Privacy Policy
Last updated July 29, 2026
ReceiptWell helps you scan receipts, budget your spending, and prepare tax-ready records. This policy explains what we collect, why, and the control you keep over your data. We wrote it to be read, not to be survived.
Who we are
ReceiptWell is operated by ReceiptWell (the “Company,” “we,” “us”), a company based in Canada. We are the party responsible for the personal information handled through the ReceiptWell website and application (the “Service”). If you have questions, contact us at privacy@receiptwell.com.
What we collect
We collect only what the Service needs to work:
- Account details — your name, email address, and (if you sign in with Google) your Google profile basics. If you use email and password, we store a secure hash of your password, never the password itself.
- Receipt and financial data — the receipt images you capture or forward, and the merchant, date, amounts, tax lines, categories, budgets, mileage, and notes you or the Service derive from them.
- Billing data — if you subscribe to Pro, our payment processor (Stripe) handles your card details. We never see or store your full card number.
- Technical data — basic logs needed to run and secure the Service (for example, IP address, device and browser type, and error diagnostics), plus page-speed measurements from the pages you visit so we can find and fix slow screens.
How we use your data
We use your information to provide the Service: to read and organize your receipts, run your budgets and tax estimates, generate exports, process your subscription, secure your account, and provide support. We also use aggregate, de-identified information to improve accuracy — for example, to make our receipt parser better over time. We do not use the content of your receipts to build advertising profiles.
Receipt images and where they are stored
Receipt images are stored in object storage (Cloudflare R2) and are accessed through short-lived, signed links — never made public. Your structured data (transactions, budgets, categories) is stored in a managed Postgres database (Neon). Some of our infrastructure providers may process or store data outside Canada, including in the United States; by using the Service you understand your data may be handled in those locations under contractual and legal safeguards.
Reading your receipts
Reading a receipt normally happens on your own device — the text recognition runs in your browser, and no image leaves your device to be read. When a receipt is hard to read (a long or crumpled tape, a dim photo) and our on-device reader can't confidently balance the totals, we may send that single receipt image to a trusted cloud service (Google's Gemini) for the sole purpose of extracting its amounts. We send the image and nothing else — not your name, your email address, or your account identifiers. The result is used only when the numbers add up, and is not used for advertising. You can always enter or correct a receipt's details yourself.
On training: Google's terms for this API treat paid and free use differently — content sent from a billedGoogle Cloud project is not used to improve or train Google's models, while free-tier use of the same API can be. We run this feature only on a billed project, so your receipt images are not used to train models. If that ever changes, we will update this policy before the change takes effect.
The on-device reader needs its recognition model files. Most of them we host ourselves; one set is downloaded by your browser from a public open-source CDN (tessdata.projectnaptha.com, with the matching program files from jsDelivr or unpkg). Those hosts see your IP address and which model file you asked for. No part of your receipt is sent to them.
Connecting QuickBooks (only if you choose to)
ReceiptWell can send your expenses to QuickBooks Online. This is off unless you connect your QuickBooks account, and nothing is sent until you press the button on a transaction (or on a batch you select).
When you do, we send Intuit — the company behind QuickBooks — the expense we are creating for you: the merchant, date, total, currency, each line item's description and amount, and a private note carrying the category, payment method, and any notes you wrote. We also attach the receipt image itself to that expense in QuickBooks, so your books hold the proof, not just the number. Once it is in QuickBooks it is governed by your agreement with Intuit, and you manage or delete it there. You can disconnect QuickBooks at any time in Settings; disconnecting stops future sends but does not remove what was already filed in your QuickBooks account.
We do not sell your data
We do not sell, rent, or trade your personal information, and we do not share it with third parties for their own marketing. We share data only with the service providers listed below, each bound to use it only to provide their service to us — and where the law requires disclosure.
Service providers we use
This is the full list of companies that can receive your data through ReceiptWell, and what each one gets:
- Vercel (hosting) — runs the website and the app. Receives your requests, IP address, and device/browser information.
- Vercel Speed Insights (page-speed measurement) — runs on every page, including pages you see after signing in. It reports how fast a page loaded and responded, along with the page's route pattern (for example /receipts/[id], not the receipt id), your device and browser, and your IP address. It never receives receipt contents, amounts, or your email address.
- Neon (database) — stores your account and your structured records: transactions, categories, budgets, mileage, and the fields read from your receipts.
- Cloudflare R2 (file storage) — stores your receipt images and the export files you generate.
- Stripe (payments) — handles subscription payments and your card details, which we never see or store.
- Resend (email) — sends your account email (verification, password reset, invitations, alerts) and, if you use the forwarding address, receives the receipts you email in.
- Google— sign-in, if you use it (see below), and the Gemini receipt read described above, which receives a single receipt image when our on-device reader can't balance the totals.
- Intuit (QuickBooks) — only if you connect QuickBooks, and only for the expenses you send. Receives the expense details and the receipt image, as described above.
- Open-source model hosts — your browser downloads text-recognition model files from a public CDN. They see your IP address, never your receipts.
- Inngest (background jobs) — used when background processing is switched on. It receives only internal record identifiers (a receipt id, a workspace id, an export job id) so it can tell our own servers what to work on; it never receives receipt images, amounts, names, or email addresses.
Company logos shown beside well-known merchants are fetched by our servers from a logo provider using a fixed list of brand domains, then cached by us. Your browser never contacts that provider, and nothing about you or your receipt is sent to it.
Some of these providers process or store data outside Canada, including in the United States.
Signing in with Google
If you choose Google sign-in, we request only your basic profile (your name, email address, and profile identifier) to create and secure your account. ReceiptWell's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not allow humans to read it except with your consent, for security or legal reasons, or as needed to operate the Service.
Cookies
We use only the cookies needed to keep you signed in and to keep the Service secure. We do not use advertising or cross-site tracking cookies.
How long we keep things
We keep personal information only as long as we need it for the purpose it was collected for. In practice:
- Receipts, transactions, budgets, and mileage — kept for as long as your account is active, because they are the records you came here to keep. They are deleted when you delete them or when your account is closed.
- Account and profile — kept while your account is active, and deleted when it is closed.
- Sign-in sessions — expire 30 days after you sign in, and you can revoke them sooner from Settings.
- Security and activity logs — the IP addresses recorded alongside sensitive actions are deleted after 90 days. The record that the action happened is kept as part of your workspace history.
- Emailed-in receipt records — the log of which address forwarded what (used to route mail and to avoid filing the same receipt twice) is deleted after 90 days. The receipt itself stays with your records.
- Payment and tax records — invoices and subscription records are kept for as long as tax and accounting law requires, even after an account closes.
When something is deleted it goes from the live Service immediately. Copies can survive a little longer in our providers' encrypted backups and point-in-time restore history, which roll forward on a fixed schedule and overwrite themselves; we do not restore deleted data from them except to recover from a failure.
Exporting and deleting your data
You can export your data at any time from the app, on any plan — exports are never paywalled. The export center gives you a CSV of your full transaction history (including line items), a PDF report, and a full-data ZIP containing that CSV plus your receipt images. The ZIP currently includes up to 1,000 receipt images — its manifest says how many were included and how many were left out. Mileage trips, vehicles, and budgets are not part of the ZIP today; if you need them, email us and we will send them to you.
You can delete individual receipts and transactions yourself, and you can ask us to delete your entire account and its data by contacting privacy@receiptwell.com. We will delete your receipt images and records, and instruct our processors to do the same, except where we must retain limited records to meet legal or tax obligations.
One honest limit: if you share a workspace with other people, deleting your account removes you and your personal record, but it does not delete that shared workspace or the receipts in it — those belong to the people still using it. Workspaces where you are the only member are erased in full, images included.
Your rights
Subject to applicable law (including Canada's PIPEDA and, where it applies, provincial privacy law), you can ask to access, correct, or delete your personal information, and withdraw consent to optional processing. To exercise these rights, contact privacy@receiptwell.com. We answer within 30 days, or within 45 days for requests made under California's privacy law. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada.
Children
ReceiptWell is a business tool intended for adults. It is not directed to children, and we do not knowingly collect data from anyone under the age of majority.
Changes to this policy
If we make a material change, we will update the date above and, where appropriate, notify you in the app or by email. Continuing to use the Service after a change means you accept the updated policy.
Contact
Questions or requests about your privacy? Email privacy@receiptwell.com and we will respond promptly.