Legal & Compliance

Privacy Policy and Terms of Service governing the use of our AI-powered automated receipt extraction platform, operated by INVISCID LABS LTD.

Last Updated: October 2026
Privacy Policy
How INVISCID LABS LTD collects, protects, and processes your data in compliance with UK GDPR.

Effective Date: 06/07/2026

Last Updated: 08/10/2026

1. Data Collection and Ingestion

The Platform collects and processes specific categories of data to provide automated financial data extraction and secure user sessions. This data includes:

  • Account Credentials:Usernames, email addresses, and securely cryptographically hashed passwords.
  • Organization & Role Data:Organization affiliations, workspace names, and hierarchical role assignments (e.g., Owner, Admin, Member) to enforce strict access controls and billing constraints.
  • Authentication Telemetry:IP addresses and secure identifiers associated with session security and rate-limiting.
  • Usage and Processing Metrics:Scan counts, scan limits, base plan limits, upload file type and size, processing job counts, extraction success or failure status, and related service logs used to enforce plan limits, operate the scanner, and report progress.
  • User Content:Uploaded receipt images and PDF documents (up to 50MB per file).
  • Derived Financial Data:Text strings and metadata extracted by AI, including merchant names, transaction totals, currency markers, timestamps, payment methods, and line-item details required for Excel generation.

2. Legal Basis for Processing

Under the UK GDPR, we must have a valid legal basis to process your data. We rely on the following:

  • Contractual Necessity:To provide the core receipt scanning service, process your payments, and manage your account and organization.
  • Legitimate Interest:To maintain the security of our platform (e.g., bot protection, rate limiting) and analyze basic website traffic to improve performance.
  • Consent:Specifically when you explicitly choose to accept an invitation to join a multi-user Organization, thereby consenting to share your basic profile data (such as name and email) and workspace activity with the administrators of that organization.

3. Data Visibility & Third-Party Sharing

To deliver a highly available, secure, and automated ecosystem, we utilize essential third-party services. These processors are strictly bound by data protection agreements:

  • Cloudflare (Turnstile, R2 Storage & Analytics):Utilized for advanced bot protection, secure object storage, and basic, privacy-first website traffic analytics. Cloudflare R2 acts as the primary encrypted vault for your uploaded receipt files. Cloudflare Turnstile runs in invisible mode, so it may verify your browser in the background without any interaction from you. Its use is subject to Cloudflare's Turnstile Privacy Addendum.
  • Google (Gemini API & Site Services):The Gemini API receives uploaded receipt images exclusively to parse and analyze financial data into schema formats. We also utilize Google site verification to monitor domain health.
  • Stripe:Acts as our complete external checkout, subscription management, and payment processor. All payment data loops directly to their environment.
  • Resend:Processes email addresses and delivers transactional loops, including account verification links.

Business Transfers

If INVISCID LABS LTD is involved in a merger, acquisition, or asset sale, your personal data may be transferred. We will provide notice before your personal data is transferred and becomes subject to a different Privacy Policy.

Internal Organization Visibility

If your account is associated with a multi-user Organization, we enforce strict data siloing between members for privacy. However, you acknowledge that Organization Owners and Administrators retain administrative oversight. They can view team member lists (including names and emails) and access high-level organization usage metrics to manage billing and enforce fair use.

4. Communications and Support

  • Customer Support:When you contact us for support via email, we retain the contents of your emails, your email address, and our responses in our secure email servers to assist you and improve our Service.
  • No Marketing Emails:We respect your inbox. We strictly use your email address for transactional and operational purposes (e.g., password resets, subscription updates). We do not send promotional or marketing emails.

5. Authentication & Session Management

The Platform implements modern, secure passwordless and federated identity protocols to guarantee account integrity:

  • Google OAuth:Processes unique identity tokens and profile email addresses supplied directly by Google to authorize the active session without exposing third-party passwords.
  • Passkeys:Securely processes public keys and hardware-verified profile tokens provided by your device OS.
  • Strictly Necessary Cookies:Employs secure state cookies managed by Better Auth solely to handle cryptographic login states and defend against CSRF attacks. We do not use tracking or advertising cookies.

6. Data Location and Secure Access

We prioritize strict regional privacy governance. Our core web application servers are hosted within the United Kingdom at data center facilities in Manchester via Hostinger UK. Our primary PostgreSQL database—which holds your account structures, metadata, and extracted receipt data—is hosted within the United Kingdom in London via Neon (on AWS infrastructure).

  • Encrypted Storage:Encrypted source files are routed through Cloudflare's distributed object storage network (Cloudflare R2), meaning your uploaded images may be temporarily cached in regions optimized for performance based on your physical location.
  • Secure Temporary Access:Your uploaded receipt files are never made publicly accessible on the internet. When you request to view a receipt, the Platform generates a secure, cryptographically signed URL that automatically expires after approximately 5 minutes, ensuring your financial documents cannot be accessed indefinitely.
  • International Processing:While our core databases and servers are strictly UK-based, some trusted sub-processors (such as Google API services and Stripe) may route or process data internationally. We ensure these transfers are legally safeguarded under UK GDPR requirements.

7. Financial and Payment Data Protection

We enforce strict data isolation regarding financial processing. Our platform does not collect, process, or store raw credit card numbers, bank account numbers, or sort codes on our servers. Checkout, recurring subscriptions, billing cycles, plan tiers, invoice events, and payment authorization are handled by Stripe. We may retain limited billing metadata such as Stripe customer IDs, subscription status, billing-cycle dates, plan tier, and transaction references needed to manage access, refunds, and support.

8. Data Ownership, Sovereignty, and AI Training

All uploaded receipt files and derived metadata belong exclusively to you. We guarantee your uploaded data remains confidential: receipts and text are processed strictly through the Google Gemini API. While Google may temporarily retain payloads for abuse monitoring, your data is never used to train, fine-tune, or iterate proprietary or third-party AI models.

9. Data Retention & Account Deletion

The Platform functions purely as an automated data processing pipeline, not a permanent archival vault. However, because we operate a multi-tenant workspace model, data ownership rules apply.

  • Organization Data Ownership: Receipts, documents, and extracted metadata uploaded to a shared Organization workspace are considered the property of that Organization. If you delete your individual user account, any receipts you uploaded to a shared workspace will be anonymized (unlinked from your identity) but will be retained by the Organization for their accounting purposes.
  • Organization Erasure: If an Organization is deleted (or if the sole owner deletes their account), all active records, uploaded files, and databases associated with that Organization are immediately and irrevocably erased from our production servers and Cloudflare R2 vaults.
  • Fraud Prevention Retention: Upon account deletion, we retain your email address on a secure, internal blocklist. We rely on our Legitimate Interest to do this strictly to enforce our Terms of Service, prevent trial-abuse, and block deleted accounts from re-registering on the Platform.

All parsed metadata tables and Cloudflare R2 bucket storage are automatically wiped after 500 days, regardless of account status.

10. Your Privacy Rights

Under the UK General Data Protection Regulation (UK GDPR), you possess extensive rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request we correct inaccurate or incomplete info.
  • Right to Erasure: Request the complete deletion of your personal data.
  • Right to Restrict: Request we pause the processing of your data.
  • Right to Object: Object to our processing of your data entirely.
  • Right to Portability: Request to export your derived receipt data (e.g., Excel).

11. Users Under 16 Years of Age

The Service is intended strictly for users who are 16 years of age (or the applicable legal age of digital consent in your jurisdiction) or older. We do not knowingly collect personal identifiable information from anyone under this required age. If we become aware that we have collected such data, we will immediately execute our erasure protocols to remove it from our servers.

12. Changes to this Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top. For significant changes, we may also notify you via email or a prominent notice within the application.

Depending on the nature of the changes and applicable laws, we may require you to explicitly consent to the updated Privacy Policy before you can continue using the service.

13. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us at:

  • Entity: Inviscid Labs Ltd
  • Email: privacy@inviscidacquity.com