Privacy Policy — Clever Invoice App
1. Scope
This privacy policy applies exclusively to the Clever Invoice mobile application (iOS and Android). For the use of our website, please refer to our general privacy policy.
2. Data Controller
dieBestenderStadt Media GmbH
Kleiner Sand 2
76829 Landau
Germany
Phone: +49 157 87685218
Email: datenschutz@clever-invoice.com
3. What Data Does the App Collect?
3.1 Account Information
During registration, we collect your email address and name. Alternatively, you can sign in via Google OAuth or Apple Sign-In, in which case we receive the profile data provided by these services (name, email). Passwords are stored exclusively as cryptographic hashes.
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
3.2 Business Data
To create invoices and quotes, we store your company data: company name, address, phone number, email, VAT ID, tax number, and bank details (IBAN, BIC).
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
3.3 Invoice and Financial Data
The app stores your created invoices, quotes, line items, recurring invoices, customer data (company name, contact person, email, phone, address, tax number) and your product and service catalog.
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
3.4 Payment Data
Payment processing is handled by Stripe (PCI-DSS Level 1 certified). Credit card data is neither stored in the app nor on our servers. We only store the Stripe customer ID and subscription status.
Legal basis: Art. 6(1)(b) GDPR (performance of contract)
3.5 Device Identifiers
We store your user ID (UUID) and, if you enable push notifications, your Firebase device token. No advertising identifiers (IDFA/GAID) are collected.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in service delivery)
4. Device Permissions
All permissions are optional. The app works without them, though with reduced functionality.
4.1 Microphone
Purpose: Voice-to-invoice feature. Your voice recording is sent to OpenAI Whisper for transcription and is not permanently stored.
Legal basis: Art. 6(1)(a) GDPR (consent)
4.2 Contacts
Purpose: Import customer data from your device contacts. Contacts are only read when explicitly triggered by you and are not shared with third parties.
Legal basis: Art. 6(1)(a) GDPR (consent)
4.3 Camera and Photo Library
Purpose: Adding images to invoices and products, and document scanning. Images are uploaded to Supabase Storage (EU servers).
Legal basis: Art. 6(1)(a) GDPR (consent)
4.4 Push Notifications
Purpose: Payment reminders, invoice status updates, and important notifications. Delivered via Firebase Cloud Messaging (Google). Only the device token is stored; no tracking is performed.
Legal basis: Art. 6(1)(a) GDPR (consent)
5. Third-Party Services and Data Processors
5.1 Supabase (Database and Authentication)
Purpose: Backend infrastructure, database, authentication, file storage
Server location: EU (Frankfurt)
Data processed: All account and business data
5.2 Stripe (Payment Processing)
Purpose: Payment processing, subscription management
Certification: PCI-DSS Level 1
Data processed: Payment method, billing information
5.3 Firebase Cloud Messaging (Push Notifications)
Purpose: Delivery of push notifications
Data processed: Device token, notification content
5.4 Anthropic Claude (AI Features)
Purpose: AI chat for invoice creation, smart parsing, suggestions
Data processed: Chat messages, invoice context (processed per request, not permanently stored by Anthropic)
5.5 OpenAI Whisper (Speech Recognition)
Purpose: Speech-to-text transcription
Data processed: Audio recordings (sent for transcription, not permanently stored)
5.6 Sentry (Error Tracking)
Purpose: Error tracking and crash reporting
Data processed: Error logs, device type, OS version (no personal data)
6. On-Device Storage
- Secure Storage (iOS Keychain / Android EncryptedSharedPreferences): Session tokens and authentication credentials — encrypted by the operating system
- AsyncStorage: User preferences, UI settings, cached data — stored locally, not transmitted
No data is stored unencrypted on the device file system.
7. Data Security
- TLS/SSL encryption for all data in transit
- AES-256-GCM encryption for sensitive tokens at rest
- Supabase Row-Level Security (RLS) for strict data isolation
- Two-factor authentication (2FA) available
8. Data Retention
- Account data: For the duration of the contractual relationship plus statutory retention periods
- Invoice and financial data: 10 years per German tax law (AO, HGB)
- Log data: 6 months
- After account deletion: Data deleted within 30 days, unless statutory retention obligations apply
9. Your Rights
Under the GDPR, you have the following rights:
- Right of access (Art. 15 GDPR)
- Right to rectification (Art. 16 GDPR)
- Right to erasure (Art. 17 GDPR)
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right to withdraw consent (Art. 7(3) GDPR)
- Right to lodge a complaint with a supervisory authority
To exercise your rights, contact us at: datenschutz@clever-invoice.com
You can manage your privacy choices directly on our Privacy Choices page.
10. No Analytics or Tracking
The app does not use any analytics libraries (no Google Analytics, no Facebook SDK, no ad tracking). No advertising identifiers are collected and no user profiling is performed.
11. International Data Transfers
The primary data storage location is in the EU (Supabase, Frankfurt). Some third-party services (Stripe, Firebase, Anthropic, OpenAI, Sentry) may process data in the United States. All transfers to the US are safeguarded by the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs).
12. Changes to This Privacy Policy
Updates will be published on this page. Material changes will be communicated via in-app notification or email.
Last updated: February 2026