SmartInvoice

Privacy Policy

Last Updated: November 24, 2025

SmartInvoice ("we", "us", or "our") provides tools for extracting, generating, and managing invoices. This Privacy Policy explains how we collect, use, access, and protect your information when you use our application and related services (the "Service").

By using SmartInvoice, you agree to the practices described in this Privacy Policy.

1. Information We Collect

1.1. Google Account Information

If you sign in with Google, we collect basic profile data:

  • Email address
  • Display name

Used solely for authentication and linking your account to your workspace.

1.2. Gmail Data Access

SmartInvoice requires access to your Gmail inbox for the purpose of reading certain emails that contain invoices and extracting attachments.

This includes:

What Gmail data we access

  • Email metadata (sender, subject, timestamp)
  • Email body (for invoice parsing, only when necessary)
  • Attachments (PDFs, images, or files that appear to be invoices)

Why we access Gmail

We use this data only to:

  • Automatically detect incoming invoice emails
  • Extract attachments that are invoices
  • Parse invoice data and add it to your workspace
  • Reduce manual data entry
  • Improve accuracy of invoice processing

What Gmail data we do NOT access or store

We do not:

  • Read emails unrelated to invoices
  • Access or store the entire inbox
  • Use Gmail data for advertising or profiling
  • Share Gmail data with third parties
  • Analyze email content for purposes other than invoice extraction

Limited, purpose-bound access

SmartInvoice uses Gmail API with restricted scopes and accesses only the messages necessary to perform invoice extraction. All access is permission-based, transparent, and revocable at any time by disconnecting your Google account.

1.3. User-Generated Data

We collect and store:

  • Invoices created or uploaded by you
  • Parsed data extracted from invoice attachments
  • Customer information you enter
  • Files you upload manually

1.4. Automatically Collected Data

  • Device information (browser type, OS)
  • Log data (IP address, timestamps, errors)
  • Usage metrics (which features you use)

2. How We Use Your Information

We use your information only for:

  • Authenticating your account
  • Extracting invoice data from Gmail messages
  • Generating, storing, and managing invoices
  • Improving SmartInvoice features and accuracy
  • Providing customer support
  • Ensuring platform security

We never sell, rent, or trade your data with third parties.

3. Sharing of Information

We share data only with:

3.1. Service Providers

Such as:

  • Google Cloud Platform (hosting, storage, security)
  • Firebase Authentication (login)
  • Cloud Run and App Engine (running our backend)

These providers process data only on our behalf.

3.2. Legal Requirements

Only if required by law, court order, or government authority.

We never share Gmail contents or user data with advertisers or external marketers.

4. Data Storage & Retention

4.1. Storage

Your data—including invoice attachments extracted from Gmail—is stored securely on Google Cloud.

4.2. Retention

We retain data only as long as your account is active.

If you delete your account, all personal data, extracted emails, and stored attachments are deleted within 30 days, unless legally required to retain them.

5. Data Security

We protect your data using industry-standard security measures:

  • HTTPS/TLS encrypted connections
  • Firewalled Google Cloud infrastructure
  • Strict IAM access controls
  • Regular audits and monitoring
  • Encryption of stored files and message metadata

No method is 100% secure, but we take extensive precautions.

6. Your Rights

You may:

  • Access your stored data
  • Request deletion of your account
  • Disconnect Gmail access at any time
  • Correct inaccurate information
  • Request an export of your stored invoice data

Contact info@smartinvoiceai.no to make such requests.

7. Children's Privacy

SmartInvoice is not intended for use by individuals under 16.

We do not knowingly collect data from children.

8. International Data Transfers

Data may be processed or stored in regions operated by Google Cloud, including the EU and US, using GDPR-compliant infrastructure.

9. Changes to This Policy

We may update this Privacy Policy as needed. We will notify users of significant changes by email or in-app.

10. Contact Us

For questions or requests related to this Privacy Policy, contact:

Email: info@smartinvoiceai.no