Trust · Proof as data
What we check, what we change, what we keep
No badges. The validator that runs, the rules it runs against, what leaves your file, what is stored and for how long, and what the public proof contains.
| Format | Ruleset version | Validator |
|---|---|---|
| XRechnung | 3.0.2 | KoSIT Validator 1.5.0, XRechnung configuration (XSD + Schematron) |
| EN 16931 | 1.3.11 | UBL/CII XSD + CEN EN 16931 Schematron |
| Peppol BIS Billing | 3.0.17 | UBL XSD + CEN EN 16931 Schematron + Peppol BIS Schematron |
| Factur-X | 1.0.07 | CII XSD + CEN EN 16931 Schematron + profile Schematron |
| FatturaPA | 1.2.2 | FatturaPA XSD + national rules |
| SimplerInvoicing | 2.0.3 | UBL XSD + SI-UBL rules |
| Belgian e-FFF | 3.0 | UBL XSD + e-FFF rules |
XRechnung files are checked with the same KoSIT validator German public-sector recipients use. Every change is followed by a new check; a file is only offered for download after it passes.
Your file is used only to check and fix your invoice and to deliver your result. Results are kept so you can download a verified file again for 90 days; validation logs are deleted after 90 days. You can request deletion at any time.
| Data | Retention |
|---|---|
| Uploaded invoices and results (XML/PDF) | Kept for your 90-day re-download window; deleted on request at any time |
| Validation and API logs | 90 days, then deleted |
| PDF/Excel extraction drafts | 24 hours, then deleted |
| Account data | Until you delete your account |
| API usage logs | 90 days |
Deletion requests: hello@invoicenavigator.eu. Full policy: Privacy policy.
Proven: this file passed this check at this time. Not proven: tax correctness or acceptance by the recipient. The proof contains no invoice content.
Signed evidence-pack certificates carry a key id; the public key is served at /.well-known/evidence-pack-keys.
| Service | Purpose | What it receives |
|---|---|---|
| Supabase | Database and sign-in (email one-time codes) | Results, hashes, account data |
| Vercel | Hosting; the checks run here | The uploaded file while it is checked |
| Stripe | Payment | Payment details; we never see the card |
| Resend | Transactional email | Your email address, the messages we send |
| Anthropic (US) | Reading fields from PDF, image, CSV and Excel on /convert; proposing values for missing mandatory fields on the checker | The uploaded file or the relevant part of the invoice |
| Upstash | Rate limits and daily spend counters | Counters keyed by IP; no invoice content |
| Sentry | Error monitoring | Stack traces; no invoice content |
| PostHog | Product analytics | Page and funnel events |
The checker itself does not send your invoice to Anthropic; only the converter and the optional proposal for a missing mandatory field do. All connections use TLS.