SI SayInvoice Voice invoicing for UK tradespeople
Help Terms Account

Privacy

How SayInvoice handles your data

This privacy policy explains what information SayInvoice collects, why we use it, where it is processed, and the choices you have when you use the website or installed mobile app to create quotes and invoices, save receipts and job photos, and prepare business records.

Last updated: 17 August 2026 Support: hello@sayinvoice.app No advertising pixels or targeted advertising

Voice

OpenAI only with permission

We ask before sending voice, text, client or document data, or a chosen receipt image to OpenAI for an AI feature.

Hosting

European regions

App/API hosting is in Railway EU West, Amsterdam. Supabase is in Central Europe, Zurich.

Payments

Payment providers handle cards

SayInvoice does not store full credit or debit card details.

Contact

One inbox

Support, privacy questions, and deletion requests go to hello@sayinvoice.app.

Controller

Who this policy applies to

SayInvoice is built for UK tradespeople and small trade businesses who want to create professional quotes and invoices from job notes. For privacy questions, data requests, or support, contact hello@sayinvoice.app.

This policy applies to SayInvoice on the website, in browser-based app screens, and in any native mobile app version we distribute through an app store.

If you enter personal data about your own customers, suppliers, staff, or contacts into SayInvoice, you are responsible for making sure you have the right to use that information. We process that customer data so we can provide the SayInvoice service to you.

Information

Data we collect or process

  • Account information, such as your email address, sign-in details, user ID, account status, setup information, and email preferences.
  • Business profile details, such as business name, owner name, business type, address, email, phone number, VAT number, bank details, payment terms, quote terms, invoice numbering, and uploaded logos.
  • Client and document data, such as customer names, customer addresses, email addresses, private notes, invoice and quote line items, totals, VAT settings, due dates, document status, and saved client records.
  • Photo and cost data you choose to save, such as receipt images, before and after job photos, links to a quote or invoice, whether a job photo should appear on a customer PDF, and receipt details including supplier, date, category, total, VAT, and currency.
  • Voice and AI data, such as audio you choose to record, transcripts, job notes, extracted invoice or quote details, and review prompts used to create drafts.
  • Billing data, such as plan details, payment confirmation, subscription records, discount information, and billing activity. We do not store full payment card numbers.
  • Referral and partner data, such as referral codes, partner links, account attribution, referral or commission status, reward and payout records, and information needed to prevent misuse.
  • Technical and usage data, such as browser type, device information, installed app runtime information, an Apple push device token when you enable iPhone notifications, your notification preferences, IP-derived connection data, app events, error logs, session information, and performance monitoring data.
  • Support information, such as messages you send us, screenshots or files you choose to share, and notes needed to investigate a support request.

Purpose

Why we use the data

  • To create, save, sync, export, and share quotes and invoices.
  • To store and organise receipt and job photos, link them to the job you choose, include selected job photos on customer PDFs, and include confirmed receipt evidence in an accountant export.
  • To turn spoken job notes into structured draft documents for you to review.
  • To remember repeat clients, profile settings, VAT settings, payment terms, and document numbering.
  • To run subscriptions, payment checks, account billing, referral discounts, referral rewards, and partner commission attribution.
  • To keep accounts secure, prevent misuse, investigate errors, monitor uptime, and improve reliability.
  • To answer support requests, troubleshoot account problems, and communicate important service updates.
  • To send optional, private iPhone reminders you enable for overdue invoices, sent quotes, unfinished drafts, monthly summaries, and referral rewards.
  • To send optional SayInvoice tips, product updates, and offers when you actively choose marketing emails and your account remains on the free plan.
  • To comply with tax, accounting, legal, regulatory, fraud-prevention, and dispute-handling obligations where they apply.

Lawful basis

Our legal basis for processing

  • Contract: to provide the app, accounts, secure account storage, billing, support, referrals, and paid plan features you ask us to provide.
  • Legitimate interests: to secure the service, prevent fraud and referral abuse, debug problems, understand product usage, improve the app, and protect SayInvoice and its users.
  • Legal obligation: where we need to keep records or respond to lawful requests relating to payments, tax, accounting, disputes, or compliance.
  • Consent: before sharing personal data with OpenAI for voice transcription, AI-assisted drafting, voice edits, private voice notes, receipt-image analysis, or AI business insights, and where we ask for optional device permissions, marketing, or non-essential tracking.

AI, voice and receipts

What SayInvoice sends to OpenAI

SayInvoice uses OpenAI, LLC as its third-party provider for voice transcription and AI-assisted features. Before any personal data is sent to OpenAI, the app asks for your explicit permission and identifies the information involved. If you do not allow this sharing, SayInvoice does not send new content to OpenAI and non-AI parts of the app remain available.

When you allow it and deliberately use an AI feature, the data sent may include:

  • Voice recordings you choose to make for a quote, invoice, voice edit, or private voice note.
  • Transcripts, typed job notes, editing instructions, and any client or business details contained in them, including names, addresses, email addresses, job descriptions, prices, and document details.
  • A compressed copy of the individual receipt image you choose to scan, so the app can suggest the supplier, purchase date, category, total, VAT amount, and currency for you to review.
  • Relevant paid invoice and resolved quote details, including client names, line items, totals, dates, and outcomes, when you request AI business insights.
  • Instructions and structured data needed to return the transcript, draft document, edit, note, receipt suggestion, or business insight you requested.

OpenAI processes that information to provide only the transcription, drafting, editing, note, receipt scan, or insight feature you requested. OpenAI states that data submitted through its API is not used to train or improve its models by default unless the API customer explicitly opts in. SayInvoice does not sell this content, share it with data brokers, or use it for advertising.

OpenAI may retain API abuse-monitoring logs containing customer content for up to 30 days by default unless it is legally required to retain them longer. OpenAI's audio transcription endpoint does not retain application state. SayInvoice does not intentionally keep raw audio recordings as permanent customer files after processing. Saved SayInvoice records may include generated text, transcripts, job notes, document details, client details, status history, and other information needed to provide the service.

You can review or withdraw AI data-sharing permission at any time in Settings > More settings > Privacy & AI. Withdrawal stops future sharing with OpenAI; it does not recall processing that you previously requested. You can also request deletion of your SayInvoice account and active account data.

AI-generated drafts and receipt suggestions are not final until you review them. You are responsible for checking names, addresses, suppliers, dates, categories, VAT, prices, payment terms, totals, and all other details before sending anything to a customer or relying on it for accounting or tax records.

We do not use AI processing to make legal, tax, credit, employment, or similarly significant decisions about you or your customers. The AI output is a drafting tool only.

Mobile app

Device permissions and local files

The installed mobile app may ask for microphone access so you can record job notes. You can deny or later change that permission in your device settings. SayInvoice does not listen in the background; recording is used when you start a voice feature.

If you choose to add a receipt, job photo, or business logo, the app may offer the system camera, photo library, or file picker. Camera and photo access is used only for the image you capture or choose; SayInvoice does not scan your library or use the camera in the background. These permissions are optional and are not needed to create invoices or quotes.

The iPhone app may ask for notification permission after explaining the reminders available. If you allow it, SayInvoice stores the Apple push device token against your signed-in account so Apple can deliver the reminder types you choose. Lock-screen messages do not include customer names, addresses, document values, private notes, or transcripts. You can switch individual reminders off in Settings or disable notifications in iPhone Settings. SayInvoice disables that device for the account when you sign out or Apple reports that its token is no longer valid. Marketing push notifications are not part of this feature.

The mobile app may create temporary local files, such as PDF exports, so you can preview, save, or share documents through Mail, WhatsApp, Messages, Files, or other apps you choose. Once you share a document through another app, that app's own terms and privacy policy apply.

Storage

Where data is stored

SayInvoice may store your account, profile, documents, clients, receipt and job photos, cost records, app settings, billing state, service events, support logs, and referral records in secure cloud systems so your account can continue working across sessions. Some app data may also be stored locally in your browser or installed app for performance and draft recovery.

Current primary infrastructure regions App/API hosting: Railway EU West, Amsterdam, Netherlands. Database, authentication, and storage: Supabase eu-central-2, Central Europe, Zurich, Switzerland.
  • If you clear browser or app storage, local-only drafts or cached data on that device may be removed.
  • If you delete documents or clients in the app, they should no longer appear in your account, subject to normal backups, logs, and legal record retention.
  • You can initiate permanent account deletion from Settings in the app. This removes the account and associated profile, client, document, receipt, job-photo, cost, settings, insight, and private logo data from active systems.
  • Saved documents may include transcripts or source job notes if those details are part of the document record.
  • Assigned receipts and job photos are normally kept while your account is active. Unassigned “save for later” photos may be removed after the warning period shown in the app; assigned items are not removed by that tidy-up rule.

Processors

Services we use

We use trusted third-party services to run the product. These include or may include:

  • Railway for app/API hosting.
  • Supabase for authentication, database, and storage.
  • Stripe for website payment, subscription, discount, and billing processing.
  • Apple for subscriptions purchased through In-App Purchase, including transaction and entitlement status.
  • OpenAI, LLC for voice transcription, AI-assisted document drafting, voice edits, private voice-note transcription, receipt-image analysis, and AI business insights, only after you grant permission in the app.
  • Error monitoring, uptime, security, and performance providers where enabled.
  • Loops for account, service, and optional marketing email delivery.
  • Hosting, domain, email, storage, and infrastructure providers needed to deliver the website and app.
  • Email, WhatsApp, Messages, or native sharing apps when you choose to send documents or referral links through them.

Payment card details are handled by our payment provider. SayInvoice receives payment confirmation and billing records, but not full card numbers.

We require service providers that process user data on our behalf, including OpenAI, to use it only to provide their contracted service, apply appropriate security and confidentiality controls, comply with applicable data-protection law, and provide the same or equivalent protection described in this policy.

Optional accounting connection

Information shared with Xero

Xero is an optional limited web beta, available only where enabled. New connections are subject to availability. The published iPhone app does not include this integration.

Where the optional integration is enabled and you consent, SayInvoice sends the invoice or cost records you select to the Xero organisation you choose. This includes relevant customer or supplier contact details, dates, amounts, descriptions and tax treatment. Enabled invoice PDFs and receipt photos, and invoice-linked job photos you explicitly select and review, are uploaded as attachments. Private photos are not made publicly accessible by SayInvoice.

SayInvoice reads the connected organisation's contacts, account and tax codes, invoices and payment information needed for setup, duplicate checks, export status and explicit payment review. Payment recording needs separate review and confirmation; it sends the amount, date and receiving account and may approve a draft invoice. It does not collect money or reconcile a bank account.

We encrypt Xero access and refresh tokens on our server and keep them out of the browser. We store connection identifiers, settings, export results, payment-operation records and your consent version, acceptance time and sign-in reference so we can provide the connection and check uncertain outcomes safely. Xero data is not used to train, fine-tune or enhance AI models.

Disconnecting stops future sharing and removes the active connection credentials after revocation is confirmed. Export and payment history may remain in SayInvoice while your account is active to prevent duplicate records and support recovery. Account deletion removes associated Xero connection, export, payment and consent records from active SayInvoice systems, subject to normal backups and any lawful retention described here. Records already sent remain in Xero and must be managed there.

Xero processes information under its own privacy notice. Review the organisation and selected records before sending. Xero sharing disclosure version: 2026-09-15-v1.

International transfers

Processing outside the UK

Some providers may process data outside the UK or European Economic Area. Where this happens, we expect those providers to use appropriate safeguards, such as contractual protections, data transfer terms, or other lawful transfer mechanisms.

Analytics, cookies and tracking

Analytics and marketing

SayInvoice uses PostHog's EU service for optional browser analytics and privacy-masked session replay on the website. These begin only after you accept analytics. The iOS app does not initialise PostHog, show an analytics or cookie prompt, or store analytics consent or analytics cookies.

Form inputs and customer, invoice, quote, and private-note areas are masked in replays. We do not intentionally send invoice text, voice recordings, private notes, payment card details, referral codes, or Stripe identifiers to PostHog. When analytics are accepted, an anonymous consent cookie also allows the server to count delivered public pages without storing the visitor's raw IP address in the event.

Separately, SayInvoice records limited server-side operational events needed to run, secure, bill, debug and protect the service. These can include processing outcomes, sign-ups, subscription journeys, payment failures, referrals and account deletion. They do not read or store information on your device and do not include session replay. We do not track you across other companies' apps or websites, use advertising pixels, use analytics for advertising, share analytics data with data brokers, or sell analytics data for targeted advertising.

When you deliberately use a SayInvoice partner link and then create a new account, a server-signed partner reference is carried into signup and saved against that account. We use it to attribute subscription commission, prevent duplicate or fraudulent claims, and maintain payment records. It does not give the partner access to your invoices, clients, payment card details, or account contents.

Optional marketing emails are off by default. You can actively choose them during account creation or in Settings. We record when and where that choice was made, and only mark free accounts as eligible. You can switch them off in Settings or use the unsubscribe link in any marketing email. Essential account, security, billing, and service messages are handled separately.

Retention

How long we keep data

  • Account, profile, client, quote, and invoice data is usually kept while your account is active or until you delete it.
  • Assigned receipt images, job photos, and their confirmed cost or job links are usually kept while your account is active or until you delete them. Unassigned “save for later” photos may expire after an in-app warning.
  • Deleting your account in the app cancels active SayInvoice website subscriptions immediately. Apple subscriptions must be cancelled separately in App Store subscription settings. Charges already made are not automatically refunded.
  • Billing, invoice, tax, referral, fraud-prevention, and dispute records may be kept for longer where needed for business, legal, accounting, or payment reasons.
  • Error logs, analytics events, and monitoring data are kept only for as long as needed to secure, debug, and improve the service.
  • OpenAI may retain API abuse-monitoring logs containing submitted content for up to 30 days by default, unless longer retention is legally required. OpenAI's audio transcription endpoint does not retain application state.
  • Backups may keep deleted data for a limited period before they are overwritten or removed through normal backup cycles.

Security

How we protect data

We use authentication, access controls, HTTPS, restricted internal access, and payment checks to protect account data. No internet service is perfectly secure, so you should also protect your device, browser, email account, and SayInvoice login.

Your rights

Access, edits, deletion, and objections

Under UK data protection law, you may have rights to access, correct, erase, restrict, object to, or receive a copy of your personal data. You may also have the right to withdraw consent where processing depends on consent.

  • You can edit profile, client, quote, invoice, receipt, cost, and job-photo details inside the app.
  • You can cancel or manage your subscription through the billing tools where available.
  • You can initiate permanent account deletion directly from Settings in the app after confirming your password.
  • You can withdraw permission for future sharing with OpenAI from Settings > More settings > Privacy & AI.
  • You can switch off optional marketing emails in Settings or use the unsubscribe link in a marketing email.
  • You can contact hello@sayinvoice.app to request help with account data, deletion, or export.
  • You can complain to the UK Information Commissioner's Office if you are unhappy with how your personal data is handled.

Children

Not for children

SayInvoice is a business tool for tradespeople and is not intended for children or personal household use. Do not create an account if you are under 18.

Updates

Changes to this policy

We may update this privacy policy as SayInvoice changes. If we make a material change, we will take reasonable steps to make the updated version available in the app or on the website.

SI
SayInvoice

Privacy information for the current SayInvoice service.

Help Terms Account
Use SayInvoice in your browser • Get the iPhone app Open SayInvoice