Spoonbill logo — a pink spoonbill bird writing with its bill

Legal

Privacy Policy

Last updated: August 9, 2026

Spoonbill is an invoicing tool for freelancers and small businesses. This policy explains what personal data we process when you visit this site or use the Spoonbill app, why we process it, and the rights you have.

The short version: we store what an invoicing service needs to work — your account, your business profile, your clients and your invoices — and nothing else. No advertising, no tracking, no selling of data.

Who is responsible

Spoonbill is operated by DK Labs (Dzmitry Kandratsenka), Rua Miguel Araujo 141, 4425-177 Porto, Portugal (the "controller" in the sense of the GDPR). The fastest way to reach us about anything in this policy is the email address at the end of this page.

What we process

Account and sign-in. When you create an account we process your email address, your display name and the sign-in method you chose (Google, Apple, or email and password). Sign-in is handled by Google Firebase Authentication; if you use a password, it is stored by Firebase — we never see it.

Business data you enter. Your business profile (name, address, tax identifiers, bank details you choose to print on invoices), your clients and your invoices are stored so we can provide the service. Invoice PDFs are kept in our object storage so sent invoices stay unchanged.

Your clients' data. Names, addresses, email addresses and VAT IDs of your invoice recipients are processed on your instructions — to create invoices, email them, and send payment reminders you enable. When a recipient opens an invoice link, we record that the invoice was viewed so we can show you its status.

Emails we send. Verification codes, invoices, payment reminders and account notices are delivered through our email provider. We keep a record of what was sent to build the invoice timeline you see in the app.

Feedback. If you send feedback from the app, we receive your message and the contact email you provide. It is forwarded to our team inbox and our internal Slack channel so we can respond.

Server logs. Like every web service, our servers record technical access data (IP address, browser type, timestamps) to keep the service running and secure. Logs are kept briefly and are not used to profile you.

Cookies, storage and analytics

This website sets one strictly necessary cookie: NEXT_LOCALE, which remembers your language choice for a year. The app keeps you signed in using Firebase Authentication’s local browser storage. Neither asks for consent, because without them the service cannot do the thing you came for.

Beyond that we use Mixpanel to understand how Spoonbill is used. The two halves of Spoonbill handle it differently, and the difference matters, so here it is in full.

On this website Mixpanel runs only if you allow it. Until you choose, nothing is loaded and nothing leaves your browser — and if you decline, the Mixpanel script is never downloaded at all. We record which pages you open, which buttons you press and which FAQ entries you expand. You can change your mind whenever you like through “Cookie settings” in the footer, and a decline is remembered so we don’t ask again.

In the app Once you have an account, we record which features you use — invoices created, sent, paid or cancelled, clients and items added, settings saved, feedback submitted — so we can tell which parts of the product earn their place. This runs on our legitimate interest in improving a product you depend on (Art. 6(1)(f) GDPR); you can object at any time under Art. 21 with the switch in Settings → Privacy inside the app, which stops it for your account on every device you sign in on.

What we send Mixpanel is deliberately thin: counts, amounts, country and tax-regime settings, and which screen you were on. Your own email address is attached to your analytics profile, so we can recognise which account a problem belongs to and reach you about it — but never your clients’ names, never the text of invoice lines, never the wording of feedback. We also tell Mixpanel not to record your IP address from the app, and the Mixpanel project stores its data in the EU.

Session recording Mixpanel also replays browsing sessions for us, and the two halves differ again. On this website — if, and only if, you allowed analytics — the replay shows the pages as you saw them, because everything here is text we wrote ourselves. In the app the replay is masked: every piece of text and every form field is replaced by a grey block before anything is sent, so we can see where a screen confused someone without ever seeing an invoice, a client, an amount or your bank details. We do not record network traffic or the browser console in either case, and the client-facing invoice page is never recorded at all.

There are no advertising pixels and no cross-site tracking anywhere on the site or in the app, and we never sell what we collect.

Who else is involved

We use a small number of service providers (processors) who handle data on our behalf and under our instructions:

  • Google Ireland Ltd. / Google LLC — Firebase Authentication for sign-in.
  • Gcore (G-Core Labs S.A.) — runs the servers, database and object storage that hold your data; the infrastructure is located in the United States.
  • Our email delivery provider — sends verification codes, invoices and reminders.
  • Mixpanel, Inc. — product analytics and session replay; the project uses Mixpanel's EU data residency, on the website it only receives anything once you have allowed it, and in-app replays are masked before they are sent.
  • Slack Technologies — receives feedback messages only, so the team sees them quickly.

Where a provider processes data outside the EU/EEA — as with our US-hosted infrastructure — transfers are protected by the EU standard contractual clauses or an adequacy decision such as the EU-US Data Privacy Framework. We never sell personal data or share it for advertising.

How long we keep data

  • Account and business data: until you delete it or your account.
  • Invoices: until you delete them. Statutory retention duties for issued invoices (for example under tax law) rest with you — export your PDFs before deleting.
  • Server logs: a few weeks, then deleted or anonymized.
  • Feedback: as long as needed to follow up.

Your rights

Under the GDPR you can at any time:

  • request a copy of the data we hold about you (Art. 15),
  • have inaccurate data corrected (Art. 16),
  • have your data deleted (Art. 17),
  • restrict processing (Art. 18),
  • receive your data in a portable format (Art. 20),
  • object to processing based on legitimate interests (Art. 21),
  • withdraw any consent you have given (Art. 7(3)).

You also have the right to lodge a complaint with a data protection supervisory authority, for example the one at your place of residence.

How we protect data

All connections are encrypted in transit (TLS). Access to production systems is restricted, and your invoice documents are stored in access-controlled object storage. No method of transmission or storage is 100% secure; if a breach ever affects your data, we will notify you as the law requires.

Children

Spoonbill is a business tool and not directed at children. We do not knowingly process data of anyone under 16; if you believe a child has provided us data, contact us and we will delete it.

Changes to this policy

We will update this page when our data practices change and adjust the date at the top. For material changes we will notify you in the app or by email.

Questions?

Write to us — a person reads and answers every message.

[email protected]