Privacy Policy
ReceiptFold turns the receipts and invoices you forward by email into rows in a spreadsheet that you own. This policy explains what we process, where it lives and what we never keep.
1. Who we are
ReceiptFold is operated by the owner of receiptfold.com ("we", "us"). Contact: [email protected].
2. What we process
- Your account: your email address, sign-in tokens, your language and your plan.
- Forwarded mail: receipts and invoices you (or a forwarding rule you set up) send to your ReceiptFold address. We parse them to extract the vendor, amount, currency, date, invoice number and period.
- Your spreadsheet: with your permission, we write the extracted rows into a Google Sheet or an Excel workbook on your OneDrive. That file is the only place the extracted invoice data is stored.
- Usage counters: how many documents were processed per month, for plan limits and billing.
3. What we never keep
- We do not store the raw emails or their attachments. A message is parsed in memory and discarded. If our parser is temporarily unavailable, the message is held in encrypted object storage for at most 24 hours and then deleted.
- We do not store the rows of your spreadsheet on our side. Dashboards read from your file and cache an aggregated view for at most five minutes.
- We do not read any file in your Google Drive or OneDrive other than the ones ReceiptFold created or you explicitly picked for an import.
4. Google and Microsoft access
When you connect a spreadsheet, we request the narrowest scope available: drive.file on Google (files created or opened with the app only) and Files.ReadWrite.AppFolder on Microsoft (the app's own folder only). Refresh tokens are encrypted at rest with a key we rotate. Disconnecting the store or deleting the workspace revokes the token at the provider and deletes it on our side. ReceiptFold's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Optional AI parsing with your own key
If you add your own OpenAI, Anthropic or Gemini API key, documents our rules cannot parse are sent to that provider under your account and their terms. The key is encrypted at rest and never shared. Without a key, nothing leaves our infrastructure.
6. Where data is processed
Mail intake and the dashboard run on Cloudflare; parsing runs on Google Cloud (us-east1). Payments, if you subscribe, are handled by Stripe; we never see your card number.
7. Retention and deletion
Account data is kept while your account exists. Deleting a workspace revokes its spreadsheet access and removes its settings, addresses and counters immediately; your spreadsheet stays with you. You can delete your account from Settings or by writing to us.
8. Your rights
You can access, export (CSV) and delete your data at any time from the dashboard. If you are in the EU/EEA or the UK you also have the rights set out in the GDPR, including the right to lodge a complaint with your supervisory authority.
9. Changes
We will post any change to this policy on this page and update the effective date above.