Security & privacy
Your invoices never leave your browser.
Every invoice you open in BaseInvoice is parsed, validated, and displayed entirely inside your own browser tab. No file is ever sent to our servers. We have no access to your invoice data.
| Data type | Collected? |
|---|---|
| Invoice file content | No — never leaves your browser |
| Supplier / buyer names | No |
| Invoice amounts & tax numbers | No |
| Email address (subscribers) | Yes — required for authentication |
| Payment / card details | No — handled entirely by Stripe |
| Anonymous usage events | Yes — no invoice content, no PII |
| IP address | Standard server logs only, auto-deleted after 90 days |
Client-side architecture
The validation engine, format parser, and fixer all run as JavaScript in your browser. When you drop a file onto BaseInvoice, it is read by the File API — it stays in memory in your tab and is never transmitted over the network. Closing the tab removes every trace.
What we don't collect
We do not collect invoice content, supplier or buyer names, amounts, tax numbers, or any other business-sensitive data contained in your invoice files. We collect no personally identifiable information from invoice processing.
What we do collect
We collect anonymous usage events (e.g. 'invoice parsed', 'format: XRechnung') to understand how the product is used. These events contain no invoice content. We collect your email address when you subscribe, and billing information is handled entirely by Stripe — we never see your card details.
GDPR
BaseInvoice is operated from Canada and serves EU users. Because invoice content never leaves your browser, there is no transfer of invoice data to process or govern. For account and billing data (email, subscription status), Stripe acts as a data processor under their own Data Processing Agreement.
Stripe as sole sub-processor
Stripe processes payment and subscription data on our behalf. Stripe is PCI DSS Level 1 certified and operates under a DPA with Anthropic-standard SCCs for EU data. No other sub-processors have access to your account data.