Privacy, written to be read.
This is the whole notice. There is no shorter version hiding a longer one, and no clause that says we may change what we do with your data whenever we like.
Last updated 30 August 2026
The short version
Billr stores what you type into an invoice, and your e-mail address so you can sign in. It does not run analytics, advertising or third-party tracking scripts. It sets only functional cookies of its own, and no tracking cookies. If you never create an account, Billr holds nothing about you at all. The invoice generator runs entirely in your browser.
- Drafts made in the free generator never leave your device.
- There is no password, so there is no password of yours to leak.
- Only functional cookies of our own. No analytics cookies, no advertising cookies.
- You can export everything and delete your account from inside the app.
- We do not sell, rent or share your data with advertisers. Ever.
Who is responsible for your data
The controller of the personal data described here (the party that decides why and how it is processed) is the operator of Billr.
The controller is the operator of Billr, established in Belgium, reachable at [email protected].
Until that entry is completed, treat this notice as a description of how the software behaves rather than as a finished legal disclosure.
What we store
Nothing here is collected in the background. Every item below exists because you typed it, uploaded it, or asked Billr to do something that requires it.
If you have an account
- Your e-mail address. It is the account identifier and the only way to sign in.
- Your business details. Name, address, tax number, logo and payment terms: the things that get printed on your invoices.
- Your invoices, credit notes, quotes and receipts, including line items, amounts, dates, tax rates, notes and status.
- Your clients, as you enter them: name, address, e-mail and tax number. You are responsible for having a basis to hold your clients’ details.
- Expenses and incoming bills you choose to log, including any file you attach.
- Your plan and billing status. Which plan you are on, when it renews, and whether a payment succeeded.
- Basic technical logs. Request timestamps, IP address and error traces, kept briefly so the service can be operated and abuse can be stopped.
If you booked a place or were invited by somebody who uses Billr
Booking pages, invitations and guest lists belong to the organiser who made them. The organiser decides what to ask and is responsible for that decision; Billr stores the answers on the organiser’s behalf and shows them to nobody else.
- What you filled in. Your name, e-mail address, the number of places, your answers to the organiser’s questions, and whether you have paid. If the organiser asked about food, your answer may say something about your health or beliefs; it is kept only to be shown to the organiser and the kitchen.
- Your reply to an invitation, per person in your household, with the time you replied. You can change it with the same link.
- Your ticket. A code that identifies your booking at the door, and the moment it was scanned.
- Whether you agreed to hear from the organiser again. Only if the organiser asked, and only with the wording you saw.
To see, correct or remove what an organiser holds about you, ask the organiser; they can do all of that from inside Billr. If you cannot reach them, write to us at [email protected] and we will help.
What we never store
- Passwords. There are none. Sign-in is a one-time code sent to your e-mail address.
- Card numbers. Payment details are entered with our payment provider and never reach Billr’s servers. We see a plan, a status and the last four digits at most.
- Behavioural profiles. No advertising identifiers, no cross-site tracking, no data brokers, no third-party analytics script embedded in the app. Billr counts visits to its own pages itself, without cookies: a code that changes every day and cannot be turned back into you, never your address.
Drafts in the free generator stay in your browser
The invoice generator is a client-side tool. What you type is held in your browser’s localStorage under the key billr.generator.v1 so that closing the tab does not lose your work. It is not transmitted to Billr, it is not readable by us, and it is not backed up anywhere.
A logo you add in the generator is read by your own browser and embedded into that same local draft as an image. It is not uploaded. Clearing your browser’s site data for Billr, or pressing Reset in the generator, removes the draft permanently, including from our reach, because we never had it.
This changes the moment you choose to save an invoice to an account. At that point the invoice is sent to our servers and stored, because storing it is the entire point of saving it.
Signing in with an e-mail code
To sign in you enter your e-mail address and we send you a six-digit code that is valid for about ten minutes and can be used once. The code is stored only in a hashed form and only until it is used or expires. Repeated failed attempts are rate limited.
A successful sign-in creates a session, which is held in the session cookie described below. There is no password to choose, forget, reuse across sites or have stolen in somebody else’s breach.
Cookies
Billr sets only functional cookies of its own. None of them follows you to other sites, none comes from a third party, and none is used for advertising or analytics.
- Session (
billr_session): keeps you signed in. Set only after you sign in, markedHttpOnlyandSecure, and it holds a signed session reference rather than your details. - Currency (
billr_currency): shows prices in your currency. Kept for 180 days. - Country (
billr_country): the country your visit comes from, as a two-letter code, so the site shows what applies there. Kept for 180 days. - Where you came from (
billr_src): one word, such as “google” or the name of a link, so we know which channel brought you if you make an account. Nothing about you as a person. Kept for 7 days.
That is also why you have not been shown a consent banner: these cookies make the site work and say nothing about who you are. Signing out removes the session cookie, and clearing site data removes them all.
E-mail we send
- Sign-in codes, when you ask for one.
- Service e-mail, such as a receipt for a payment or notice of an important change to this notice or the terms.
- Invoices you send from Billr to your own clients. These go out on your behalf, with your name in the message.
An invoice e-mail sent from Billr contains a small tracking image so the app can tell you when your client opened it. That signal is shown only to you, is tied to your invoice, and is not used to build any profile of the recipient. Many mail clients block it, so treat it as a hint rather than proof. If you would rather not use it, download the PDF and send it from your own mailbox instead.
We do not send marketing e-mail to your clients, and we do not sell their addresses.
Who else sees it
Billr uses a small number of service providers to run the product, each processing data only on our instructions and only for the purpose described:
- A hosting and database provider, to run the application and store your data.
- An e-mail delivery provider, to send sign-in codes and the invoices you send.
- A payment provider, to take payment for paid plans and hold your card details.
- A Peppol access point, to send and receive e-invoices when you switch that on. Registering your business on the network includes an identity check of the person who does so, carried out by that provider.
The current list of providers, and the countries they operate in, is available on request from the contact address above. Where data is transferred outside the UK or the European Economic Area, it is covered by an appropriate transfer mechanism. We do not sell personal data, and we do not share it with advertisers.
How long we keep it
- Account and invoice data: for as long as your account exists. Invoices are business records. We will not quietly delete them for you.
- Sign-in codes: until used or expired, a matter of minutes.
- Technical logs: a short rolling window, then discarded.
- After you delete your account: your data is removed from the live system immediately and drops out of encrypted backups within about thirty days. Records we are legally required to keep, such as our own invoices to you, are retained for the statutory period.
Your rights
If you are in the UK, the European Economic Area or another jurisdiction with comparable law, you have the right to access your data, correct it, delete it, get a portable copy, restrict or object to processing, and complain to your data protection authority. Nothing here asks you to waive any of that.
Most of these are buttons rather than requests: your data is visible in the app, editable in the app, exportable in the app and deletable in the app. For anything that is not, write to the contact address above and we will answer within thirty days.
Data export and account deletion
Export. From your account settings you can export your invoices, clients and expenses as CSV, and download any invoice as a PDF. This is available on every plan, including the free one, and is not restricted when a paid plan ends.
Deletion. Also from your account settings, you can delete your account. This removes your invoices, clients, expenses, business details and e-mail address from the live system. It cannot be undone, so export first if you want a copy. Deleting your account also cancels any paid plan.
Deleting the browser draft is separate and entirely in your hands: press Reset in the generator, or clear site data for this domain.
Security
Traffic is encrypted in transit with TLS and data is encrypted at rest by our hosting provider. Sessions are signed and time limited. Access to production data is limited to the people who operate the service, and there is no password database to steal because there are no passwords.
No system is perfect. If you believe you have found a security problem, please write to the contact address above before disclosing it publicly, and we will work with you.
Changes to this notice
If this notice changes materially (a new category of data, a new purpose, a new kind of recipient), we will e-mail account holders before the change takes effect and update the date at the top of this page. Cosmetic edits and clarifications are made without notice.
Contact
Questions about this notice, or about the data Billr holds on you, go to the operator of the service.
The controller is the operator of Billr, established in Belgium, reachable at [email protected].
See also the terms of service, which cover what Billr does and does not promise, and pricing for what each plan includes.