Effective September 5, 2026
This Privacy Policy explains how we handle information when you use the iOS app (the “App”), visit our public website, or contact support. The App is designed as a local-first invoice maker and does not require a separate account.
The App lets you enter and store information used to create invoices, including:
This information is stored in the App's private container on your device. The App may create a local database backup before a database upgrade so that it can recover from a failed migration. The backup remains inside the App's container.
On iOS 17 and later, when iCloud is available, the App automatically synchronizes business details, clients, catalog items, and invoices through your private Apple CloudKit database. This private data belongs to your Apple Account, counts against your iCloud storage, and is not uploaded to Firebase, Amplitude, or servers operated by us. The App stores document content in a CloudKit encrypted field. Technical record metadata, such as a random synchronization identifier and timestamps, does not contain invoice content. On iOS 16 or when iCloud is unavailable, the App continues to work locally without synchronization.
When you export or share an invoice, iOS presents the system share sheet. Any transfer to another app, person, or service happens only through the destination you select and is then governed by that destination's privacy practices.
Release versions of the App use Amplitude to understand whether core screens and subscription flows work as expected. Debug builds do not send analytics.
The App sends event names describing actions such as opening a screen, creating or editing an invoice, viewing subscription plans, restoring purchases, the outcome of a purchase attempt, and whether iCloud synchronization was available or completed. A purchase event may include the App Store product identifier, and a plan-toggle event may include whether all plans were shown. We do not send invoice contents, business details, client details, logos, payment credentials, or generated PDFs to Amplitude.
Amplitude also records sessions and basic application lifecycle events. Its SDK may process a pseudonymous device identifier, product interaction data, purchase-related interaction data, and general device or app metadata for analytics. We have disabled automatic screen-view capture, element-interaction capture, network capture, IDFV collection, carrier collection, IP-derived location properties, remote autocapture configuration, and SDK diagnostics. We do not use Amplitude data for advertising or tracking you across apps or websites.
Analytics is sent to Amplitude's United States data region. See the Amplitude Privacy Notice.
Subscriptions are offered through Apple's StoreKit and are processed by Apple. Apple handles your App Store account, payment method, billing, and refunds. The App receives only the product and subscription status needed to provide access and restore purchases; we do not receive your payment card or bank details. See Apple's Privacy Policy.
Our public website contains product information and legal documents and is hosted on Firebase Hosting. Google may process ordinary request information, such as an IP address and browser or device metadata, to deliver and secure the site. See the Google Privacy Policy.
If you email support, we receive the address you use and any information you choose to include. Please do not send invoice contents, client details, or other confidential information unless it is necessary for your request.
You can view your synchronized business and invoice data in the App and export invoices as PDFs. You may ask us to delete support or analytics information associated with you. Because the App has no separate account and analytics uses a pseudonymous device identifier, we may need additional information to locate a record and may not always be able to connect a record to you. We cannot access or delete content held only in your private iCloud database on your behalf.
Where applicable law requires a legal basis, we process information as necessary to provide requested services, based on our legitimate interests in operating and improving the App, with consent where required, or to comply with legal obligations.
We use Apple for private iCloud synchronization and subscriptions, Amplitude for limited analytics, and Google for public website hosting as described above. We may also disclose information if required by law, to protect rights or safety, or as part of a business reorganization subject to appropriate safeguards. These providers may process information in countries other than your own.
The App is not directed to children who are below the minimum age for consenting to the processing of personal information in their jurisdiction. We do not knowingly request personal information from children.
We use reasonable technical and organizational measures appropriate to the information we handle. No device, transmission method, or storage system can be guaranteed to be completely secure. You are responsible for securing your device and for choosing safe destinations when sharing invoices.
We may update this policy when the App or our practices change. The effective date above identifies the current version.
For privacy questions, access or deletion requests, or other support, email ios-app-support@pm.me.