Privacy Policy
Last updated: 29 July 2026
Who we are
What we collect
- Account data: email address, name if provided, and session and security data such as IP address and browser details.
- Receipt data: receipt images or PDFs and the details they contain, such as merchant, date, amount, tax, category, notes, line items, and the last four digits of a payment card when present.
- OCR data: files sent for extraction, processing status, extracted fields, and your OCR consent record.
- Feedback: the title and description you submit, plus browser details for bug reports.
- Access requests: your email and any optional notes.
- Analytics: limited page-view and performance data through Vercel Analytics, only if you accept optional analytics.
Why we use data
- To provide the service: create and secure accounts, store receipts, and provide exports and settings.
- With consent: send files to OpenAI for OCR and load optional analytics. You can decline OCR and change your analytics choice at any time.
- For legitimate interests: prevent abuse, maintain security, and fix problems reported through feedback.
OCR processing
If you enable scanning, your receipt image or PDF is sent to OpenAI to extract text and receipt fields. Only upload files you are authorised to process. We send requests with store: false, which asks OpenAI not to keep the response for later retrieval. OpenAI may still retain content for abuse monitoring under its API policies. OpenAI says API data is not used to train its models by default.
Service providers
- Supabase — database and private receipt storage
- OpenAI — optional OCR
- Resend — magic links and account emails
- Vercel — hosting and optional analytics
- GitHub — feedback submitted as product issues
These providers may process data outside the UK or European Economic Area under their own privacy terms and applicable transfer safeguards.
Cookies and analytics
Essential cookies are needed for authentication and session security. Optional analytics only load after you accept through the banner or the controls below. You can change your choice from Account → Privacy.
Analytics preference
Current choice: Not set. Optional Vercel Analytics is only loaded when accepted.
Retention and deletion
We keep account and receipt data while your account is active. A daily job also applies these limits:
- Raw OCR responses are cleared after 7 days.
- Unattached OCR jobs and their uploaded files are deleted after 30 days.
- Access requests are deleted after 90 days if pending, or 30 days after a decision.
Deleting your account removes your receipts, categories, exports, OCR jobs, and stored files from our systems. Copies held by providers or backups may remain temporarily under their retention rules.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or export your data, object to some processing, and withdraw consent. Contact us to exercise these rights.
- Export receipt data as CSV from Receipts.
- Delete your account from Account → Profile.
- For other requests, contact us using the details above. You may also complain to your local data-protection authority.
Security
We use HTTPS, private receipt storage, user-access checks, and short-lived hashed magic-link tokens. We take reasonable steps to protect your data, but no online service can guarantee complete security.
Changes
We may update this policy as the service changes. We will update the date above. See our Terms of Service for the rules governing use of the service.