Legal
Last updated March 29, 2026
This Privacy Policy describes how FilmInvoice (“we,” “us,” or “our”), operated by JJ Stratton LLC at filminvoice.app, collects, uses, and protects your information. This policy is incorporated into our Terms of Service.
We do not sell your personal information. We share information only in these circumstances:
Firebase
Authentication
Neon
Database hosting
Vercel
Application hosting
Resend
Email delivery
Lemon Squeezy
Subscription billing
OpenRouter
AI model access
We do not send your SSN, bank details, or other sensitive financial data to AI providers — only chat messages, uploaded images, and contextual information needed to generate responses.
AES-256-GCM encrypted at the application level
You have the right to:
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
To exercise any of these rights, contact us at support@filminvoice.app. We will verify your identity before processing your request.
We use industry-standard security measures including HTTPS encryption for all data in transit, HTTP-only cookies for authentication, and secure hosting infrastructure.
Sensitive financial data (SSN/EIN, bank routing and account numbers) is encrypted at the application level using AES-256-GCM with a 256-bit key before it reaches the database. The encryption key is stored separately from the database in a secure environment. A database breach would expose only encrypted ciphertext that is computationally infeasible to decrypt without the key.
Sensitive documents such as W-9s and invoices containing ACH details are generated on demand in memory and are not persisted as stored files. This means there are no cached PDF artifacts containing your SSN or bank details sitting in our storage.
However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
We use a single essential cookie (“AuthToken”) for authentication. We do not use tracking cookies, analytics cookies, or advertising cookies. The auth cookie is HTTP-only, secure, and expires after 12 days.
The Service is not intended for users under 18 years of age. We do not knowingly collect information from children.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service. The “Last updated” date at the top indicates the most recent revision.
Questions about this Privacy Policy? Contact us at support@filminvoice.app.