Privacy policy
Short version: no trackers and no advertising cookies. Dropping a file on the validator, pressing Generate on the generator, or calling the validation API without a key, sends that invoice to our servers to produce the result; it is processed in memory and dropped, never stored. Those free doors also keep a daily counter per IP address, so nobody can exhaust them for everyone else, and what that counter stores is a salted hash of your address, never the address itself. Beyond that, the only personal data we keep is what you hand over yourself — an email address, or your GitHub account if you sign in to get an API key. The detail follows.
If you subscribe, your card is never handled here: Polar Software Inc. sells the subscription and holds the billing details. See Payments.
What happens to your invoice
The file you drop on the validator, or the invoice data you type into the generator, is uploaded: to our own server first, which forwards it to einvoicekit's validation API to run the full official rule set. It is read into memory there, extracting the embedded XML from a Factur-X PDF where relevant, and checked. Once the result comes back, it is dropped: it is never written to a database, never logged and never kept beyond the request that processed it. Nobody looks at it, and there is nothing left afterwards for us to look at.
What we do collect
- Email address
- One place asks for one, and only if you choose to use it: the higher-volume form. It is stored as you typed it, next to a normalised copy (lower case, and for the domains where it makes no difference, without dots or +tags in the part before the @), so the same person asking more than once shows up as one prospect instead of several. It is a tidied address, not a hash: we can still read it. The volume band you picked on that form is stored with it, and if you were signed in, so is which account asked.
- Per-IP daily counter, for the free validator, generator and keyless API calls
- Every free run on those two tools, and every call to the validation API made without an API key, counts against one shared daily limit, kept per IP address so nobody can exhaust it for everyone else. What is stored is a salted SHA-256 hash of your IP address, never the raw address, in a row keyed by that hash and the calendar day. The rows carry nothing else, and they are safe to delete at any time: losing one only resets a visitor's count for that day.
- Optional free text
- Your answer to "what are you building?", if you choose to answer.
- GitHub account, if you sign in for an API key
- Your GitHub user id and the primary email address on that account. The id is what makes one key per account possible; the email is how we reach you if you ask for more volume. We ask GitHub for nothing else — no repositories, no organisations — and the access token GitHub returns is used once to read those two values and then discarded. It is never stored.
- API usage counters
- If you hold an API key: how many validations and how many generated invoices it made, per day. Numbers, nothing about the invoices themselves.
- Which plan your account is on
- One word, free or Pro, written when a subscription starts or ends. It is the only thing a payment leaves behind in our database: no name, no address, no invoice, no card, not even a payment reference.
- Validation counters
- The shape of each run: container (PDF or XML), syntax (UBL or CII) and whether it passed. No file, no file name, no invoice number, no identifier. It tells us which format to build first, nothing about you.
- Campaign parameters
- If you arrived from one of our ads, the campaign parameters in the URL (utm_source, utm_campaign, gclid) are stored alongside the anonymous validation counters above, so we know which ad works.
- Traffic statistics from the host
- No analytics product runs on this site: no analytics script, no beacon, nothing loaded from a third party. What exists is the aggregate traffic count Cloudflare, Inc. produces at its edge as a by-product of serving the pages, with no individual profile and no cross-site tracking.
Why, and on what basis
Three purposes. If you ask for more API volume than the free tier gives you, to answer that request: the address, the volume and whatever you chose to write are recorded so we can get back to you with a number and a payment link — legal basis: steps taken at your request before a contract exists (GDPR article 6.1.b). If you sign in for an API key, to run the service you asked for: issue the key and count it against a daily allowance — legal basis: performance of a contract (article 6.1.b), which is also the basis for running a subscription you bought. And, on the free validator and generator and on validation API calls made without a key, to stop one visitor from exhausting them for everyone else, a daily limit keyed to a salted hash of your IP address — legal basis: legitimate interest (article 6.1.f), balanced by never keeping the raw address and by rows that carry nothing anyone could trace back to a person. We do not sell, rent or share the data, and we run no targeted advertising on it.
How long
Per purpose, and describing what the code actually does rather than a schedule nobody runs:
- Higher-volume requests
- 3 years from the last contact, or until you ask for deletion if that comes first.
- Your account, your API keys and their usage counters
- For as long as the account exists. Ask for deletion and the account, its keys and its counters go with it.
- A key you revoked
- The row stays, disabled, holding the hash of the key and the name you gave it. It is kept precisely so that key can never be used or re-enabled again, and it is deleted with the account.
- Validation counters
- Kept without a time limit, because there is nothing in them to delete: no address, no identifier, nothing that points back to a person.
- The per-IP daily counter
- One row per hash per calendar day. Rows are pruneable at any time, because the hash cannot be turned back into an address and losing a row only resets that day's count for whoever it belonged to. There is no address in them to delete on request.
An account that has held a subscription keeps only the plan word for as long as the account exists, and it goes when the account does. The billing records themselves are Polar's, not ours, and Polar keeps them for the period its own policy and the tax law it answers to require.
Where it is stored, and who else is involved
In a Cloudflare, Inc. D1 database located in the Cloudflare D1, Western Europe (WEUR) region. The host may process data in the United States; it participates in the EU-US Data Privacy Framework and offers the European Commission's standard contractual clauses.
Besides the host, the full list of who else touches any of this is short and closed:
- GitHub (Microsoft Corporation, United States)
- Only if you choose to sign in. GitHub learns that you signed in to einvoicekit, because it is the one authenticating you, and it tells us the two values listed above. We send it nothing about you that it did not already have.
- Polar Software Inc., and its processor Stripe, Inc.
- Only if you subscribe, and only for the billing itself. See Payments.
Nobody else. No advertising network, no data broker, no analytics vendor.
Cookies and local storage
No advertising or tracking cookie is ever set, and no third-party script is loaded. Browsing the site sets no cookie at all. One technical storage is used inside your browser and never transmitted on its own: the campaign parameters of your visit, kept for the lifetime of the browser tab only. Closing the tab removes them.
Signing in with GitHub to get an API key does set cookies, because it cannot work without them. They are strictly necessary, readable only by our server, and never used to follow you: one holds your sign-in session, valid for up to seven days, and one carries a freshly issued key from the server to the page that displays it, for two minutes. They expire on their own, and nothing about them is shared.
Payments
Payments do not happen on this site. Checkout and the billing portal are hosted by Polar (Polar Software Inc., 3500 South DuPont Highway, Dover, DE 19901, United States), which sells the subscription as reseller and carries the sales tax. Polar is the seller on your invoice. Your card is entered on Polar's own page and read by Stripe, Inc. on Polar's behalf. We never receive it, never store it and cannot see it, not even the last four digits.
What Polar collects to bill you (your name and email, billing address, business name and tax number if you give one, and the card type and its last four digits) stays with Polar, under its own privacy policy. Your invoices and payment history live in Polar's customer portal, which your dashboard links to. Polar is in the United States and transfers data under the European Commission's standard contractual clauses.
The only thing that crosses back to us is which plan your account is on. Cancelling is done in that same portal, and it takes effect at the end of the period you already paid for.
Security
The protections that matter here are the ones the design makes possible, so they are worth stating as facts rather than as adjectives:
- Your invoice is processed in memory and dropped as soon as the verdict is produced, so there is no store of your documents for anyone to breach, ourselves included.
- An API key is stored only as a SHA-256 hash. The plaintext exists once, on the screen that hands it to you. We cannot recover it, which is why a lost key is replaced rather than looked up.
- The per-IP daily counter stores a salted SHA-256 hash of the address, never the address itself, so the counter is useless to anyone who gets hold of it.
- Everything, pages and API alike, is served over HTTPS.
- The GitHub access token is used once during sign-in and discarded in the same request. It is never written to the database.
- No card detail ever reaches a server of ours, in any form.
Your rights
Where we rely on your consent, you can withdraw it at any time, and withdrawing it is as easy as giving it: one email, no reason needed. Withdrawal does not affect anything we lawfully did with the data before you withdrew it (GDPR article 13.2.c).
You have the right to access, rectify, erase, port, restrict and object. Email contact@einvoicekit.com and that is enough: no form, no proof of identity beyond what is strictly necessary. We answer within one month. If our answer does not satisfy you, you can lodge a complaint with the French data protection authority, the CNIL (cnil.fr), or with your own national authority.
Data protection officer
None appointed, and none required: article 37 asks for one where the core activity is large-scale monitoring of people or special-category data, and neither describes this site. Writing to contact@einvoicekit.com reaches the person who wrote this page.
Changes to this policy
The date at the bottom moves whenever the text does. A change that would widen what is collected, or add someone to the list above, is stated here before it takes effect, rather than edited in quietly.
Data controller
VIZALGO, 65 rue de la Croix, 92000 Nanterre, France. Nanterre Trade and Companies Register (RCS) 907 455 778. Contact: contact@einvoicekit.com.
Last updated: 3 September 2026.