Trust

Your invoices, and who can reach them.

A free product should not mean a careless one. Here is how the data you put into Invoice Forever is actually handled, described precisely enough that you can hold us to it.

Everything of substance stays in the EU

The database holding your invoices, clients, saved items and settings runs in the European Union. Files you upload, in practice a business logo, sit on DigitalOcean Spaces in Amsterdam. Website hosting and transactional email use United States providers under Standard Contractual Clauses, and those touch request metadata and your email address rather than your records. Every provider is listed with its location and transfer basis on the subprocessors page.

Isolation is enforced on the server, every request

The common way accounts leak into each other is a UI that filters by user while the backend happily returns anything asked of it. That is not how this is built. Every backend function begins by resolving the caller to a user, and every query is scoped to that user before it touches a record. There is no request shape that returns someone else's invoice, because the filter is not a parameter the client gets to send.

Sensitive operations are additionally rate-limited, so a stolen session cannot be used to hammer the account in bulk.

Encryption and passwords

Traffic is HTTPS end to end. The database and file storage encrypt at rest. Your password is never stored: we keep a salted hash, which can confirm the password you type is right but cannot be turned back into it. If you sign in with Google instead, we never see a password at all.

What deletion actually does

Delete your account from Settings and it happens straight away, without emailing anyone to ask. Your login is removed along with its sessions, then your invoices, clients, saved items, expenses, business details and settings are purged, and uploaded logos are deleted from file storage.

One deliberate exception: donation records survive, because they are financial records with their own retention rules. They are stripped of your name, email and account link first, so what remains is an amount and a date attached to nobody.

Backups age out on their normal rotation rather than being surgically edited, which is standard practice and worth stating plainly rather than implying that deletion reaches back through every historical snapshot instantly.

Shared invoice links

Sending an invoice generates a link containing a long random token. Anyone with the link can see that invoice, which is exactly what you want when you send it to a client who should not need an account to pay you. The token is not guessable and grants access to one invoice, never to your account or anything else in it.

You can always take your data out

Settings has an Export Data button that downloads everything in one file. It is not a support request, a paid feature or a queue you wait in. An export you can run at any moment is the only real guarantee against a service going bad, so it stays free and instant.

Nothing watching you

No advertising networks, no tracking pixels, no session recording, no chat widget, no third-party scripts of any kind. Analytics are anonymous and cookieless, which is why the site has no consent banner. The full list of what is stored in your browser is on the cookies page, and it is four entries long.

What we are not claiming

Being straight about the limits matters more than a page of badges. Invoice Forever is not SOC 2 or ISO 27001 certified, because those audits cost more than this project spends in a year. Your invoices are not end-to-end encrypted, since the server has to render PDFs and build e-invoice XML from their contents. There is no formal uptime guarantee, and the service is provided as-is.

If any of that is a blocker for your situation, it is better that you know it now than discover it later.

Reporting a vulnerability

Email hello@invoiceforever.com with enough detail to reproduce the issue. It reaches a person, not a ticket queue. Please give us a reasonable window to fix it before publishing. We have no bug bounty budget, but we will credit you in the changelog if you would like to be.

Common questions

Where is my invoice data stored?

In the European Union. The application database runs on Convex in the EU, and files you upload are stored on DigitalOcean Spaces in Amsterdam. Your invoices and client records do not leave the EEA.

Is my data encrypted?

Yes. Everything travels over HTTPS, and the database and file storage both encrypt data at rest. Passwords are never stored, only a salted hash that cannot be reversed back into your password.

Can anyone at Invoice Forever read my invoices?

Technically an operator with production database access could, which is true of every hosted service that does not end-to-end encrypt. We do not, and there is exactly one person with that access. Nothing is mined, sold, used for advertising or used to train models.

What happens when I delete my account?

Deletion is immediate and self-serve from Settings. Your login, invoices, clients, saved items, expenses, business details and settings are purged, and uploaded logos are removed from file storage. Donation records are kept for accounting but stripped of your name, email and account link.

Is a shared invoice link public?

Anyone holding the link can view that one invoice, which is the point of sending it to a client. The token is long and random, so links cannot be guessed, and it grants access to that single invoice and nothing else in your account.

Related

Privacy policy · Cookies and local storage · Subprocessors · Data processing agreement

Invoicing that keeps your data yours.

Free forever, exportable any time, deletable in one click.

Create a free account