Privacy Policy
This Privacy Policy informs you in accordance with Articles 13 and 14 of the General Data Protection Regulation (GDPR) about the processing of personal data when you use the service "Butterbill" (https://butterbill.app).
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
Johann Philipp Strathausen
Sole proprietor (freelance software developer)
Krachtstr. 8
10245 Berlin
Germany
Email: philipp@stratha.us
VAT ID: DE294406882
No data protection officer is required to be appointed by law. For all data protection matters you can contact the controller directly using the details above.
2. Overview of Processing
Butterbill is a chat-based invoicing application. Users create and manage invoices by chatting with an AI assistant; the application performs the actual calculations deterministically and generates PDF and e-invoices (ZUGFeRD/XRechnung).
We process personal data only to the extent necessary to provide the service. This concerns:
- Account data for registration and sign-in,
- content you enter, in particular invoice data, chat messages and uploaded files,
- technical data that necessarily arises when operating the application (e.g. server logs, essential cookies).
The following sections describe each processing activity in detail.
3. Categories of Data Processed, Purposes and Legal Bases
3.1 Account data
Data processed: email address, display name, timestamps (e.g. registration and sign-in times).
Purpose: creation and administration of your user account, authentication (sign-in via magic link), provision of the contractually agreed functions.
Legal basis: Art. 6(1)(b) GDPR (performance of the user contract or pre-contractual steps).
3.2 Content you enter
Data processed: invoice data including the names, addresses, VAT identification numbers and amounts of your own clients; chat messages; uploaded files (e.g. invoice PDFs).
Purpose: creation, management, calculation and output of invoices, and provision of the AI-assisted feature.
Legal basis: Art. 6(1)(b) GDPR (performance of contract). Insofar as your content contains personal data of third parties (your clients), please also refer to Section 10 (Processing on behalf of business customers).
3.3 Technical data / server logs
Data processed: IP address, timestamp and other technically necessary connection data that arise temporarily in the server logs.
Purpose: provision, security, stability and troubleshooting of the service.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security, availability and functionality of the service).
Retention: see Sections 9 and 11.
3.4 Sending invoice emails on the user's instruction
Data processed: recipient address (your client), invoice content and the metadata required for delivery.
Purpose: sending an invoice by email where you instruct Butterbill to do so via the approval-gated send function.
Legal basis: The send is carried out to perform the user contract with you, on your instruction, Art. 6(1)(b) GDPR. Any personal data of your clients processed in this context is processed solely on your instructions and on your behalf as part of processing on behalf of a controller under Art. 28 GDPR (see Section 10). The in-app approval required to send is a technical confirmation of your instruction and does not constitute data protection consent by the person affected by the delivery (your client).
3.5 The provider's own business records and statutory retention
Where the provider's own business records arise in connection with a paid subscription (Butterbill Pro) — in particular the provider's invoices to its subscribers and the associated accounting vouchers — the provider processes and retains these on the basis of Art. 6(1)(c) GDPR (legal obligation) in order to comply with tax and retention law (see Section 11). This retention concerns only the provider's own records, not the personal data that the provider processes merely as a processor on behalf of a user (see Sections 10 and 11).
4. Whether Provision of Data Is Required (Art. 13(2)(e) GDPR)
Providing your account data (email address, display name) and the content you enter to create invoices is necessary in order to use Butterbill. You are neither legally nor contractually obliged to provide this data; however, without it the user contract cannot be performed and the service cannot be provided. There is no obligation to provide data beyond this.
5. Cookies
Butterbill uses strictly necessary (essential) cookies only:
- a session cookie, required for sign-in and to maintain your session, and
- a locale cookie, which stores your chosen language.
These cookies are strictly necessary to operate the application. The legal basis is § 25(2) TDDDG (strictly necessary storage) in conjunction with Art. 6(1)(f) GDPR.
We do not use any analytics, tracking or advertising cookies and no third-party services for analytics or marketing purposes. Because only essential cookies are used, no cookie banner and no consent is required for the use of cookies.
6. Processors and Sub-Processors
To provide the service, we use carefully selected service providers that process personal data on our behalf and on our instructions (Art. 28 GDPR). Corresponding data processing agreements (DPA) are in place with all providers.
| Provider | Purpose | Location | Transfer basis / Safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of the application and PostgreSQL database (Falkenstein data center, EU) | Germany / EU | DPA under Art. 28 GDPR; no third-country transfer |
| Anthropic PBC | Provision of the Claude LLM (processing your chat messages and entered/uploaded content to generate assistant responses) | USA | European Commission adequacy decision based on the EU-US Data Privacy Framework (Art. 45 GDPR), as Anthropic is DPF-certified; additionally EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and supplementary measures; DPA; limited retention per Anthropic's API terms |
| Resend, Inc. | Delivery of transactional emails (magic sign-in links and user-initiated invoice emails) | USA | European Commission adequacy decision based on the EU-US Data Privacy Framework (Art. 45 GDPR), as Resend is DPF-certified; additionally EU Standard Contractual Clauses (Art. 46(2)(c) GDPR); DPA |
| Vercel Inc. | Blob object storage for uploaded documents, plus domain/DNS | USA | European Commission adequacy decision based on the EU-US Data Privacy Framework (Art. 45 GDPR), as Vercel is DPF-certified; additionally EU Standard Contractual Clauses (Art. 46(2)(c) GDPR); DPA |
7. International Data Transfers (Art. 44 et seq. GDPR)
The application servers and the database are operated in Germany (EU) with Hetzner; to that extent there is no transfer to a third country.
Some of the providers named in Section 6 (Anthropic, Resend, Vercel) are based in the USA. Each of these providers is certified under the EU-US Data Privacy Framework (DPF). Transfers of personal data to them therefore take place primarily on the basis of the European Commission's adequacy decision of 10 July 2023 pursuant to Art. 45 GDPR. In addition, we have agreed with these providers the Standard Contractual Clauses (SCC) pursuant to Art. 46(2)(c) GDPR adopted by the European Commission, together with appropriate supplementary measures (including encryption in transit and at rest, access restrictions and contractual assurances), which also apply should a provider fail to maintain its DPF certification. On request, for each recipient we will provide you with further information on the applicable basis and a copy of the appropriate safeguards.
8. Use of Artificial Intelligence (AI)
To provide the assistant feature, your chat messages and the content you enter and upload are processed by the Claude large language model operated by Anthropic PBC (see Section 6). This serves solely to generate assistant responses in the context of creating and managing invoices.
The content transmitted to the Claude API is used only to generate the assistant's responses and is not used to train Anthropic's models. This is consistent with Anthropic's commercial API terms and is secured in the data processing agreement (DPA) concluded with Anthropic; a limited retention period applies under Anthropic's API terms.
Solely automated individual decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you (Art. 22 GDPR) does not take place. The actual arithmetic (amounts, taxes, totals) is performed deterministically by the application itself and not by the language model.
9. Hosting and Server Logs
The application and database are operated by Hetzner Online GmbH in the Falkenstein data center (Germany, EU). When you access the service, log data arises temporarily on the server side, in particular IP address and timestamp. This data serves security, availability and troubleshooting purposes. The legal basis is Art. 6(1)(f) GDPR.
Log data containing IP addresses is deleted or anonymised/aggregated after 7 days at the latest. Longer storage occurs only insofar as it is necessary to investigate a specifically documented security incident; the data concerned is deleted as soon as the incident has been finally dealt with and no purposes preclude deletion.
10. Processing on Behalf of Business Customers (Art. 28 GDPR)
Because users store personal data of their own clients (e.g. names, addresses, VAT IDs) in Butterbill, we process that data solely on the instructions of and on behalf of the respective user. Towards business customers, the provider therefore acts as a processor within the meaning of Art. 28 GDPR; the controller for that data is the respective user. A data processing agreement (DPA) is offered to business customers on request.
Personal data that the provider processes solely as a processor on behalf of a user is deleted or returned on that user's instruction; the DPA governs its deletion and retention. In this respect the provider does not assert any retention obligations of its own under tax or commercial law. Statutory retention obligations of the provider concern exclusively the provider's own business records (see Section 11).
11. Retention Periods
We store personal data only for as long as necessary for the respective purposes. The following criteria apply:
- Account data: until you delete your user account.
- Chat messages and uploaded files: until you clear your conversation or delete your account.
- Server logs containing IP addresses: deleted or anonymised/aggregated after 7 days at the latest; beyond that only in the case of a specifically documented security incident, until it is resolved (see Section 9).
- Third-party data processed only on a user's behalf: deleted/returned on the user's instruction in accordance with the DPA (see Section 10).
Irrespective of the above, we retain the provider's own business records (in particular our invoices to Pro subscribers and the associated accounting vouchers) for as long as statutory retention obligations require. Pursuant to § 147(3) of the German Fiscal Code (AO), the retention period for accounting vouchers has been eight years since 1 January 2025 (previously ten years); for other records subject to retention, periods of six or ten years apply depending on the type. As the provider is a freelancer (Freiberufler) and not a merchant within the meaning of the German Commercial Code, commercial retention obligations under § 257 HGB do not in principle apply. Once the relevant periods expire, the data is deleted.
12. Your Rights as a Data Subject
Under the GDPR you have the following rights:
- Access to the data processed about you (Art. 15 GDPR),
- Rectification of inaccurate data (Art. 16 GDPR),
- Erasure (Art. 17 GDPR),
- Restriction of processing (Art. 18 GDPR),
- Data portability (Art. 20 GDPR),
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR),
- Withdrawal of a given consent with effect for the future (Art. 7(3) GDPR); the lawfulness of processing carried out before withdrawal remains unaffected.
To exercise these rights, an informal message to the contact details in Section 1 is sufficient. If your request concerns personal data that we process merely as a processor on behalf of a user (Section 10), we will refer you to the responsible user.
Right to lodge a complaint with a supervisory authority
Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The supervisory authority responsible for the controller is:
Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit)
Alt-Moabit 59–61, 10555 Berlin, Germany
13. Data Security
We take appropriate technical and organizational measures to protect your data. The transmission between your device and the service is encrypted via TLS (HTTPS). Access to data is limited to the purposes necessary to provide the service; every database query in the application context is scoped to the respective user session.
14. Changes to This Privacy Policy
We reserve the right to amend this Privacy Policy in order to adapt it to changes in the legal situation or to changes in the service and data processing. The current version published at https://butterbill.app applies. In the event of material changes we will inform you in an appropriate manner.