Last updated: 2026-02-21
Privacy Overview
- Receipt data is processed securely and deleted immediately after processing.
- No personal data or receipts are stored on our servers.
- We never sell your personal information. Data is shared only with Google Gemini AI for classification (see Section 4).
- You control your data completely, including optional iCloud backup.
1. Introduction
ReceiptIQ ("we," "us," or "our") values your privacy. This Privacy Policy explains how we handle your data when you use our iOS app.
2. Information We Collect and Send
When you use ReceiptIQ's AI-powered features, the following data is sent from your device to our servers, which then forward it to Google Gemini AI for processing:
- Receipt Text: When you scan a receipt, the text extracted by on-device OCR is sent to our servers, which forward it to Google Gemini AI for classification. The original receipt image never leaves your device. The structured data is immediately returned and no copies are stored on our servers.
- Voice Input Transcriptions: When you use voice input to add a transaction, the transcribed text is sent to our servers and forwarded to Google Gemini AI for parsing into structured receipt data.
- Bank Statement Text: When you scan a bank statement, the extracted text is sent to our servers and forwarded to Google Gemini AI for parsing into individual transactions.
- Aggregated Spending Summaries: When you request spending insights, aggregated category totals and budget data (not individual receipt details) are sent to our servers and forwarded to Google Gemini AI for analysis.
- Device Language & Country: Your device's language and country settings are sent to provide localized AI responses.
- Device Identifier: A unique device identifier is sent for rate limiting and fair usage enforcement. This identifier cannot be used to identify you personally.
- iCloud Backup: If enabled in settings, your receipt data can be backed up to your personal iCloud account. This is an optional feature that you can enable or disable at any time. The backup is encrypted and only accessible through your Apple ID.
What We Do NOT Send: By default, receipt images stay on your device and are never uploaded. We do not collect your name, email address, or any other personal identity information through AI processing.
Optional: Multimodal Processing (Beta): You can opt in to enhanced scanning accuracy via Settings → Developer Options → Server Mode: Beta → "Send Receipt Image (Beta)". When enabled:
- A resized copy of the receipt image (max 512 px, ~150 KB JPEG) is sent to our beta server alongside the OCR text.
- The image is processed by Google Gemini for scan accuracy only.
- No image is stored on our servers. We do not log, retain, or back up images.
- Because we use a paid Google AI API, your image is not used to train Google's models. Images are also never used for advertising or user profiling.
- You can disable this at any time in Settings. Default is OFF — when off, receipt images stay on your device, as described above.
This feature is in Beta. Default behavior remains: receipt images stay on your device.
Optional: Web Sync (Developer Beta): You can opt in to a read-only browser view of your receipts at app.receiptiq.me via Settings → Developer Mode → Web Sync (Beta). Unlike all other ReceiptIQ features, this one does store your data on our servers, so it has a stricter disclosure. When enabled:
- A copy of each receipt's structured data (store name, date, items, totals, category) is sent to our Cloudflare backend and stored in a Cloudflare D1 database located in Western North America.
- Receipt images are stored in Cloudflare R2 object storage, scoped to your Apple stable user id. Maximum file size 5 MB per image, JPEG.
- Authentication uses Sign In with Apple. We receive your Apple stable user id (a long opaque string, not your real email unless you choose to share it) and store it as the row key. If you use Apple's "Hide My Email" feature, we only ever see the private-relay address.
- Data is only accessible to you via your Apple ID. There is no admin dashboard, no analytics on the contents, and no third-party access.
- Data is not used to train any AI model, for advertising, or for any purpose other than serving your own browser view.
- When you turn off the Web Sync toggle or sign out, no new data is uploaded. Already-uploaded data remains until you delete it (a delete-my-data flow will be added before this feature leaves Developer Mode).
- This feature is gated behind Developer Mode and is intended for the developer's own testing. Default is OFF.
Standard ReceiptIQ behavior — receipt data never leaving your device + your iCloud — is unchanged when Web Sync is OFF.
Your Consent is Required: Before any data is sent for AI processing, the app presents a clear consent screen explaining exactly what data is shared and who receives it. You must explicitly agree before any data leaves your device. You can revoke consent at any time in Settings > Data & Privacy, and continue using the app for manual transaction entry.
Data Storage: Your data is processed in real-time by Google Gemini AI and is never retained or stored on our servers or by Google. When iCloud backup is enabled, your data is stored securely in your personal iCloud account, not on our servers.
3. Use of Your Information
- AI Classification: Receipt text, voice transcriptions, and bank statement text are sent to our servers, which forward them to Google Gemini AI for classification into structured expense data (store name, date, items, categories, totals).
- Spending Insights: Aggregated spending summaries are sent to our servers, which forward them to Google Gemini AI to generate personalized spending analysis and budget recommendations.
- Providing Services: We process your data solely to categorize expenses and present them in a structured format. Data is not used for advertising, profiling, or any purpose other than providing app functionality.
- Support Services: If you request technical support, we might briefly access your data strictly to resolve your issue, with your explicit consent.
4. Third-Party Data Sharing
- We do not sell your personal information to any third parties.
- Google Gemini AI: Receipt text, voice transcriptions, bank statement text, and aggregated spending summaries are forwarded from our servers to Google Gemini AI (operated by Google LLC) for classification and analysis. Google processes this data under their Gemini API Terms of Service. According to Google's data governance, data sent via the Gemini API is not used to train Google's models.
- Both ReceiptIQ and Google maintain strict data protection standards. No receipt images are ever shared — only extracted text.
- Apart from Google Gemini AI, we do not share your data with any other third parties.
5. Data Security
- We implement robust security measures to protect your data during processing.
- However, we cannot guarantee absolute security. Use the app at your own discretion and risk.
6. Fair Use Policy
- This app is designed exclusively for personal receipt management. Excessive or commercial use may trigger usage limits.
- To maintain fair usage, each user is limited to uploading a maximum of 20 receipts per 24-hour period, which should be sufficient for typical personal and family expenses.
- iCloud backup and restore features are subject to your Apple ID's storage limits and iCloud terms of service.
- Please contact us if you're interested in commercial or high-volume plans.
7. Your Data, Your Control
- You may stop using ReceiptIQ at any time without penalty.
- For questions about data handling or requests regarding data privacy, contact us at [email protected].
8. Updates to This Policy
We may update this Privacy Policy periodically. Continued use of ReceiptIQ following any changes means you accept those changes.
9. Contact Information
If you have any concerns or questions about this Privacy Policy, please reach out to us at [email protected].