Privacy Policy
Last updated July 18, 2026
Invorest provides free invoicing and accounts-receivable tools, built by the team behind Duefy. We've designed the site to need as little of your data as possible. This page explains, in plain terms, what is processed, why, and for how long.
No account, no tracking cookies
You don't sign up or log in to use any tool, and we don't set advertising or cross-site tracking cookies. There are no third-party trackers or ad networks on the site.
Browser-based tools and local storage
The generators and calculators (invoice, quote, receipt, credit note, statement, timesheet, payment plan, and the calculators) normally process the details you enter in your browser. Calculations and browser-generated PDF/CSV files do not need to be uploaded to Invorest. To make tools convenient, recent drafts, business details, and display preferences may be saved in your browser's local storage. A tool's Reset action clears its draft; clearing site data in your browser clears all local storage.
AI tools
The AI tools (AI contract, quote/SOW, reminder writer, collection-risk predictor and excuse translator) work differently because the text has to be generated for you. When you click "Generate", the details you entered are sent to our server and on to our AI provider (Anthropic) to produce the result. Our application does not intentionally write the prompt or generated result to its analytics or feedback files, but Anthropic processes the request under its own terms and data practices. Please avoid entering sensitive personal data that the document does not need.
Downloading and sharing a document
Downloads are created locally in your browser. When you use a Share or Email action, Invorest hands the document or a prepared message to your device's Web Share interface or local email app; it is not sent through the Invorest server. The app and delivery service you choose then process it under their own privacy practices.
Feedback
When you use the Feedback button, we store your message, the page it came from, the time, and the email address you optionally provide. We retain feedback for up to 12 months so the team can investigate and respond. If feedback notifications are configured, the message, page, and optional address are forwarded to the team's inbox through our notification provider, Resend. Providing an email means we may reply about that feedback; it is not consent to general marketing email. A daily retention job removes expired feedback files.
Privacy-friendly analytics
We use lightweight, first-party analytics to understand which tools are useful. We record an event name, page path, referrer hostname, a campaign label for explicitly marked Duefy links, and the controlled Auto/A4/Letter value when you change the PDF paper preference. We do not use analytics cookies. Paper-preference analytics records do not retain a referrer or visitor identifier. When a server secret is configured, page and funnel events also contain a pseudonymous identifier derived from the request IP address and browser user agent; it changes each UTC day and is used only to de-duplicate daily events. When no secret is configured, no visitor identifier is stored in the analytics event files. Analytics files are retained for up to 90 days and expired files are removed by a daily retention job.
Abuse-prevention counters
API endpoints use rolling request counters to control automated abuse and AI cost. A network address is converted to a keyed, installation-local HMAC before it is used as a counter key; raw addresses are not written to these counter files. Expired entries stop counting immediately, and inactive counter files are purged both opportunistically and by the daily retention job. These counters are not used for analytics or advertising.
Operational server logs
Like most websites, our Nginx server writes operational access and error logs. These can include an IP address, request time, requested URL, response status, referrer, and browser user agent. They are used to operate, diagnose, and protect the service, not for advertising. The current server rotates logs daily and keeps 10 rotations; incident records may be retained longer when reasonably needed to investigate abuse or a service failure.
Links to Duefy
Explicit Duefy recommendation links carry utm_source=invorest,
utm_medium=tool, and a page-specific campaign label so we can attribute the visit.
If you follow one, Duefy's own privacy policy applies there.
Sale and advertising
We do not sell personal data or share it with advertising networks. The service providers described above receive only the data needed for the feature you choose or for operating the site.
Access, deletion, and contact
To ask a privacy question or request deletion of identifiable feedback, use the Feedback button at the bottom of any page, include “privacy request,” and give us enough detail (such as the submitted email, date, and page) to locate it. Daily analytics identifiers are deliberately pseudonymous and cannot normally be connected back to a person for an access or deletion request. You can remove browser-stored data at any time by resetting the tool or clearing Invorest's site data. If this policy changes, we will update the date above.