Privacy Policy

What we collect

Nothing readable. Seriously.

How it works

  1. You enter a password
  2. Your browser creates an encryption key from it
  3. All your data is encrypted before it leaves your browser
  4. We store encrypted blobs that look like: a8f3k2...x9z
  5. We cannot decrypt this. Only your password can.

What we can't do

  • Read your invoices
  • See your client names
  • Access your financial data
  • Recover your password
  • Comply with data requests (we have no readable data)

Your rights

  • Delete everything: just forget your password
  • Export: download PDFs anytime
  • Portability: your data is yours (encrypted)

Technical implementation

Encryption: AES-256-GCM
Key derivation: PBKDF2 with 600,000 iterations
Implementation: Web Crypto API (native browser)
Storage: IndexedDB (local) + optional encrypted cloud sync

Contact

Questions? Reach us at [email protected]

Last updated: January 2026