Security & recovery

Protect the document you are working on — and keep a recoverable copy when it matters.

InvoiceCraftly keeps ordinary editable documents on this device by default. Optional accounts and Personal Cloud backups are separate features. This page explains the security model, recovery limits, and checks to make before you rely on an exported invoice.

Last reviewed 28 August 2026 Editable documents stay on this device by default Personal Cloud backups are user-initiated
Working documents

Ordinary editing stays on this device

Invoice, client, line-item, payment, note, settings, and uploaded-logo data are stored in this browser during the normal editing workflow. An optional InvoiceCraftly account does not automatically upload those editable documents.

That limits the amount of invoice content held by InvoiceCraftly, but it also means a copy that exists only on one device can be lost if browser data is cleared, storage fails, or the device is unavailable.

Backup and recovery

Personal Cloud saves a backup when you ask it to

After you connect Google Drive or Dropbox, Back up now creates a recovery copy in your selected storage provider. This is not continuous synchronization and it does not mirror every edit automatically.

Restore replaces the current workspace only after you select a backup and confirm the action. Keep more than one important copy when your record-keeping process requires it.

Read the backup guidance
Optional accounts

Account access and document storage are separate

InvoiceCraftly supports optional account sign-in for account features such as Personal Cloud. Signing in does not turn the ordinary editor into an InvoiceCraftly-hosted document library.

Protect access to your Google account, Dropbox account, device, browser profile, and InvoiceCraftly session. Anyone who can access those environments may be able to access the information available there.

External services

Network features use separate service boundaries

Features such as company lookup, VIES checking, Smart Import AI extraction, Personal Cloud, analytics you have allowed, and submitted forms use external services or InvoiceCraftly service endpoints. The Privacy & Data Control page explains what is sent for each feature.

Review unexpected lookup or extraction results before using them. A public-registry result is useful source data, but it is not identity certification or a substitute for checking the customer and transaction details relevant to your invoice.

Exports

Review the finished document before sending

PDF, PNG, and SVG exports are visual documents. Check names, identifiers, dates, amounts, tax treatment, payment details, references, QR codes, and the final layout before sending or archiving them.

CSV is an editable data export, not a complete workspace backup.

Structured invoice export

EN 16931 / UBL XML export is available in beta

InvoiceCraftly can create an EN 16931-oriented UBL XML file from a supported invoice. Treat the current structured export as a beta workflow and run the formal validation required by your recipient or process.

Peppol, EHF, or other network delivery and recipient acceptance are separate from creating the XML file.

Main risks to plan for

Security also depends on your device and recovery process

  • Local data loss: browser storage can be cleared or become unavailable. Back up important work.
  • Device access: malware, a compromised browser profile, or another person with device access can expose locally available documents.
  • Cloud account access: backups in Google Drive or Dropbox depend on the security of that provider account.
  • Input accuracy: imported, looked-up, calculated, or AI-extracted details still need review before they become part of an issued document.
  • Record keeping: keep exported invoices and accounting records according to the requirements that apply to your business.
Practical security checklist

Before you rely on a document

  • Keep a recoverable backup of important editable work.
  • Verify payment destinations and scan payment QR codes before sharing them.
  • Review company identifiers and VAT/tax details against the source appropriate to the transaction.
  • Use formal structured-invoice validation when your recipient, accounting system, or delivery network requires it.
  • Protect the device and external accounts that hold your documents or backups.
Responsible reporting

Found a security or privacy concern?

Please avoid sending live invoice content, credentials, bank details, or other sensitive data in the initial report. Describe the affected page, browser, and safe reproduction steps instead.

Keeping this page current

Security guidance changes with the product

User-visible changes to storage, accounts, exports, recovery, and security boundaries are reflected here and in the public changelog.

View the product changelog
Create carefully

Create, review, back up, and export.

InvoiceCraftly gives you the document workflow; keep the recovery copies and checks your business needs.

Open invoice editor