Start free with 10 invoices per month. No credit card required.

Privacy · updated 2 October 2026

How Costlr handles your information.

This notice describes current data handling and distinguishes available controls from retention and deletion work still being completed.

Information used by the service

Account information includes your name, email, profile image, sign-in/session information and workspace membership. Invoices can include supplier and customer names, addresses, line items, prices, tax and payment wording.

Costlr stores originals, extracted text, structured results, product mappings, corrections, price observations and usage records. Enabled email ingestion handles message and attachment information needed to route and process invoices.

Why this information is used

Information supports authentication, workspace access, invoice processing, price history, successful-invoice accounting and investigation of processing failures.

Optional invoice-result emails and paid daily digests use the verified owner email and saved preferences. Turn optional updates off in Settings → Notifications. Necessary sign-in and session storage supports account access.

Service providers

Clerk handles identity and sessions. Supabase stores relational data. Cloudflare R2 stores files; Cloudflare services handle ingestion and document processing. The configured DeepSeek adapter structures invoice text, and Brevo delivers enabled email updates.

Invoice content needed for extraction is sent to configured providers. Polar is the planned billing provider; live checkout is not yet available. Provider regions, transfer arrangements and provider retention settings require confirmation before this draft is finalized.

Access and sharing

Authorized workspace members can access workspace information. Invoice originals use authenticated, short-lived delivery. Optional digests can include temporary protected links to product thumbnails.

Only upload information you are authorized to provide. Avoid unrelated personal or sensitive information in invoices and support enquiries.

Retention and deletion

Original invoices remain associated with the owning workspace. Temporary raw email has a seven-day cleanup policy in the receiving workflow when deployed and configured; durable originals are separate.

Self-service deletion and a fully verified cross-store workspace deletion workflow are not currently available. Closing an account must not be assumed to erase invoices. No automatic deletion deadline for durable invoices is promised here.

Request current retention or deletion status through Contact. Do not send an invoice copy with the initial request.

Requests and updates

Edit available personal details in Settings → Account. Contact us for access, correction or deletion enquiries that cannot be completed in the app. Account authority must be verified before private data is disclosed or changed.

Applicable rights, legal bases, regulator details and statutory response periods will be documented once the operating entity and jurisdiction are confirmed. Updates will be reflected in the date above.