Privacy

The privacy policy.

Updated · 2026-08-15

1. Who we are

Invice ("we") is an independent research project, operated by the person who builds it. We are based in Canada. Privacy questions: hello@invice.ai.

2. What data we collect

Account data you provide at signup. Documents you upload to your vault. The content of emails your agent sends and receives on the mailboxes you connect, kept as a bounded excerpt so the agent can act on a reply. Mission configurations and logs. API keys encrypted with AES-256, never stored in plaintext. Anonymized usage analytics.

3. How that data is used

Your data is used to run the missions you set up, and nothing else. Message excerpts and document text are passed to the AI model provider you connect, under your own key and that provider’s terms, so your agent can decide what to do next. We do not use your data to train AI models. We do not sell or rent it. We do not use it for advertising. Invice staff do not browse your mailbox, your vault, or your client records; access to production data happens only to operate the service or to resolve a support issue you raise.

4. How your API key is handled

Your AI model API key is encrypted using AES-256 before storage. It is decrypted in isolated memory only during your active session and immediately discarded afterward. It is never logged, never sent to third parties, and never accessible to Invice employees. You can revoke it at any time.

5. Document vault security

Uploaded documents live in a private, workspace-scoped store protected by row-level security. A file is reachable only by members of the workspace that owns it, enforced at the database layer on every request, and encrypted at rest by the storage layer. Invice extracts text from your documents and indexes it so your agent can retrieve the passages relevant to a task; that index is scoped to your workspace. Per-file application-layer encryption (a distinct key per document, held separately from the file) is on our roadmap and not yet live; we list it as planned rather than claim it as shipped.

6. Email integration

When you connect Gmail or Outlook via OAuth, Invice receives an access token limited to the scopes shown on the consent screen. Your agent uses it to read the messages it needs to act on and to send on your behalf during active missions. Message content is stored as a bounded excerpt, scoped to your workspace, and is passed to the model provider you have connected so the agent can interpret it. Disconnecting a mailbox deletes the stored token and ends Invice’s access. You can also revoke the grant directly in your Google or Microsoft account settings.

7. Google user data and Limited Use

Invice’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Your Google data is used only to deliver the features you switch on. It is never used for advertising, never sold, and never used by Invice to train any model. Where your agent needs a model to interpret a message, the relevant content is sent to the AI provider you have connected, under your own account and that provider’s terms; you choose that provider and can change or disconnect it at any time. Human access happens only with your explicit consent, to resolve a support issue you raise, for security purposes, or where the law requires it.

8. Retention

Active account data is retained for the duration of your subscription. Upon cancellation, your data is available for export for 30 days, then permanently deleted. Request deletion any time: hello@invice.ai.

9. Your rights (PIPEDA / GDPR)

You have the right to access, correct, or delete your personal data. Canadian users are protected under PIPEDA; EU/UK users under GDPR. Contact hello@invice.ai.

10. Changes to this policy

We notify you by email and in-app notice at least 14 days before any material change.

11. Data location and cross-border processing

Application hosting is pinned to Montreal (Vercel region yul1) and the database and file storage are configured in a Canadian region. Three flows leave the country and we name them rather than round them off. Your own model provider processes prompts under your API key and commonly runs in the United States. Vault embeddings run under our key and currently process in the United States (OpenAI); we are moving that flow to Cohere so it stays in Canada. A learning step that runs when a mission completes also processes the mission goal and short excerpts of mission emails under our key (Anthropic, United States); the contact names, email addresses and phone numbers it matches from your records are replaced with neutral placeholders before that content leaves Invice, and identifying details it does not match, including any typed inside a message, may still be included. This sentence is dated August 21, 2026 and will be removed when learning inference runs in a Canadian region. We are completing an end-to-end review of every remaining system that touches client data, including backups, replicas and logs, and we will state the full picture here once that review is recorded rather than describe it in advance. Each cross-border data flow is assessed and documented under Quebec’s Law 25 (s. 17); a summary is available on request.

12. Privacy Officer

For any privacy request or concern under Quebec’s Law 25, contact our Privacy Officer at hello@invice.ai.