Zum Inhalt springen

Privacy Policy — Clever Invoice App

1. Scope

This privacy policy applies exclusively to the Clever Invoice mobile application (iOS and Android). For the use of our website, please refer to our general privacy policy.

2. Data Controller

dieBestenderStadt Media GmbH
Kleiner Sand 2
76829 Landau
Germany

Phone: +49 157 87685218
Email: datenschutz@clever-invoice.com

3. What Data Does the App Collect?

3.1 Account Information

During registration, we collect your email address and name. Alternatively, you can sign in via Google OAuth or Apple Sign-In, in which case we receive the profile data provided by these services (name, email). Passwords are stored exclusively as cryptographic hashes.

Legal basis: Art. 6(1)(b) GDPR (performance of contract)

3.2 Business Data

To create invoices and quotes, we store your company data: company name, address, phone number, email, VAT ID, tax number, and bank details (IBAN, BIC).

Legal basis: Art. 6(1)(b) GDPR (performance of contract)

3.3 Invoice and Financial Data

The app stores your created invoices, quotes, line items, recurring invoices, customer data (company name, contact person, email, phone, address, tax number) and your product and service catalog.

Legal basis: Art. 6(1)(b) GDPR (performance of contract)

3.4 Payment Data

Payment processing is handled by Stripe (PCI-DSS Level 1 certified). Credit card data is neither stored in the app nor on our servers. We only store the Stripe customer ID and subscription status.

Legal basis: Art. 6(1)(b) GDPR (performance of contract)

3.5 Device Identifiers

We store your user ID (UUID) and, if you enable push notifications, your Firebase device token. No advertising identifiers (IDFA/GAID) are collected.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in service delivery)

4. Device Permissions

All permissions are optional. The app works without them, though with reduced functionality.

4.1 Microphone

Purpose: Voice-to-invoice feature. Your voice recording is sent to OpenAI Whisper for transcription and is not permanently stored.

Legal basis: Art. 6(1)(a) GDPR (consent)

4.2 Contacts

Purpose: Import customer data from your device contacts. Contacts are only read when explicitly triggered by you and are not shared with third parties.

Legal basis: Art. 6(1)(a) GDPR (consent)

4.3 Camera and Photo Library

Purpose: Adding images to invoices and products, and document scanning. Images are uploaded to Supabase Storage (EU servers).

Legal basis: Art. 6(1)(a) GDPR (consent)

4.4 Push Notifications

Purpose: Payment reminders, invoice status updates, and important notifications. Delivered via Firebase Cloud Messaging (Google). Only the device token is stored; no tracking is performed.

Legal basis: Art. 6(1)(a) GDPR (consent)

5. Third-Party Services and Data Processors

5.1 Supabase (Database and Authentication)

Purpose: Backend infrastructure, database, authentication, file storage
Server location: EU (Frankfurt)
Data processed: All account and business data

5.2 Stripe (Payment Processing)

Purpose: Payment processing, subscription management
Certification: PCI-DSS Level 1
Data processed: Payment method, billing information

5.3 Firebase Cloud Messaging (Push Notifications)

Purpose: Delivery of push notifications
Data processed: Device token, notification content

5.4 Anthropic Claude (AI Features)

Purpose: AI chat for invoice creation, smart parsing, suggestions
Data processed: Chat messages, invoice context (processed per request, not permanently stored by Anthropic)

5.5 OpenAI Whisper (Speech Recognition)

Purpose: Speech-to-text transcription
Data processed: Audio recordings (sent for transcription, not permanently stored)

5.6 Sentry (Error Tracking)

Purpose: Error tracking and crash reporting
Data processed: Error logs, device type, OS version (no personal data)

6. On-Device Storage

  • Secure Storage (iOS Keychain / Android EncryptedSharedPreferences): Session tokens and authentication credentials — encrypted by the operating system
  • AsyncStorage: User preferences, UI settings, cached data — stored locally, not transmitted

No data is stored unencrypted on the device file system.

7. Data Security

  • TLS/SSL encryption for all data in transit
  • AES-256-GCM encryption for sensitive tokens at rest
  • Supabase Row-Level Security (RLS) for strict data isolation
  • Two-factor authentication (2FA) available

8. Data Retention

  • Account data: For the duration of the contractual relationship plus statutory retention periods
  • Invoice and financial data: 10 years per German tax law (AO, HGB)
  • Log data: 6 months
  • After account deletion: Data deleted within 30 days, unless statutory retention obligations apply

9. Your Rights

Under the GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)
  • Right to lodge a complaint with a supervisory authority

To exercise your rights, contact us at: datenschutz@clever-invoice.com

You can manage your privacy choices directly on our Privacy Choices page.

10. No Analytics or Tracking

The app does not use any analytics libraries (no Google Analytics, no Facebook SDK, no ad tracking). No advertising identifiers are collected and no user profiling is performed.

11. International Data Transfers

The primary data storage location is in the EU (Supabase, Frankfurt). Some third-party services (Stripe, Firebase, Anthropic, OpenAI, Sentry) may process data in the United States. All transfers to the US are safeguarded by the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs).

12. Changes to This Privacy Policy

Updates will be published on this page. Material changes will be communicated via in-app notification or email.

Last updated: February 2026