Privacy Policy
Effective Date: August 24, 2026
Last Updated: August 24, 2026
Operated by: Simple Labs Inc., a Canadian company
Privacy Officer: Alex Chiu, privacy@invisiple.com
1. Scope
This policy governs all Invisiple products and services, including our WhatsApp and Telegram integrations, our web application, and any future mobile applications.
2. What We Collect
Information you provide directly: your name, email address, phone number, business details (business name, entity type, region, industry), and the financial documents you send us (receipts, invoices, and related records) through WhatsApp, Telegram, email, or direct upload.
Information from connected accounts (optional): if you choose to connect a bank account, accounting software, or other financial tool, we receive transaction and account information from that provider for as long as the connection is active. For bank connections, this includes the amount, merchant or payee name, description, date, and currency of each transaction in the connected account, along with the category our banking data provider assigns to it. Section 7A explains where each of those goes.
Information generated from your activity: to power features like tax alerts and financial insights, our system derives categorized, summarized signals from your activity (for example, spending categories and patterns) rather than working from raw figures directly on our servers.
Information collected automatically: session and login information (including how you authenticated and when), IP address, and device/browser information, for account security and fraud prevention.
What we do not collect: we do not collect your bank login credentials or your payment card numbers. These are handled exclusively by our banking and billing partners and never pass through or touch our systems. We do hold an encrypted access key issued to us by our banking data provider, which we use to read transactions from an account you connected. It is not a password, you never give it to us, and we use it for nothing else. See Section 7A.
3. How Your Data Is Stored
Invisiple is built around a simple principle: your financial records belong to you, and they live in your own Google Drive, not on a central Invisiple server. When you connect your Google account, we create a dedicated, encrypted storage area inside your own Drive that only the Invisiple app can read or write to. We deliberately request the most limited Google Drive permission available (access only to files our app itself creates). We cannot see, and never request access to, the rest of your Google Drive, your email, or any other Google data.
Everything written to that storage area is encrypted before it ever leaves our systems, using industry-standard encryption. We also generate a set of human-readable working documents (such as expense and income summaries) in your Drive so you always have direct, plain access to your own records, independent of Invisiple.
Our own servers and databases are intentionally designed to hold as little as possible. Where we do keep records on our servers (for example, to detect duplicate submissions, maintain an audit trail, or support the app's day-to-day operation), we store hashes, category bands, timestamps, and pointers rather than the underlying sensitive detail itself. In practice, this means that even if our servers were ever compromised, an attacker would not find your exact transaction amounts, merchant names, or receipt contents sitting there in readable form.
Identifying information (such as who a record belongs to) and the sensitive content of a record are also kept separate from one another internally, using independently-held keys. This means that no single point of compromise is sufficient, on its own, to connect a piece of financial detail back to a specific person.
All data in transit between your device, our servers, and our service providers is encrypted using TLS. Where our systems process your information (for example, to read a receipt or route a message), that processing happens in an ephemeral layer: data exists only for the duration of the operation and is not retained afterward in that form, with your identifying information stripped out before that processing occurs wherever possible.
4. How We Use Your Information
We use your information to:
- process and organize your financial records (receipts, invoices, income, expenses, mileage,
- maintain your books and generate reports, summaries, and forecasts;
- detect relevant tax obligations and other financial triggers and alert you to them;
- authenticate you and keep your account secure;
- communicate with you about your account and respond to your requests; and
- improve and maintain the product.
debts, and related documents);
Summarized, categorized signals derived from your activity may also be used to train and improve our own forecasting and intelligence features. We do not use your information for advertising, and we do not sell your information to anyone.
5. Voice Notes
If you send Invisiple a voice note, it is transcribed entirely on our own infrastructure. Unlike other content, voice notes are never sent to any third-party service for processing.
6. Receipt Processing
To extract information from a photo of a receipt, that image is sent to a third-party optical character recognition ("OCR") service for text extraction. This is currently unavoidable for the product to function. The image is processed and is not retained by us outside of your own Drive vault once processing is complete.
7. Email Receipt Sync
If you choose to connect an email account, we request read access to that mailbox for the sole purpose of finding, extracting, and organizing the receipts and invoices sent to you. We do not request the ability to send email, delete email, or change your mailbox in any way, and we never access an email account you have not explicitly connected.
We currently support Gmail, Outlook and Microsoft 365, and standard IMAP for business email on your own domain. Each works differently in ways that affect you, so each is described separately below.
What we look at, and what we never fetch. For Gmail and for Outlook and Microsoft 365, the search that finds receipt emails runs at your email provider, not on our servers. We ask your provider for the messages that look like receipts or invoices, and messages that do not match are never sent to us at all. We do not download your mailbox, we do not build an index of it, and we do not read messages outside those results. Matching messages are processed by the same extraction pipeline described in Section 6. Content unrelated to receipts is not retained. As with photographed receipts, the extracted information is written to your own Drive vault as described in Section 3, and our servers keep only the limited, non-identifying records described there, plus the identifier your provider assigns to each message so that the same email is never filed twice.
Gmail. We use Google's official API with a single read-only mail permission and nothing else. You can disconnect at any time from Settings, which both deletes the credential we hold and revokes our access at Google, so access stops immediately and completely. You can also remove our access yourself at any time from your Google account's security settings.
Outlook and Microsoft 365. We use Microsoft's official Graph API with a single read-only mail permission and nothing else. Disconnecting in Settings deletes the credential we hold, and we stop reading your mailbox at that moment. There is one difference from Gmail that we want to be straightforward about: Microsoft does not provide a way for an application to cancel its own authorization. That means disconnecting inside Invisiple stops us from using the access, but the authorization record stays listed in your Microsoft account until you remove it there yourself. You can do that at any time from your Microsoft account's app permissions page. We cannot do it for you, and we would rather say so than let you believe otherwise.
Business email on your own domain (IMAP). Some business mail is hosted somewhere that does not offer the kind of secure, revocable connection Gmail and Microsoft do. For those accounts we connect using IMAP, which is the standard protocol email programs use. Connecting this way is different in several important respects, and you should understand them before choosing it:
- It requires storing a password. We ask for an application specific password wherever your
- IMAP has no read-only mode. Unlike the Gmail and Microsoft connections above, which are
- We cannot revoke it. Disconnecting inside Invisiple deletes our copy of the password and we
- We store it in a form that can be decrypted, because it has to be sent to your mail server
- If your mail server rejects the password several times in a row, we stop trying, disable the
provider offers one, because it can be revoked on its own without changing your main password. Where your provider does not offer one, the only option is your mailbox password.
limited to reading mail and cannot do anything else, an IMAP password is not restricted in what it permits. We only ever use it to read mail looking for receipts, but the password itself is not limited to that.
stop using it immediately. It does not and cannot cancel the password itself. To be certain the credential is dead, change it or delete it at your email provider. We recommend doing that as well as disconnecting.
on every check. It is encrypted at rest with a key held separately from the database, and it is decrypted only in memory at the moment of a check. It is never written to a log, an error report, or any other record. See Section 12.
connection, and tell you it needs to be reconnected. We do this so a changed password cannot turn into an indefinite series of failed sign-in attempts against your account. We cannot tell the difference between a routine password change and anything else, so we will only ask you to reconnect.
Because of the above, we recommend Gmail or Microsoft wherever your business email is hosted with them, including when your business uses its own domain. Many custom domains are hosted on Google Workspace or Microsoft 365 without the owner necessarily thinking of it that way, and we check for that when you connect so we can offer you the more secure option instead of IMAP.
Disconnecting. You can disconnect any email account at any time from Settings. This deletes the credential we hold for it and stops all future access by us, with the provider-specific limits described above. You can also reverse a specific connection's prior sync, which retroactively removes the receipts it contributed, subject to a short cooldown period to prevent abuse. Receipts you have already matched to a bank transaction, or that fall in a year you have exported an audit package for, are flagged for manual removal instead, so that your existing records stay intact. Nothing is erased outright: a reversed receipt is marked as reversed and kept, so your history stays complete.
Business mailboxes. We ask you to connect business mailboxes only, and not a personal account you also use for private correspondence. We cannot reliably tell the two apart, so this is a request rather than something we block: if the address you connect looks like a personal one, we will warn you and let you decide. If a personal purchase needs to be in your books, you can forward that one receipt to us instead of connecting the whole mailbox, which we think is the better choice.
7A. Bank Connections
Connecting a bank account is entirely optional. Invisiple works without it.
Your bank login stays with our banking data provider. When you connect an account, you sign in through our banking data provider, not through Invisiple. Your bank username, password, and any multi-factor codes are handled by that provider and never pass through or touch our systems. We never see them and we cannot store them.
What we hold is an access key that provider issues to us. We use it for exactly two things: reading the transactions in the account you connected, and reading the recurring payment patterns in that same account so we can spot subscriptions and loan payments for you. We do not use it to initiate payments, and it cannot reach any account you did not connect. It is encrypted before it is stored, with the encryption key kept in a separate system from the database it sits in.
Your transaction detail goes into your own Drive, not into our database. When a transaction arrives, the full detail, meaning the exact amount, the merchant name, the description, and the date, is encrypted and written into your own Google Drive vault before anything else happens. If that write does not succeed, we do not record the transaction at all, and it is retried on the next sync. There is no path by which a transaction is recorded on our servers but not in your Drive.
A plain, readable copy is also added to the expense spreadsheet in your own Drive, so you can always read your own records directly without going through Invisiple. That spreadsheet is your working document. Our app can read it back, because our app created it, and it does so to check for duplicates when the same purchase reaches us twice, for example once as a photo of a receipt and once as a bank charge.
What stays on our servers is deliberately partial. For each transaction, our own database keeps a record that does not contain the amount or the merchant name. Instead it holds:
- the transaction's reference number from our banking data provider;
- which business and which connected account it belongs to;
- the date and the currency;
- whether it was money in or money out;
- a spending range rather than a figure, for example "between $100 and $500";
- a one-way code derived from the merchant name, which lets us recognize that two transactions
- the spending category assigned by our banking data provider, and our own category for it;
- the processing status, and pointers back to the record in your Drive.
came from the same merchant without our database holding the name itself;
We keep the range and the one-way code, rather than nothing at all, because features like duplicate detection, recurring-charge detection, and loan-payment matching need to compare transactions to each other. They do that comparison without our database holding what you actually spent or who you actually paid. We should be straightforward about what that leaves: someone who obtained a copy of our database would not find your amounts or your merchants, but they would find the shape of your spending, meaning how often, in what rough size, in what category, and which merchants recur without knowing which merchants those are.
When a feature genuinely needs the real figures, for example to show you your books, it reads them from your Drive for the length of that request and does not write them into our database afterwards.
When we ask you to confirm something. Sometimes we will message you to ask whether a bank charge and a receipt are the same purchase. That question quotes the real merchant and amount, so that it can be understood. The stored copy of that question is encrypted at rest. Once you answer it, or once it expires, it is marked as settled and kept in that state rather than deleted, so there is a record of what was asked and what you decided.
Disconnecting a bank account. We are currently building a self-serve way to disconnect a connected bank account from within the app. Until that is available, email privacy@invisiple.com and we will disconnect it for you. Disconnecting stops any further transactions from reaching us. Records already created stay where they are: the detail in your Drive, which remains yours, and the partial records described above on our servers, subject to Section 10.
8. Sharing With Your Accountant
You can connect your own accountant to your account at any time from Settings → Accountant. Adding an accountant requires mutual consent: they must accept the connection before anything is shared, and you can remove them at any time from the same settings, which stops future access. This works whether or not your accountant separately uses Invisiple's accountant portal.
From the same settings, you control what your accountant receives (for example, a raw CSV ledger, a summary report, analyzed metrics, or alert history) and how they're notified when something is sent. A log of connection and sharing events is available for you to review.
Separately, Invisiple offers an accountant portal that accounting firms use to manage their clients' books directly (our Managed and Managed Plus plans). If an accounting firm invites you as a client, you'll receive a link by email that you must open and confirm before any of your financial records are shared with that firm. If you decline, don't respond, or later withdraw consent, the firm cannot access your records.
If you already have your own self-serve Invisiple account and separately connect an accountant who has their own Invisiple portal account, that accountant may additionally import you into their managed roster. This does not change or downgrade your existing self-serve plan or dashboard, it's a separate, additive relationship that the accountant, not you, is billed for. You'll be notified if this happens, and if the accountant later removes you from their roster, or your connection to them is otherwise revoked, you'll be notified and their billing for you stops on the next cycle.
Once you've granted any of the consents described above, a copy of your data is accessible to your accountant or accounting firm outside of Invisiple's direct control, subject to their own data handling practices, not this policy. You can withdraw your consent at any time, which stops future access, though it does not affect records already viewed or exported by them.
9. Who We Share Information With
We do not sell your information. Other than the accountant sharing described in Section 8 (which requires your explicit consent), we share information only with the service providers necessary to operate Invisiple, each of which is contractually restricted to using your information solely to provide their service to us:
- Google: for sign-in, the Drive storage described in Section 3, and, if you connect a Gmail
- Microsoft: if you connect an Outlook or Microsoft 365 mailbox, read-only access to that
- Your own mail provider, if you connect a mailbox over IMAP: in that case we connect
- A third-party OCR provider: for receipt text extraction, as described in Section 6.
- Our database and hosting providers: to run the application and store the limited
- Meta (WhatsApp) and Telegram: if you choose to communicate with Invisiple through those
- Our banking data provider: only if and when you choose to connect a bank account. That
- Accounting software providers: only if and when you choose to connect accounting software
- Our payment processor: to handle billing, if you are a paying customer.
account, read-only access to that mailbox as described in Section 7.
mailbox as described in Section 7. Microsoft is not involved in any other part of Invisiple.
directly to whatever mail server hosts your business email, using credentials you supply. We do not choose that provider and we have no relationship with them, so their handling of your mail is governed by their terms and not by this policy. See Section 7.
information described in Section 3.
channels, the relevant message content is transmitted through their platforms.
provider holds your bank login, connects to your bank on your behalf, and sends us the transaction information described in Section 7A. Your bank credentials stay with them and never reach us.
such as QuickBooks or Xero.
We may also disclose information if required by law, or in connection with a business transfer (such as a merger or acquisition), in which case we will notify affected users.
10. Data Retention and Deletion
Your Drive vault remains under your own control at all times. You can access, export, or delete those files directly from your own Google Drive independent of us, at any time.
We are currently building out a fully automated account deletion and data export process. Until that is complete, if you would like your account information deleted or exported, you can request this by emailing privacy@invisiple.com, and we will handle your request manually. We aim to complete deletion requests within a reasonable time and will confirm with you once complete.
We retain limited records (such as billing history and security audit logs) for as long as reasonably necessary for legal, accounting, tax, and security purposes, consistent with Canadian recordkeeping requirements.
Records retained even after account deletion. Certain records, specifically non-reversible hashes and audit-trail entries used to prevent duplicate processing and to maintain a security and compliance record, are retained for up to ten (10) years following account deletion, even where you have requested deletion of your account. This reflects Canadian recordkeeping obligations (a minimum of seven years under CRA requirements) as well as longer retention periods that may apply under other jurisdictions' recordkeeping laws. These retained records are not usable to reconstruct your financial detail on their own.
11. Your Rights
Subject to applicable law, you have the right to:
- request access to the information we hold about you;
- request correction of inaccurate information;
- request deletion of your account and associated information (see Section 10);
- withdraw any consent you've given, including consent to share data with your accountant (see
- file a complaint with the Office of the Privacy Commissioner of Canada if you believe we have
Section 8), where our use of your information relies on that consent; and
not handled your information appropriately.
To exercise any of these rights, contact us at privacy@invisiple.com.
12. Security
We take a defense-in-depth approach to protecting your information: encryption of data at rest and in transit, separation of identifying information from sensitive content, strict limits on what our servers store directly, and restricted access to the systems that hold your data. No system can guarantee perfect security, but if we become aware of a security incident that meets the threshold for notification under Canadian law, we will notify affected users and the relevant authorities as required.
13. AI-Generated and AI-Powered Content
Invisiple makes extensive use of artificial intelligence throughout the product and on our website. This includes AI systems that read and interpret your financial documents, generate categorizations, summaries, forecasts, alerts, and other content you see in the app, and that may power certain content on our website. Where content you interact with is generated or substantially shaped by AI, we disclose that here in accordance with applicable transparency requirements, including those under EU law. You should not treat AI-generated content, including tax alerts, forecasts, or summaries, as professional tax, legal, or financial advice; see also our Terms of Service.
14. Minors
Invisiple is intended for business use by adults and is not directed at, or intended for use by, anyone under the age of 18. If you believe a minor has created an account, please contact us at privacy@invisiple.com so we can address it.
15. Changes to This Policy
We will announce material changes to this policy at least 30 days before they take effect, by email or in-app notification.
16. Contact Us
Questions about this policy or your information can be directed to our Privacy Officer at privacy@invisiple.com, or general support at support@invisiple.com.