← What Receipt?

Privacy Policy

Effective: 2026-10-01 (draft, pending legal review)

Draft. Replace the bracketed items and have it reviewed before publishing. Google's OAuth verification checks that the Limited Use paragraph below is present verbatim.

Who we are

What Receipt? is operated by Dylan Roy ("we"). Contact: privacy@whatreceipt.app. Mail: 7251 Maple Grove Road, Cloquet, MN 55720, United States.

What we collect

DataWhyKept
Account email and sign-in identity (via Firebase Authentication, Apple or Google sign-in)To create and secure your accountUntil you delete your account
Receipt images and PDFs you upload or that we import from your emailTo read, file and show your receiptsUntil you delete the receipt or your account
Fields extracted from receipts (vendor, date, amounts, categories, visible text)The product: search, insights, exportsSame as above
Gmail connection: an encrypted refresh token, your Gmail address, and a list of message IDs we have already checkedTo import receipts and avoid re-processing the same messageUntil you disconnect Gmail or delete your account
Billing status (plan, renewal date) from Stripe, Apple or GoogleTo unlock paid featuresDuration of the subscription plus accounting retention
Basic technical logs (request timestamps, errors)To keep the service running30 days

We do not sell personal data. We do not show ads. We do not build advertising profiles.

Gmail access

If you connect Gmail, you grant What Receipt? read-only access (gmail.readonly). We use it only to search for receipt-like messages (for example, messages whose subject mentions a receipt, invoice or order confirmation, or that carry a PDF attachment with those words), and to download the receipt attachment or the message text when it is a receipt. Messages that are not receipts are not stored; we keep only their message ID so we do not check them again.

We never read, store or index your mailbox as a whole, your contacts, labels, or messages that are not receipts. We do not send email from your account.

Limited Use disclosure. What Receipt?'s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

You can disconnect Gmail at any time in Settings. Disconnecting revokes our access with Google and deletes the stored token and the message index. Receipts already imported remain in your account unless you delete them.

How receipts are read

Receipt images, PDFs and receipt email text are sent once to an AI model provider (Anthropic) to extract the fields shown in the app. Under our agreement with the provider this content is not used to train their models. Extracted fields are stored in your account; the request itself is not retained by us beyond the technical logs above.

Where data is stored and who processes it

Your choices and rights

The Mac Privacy Edition

The Mac app, when not signed in to an account, stores everything on your computer and sends nothing to us. If you enable the optional local AI, it runs on your machine.

Children

What Receipt? is not directed at children under 13 and we do not knowingly collect their data.

Changes

We will post changes here and, for material changes, notify you in the app or by email.