Privacy Policy
Last updated: 11 October 2026
An honest note about this document
This document is written in plain English to describe, as accurately as we can, how Charming Invoices actually works today. It has not yet been reviewed by a lawyer, and any fact we have not yet confirmed is clearly marked as a placeholder. If anything here contradicts how the product behaves, tell us and we will fix one or the other.
In short: we store what you enter so you can invoice your clients, we send emails only when you or your settings ask us to, we do not sell data or run ad trackers, and a few optional features send data to the providers listed below. The details follow.
1. Who we are and what this covers
Charming Invoices (“Charming”, “we”, “us”) is an invoicing web application for freelancers and small businesses, available at charminginvoices.com. It is operated by Charming Invoices, a subsidiary of PhraseMine, 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA.
This policy covers the website, the web application, the emails it sends, and the public invoice links it generates. It does not cover other websites you reach from ours, or the services of the providers listed under “Sub-processors”, which have their own policies.
2. Your data and your clients' data
This policy is about two different groups of people, and our role differs for each:
- You, the account holder (and teammates you invite). We decide how your account data is used, as described in this policy.
- Your clients — the people and companies whose names, email addresses and other details you enter so you can invoice them. For that data, you are in charge: you decide what to store, who to invoice and who to email. We process it only on your instructions, to provide the service to you (in privacy-law terms, you are the controller and we act as your processor). We do not market to your clients, profile them, sell their data, or use it for anything other than producing, delivering and tracking the invoices you create.
If you are one of our users’ clients and have a question about an invoice or email you received, please contact the business that sent it first: they control that data. You can also contact us at [email protected] and we will help or pass your request on.
3. What we collect
Account information
Your name, email address, and whether that address has been verified. You can sign in with an email and password or with a single-use emailed sign-in link (“magic link”). We store passwords only as a one-way hash, never the password itself, and store magic-link tokens only in hashed form. We do not currently offer sign-in through Google, GitHub or any other third-party account.
Sessions
When you sign in we create a session record that includes the IP address and browser user-agent string of the device that signed in, plus an expiry time. This keeps you signed in and helps us investigate an account that looks compromised.
The data you enter
The app exists to store what you put into it, including:
- Business profiles: business name, address, email, phone, tax ID, bank or payment details text, a payment link, invoice numbering, default terms and notes, email templates and reminder settings, and invoice design settings.
- Clients: name, email address, postal address, phone and free-text notes.
- Invoices: line items, amounts, taxes, dates, notes and terms, payments you record against them, and a snapshot of the client and business details at the time the invoice was sent.
- Recurring invoice schedules, saved line items and saved text snippets.
- Teammate invitations: the invitee’s email address and role, and the resulting membership.
Files
- Logos and letterheads you upload are re-encoded as image files and stored on our server. They are served from a public web address so that they can appear on your invoices; anyone who has that address can view the image.
- Invoice PDFs are generated when you send an invoice and kept in private storage outside the public web folder. They are available only to signed-in members of your business and to anyone holding that invoice’s public link.
Invoice activity
Each invoice has an activity timeline: when it was sent or re-sent (including the recipient address), viewed, paid, voided, when payments were recorded or removed, and when reminders went out. See “View tracking” and “Reminder emails” below.
Billing information
Paid plans are bought through Stripe. You enter card details on Stripe’s own checkout pages; we never see or store your card number. We store the result: your Stripe customer and subscription identifiers, which plan you hold, the subscription status and billing interval, and when the current period ends.
What we do not collect
We do not use advertising cookies or third-party analytics or tracking scripts, and we do not buy data about you from data brokers.
4. How and why we use it
- To provide the service you asked for — storing your businesses, clients and invoices, rendering PDFs, generating public invoice links, sending the emails described below, and creating recurring invoice drafts on schedule.
- To run your account — sign-in, email verification, password resets, magic links, teammate invitations and remembering which business you are working in.
- To take payment for paid plans through Stripe and to know which features your plan includes.
- To keep the service secure and working — rate limiting, abuse prevention, diagnosing errors and keeping backups.
- To meet legal obligations, such as accounting and tax rules for the payments we receive.
We do not sell your data or your clients’ data, rent it, or share it with anyone for their own marketing. We do not use your data, your clients’ data, your invoices or anything you send to our AI features to train AI models on our side.
5. AI features
Charming has two optional AI-assisted features. Both send data to a third-party AI model through OpenRouter, a service that routes the request to the company hosting the model. By default that is a Google Gemini model; we may change the model from time to time. OpenRouter and the model provider process the request under their own terms and privacy policies. We cannot verify or guarantee what they retain or how they use it beyond those terms, so please do not include anything you would not want a third party to receive.
AI invoice drafting (paid plans)
You type a plain-English description of your work and the model suggests line items (and, if you ask, a due date, terms and a note). Only the text you typed is sent, at the moment you ask for a draft. Your stored clients, invoices and business details are not sent. We do not store your description or the model’s answer on our side beyond what you choose to save on the invoice. Our logs record that a draft was requested (your user and business IDs, the length of the description, token counts and whether it succeeded), not its content.
Brand import
The brand importer suggests invoice designs that match your brand. You can give it any combination of a website address, images you drop in (a logo, screenshots, a business card, an old invoice), and the logo you have already uploaded.
- Images you drop in are analysed on our server for colours. In addition, up to three of them are downscaled (to at most 768 pixels on the longest side), re-encoded as JPEG, and sent to the AI model, which is asked only for brand cues: colours, typography style, overall feel, whether a logo is visible, and which of our designs fit. Any text in the images (including names or amounts on an old invoice) is sent along with the image, even though the model is instructed to ignore it. We do not keep the images after the import, except that a logo you drop in is added to your business.
- A website address makes our server fetch that public page (and the images and stylesheets it references) once, identifying itself as the Charming brand importer, to read colours, fonts and a logo. Website content is not sent to the AI model.
- Your already-uploaded logo is analysed on our server only and is not sent to the AI model.
The AI look is skipped automatically if it is unavailable or the daily allowance is used up. If you prefer that no images go to an AI provider at all, don’t drop images into the importer: upload your logo in your business settings instead, and use the importer with a website address or your stored logo only.
6. View tracking of public invoice links
When you send or share an invoice, it gets a public link containing a long random token, so your client can view and download it without an account. These pages are marked so search engines do not index them. Anyone who has the link can open that invoice, so treat it like the invoice itself. Drafts and voided invoices cannot be opened through a public link.
So that you can see whether your client has opened an invoice, we record views of that page. For each invoice we store only:
- when it was first viewed;
- when it was last viewed;
- how many times it has been viewed; and
- a “viewed” entry on the invoice’s activity timeline, with the time.
We do not store the viewer’s IP address, browser user-agent, location or any identifier with these view records. The browser’s user-agent is read at the moment of the visit only to skip obvious bots and link-preview tools. Visits by signed-in members of the business that issued the invoice are not counted, and repeat visits within 30 minutes count as one. Some email security scanners open links automatically and may still be counted, so views are a helpful signal rather than proof that a person read the invoice. View information is visible to members of the issuing business.
Like any website, our web server may separately record the visit in its access logs (see “Logs”).
7. Reminder emails and other emails we send
All email is delivered through Resend from our sending address at mail.charminginvoices.com. Emails sent for a business show that business’s name as the sender name and, when the business has an email address set, replies go to that business, not to us.
Invoice emails
When you send or re-send an invoice, we email it to the client address on the invoice, with the invoice PDF attached and a link to view it online. If you choose, a copy goes to you.
Payment reminder emails to your clients
Reminders are off by default. A business owner or admin can turn them on for a business and choose the schedule: before the due date, on the due date, and/or repeated after it is overdue, up to a set number of times. Reminders go only to the client email on an unpaid, sent invoice, contain a link to the invoice (no attachment), and stop automatically once the invoice is paid or voided. We record each reminder sent (which reminder, the recipient address and the time) so the same reminder is never sent twice and so it appears on the invoice timeline.
These emails are sent on the business’s behalf. The business that turns them on is responsible for having a legitimate reason to email its clients about what they owe.
Stopping reminders. Every reminder email contains a “stop payment reminders” link, and supports the one-click unsubscribe button that some email apps show. Following the link and confirming stops all automatic payment reminders from that business to you, for every invoice it has issued you, not just the one in the email. No account or sign-in is needed. We record when you opted out (on your client record and on the invoice’s activity timeline) so the business can see why reminders stopped. Opting out does not cancel what you owe and does not stop emails the business sends itself, such as a new invoice; only the business can turn reminders back on, and it should do so only with your agreement. You can also reply to the email or contact the business that sent it, or email us at [email protected] and we will help.
Emails to you and your team
- Account emails: verification, password reset and magic sign-in links.
- Teammate invitations, sent to the address you enter.
- A digest to every member of a business when new recurring invoice drafts are ready to review. Recurring invoices are created as drafts; they are never sent to your clients until someone on your team sends them.
We do not send marketing emails to your clients.
8. Sub-processors
We rely on a short list of service providers. Each receives only what it needs for its job:
- Hetzner — hosts the server that runs the application, its database and stored files, in a data centre in Nuremberg, Germany.
- Cloudflare (R2 storage) — stores our off-site backups of the database and stored files.
- Resend — delivers every email the app sends, so it receives recipient addresses and email content, including invoice PDF attachments.
- Stripe — processes payments for our paid plans. It receives your email address and the payment details you enter on its pages.
- OpenRouter, and through it the AI model provider serving the request (by default Google) — only when you use an AI feature, as described in “AI features”.
- Sentry — error monitoring. When something breaks on our server, in a scheduled job or in your browser, a technical error report (the error type and a scrubbed message, stack trace, page address without its query string, and browser, device and runtime type) is sent to Sentry. Our configuration does not attach IP addresses, cookies, request bodies, query strings, most request headers or your account identity, and redacts email addresses, invoice-link tokens and other credentials before a report leaves. Browser reports go directly from your browser to Sentry, so Sentry necessarily sees the connection, as any website you contact does. We only send errors: no session recordings or browsing analytics. Sentry stores reports in [PLACEHOLDER: Sentry data region (US or EU)] and keeps them under its own retention schedule.
Our website fonts are served from our own server, so pages do not load fonts from Google or other font services. If this list changes in a way that matters, we will update this page.
10. Logs
Our web server keeps standard access logs (IP address, time, requested address, browser user-agent), which can include public invoice link addresses. The application writes operational logs to help us find and fix problems. We deliberately keep these lean: errors are logged by type and status code rather than with their full contents, and we avoid logging email bodies, AI prompts, sign-in links or invoice contents. Log lines may contain internal IDs (for example of a user, business or invoice). Error reports also go to our error-monitoring provider, Sentry, as described under “Sub-processors”.
For rate limiting, IP addresses and user IDs are counted in memory for short periods; they are not written to the database. Server and application logs are kept for up to 30 days and then deleted.
11. Retention and deletion
We keep your account data for as long as your account exists, because an invoicing record that disappears is not much use. What happens when you remove things today:
- Draft invoices can be deleted, and are removed from the database.
- Sent, paid and voided invoices cannot be deleted in the app, because they are financial records; you can void an invoice instead.
- Clients and businesses are archived, not deleted, when you remove them in the app. Archived data stays in the database because your invoices refer to it.
- Your account: there is not yet a self-service way to delete your account. Email [email protected] from the address on your account and we will delete your account and the businesses, clients, invoices and files that belong only to you. If you have an active Pro subscription, cancel it first (or ask us to).
- Uploaded files you replace may remain in storage until cleaned up; you can ask us to remove them.
- Backups: we take daily backups of the database and stored files and keep them for 7 days, so deleted data can remain in backups for up to about a week.
- Payment records for plans you bought are kept by Stripe under its own rules, and we may keep records needed for tax and accounting purposes after your account is deleted.
- Sessions and sign-in tokens expire and stop working; expired records may remain in the database until they are cleaned up or your account is deleted.
- Emails that have been delivered cannot be recalled; Resend keeps delivery records under its own retention schedule.
12. Security
We take reasonable, proportionate measures for a small service, including:
- HTTPS for all traffic.
- Passwords stored only as hashes; magic-link tokens stored only as hashes.
- Rate limits on sign-in, sign-up, password reset, magic-link and email-sending actions.
- Access to every business’s data checked on the server for each request, according to the user’s role in that business.
- The database is not reachable from the internet.
- Invoice PDFs kept outside the public web folder; public invoice links use long random tokens and pages tell browsers not to pass the link on to other sites.
- Uploaded images re-encoded before they are stored or served.
No system is perfectly secure, and we do not claim any security certification. If we become aware of a breach affecting your data, we will tell you what happened, what was affected and what we are doing about it, as required by applicable law.
13. International transfers
Your account data, invoices and files are stored on our server in Nuremberg, Germany, in the European Union. Charming is operated by a company based in the United States, and several of our sub-processors (including Resend, OpenRouter and the AI model providers it routes to, Stripe and Sentry) may process data outside the EU, including in the United States. When data is transferred, we rely on the transfer terms those providers offer. Data protection laws in those countries may differ from the laws where you live.
14. Your rights and choices
Depending on where you live, privacy laws may give you rights over your personal data, such as the right to:
- access a copy of it;
- have it corrected;
- have it deleted;
- receive it in a portable format;
- object to or restrict certain uses of it; and
- complain to your local data protection authority.
We will honour these requests for any account holder who asks, whatever the law where they live, subject to the exceptions above (such as records we must keep). Most of your data can be edited directly in the app, and invoices can be exported as CSV. For anything else, email [email protected] from the address on your account. We aim to respond within 30 days and may need to confirm your identity first.
If you are a client of one of our users, please send requests about your data to that business first, since they decide how it is used; we will support them in responding.
15. Children
Charming Invoices is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, email us and we will remove it.
16. Changes to this policy
When this policy changes we update the “Last updated” date at the top. For changes that materially affect how we handle your data, we will email account holders before the change takes effect.
17. Contact
Privacy questions, data requests or corrections to this page: [email protected]. Postal address: 131 Continental Dr, Suite 305, Newark, Delaware 19713, USA.
See also our Terms of Service.