Pilot legal pack, not counsel-approved. Controller: David Carvalhão. Placeholders like [PRIVACY_EMAIL] are intentional.
Privacy Policy (Invite-Only Pilot)
Who we are
Controller: David Carvalhão Product: Lighterate Contact for privacy: [PRIVACY_EMAIL] Postal address: Rua da Índia 4 - 3, 3080-137 Figueira da Foz Hosting region: European Union (Supabase eu-central-1 Frankfurt; web app server functions on Vercel in Frankfurt, fra1; background worker on Fly.io in Amsterdam). Exception: the AI invoice-extraction step uses a US-based provider and may involve processing outside the EU/EEA: see “AI invoice extraction” and “International transfers”.
This policy applies to the invite-only pilot of Lighterate (the “Service”). It also covers our public website and the pilot waitlist (see “Waitlist and public website”).
What the Service does
You sign in with Google or Microsoft. That login identity is tied to one mailbox of the same provider. With your authorization, we read that mailbox to find invoice PDF attachments, store those invoice PDFs and extracted fields, and notify you in the app when new invoices appear (no email push in this pilot).
To extract the fields, we send the text of each invoice (not the PDF file, and never email content) to an AI model through OpenRouter (see below). During onboarding you may optionally give us your name, your postal address, your NIF and a second NIF (each NIF with its country) so we can tell you apart from the invoice issuer and sort personal vs business invoices. You can skip this step.
Personal data we process
| Category | Examples | Source |
|---|---|---|
| Account / identity | Email address, display name from Google or Microsoft; language preference | Identity provider at login; language preference set by you in the app or taken from your browser |
| Terms and privacy acceptance record | When you accepted the Terms and Privacy Policy, which versions, the interface language, your browser user agent and your IP address at that moment | Our systems, when you tick the acceptance box |
| Optional onboarding details | Your full name; your postal address (address lines, postal code, city, country); your own NIF (tax number) and its country; an optional second NIF (a household member or a company) and its country | You, only if you choose to fill them in (skippable) |
| Mailbox connection | Encrypted OAuth refresh token; sync cursor; the address of the connected mailbox; opaque message/attachment identifiers; the date each email with an invoice was received (used to order syncing) | Your OAuth grant |
| Invoice files | Invoice PDF files only | Mailbox attachments we classify as invoices |
| PDF fingerprints | A technical fingerprint (a SHA-256 hash) of each PDF attachment we check, including attachments we determine are not invoices. Used only to avoid processing the same file twice; the hash cannot be used to reconstruct the file. For each attachment we check (invoice or not), we also keep an internal mailbox message reference (an opaque identifier from your email provider, not an email header) so we don't download the same attachment twice | Calculated by us from the PDF attachment; message reference from your email provider |
| Invoice text (for AI extraction) | Text extracted from the invoice PDF, kept as a text file next to the invoice PDF in our EU storage. It can include names, addresses, NIFs and similar details of you, of the invoice issuer and of anyone else shown on the invoice | Your invoice PDFs |
| Extracted invoice fields | Issuer/supplier name and tax number (may be a company or a natural person), customer name/NIF as printed on the invoice, amounts, dates, similar structured fields, and (when available) a personal/business label | AI extraction (see “AI invoice extraction”) and matching on our servers |
| Amounts you correct | Total, net amount, VAT and VAT breakdown that you enter after checking an invoice, which of them you changed, whether you confirmed the amounts as correct or confirmed dates we had flagged, and when, and the amounts as originally extracted (kept so you can restore them, and deleted when you do) | You, in the app |
| Public supplier reference data | Supplier company names and VAT/tax numbers from public sources (may include sole traders) | Public registries and public invoice data (see “Public supplier reference data”) |
| Technical | Auth session data; minimal operational logs (no email subject, body, or headers); request logs kept by our hosting providers, which include your IP address | Our systems and our hosting providers |
We do not store email subject lines, bodies, or headers in our database or logs, and we never send them to the AI provider. To find PDF attachments, our background worker briefly reads each email's structure in memory in the EU and discards the subject and headers immediately.
Microsoft accounts (pilot)
For Microsoft, this pilot supports personal Microsoft accounts only (Outlook.com / Live / MSA). Work or school Microsoft 365 accounts are out of scope for stage 1 (no admin-consent path).
Why we process data (lawful basis)
Under the GDPR (and Portuguese Lei n.º 58/2019):
| Purpose | Data | Lawful basis |
|---|---|---|
| Providing the Service you request: sign-in, read-only mailbox access, finding and storing invoice PDFs, avoiding processing the same file twice, AI extraction of invoice fields, letting you check and correct extracted amounts, background sync, in-app notices | Account, mailbox connection, invoice PDFs, PDF fingerprints, invoice text, extracted fields, amounts you correct | Article 6(1)(b) — necessary to perform the Service you request |
| Telling you apart from the invoice issuer and sorting invoices as personal or business | Your optional name, postal address, NIF and optional second NIF, with the country of each NIF | Consent — Article 6(1)(a). The fields are optional and skippable; you can withdraw at any time by editing or deleting them (saving all fields empty counts as withdrawal), with no effect on the core Service. Withdrawal does not affect processing done before it |
| Processing other people’s details that appear on your invoices (for example a sole-trader issuer) or that you enter as a second NIF with its country (for example a household member) | Names, NIFs and similar details of third parties | Legitimate interests — Article 6(1)(f): yours and ours in correctly organising invoices you already hold. Used only for matching and sorting |
| Matching invoice issuers against public supplier reference data | Public supplier names and VAT/tax numbers | Legitimate interests — Article 6(1)(f) (accurate supplier matching) |
| Security, abuse prevention and minimal operational logs | Technical data | Legitimate interests — Article 6(1)(f) |
| Keeping a record that you accepted the Terms and Privacy Policy, so we can show which version applied | Acceptance record | Legitimate interests (Article 6(1)(f)): being able to demonstrate the agreement and defend legal claims |
If we later ask for other optional choices (for example analytics), we will rely on consent (Article 6(1)(a)) and you can withdraw it as easily as you gave it.
No automated decisions with legal effects. We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you (Article 22 GDPR), and we do not profile you. AI-extracted fields and the personal/business label are organisational aids only; please review them.
Optional onboarding details (name, address and NIF)
- What: your full name, your postal address (address lines, postal code, city and country), your own NIF (in EU VAT format, for example
PT123456789) and its country, and optionally a second NIF (a household member or a company) and its country. All of these are optional and you can skip them. Only enter your own address. - Why: only to tell you (the invoice customer) apart from the invoice issuer during extraction and, when available, to sort invoices as personal or business. We do not use them for anything else, and we do not sell them.
- Where: stored in our database in the EU (Supabase, Frankfurt). The name, address, NIFs and tax-number countries you enter here are never added to the requests sent to the AI provider: we compare them with the extracted invoice fields on our own servers after extraction. However, the invoice text we send for extraction is the full text of the invoice, which may itself show your name, NIF and address as printed on it (see “AI invoice extraction”). If you entered your name or a Portuguese NIF (including a second Portuguese NIF) during onboarding, we automatically remove them from the invoice text before it is sent for AI extraction. This is best-effort: other details on the invoice (for example your address, a tax number from another country, a customer number printed without a label, or a differently formatted name) may still be sent. We do not remove your address from the invoice text.
- Second NIF: only enter another person’s NIF (and its country) if you are entitled to do so, and let that person know. A company NIF is usually not personal data, unless it belongs to a sole trader.
- Control: you can edit or remove them at any time; saving all fields empty withdraws your consent. They are deleted when you disconnect your mailbox or delete your account.
Sign-in and mailbox access (one step)
When you choose Google or Microsoft, we request sign-in and mailbox read-only access in the same OAuth consent. There is no separate mailbox-connect step in this pilot.
Mailbox access in plain terms
In that single consent you authorize read-only mailbox access so we can:
- Look for PDF attachments that look like invoices
- Download those PDFs for classification and extraction
- Keep an encrypted refresh token so a background worker can check for new invoices while you are offline
We only backfill up to 30 days of history from the moment you connect. PDFs that are not invoices are deleted immediately after classification; we keep only their technical fingerprint (see “How long we keep data”).
Where data is stored and who helps us (subprocessors)
| Subprocessor / recipient | Role | Location | Transfer safeguard |
|---|---|---|---|
| Supabase | Auth, database, private file storage (including optional onboarding details) | EU (eu-central-1, Frankfurt) | Not applicable (EU) |
| Fly.io | Background worker (mailbox sync, PDF text extraction) | EU (Amsterdam, ams) | Not applicable (EU) |
| Vercel Inc. | Hosts the web app and its server functions (sign-in session, acceptance record, app pages) | EU (Frankfurt, fra1) | Not applicable for the functions (EU). For any remote access or support from the US: Vercel Inc. is certified under the EU-U.S. Data Privacy Framework (checked 2026-09-29) |
| Google or Microsoft | Login and mailbox APIs | Per their terms; you choose the provider. Microsoft: personal MSA only in this pilot | Per their terms |
| OpenRouter, Inc. | AI API router: receives the invoice text and forwards it to the AI model | United States | Standard Contractual Clauses (Article 46(2)(c) GDPR) in OpenRouter’s Data Processing Agreement. Not certified under the EU–US Data Privacy Framework (checked 2026-09-29) |
| Microsoft Corporation (Azure OpenAI Service), engaged by OpenRouter as its sub-processor | Runs the model openai/gpt-4o-mini on a zero-data-retention endpoint. We require zero data retention and no training on every request; Azure is currently the only such provider OpenRouter lists for this model | Region not confirmed: may be processed in the United States or elsewhere outside the EU/EEA | Onward transfer under OpenRouter’s contractual safeguards (Standard Contractual Clauses in OpenRouter’s Data Processing Agreement). Microsoft Corporation is also certified under the EU–US Data Privacy Framework (checked 2026-09-29) |
Sign-in check at the edge: before a request reaches our Frankfurt functions, a lightweight sign-in check (your session token) runs on Vercel's global edge network, at the location nearest you.
We do not sell your personal data.
AI invoice extraction (OpenRouter / Microsoft Azure)
This is a proof-of-concept phase of the pilot.
- We extract the text from each invoice PDF on our own servers.
- We send only that invoice text to OpenRouter, Inc. (a US-based AI API router), which forwards it to the model `openai/gpt-4o-mini`. We require OpenRouter to use only zero-data-retention endpoints of providers that do not use our requests for training (currently Microsoft Azure). If no such endpoint is available, the invoice stays pending and its text is never sent to a provider that retains data. We do not send the PDF file, and we never send email subjects, bodies or headers.
- The model returns structured fields, which we store in the EU.
Please note:
- Invoice text can contain personal data — for example names, addresses and NIFs of you, of the issuer and of other people shown on the invoice.
- The invoice text is the full text of the invoice. It often shows the customer’s name, NIF and address as printed on it, so your name, NIF and address can reach OpenRouter and the model provider as part of the invoice text. The optional name, address, NIFs and tax-number countries you enter at onboarding are never added to these requests; we match them on our own servers.
- Best-effort removal: If you entered your name or a Portuguese NIF (including a second Portuguese NIF) during onboarding, we automatically remove them from the invoice text before it is sent for AI extraction. This is best-effort: other details on the invoice (for example your address, a tax number from another country, a customer number printed without a label, or a differently formatted name) may still be sent. We do not remove your address from the invoice text.
- Other details we remove: before we send the text, we also replace these details with placeholders, on a best-effort basis: electricity supply point codes (CPE), meter numbers, phone numbers, IBANs, email addresses, health-service user and case numbers, and customer, account, contract and similar numbers printed next to a label. The unmodified text stays only on our own servers in the EU. Details printed in an unusual format may still be sent.
- Processing may take place outside the EU/EEA, in particular in the United States (see “International transfers”). We therefore do not claim that all processing stays in the EU.
- Provider practices (as published by the providers at the date of this policy): OpenRouter states that it does not use inputs or outputs for model training and does not store prompt or response content unless the account holder opts in to logging. It stores request metadata (for example token counts and latency) and may sample a small number of prompts for anonymous categorisation that is not linked to our account. On every request we require OpenRouter to deny data collection (only providers that do not use our requests for training) and to use only zero-data-retention endpoints; OpenRouter lists the Microsoft Azure endpoints for this model as zero-data-retention. If none is available, the invoice stays pending; its text is never sent to a provider that retains data. We also keep prompt logging and OpenRouter’s use of inputs switched off in our OpenRouter account.
- AI output can be wrong. Please review extracted fields before relying on them.
- Amounts you correct: you can check an invoice's amounts against the PDF and correct the total, net amount, VAT and VAT breakdown, or confirm that they are correct. We mark changed amounts as corrected by you and, the first time you correct or confirm, keep a copy of the amounts as originally extracted, so you can see them and restore them; if you restore them, we put the original amounts back and delete the saved copy. Your corrections and confirmations are stored only with the invoice, in the EU. We do not send them to OpenRouter, Microsoft or any other AI provider, and we do not use them to train or tune any AI model or our extraction. Corrected amounts are your own entries; the invoice PDF remains the original document.
International transfers
Our own hosting (Supabase, Fly.io and Vercel's server functions in Frankfurt) is in the EU. Vercel Inc. is a US company; for any remote access or support from the US, it is certified under the EU-U.S. Data Privacy Framework (checked 2026-09-29). The AI extraction step involves transfers of invoice text to the United States and possibly other countries outside the EU/EEA (GDPR Chapter V):
- OpenRouter, Inc. is not certified under the EU–US Data Privacy Framework. We rely on the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914, controller-to-processor module), incorporated in OpenRouter’s Data Processing Agreement — Article 46(2)(c) GDPR.
- Microsoft (Azure) runs the model as OpenRouter’s sub-processor. The Azure region used is not confirmed, so the invoice text may be processed in the United States or elsewhere outside the EU/EEA. The onward transfer relies on OpenRouter’s contractual safeguards, including the Standard Contractual Clauses in OpenRouter’s Data Processing Agreement. Microsoft Corporation is also certified under the EU–US Data Privacy Framework (European Commission adequacy decision of 10 July 2023, Article 45 GDPR).
US law may allow public authorities to access data held by US companies. To limit this risk, we send only invoice text (never email content, and never the onboarding fields you enter, although the invoice text itself may show your name, NIF and address) keep optional provider logging switched off and use only zero-data-retention endpoints. You can ask for a copy of the relevant safeguards at [PRIVACY_EMAIL].
Vendor names that identify people
Extracted invoice fields may include a vendor or supplier name and tax number. That name can be a company or a natural person (for example a sole trader or freelancer named on the invoice). We store that field only to help you organize invoices. We do not use it to build marketing profiles or contact those vendors.
Public supplier reference data
We keep a reference table of supplier names and VAT/tax numbers taken from public sources (public registries and public invoice data), used only to match invoice issuers correctly. It is mostly company data, but sole traders (*empresários em nome individual*) are natural persons, so it may contain limited public personal data about them. We do not use it for marketing or to contact anyone. If you are listed and want an entry corrected or removed, or wish to object, contact [PRIVACY_EMAIL].
How long we keep data
| Data | Retention |
|---|---|
| Encrypted mailbox token + sync cursor | While your mailbox stays connected and your account is active |
| Non-invoice PDFs | Deleted immediately after classification (only the fingerprint below is kept) |
| Invoice PDFs + extracted fields | Until you disconnect the mailbox, delete your account, or ask us to erase them, and in any case no longer than 24 months from the date we stored that invoice (then auto-deleted). Amounts you correct, your confirmations and the originally extracted amounts are part of the invoice record and are deleted with it. The saved original amounts are also deleted as soon as you restore them |
| PDF fingerprints (SHA-256 hashes) | For invoices: kept with the invoice and deleted with it. For attachments that are not invoices: deleted after at most 24 months. All fingerprints are deleted when you disconnect your mailbox or delete your account |
| Invoice text sent for AI extraction | On our servers: kept as a text file with the invoice PDF and deleted with it (see “Invoice PDFs + extracted fields”). At OpenRouter: prompt content not stored (logging off). At Microsoft Azure: zero data retention (OpenRouter lists these endpoints as not retaining prompts). We do not use endpoints without zero data retention |
| Optional onboarding details (name, address, NIF, second NIF and their countries) | Until you edit or remove them, and in any case deleted when you disconnect your mailbox or delete your account |
| Public supplier reference data | While needed for supplier matching during the pilot; entries corrected or removed on request |
| Auth identity (email address, display name, language preference) | While your account exists (it is kept if you only disconnect your mailbox), then deleted with your account |
| Terms and privacy acceptance record | While your account exists (it is kept if you only disconnect your mailbox), then deleted with your account |
| Hosting providers' request logs (including IP addresses) | For the hosting provider's standard log retention period: Vercel (web app): about 1 hour on our current plan; Fly.io (background worker): about 7 days, according to each provider's published documentation. These periods can change if we change plan |
Disconnect and deletion
You can disconnect your mailbox in the Service. On disconnect we delete:
- the encrypted refresh token and sync cursor
- stored invoice PDFs and their extracted text
- extracted invoice rows and related sync state
- PDF fingerprints, including those of attachments that were not invoices
- your optional onboarding details (name, address, NIF, second NIF and their countries)
Disconnecting does not delete your account. We keep your email address, display name, language preference and your acceptance record until you delete your account.
You should also revoke the app in your Google or Microsoft account settings. You may request erasure of remaining account data by emailing [PRIVACY_EMAIL].
Your rights
You may request access, rectification, erasure, restriction, portability, and objection where applicable. In particular:
- Rectification: you can check and correct an invoice's amounts yourself in the app (see “AI invoice extraction”). For anything else, email us.
- Withdraw consent for your optional onboarding details at any time by editing or deleting them in the Service (or by emailing us). This has no effect on the core Service and does not affect processing before withdrawal.
- Object to processing based on legitimate interests — for example if you are a sole trader listed in our supplier reference data, or if a user entered your NIF as a second NIF.
- No solely automated decisions with legal or similarly significant effects are made about you (Article 22 GDPR).
To exercise your rights, email [PRIVACY_EMAIL]. We will reply within one month (Article 12(3) GDPR). You may lodge a complaint with the Portuguese supervisory authority CNPD (https://www.cnpd.pt) or another EU supervisory authority where you live or work.
Notifications (pilot)
New-invoice notices are in-app only (for example Realtime / status in the Service). We do not send email push notifications in this pilot.
Waitlist and public website
This section covers the public Lighterate website ([LANDING_HOST]) and its pilot waitlist. The controller is the same (David Carvalhão, see “Who we are”). Joining the waitlist does not create an account and gives us no access to your mailbox.
- What we collect: your email address (required), your first name (optional) and which mailbox you use, Gmail or Outlook (required).
- Why: to invite you to the pilot by email and to know which mailbox you use (for example, to tell you when Outlook is supported).
- Lawful basis: steps taken at your request before entering into a contract (Article 6(1)(b) GDPR), namely your request to join the pilot. If we use basic measures against spam and abuse of the form (for example, limiting repeated sign-ups), we rely on our legitimate interest in keeping the form secure (Article 6(1)(f)).
- Where it is stored: [WAITLIST_STORAGE: must be EU, e.g. Supabase EU]. Waitlist details are not sent to our AI provider.
- No newsletters: we never use your waitlist details for marketing newsletters unless you separately opt in.
- How long: we delete your waitlist entry when you join the pilot (from then on, the rest of this policy applies to your account), if you have not joined within 12 months, or when the pilot ends, whichever comes first.
- Removal: you can ask us to remove you from the waitlist at any time by emailing [PRIVACY_EMAIL]. Your other rights (see “Your rights”) also apply.
- Website hosting and server logs: the website is hosted by [LANDING_HOST]. Like any web host, it may record technical data when you visit (such as your IP address, browser type, the page requested and the time) in server logs, to deliver and protect the website (Article 6(1)(f)). These logs are limited to what the host keeps, and we do not use them to identify or profile visitors.
- No analytics or tracking: the website does not use analytics, advertising or tracking cookies and does not load third-party scripts. Its fonts are served from the website itself, not from Google Fonts or any other third party.
Cookies and similar technologies
The pilot uses strictly necessary cookies / local storage for authentication and security. If you choose a language with the “English · Português” switch at the bottom of the page, we also set one first-party cookie, lt_locale, that stores only that choice (en or pt) for up to 1 year, so that the app keeps showing your language. It is set only when you choose a language, contains no identifier, is not linked to your account and is not used for anything else. You can delete it in your browser at any time; the app then follows your browser's language. We do not use third-party analytics or marketing cookies in this pilot. If that changes, we will update this policy and obtain consent where required (Lei n.º 41/2004).
Security
Mailbox refresh tokens are encrypted at rest. Invoice PDFs are stored in a private bucket. Access is limited to your account. Invoice text is sent to OpenRouter over an encrypted connection. No security measure is perfect; please use a strong account with your identity provider.
Changes
We may update this policy for the pilot. Material changes will be notified to invitees in the app, and you will be asked to review and accept the updated policy at your next login. The 2026-09-29 update is a material change (AI extraction through OpenRouter with possible US processing, optional onboarding details, public supplier reference data). The 2026-09-29.1 update adds: the record of your acceptance (including IP address and browser user agent), your language preference, the connected mailbox address and email received dates, Vercel as a hosting provider (functions in Frankfurt; a sign-in check at the nearest edge location) and hosting log retention.
App URL (pilot)
This invite-only pilot app is served at https://lighterate.com (OAuth redirect https://lighterate.com/auth/callback). Access is by invitation only. Privacy and Terms are shown in-app at /privacy and /terms. Google OAuth brand/restricted-scope verification (which needs a public privacy URL on the same domain as the home page) is still pending.
Contact
Privacy questions: [PRIVACY_EMAIL]