Privacy Policy

Last updated: September 11, 2026

1. Introduction

Energy Invoice Matcher ("we," "our," or "us") operates the Energy Invoice Matcher web application (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this policy carefully. By using the Service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and a password. Your password is stored in a securely hashed format and is never stored or accessible in plain text.

Invoice Data

When you upload invoices for comparison, we process the PDF or spreadsheet files you submit to extract structured data such as invoice numbers, dates, amounts, line items, counterparty names, delivery locations, volumes, and pricing information. We use a tiered approach designed to retain as little as possible for as short a time as possible:

  • Raw documents. The files you upload are processed in memory and are not stored, unless you enable the optional "debug retention" preference in your account settings (off by default), in which case they are retained for up to 48 hours to help us investigate extraction issues, then automatically deleted.
  • Reconciliation data. The extracted transactions, matches, and discrepancies produced by a comparison exist only for the duration of that request and are discarded when you leave the results page — unless you explicitly create a share link, in which case that data is retained only for the sharing period disclosed at the time (currently 7 days), then permanently deleted.
  • Aggregate metadata. We retain non-identifying statistics about each comparison you run — such as the number of invoices, pages, and line items processed, match rates, discrepancy counts, processing time, error types, and AI usage cost — for longer-term reporting, auditing, and service improvement. This aggregate data does not include filenames, invoice numbers, counterparty names, or line-item commercial terms.
  • Shared link viewers. If someone opens a reconciliation you've shared via a link, we ask them to verify their email address with a one-time code before we show the results. We keep a record of that verified email address and which shared link it viewed — including after the link itself expires — so we know who has viewed a shared analysis. We do not add this email address to any marketing list or use it for outreach unless that person separately contacts us or creates an account.

Automatically Collected Information

We automatically collect certain technical information when you use the Service, including your IP address, browser type, and user agent. This information is used solely for session management and security purposes.

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process and compare your uploaded invoices
  • Authenticate your identity and manage your account
  • Send transactional emails (e.g., email verification, password resets)
  • Verify the identity of, and maintain a record of, people who view a reconciliation shared with them via a link
  • Monitor and improve the reliability and security of the Service

4. Third-Party Data Processing

OpenAI

To extract structured data from your invoices, we send the text content of uploaded PDFs to OpenAI's API for processing. Before transmission, we automatically redact sensitive financial information including bank account numbers, routing numbers, SWIFT/BIC codes, IBANs, and tax identification numbers. We do not send the original PDF files or images to OpenAI — only sanitized text content. OpenAI's use of this data is governed by their API data usage policy.

Invoice comparisons are performed entirely on our servers and are not sent to any third party.

Error Monitoring

We use Sentry for error monitoring to maintain the reliability of our Service. Sentry receives technical error reports when issues occur. Personally identifiable information is not sent to Sentry by default.

Email Services

We use third-party email providers to deliver transactional emails (such as email verification and password reset messages). These providers receive only your email address and the email content necessary to deliver the message.

5. Data Storage and Security

Your account data is stored on secure servers. Uploaded invoice files are processed in memory by default and are not written to disk. When you opt in to debug retention or create a share link, the corresponding files or reconciliation data are stored in a private directory that is not publicly accessible. We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

Your account is isolated from other users through multi-tenant architecture. You can only access your own invoices, comparisons, and data.

6. Data Retention

We don't permanently retain your invoices.

Source documents are automatically deleted within 48 hours (and, by default, are never stored at all). Reconciliation data — the transactions, matches, and discrepancies from a comparison — is temporary and deleted automatically unless you explicitly choose to share a reconciliation, in which case it is retained only for the sharing period disclosed at the time you create the link.

Verified email addresses of shared-link viewers are retained indefinitely as a record of who has viewed a shared analysis, even after the underlying share link expires and is deleted.

Aggregate, non-identifying metadata about your comparisons (counts, match rates, processing time, error types, AI usage cost) is retained longer-term as part of your account to support reporting and an audit trail of your usage. We retain your account information for as long as your account is active or as needed to provide you the Service. If you delete your account, we will delete your personal information and any retained invoice or reconciliation data within a reasonable timeframe, except where we are required to retain it for legal or regulatory purposes.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your personal information
  • Export your data in a portable format
  • Object to or restrict certain processing of your data

To exercise any of these rights, please contact us at the email address provided below.

8. Cookies

We use essential cookies required for the Service to function, including session cookies for authentication and CSRF protection tokens for security. On our public marketing and sign-up pages (before you log in), we also use Google Analytics to measure site traffic and where visitors drop off during sign-up. Google Analytics is not loaded anywhere in the authenticated application — it stops the moment you log in. We do not use advertising cookies or cross-site tracking.

9. Children's Privacy

The Service is not intended for use by children under the age of 18. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:

Email: privacy@energyinvoicematcher.com