Privacy Notice

Vidima is built so your invoices and customer data stay on your computer. This page describes — in plain language — exactly what leaves your device, what we store on our servers, and your rights.

TL;DR

Your invoices, customers, settings, and signing keys live on your device. By default they never leave it; if you enable optional Pro or Studio sync, they leave only as an end-to-end encrypted blob we cannot read.

Three things leave your device when Vidima is online: license activation (to enforce the device allowance included in your tier), update checks (so we can tell you when there's a new version), and payment (when you buy, handled by Stripe).

What we don't do: app telemetry, behavioural tracking, ads, third-party cookies or crash reports. The desktop app ships with none of that.

1. Who we are

This privacy notice is issued by Helvecraft, an LLC registered in the United States and operating in Switzerland. Helvecraft is the data controller for the limited data described below.

2. What stays on your device

Everything you create or import in Vidima — and we mean everything — is stored on your own computer in a folder under your user profile (on Windows: %APPDATA%/Vidima). That includes:

We have no readable copy of any of this. If you enable the optional sync (Pro/Studio), we hold only an end-to-end encrypted blob we cannot decrypt — see section 3. If your device fails and you have no backup or sync set up, that data is not recoverable from us — there is nothing readable for us to recover.

3. What leaves your device when you use online features

License activation and heartbeat — our license activation service

To enforce the device allowance included in your tier, Vidima sends, on activation and periodically thereafter:

Why: to count bound devices against the tier limit and offer a transfer when all seats are in use.

Stored: Cloudflare D1 database (vidima-activations), one row per bound device containing the key hash, opaque device identifier, and activation and heartbeat timestamps.

Legal basis (nFADP / GDPR Art. 6(1)(b)): performance of the licensing contract you accept when you activate Vidima.

Update checks — our update service

When Vidima starts (and roughly once a day after that) it asks our update server whether a newer version is available. The request includes:

Why: so the app can tell you that 1.0.27-beta is out and offer the download.

Stored: the response is computed on the fly. The request itself is logged by Cloudflare for security and abuse prevention (typical edge-log retention, IP truncated).

Opt-out: you can disable the auto-updater in the app's settings. When you install Vidima from the Microsoft Store, the updater is disabled automatically (the Store handles updates).

Multi-device sync — optional, end-to-end encrypted (Pro & Studio)

Sync is off by default and available only on the Pro and Studio tiers. If you turn it on, here is exactly what happens to your data:

Why: to keep your invoices and configuration in step across your machines without ever handing your readable data to anyone — including us.

Stored: encrypted blobs on Cloudflare R2. D1 holds the minimum pseudonymous protocol metadata needed to coordinate them: a licence hash, opaque device IDs, a server-generated network generation, the designated primary device, version and timestamps, ciphertext size and integrity hash, and short-lived operation leases. We store no plaintext, decryption key, device name, raw IP address or User-Agent for sync. A keyed HMAC used for abuse rate-limiting expires within about 10 minutes.

Your controls: leaving sync off uploads nothing. Disconnecting one device removes that device's active binding but keeps the shared encrypted network for your other devices. The primary device's separate, double-confirmed “End synchronization” action deletes all encrypted blobs and active network/device/operation metadata. A content-free termination receipt is retained for up to 180 days so retries from older app versions cannot affect a newly created network.

PDF verification — verify.vidima.ch

Every invoice PDF you generate carries a small QR code in the footer that points to verify.vidima.ch. When your customer (not you) scans it, the verifier shows them: who issued the invoice, when, the amount, and whether the PDF is authentic.

What goes into that QR: only what you put there — issuer, date, amount, and the ECDSA signature. No customer-side data is collected when someone verifies; the QR contains its own payload.

Stored: nothing about the verifier visit is retained beyond standard edge logs.

Payment — Stripe

When you buy a Vidima license, you are redirected to a Stripe-hosted checkout page. Your card data goes directly to Stripe — Helvecraft never sees it. Stripe is our sub-processor for payments.

What we receive from Stripe afterward: your email, your invoice address (for the tax receipt) and the fact that payment succeeded. We use that to issue your license key. See Stripe's privacy policy for what Stripe does with your data.

Website measurement — first-party and aggregated

On vidima.ch we keep daily aggregate counts for a small funnel: landing, pricing view, download intent and redirect, trial lead and app activation, checkout, paid or complimentary licence, Store link and feedback sent.

4. What we do not collect

5. Sub-processors

We rely on the following third parties to run the online parts of Vidima:

The Vidima desktop app itself has no other network calls than the ones listed above.

6. Where the data is stored

7. How long we keep things

8. Your rights

Under the Swiss Federal Act on Data Protection (nFADP, in force since 1 September 2023) and, where applicable, the EU General Data Protection Regulation (GDPR), you have the right to:

To exercise any of these rights, email info@helvecraft.com. We aim to respond within 30 days.

9. Children

Vidima is a professional invoicing tool intended for businesses and self-employed adults. It is not designed for, marketed to, or intended to be used by anyone under 18.

10. Security

Your data on your device can be protected by an optional session PIN, after which Vidima encrypts your state file at rest with AES-GCM. Our infrastructure runs on Cloudflare with TLS in transit and minimal stored data. We store only key hashes for activations; the complete signed key may be retained in operational purchase and redemption records when needed for delivery, recovery, and support.

If a security incident affecting your data occurs and the law requires it, we will notify you promptly.

11. Changes to this notice

If we materially change this notice, we'll bump the "Last updated" date below and, where appropriate, notify you the next time the app boots. Routine clarifications without substantive change won't trigger a notification.

12. Contact

Questions, requests, or just want to understand something better:

Last updated: 2026-07-12

Effective: 2026-05-23

Version: 1.0