Security Policy

Last Updated: [LAST UPDATED]

Security at a Glance

InvoiceMaker is built with security and privacy as core principles:

1. Data Storage and Protection

Local-Only Storage

Where Your Data Lives:

What This Means for You: If you delete the app, all your data is permanently removed from your device. There are no cloud backups. We recommend exporting important invoices as PDFs for your records.

1.1 iOS Device Security

Your data benefits from Apple's industry-leading device security:

1.2 PDF Export Security

When you export invoices as PDF files:

2. Network Security

2.1 Minimal Network Access

InvoiceMaker has limited network usage:

2.2 Third-Party Service Security

Google AdMob (Free Users Only)

Apple StoreKit (All Users)

3. Permissions and Access

3.1 Required Permissions

InvoiceMaker requests minimal permissions:

What We DON'T Request: Camera, microphone, location, photos, calendars, reminders, Bluetooth, local network, or any other sensitive permissions.

3.2 Data Access by Third Parties

InvoiceMaker does not share your invoice, client, or business data with any third parties.

The only data shared with third parties is:

Your business data (invoices, clients, estimates, financial information) remains 100% local and private.

4. Security Best Practices

4.1 Recommendations for Users

To maximize the security of your data:

  1. Enable Device Passcode: Use a strong passcode, Face ID, or Touch ID to lock your device
  2. Keep iOS Updated: Install security updates promptly (Settings → General → Software Update)
  3. Enable Find My iPhone: Allows remote wipe if device is lost or stolen
  4. Export Backups: Regularly export important invoices as PDFs and store securely (iCloud, encrypted USB drive)
  5. Password-Protect PDFs: Use Files app or third-party tools to encrypt sensitive PDFs before sharing
  6. Review Sharing: When sharing invoices via email/AirDrop, verify recipient before sending
  7. Secure Email: Use secure email providers when emailing invoices containing financial data

4.2 What We Do to Protect You

5. Data Retention and Deletion

5.1 How Long We Keep Data

On Your Device:

On Our Servers:

5.2 How to Delete Your Data

Delete Individual Items:

  1. Swipe left on any invoice, estimate, or client
  2. Tap "Delete"
  3. Confirm deletion (permanent and irreversible)

Delete All Data:

  1. Open iPhone/iPad Settings
  2. Scroll to "InvoiceMaker"
  3. Tap "Delete App"
  4. All app data is permanently removed from your device
Important: Data deletion is permanent and cannot be undone. We have no backups of your data. Export important invoices as PDFs before deleting.

6. Security Incident Response

6.1 Vulnerability Disclosure

If you discover a security vulnerability in InvoiceMaker, we encourage responsible disclosure:

  1. Email us: with subject line "Security Vulnerability"
  2. Include:
    • Description of the vulnerability
    • Steps to reproduce
    • Potential impact
    • Suggested fix (if applicable)
  3. Give us time: Allow us reasonable time (typically 90 days) to address the issue before public disclosure
  4. Do not: Publicly disclose the vulnerability before we've had a chance to fix it
We appreciate security researchers who help keep InvoiceMaker safe for all users. Responsible disclosure helps us fix issues quickly and protect the community.

6.2 Breach Notification

Current Architecture: Given our local-first design with no cloud storage:

If We Discover a Vulnerability:

7. Children's Privacy and Security

InvoiceMaker is not directed at children under 13. We do not knowingly collect data from children.

8. International Security Standards

8.1 GDPR Compliance (European Users)

InvoiceMaker respects GDPR principles:

8.2 CCPA Compliance (California Users)

Under the California Consumer Privacy Act:

9. Updates to This Policy

We may update this Security Policy to reflect:

When we update this policy:

Contact Us

If you have questions or concerns about security:

Email:

Subject Line: "Security Question" or "Security Vulnerability"

Mailing Address:
[YOUR COMPANY NAME]
[YOUR ADDRESS]
[CITY, STATE/PROVINCE, ZIP/POSTAL CODE]
[COUNTRY]