Privacy & data storage

Your invoice workspace stays in your browser.

A clear explanation of the current release, so you can decide what information belongs here.

Last updated September 26, 2026

What the app stores

When you import a CSV, add an invoice, or write a follow-up note, Orvaket stores that workspace in your browser's local storage on this device. The workspace can include customer names, invoice numbers, email addresses, amounts, dates, owners, blockers, and notes that you choose to enter. By default, the live workspace is readable browser data. You can choose to encrypt future local saves with a workspace passphrase.

The current app has no account system, cloud sync, server-side backup, analytics script, or automatic email sending. Its code runs in your browser. We do not receive your imported invoices or notes through an application server.

Back up your work.

Browser storage can be lost if you clear site data, change browsers, use private browsing, or switch devices. Choose Backup options in the workspace. A passphrase-encrypted JSON backup protects the exported file with AES-256-GCM and a key derived using PBKDF2-SHA256; each file uses fresh random salt and IV. Keep the passphrase separately: Orvaket does not save or recover it. You can also choose a readable JSON backup. Both kinds can be restored later.

What the host may see

This website is served by Cloudflare Pages. Cloudflare may process request information, such as an IP address, to deliver and protect the site; see its privacy policy. The public source code is available on GitHub. The application has no server that receives imported invoices or notes.

What happens when you use external actions

Open email app creates a draft in your own email software. Copy draft copies text to your clipboard. Nothing is sent automatically. Backup options and Export CSV create files on your device. CSV exports and readable JSON backups are not encrypted. If you open a GitHub feedback link, you leave Orvaket and GitHub's own policies apply.

Who can access the stored workspace

The default local workspace is not encrypted. Optional local workspace encryption uses a passphrase-derived key with PBKDF2-SHA256 and AES-256-GCM. An older readable browser copy remains until you download and verify its backup, then explicitly remove that older copy. Lock the workspace when finished: while a tab is unlocked, decrypted information is available to that tab. A compromised browser origin or extension may also expose it. Orvaket cannot recover a lost workspace or backup passphrase. Readable JSON and CSV exports remain unencrypted; an encrypted local workspace does not make those files private. Use a trusted device and avoid bank credentials, identity documents, or sensitive dispute details in notes. Only import records you are authorized to handle.

Moving from an older address.

Work saved at the earlier Duekrio address, Duenara address, or GitHub Pages address stays in that browser origin. The GitHub Pages address shares its origin with other paths under akam1123.github.io, so code on those paths could access readable old browser data. Open the old workspace, unlock it if necessary, and download a JSON backup through Backup options. Then open the Orvaket workspace, choose Restore backup, and verify the invoices before clearing the older copy. A backup passphrase cannot be recovered by Orvaket. CSV alone does not preserve the whole workspace.

Delete or move your data

You can delete individual invoices in the workspace. To remove all locally saved data, clear site data for this website in your browser settings. Export a JSON backup first if you may need it. Different website addresses and an offline HTML copy use separate browser storage; a backup file is the way to move work between them.

Operator and private contact

Orvaket is operated by Ariel, an individual in Israel. For a private support or privacy request, email arielfaber123@gmail.com. Email is handled by your and our email providers, not by the Orvaket workspace. Include only the information needed for your request; do not send an entire invoice export, passwords, card details, or identity documents.

Use the public feedback form on GitHub only for non-confidential product feedback. For a software security vulnerability, use GitHub's private vulnerability reporting. These GitHub routes require an account. Do not include customer or invoice data in a public issue.

Ready to work?

Start with fictional sample data, then decide whether to import your own CSV.

Open free workspace