Privacy Policy
Last updated: 6 October 2026
InvoiceSheet Lite (“we”, “the service”) turns invoice and receipt files into spreadsheets. It is run by an independent developer. This policy explains what data the service handles, why, and for how long. For any privacy question or request, email gyan71@outlook.com.
1. Files you upload
- You upload invoice or receipt files (PDF, PNG or JPG, one at a time, up to 15 MB). They may contain business details such as vendor names, addresses, tax IDs and amounts.
- PNG and JPG images are read in your browser. PDFs are sent to our server so it can read the text layer or render the pages as images. The file is processed in memory or a temporary folder and deleted as soon as the response is sent.
- We do not keep copies of your files or of the extracted results on our servers, and we do not use them to train AI models.
- For scanned files the browser may load open-source OCR and PDF libraries (Tesseract.js, PDF.js) from the jsDelivr CDN. They run locally; your file is not sent to the CDN.
2. Hosted AI
- When you use Hosted AI (the free trial or the $9/month plan), the file — or the text and page images read from it — is sent through our server to the third-party AI model provider we have configured, which returns the extracted invoice fields.
- Our server handles the request in memory or temporary storage and discards the file and the result once the response is sent. We do not store invoice contents long-term. The model provider processes the data under its own terms, only to return the result.
- We record minimal operational events such as processing time, token count, model name and error type. These never include invoice contents or keys.
3. Your own API key (BYOK)
- The API key, base URL and model you enter are saved only in your browser’s localStorage. By default your browser calls your provider directly.
- If your provider blocks browser requests and the relay option is on, the request (including your key) passes through our server once on its way to your provider. The relay does not log or store your key or the request contents.
- What your provider does with the data is governed by your agreement with that provider.
4. Subscription and billing
- Payments are processed by Stripe. We never see or store your card number.
- After checkout we store, in our database hosted on Supabase: the email you used at Stripe checkout, your license key, your Stripe customer and subscription IDs, the subscription status and billing period dates, and how many Hosted AI runs you used in each billing period (for the fair-use cap).
- If you create an account (optional), Supabase Auth stores that email address, a hashed password, sign-in timestamps, and — at sign-up only — a short-lived 6-digit email confirmation code so we can confirm the mailbox and find the subscription bought with that email.
- For the free Hosted AI trial we store an anonymous random browser ID with a trial counter, and a salted hash of your IP address (never the raw IP) to limit abuse.
5. Data stored in your browser
- History: extracted results are saved only in this browser’s localStorage (
isl_history_v1). Delete them any time with “Clear history”. - We use localStorage, not tracking cookies, for: language (
isl_lang), selected mode (isl_mode), anonymous client ID (isl_client_id), free-trial counter (isl_trial_used), license key (isl_license), sign-in session (isl_auth: sign-in tokens and your email, only if you sign in) and BYOK settings (isl_byok). - We do not use advertising or analytics cookies. Stripe’s checkout and customer portal pages set their own cookies on Stripe’s domain.
6. Server logs
To run the service and prevent abuse, our server logs each API request’s method, path, status code and response time. Your IP address is used in memory for rate limiting. Our hosting provider may keep standard access logs.
7. Who we share data with
We do not sell personal data. We share it only with the processors needed to run the service — our hosting provider, Supabase (database and email sign-in), Stripe (payments) and, for Hosted AI only, the AI model provider — or when required by law.
8. How long we keep data
- Uploaded files and extraction results: not kept after the request.
- License and billing records: while your subscription exists, and afterwards as long as needed for accounting and legal obligations.
- Operational events: deleted after 90 days.
- Anonymous trial counters: kept to enforce the free-trial limit.
9. Your choices and rights
You can ask to access, correct or delete the data we hold about you (for example your license and checkout email) by emailing gyan71@outlook.com, preferably from your checkout email address. We reply within 30 days. You can manage or cancel your subscription at any time under “Billing & usage” → “Manage subscription” (Stripe customer portal).
10. Children
The service is meant for business and personal bookkeeping and is not directed at children under 16.
11. Changes
If we change this policy, we update this page and the date above. Material changes are announced to subscribers by email.
12. Contact
Email: gyan71@outlook.com