Billora – Invoice Maker (“Billora”, “the app”, “we”, “us”) is operated by [Billora – Invoice Maker], Ahmedabad, India.
This policy explains what the app collects, why, where it is stored, and how to get rid of it. Contact us at [billorainvoicemaker@gmail.com] with any question about it.
1. The short version
- We collect the data you type into the app so the app can work. That’s it.
- We do not sell your data, share it for advertising, or use it to train AI models.
- There is no analytics SDK, no advertising SDK, and no third-party tracker in this app. We do not know which screens you visit or how long you use it.
- Photos of bills are read on your device. The image is never uploaded to us.
- You can delete your account and your data from inside the app at any time.
2. What we collect
2.1 Information you give us
| Category | What it includes | Why |
|---|---|---|
| Account | Email address, password, display name | To create and secure your account |
| Business profile | Business name, legal name, GSTIN, PAN, email, phone, address, currency, invoice prefix, default tax rate, payment terms | Printed on the invoices you issue |
| Payment details | UPI ID, payment QR images you upload | To generate the “Scan to pay” code on your invoices |
| Customers | Names, email addresses, phone numbers, GSTIN, billing and shipping addresses, opening balances, tags, notes | So you can bill them |
| Products & services | Names, descriptions, prices, tax rates | To fill in invoice line items |
| Invoices & payments | Invoice numbers, dates, line items, discounts, taxes, totals, payment amounts, methods, references, notes | The core records the app exists to keep |
Some of this is other people’s personal data — your customers’. You are the controller of that data; we process it on your behalf, only to provide the app.
2.2 Collected automatically
- Push notification token, if you allow notifications. Used only to send notifications to your device.
- Authentication metadata kept by Firebase Authentication: account creation time, last sign-in time, and the IP address of a sign-in request.
We do not collect device identifiers for advertising, location, contacts, your calendar, browsing history, or app usage analytics.
3. Device permissions
The app asks only when you use the feature that needs it. Declining leaves the rest of the app fully usable.
| Permission | Used for |
|---|---|
| Camera | Photographing a bill to scan, or a printed payment QR |
| Photos / files | Choosing an existing bill image or PDF, or a saved QR image |
| Microphone | Voice entry, if you use it |
| Notifications | Payment and due-date reminders |
4. On-device processing
Two things people usually assume are cloud services are not in this app:
- Bill scanning (OCR) uses Google ML Kit’s on-device text recognition. The photo and the text extracted from it stay on your device. The image is not uploaded to us or to anyone else.
- Invoice drafting is done by logic running inside the app. No invoice content, customer detail, or bill image is ever sent to an AI provider, and none of your data is used to train any model.
Voice input is the exception. If you use it, your speech is handled by your device’s own speech recognition — Apple’s on iOS, Google’s on Android — which may transmit audio to those companies under their privacy policies, not ours. We never receive the audio. Don’t use voice input if that concerns you.
5. Where your data is stored
Your account and records are stored with Google Firebase (Firebase Authentication and Cloud Firestore), operated by Google LLC.
The Firestore database is located in asia-south1 (Mumbai, India). Your invoice records are held in India. Firebase Authentication is a global Google service and may process authentication data outside India.
The app also keeps a copy on your device so it works offline. Uploaded payment QR images are stored only on your device and are never uploaded.
6. Third parties
We use as few as possible. There are no advertising or analytics partners.
| Who | What they receive | Why |
|---|---|---|
| Google Firebase | Your account and business records (§2) | Authentication, database, push notifications |
| Google Fonts | Your IP address, when a font is first downloaded | The app fetches its typeface at first run and caches it |
| Apple / Google speech services | Voice audio, only when you use voice input | Speech-to-text (§4) |
| Your device’s share sheet | Only the specific PDF you choose to share | Sending an invoice to a customer |
When you share an invoice PDF, it goes wherever you send it — email, WhatsApp, anywhere. That is outside our control and governed by whatever service you pick.
7. How long we keep it
We keep your data for as long as your account exists.
When you delete your account (Profile → My Profile → Delete my account):
- Your account closes immediately. You cannot sign in again.
- Your records are retained for 30 days, then permanently erased.
The 30-day period exists because invoices are financial records and you may be required to produce one you issued. During that window the data is not used for anything — it sits marked for deletion, and no one can sign in to reach it.
Deleting the app without deleting your account does not delete your data.
8. Your rights
You can, from inside the app:
- See and correct everything held about you and your customers.
- Export any invoice as a PDF before deleting your account.
- Delete your account and all its data (§7).
To ask anything else about your data, or to raise a complaint, email [SUPPORT EMAIL]. We aim to respond within [30] days.
Depending on where you live, you may also have rights to object to processing, restrict it, or lodge a complaint with a data protection authority.
9. Security
Data in transit is encrypted with TLS. Data at rest in Firebase is encrypted by Google. Access is enforced by server-side security rules that scope every record to the account that created it — one account cannot read another’s data, and that is enforced by the server, not by the app.
Your password is handled by Firebase Authentication and is never visible to us.
No system is perfectly secure. Use a strong, unique password.
10. Children
Billora is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us data, email [billorainvoicemaker@gmail.com] and we will delete it.
11. Changes
If we change this policy we will update the date at the top and, for anything material, tell you in the app before it takes effect.
12. Contact
[Billora – Invoice Maker][Ahmedabad, India] Email: [billorainvoicemaker@gmail.com]
