Invoice MakerUpdated October 5, 2026

Invoice Maker privacy policy

Effective October 5, 2026. Invoice Maker: Estimates & PDF is operated by Pondir Studio LLC. The app is in release preparation. Optional AI is not yet enabled for public use; the AI sections below explain how it is designed to work when made available.

Your documents stay on your device

Invoices, estimates, clients, saved items, business details, logos, payment records, historical versions and PDFs are stored in the app's local library. Manual tools do not require a Pondir account. The app has no advertising, cross-app tracking or third-party analytics SDK. Local usage counts remain on your device. Pondir does not receive your document library through normal manual use.

Exports, backups and reminders

You choose where to save or share documents and backups using Apple's Files and share sheet. Exports contain business and client information and are not encrypted by the app. Protect them and any copies you send. Apple's device backup services and your chosen destinations handle copies under their own policies. There is no app cloud sync for financial documents.

Optional owner reminders are scheduled locally with your notification permission. They do not send messages to clients. Turn them off in the app or iPhone Settings.

Apple subscriptions and secure access

Apple processes subscriptions and payment information. Pondir does not receive your card details. StoreKit verifies access to Pro. For optional AI, Pondir's service also verifies Apple subscription proofs and App Attest device assertions to prevent unauthorized use and enforce shared allowances. These proofs are never sent to the AI model.

AI ownership recovery uses an independent secret in Apple Keychain. A hash of that secret binds ownership to the Apple transaction. The secret may synchronize through iCloud Keychain, or you can explicitly export and import a recovery key. It is separate from document backups, is not forwarded to the model and is not persisted by Pondir's service. Protect an exported recovery key like a password.

Optional AI needs your consent

Before any AI request, the app asks for explicit consent to send the selected text and necessary facts to Pondir's service, OpenRouter and OpenAI. You can decline or withdraw consent in Settings and continue using manual tools. Opening an AI screen alone does not send a provider request.

Notes-to-document requests send the notes you submit and, when selected, saved item descriptions, units and prices needed to match your catalog. Polishing sends the chosen description. Message drafting sends placeholder fact keys; the app fills actual document facts locally. The model does not receive your whole library, contact fields, logos, bank instructions or Apple proofs. Text you type can itself contain personal or payment information, so review it before submitting.

Suggestions require your review. Missing prices stay blank. AI does not choose tax rates, calculate authoritative totals, issue invoices or send messages automatically. Accepted suggestions become part of your local document only when you apply them.

AI service records and retention

When optional AI is enabled, the service processes pseudonymous device and billing identifiers, subscription status, request identifiers, quota and cost counters, and security information derived from connection IP addresses. These support authentication, abuse prevention, allowance enforcement and retry recovery. The service is designed not to log request or response text. Its hosting provider, Railway, processes infrastructure data; the provisioned staging database is in the United States.

A successful result is encrypted temporarily for retry recovery, with a 90-second expiry and a two-minute retention limit. Request metadata is retained for seven days. Quota, cost and security records are retained for approximately 90 days, using calendar month boundaries for monthly counters. Inactive or expired device and entitlement records are removed after 90 days. Disconnecting AI access revokes that device's session and removes eligible recovery content; it does not reset shared usage or security history. These service and backup controls must be verified before public AI is enabled.

Provider processing

The intended route is OpenRouter to OpenAI, with restricted routing and requests that disable stored model responses. This does not mean zero retention. OpenAI's default abuse-monitoring logs may include submitted content and may be retained for up to 30 days, with legal or other stated exceptions. Provider processing and retention are governed by their policies and applicable account controls. Pondir cannot promise to erase provider-held records outside its control.

Read OpenRouter's privacy policy and OpenAI's API data controls before choosing AI.

Deletion and your choices

Erase All Data removes the app's local document library. It does not cancel an Apple subscription, delete files you exported or erase Apple backups. Cancel subscriptions in Apple Account settings. AI consent and ownership recovery are managed separately in Settings. For access, correction or deletion requests concerning Pondir-held service records or support correspondence, email dylan@pondir.com. Some records may need to remain for security or legal obligations; we will explain any applicable limits.

Support and this website

If you email us, we receive the information you choose to send and use it to answer your request. Avoid attaching private invoices or client information unless necessary. Visiting pondir.com is separate from using the native app and is covered by the Pondir website privacy policy, including its website analytics and consent settings.

Changes

We will update this page when practices change. Material changes to AI providers or data use require an updated in-app disclosure and consent before further AI requests.

Invoice Maker support · Terms of use