In short: without an account, everything stays on your device. With an account, your data is encrypted on your device before it reaches us — so we never see it either way.
This is a courtesy translation. The legally binding version is the German privacy policy.
Everything you enter in Honorio — your own details, clients, price rules, invoices and the generated PDFs, plus trips for the mileage log and expenses with photographed receipts — is first stored exclusively in the app's storage on your device. Honorio works fully without an account; without one, none of this data leaves your device. If you create an account, the section Account and sync applies in addition.
If you use the import, Honorio asks for read access to your calendars. Events are processed on the device and do not leave it. Honorio writes nothing into your calendars and changes nothing there. The permission is only requested when you actually start an import — not on first launch.
If you enter the address of a calendar feed, the app fetches that address directly from your device. The connection is between your device and the provider you entered yourself. We are not involved and learn neither the address nor its contents.
The same applies to booking platforms such as Calendly or Acuity where you store an access key: the app calls them directly from your device. The access key is treated like any other content — it stays on the device and, if you use an account, is only synced in encrypted form. It is readable only by you.
An account is optional. If you create one, Honorio syncs your invoices, clients, trips, expenses and settings between your devices. All content is encrypted on your device (AES-256-GCM) first. The key is derived from your password and never leaves your device.
Our server therefore holds only:
From a record's type and timestamp one can tell that and when you logged, say, an expense — but not which. The content stays encrypted, photographed receipts included.
The legal basis is performance of the usage contract (Art. 6 (1) (b) GDPR). If you delete your account, this data disappears immediately and completely; there is no retention period.
Login attempts are logged with time, IP address and outcome for 14 days to prevent abuse (Art. 6 (1) (f) GDPR).
The server is located in Germany and operated by Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen) as a processor. Your data does not leave the European Union.
A share link places an encrypted bundle of your invoices on our server. The key sits exclusively in the fragment of the link — the part after the “#” — and browsers never send that part to servers. We cannot open the content. Anyone with the link can. If you revoke a share, the bundle is deleted; every share also expires after 90 days.
Then we cannot help you — not out of unwillingness, but because we cannot open the data. That is why you receive a printable recovery key when you create the account. Keep it like a spare key.
You can take out the Premium subscription in the apps or on this website. In the apps, billing runs through the App Store or Google Play; payment data is processed exclusively by Apple or Google — we never receive it.
On the website, Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Dublin, Ireland) handles the payment as payment provider. You enter your card details directly on Stripe's payment page; they never reach our server. We store a Stripe customer reference with your account and the state of your subscription. Stripe may also transfer data to its US parent company, based on the EU-US Data Privacy Framework. The legal basis is performance of the contract (Art. 6 (1) (b) GDPR). More in Stripe's privacy policy.
The site uses no cookies, no analytics and no embedded third-party content. When you access it, the web server processes technically necessary connection data (including the IP address) for delivery and abuse prevention. The legal basis is Art. 6 (1) (f) GDPR; the logs are deleted after a short time.
If you write to us, we process your message and sender address solely to reply (Art. 6 (1) (b) or (f) GDPR).
You have the rights to access, rectification, erasure, restriction, data portability and objection, plus the right to complain to the Austrian data protection authority. If you use Honorio without an account, we simply hold nothing about you; the rights then only concern any e-mail correspondence. With an account we can hand over your e-mail address, purchase status and the list of your records, and delete all of it — the content of the records, however, only as it sits with us: encrypted. You can export it readably yourself, any time, in the app.
Stefan Ischkum
Mannswörther Straße 63
2320 Schwechat, Austria
E-mail: info@honorio.eu
30 August 2026