Privacy Policy
1. Introduction
This Privacy Policy explains how ReceiptFlow ("we", "our", or "us") collects, uses, and protects information when you use the ReceiptFlow mobile application.
2. Contact
If you have privacy questions, contact: bob.marin9613@gmail.com
3. Information We Process
3.1 Receipt and app data
ReceiptFlow processes receipt images on your device to recognize text. A saved receipt record may include vendor, amount, tax, date, category, notes, raw recognized text, client and project names, receipt number, payment method, currency, deductible status, duplicate and quality information, timestamps, and an edit audit trail. Recognized text may also contain names, addresses, phone numbers, payment-related details, or other personal or financial information printed on a receipt.
The source image is used for on-device recognition and is not added to the saved ReceiptFlow record or Google Drive backup. Receipt records, merchant rules, tax-mode status, app settings, reminder preferences, and purchase entitlement status are stored locally on your device.
3.2 Permissions and device access
- Camera: to capture a receipt for on-device text recognition.
- Photos/Media: to select a receipt image from your device.
- Notifications: to deliver reminders you configure.
- Internet: to load ads, process purchases, connect optional Google Drive backup, and transmit optional analytics or crash diagnostics after consent.
3.3 Optional Google Sign-In and Google Drive backup
Google Drive backup is an optional premium feature. ReceiptFlow does not create a ReceiptFlow account. If you choose to connect Google Drive, Google Sign-In authenticates an existing Google Account. Google Sign-In may make basic account details such as your name, email address, and Google account identifier available during authentication. ReceiptFlow uses and stores the connected email address locally only to show which account is connected; it does not include that email address in analytics or the backup file.
ReceiptFlow requests only the Google Drive application-data scope. It creates or updates a file named receiptflow_backup.json in the hidden appDataFolder of your own Google Drive. That folder is accessible to ReceiptFlow through your authorization and is not a normal user-visible Drive folder.
The backup contains the saved receipt records described in section 3.1, including raw recognized text, together with merchant rules and tax-mode status. It does not contain the source receipt images, Google account email, purchase credentials, or advertising data. Backup traffic is encrypted in transit by Google's HTTPS services.
3.4 Optional Firebase Analytics and Crashlytics
Firebase Analytics and Firebase Crashlytics are disabled by default. ReceiptFlow asks you once whether you want to share limited usage analytics and crash diagnostics. They remain off unless you explicitly allow them, and you can change the choice later under Settings.
If enabled, Google Firebase may process app and device information, pseudonymous installation or device identifiers, automatically generated app/session events, controlled feature events (such as onboarding completion, camera versus gallery entry, OCR success or failure, reminder status, paywall and purchase outcome, and export format), and crash reports containing stack traces and technical app/device state.
ReceiptFlow does not intentionally send receipt or OCR contents, vendor names, amounts, taxes, dates, notes, categories you enter, client or project data, images, file paths, exact reminder times, Google account email, purchase tokens, or order IDs to Firebase. Firebase advertising-ID collection and Analytics ad-personalization signals are disabled in the app configuration.
Turning this setting off requests the Firebase SDKs to stop future automatic collection and deletes Crashlytics reports that remain unsent on your device. It does not delete analytics events or crash reports that were already transmitted to Google.
3.5 Google AdMob and advertising consent
The free version may display Google AdMob ads. AdMob may automatically collect and share an IP address (which can estimate approximate location), app interactions, diagnostic information, and device or account identifiers (including an advertising identifier when available) for advertising, analytics, personalization where permitted, and fraud prevention. ReceiptFlow does not send receipt records or receipt images to AdMob.
Where required, Google's User Messaging Platform asks for advertising consent before ads are requested. You can review or change available advertising privacy choices in ReceiptFlow Settings. This advertising choice is separate from the optional Firebase Analytics and Crashlytics choice.
3.6 Purchases
Google Play Billing processes in-app purchases. ReceiptFlow receives the product and purchase status needed to unlock premium features. Google handles payment credentials under its own policies; ReceiptFlow does not receive or store your full payment-card details.
4. How We Use Information
We use information to:
- Provide core receipt scanning and expense tracking functionality.
- Save and display your receipt history.
- Generate exports (CSV/PDF) when requested.
- Provide optional Google Drive backup and restore when you connect it.
- Improve app reliability and user experience when optional Firebase collection is enabled.
- Display ads and process advertising choices in the free version.
- Process purchase status and unlock premium features.
5. Data Storage and Retention
- Receipt and settings data are stored locally on your device until you delete them or the operating system removes the app's data.
- If you enable Google Drive backup, the latest backup remains in your Google Drive application-data folder until it is overwritten or you remove that app data through Google Drive.
- Deleting or uninstalling ReceiptFlow from your phone does not by itself guarantee deletion of an existing Google Drive backup.
- Google, Firebase, AdMob, and Google Play retain data they process according to their applicable settings, retention rules, and privacy policies.
6. Data Sharing
We do not sell your personal data.
Data is transmitted to Google only when needed for the features described above: Google Sign-In and Drive for optional backup, Firebase after optional telemetry consent, AdMob for advertising, and Google Play for purchases. These services process data under their own terms and privacy policies.
7. Children's Privacy
ReceiptFlow is not directed to children under 13. If you believe a child has provided personal data, contact us and we will address the issue.
8. Your Choices
You can:
- Revoke permissions in device settings.
- Disable reminders in app settings.
- Delete receipts and notes stored locally in the app.
- Turn optional Firebase Analytics and Crashlytics on or off in ReceiptFlow Settings.
- Review or change available AdMob privacy choices in ReceiptFlow Settings.
- Connect or disconnect Google Drive backup.
Google Drive disconnection and deletion: Disconnecting Google Drive in ReceiptFlow clears the locally cached connected-email and backup status, turns off automatic backup, and asks Google Sign-In to disconnect the Google authorization. It does not delete receiptflow_backup.json or the hidden Drive application-data folder.
Deleting a receipt in ReceiptFlow deletes the local record. If automatic backup remains enabled, a later backup updates the single Drive backup with the current local data. If no later backup occurs, the existing Drive backup may still contain the previously backed-up record. ReceiptFlow currently has no in-app command to delete the remote backup. To remove it, delete ReceiptFlow's hidden app data using Google Drive's connected-app or manage-app-data controls. You may also contact us for guidance.
Because ReceiptFlow does not create its own user account, there is no separate ReceiptFlow account to delete.
9. Security
We use reasonable safeguards, but no method of storage or transmission is 100% secure.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Updated versions will include a new "Last updated" date.
11. Legal Basis and Regional Rights
Depending on your region, you may have rights to access, correct, delete, object to, withdraw consent for, or limit processing of your personal data. You can withdraw optional Firebase consent and available advertising consent through Settings. For other requests, contact us at the email above. We may need information sufficient to understand the request, but we cannot directly access or delete data that exists only on your device or in your private Google Drive.