Data & security

Last updated: 11 October 2026 · Invoice24 by Alphabet Technology, Jaipur, India

How Invoice24 stores, protects, keeps and deletes data – what happens on your device, in your Google Drive and on our server.

In short

  • Your workspace lives in your browser and, if you choose, your own Google Drive – not on our servers.
  • Set a login and everything is encrypted on your device with AES-256 before it is saved anywhere.
  • Export everything as a backup file, PDF or Excel at any time.
  • Delete it yourself in one click; we delete your account record within 30 days of a request.

1. Where your data lives

DataStored inWho can read it
Clients, projects, sales, quotations, invoices, letters, settingsYour browser on each device (IndexedDB)You, and anyone who can open your browser – unless you set a login
The same, syncedOne file in your own Google Drive (invoice-studio-data.json), if you turn sync onYou. Encrypted if you set a login.
Tax documents and attachments you addYour browser, and separate files in your Google Drive if sync is onYou. Encrypted if you set a login.
Optional auto-backupA file on your computer that you choose (Chrome / Edge)You
Your account record (if you sign in with Google)Our account serverYou and our support staff – see the Privacy policy

2. Encryption

  • With a login set, everything the app saves – browser storage, your Google Drive file, attachments and backups – is encrypted on your device with AES-256-GCM. Your password is turned into a key with PBKDF2 (310,000 rounds of SHA-256). Your password never leaves your device and is never stored.
  • With Continue with Google, our server keeps a random vault key for your account so that you can unlock your workspace on a new device. Your workspace itself is never sent to our server, so we can’t read it.
  • Without a login, data in your browser is not encrypted. Anyone with access to your computer and browser profile could open it, so set a login on shared computers.
  • All traffic to invoice24.in, Google and our account server uses HTTPS.

3. How long we keep things

WhatHow long
Your business dataAs long as you keep it. Deleted items stay in the app’s recycle bin for 30 days.
Your account recordWhile you use Invoice24; deleted within 30 days of your request
List of your recent devicesThe 10 most recent
Daily activity (which accounts opened the app that day)120 days
Account server backups14 days – so deleted records leave our backups within 14 days
Anonymous install counts (no sign-in)Until you ask us to remove them, or we stop needing usage counts
Web server access logsA limited time, for security and troubleshooting
Quotation approval linksNever stored – the quote lives inside the link

4. Export your data

  • Settings → Data & backup → Download backup (.json): your whole workspace in one file, which you can restore any time.
  • Invoices and quotations as PDF, and registers and reports as Excel or CSV, from the Invoices and Reports pages.
  • Your synced file is always in your own Google Drive.
  • For a copy of your account record, write to info@alphabettechnology.in.

5. Delete your data

  1. From this browser: Settings → Data & backup → Erase everything. Download a backup first if you might need it.
  2. From Google Drive: delete the file invoice-studio-data.json and any invoice-studio-doc-… files, then empty Drive’s bin. You can also remove Invoice24’s access in your Google account under Security → Third-party connections.
  3. From our server: email info@alphabettechnology.in from your account’s address and ask us to delete your account. We delete it within 30 days, and it leaves our backups within a further 14 days.

6. Who processes data for us

ProviderRoleData
Our hosting providerRuns the server for invoice24.in and the account serverAccount records and web server logs
GoogleSign-in, and Drive storage you chooseSign-in details; your encrypted workspace file in your own Drive
Google (Tag Manager, Analytics)Website analytics on public pages, with your consentPages viewed and browser details – never anything from the app

7. How we protect our servers

  • The account server stores no invoices or client data, so there is very little to steal.
  • Google sign-in tokens are checked against Google’s public keys, audience and expiry. Sessions are signed tokens.
  • Admin passwords are stored only as scrypt hashes. Admin sessions use a secure, HTTP-only cookie, and admin changes need an extra header against cross-site requests.
  • Sign-in attempts are rate-limited, and an admin email is locked for 15 minutes after repeated wrong passwords.
  • Security headers protect the site against being framed by other sites and force HTTPS.
  • Every update runs automated sign-in, admin and abuse tests before it is deployed.
  • Dependencies are checked for known vulnerabilities and kept up to date.

8. If something goes wrong

If we learn of a security incident affecting personal data we hold, we will contain it, inform affected users and the Data Protection Board of India as required by law, and explain what happened and what we are doing about it.

9. Report a security problem

Found a vulnerability? Please email info@alphabettechnology.in with the subject “Security report” and give us a reasonable time to fix it before telling others. Please don’t access other people’s data or disrupt the service while testing. We appreciate responsible reports.

Questions or requests

Write to info@alphabettechnology.in. We reply within 7 days and resolve requests within 30 days.