Privacy Notice
Vidima is built so your invoices and customer data stay on your computer. This page describes — in plain language — exactly what leaves your device, what we store on our servers, and your rights.
TL;DR
Your invoices, customers, settings, and signing keys live on your device. By default they never leave it; if you enable optional Pro or Studio sync, they leave only as an end-to-end encrypted blob we cannot read.
Three things leave your device when Vidima is online: license activation (to enforce the device allowance included in your tier), update checks (so we can tell you when there's a new version), and payment (when you buy, handled by Stripe).
What we don't do: app telemetry, behavioural tracking, ads, third-party cookies or crash reports. The desktop app ships with none of that.
1. Who we are
This privacy notice is issued by Helvecraft, an LLC registered in the United States and operating in Switzerland. Helvecraft is the data controller for the limited data described below.
- Phone: +41 79 959 22 10
- Contact: info@helvecraft.com
- Products covered: the Vidima desktop application (Windows and macOS) and the websites
vidima.chandverify.vidima.ch
2. What stays on your device
Everything you create or import in Vidima — and we mean everything — is stored on your own computer in a folder under your user profile (on Windows: %APPDATA%/Vidima). That includes:
- Customers, suppliers, products and services
- Invoices, credit notes, payment reminders, drafts
- VAT settings (effective or flat-rate, AFC rates)
- Your signing key for the cryptographic seal on PDFs
- Automatic local snapshots (every ~6 hours) and any backups you export
- Your language and UI preferences
We have no readable copy of any of this. If you enable the optional sync (Pro/Studio), we hold only an end-to-end encrypted blob we cannot decrypt — see section 3. If your device fails and you have no backup or sync set up, that data is not recoverable from us — there is nothing readable for us to recover.
3. What leaves your device when you use online features
License activation and heartbeat — our license activation service
To enforce the device allowance included in your tier, Vidima sends, on activation and periodically thereafter:
- The complete signed key, transmitted over TLS for validation; the activation record retains only its hash. For delivery, resend or redemption, the signed key may also be retained in restricted operational purchase and redemption records.
- An opaque device identifier (derived locally with SHA-256). Versions currently in distribution may also transmit an optional device name; the service discards it and does not retain it.
Why: to count bound devices against the tier limit and offer a transfer when all seats are in use.
Stored: Cloudflare D1 database (vidima-activations), one row per bound device containing the key hash, opaque device identifier, and activation and heartbeat timestamps.
Legal basis (nFADP / GDPR Art. 6(1)(b)): performance of the licensing contract you accept when you activate Vidima.
Update checks — our update service
When Vidima starts (and roughly once a day after that) it asks our update server whether a newer version is available. The request includes:
- Your current Vidima version
- Your operating system and architecture
Why: so the app can tell you that 1.0.27-beta is out and offer the download.
Stored: the response is computed on the fly. The request itself is logged by Cloudflare for security and abuse prevention (typical edge-log retention, IP truncated).
Opt-out: you can disable the auto-updater in the app's settings. When you install Vidima from the Microsoft Store, the updater is disabled automatically (the Store handles updates).
Multi-device sync — optional, end-to-end encrypted (Pro & Studio)
Sync is off by default and available only on the Pro and Studio tiers. If you turn it on, here is exactly what happens to your data:
- Vidima derives an encryption key on your device from a secret only you hold (and your recovery code). That key never leaves your devices and is never sent to us.
- Your data is encrypted on the device before it is uploaded. What reaches our relay is an opaque encrypted blob — we store the content only as ciphertext.
- Because we never have the key, not even we can read your data (zero-knowledge). The relay's only job is to pass that encrypted blob between the devices on your own licence.
- Your other devices download the blob and decrypt it locally with the same key, so they stay up to date automatically.
Why: to keep your invoices and configuration in step across your machines without ever handing your readable data to anyone — including us.
Stored: encrypted blobs on Cloudflare R2. D1 holds the minimum pseudonymous protocol metadata needed to coordinate them: a licence hash, opaque device IDs, a server-generated network generation, the designated primary device, version and timestamps, ciphertext size and integrity hash, and short-lived operation leases. We store no plaintext, decryption key, device name, raw IP address or User-Agent for sync. A keyed HMAC used for abuse rate-limiting expires within about 10 minutes.
Your controls: leaving sync off uploads nothing. Disconnecting one device removes that device's active binding but keeps the shared encrypted network for your other devices. The primary device's separate, double-confirmed “End synchronization” action deletes all encrypted blobs and active network/device/operation metadata. A content-free termination receipt is retained for up to 180 days so retries from older app versions cannot affect a newly created network.
PDF verification — verify.vidima.ch
Every invoice PDF you generate carries a small QR code in the footer that points to verify.vidima.ch. When your customer (not you) scans it, the verifier shows them: who issued the invoice, when, the amount, and whether the PDF is authentic.
What goes into that QR: only what you put there — issuer, date, amount, and the ECDSA signature. No customer-side data is collected when someone verifies; the QR contains its own payload.
Stored: nothing about the verifier visit is retained beyond standard edge logs.
Payment — Stripe
When you buy a Vidima license, you are redirected to a Stripe-hosted checkout page. Your card data goes directly to Stripe — Helvecraft never sees it. Stripe is our sub-processor for payments.
What we receive from Stripe afterward: your email, your invoice address (for the tax receipt) and the fact that payment succeeded. We use that to issue your license key. See Stripe's privacy policy for what Stripe does with your data.
Website measurement — first-party and aggregated
On vidima.ch we keep daily aggregate counts for a small funnel: landing, pricing view, download intent and redirect, trial lead and app activation, checkout, paid or complimentary licence, Store link and feedback sent.
- No Google Analytics, advertising tracker or third-party analytics script is loaded.
- No raw IP address, user-agent, email, feedback message, full referrer URL or browser session identifier is stored in the measurement tables.
- A random identifier exists only in your tab's
sessionStorage. The server uses it transiently to create an HMAC deduplication key, then discards it; that key expires after 48 hours. - Campaign and referrer data is reduced to an allowlisted category. A random checkout-attempt reference is retained for at most 90 days only to reconcile the Stripe session.
- Browser-side measurement honours Global Privacy Control and Do Not Track. Necessary server records for an explicit trial, payment, licence activation or support action still apply.
4. What we do not collect
- The readable contents of your invoices, customers, products, or any document (if you enable sync, what we hold is end-to-end encrypted ciphertext we cannot read)
- Telemetry or behavioural analytics inside the desktop app, and raw browsing clickstreams on the website
- Crash reports (Vidima ships with no telemetry SDK)
- Third-party advertising trackers
- Cookies for behavioural profiling (the websites use only strictly necessary state)
5. Sub-processors
We rely on the following third parties to run the online parts of Vidima:
- Cloudflare, Inc. — Workers, R2, D1, Pages and CDN for our infrastructure. Cloudflare may log request metadata for security and abuse prevention.
- Stripe Payments Europe Ltd. — payment processing.
The Vidima desktop app itself has no other network calls than the ones listed above.
6. Where the data is stored
- Your device data: on your device. We have no readable copy.
- Sync data (only if you enable it on Pro/Studio): end-to-end encrypted blobs on Cloudflare R2/D1. We store ciphertext only and hold no decryption key, so we cannot read it.
- License activation records: Cloudflare D1, replicated across Cloudflare's global edge network.
- Payment data: Stripe's infrastructure (EU/EEA-based processing for European customers).
7. How long we keep things
- License activation row: while the device remains bound. It is deleted when that device is deactivated or displaced by a transfer.
- Update-check requests: not persisted by us. Cloudflare may keep edge logs for a short period per their policy.
- Optional sync: encrypted blobs and active protocol metadata remain while the network exists. “End synchronization” deletes them; its content-free retry receipt expires within 180 days. Operation leases and HMAC rate-limit entries expire within about 10 minutes. Abandoned empty networks with no active device are removed after 30 days.
- Payment records: retained by Stripe per their policy and by us for Swiss bookkeeping obligations (typically 10 years for tax records).
- Signed key and redemption record: for the validity of the licence and for as long as needed for delivery, recovery, revocation and support.
- Download and trial leads: deleted within 30 days after unsubscribing; otherwise no later than 24 months after the last interaction.
- Website measurement: anonymous daily aggregates for up to 24 months; transient deduplication keys for 48 hours; checkout-attempt and feedback receipts for up to 90 days.
- Support emails: as long as needed to resolve your request, plus reasonable archival.
8. Your rights
Under the Swiss Federal Act on Data Protection (nFADP, in force since 1 September 2023) and, where applicable, the EU General Data Protection Regulation (GDPR), you have the right to:
- Access — ask us what data we hold about you
- Rectification — ask us to correct anything inaccurate
- Erasure — ask us to delete your data (we can delete your license activation row; the data on your device is yours to delete from your own machine)
- Portability — receive your data in a portable format (your invoices already are: they live as JSON on your device and Vidima has built-in export)
- Object — ask us to stop processing in certain circumstances
- Lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC / edoeb.admin.ch) or your local EU supervisory authority
To exercise any of these rights, email info@helvecraft.com. We aim to respond within 30 days.
9. Children
Vidima is a professional invoicing tool intended for businesses and self-employed adults. It is not designed for, marketed to, or intended to be used by anyone under 18.
10. Security
Your data on your device can be protected by an optional session PIN, after which Vidima encrypts your state file at rest with AES-GCM. Our infrastructure runs on Cloudflare with TLS in transit and minimal stored data. We store only key hashes for activations; the complete signed key may be retained in operational purchase and redemption records when needed for delivery, recovery, and support.
If a security incident affecting your data occurs and the law requires it, we will notify you promptly.
11. Changes to this notice
If we materially change this notice, we'll bump the "Last updated" date below and, where appropriate, notify you the next time the app boots. Routine clarifications without substantive change won't trigger a notification.
12. Contact
Questions, requests, or just want to understand something better:
- Email info@helvecraft.com
- Phone: +41 79 959 22 10
idima