Privacy Policy

Last updated: July 2026

Quick Summary

Before diving into the details, here's what matters most about how we handle your data.

  • 🚫 We don't sell your data. Never. Full stop.
  • πŸ”’ Your data belongs to you. We don't monitor your invoices or client information
  • πŸ‡¨πŸ‡­ Swiss privacy standards. Compliant with the FADP, GDPR and CCPA
  • 🏦 Bank data only with your consent. Read-only bLink connections, revocable at any time
  • πŸŽ›οΈ You control your data. Delete your account at any time
  • πŸ›‘οΈ Security built in. Encryption protects data in transit and at rest

Who we are

Magic Heidi is operated by Magic Heidi AG, Route de Vaux 1, 1126 Vaux, Switzerland, registered under UID CHE-215.620.945. Magic Heidi AG is the data controller for the processing described in this policy.

Contact for privacy requests:

For complaints, you may also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC): https://www.edoeb.admin.ch


Scope

This Privacy Policy applies to:

  • the Magic Heidi mobile apps (iOS and Android);
  • the Magic Heidi desktop apps (Mac and Windows);
  • the Magic Heidi web app;
  • our website at https://magicheidi.ch.

By accessing the Service, you accept our Terms of Service and this Privacy Policy. Using Magic Heidi requires agreement to both.


Data we collect

As invoicing and accounting software, Magic Heidi needs certain information. Here is exactly what we collect and why:

  • Business data. Company name, address, IBAN, payment details and VAT number.
  • Invoicing data. Products and services, prices, payment terms and invoice history.
  • Client information. Client names, addresses, contact details and payment history.
  • Account information. Email address, sign-in method used and subscription status.
  • Uploaded documents. Receipts, invoices and expense attachments you upload or forward to us.
  • Bank account data (only if you connect a bank). If you connect a bank account via bLink, we receive account information from your bank: account identifiers (such as the IBAN), account balances and transaction data (date, amount, currency, counterparty and payment reference). See "Open banking via SIX bLink" below.

Automatically collected data

Usage data:

  • app features used;
  • error logs and crash reports;
  • device type and operating system.

We do not collect:

  • location data;
  • contact lists;
  • photos (unless you upload receipts);
  • browsing history;
  • your e-banking credentials β€” you authenticate directly with your bank, and we never see your login details.

How we use your data

We use your data for these specific purposes:

To provide our services

  • creating legally compliant invoices;
  • synchronising your data across devices;
  • processing your payments and subscriptions;
  • sending invoices and payment reminders to your clients;
  • retrieving bank account information you have connected and matching transactions to your invoices and expenses (reconciliation).

To improve Magic Heidi

  • fixing bugs and technical issues;
  • analysing which features need improvement;
  • testing new features.

To communicate with you

  • responding to support requests;
  • sending important product updates;
  • sharing tips on using the app (opt-in only).

AI processing for receipt scans

When you upload a receipt, invoice or expense attachment, we process the file to extract fields such as vendor, date, currency, VAT, amount and category suggestions.

  • Receipt images, PDFs, screenshots and forwarded email attachments may be sent to Anthropic for extraction.
  • This processing takes place only to deliver the feature you requested.
  • We do not use your uploaded receipt data to train our own Magic Heidi models.
  • AI processing never changes your accounting data automatically without your review.
  • Original files remain part of your records until you have them deleted or you delete your account, subject to statutory retention obligations.

If you choose to connect a bank account, the connection is made through bLink, the Swiss open banking platform operated by SIX. Here is how it works:

  • What we retrieve. Read-only account information from your bank: account identifiers, balances and transactions. We do not initiate payments.
  • Your consent. A connection is established only with your explicit consent, which you grant through the consent process provided by SIX ("Consent as a Service") and/or your bank. The scope and duration of your consent are shown to you when you grant it.
  • Background refresh. Where your consent covers it, we retrieve account information periodically in the background (offline access) so your records stay current without you being signed in.
  • Your credentials stay with your bank. You authenticate directly with your bank. Magic Heidi never receives or stores your e-banking login details.
  • Who is involved. SIX processes connection and consent data in order to operate the bLink platform, and your bank knows that Magic Heidi retrieves data on your behalf. Each of them acts under its own responsibility and terms.
  • Revoking access. You can revoke a bank connection at any time in Magic Heidi or with your bank. Revocation stops all future retrieval. Transaction data already retrieved remains part of your accounting records and is retained as described under "Data retention" below.

Under Swiss law and the GDPR, we process your data on the basis of:

  • Contract: we need your data to provide the service you signed up for;
  • Consent: for bank account connections and optional communications β€” you decide;
  • Legitimate interest: for security, fraud prevention and service improvement;
  • Legal obligation: for records we are required by law to keep.

Third-party providers

We work with trusted partners. Each meets strict security and compliance standards, and all third parties processing personal data on our behalf are contractually bound by data protection obligations.

Named processors and partners

  • Firebase (Google): authentication, application data and synchronisation. ISO 27001 certified, SOC compliant.
  • Google Cloud: storage of uploaded files such as receipts and attachments. ISO 27001 certified.
  • SIX (bLink): open banking platform through which bank account information is retrieved with your consent, including consent management ("Consent as a Service").
  • Anthropic: AI extraction for receipt and expense scans.
  • RevenueCat: subscription management. GDPR compliant.
  • Stripe: payment processing on the web, where applicable.
  • Apple App Store / Google Play: mobile billing and distribution.
  • Postmark: transactional emails. ISO 27001, SOC 2 Type II compliant.
  • Mixpanel: anonymised product analytics. GDPR compliant with data anonymisation.
  • Vercel Analytics: website analytics.
  • Sentry: error monitoring and diagnostics.

If you enable optional integrations (for example Stripe, Shopify or Zapier), we process data from those services according to the configuration you choose.


International data transfers

Our primary application data is hosted in Switzerland. Some service providers may, however, process limited data in other countries, including the USA and the EU, depending on the service concerned.

Examples:

  • Switzerland: primary application hosting, stored customer data, and the SIX bLink platform;
  • USA: Anthropic, Mixpanel, RevenueCat, Stripe, Sentry, Postmark and Vercel Analytics;
  • EU and other supported regions: certain Google infrastructure and delivery networks may process data closer to you.

Where personal data is transferred outside Switzerland or your country, we rely on standard contractual clauses, adequacy decisions or other legally permitted transfer mechanisms.


Data retention

We keep your data only as long as necessary:

Data typeRetention period
Account informationUntil account deletion
Invoicing, expense and business dataUntil account deletion, unless longer retention is legally required
Uploaded receipts and attachmentsWith your records until deletion, subject to statutory retention obligations
Bank account and transaction data (bLink)With your accounting records until deletion, subject to statutory retention obligations (up to 10 years under Art. 958f of the Swiss Code of Obligations)
Consent records for bank connectionsFor the duration of the consent and as long as required to demonstrate that valid consent was given
Usage analytics24 months (anonymised)
Support conversations36 months
Payment records10 years (legal obligation)
Encrypted backupsUp to 90 days after deletion

When you delete your account, we remove or restrict personal data we no longer need within 30 days. Records we are legally required to keep, such as accounting or payment data, may be retained further. Encrypted backups may persist for up to 90 days before being permanently deleted.


Your rights β€” you control your data

Here is what you can do with your data at any time:

  • Access & export. Request a copy of all your data and download invoices, client lists and business data in standard formats.
  • Correct & update. Update incorrect information directly in the app or contact us.
  • Delete & restrict. Use in-app account deletion or write to us. We irreversibly delete your data within 30 days, subject to statutory retention.
  • Object & complain. Object to marketing communications and certain processing. If you are unhappy, you can contact the FDPIC or your local data protection authority.
  • Revoke bank connections. Withdraw your consent to any bank connection at any time, in the app or with your bank.

Swiss data protection rights (FADP)

As a Swiss resident you have rights under the Federal Act on Data Protection (FADP), in force since September 2023:

  • right to information about data processing;
  • right of access to your personal data;
  • right to data portability;
  • right to rectification of inaccurate data;
  • right to erasure ("right to be forgotten");
  • right to restriction of processing;
  • right to object to processing.

The FADP requires privacy by design and by default. We implement this by collecting only necessary data and using privacy-friendly default settings.

European Union rights (GDPR)

If you are located in the EU, UK, Liechtenstein, Norway or Iceland, you have additional rights under the GDPR:

  • all rights listed above;
  • the right to lodge a complaint with your local supervisory authority;
  • the right to withdraw consent at any time;
  • the right not to be subject to automated decision-making.

We make no automated decisions that significantly affect you.

California rights (CCPA/CPRA)

California residents have the following rights:

  • Right to know: what personal data we collect and why;
  • Right to delete: request deletion of your personal data;
  • Right to opt out: we do not sell personal data, so no opt-out is needed;
  • Right to non-discrimination: we will not treat you differently for exercising your rights.

We do not sell your personal data. We do not share it for money or other valuable consideration.


Security measures

We protect your data with multiple layers of security:

  • Encryption. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Access controls. Access on a need-to-know basis with multi-factor authentication.
  • Infrastructure. Regular security audits and automated vulnerability scanning.
  • Privacy by design. We collect only what is necessary, with privacy-friendly defaults.

Data breach notification

In the event of a security breach affecting your personal data, we will:

  1. notify the FDPIC without undue delay β€” and, where required, within 72 hours;
  2. contact you directly if there is a high risk to your rights;
  3. explain what happened and what measures we are taking.

Cookies and tracking

On our website

We use a small number of essential and measurement technologies on our website:

  • Essential cookies: required for the website to function;
  • Mixpanel: measures product and referral activity on the website;
  • Vercel Analytics: provides aggregated website and performance metrics;
  • Sentry: captures technical errors and diagnostic data when problems occur.

You can block or delete non-essential website cookies in your browser settings.

In our apps

Our mobile and desktop apps do not use browser cookies, but may send limited analytics and error telemetry via SDKs such as Mixpanel and Sentry. For sign-in we use secure authentication tokens rather than browser cookies.


Children's privacy

Magic Heidi is designed for business use. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, please contact us immediately.


Changes to this policy

We may update this Privacy Policy when laws change or we adapt our services. For material changes we will:

  1. update the "Last updated" date;
  2. notify you via the app or by email;
  3. obtain your consent where required.

Continued use of Magic Heidi after changes take effect means you accept the updated policy.


Questions?

We are happy to explain anything in this policy. Contact us:

Email: hello@magicheidi.ch

Postal address: Magic Heidi AG Route de Vaux 1, 1126 Vaux Switzerland

For unresolved privacy concerns, contact the Swiss Federal Data Protection and Information Commissioner: