InvoiceSheet Lite

Privacy Policy

Last updated: 6 October 2026

InvoiceSheet Lite (“we”, “the service”) turns invoice and receipt files into spreadsheets. It is run by an independent developer. This policy explains what data the service handles, why, and for how long. For any privacy question or request, email gyan71@outlook.com.

1. Files you upload

  • You upload invoice or receipt files (PDF, PNG or JPG, one at a time, up to 15 MB). They may contain business details such as vendor names, addresses, tax IDs and amounts.
  • PNG and JPG images are read in your browser. PDFs are sent to our server so it can read the text layer or render the pages as images. The file is processed in memory or a temporary folder and deleted as soon as the response is sent.
  • We do not keep copies of your files or of the extracted results on our servers, and we do not use them to train AI models.
  • For scanned files the browser may load open-source OCR and PDF libraries (Tesseract.js, PDF.js) from the jsDelivr CDN. They run locally; your file is not sent to the CDN.

2. Hosted AI

  • When you use Hosted AI (the free trial or the $9/month plan), the file — or the text and page images read from it — is sent through our server to the third-party AI model provider we have configured, which returns the extracted invoice fields.
  • Our server handles the request in memory or temporary storage and discards the file and the result once the response is sent. We do not store invoice contents long-term. The model provider processes the data under its own terms, only to return the result.
  • We record minimal operational events such as processing time, token count, model name and error type. These never include invoice contents or keys.

3. Your own API key (BYOK)

  • The API key, base URL and model you enter are saved only in your browser’s localStorage. By default your browser calls your provider directly.
  • If your provider blocks browser requests and the relay option is on, the request (including your key) passes through our server once on its way to your provider. The relay does not log or store your key or the request contents.
  • What your provider does with the data is governed by your agreement with that provider.

4. Subscription and billing

  • Payments are processed by Stripe. We never see or store your card number.
  • After checkout we store, in our database hosted on Supabase: the email you used at Stripe checkout, your license key, your Stripe customer and subscription IDs, the subscription status and billing period dates, and how many Hosted AI runs you used in each billing period (for the fair-use cap).
  • If you create an account (optional), Supabase Auth stores that email address, a hashed password, sign-in timestamps, and — at sign-up only — a short-lived 6-digit email confirmation code so we can confirm the mailbox and find the subscription bought with that email.
  • For the free Hosted AI trial we store an anonymous random browser ID with a trial counter, and a salted hash of your IP address (never the raw IP) to limit abuse.

5. Data stored in your browser

  • History: extracted results are saved only in this browser’s localStorage (isl_history_v1). Delete them any time with “Clear history”.
  • We use localStorage, not tracking cookies, for: language (isl_lang), selected mode (isl_mode), anonymous client ID (isl_client_id), free-trial counter (isl_trial_used), license key (isl_license), sign-in session (isl_auth: sign-in tokens and your email, only if you sign in) and BYOK settings (isl_byok).
  • We do not use advertising or analytics cookies. Stripe’s checkout and customer portal pages set their own cookies on Stripe’s domain.

6. Server logs

To run the service and prevent abuse, our server logs each API request’s method, path, status code and response time. Your IP address is used in memory for rate limiting. Our hosting provider may keep standard access logs.

7. Who we share data with

We do not sell personal data. We share it only with the processors needed to run the service — our hosting provider, Supabase (database and email sign-in), Stripe (payments) and, for Hosted AI only, the AI model provider — or when required by law.

8. How long we keep data

  • Uploaded files and extraction results: not kept after the request.
  • License and billing records: while your subscription exists, and afterwards as long as needed for accounting and legal obligations.
  • Operational events: deleted after 90 days.
  • Anonymous trial counters: kept to enforce the free-trial limit.

9. Your choices and rights

You can ask to access, correct or delete the data we hold about you (for example your license and checkout email) by emailing gyan71@outlook.com, preferably from your checkout email address. We reply within 30 days. You can manage or cancel your subscription at any time under “Billing & usage” → “Manage subscription” (Stripe customer portal).

10. Children

The service is meant for business and personal bookkeeping and is not directed at children under 16.

11. Changes

If we change this policy, we update this page and the date above. Material changes are announced to subscribers by email.

12. Contact

Email: gyan71@outlook.com

隐私政策

最后更新:2026 年 10 月 6 日

InvoiceSheet Lite(以下简称“我们”或“本服务”)可将发票和收据文件转换为表格,由一名独立开发者运营。本政策说明本服务会处理哪些数据、为什么处理以及保存多久。如有任何隐私问题或请求,请发送邮件至 gyan71@outlook.com。

1. 你上传的文件

  • 你上传的是发票或收据文件(PDF、PNG 或 JPG,每次一张,最大 15 MB),其中可能包含销售方名称、地址、税号、金额等业务信息。
  • PNG、JPG 图片在你的浏览器中读取。PDF 会发送到我们的服务器,用于读取文字层或把页面渲染成图片;文件只在内存或临时目录中处理,响应发出后立即删除。
  • 我们不会在服务器上保留你的文件或提取结果,也不会用它们训练 AI 模型。
  • 处理扫描件时,浏览器可能会从 jsDelivr CDN 加载开源 OCR 和 PDF 库(Tesseract.js、PDF.js)。这些库在本地运行,你的文件不会发送给 CDN。

2. 托管 AI

  • 使用托管 AI(免费试用或每月 $9 的订阅)时,文件——或从文件中读取的文字和页面图片——会经我们的服务器发送给我们配置的第三方 AI 模型服务商,由其返回提取出的发票字段。
  • 我们的服务器只在内存或临时存储中处理请求,响应发出后即丢弃文件和结果,不会长期保存发票内容。模型服务商仅为返回结果而按其自身条款处理这些数据。
  • 我们会记录少量运行事件,例如处理耗时、token 数、模型名称和错误类型,其中不包含发票内容或任何密钥。

3. 使用自己的 API Key(BYOK)

  • 你填写的 API Key、API 地址和模型只保存在你浏览器的 localStorage 中。默认情况下,浏览器直接请求你的服务商。
  • 如果服务商拦截浏览器请求且你开启了中转选项,请求(包括你的 Key)会经我们的服务器转发一次到你的服务商。中转不会记录或保存你的 Key 和请求内容。
  • 你的服务商如何处理数据,由你与该服务商之间的协议决定。

4. 订阅与账单

  • 付款由 Stripe 处理,我们不会看到或保存你的银行卡号。
  • 完成支付后,我们会在托管于 Supabase 的数据库中保存:你在 Stripe 结账时使用的邮箱、许可证密钥、Stripe 客户 ID 和订阅 ID、订阅状态与计费周期日期,以及每个计费周期内托管 AI 的使用次数(用于合理使用额度)。
  • 如果你选择创建账号,Supabase Auth 会保存该邮箱地址、哈希后的密码、登录时间,以及仅在注册时使用的短期 6 位邮箱验证码,以便确认邮箱并找到用该邮箱购买的订阅。
  • 对于托管 AI 免费试用,我们会保存一个匿名的随机浏览器 ID 及其试用次数,以及你 IP 地址的加盐哈希值(绝不保存原始 IP),用于防止滥用。

5. 保存在你浏览器中的数据

  • 历史记录:提取结果只保存在此浏览器的 localStorage 中(isl_history_v1),可随时通过“清除历史”删除。
  • 我们使用 localStorage 而非跟踪类 Cookie 来保存:界面语言(isl_lang)、所选模式(isl_mode)、匿名客户端 ID(isl_client_id)、免费试用次数(isl_trial_used)、许可证密钥(isl_license)、登录状态(isl_auth:登录令牌和你的邮箱,仅在登录后保存)和 BYOK 设置(isl_byok)。
  • 我们不使用广告或统计分析类 Cookie。Stripe 的结账页和客户门户会在 Stripe 自己的域名下设置其 Cookie。

6. 服务器日志

为运行服务和防止滥用,服务器会记录每个 API 请求的方法、路径、状态码和响应时间。你的 IP 地址仅在内存中用于频率限制。我们的托管服务商可能保留标准访问日志。

7. 数据共享

我们不出售个人数据。仅在运行服务所必需的范围内与以下处理方共享:托管服务商、Supabase(数据库和邮箱登录)、Stripe(支付),以及仅在使用托管 AI 时的 AI 模型服务商;或在法律要求时共享。

8. 保存期限

  • 上传的文件和提取结果:请求结束后不保留。
  • 许可证和账单记录:订阅存续期间保存,之后在会计和法律义务所需的期限内保存。
  • 运行事件:90 天后删除。
  • 匿名试用计数:为执行免费试用次数限制而保留。

9. 你的选择与权利

你可以发送邮件至 gyan71@outlook.com(最好使用结账邮箱),要求查阅、更正或删除我们保存的与你有关的数据(例如许可证和结账邮箱)。我们会在 30 天内答复。你可以随时在“账单与用量”→“管理订阅”(Stripe 客户门户)中管理或取消订阅。

10. 未成年人

本服务面向企业和个人记账用途,不面向 16 岁以下的未成年人。

11. 政策变更

如本政策有变更,我们会更新本页面及上方日期;重大变更会通过邮件通知订阅用户。

12. 联系方式

邮箱:gyan71@outlook.com