Privacy Policy
Effective 2026-08-15
Who we are
Invoxa is the controller of the data described below. For any question about this policy, or to exercise any right described in it, write to support@invoxa.co.il.
The service collects a business's purchase invoices from several sources, reads the details out of them, and produces a month-end export for the business's accountant.
What we collect
- Account data: the email address used to sign in and the business name.
- Documents: the invoice and receipt files you upload or that arrive through a connected source, kept exactly as received.
- Extracted financial data: supplier, document number, date, total, VAT, currency, and line items read out of those documents.
- Connection data: for a connected mailbox, the mailbox address, an encrypted Google refresh token, and a sync cursor.
- Operational logs: timestamps and error records needed to run and debug the service. These do not contain document contents.
Data we receive from Google APIs
Connecting a Gmail mailbox is optional and is never required to use the service. When you connect one, we request a single scope, gmail.readonly, which is read-only. The app cannot send, delete, or modify anything in your mailbox.
We use that access for exactly one purpose:
- Listing incoming messages that carry attachments, in order to find purchase documents.
- Downloading those attachments whose file type can be a purchase document (PDF and common image formats).
What we store from the mailbox:
- The downloaded attachment files themselves, which become documents in your account.
- The address of the connected mailbox, shown to you in the app and used to prevent the same mailbox being connected to two accounts.
- A Gmail history cursor, which is an opaque position marker used to resume syncing.
What we do not store:
- Message bodies, subject lines, sender and recipient lists, and message metadata beyond the sync cursor.
- Attachments whose file type cannot be a purchase document.
- Anything at all from messages without attachments.
Limited Use
Invoxa's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, data received from Google APIs is:
- Never used for advertising, and never sold or rented to anyone.
- Never used to develop, improve, or train generalized artificial intelligence or machine learning models.
- Never transferred to third parties except the sub-processors named below, and only to provide the features you asked for.
- Not read by our staff, except with your explicit request or consent (for example when you ask for support on a specific document), where necessary for security or abuse investigation, or where the law requires it.
How documents are processed
To read the fields out of a document, its file is sent to Google Vertex AI in the European Union under terms that prohibit the provider from retaining the content or using it to train models. No consumer AI endpoint is ever used. The extracted fields are stored in your account, and you confirm or correct them before they count toward anything.
Our sub-processors are:
- Supabase (database, authentication, file storage), hosted in the European Union.
- Vercel (application hosting), functions pinned to the Frankfurt region.
- Google Cloud Vertex AI (document field extraction), in the European Union.
Storage, location, and security
- All data is stored and processed in the European Union.
- Files and database contents are encrypted at rest and in transit.
- The Google refresh token for a connected mailbox is additionally encrypted with AES-256-GCM under a key held only by the server, and is never readable by the browser.
- Each business's data is isolated at the database level, so one account cannot read another's documents.
How long we keep it
Purchase documents are tax records. We keep them for seven years by default, which is the retention period Israeli tax law expects, and the period can be configured per account.
Disconnecting a mailbox deletes the stored refresh token immediately, revokes the grant at Google, and stops all further access. Documents already collected are not deleted by disconnecting, because they are your financial records. Deleting your account removes your documents and extracted data, subject to the retention obligations above.
Your controls
- Disconnect the mailbox at any time from the email intake screen in the app.
- Revoke access directly from your Google account at myaccount.google.com/permissions.
- Request access to, correction of, or deletion of your personal data by writing to the address above.
- Delete individual documents from inside the app.
You have the rights granted by Israel's Privacy Protection Law, and, where it applies to you, by the GDPR: access, rectification, erasure, restriction, portability, and objection.
Changes to this policy
If this policy changes in a way that affects how Google user data is handled, we will update this page and the effective date above, and notify account holders before the change takes effect.
Contact
Invoxa, support@invoxa.co.il. See also our Terms of Service.