Privacy Policy
Last updated · May 11, 2026 · v1.0
This Privacy Policy describes how Factoo collects, uses, and shares your personal data when you use our mobile application and related services. It is drafted in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on Personal Data Protection (LOPDGDD).
1. Data controller
The joint controllers responsible for processing your personal data are:
- Controller: Naan Projects — Factoo application
- Natural persons responsible: Narciso Rubio and Antonio Angosto (individual developers, Spain)
- Contact email: naan.projects@outlook.com
- Jurisdiction: Spain (European Union)
2. Data we collect
2.1 Data you provide directly
- Account data: email address and hashed password on signup. If you use “Sign in with Google”, we receive your email and name from the provider (not your Google password).
- Issuer data: legal/trade name, tax ID (VAT/NIF), postal address, ZIP, city, country, phone, email, website, IBAN, BIC/SWIFT, logo and any other data needed to issue invoices on your behalf.
- Client data: identification and tax information about the persons or businesses you invoice, entered by you in the app. You are responsible for having a valid legal basis to process your clients' data (Article 6 GDPR); Factoo acts as a processor with respect to that data.
- Invoice content: line items, amounts, dates, payment methods, notes, and all content of invoices you issue or save as drafts.
2.2 Data collected automatically
- Usage data: anonymous events about how you use the app (screens visited, actions, templates selected, number of invoices issued). Collected via Firebase Analytics.
- Error logs: when the app crashes, we collect technical information about the error (OS version, device model, stack trace). Processed by Sentry (EU region).
- Android Advertising ID (AAID): when using the free version and viewing ads, AdMob uses your Android advertising identifier. You can reset or limit it in your device settings (Settings › Google › Ads).
- Subscription data: when you purchase a paid plan, RevenueCat and Google Play Billing process the transaction. We receive the product ID, period start/end dates, subscription status, and an anonymous customer identifier. We do not receive your payment card details — payment is processed directly by Google.
3. How we use your data
- Provide the service: create and manage your account, generate invoices with your data, store them and let you view or share them.
- Comply with legal obligations: retain issued invoices for the legally required period (5 years in Spain per Article 30 of the Commercial Code).
- Process subscriptions: activate your paid plan after purchase and properly reflect renewals, cancellations and expirations.
- Show ads (only on the free plan and to users who consented via the AdMob GDPR screen on first launch).
- Improve the product: analyze aggregated usage data to detect bugs, prioritize improvements and understand which features deliver most value.
- Detect and diagnose errors: send crash logs to Sentry to fix issues and maintain app stability.
- Service communications: send you transactional emails (account verification, password reset, critical notices). We do not send commercial emails without your consent.
4. Legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Provision of service (account, invoices, subscription) | Performance of a contract (Art. 6(1)(b)) |
| Retention of invoices for the legal period | Legal obligation (Art. 6(1)(c)) |
| Analytics (Firebase Analytics) | Consent (Art. 6(1)(a)) or legitimate interest in improving the product (Art. 6(1)(f)), depending on jurisdiction |
| Personalized advertising (AdMob) | Consent (Art. 6(1)(a)) — collected via UMP GDPR screen on first use |
| Error logs (Sentry) | Legitimate interest in ensuring service stability (Art. 6(1)(f)) |
| Transactional communications | Performance of a contract (Art. 6(1)(b)) |
5. Who we share data with
We work with the following processors and sub-processors. All are subject to data processing agreements compliant with Article 28 GDPR and provide equivalent data protection guarantees.
| Service | Purpose | Location |
|---|---|---|
| Supabase | Authentication, database, logo storage | EU (eu-west) |
| Sentry | Error and crash monitoring | EU (Frankfurt) |
| Firebase Analytics (Google) | Anonymous usage analytics | US (under DPF) |
| Google AdMob | Serving ads on the free plan | US (under DPF) |
| RevenueCat | Subscription and in-app purchase management | US (under DPF and SCCs) |
| Google Play Billing | Processing subscription payments on Android | US |
We do not sell your personal data and do not share it with advertisers on an individual basis. AdMob receives only anonymous advertising identifiers and contextual device data to serve ads — never your name, email or invoice content.
6. International transfers
Some of our providers (Google, RevenueCat) are located in the United States. These transfers rely on the following safeguards:
- EU-US Data Privacy Framework (DPF): Google and other DPF-adherent providers are recognized by the European Commission as offering an adequate level of protection.
- Standard Contractual Clauses (SCCs): where applicable, we sign the EU-approved standard clauses (Decision 2021/914) with our providers.
Supabase and Sentry store your data exclusively on servers located in the European Union.
7. Retention period
- Invoices and issuer data: 5 years from the issue date (Article 30 of the Spanish Commercial Code). Even if you delete your account, we retain invoices in anonymized form to comply with this legal obligation.
- Client data: until you delete it from the app or cancel your account. Soft-delete preserves referential integrity with invoices until the 5-year legal period expires.
- Account data: until you request deletion. We delete personal data within 30 days of the request, except data needed to comply with legal obligations (see above).
- Analytics data: up to 14 months (Firebase Analytics default).
- Error logs: 90 days (Sentry default).
8. Your rights
As the data subject, you may exercise the following rights at any time:
- Access: get a copy of the data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure (“right to be forgotten”): request deletion of your data, subject to legal retention obligations.
- Objection: object to processing based on legitimate interest.
- Restriction: request restriction of processing while a complaint is resolved.
- Portability: receive your data in a structured, machine-readable format.
- Withdrawal of consent: in consent-based processing (analytics, ads), you may withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise these rights, email naan.projects@outlook.com stating the right you wish to exercise and attaching a copy of your ID document so we can verify your identity. We will respond within one month.
If you believe your request has not been properly addressed, you may file a complaint with the competent supervisory authority. In Spain this is the Spanish Data Protection Agency (www.aepd.es).
9. Data security
- All communications between the app and our servers use TLS 1.2 or higher.
- Passwords are stored only as bcrypt hashes; no one at Factoo has access to your password in plain text.
- Databases are protected with Row Level Security policies: each user can only access their own data.
- Uploaded logos are stored in a private bucket and served via signed, time-limited URLs.
- Administrative access is restricted to the developer and requires two-factor authentication.
No security measure is absolutely foolproof. In the event of a security breach affecting your personal data, we will notify you without undue delay, in accordance with Article 34 GDPR.
10. Minors
Factoo is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you discover that a minor has provided us with data, contact us to remove it.
11. Changes to this policy
We may update this Privacy Policy to reflect changes in our practices or for legal, operational or regulatory reasons. We will notify you of material changes by email or via a prominent in-app notice before they take effect. The “Last updated” date at the top of this document always reflects the current version.
12. How to contact us
- Email: naan.projects@outlook.com