XOWE Privacy Policy

Effective date: 31 August 2026 Last updated: 4 September 2026 (your business profile is now also kept on our servers as a separate record, so that it survives a reinstall)

XOWE is an invoicing app for iPhone published by TivForge LLC, a limited liability company registered in North Carolina, United States ("TivForge", "we", "us", "our").

This policy explains what personal data XOWE and its supporting services collect, why we collect it, who we share it with, how long we keep it, and what rights you have.

For any privacy question or request, write to support@tivforge.com.


1. Two kinds of data, two different roles

XOWE handles two categories of personal data, and our role under data protection law is different for each.

Your data — we are the controller. Information about you as the person using XOWE: your business profile, your subscription status, how you use the app, your device. We decide why and how it is processed, and this policy governs it.

Your clients' data — we are a processor acting for you. The names, companies, addresses, email addresses, phone numbers and financial details you enter about the people and businesses you invoice. You decide what to enter and what to do with it; we store, render and transmit it on your instructions and for no purpose of our own. For that data you are the controller and we act for you under our Data Processing Addendum.

If you are subject to the GDPR or UK GDPR, entering another person's data into XOWE makes you responsible for having a lawful basis to do so and for informing that person about it — including that the document you send them may be delivered as a link hosted by us, and that they may receive payment reminder emails that we send on your behalf. Section 6 describes both.


2. There is no account, but there is an identifier

XOWE has no sign-up, no email login and no password. Instead, the first time you launch the app it generates a random identifier — the installation ID — and stores it in the iOS Keychain, together with a secret used to authenticate your device to our servers.

Two things you should know about it:

The same installation ID is used as your identifier in our analytics, in our crash reports and with our subscription provider (section 5). It is not derived from your name, your email address or any Apple identifier, and we do not use it to identify you anywhere outside XOWE.


3. What we collect

3.1 Your business profile

Your business name, address and contact details, any tax identifiers you enter, your website, your invoice and estimate numbering, your default currency and your tax rates. You enter this on your device, and it is what appears at the top of the documents you send.

Because your invoices and estimates are rendered into PDF on our servers, your business profile is transmitted to us and stored as part of each document you preview, send or sync. Your logo image is stored on our servers separately, so that it can be placed on every document without being re-uploaded each time. Your business name, address, contact details, website and default currency are also kept on our servers as a single, separate record, so that they come back if you reinstall the app; that record is replaced whenever you save your business profile, and it is erased with everything else when you delete your data.

3.2 Your clients' data — processed on your behalf

For each client you save: name, company name, email address, phone number, postal address and website.

For each invoice or estimate: the line items and their descriptions, quantities, unit prices, billing units, tax rates, totals and currency, the issue date, the due date or validity date, the document number, its status, and — where you send it — the date it was sent and whether it has been viewed or paid.

3.3 Contacts and photos

If you choose to import a client from your address book, iOS asks for your permission first and we read only the contact you select: its name, organisation, first email address, first phone number, first postal address and first website. Those fields are copied into your client list. We do not read, upload, index or retain your address book as a whole, and we never send it to our servers.

If you choose to upload a business logo, iOS asks for your permission and we receive only the image you pick.

You can refuse either permission, or withdraw it later in iOS Settings; the rest of the app continues to work.

3.4 Address autocomplete

When you type into an address field, the text you have typed is sent to the Google Places API so that it can return address suggestions. The request contains only the text of that field — never your client list, your documents or your identifiers. Google processes it as an independent controller under its own privacy policy.

3.5 Payments you receive

If you connect a Stripe account, we store the identifier of your connected Stripe account, the email address Stripe reports for it, and, for each payment link we create, its Stripe identifier, URL, amount, currency and status.

We never receive or store your customers' card numbers, bank details or any payment credentials. Those are entered on a page hosted by Stripe and go directly to Stripe, which acts as an independent controller for the payments it processes. See stripe.com/privacy.

3.6 Your subscription

Subscriptions are sold through Apple's App Store. Apple processes the payment; we never see your payment method. Our subscription provider RevenueCat receives your installation ID and the App Store transaction data needed to tell us whether your subscription is active.

3.7 Push notifications

If you allow notifications, we store the Apple push token for your device so that we can tell you when one of your invoices has been viewed or paid. You can withdraw the permission at any time in iOS Settings.

3.8 Analytics

When analytics are enabled, we send Amplitude a record of how the app is used: which screens you open, which features you use, documents created, sent, paid or declined, subscription and paywall events, and errors you encounter. Each event carries your installation ID, the app version and build environment, your iOS version, your device model, your app language, and your IP address, from which Amplitude derives an approximate country. City-level geolocation, Apple's Identifier for Vendors and your mobile carrier are switched off in our configuration.

Analytics never contain your clients' names or contact details, the contents of your documents, or the amounts on them. Where a count would be revealing, it is sent as a range rather than an exact number.

In the European Economic Area, the United Kingdom and Switzerland, analytics stay off until you switch them on. Elsewhere they are on by default. In both cases the switch is in Settings → Data & Privacy → Share Analytics, and turning it off stops the sending immediately.

We do not track you across other companies' apps or websites, we use no advertising identifiers, we show no advertising, and we share nothing with data brokers.

3.9 Crash reports

If the app crashes, Firebase Crashlytics (Google) receives a crash report containing the stack trace, the app version, your iOS version, your device model and state, and your installation ID, which lets us tell one user's repeated crash apart from many users' single crashes. Crash reports are not disabled by the analytics switch, because we rely on them to keep the app working.

3.10 Server logs

Our servers record each request they receive: date and time, IP address, user agent, the endpoint called, the response status and how long it took. We use these records to operate the service, investigate faults and detect abuse.

3.11 Support messages

When you use Contact Us, we receive the message you write, together with the app version, build environment and device information shown to you in the form before you send it. The message reaches us as email in our support mailbox. Nothing about it is stored in the app's database.


4. Why we use this data, and our legal basis

If you are in the EEA, the UK or Switzerland, the following are our purposes and our legal bases under Article 6 GDPR.

Purpose Legal basis
Running the app, storing and syncing your documents, clients, items and settings Performance of a contract with you
Rendering your documents into PDF and hosting the link you share with your client Performance of a contract with you; for the data about your client, we act as your processor on your instructions
Sending payment reminder emails to your clients, when you have enabled them We act as your processor on your instructions; you are responsible for the lawful basis towards the recipient
Creating Stripe payment links and recording their status Performance of a contract with you
Sending you push notifications Your consent, given through the iOS permission prompt
Managing your subscription and premium features Performance of a contract with you
Product analytics Your consent in the EEA, UK and Switzerland; our legitimate interest in improving the app elsewhere
Crash reporting Our legitimate interest in keeping the app working
Server logs, security and abuse prevention Our legitimate interest in a secure and available service
Answering your support messages Performance of a contract with you and our legitimate interest in supporting our users
Complying with law, and establishing or defending legal claims Legal obligation and our legitimate interest

Where we rely on legitimate interests, we have weighed them against your interests and rights and you may object at any time (section 9).


5. Who we share data with

We use the following service providers. Each receives only what it needs for its function.

Provider Function Role Location
InMotion Hosting Server and database hosting Processor Ashburn, Virginia, USA
Amplitude, Inc. Product analytics Processor USA
Google LLC (Firebase Crashlytics) Crash reporting Processor USA
Google LLC (Places API) Address suggestions Independent controller USA
RevenueCat, Inc. Subscription status Processor USA
Resend, Inc. Sending emails to your clients Processor USA
Apple Inc. App Store purchases; delivery of push notifications Independent controller for App Store purchases; processor for push delivery USA
Namecheap, Inc. (PrivateEmail) Our support mailbox Processor USA
Stripe, Inc. Card payments to your connected account Independent controller USA and Ireland

The current list of the subprocessors that touch your clients' data is maintained in Annex C of the Data Processing Addendum.

We may also disclose personal data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims. If TivForge LLC is acquired or merged, data may transfer to the acquiring entity, which will remain bound by this policy or give notice before changing it.

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months.


6. Links and emails we send to your clients

The share link. When you send an invoice or estimate, we create a page at xowe.tivforge.com/i/<token> where the recipient can view and download it and, if you created a payment link, pay it. The token is long and random and the page is excluded from search engine indexing, but anyone who has the link can open the page without any further check — it is a capability link, exactly like an unlisted file link. Treat it accordingly when forwarding.

Each link is valid for 180 days from the moment it is created. Sending the same document again issues a new link and invalidates the previous one.

Reminder emails. If you enable email reminders, we send the recipient of an unpaid invoice an email around its due date — up to three before it and three after — on your behalf and from our sending domain, with your business named as the sender. Every reminder carries a link that lets the recipient stop further reminders for that invoice. If an email hard-bounces or is reported as spam, we record that address on a suppression list for your installation and stop emailing it.

We send no marketing email to your clients and use their addresses for nothing else.


7. International data transfers

Our servers and all of our service providers are located in the United States. If you are in the EEA, the UK or Switzerland, using XOWE means your personal data is transferred to the United States.

For your own personal data, the safeguard depends on the provider. Where a provider listed in section 5 makes the European Commission's Standard Contractual Clauses available — with, for the United Kingdom, the ICO's International Data Transfer Addendum, and their Swiss equivalents — the transfer rests on those, together with the measures described in section 11. Where a provider offers no such mechanism, the transfer rests on being necessary to perform our contract with you (Article 49(1)(b) GDPR). We would rather say that plainly than imply a safeguard we do not have in place. Write to support@tivforge.com and we will tell you which mechanism applies to a particular provider and give you a copy of it where we hold one.

Where a transfer is to a provider acting as an independent controller (Google's Places API, Stripe, Apple), that provider is responsible for its own transfer mechanism under its own privacy policy.

For the data you process about your clients, our Data Processing Addendum incorporates the Standard Contractual Clauses (Module Two, controller to processor), the UK International Data Transfer Addendum and the Swiss equivalents, and applies them to that transfer.


8. How long we keep data, and how to delete it

Data Retention
Documents, clients, catalogue items, tax rates, business profile, logo, settings Until you delete them, or until you delete everything. We do not automatically delete the data of inactive installations.
Payment links and connected account records Until you delete everything, or until you disconnect Stripe
Push notification tokens Until you disable notifications or delete everything
Reminder and email suppression records Until you delete everything
Analytics events Until you delete everything, or you ask us to delete them
Crash reports 90 days, then deleted by Google
Server logs, including IP addresses 90 days
Support emails Kept in our support mailbox as ordinary correspondence, and deleted on request

Deleting everything. Settings → Data & Privacy → Delete All My Data erases, in a single operation, every record held for your installation on our servers: your documents, clients, catalogue items, tax rates, business profile, logo, payment links, connected account link, push tokens, reminder records, suppression records and numbering counters. Your installation is then closed permanently and its identifier cannot be reused. We also submit a deletion request for your installation ID to Amplitude so that your analytics history is removed.

Four things that deletion does not reach, for reasons outside our control:

Backups. We take a nightly backup of our database, encrypted before it is written to disk. A copy stays on the server for a few days and is retained for up to 30 days on storage we own and control in the United States; no third party holds it, and the key that decrypts it is kept apart from the backups themselves. Data you delete disappears from the live service at once, but a copy may persist in a backup until it is rotated out — 30 days at most. Backups are used only to restore the Service after a failure.

Deleting the app from your iPhone does not delete anything on our servers — see section 2.


9. Your rights

If you are in the EEA, the UK or Switzerland, you have the right to access your personal data, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time without affecting processing already carried out.

Some of these you can exercise yourself in the app: analytics consent through the Share Analytics switch, push notifications through iOS Settings, correction and erasure of any document or client by editing or deleting it, and full erasure through Delete All My Data.

For anything else, the surest route is Settings → Contact Us in the app: a message sent from there carries your installation ID to us automatically, so we can find your data without you having to know or type anything. You can also write to support@tivforge.com. We answer within one month.

Because there is no account, an email sent from outside the app does not by itself tell us which installation is yours. If we cannot identify it from what you send us, we will ask you for information that would let us — and where we genuinely cannot identify you, Article 11 GDPR allows us to say so rather than to guess. Sending the request from the app avoids this entirely. We will not use anything you send us for identification for any other purpose.

You also have the right to lodge a complaint with your data protection supervisory authority.

If you are the recipient of an invoice sent through XOWE and want to know about, correct or delete data held about you, please contact the business that invoiced you: they decide what is held and we act on their instructions. If you contact us instead, we will pass your request on to them and tell you that we have.


10. Notice for residents of US states

California

Under the California Consumer Privacy Act as amended by the CPRA, in the preceding twelve months we have collected the following categories of personal information, described in detail in section 3: identifiers (installation ID, IP address, push token, and the contact details you enter), commercial information (your documents, subscription and payment link records), internet or network activity (app usage, crash reports, server logs), coarse geographic location inferred from your IP address, and professional or employment-related information (your business profile). We collect them from you and from your use of the app, for the business purposes listed in section 4, and disclose them for those purposes to the providers listed in section 5.

We do not sell personal information and we do not share it for cross-context behavioural advertising. We do not knowingly collect or process the personal information of anyone under 16, and we therefore do not sell or share it. We do not use personal information to make decisions about you that produce legal or similarly significant effects.

You have the right to know, to delete, to correct, to opt out of sale or sharing (which we do not do), to limit the use of sensitive personal information (which we do not collect), and not to be discriminated against for exercising any of them. To exercise them, use Delete All My Data in the app or write to support@tivforge.com; we respond within 45 days and may extend once by a further 45 days where necessary. An authorised agent may act for you on presentation of written authorisation.

Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana and other states

If you live in a US state with a comprehensive privacy law, you have, to the extent that law gives them to you, the rights to confirm and access the personal data we hold about you, to correct it, to delete it, to obtain a portable copy, and to opt out of targeted advertising, of the sale of personal data and of profiling with legal or similarly significant effects — none of which we do. We do not use sensitive data, we do not profile, and we do not sell or share personal data, so there is nothing to opt out of; we honour opt-out preference signals such as Global Privacy Control regardless.

Exercise them the same way: Delete All My Data in the app, Settings → Contact Us, or support@tivforge.com. We answer within 45 days and may extend once where the law allows.

Appeals. If we refuse a request, we will tell you why. You may appeal by replying to that answer or by writing to support@tivforge.com with the subject "Appeal". A different person reviews it and we answer within 45 days, in writing, with our reasons. If we refuse the appeal, we will give you a link to submit a complaint to your state's Attorney General.

Many of these laws do not apply to personal data processed in a commercial or employment context. Where a law does not reach the data, we will still handle a request of this kind the same way — it is simpler than working out which rule applies to whom.


11. Security

Traffic between the app and our servers travels over TLS. Your installation secret is stored in the iOS Keychain and held on our servers only as a hash. Access to our production servers and database is limited to personnel who need it. Stripe payment credentials never reach us.

No system is completely secure, and we cannot guarantee absolute security. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the competent authority as required by law.


12. Children

XOWE is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 13 in the United States, or under 16 in the EEA and the United Kingdom. Our Terms of Use require you to be at least 18. If you believe a child has provided us with personal data, write to support@tivforge.com and we will delete it.


13. Changes to this policy

We may update this policy. The current version is always at tivforge.com/xowe/privacy with its effective date at the top. If a change materially affects how we use your personal data, we will publish it there with a new effective date at least 14 days before it takes effect and, where you have enabled notifications, send you a push notification; where the law requires consent we will ask for it in the app. Because the Service has no accounts and we hold no email address for you, that page is the authoritative record — check it if you have notifications switched off.


14. Contact

TivForge LLC 5144 Mabe Drive Holly Springs, NC 27540 United States support@tivforge.com

Privacy questions, data subject requests and complaints all reach us at that address and are handled as described in section 9.