Privacy Policy and Terms of Service governing the use of our AI-powered automated receipt extraction platform, operated by INVISCID LABS LTD.
Effective Date: 06/07/2026
Last Updated: 08/10/2026
The Platform collects and processes specific categories of data to provide automated financial data extraction and secure user sessions. This data includes:
Under the UK GDPR, we must have a valid legal basis to process your data. We rely on the following:
To deliver a highly available, secure, and automated ecosystem, we utilize essential third-party services. These processors are strictly bound by data protection agreements:
If INVISCID LABS LTD is involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will provide notice before your personal data is transferred and becomes subject to a different Privacy Policy.
If your account is associated with a multi-user Organization, we enforce strict data siloing between members for privacy. However, you acknowledge that Organization Owners and Administrators retain administrative oversight. They can view team member lists (including names and emails) and access high-level organization usage metrics to manage billing and enforce fair use.
The Platform implements modern, secure passwordless and federated identity protocols to guarantee account integrity:
We prioritize strict regional privacy governance. Our core web application servers are hosted within the United Kingdom at data center facilities in Manchester via Hostinger UK. Our primary PostgreSQL database—which holds your account structures, metadata, and extracted receipt data—is hosted within the United Kingdom in London via Neon (on AWS infrastructure).
We enforce strict data isolation regarding financial processing. Our platform does not collect, process, or store raw credit card numbers, bank account numbers, or sort codes on our servers. Checkout, recurring subscriptions, billing cycles, plan tiers, invoice events, and payment authorization are handled by Stripe. We may retain limited billing metadata such as Stripe customer IDs, subscription status, billing-cycle dates, plan tier, and transaction references needed to manage access, refunds, and support.
All uploaded receipt files and derived metadata belong exclusively to you. We guarantee your uploaded data remains confidential: receipts and text are processed strictly through the Google Gemini API. While Google may temporarily retain payloads for abuse monitoring, your data is never used to train, fine-tune, or iterate proprietary or third-party AI models.
The Platform functions purely as an automated data processing pipeline, not a permanent archival vault. However, because we operate a multi-tenant workspace model, data ownership rules apply.
All parsed metadata tables and Cloudflare R2 bucket storage are automatically wiped after 500 days, regardless of account status.
Under the UK General Data Protection Regulation (UK GDPR), you possess extensive rights regarding your personal data:
The Service is intended strictly for users who are 16 years of age (or the applicable legal age of digital consent in your jurisdiction) or older. We do not knowingly collect personal identifiable information from anyone under this required age. If we become aware that we have collected such data, we will immediately execute our erasure protocols to remove it from our servers.
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top. For significant changes, we may also notify you via email or a prominent notice within the application.
Depending on the nature of the changes and applicable laws, we may require you to explicitly consent to the updated Privacy Policy before you can continue using the service.
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at: