Invoice Maker

Privacy policy

What stays on your device, what is collected, and how to get in touch.

Effective date: 2026-10-06

Contact: klm.labs.inc@gmail.com

Invoice Maker is made by KLM Labs. It creates invoices and estimates on a device and lets the user share a PDF when they choose.

What changes in this revision. PostHog no longer stores your IP address with analytics events: it still works out an approximate location from it when an event arrives, then discards it. Nothing else about the app, your data or your subscription changed.

Previous revision (2026-09-23). Invoice Maker now offers subscriptions. Purchases are made through the App Store or Google Play, and RevenueCat, Inc. processes subscription records for KLM Labs so the app can check, unlock and restore your subscription. That revision added a section describing that processing, the subscription events recorded by analytics, and how to ask for subscription records to be deleted. Invoice Creator is now called Invoice Maker. Nothing else about the app, your data or your subscription changed.

Previous revision (2026-09-11). Analytics collection is automatic in native builds that include a bundled analytics key. There is no analytics setting in the app. Collection includes approximate location derived from the internet connection and masked screen recordings, as described below. That revision also detailed automatic analytics metadata, IP-address storage, and the technical headers sent for app updates.

The short version

  • Your business and client data stays on your device. Names, addresses, contact details, invoice contents, amounts and your logo are stored locally and are never sent to us.
  • Builds configured for analytics collect usage data under a random device identifier. Builds without an analytics key do not send PostHog data; update checks below still occur.
  • That usage data includes which screens you visit, an approximate location (country, city, postal area) worked out from your internet connection, and a masked screen recording in which text and images are hidden.
  • Subscriptions are paid through Apple or Google. We never see your card or bank details. RevenueCat receives your purchase records and a random app user ID so the app can check and restore your subscription.
  • There is no account and no sign-up. The app never asks for your name or email address. Your usage and subscription records are kept together by random identifiers, so they are linked to you (see below).
  • We do not sell data, show adverts, or track you across other apps.

What stays on your device

The information you enter in the app — business details, client names and contact details, invoice and estimate content, dates, notes, totals, and any logo image you choose — is stored locally in the app's own database. The app is designed to work offline. We cannot view, retrieve, or delete this information, because it never reaches us.

This is unchanged, and it is the point of the app.

Product analytics

The app includes product analytics so we can see which features are used and where people get stuck. It sends no PostHog data when built without an analytics key.

Collection is always enabled in native builds with a bundled analytics key. The app provides no analytics setting. Builds without a key and the web build send no PostHog data. Update checks operate independently of analytics. Updating the app does not delete previously collected records.

Who processes it. PostHog, Inc. processes analytics for KLM Labs. The app’s default PostHog endpoint is in the United States; the service endpoint can be configured for a build. PostHog’s privacy policy describes its processing practices.

What analytics collects

Events describing what you did, not what you wrote. For example: the app was opened, onboarding was completed, an invoice was previewed, a save failed. Screen names are recorded as templates such as /invoice/[id] — never the actual invoice identifier.

Subscription events. When the subscribe screen is shown, where it was opened from, whether plans could be loaded, which plan (yearly or monthly) a purchase was started for, whether it included a free trial, whether a purchase or restore completed, was cancelled or failed, with a generic reason such as a network or store error, and whether a restore found an active subscription. These events never include a price, an amount, or store receipt details.

Event details are restricted, by design, to counts, fixed categories and yes/no values. No client name, business name, address, email address, phone number, invoice or estimate number, document text, note, logo, PDF, currency, tax rate, or money amount is ever included in an event.

Technical information about the app and device:

  • App version, build number, platform (iOS or Android), and which kind of build it is.
  • Device category (reported as mobile), screen width and screen height.
  • The analytics software's name and version, an event timestamp and a randomly generated event identifier.
  • Technical indicators that the activity has no identified login and is not being used to create a person profile.
  • When available, feature settings received from the analytics service: their names and values, and a list of active settings.

A pseudonymous identifier for your device and session, generated by PostHog. It is not your name, email address or a login identity, and the app has no account or login. Events and recordings are kept together under this random identifier, so they are linked to you: a random identifier does not make those records unlinked data.

An approximate location. PostHog works out a country, city and postal area from the internet address your device connects from, at the moment an event arrives. PostHog is set to discard your IP address once the location is worked out, instead of storing it with analytics events. The app does not ask for location permission and never reads your device's GPS. This is the same approximation any website can make from a connection. We use it to understand which countries and regions our users are in.

A masked recording of the app's screens. So we can see where people tap, what they struggle with, and where they give up, the app records the screens you visit while using it.

These recordings are masked before they leave your device:

What is maskedResult
All text on screenClient names, addresses, invoice numbers and amounts appear as blocks, not readable words. This covers text the app displays, not only text you type
All imagesYour business logo appears as a placeholder
System pickersThe photo picker's contents are hidden

Console output is not recorded. Analytics and recordings are retained according to the retention settings of the services that process them. Contact us for information about retention or to request deletion.

Masking is a technical measure applied on the device. We enable every masking option the recording software provides, and we treat any change to that as a change to this policy.

What analytics never collects

We do not collect your name, your clients' names, addresses, email addresses, phone numbers, invoice or estimate numbers, document contents, notes, logo images, PDF contents, currencies, tax rates, or any money amount. We do not collect your precise location. We do not collect contacts, photos, calendar, messages, or files.

We do not sell or rent data, do not use it for advertising, do not share it with data brokers, and do not track you across other apps or websites.

Subscriptions and purchases

After first-run setup, the app needs an active subscription or free trial. This section applies to builds configured for subscriptions, which includes the versions published on the App Store and Google Play; builds without a subscription key make no requests to RevenueCat.

Payment is handled by Apple or Google. You buy, pay for, manage and cancel subscriptions with your Apple Account or Google Play account. Apple and Google process the payment under their own privacy policies. KLM Labs never receives or stores your card or bank details, and the app sends no name or email address to RevenueCat.

Who processes subscription records. RevenueCat, Inc. processes subscription records for KLM Labs as a service provider. The app contacts RevenueCat when it starts, to check your subscription; when it shows the plans; and when you subscribe or restore purchases.

What RevenueCat receives:

  • A random app user ID created by RevenueCat's software when the app first uses it. It is not your name, email or store account, and it is used to keep your purchase records together.
  • Your purchase records for this app from the App Store or Google Play: the store's receipt or purchase token and the store's transaction IDs, and from them the plan bought, its price and currency, and purchase, trial, renewal, cancellation, billing-problem and expiry dates.
  • Technical information sent with each request: app version and build, app identifier, operating-system version, device model (and, on Android, device brand), preferred languages, store country, the version of RevenueCat's software, and whether the purchase is a test purchase.
  • On iPhone and iPad, the identifier for vendor, a random identifier that iOS gives to apps from the same developer on one device.
  • The app's random analytics identifier, so subscription events can be matched with the app's usage analytics. It is not your name, email or store account.
  • As with any internet request, your IP address is visible to RevenueCat's servers.

Why. To confirm purchases with Apple or Google and prevent fraud; to unlock the app while your subscription or trial is active; to restore your subscription after reinstalling or on a new device; and to give KLM Labs subscription reports, such as how many trials started, renewed or were cancelled, and the resulting revenue.

What it never receives. No invoice, estimate, client or business data, logo, PDF, or money amount from your documents is sent to RevenueCat. RevenueCat does not use this data to show you adverts or to track you across other apps.

Keeping and deleting subscription records. RevenueCat keeps subscription records under its agreement with KLM Labs and its own privacy policy. You can ask us to delete the RevenueCat record for your purchases; tell us the platform and roughly when you subscribed so we can find it. Deleting that record does not cancel a subscription, and Apple and Google keep their own purchase records. Removing the app does not cancel a subscription or delete records already held by RevenueCat.

App updates

The app uses expo-updates to deliver small fixes without waiting for a store update. This is enabled as of version 1.0.0. Native release builds check Expo, Inc.’s servers for a newer version of the app’s code when the app launches. These requests are independent of PostHog and also occur in native release builds without an analytics key. Development and web builds do not use this native update process.

The update request sends these technical headers:

  • The runtime-version fingerprint, the build's update channel, and the platform.
  • A randomly generated installation identifier (EAS-Client-ID) that lets Expo serve updates consistently to the same install.
  • The identifiers of the currently running update and the update embedded in the installed app, when available.
  • The update protocol and API versions, the native update environment, the accepted response formats, and a request for errors in JSON format.
  • If updates recently failed to launch, their identifiers; if a previous fatal app error was saved, its error details, limited to 1,024 characters.
  • Technical headers previously supplied by the update server, when present, sent back on later checks.

When downloading update files, requests also carry the identifier of the requested update and may indicate support for downloading a patch instead of a complete file.

The installation identifier is created on your device, is not derived from your hardware and is not tied to an account. It does link technical requests to the same installation. As with any internet request, Expo's servers also see your device's IP address. What Expo does with that is governed by its own privacy policy: https://expo.dev/privacy.

The check never carries invoice data, client data, business or document data, logo images, PDF contents, or any money amount. Removing the app does not itself delete records already held by Expo.

Photo-library access

The app lets you optionally choose one image as a business logo, which appears on your business profile and on generated PDFs. The image is read on the device and stored locally with the business profile; it is never uploaded. Choosing a logo is optional — you can decline photo-library access, or clear a chosen logo, and continue using every feature. If the image cannot be read, the app says so and saves the profile without a logo.

Sharing PDFs

The app generates a PDF on the device and opens your operating system's share sheet. It does not send email, messages, or PDFs itself. A PDF leaves your device only if you choose a destination in that share sheet. Once shared, that destination and recipient handle the PDF under their own privacy practices.

Children's data

Invoice Maker is a business tool and is not directed to children. We do not knowingly collect children's personal information. If you believe a child has used the app, its local data can be removed by uninstalling the app, and you can contact us to ask that any analytics data be deleted.

Your choices and your rights

  • Delete your local data by uninstalling the app. This removes the app's database from that device. Device backups, if enabled by the device owner, are controlled by the operating system, not by us.
  • Cancel a subscription in your Apple Account or Google Play settings; see the terms for the steps. Deleting the app does not cancel it.
  • Ask us to delete subscription records held by RevenueCat. Email klm.labs.inc@gmail.com with the platform and roughly when you subscribed.
  • Ask us to delete analytics data. Email klm.labs.inc@gmail.com. Because analytics records use a random identifier rather than an account or name, please include the approximate dates you used the app and the device platform to help us investigate. We may need additional information to locate records, and will explain what we can locate and delete. Uninstalling the app does not delete records already held by PostHog, Expo or RevenueCat.
  • Ask what we hold. Email the same address and we will tell you.

Depending on where you live, you may have additional rights over personal data, including access, correction, deletion, and objecting to processing. Contact us and we will respond in accordance with applicable law.

Changes to this policy

If the app's data practices change, this policy and the store privacy disclosures will be updated before that version is released. The effective date at the top of this page reflects the most recent change. Questions can be sent to klm.labs.inc@gmail.com.