompts or model responses.

For Legal Reasons

  • To comply with legal obligations
  • To respond to lawful requests from authorities
  • To enforce our Terms of Service
  • To protect our rights or property
  • To prevent fraud or abuse

Business Transfers

If we are acquired or merge with another company, your information may be transferred as part of that transaction. We will notify you of any such change.

International Processing and Transfers

We operate from the United States and may process information in the United States and other countries where we or our service providers operate. Those countries may have data-protection rules that differ from the rules where you live. When applicable law requires safeguards for an international transfer, we will use a legally recognized transfer mechanism or another permitted safeguard. You may contact us at hello@huvia.ai with questions about the safeguards that apply to your information.

Data Security

We implement industry-standard security measures to protect your information:

Technical Measures

  • Encryption in transit (SSL/TLS)
  • Encryption at rest (database-level)
  • Secure authentication (hashed passwords)
  • Row-level access controls and server-side authorization checks

Organizational Measures

  • Restricted access to production credentials and service-role keys
  • Secure development and monitoring practices appropriate to the Service

Third-Party Security

  • Stripe handles payment-card data within its payment environment
  • Supabase provides authentication, database, and row-level security infrastructure
  • Emailit, DeepSeek, Google, Vercel, and other providers apply their own security controls to the information they process

However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

Your Rights and Choices

Depending on where you live and the law that applies to your information, you may have the following rights regarding your information. We will verify requests as permitted by law and may deny or limit a request when a legal exception applies.

Access

Request a copy of your personal information. Email: hello@huvia.ai

Correction

Update inaccurate information in your account settings

Deletion

Request deletion of your account and data. Note: Some information may be retained for legal compliance

Opt-Out

  • Disable optional browser storage through your browser settings

Additional Regional Rights

Where applicable, you may also have rights to restrict or object to certain processing, receive your information in a portable format, withdraw consent where processing relies on consent, or appeal a decision about a privacy request. You may complain to your local data-protection authority.

To exercise these rights, contact us at hello@huvia.ai.

Data Retention

We retain information only for as long as:

  • Your account is active
  • Necessary to provide Services
  • Meet legal, tax, accounting, security, fraud-prevention, dispute, and enforcement obligations

When you delete your account:

  • The account, invoices, clients, audit records, and related application data are submitted for deletion through the account-deletion flow
  • Some information may remain in provider systems, backups, security logs, payment records, or legal records for the period required by the applicable provider or law
  • Deletion does not automatically delete your separate Stripe account or records Stripe is required to retain

Children's Privacy

Our Services are not intended for users under 18 years of age. We do not knowingly collect information from children under 18. If you believe we have collected information from a child under 18, please contact us immediately at hello@huvia.ai.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. For material changes, we will make reasonable efforts to notify you by email.

Your continued use of the Services after changes constitutes acceptance of the updated policy.

Contact Us

Questions about this Privacy Policy?

Mailing address: PO Box 1303, Kernersville, NC 27285-1303, USA

Email: hello@huvia.ai