Privacy Policy
Last updated: June 2026
1. Who We Are
Atomic Works ("we", "us", "our") is a web-based invoicing platform for freelancers and small businesses, available at atomicworksinvoices.com. This policy explains how we collect, use, and protect your personal information. Contact: hello@atomicworksinvoices.com
2. Information We Collect
We collect the following information when you use Atomic Works:
- Account information: your name and email address, collected via Google OAuth when you sign up
- Invoice and business data: invoices, line items, client names and contact information, amounts, dates, notes, logos, and branding settings you enter
- AI-related data: invoice descriptions you submit for AI parsing, email samples used to match your writing tone for follow-ups, and generated draft content
- Payment information: subscription billing is handled by Stripe — we store Stripe customer and subscription identifiers, not your full card details. Client invoice payments are processed on your Stripe Connect account.
- Usage data: page views and feature usage via Vercel Web Analytics to improve the Service
- Communications: if you contact us by email, we retain that correspondence
We never collect Social Security Numbers (SSN). EIN and VAT numbers are optional, user-entered, and used only for display on your invoices.
3. How We Use Your Information
We use your information to:
- Provide and operate the Service
- Process subscription payments via Stripe
- Send invoices and payment reminders on your behalf (Pro tier)
- Generate AI-assisted invoices and follow-up emails via the Anthropic API
- Send transactional emails (payment confirmations, billing receipts)
- Respond to support requests
- Improve the Service through usage analytics
We do not sell your data. We do not use your invoice or client data for advertising. We do not share your business data with third parties except as described in Section 4.
4. Third-Party Services
We use the following third-party services to operate Atomic Works. Each has its own privacy policy:
- Supabase — database and file storage for profiles, invoices, and PDFs. Privacy Policy
- Stripe — payment processing for subscriptions and invoice payments. Privacy Policy
- Resend — transactional email delivery. Privacy Policy
- Anthropic — AI API for invoice parsing and follow-up drafts. Invoice text and writing samples are sent to Anthropic for processing. Privacy Policy
- Google — OAuth login ("Continue with Google"). Privacy Policy
- Vercel — hosting, infrastructure, and Web Analytics. Privacy Policy
5. Data Retention
We retain your data for as long as your account is active. When you delete your account, we permanently delete app data linked to your account, including profiles, clients, and invoices, subject to limited backup retention on our infrastructure providers. You may request a JSON export of your data from Settings before deletion, or contact us at hello@atomicworksinvoices.com.
6. Data Security
All data is encrypted in transit (HTTPS/TLS). Invoice PDFs are stored with access controls and served via signed URLs with short expiry — they are not permanently public, but anyone with a valid invoice link may view the invoice page. We use industry-standard security practices.
Despite these measures, no system is completely secure. We cannot guarantee absolute security of your data.
7. Your Rights
You have the right to:
- Access — request a copy of the data we hold about you
- Correction — request correction of inaccurate data
- Deletion — delete your account and data from Settings
- Export — download your invoice and client data as JSON before deletion
- Objection — object to certain uses of your data
To exercise any of these rights, contact us at hello@atomicworksinvoices.com. We will respond within 30 days.
8. GDPR (European Users)
If you are in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR), including data portability, restriction of processing, and the right to lodge a complaint with your local data protection authority.
Our legal basis for processing your data is: (a) contract performance — to provide the Service you signed up for; (b) legitimate interests — to improve the Service and prevent fraud; (c) consent — where you enable optional features such as AI follow-ups.
You may have the right to cancel a subscription within 14 days of purchase under EU consumer law, regardless of our standard refund policy.
9. CCPA (California Users)
If you are a California resident, you have the right to:
- Know what personal information we collect and how it is used
- Request deletion of your personal information
- Opt out of the sale of personal information
We do not sell personal information. To exercise your rights, contact us at hello@atomicworksinvoices.com.
10. Cookies and Analytics
We use essential cookies for authentication sessions (NextAuth). We use Vercel Web Analytics for aggregated page-view metrics. We do not use advertising cookies or sell data to ad networks.
11. Children's Privacy
The Service is not directed to anyone under the age of 18. We do not knowingly collect personal information from minors. If you believe a minor has provided us with personal information, contact us and we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the app. The "last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact
For privacy questions, data requests, or concerns, contact us at: hello@atomicworksinvoices.com
For EU users, if you are unsatisfied with our response, you may lodge a complaint with your national data protection authority.