Draft legal notice
Privacy Policy
Last updated: May 29, 2026
Invoice Wzrd is a tenant-ready invoice capture and workflow service. This draft policy is published so OAuth providers, trial users, and reviewers can understand what data the service is designed to collect and how that data is protected before production launch.
Information We Process
Invoice Wzrd may process account profile details, tenant membership details, connected mailbox metadata, uploaded invoice and receipt files, extracted document text, workflow decisions, audit logs, and billing status. When a user connects Microsoft 365 or Google Gmail, Invoice Wzrd requests read-only mailbox access for invoice capture.
How We Use Information
We use information to authenticate users, connect capture channels, ingest invoices and receipts, classify documents, support approval workflows, export approved records, measure usage, protect tenants, and provide support when a tenant grants access.
Google and Microsoft Data
Mailbox access is used only to find and ingest invoice-related documents into the same tenant-scoped pipeline used by upload, forwarding, and WhatsApp capture. Invoice Wzrd does not sell Google or Microsoft user data. OAuth refresh tokens are stored server-side and encrypted before persistence.
Tenant Isolation and Security
Production tenants are isolated from each other. Development and test data are kept separate from production. The service is designed to use tenant-scoped database access, encrypted secrets, signed OAuth state, webhook verification, audit logs, and redacted logging.
Sharing and Retention
We share information only with service providers needed to operate the product, comply with legal obligations, protect the service, or complete tenant-requested exports. Tenant data is retained for the active service relationship and deleted or exported according to the tenant's instructions and applicable law. Invoice Wzrd may retain its own billing, tax, security audit, legal-hold, and contracted archive records for restricted compliance purposes, but tenant supplier documents are not kept merely because the tenant may have its own tax retention duties.
Access, Export, and Erasure
Tenant users can request account export and erasure workflows. Erasure deletes or anonymizes account identity, authentication secrets, source connectors, tenant documents, and non-retained operational data after export where feasible. Backup copies expire through the backup lifecycle and deletion tombstones prevent erased tenants from being restored into active service.
Model Training Consent
Model training is opt-in and off by default. Invoice Wzrd does not use tenant documents, OCR samples, feedback, or classifier training examples for model training unless explicit consent is granted for the relevant scope and the data is de-identified.
Contact
For privacy questions, contact Plan-B Systems at mike@plan-b.systems.