Privacy Policy
Last updated: July 7, 2026
This Policy explains what information ReceiptCash AI collects, how we use it, and your choices. We only collect what we need to run the Service, and we never sell your data or show ads.
Information we collect
- Account info: your name, email address, and (optionally) your country/region.
- Receipt data: the text extracted from receipts you scan (store, date, items, prices). We do not keep your receipt photos — the image is deleted immediately after the text is extracted.
- Claim & refund data: claims you draft and amounts you report as recovered.
- Support data: details you send us (email, phone/WhatsApp, message, attachments) when you contact support.
- Community content: posts and comments you share in Refund Republic are visible to other users along with your display name. Please don't include sensitive personal data. You can delete your posts, and you can report others' content for review.
- Usage data: basic technical information needed to operate and secure the app (e.g., device type, approximate region, app events).
- Payment data: handled by our payment provider (a Merchant of Record). We receive confirmation of a transaction but never your full card number.
How we use it
To provide the Service (scan receipts, match store policies, draft claims), to track your savings and achievements, to process the unlock price and service-credit purchases, to provide customer support, and to improve and secure the app.
Service providers we share data with
We use trusted third parties strictly to run the Service:
- Supabase — database, authentication, and storage.
- Google (Gemini AI) & Groq — read receipt text and draft/translate claims during processing.
- Google Sign-In — if you choose to log in with Google.
- our Merchant of Record — our Merchant of Record; processes payments and taxes.
- Vercel & Cloudflare — application hosting, delivery, and security.
We do not sell your personal information to anyone.
Data retention & deletion
We keep your account data while your account is active. You can request deletion of your account and associated data at any time by emailing [email protected]; we will delete it within 30 days, except where we must retain limited records for legal or accounting reasons.
Your rights
Depending on where you live (including under GDPR/UK GDPR and similar laws), you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these, contact us at the email below.
Security
We use encryption in transit (HTTPS), row-level access controls, and reputable infrastructure providers. Receipt images are never stored after processing. No system is perfectly secure, but we work to protect your data.
Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from children.
Asia-Pacific: your regional privacy rights
Where you live, additional data-protection laws may apply to you. We apply the same protections to everyone, and the rights below are available regardless of where you are.
- Singapore (PDPA). We have designated a Data Protection Officer (see “Data Protection Officer” below). You may withdraw consent, and request access to or correction of your personal data, at any time.
- Japan (APPI), South Korea (PIPA), Taiwan (PDPA), India (DPDP Act), Australia (Privacy Act). You may request access, correction, deletion, or withdrawal of consent, and may complain to your national data-protection authority.
- Cross-border processing. Our infrastructure providers (listed above) process and store data outside your country. We only use reputable providers that maintain protections comparable to those required by your local law, and we contract them to protect your data.
Data Protection Officer
We have appointed a Data Protection Officer responsible for how we handle personal data. You can reach the DPO — including to make an access, correction, deletion or consent-withdrawal request, or to raise a complaint — at [email protected] (subject line: “DPO request”). We aim to acknowledge within 5 working days and to respond substantively within 30 days.
What we deliberately do not collect
By design, we minimise sensitive data rather than protect it after the fact:
- We do not keep receipt or document images after processing.
- We do not collect passport numbers, national ID numbers, nationality or immigration status.
- We do not store health information. Where a document is reviewed for billing errors, it is read in memory and only a non-identifying summary of the billing issue is kept.
- We do not connect to your bank, hold your money, or process your refund — the retailer, airline, insurer or authority pays you directly.
Contact
Questions about your privacy? Email [email protected].