RECEIPT SCANNER

Privacy & Security

Private by design.

Your receipts, project finances and reports are protected by authenticated access, private storage and workspace/project permissions.

How your data is protected

Security controls used by Receipt Scanner today.

Private storageReceipt images and generated reports are stored in private Supabase Storage buckets, not public folders.
Access controlsDatabase Row Level Security and project permissions limit what signed-in users can see and change.
Encrypted connectionsApp traffic uses HTTPS/TLS. Hosted database and storage encryption at rest is provided by our infrastructure provider.
Protected Google credentialsGoogle refresh tokens are additionally encrypted with AES-256-GCM before they are stored.

Data retention

We keep application data only while it is needed for your account and projects.

Active account: project data remains available while the account/workspace exists so you can reopen projects and access final reports.

Deleted receipts: Receipt Scanner provides a short Undo period before permanent receipt deletion is finalized.

Deleted account: data belonging to workspaces you own is removed from the live Receipt Scanner application when account deletion completes. Shared-project accounting history may remain without your account identity so another owner’s financial records are not corrupted.

Provider records: temporary infrastructure backups, security logs, email delivery records and legally required payment records may remain for limited periods under the applicable service provider’s retention rules.

Privacy Policy

Effective August 22, 2026

Information we process

Receipt Scanner processes account information, project and team details, receipt images, expense and cash-flow data, accounting lines, report files and the settings you choose to connect.

How we use it

We use this information only to authenticate users, run your projects, process receipts, calculate project balances, synchronize features you enable, generate reports, provide support and operate billing.

Service providers

Receipt Scanner uses Supabase for hosted authentication, database and file storage; Google Gemini for AI receipt recognition when you use scanning; Google APIs when you connect Google Sheets; Stripe for subscription billing; Postmark for transactional invitation email; and Vercel for application hosting.

AI receipt processing

When AI Scan is used, the receipt image is sent to Google Gemini for recognition. Receipt Scanner requests non-persistent processing for these interactions. The extracted values you confirm are then stored with your expense.

Sharing

We do not make your project data public and do not sell it to advertisers. Data is shared with authorized project/workspace members and with service providers only as required to operate the features you use.

Google Workspace API data

Google Sheets access is optional. When connected, Receipt Scanner reads and writes project information only in the spreadsheet you explicitly select for the project.

Limited Use compliance: The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Receipt Scanner does not use Google Workspace API user data to create, train, or improve foundational or generalized AI/ML models.

Payments

Payment information is handled by Stripe. Receipt Scanner does not store your full card number.

Your choices

You can remove individual receipts, disconnect optional integrations, stop using the service, or permanently delete your Receipt Scanner account. Account deletion also cancels an active Receipt Scanner subscription attached to an owned workspace.

Contact

Privacy, data-access or deletion questions can be sent to support@receiptscanner.pro.

Sign in to manage or delete your Receipt Scanner account.

Sign in