Qrilly is a free tool for creating, storing and sending Swiss QR-bill invoices. Using it is entirely optional and your own choice. By creating an account or using the service you accept these terms; if you do not accept them, please do not use it.
You alone decide what you enter and what you do with it. You are solely responsible for the accuracy and legality of everything you provide - your payment details and IBAN, amounts, VAT rates, invoice contents, and the personal data of your clients - and for the invoices you create, send, cancel or delete.
You confirm that you are entitled to process the personal data of the people you enter, and that you meet your own legal duties as an invoice issuer (bookkeeping, VAT, data protection, record retention).
Check every invoice and its QR bill before you rely on it. Qrilly does not review your invoices and is not a party to any contract or payment between you and your clients.
Your data is stored in the cloud, in a MongoDB Atlas database cluster operated by a third-party provider - not on your device and not on a local database. The service is hosted by further third-party providers (see the Privacy policy). Their availability, security and location are outside the publisher’s control.
Passwords are hashed (a one-way transformation): the publisher cannot read them back and never stores them in plain text.
Your clients’ and invoices’ personal details are encrypted (AES-256-GCM, reversible with a key) before being written to the database: client names, emails, addresses and notes; invoice recipient names, emails and addresses, group titles, line-item descriptions, messages and notes; and the notes on logged hours. Each account has its own key, which is in turn protected by a master key held by the service.
Not everything is encrypted: your account name and email, your sender presets (business name, address, IBAN, logo, numbering and defaults), amounts, dates, invoice numbers, quantities and group names are stored as normal readable data, because the service needs them to work.
Because the service holds the keys it needs to display and rebuild your invoices, encryption protects against a leak of the database on its own; it is not end-to-end encryption and does not prevent the service itself from technically accessing your data.
No system is perfectly secure. Do not store anything you are not prepared to risk.
A deleted invoice is kept in a trash for 15 days, during which you can restore it; after that it is removed permanently together with the hours it billed. An invoice already marked as paid cannot be deleted. You can delete your whole account at any time under Settings, and download all your data before you do.
Keep your own backups and records: the publisher does not guarantee that data will never be lost, altered or unavailable.
The service is provided "as is" and "as available", without warranty of any kind - including that it is error-free, uninterrupted, secure, suitable for your purpose, or that generated QR bills will be accepted by every bank or payment app.
To the fullest extent permitted by law, the developer and publisher of Qrilly accept no liability whatsoever for any loss or damage arising from the use of, or inability to use, the service - including lost or incorrect data, wrong or unpaid invoices, lost income, tax or accounting consequences, claims by your clients or third parties, or data breaches at the underlying providers. Where liability cannot be excluded by mandatory law, it is limited to the minimum the law requires.
Keep your password secret. Accounts used for spam, fraud or that put the service at risk may be suspended or removed, and the service may be changed or discontinued at any time.
We may update these terms; the date below shows the latest version, and continuing to use the service means you accept it. Swiss law applies.