barcoder

Privacy notice: Barcoder

Last updated: 6 October 2026

Barcoder checks payment QR codes and barcodes against the invoice they come with, so you don't pay the wrong account. This notice explains what we do with personal data on the Barcoder wiki (docs.barcoder.ai), app (barcoder.ai), API and MCP server (api.barcoder.ai).

Who we are

LumiVerse d.o.o., Markuševečka cesta 20C, 10000 Zagreb, Croatia. OIB 88595646800, MBS 05772087. Email: info@lumiverse.hr. Web: https://www.lumiverse.hr/. We are the controller of the data described here. For business accounts, see "Business accounts" below. We have not appointed a data protection officer, because the law does not require one for a company of our size and activity (Art. 37 GDPR).

What we collect, and why

If you use the wiki. The wiki has no accounts, no analytics and no tracking cookies. Fonts are served from our own server. The wiki's scanner reads codes in your browser; images are not sent to us. Our servers may log your IP address for security, for up to 30 days.

If you try the app without an account (trial). To give you a limited number of free cases and stop abuse, we:

Basis: our legitimate interest in preventing abuse of the free trial.

If you create an account.

Basis: our contract with you. If you arrived via a campaign link, we keep the campaign tags (utm_source and similar) for internal statistics for 12 months (legitimate interest).

When you check an invoice. You upload a PDF or photo, or send fields and a code payload through the API.

Basis: our contract with you (for your data) and legitimate interest in preventing payment fraud (for the payee's data).

If you are a payee (the person or business being paid on an invoice someone checked with Barcoder). We received your name, address, account details and possibly your VAT number from our user, not from you. We use them only for that user: to check that the payment code and the invoice agree, and to warn that user if the same payee appears with different account details in their own earlier checks. We keep them as text for 90 days. We never show them to anyone except the user who checked that invoice, never publish them and never use them for marketing. We cannot inform every payee individually: we have no way to contact you and doing so would need more data about you. That is why we publish this section. You have the rights below. Write to info@lumiverse.hr with the IBAN concerned and proof that you hold the account, and we will tell you what we hold and delete it on request.

How long we keep it

Who receives data

We use these service providers, under contracts that require them to protect the data:

RecipientWhat forWhere
Hetzner Online GmbHHosting (servers, database)Falkenstein, Germany
Brevo (Sendinblue SAS)Sending sign-in emails (your email address and the link)EU (France, Belgium); some of Brevo's support sub-processors are in the USA or India, under the Standard Contractual Clauses or the EU–US Data Privacy Framework
OpenRouter, Inc.Routing the invoice image or text to the AI modelUSA (Standard Contractual Clauses)
Together Computer, Inc. (Together.ai)Running the AI model that reads the invoiceUSA (Standard Contractual Clauses)
European Commission (VIES) and national tax authoritiesChecking whether a VAT number is validEU

AI providers. When you ask us to read an invoice, page images of it go to OpenRouter, which sends them only to Together.ai. We instruct OpenRouter not to use providers that collect data for training, and not to fall back to any other provider. OpenRouter does not log the content of requests (see https://openrouter.ai/privacy). Together.ai does not use the content for training; under its default terms it may keep inputs and outputs for a limited time (see https://www.together.ai/privacy).

Transfers outside the EU. OpenRouter and Together.ai are in the USA. Neither is certified under the EU–US Data Privacy Framework, so we rely on the European Commission's Standard Contractual Clauses in our data processing agreements with them. You can ask us for a copy of the safeguards.

We don't sell personal data and don't share it with advertisers. We may disclose data where the law requires it.

Cookies and browser storage

We store only what the service needs:

Nothing else is stored in your browser. The campaign link you arrived from, and the address we just emailed a sign-in link to, are kept only in the page's memory and are gone when you leave or reload the page.

There are no analytics or advertising cookies, so we show no cookie banner.

AI and automated checks

Your rights

You can ask us to:

You can object at any time to processing based on legitimate interest, including payee records; we will stop unless we have compelling grounds, and we will not use it for direct marketing at all. You can download a copy of your data in Settings → Download my data. You can delete your account in Settings. Write to info@lumiverse.hr for anything else. We answer within one month, and may ask you to prove your identity. You can complain to the Croatian data protection authority, Agencija za zaštitu osobnih podataka (AZOP), Ulica Metela Ožegovića 16, 10000 Zagreb, https://azop.hr, or to the authority where you live or work.

If you are in Brazil or India

Brazil (LGPD). If you use Barcoder from Brazil, the Lei Geral de Proteção de Dados (Lei nº 13.709/2018) applies as well. You have the rights in its Art. 18:

Your data is processed in the EU (Germany) and, for reading invoices, in the USA, under the safeguards described in "Who receives data" (Art. 33 LGPD). Write to info@lumiverse.hr. You can also complain to the Autoridade Nacional de Proteção de Dados (ANPD), https://www.gov.br/anpd.

India (DPDP Act). If you use Barcoder from India, the Digital Personal Data Protection Act, 2023 applies as well. You can ask us for:

Send requests and grievances to info@lumiverse.hr. We answer promptly, and within 90 days at the latest. If you are not satisfied with our answer, you can complain to the Data Protection Board of India.

Business accounts

When a business uses Barcoder to check its own invoices, we process case data on its behalf as its processor; we sign a data processing agreement on request. A business account keeps no case reports (only the standard and the verdict of each case) unless someone at the business turns on "Keep case reports (includes payee details) for 90 days" in Settings; we record who turned it on and when. Payee details are never used for anything but that business's own checks.

Children

Barcoder is not intended for people under 16, and we don't knowingly collect their data.

Security

Connections are encrypted (HTTPS). Secrets are stored only as one-way hashes. IP addresses and device ids are stored only as keyed hashes. Documents are never stored. Access to production data is limited to LumiVerse staff who need it.

Changes

We'll post changes here with a new date. For significant changes, we'll email account holders before they apply.

Contact

LumiVerse d.o.o., info@lumiverse.hr.