Privacy notice: Barcoder
Last updated: 6 October 2026
Barcoder checks payment QR codes and barcodes against the invoice they come with, so you don't pay the wrong account. This notice explains what we do with personal data on the Barcoder wiki (docs.barcoder.ai), app (barcoder.ai), API and MCP server (api.barcoder.ai).
Who we are
LumiVerse d.o.o., Markuševečka cesta 20C, 10000 Zagreb, Croatia. OIB 88595646800, MBS 05772087. Email: info@lumiverse.hr. Web: https://www.lumiverse.hr/. We are the controller of the data described here. For business accounts, see "Business accounts" below. We have not appointed a data protection officer, because the law does not require one for a company of our size and activity (Art. 37 GDPR).
What we collect, and why
If you use the wiki. The wiki has no accounts, no analytics and no tracking cookies. Fonts are served from our own server. The wiki's scanner reads codes in your browser; images are not sent to us. Our servers may log your IP address for security, for up to 30 days.
If you try the app without an account (trial). To give you a limited number of free cases and stop abuse, we:
- store a random device identifier in your browser;
- set a trial cookie;
- keep only a keyed hash (a one-way code) of that identifier and of your IP address.
Basis: our legitimate interest in preventing abuse of the free trial.
If you create an account.
- Your email address, an optional name, and how you sign in.
- Sign-in links, sessions and API keys (stored only as one-way hashes).
- The apps you connect via OAuth/MCP.
- Your usage.
Basis: our contract with you. If you arrived via a campaign link, we keep the campaign tags (utm_source and similar) for internal statistics for 12 months (legitimate interest).
When you check an invoice. You upload a PDF or photo, or send fields and a code payload through the API.
- We decode the payment code and read the invoice with an AI model.
- You confirm the fields, and we compare the document with the code.
- We never store the document or the image: it is processed in memory and discarded.
- We store a text report of the case: what the document and the code said (payee name, address, the account paid: IBAN, domestic account, Pix key, UPI ID or Swish number, tax or VAT number, amount, currency, reference), the checks and the verdict. It is deleted automatically 90 days after the case.
- We compare the payee with the payees in your own case reports from the last 90 days, to warn you when, for example, a payee you know turns up with a different account (a common invoice fraud). We never compare with other users' cases.
Basis: our contract with you (for your data) and legitimate interest in preventing payment fraud (for the payee's data).
If you are a payee (the person or business being paid on an invoice someone checked with Barcoder). We received your name, address, account details and possibly your VAT number from our user, not from you. We use them only for that user: to check that the payment code and the invoice agree, and to warn that user if the same payee appears with different account details in their own earlier checks. We keep them as text for 90 days. We never show them to anyone except the user who checked that invoice, never publish them and never use them for marketing. We cannot inform every payee individually: we have no way to contact you and doing so would need more data about you. That is why we publish this section. You have the rights below. Write to info@lumiverse.hr with the IBAN concerned and proof that you hold the account, and we will tell you what we hold and delete it on request.
How long we keep it
- Account data: until you delete your account. Deleting it signs you out everywhere and stops all use of your data at once; we erase it 30 days later (the delay lets us undo a mistaken or fraudulent deletion if you ask in time).
- After erasure we keep, for 12 months, only a one-way keyed hash of your email address, so the same address can't delete and re-register to get a new free allowance (legitimate interest in preventing abuse). After 12 months it is erased too.
- Purchases: if you bought a pack or a subscription, the purchase records (what, when, how much) and the Stripe customer record are kept as long as Croatian accounting and tax law requires (legal obligation), even after your account is erased. They hold no case data.
- Case reports, including payee details: 90 days.
- Case summaries (standard, verdict, date): as long as your account exists.
- Sign-in links: 24 hours after they expire. Sessions: 30 days after they end.
- Trial data: 90 days. IP hashes: 48 hours.
- Campaign tags: 12 months.
- Server logs: up to 30 days. Database backups: 7 days, rolling.
- Records of a business turning case reports on or off (who, when and which text version): account lifetime + 5 years (the general limitation period under Croatian law), so we can show what was agreed. They survive erasure for that reason.
Who receives data
We use these service providers, under contracts that require them to protect the data:
| Recipient | What for | Where |
|---|---|---|
| Hetzner Online GmbH | Hosting (servers, database) | Falkenstein, Germany |
| Brevo (Sendinblue SAS) | Sending sign-in emails (your email address and the link) | EU (France, Belgium); some of Brevo's support sub-processors are in the USA or India, under the Standard Contractual Clauses or the EU–US Data Privacy Framework |
| OpenRouter, Inc. | Routing the invoice image or text to the AI model | USA (Standard Contractual Clauses) |
| Together Computer, Inc. (Together.ai) | Running the AI model that reads the invoice | USA (Standard Contractual Clauses) |
| European Commission (VIES) and national tax authorities | Checking whether a VAT number is valid | EU |
AI providers. When you ask us to read an invoice, page images of it go to OpenRouter, which sends them only to Together.ai. We instruct OpenRouter not to use providers that collect data for training, and not to fall back to any other provider. OpenRouter does not log the content of requests (see https://openrouter.ai/privacy). Together.ai does not use the content for training; under its default terms it may keep inputs and outputs for a limited time (see https://www.together.ai/privacy).
Transfers outside the EU. OpenRouter and Together.ai are in the USA. Neither is certified under the EU–US Data Privacy Framework, so we rely on the European Commission's Standard Contractual Clauses in our data processing agreements with them. You can ask us for a copy of the safeguards.
We don't sell personal data and don't share it with advertisers. We may disclose data where the law requires it.
Cookies and browser storage
We store only what the service needs:
bc_sessioncookie: keeps you signed in (30 days).bc_trialcookie: your free trial (90 days).bc_langcookie: the language and region you chose with the language switch (1 year). It is set only when you use the switch; without it, the page follows your browser's language.bc_device(local storage): a random id, set only when you start a free check; it stops the trial from being reset. It is strictly necessary for the free trial you asked for.
Nothing else is stored in your browser. The campaign link you arrived from, and the address we just emailed a sign-in link to, are kept only in the page's memory and are gone when you leave or reload the page.
There are no analytics or advertising cookies, so we show no cookie banner.
AI and automated checks
- An AI model reads the invoice and proposes fields, each with a confidence score. You see the fields and confirm or correct them before the check.
- The check then compares the confirmed fields with the code and gives MATCH (the code pays the payee and amount the invoice names), MISMATCH (they differ: don't pay until you've checked) or review, with the reason for each check.
- The verdict is advice to you. It doesn't stop, approve or make any payment, and it has no legal effect on you or the payee. You decide whether to pay. So no decision is made solely by automated means in the sense of Art. 22 GDPR. A MATCH is not a guarantee that a payment is safe.
Your rights
You can ask us to:
- give you access to your data and a copy;
- correct it;
- erase it;
- restrict its use;
- send it to you or another provider in a machine-readable format (portability, for data you gave us under contract).
You can object at any time to processing based on legitimate interest, including payee records; we will stop unless we have compelling grounds, and we will not use it for direct marketing at all. You can download a copy of your data in Settings → Download my data. You can delete your account in Settings. Write to info@lumiverse.hr for anything else. We answer within one month, and may ask you to prove your identity. You can complain to the Croatian data protection authority, Agencija za zaštitu osobnih podataka (AZOP), Ulica Metela Ožegovića 16, 10000 Zagreb, https://azop.hr, or to the authority where you live or work.
If you are in Brazil or India
Brazil (LGPD). If you use Barcoder from Brazil, the Lei Geral de Proteção de Dados (Lei nº 13.709/2018) applies as well. You have the rights in its Art. 18:
- confirmation that we process your data, and access to it;
- correction;
- anonymisation, blocking or deletion of unnecessary data;
- portability;
- information about who we share it with;
- the right to revoke consent where processing relies on it.
Your data is processed in the EU (Germany) and, for reading invoices, in the USA, under the safeguards described in "Who receives data" (Art. 33 LGPD). Write to info@lumiverse.hr. You can also complain to the Autoridade Nacional de Proteção de Dados (ANPD), https://www.gov.br/anpd.
India (DPDP Act). If you use Barcoder from India, the Digital Personal Data Protection Act, 2023 applies as well. You can ask us for:
- a summary of the personal data we process about you and who we share it with;
- its correction, completion, update or erasure;
- the nomination of a person to exercise your rights if you die or are incapacitated.
Send requests and grievances to info@lumiverse.hr. We answer promptly, and within 90 days at the latest. If you are not satisfied with our answer, you can complain to the Data Protection Board of India.
Business accounts
When a business uses Barcoder to check its own invoices, we process case data on its behalf as its processor; we sign a data processing agreement on request. A business account keeps no case reports (only the standard and the verdict of each case) unless someone at the business turns on "Keep case reports (includes payee details) for 90 days" in Settings; we record who turned it on and when. Payee details are never used for anything but that business's own checks.
Children
Barcoder is not intended for people under 16, and we don't knowingly collect their data.
Security
Connections are encrypted (HTTPS). Secrets are stored only as one-way hashes. IP addresses and device ids are stored only as keyed hashes. Documents are never stored. Access to production data is limited to LumiVerse staff who need it.
Changes
We'll post changes here with a new date. For significant changes, we'll email account holders before they apply.
Contact
LumiVerse d.o.o., info@lumiverse.hr.