PRIVACY

Privacy Policy

Last updated 28 Aug 2026

This policy describes what Mr Invoice actually does with your data, in detail and without euphemism. Where something is less private than you might assume, it says so plainly rather than leaving you to find out. Read the summary first; everything after it is the same information with the specifics attached.

The short version

We are 4AM TECH IO PRIVATE LIMITED. Mr Invoice is free and paid for by ads. Signing in is required to use the app.

Your books are stored on your device. When you are signed in and your business exists on our server, invoices, customers and products are also stored on our server so they follow you between devices. Cloud backup, if you turn it on, sends a copy of nearly everything.

Cloud backup is protected in transit and by access control. It is NOT end-to-end encrypted today, so we could technically read it. We would rather tell you that than imply otherwise.

We do not sell your data, we do not share it with data brokers, and the app contains no analytics or tracking SDK of any kind. The only third party the app itself talks to for advertising is Google AdMob.

Who we are and how to reach us

Mr Invoice is built and operated by 4AM TECH IO PRIVATE LIMITED. For anything about your data, email privacy@mrinvoice.store. For legal notices, legal@mrinvoice.store. You can also open a ticket from Settings · Help and support, which reaches the same people.

What stays on your device

Everything you create is written first to on-device storage: invoices, quotations, proformas, delivery challans, credit and debit notes, customers and vendors, products, stock movements, batches and serial numbers, warehouses, expenses, payments, bank and cash accounts, POS counters, tax rates, units, categories, reminder templates, your business profile and its logo and signature.

If you never sign in to cloud features and never turn on backup, that data does not leave the device. Uninstalling the app or clearing its storage deletes it permanently, and we cannot get it back for you.

Your app-lock PIN and your backup passphrase never leave the device and are never sent to us. We store only a PBKDF2 verifier derived from them, locally. Face ID, Touch ID and fingerprint checks are performed by your operating system; we receive a yes or no and never the biometric itself.

What we store on our servers, and when

Your account. Email address, a hash of your password (never the password), and whatever you choose to put in your profile: name, phone number, country, preferred currency, language and avatar. A phone number is optional and we never send SMS.

Your businesses. Name, legal name, logo, address, tax registration label and number, phone, email, website, currency, country, invoice prefix and numbering, default terms, footer note and signature label. This is created when you finish onboarding or add a business, and is needed for any cloud feature to work at all.

Your documents, while signed in. Once a business exists on our server, creating or editing an invoice, a customer or vendor, or a product writes that record to our server as well as your device. That includes the customer names, addresses, phone numbers, email addresses and tax numbers you enter, and every line of every invoice.

Cloud backup, only if you turn it on. A copy of sixteen sets of records: customers and vendors, products, invoices, expenses, businesses, expense categories, payments, bank accounts, warehouses, units, tax rates, stock movements, reminder templates, product categories, POS counters and saved invoice templates.

Sign-in sessions. For each active session: a device label such as "Pixel 7 · Android 14", the platform, the IP address the session was created from, the browser or app user agent, and the times it was created and last used. Settings · Security lists these and lets you end any of them.

An install identifier. A random identifier the app generates for itself and stores locally. It is not your advertising ID and not a hardware serial. It is sent with the update check so a staged rollout gives the same device the same answer each launch.

Cloud backup is not end-to-end encrypted yet

We want to be exact about this, because an earlier version of this policy claimed otherwise.

Backup data travels over HTTPS and is stored on our server behind authentication, so it is not readable by other users or by someone intercepting the connection. It is not encrypted with a key only you hold, which means our servers, and anyone we have to trust to run them, could in principle read it.

The passphrase screen in Settings prepares for end-to-end encryption and derives a key on your device, but the encryption of the uploaded payload itself is not switched on. Until this policy says otherwise, treat cloud backup as data we hold rather than data we merely store for you. If that is not acceptable for your books, leave backup off; every feature works without it.

Ads

Ads are served by Google AdMob, and they are what makes the app free. AdMob may use your device advertising ID to choose which ads to show and to measure them. You can reset or delete that ID from your device settings at any time, and the app keeps working exactly as before.

If you are in the EEA, the UK or Switzerland, we ask for your consent through Google’s User Messaging Platform before ads load, and you can change your answer at any time from Settings · Privacy choices. Where consent is refused or not given, ads are non-personalised.

We do not pass your invoices, customers, products, figures or email address to AdMob or to any other advertiser. AdMob receives what an ad SDK ordinarily receives, including your IP address, device and app information, and the advertising ID where you have allowed it.

The ad-free subscription and in-app purchases

There is one paid product: Ad-Free, monthly or yearly. It removes ads and nothing else. Every feature of the app is free with or without it.

The purchase itself happens entirely inside Google Play or the App Store. We never see and never receive your card number, bank details, billing address or any other payment credential.

What we do receive and store is the receipt: the store transaction identifier, the product identifier, and when the current period expires. That row is the only thing that decides whether your ads are off. Restoring purchases sends the same kind of receipt again so the row can be rebuilt on a new device.

Apple also notifies our server directly when a subscription renews, lapses, is cancelled or is refunded, so that ad removal starts and stops at the right moment even if you never open the app. Those notifications carry the same transaction and expiry details, signed by Apple.

Shared invoice links

When you use "Copy secure link" to share an invoice, the rendered PDF is uploaded to our server and given a long, unguessable web address, along with the invoice number, the customer name, the currency and the total.

Anyone who has that address can open the invoice without signing in. That is the point of the feature, and it is also its risk: treat the link like the invoice itself and only send it to the person it is for.

The hosted copy is deleted automatically 90 days after it is created. Sharing a PDF through WhatsApp, email or your printer instead hands the file to that app, and what happens next is governed by that app rather than by us.

Support, bug reports and feedback

When you open a support ticket or report a bug we receive the subject and message you write, and any files you attach. Attachments can include screenshots, photos, video and PDFs, so check what is visible in them before sending.

A bug report also includes a small device panel, shown to you on the screen before you send it: platform, app version, operating system version, device model and language. Nothing is collected silently.

If you rate the app inside the app and choose to tell us more, your rating and the note you write are sent to us as a support ticket. They are not published anywhere and are not linked to any public store review.

Notifications and reminders

The bell icon shows a list our server keeps for your account, such as reminders about documents you created. It is fetched when you open the app.

Mr Invoice has no push service. There is no Firebase Cloud Messaging token, and no third party is given a way to wake your device on our behalf. The Android notification permission is requested only so alerts the app raises itself can be displayed. Payment reminders you set up are messages you send yourself, from your own WhatsApp or email.

Permissions, and exactly why each one exists

Camera. Scanning barcodes at the counter and photographing a receipt or a bug. Images stay on your device unless you attach them to a support ticket.

Photos and files. Choosing a business logo or signature, attaching evidence to a report, importing a CSV of customers or products, and saving a PDF or export where you choose.

Notifications. Showing the app’s own alerts. See above.

Biometrics. Unlocking the app, if you switch app lock on. The check happens in your operating system.

USB. Talking to a thermal receipt printer plugged into the phone. Nothing is transmitted anywhere else.

We never ask for location, contacts, SMS, call logs, microphone or health data, and the app contains no code that reads them.

What the app downloads while you use it

Invoice templates, help articles, tutorials, release notes, tax rate catalogues, plan and price lists, ad settings and the update check are fetched from our servers. These are downloads, not uploads: the update check sends your platform, app version, build number and the install identifier described above.

The app also downloads its typefaces from Google Fonts the first time it needs them, and caches them. That request reaches Google and, like any web request, reveals your IP address to them. It carries no account information and happens whether or not you are signed in.

Links that leave the app

The "Who we are" card on Home and in Settings opens 4amtech.com in your browser. It is our company site, but once you are there you are on a normal website and this policy no longer applies. The same is true of the links to our support site, the Google Play and App Store listings, and any address you tap inside a help article.

Sharing to WhatsApp, email or another app hands that app a file and hands you over to their privacy policy for what follows.

Third parties, in full

Google AdMob and Google’s User Messaging Platform, for ads and for the consent prompt.

Google Play Billing and Apple App Store / StoreKit, for the ad-free subscription and for verifying its receipts.

Google Fonts, for the app’s typefaces.

Sentry, which monitors errors on our server so we can fix them. It receives the technical detail of a failed request, with authorisation headers, cookies, tokens, passwords and secrets stripped out before the event leaves our machine.

Hostinger, whose servers our API, database and file storage run on.

That is the complete list. There is no advertising network beside AdMob, no analytics product, no attribution SDK, no social login, no chat widget and no data broker.

Server logs

Our API records ordinary web-server information for each request: the IP address it came from, the user agent, the path, the response status and a request identifier used to trace a single call through the system. This is how we detect abuse and diagnose faults. Request and response bodies are not logged as a matter of course, and sensitive fields are scrubbed from anything sent to our error monitor.

How long we keep things

Ended sign-in sessions and expired one-time codes are deleted automatically 30 days after they end, by a job that runs daily.

Hosted shared-invoice PDFs are deleted 90 days after the link is created.

Purchase receipts are kept while they matter to your entitlement, so that ad removal survives a reinstall.

Everything else is kept while your account exists, because it is your working data and deleting it would delete your books.

Your rights, and how to use them

See and correct. Your profile and every business record are editable in Settings. Your documents are editable where you created them.

Export. Invoices, customers and products can be exported to CSV and PDF from inside the app, without asking us.

Delete. Settings · Delete account removes your account and, with it, the businesses, invoices, customers, products, expenses, payments, backups and uploaded logos held for you. It is a permanent deletion rather than a flag, it asks for your password first, and it cannot be undone. Data already on your device is yours to remove by uninstalling.

End sessions. Settings · Security ends any device’s session, or all of them at once.

Ask us. Email privacy@mrinvoice.store for access, correction, deletion, portability or an objection. We reply within 7 business days, wherever you are. If you are in the EEA or the UK you may also complain to your data protection authority.

Where your data is processed

Our servers are in Europe. If you use Mr Invoice from another country, your data is transferred there and processed there. The stores, ad and font services named above operate globally and move data under their own terms.

Children

Mr Invoice is a tool for running a business and is not directed at children. We do not knowingly collect information from anyone under 13, or under the age of digital consent where you live. If you believe a child has given us information, write to privacy@mrinvoice.store and we will delete it.

Changes to this policy

When something material changes we update the date at the top and describe the change in the app’s release notes. If a change widens what we collect or what we do with it, we will say so prominently rather than quietly reissuing the text.

Contact

4AM TECH IO PRIVATE LIMITED. Privacy: privacy@mrinvoice.store. Legal: legal@mrinvoice.store. Support: Settings · Help and support, or the ticket system inside the app.