This policy explains how GiveMeMood ("we") handles personal data in two separate places: the Invoice Flow Android app, and the website invoiceflow.management. They are treated separately because they work very differently.
1. The short version
- Invoice Flow is offline-first. Your invoices, clients, products, expenses and business profile are stored in a database on your own device. We do not host them and cannot read them.
- The app requires no account and no sign-up.
- The app sends anonymous usage statistics and crash reports so we can find bugs and see which features are used.
- This website uses analytics cookies via Google Tag Manager and Google Analytics 4. See the cookie policy.
- Payments are handled entirely by Google Play. We never see your card details.
2. Data the app stores on your device
Everything you enter into Invoice Flow stays in local storage on your phone or tablet: business profile and logos, clients and client groups, invoices, estimates, contracts, products and inventory, expenses and receipt photos, projects, time entries, tax and late-fee settings, PDF templates and app settings.
We have no server copy of any of it. If you uninstall the app without making a backup, that data is gone — we cannot restore it for you. Backups you create are ordinary files written to a location you choose on your device or in your own cloud storage; we never receive them.
3. Data we do collect
3.1 In the app — analytics and diagnostics
The app uses Google Firebase (Analytics, Crashlytics and Cloud Messaging). What is sent:
| Category | Examples | Why |
|---|---|---|
| Usage events | Which screens are opened, which features are used, subscription funnel steps, milestone events (e.g. first invoice created) | To see what people actually use and where they get stuck |
| Device and app info | App version, Android version, device model, language, country (derived from IP, then discarded), a randomly generated app instance ID | To reproduce bugs and prioritise devices |
| Crash reports | Stack traces, the state of the app at the moment it crashed | To fix crashes |
| Push token | A Firebase Cloud Messaging token bound to your app installation | To deliver notifications you have opted into |
Content is never included. No invoice, client name, amount, address, note, logo or receipt photo is ever sent in an analytics event. Events carry counts and identifiers of features, not the data inside them.
The app instance ID is not your name, phone number or Google account. It is a random identifier that is reset when you clear app data or reinstall.
3.2 On this website
The website measures pageviews, scroll depth, reading time, search terms typed into the site search, language switches, clicks on internal links and clicks on the "Get it on Google Play" buttons. This runs through Google Tag Manager into Google Analytics 4 and is covered in detail in the cookie policy, which also tells you how to turn it off.
Our hosting provider additionally keeps standard server logs (IP address, time, requested URL, user agent) for security and abuse handling.
3.3 When you write to us
If you email one of the addresses on our imprint page, we keep your message and address for as long as needed to deal with it and to comply with record-keeping obligations.
4. Payments
Subscriptions are sold and processed by Google Play under Google's own terms. Google tells the app only whether an active entitlement exists. We never receive your card number, billing address or full payment history. Google's handling of that data is governed by the Google Privacy Policy.
5. Legal bases (GDPR)
| Processing | Basis |
|---|---|
| Running the app and storing your data locally | Performance of a contract (Art. 6(1)(b)) |
| App analytics and crash reporting | Legitimate interest in a working, improving product (Art. 6(1)(f)) — you can opt out, see section 7 |
| Website analytics cookies | Consent (Art. 6(1)(a)) |
| Push notifications | Consent (Art. 6(1)(a)) — Android asks before any notification is shown |
| Server logs, fraud and abuse prevention | Legitimate interest (Art. 6(1)(f)) |
6. Who we share data with
We do not sell personal data and we do not share it with advertisers or data brokers. Data is shared only with the processors that make the service work:
- Google (Firebase, Google Analytics, Google Tag Manager, Google Play) — analytics, crash reporting, notifications, billing.
- Our hosting provider — serving this website. TODO(owner): name the host once the Cloudflare/hosting setup is finalised.
Data may be processed outside your country, including in the United States, under the transfer mechanisms Google publishes (Standard Contractual Clauses and the EU–US Data Privacy Framework).
7. Your choices and rights
7.1 Turning analytics off
- App: Settings → Privacy → turn off usage analytics. TODO(owner): confirm the exact menu path before publishing, and make sure the toggle exists in the shipped build.
- Website: decline analytics in the cookie banner, or use the control described in the cookie policy.
- Notifications: Android system settings, per app.
7.2 Your rights
Under GDPR (and equivalents such as the UK GDPR and the CCPA) you may request access, correction, deletion, restriction, portability, and object to processing based on legitimate interest. Write to [email protected]. We answer within 30 days.
Note what this means in practice: because your business data never leaves your device, we usually hold nothing about you beyond anonymous analytics. A deletion request will therefore usually be answered by deleting analytics identifiers and any email correspondence — your own data you delete yourself by clearing app data or uninstalling.
You also have the right to complain to your local data protection authority.
8. Retention
- App analytics events: up to 14 months in Google Analytics, then deleted.
- Crash reports: up to 90 days.
- Website analytics: up to 14 months.
- Server logs: up to 30 days.
- Email correspondence: up to 3 years.
9. Children
Invoice Flow is a business tool and is not directed at children under 16. We do not knowingly collect data from them.
10. Security
App data lives inside the app's private storage, which Android isolates from other apps. Traffic to our services uses TLS. No system is perfectly secure — if you find a vulnerability, please report it to [email protected] rather than disclosing it publicly.
11. Changes
If this policy changes materially we will update the date at the top and, where
the change is significant, announce it in the app. The current version always
lives at https://invoiceflow.management/legal/privacy/ — this is the URL declared
in the Google Play listing.
12. Contact
Privacy questions and data-subject requests: [email protected]
Formal data protection contact: [email protected]
Everything else: [email protected]