Privacy Policy
Effective date: July 25, 2026
InvoiceReply ("we," "us," "our") is a service that watches a connected email inbox for replies to invoices, classifies what each reply means, and helps accounts receivable teams track them. This policy explains what data we collect, why, and what we do — and don't do — with it.
The short version: we request read-only access to your connected inbox to find and classify invoice-related replies. We never request permission to send email on your behalf. We never sell your data or share it with third parties for their own marketing purposes. You can revoke our access at any time directly in your Google or Microsoft account settings.
1. Who this applies to
This policy covers the InvoiceReply web application, the connected-inbox polling worker, and any data processed through your account, whether you're the account owner (the vendor using InvoiceReply) or a stakeholder (a customer contact with scoped access to specific invoices via a magic-link login).
2. Data we collect
2.1 Account information
When you sign in, we collect your email address and basic profile information from Google or Microsoft's sign-in flow. Stakeholders sign in via a passwordless magic link sent to their email — we don't collect a password from anyone.
2.2 Connected inbox (Gmail or Outlook)
When you connect a Gmail or Microsoft 365/Outlook inbox, we request read-only access (Gmail's gmail.readonly scope, or Microsoft Graph's Mail.Read scope). With that access, we read:
- Message metadata: sender, recipients, subject line, and timestamps
- Message body content and a short excerpt
- Whether a message has attachments and their file names (we do not read or store attachment contents)
This access currently covers your connected inbox generally, not a narrowed label or folder — we do not yet offer a way to scope access to only certain labels or folders, though this is something we're evaluating. We do not read messages in any other inbox, and we never request or use permission to send, delete, or modify email on your behalf.
2.3 Google Sheets (optional)
If you choose to project your invoice data into a Google Sheet, we use Google's drive.file scope, which only grants access to the single specific spreadsheet you select through Google's file picker — not your broader Google Drive.
2.4 QuickBooks (optional)
If you connect QuickBooks Online, we import invoice, customer, and payment data from your connected company file to match against email threads and improve classification accuracy.
2.5 Payment information
Subscription payments are processed entirely by Stripe. We never see or store your full card number — Stripe shares only what's needed for us to manage your subscription (such as your subscription status and a payment method reference).
2.6 Usage and diagnostic data
We use standard product analytics and error-tracking tools to understand how the product is used and to fix bugs. See "Third parties" below for which providers.
3. How we use your data
- Classification: reply text is sent to an AI provider to classify what a reply means (paid, promise to pay, dispute, wrong recipient, or unclear) and extract relevant details like a promised payment date.
- Semantic search: reply text is also converted into a numeric representation ("embedding") so you can search your reply history by meaning rather than exact keywords.
- Invoice tracking: classified replies update your in-house tracker and, if connected, your external Smartsheet/Sheets/Excel tracker or QuickBooks.
- Digests and notifications: we send scheduled email summaries of activity relevant to you or your stakeholders.
- Pattern detection: we look for patterns across your invoice history, like a customer who repeatedly disputes invoices or is consistently slow to pay, to surface as suggested actions.
We do not use your data to train general-purpose AI or machine learning models, and we do not use it for advertising, including retargeting or interest-based advertising.
4. Third parties we share data with
We share data with the following service providers, only as needed to operate InvoiceReply. None of them are permitted to use your data for their own independent purposes.
- Google / Microsoft — for sign-in and inbox access, per the scopes described above.
- Anthropic and/or OpenAI — process message text to classify replies and generate embeddings for search.
- Intuit (QuickBooks) — if you connect QuickBooks, to import invoice and payment data.
- Postmark — sends transactional email and scheduled digests on our behalf.
- Stripe — processes subscription payments.
- Sentry — error tracking, to help us find and fix bugs.
- PostHog — product analytics.
We may also disclose data if required by law, to protect our rights or the safety of others, or as part of a merger, acquisition, or sale of assets — in which case we'll notify affected users.
5. Data retention and deletion
We retain your data for as long as your account is active. If you'd like your data deleted, contact us at the email below and we'll delete it, other than what we're required to retain for legal or accounting purposes (such as billing records).
You can revoke InvoiceReply's access to your inbox at any time, independent of us, through your Google account (myaccount.google.com/permissions) or Microsoft account (myaccount.microsoft.com) settings.
6. Security
OAuth tokens (the credentials that let us read your inbox) are encrypted at rest using AES-256-GCM. We use industry-standard practices to protect data in transit and at rest, but no system is perfectly secure, and we can't guarantee absolute security.
7. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these rights, contact us at the email below.
8. Children's privacy
InvoiceReply is a business tool and is not directed at, or intended for use by, children. We do not knowingly collect data from anyone under 16.
9. International data transfers
Our infrastructure is hosted in the United States. If you're accessing InvoiceReply from outside the US, your data will be transferred to and processed in the US.
10. Changes to this policy
We may update this policy as the product changes. If we make material changes, we'll update the effective date above and, where required, notify you directly.
11. Contact
Questions about this policy or your data: privacy@invoicereply.com.