Privacy Policy
Last updated: September 9, 2026
1. Who we are
INVOX ("we", "us") operates the invoice processing platform available at app.invox.lt(the "Service"). The Service is used by accounting firms and their clients to digitize, verify, and export invoice data. For any privacy question or request, contact us at support@invox.lt.
2. Data we collect
- Account data: name, email address, password (stored hashed), role, and firm membership.
- Invoice documents and extracted data: invoice files you upload, email to us, or sync from Google Drive, and the structured financial data extracted from them (supplier and buyer details, dates, line items, VAT amounts, totals).
- Usage and audit data: actions taken in the Service are recorded in an audit trail for security and accountability, along with technical logs (IP address, browser type, timestamps).
- Cookies: we use cookies for authentication and, with your consent, analytics. See the cookie banner for choices.
3. Google user data
Google Sign-In. If you sign in or register with your Google account, we receive your name, email address, and profile picture from Google (the openid email profile scopes). We use them only to create and identify your INVOX account and to show your name in the Service. You can unlink your Google account in your profile settings at any time; we then delete the stored Google account link.
Google Drive.If you connect the optional Google Drive integration, INVOX requests access to Google Drive via Google's OAuth consent screen. We use this access exclusively to provide the features you configure:
- Drive read access is used only to list and download invoice files from the specific folder(s) you select for automatic invoice intake.
- Drive write access is used only to create processed invoice files and export documents in the folder(s) you select for delivery.
Invoice files retrieved from your Drive are stored in our encrypted document storage and processed through the same pipeline as manually uploaded invoices. OAuth tokens are stored encrypted (AES-256-GCM) and are never shared with third parties. We do not use Google user data for advertising, do not sell it, and do not allow humans to read it except with your explicit permission for support, where required for security or legal compliance, or as part of the human invoice review that is the core function of the Service.
INVOX's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect the Google Drive integration at any time in the Service settings, or revoke INVOX's access from your Google Account permissions. Upon revocation we stop all access immediately and delete the stored OAuth tokens.
4. How we use data
We process data solely to provide the Service: extracting structured data from invoices using AI vision models, verifying and reviewing it, exporting it in the formats you choose, and maintaining security and audit trails. Invoice content is sent to our AI processing providers only for extraction and is not used by us to train models. We do not sell personal data and do not use it for advertising.
5. Data sharing
We share data only with processors necessary to run the Service:
- Cloud hosting and encrypted document storage providers.
- AI model providers, strictly for invoice data extraction.
- Email delivery providers, for transactional email.
Within the Service, invoice data is visible only to your own accounting firm's authorized users and our reviewers. Data is never shared across client firms. We may disclose data where required by law.
6. Retention and deletion
Invoice documents and extracted data are retained for as long as your firm's account is active, as they form part of your accounting records. When an account is terminated, or upon a verified deletion request to support@invox.lt, we delete the associated data within 30 days, except where longer retention is required by law.
7. Security
Data is encrypted in transit (TLS) and at rest. Credentials and integration secrets are encrypted with AES-256-GCM. Access is role-based, scoped per client firm, and recorded in an audit log.
8. Your rights
If you are in the European Union, you have the rights provided by the GDPR: access, rectification, erasure, restriction, portability, and objection. To exercise them, contact support@invox.lt. You also have the right to lodge a complaint with your supervisory authority (in Lithuania, the State Data Protection Inspectorate).
9. Changes
We may update this policy from time to time. Material changes will be announced in the Service, and the "Last updated" date above will be revised.

