Vexlo
  • Guides
  • AI
  • Get involved
  • Comparison
  • FAQ
  • Terms
  • Privacy
DEENFRIT

Privacy Policy

Last updated: 23 July 2026

1. Controller

devs group GmbH
8280 Kreuzlingen
devs-group.ch

2. Independence and voluntary use

This app is not an official product of Bexio AG. "Bexio" is a registered trademark of Bexio AG. It is developed and operated independently by devs group. Use is entirely voluntary. You decide whether and how long you use this App. Uninstallation is possible at any time and deletes all local data.

3. Principle: Minimal data retention

The Provider does not store any of your Bexio business data (invoices, contacts, files) on its own servers. This data is stored exclusively locally on your device. API requests to Bexio are routed through a backend system of the Provider that acts as a proxy and forwards requests to the official Bexio API. This backend neither logs nor analyses your requests or business data. Only the authentication tokens and minimal state data necessary for operation are stored server-side (see sections 4 and 5).

4. What data is stored locally on your device

Authentication (OAuth / Device Token)

When signing in, you authenticate directly with Bexio via a secure OAuth process (PKCE). The Bexio credentials (Access Token and Refresh Token) are stored and managed exclusively on the Provider’s backend system – they never reach your device. Only a device-specific token (Device Token) is stored in the secure keychain (Keychain/Keystore) on your device, which identifies your device to the backend. Your Bexio password is never stored in the App or transmitted to the Provider.

Server-side storage of Bexio tokens serves two purposes: (1) the OAuth client secret is kept server-side and never transmitted to the device, enhancing authentication security; (2) the notification service can check in the background whether relevant status changes have occurred to trigger push notifications. The tokens are used exclusively for these purposes and are deleted when access is revoked.

Minimal server-side state data

To detect whether anything has changed since the last check, the backend stores an absolute minimum of state data per account. This exclusively includes:

  • Last known count/IDs of files in the inbox (to detect new files)
  • Last known status of invoices (to detect status changes such as "paid" or "overdue")

This data contains no content (no file names, amounts, customer names or other business data). It serves exclusively for comparison ("has anything changed?") and is deleted upon sign-out or revocation of access.

Cached Bexio data

For offline use, the following data from your Bexio account is cached locally on your device in a SQLite database:

  • Invoices (master data, line items, status)
  • Supplier bills (master data, line items, attachment metadata)
  • Files in the inbox (metadata, preview images)
  • Contacts (name, address, for invoice creation)
  • Company name (for dashboard display)

This data does not leave your device. You can clear the local cache at any time in the app settings.

Push notifications (optional)

Push notifications are an optional feature that you must actively enable. When activated, a device-specific push token is transmitted to the Provider’s notification service. This token contains no personal data and serves exclusively for delivering notifications (e.g. invoice paid, invoice overdue, new files). You can disable push notifications at any time in the app settings.

5. What data the Provider processes

The Provider stores server-side exclusively:

  • Bexio Access Token and Refresh Token: encrypted, for authentication with Bexio and for background checks
  • Push Token (only with activated notifications): for delivering push messages
  • Minimal state data: last known file count/IDs and invoice status, without content (see section 4)
  • Feedback messages (only if you use the feedback chat): messages you write, together with your company name and timestamps, in order to answer your request

The Provider stores no IP addresses, no server logs and no usage data. The backend system forwards API requests to Bexio without logging or storing them.

The Provider has no access to your Bexio data, your Bexio password, your invoices, contacts or files.

6. Data sharing

Your data is not sold, rented or shared with third parties for advertising or analytics purposes. No tracking takes place in the App; for the website's conversion tracking see section 9. The following third-party services are technically integrated:

  • Bexio AG: API requests are forwarded through the Provider’s backend to the official Bexio API (in accordance with their Privacy Policy)
  • Apple Push Notification Service / Firebase Cloud Messaging: Delivery of push notifications (only when activated). Further details in the Firebase Privacy Policy.
  • Slack (Salesforce, Inc., USA): messages from the feedback chat are forwarded to the provider's internal Slack workspace for answering. Slack is certified under the Swiss-U.S. Data Privacy Framework. See the Slack Privacy Policy.

7. Storage duration and deletion

  • Local Bexio data: Immediate deletion upon uninstalling the App or clearing the cache in settings
  • Device Token (local): Deletion upon sign-out or uninstallation from the keychain
  • Bexio Tokens (server-side): Deletion upon sign-out, revocation of access in Bexio, or upon request
  • Push Token: Deletion upon deactivation of notifications or uninstallation
  • Server-side state data: Deletion upon sign-out, revocation of access, or upon request
  • Automatic deletion upon inactivity: Accounts that have not connected to the App for more than 90 days are automatically and completely deleted from the server (Bexio Tokens, Push Token, state data). A new sign-in is required after deletion.
  • Feedback messages (server-side): deleted when the account is deleted, upon automatic deletion after inactivity, or on request

Since nearly all data is stored exclusively on your device, you have complete control over its deletion.

8. Your rights

Under the Swiss Data Protection Act (nDSG, in force since 1 September 2023), you have the following rights:

  • Information: You can request information about the data stored by the Provider at any time. This includes Bexio Tokens, Push Token and minimal state data (see section 5).
  • Deletion: Uninstalling the App deletes all local data. Server-side data (Tokens, state data) are deleted upon sign-out or after 90 days of inactivity. You can request immediate deletion by email at any time.
  • Revocation: Revoke OAuth access at any time in your Bexio account under "Connected Apps".
  • Complaint: You have the right to file a complaint with the competent data protection authority (FDPIC).

9. Cookies, tracking and advertising

The App uses no cookies, no tracking and no advertising. No user profiles are created.

This website uses Google Ads (gtag.js), a service of Google Ireland Limited, solely to measure the success of advertising (conversion tracking). This technology is only loaded after you have explicitly consented in the cookie banner. Only then are cookies set and data transmitted to Google, which may include a transfer to the USA. Without your consent nothing is loaded; only a technically necessary cookie storing your banner choice is set.

Your consent is voluntary. You can withdraw it at any time via “Cookie settings” in the page footer or by deleting the cookies set for this website in your browser. The legal basis for processing is your consent.

Chat widget on the website

This website embeds a chat widget (AIgent), a service operated by devs group GmbH itself. It is an integral part of the website and loads automatically when you visit; its sole purpose is to answer your questions about Vexlo. The widget sets no advertising or tracking cookies and creates no usage profiles; only technically necessary data (e.g. the conversation history) is stored in your browser.

Only when you actively send a message are your input and the conversation history transmitted to the AIgent servers of devs group GmbH and processed there by an AI language model to generate a reply; requests may also be passed to model providers acting as processors. Your content is not used to train AI models. Please do not enter passwords, financial data or sensitive personal data in the chat. The legal basis is our legitimate interest in answering your questions directly; using the chat is voluntary.

Feature requests on the website

On the “Get involved” page you can voluntarily send us a feature request. We process your email address (required), your name (optional) and the text of your request. The data is stored on our server in Switzerland and used only to handle your request and to notify you once the feature is available.

There is no newsletter and no sharing for advertising purposes. The legal basis is our legitimate interest in improving the app; providing the data is voluntary. You can request deletion of your feature request at any time by email.

10. Data security

The App uses the security mechanisms of your device (Keychain/Keystore for tokens, App Sandbox for the local database). Communication with the Bexio API is exclusively via encrypted HTTPS connections. However, the Provider cannot guarantee absolute security and is not liable for unauthorised access to your device.

Data processing for AI features

When you actively trigger an AI feature, the content required for it (for example receipt images, extracted text and associated metadata) is transmitted for processing to the AI infrastructure of the Swiss provider Infomaniak. Processing occurs solely as a result of your explicit action.

Swiss data sovereignty. Infomaniak operates its AI services on its own servers in Switzerland. According to Infomaniak, the transmitted data does not leave Switzerland, is not used to train AI models and is subject to the revised Swiss FADP and the GDPR. The provider values this Swiss data sovereignty but is not responsible for Infomaniak's actual data processing. The data protection provisions of Infomaniak are decisive in this respect.

No content is used to train AI models of the provider or third parties. Only the data required to produce the requested result is transmitted.

App stores. The app is distributed via the Apple App Store and Google Play. For the platform itself, the data protection and tracking provisions of Apple and Google apply in addition (see Apple Privacy and Google Privacy).

11. Changes

This Privacy Policy may be amended at any time. The current version is always available on this page.

Vexlo

The native Bexio app for your phone – invoices, receipts, management and more, on the go.

App StoreGoogle Play

Product

  • AI
  • Comparison
  • FAQ
  • Guides
  • Changelog

Legal

  • Terms
  • Privacy
  • Delete account

Company

  • devs group GmbH
  • 8280 Kreuzlingen, CH

Independent product, not affiliated with Bexio AG.

Made with ❤️ in 🇨🇭 bydevs group·© 2026 devs group GmbH·