Privacy Policy
Effective: 2026-10-01 (draft, pending legal review)
Draft. Replace the bracketed items and have it reviewed before publishing. Google's OAuth verification checks that the Limited Use paragraph below is present verbatim.
Who we are
What Receipt? is operated by Dylan Roy ("we"). Contact: privacy@whatreceipt.app. Mail: 7251 Maple Grove Road, Cloquet, MN 55720, United States.
What we collect
| Data | Why | Kept |
|---|---|---|
| Account email and sign-in identity (via Firebase Authentication, Apple or Google sign-in) | To create and secure your account | Until you delete your account |
| Receipt images and PDFs you upload or that we import from your email | To read, file and show your receipts | Until you delete the receipt or your account |
| Fields extracted from receipts (vendor, date, amounts, categories, visible text) | The product: search, insights, exports | Same as above |
| Gmail connection: an encrypted refresh token, your Gmail address, and a list of message IDs we have already checked | To import receipts and avoid re-processing the same message | Until you disconnect Gmail or delete your account |
| Billing status (plan, renewal date) from Stripe, Apple or Google | To unlock paid features | Duration of the subscription plus accounting retention |
| Basic technical logs (request timestamps, errors) | To keep the service running | 30 days |
We do not sell personal data. We do not show ads. We do not build advertising profiles.
Gmail access
If you connect Gmail, you grant What Receipt? read-only access (gmail.readonly). We use it only to search for receipt-like messages (for example, messages whose subject mentions a receipt, invoice or order confirmation, or that carry a PDF attachment with those words), and to download the receipt attachment or the message text when it is a receipt. Messages that are not receipts are not stored; we keep only their message ID so we do not check them again.
We never read, store or index your mailbox as a whole, your contacts, labels, or messages that are not receipts. We do not send email from your account.
Limited Use disclosure. What Receipt?'s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Gmail at any time in Settings. Disconnecting revokes our access with Google and deletes the stored token and the message index. Receipts already imported remain in your account unless you delete them.
How receipts are read
Receipt images, PDFs and receipt email text are sent once to an AI model provider (Anthropic) to extract the fields shown in the app. Under our agreement with the provider this content is not used to train their models. Extracted fields are stored in your account; the request itself is not retained by us beyond the technical logs above.
Where data is stored and who processes it
- Google Cloud / Firebase (authentication, application servers, database, private file storage) — United States (us-central1).
- Anthropic (receipt field extraction).
- Stripe, Apple, Google (payments; we never see full card numbers).
Your choices and rights
- Export everything as CSV or Excel at any time from the app.
- Delete any receipt, disconnect Gmail, or delete your whole account from Settings. Account deletion removes your receipts, files, extracted data, and Gmail connection within 30 days (backups roll off within 35 days).
- If you are in the EU/UK or California you may also have rights to access, correct, restrict or object; email us and we will honor them within 30 days.
The Mac Privacy Edition
The Mac app, when not signed in to an account, stores everything on your computer and sends nothing to us. If you enable the optional local AI, it runs on your machine.
Children
What Receipt? is not directed at children under 13 and we do not knowingly collect their data.
Changes
We will post changes here and, for material changes, notify you in the app or by email.