CodeXcess logo CodeXcess
How it works Features About FAQ Contact
Get the app
How it works Features About FAQ Contact Get the app
← Back to CodeXcess
Legal · Receiptly

Privacy Policy for Receiptly: Receipt Tracker

Effective Date: January 1, 2026  Last Updated: August 11, 2026


1. Introduction

Code Xcess ("we," "us," or "our") operates the Receiptly mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App, including when you create, join, or use a Group (a shared receipt space).

Please read this Privacy Policy carefully. By using Receiptly, you agree to the collection and use of information in accordance with this policy.

What's new in this version (v3.0):
  • You can now delete your account and all its data from inside the App — Settings → Delete account. Deletion is immediate and irreversible. See §7.5 and §9.3.
  • Group invitation emails are now sent through Resend, not Amazon SES. We no longer use any Amazon Web Services in the App. See §5.5.
  • New sign-in options: Sign In with Apple (iOS), mandatory email verification for email/password accounts, and linking of Email/Google/Apple sign-ins that share one email address into a single account. See §2.1 and §5.1.
  • Device attestation (Firebase App Check) now verifies that requests come from a genuine, untampered copy of the App. See §2.4 and §5.7.
  • Blocked senders: you can permanently block a specific person from inviting you to any Group. Your email address is stored only as a one-way hash for this. See §3.6.
  • Multi-currency display and sharing receipts into the App from other apps (banking apps, email, online stores). See §2.2 and §5.6.
  • Notification history is now browsable in-app and is automatically deleted after 365 days. See §7.6.

2. Information We Collect

2.1 Personal Information

When you use Receiptly, we may collect the following personal information:

  • Account Information: Email address, display name, and — if you upload one — a profile photo
  • Authentication Data: Login credentials and authentication tokens; which sign-in methods are linked to your account (email/password, Google, and/or Apple); and whether your email address has been verified
  • Payment Information: Purchase receipts, transaction identifiers, and subscription status (processed through Google Play Billing and the Apple App Store)
  • Preferences: Your default currency, AI usage mode, theme, amount-visibility setting, and similar in-app settings

Your display name is editable in-app and is not limited to your Google or Apple account name. If you are a member of a Group, your display name and profile photo are visible to other members of that Group (see §3.4).

If you sign in with a method that uses the same email address as an account you already have, the App will offer to link the two so that Email, Google, and Apple all reach one account rather than creating duplicates. Linking is initiated by you and requires you to sign in successfully with an existing method first.

If you use Sign In with Apple and choose Apple's private email relay, we receive only the relay address Apple provides, not your real email address.

2.2 Receipt Data

  • Receipt Images/PDFs: Documents you upload through the App — captured with the camera, picked from your gallery or files, or shared into the App from another app (for example a banking app, an email client, or an online store) using your device's share sheet. A receipt shared in this way always starts out destined for your personal space, never a Group, unless you move it yourself.
  • Extracted Receipt Information: Merchant name, date, price, currency, category, payment method, and notes extracted via on-device OCR or AI scanning
  • Converted Amounts: For a receipt not already in your default currency, we also store the converted amount, the currency it was converted into, and the date of the exchange rate used. Your original amount and currency are never altered. See §5.6.
  • Receipt Metadata: Upload date, last-edited date, who last edited it, favourite status, receipt type (income/expense)
  • Custom Categories & Payment Methods: Custom category names/icons and custom payment method names you create (personal or, if applicable, Group-level)

2.3 Group Data

If you create, join, or are invited to a Group, we additionally process:

  • Invitee Email Address: When another user invites you to a Group, we collect and store the email address they entered, in order to send the invitation and verify your identity when you accept it
  • Invitation Delivery Status: Whether an invitation was delivered, bounced, or was reported as spam, so the sender can correct a mistyped address and so we can suppress repeat invitations to addresses that reject them (see §3.5)
  • Group Membership: Which Groups you belong to, your role within each Group (Owner, Admin, or Member), and when you joined
  • Shared Receipt Data: Receipts uploaded to a Group, and who uploaded or last edited each one (visible to other Group members, see §3.4)
  • Blocked Senders: If you block someone from inviting you, we store their user identifier alongside a one-way cryptographic hash of your email address. The raw email address is not stored in the block record (see §3.6).

2.4 Device Information

  • Device Identifiers: A device-specific identifier and a push-notification (FCM) token, plus your device model, platform, and App version, used to deliver notifications and to let you manage sessions
  • Device Attestation: The App uses Firebase App Check to prove that a request comes from a genuine, untampered copy of Receiptly on a real device. This produces a short-lived attestation token derived from Google Play Integrity (Android) or Apple App Attest (iOS). It contains no personal information, is not used to identify or track you, and is not linked to your receipts. See §5.7.
  • Usage Data: App interactions, feature usage, and error logs
  • Storage Usage: Amount of storage consumed by your receipts (personal and, if applicable, each Group you own)

2.5 Automatically Collected Information

  • Technical Data: IP address, device type, operating system, app version
  • Analytics Data: App performance metrics and crash reports

3. Groups (Shared Receipts)

Receiptly's Group feature lets multiple users share one receipt history, for example, couples, families, or small businesses. Internally, this feature is referred to as a "workspace," but is labelled "Group" throughout the App.

3.1 Who Can Use Groups

  • Creating and owning a Group requires a Premium subscription. The Group owner allocates storage and AI-scan quota from their own plan to the Group.
  • Joining a Group as a member is available to users on any subscription plan, including Free.

3.2 How Group Invitations Work

When an existing Receiptly user invites you to a Group:

  1. They enter your email address in the App.
  2. We send you an invitation email via Resend (see §5.5) containing a secure, time-limited link.
  3. The link opens a web page hosted by us that confirms the invitation is still valid and hands you off to the App. That page only reads the invitation — it never joins you to anything, so an email provider that pre-scans links cannot accept an invitation on your behalf.
  4. The invitation expires after 48 hours and can only be used once.
  5. If you don't already have a Receiptly account, the link will prompt you to create one before joining.
  6. You must accept the invitation while signed in with the same email address the invitation was sent to.

We retain a record of the invitation (the invited email address, who sent it, and its status) as described in §7.4.

Every invitation email also contains a "Block future invitations" link, so you can stop a specific sender without needing a Receiptly account (see §3.6).

3.3 What Happens to Data Inside a Group

  • Receipts uploaded to a Group belong to the Group, not to the individual member who uploaded them. If a member leaves or is removed from a Group, their previously uploaded receipts remain in the Group and remain visible to other members.
  • Your personal receipts (those not uploaded to a Group) are never visible to other users, including other members of any Group you belong to.
  • You choose, at the time of uploading a receipt, whether it is saved to your personal space or to a specific Group. This choice is explicit: a personal receipt is never automatically shared into a Group.

3.4 What Other Group Members Can See About You

If you are a member of a Group, other members of that same Group can see:

  • Your display name, shown next to receipts you've uploaded or edited within that Group ("Uploaded by" / "Last update by")
  • Receipts you upload to that Group, and any edits you make to Group receipts
  • Your role within the Group (Owner, Admin, or Member)

Other Group members cannot see:

  • Your personal (non-Group) receipts
  • Your email address (beyond what was used to invite you, if they were the inviter)
  • Your activity in any other Group you belong to
  • Your personal subscription plan or billing information

3.5 Invitation Delivery and Anti-Abuse Controls

So that the invitation feature cannot be used to spam an address, and so that senders can see when an invitation never arrived, we process delivery outcomes and apply limits:

  • Our email provider reports back whether a message was delivered, bounced (the address rejected it), or was marked as spam. We record that outcome against the pending invitation so the sender can correct a mistyped address. The sender sees only the status, not the contents of any reply.
  • An address that hard-bounces or reports an invitation as spam is suppressed: further invitations to that address from that sender are refused.
  • We enforce limits per address (at most 3 invitation attempts per address, per Group), per sender (at most 200 invitations per day), and per Group (at most 200 outstanding invitations).

These controls exist to protect recipients from unwanted mail and to keep our sending reputation healthy. They are applied automatically and involve no human review of your messages.

3.6 Blocking Invitations from a Specific Sender

  • Every invitation email carries a "Block future invitations" link. Opening it shows a confirmation page; nothing is blocked until you explicitly confirm, so a link pre-scanner cannot trigger it. The action is reversible from the same page.
  • Once blocked, that person can no longer invite you to any Group. Blocking does not affect Groups you have already joined, and the blocked person is not told that you blocked them.
  • A block is stored as the blocked sender's user identifier plus a SHA-256 hash of your email address — your raw email address is not stored in the block record and cannot be recovered from it.
  • If you have a Receiptly account whose email matches, you can review and remove your blocks in the App under Settings → Blocked senders. If you don't have an account, use the link in the email.

3.7 Group Data Retention and Deletion

  • While a Group's owner maintains an active Premium subscription, Group data is retained indefinitely.
  • If the owner's Premium subscription lapses (expires, is cancelled, or downgraded), the Group is locked (read-only) and enters a grace period.
  • If the subscription is not restored within the grace period, all data belonging to that Group, including every member's uploaded receipts, is permanently deleted. This differs from personal account retention (see §7), because Groups are a Premium-exclusive feature with no equivalent storage allowance on lower plans.
  • Members of a Group receive in-app and push notifications at multiple points during the grace period, so they have the opportunity to export their data or encourage the owner to restore their subscription.
  • If you leave a Group voluntarily, are removed by an Owner/Admin, or delete your Receiptly account, your access ends immediately, but receipts you previously uploaded remain part of the Group (see §3.3 and §7.5) unless the Group itself is later deleted.

4. How We Use Your Information

We use the collected information for the following purposes:

4.1 Service Delivery

  • Provide OCR and AI-powered receipt scanning functionality
  • Store and manage your receipt documents, personal and Group
  • Generate expense and income summaries on your dashboard
  • Convert receipt amounts into your chosen default currency (or your Group's currency)
  • Deliver push notifications about subscription status, data retention, and Group activity, and keep an in-app history of those notifications

4.2 Account Management

  • Create and maintain your user account
  • Process authentication via email/password, Google Sign-In, or Sign In with Apple
  • Send an email-verification link to email/password accounts, and link sign-in methods that share one email address into a single account at your request
  • Re-verify your identity before an irreversible action such as deleting your account
  • Manage subscription plans and billing
  • Manage Group membership, roles, and invitations

4.3 AI Processing

  • Process receipt images using Google Gemini AI (via the Firebase AI Logic SDK). This is optional: you can set the App to never use AI and rely entirely on on-device OCR (see §9.4).
  • Track AI scan usage based on your subscription plan (and, for Group uploads, the Group owner's allocated quota)
  • Provide accurate data extraction from receipts

When you choose an AI scan, the receipt image is sent to Google's Gemini service for extraction. We do not use your receipts to train any AI model. When you choose OCR instead, text recognition runs entirely on your device and the image is not sent for AI processing at all.

4.4 Storage Management

  • Store receipt images and PDFs on Wasabi Cloud Storage
  • Generate secure presigned URLs for file access
  • Enforce storage quotas based on subscription tier and, for Groups, the owner's allocation
  • Execute data retention policies for expired subscriptions and expired Group ownership

4.5 Communication

  • Send subscription expiry warnings
  • Notify users about impending data deletion (personal or Group)
  • Send Group invitation emails
  • Notify Group members of changes to Group status (locked, grace period, deletion, membership changes)
  • Respond to customer support inquiries

4.6 Security and Abuse Prevention

  • Verify that requests come from a genuine, untampered copy of the App (device attestation — see §5.7)
  • Enforce storage, AI-scan, and subscription limits on our servers, so they cannot be bypassed from a modified client
  • Detect and prevent abuse of the Group invitation feature (see §3.5)
  • Verify purchase receipts with Google and Apple to prevent fraudulent subscription claims

4.7 Improvements

  • Analyze app usage to improve features
  • Fix bugs and optimize performance
  • Develop new functionality

5. Data Processing and Third-Party Services

5.1 Firebase Services (Google)

  • Firebase Authentication: User authentication and account management (email/password with email verification, Google Sign-In, Sign In with Apple)
  • Cloud Firestore: Storage of receipt metadata, user profiles, and Group data, in the asia-southeast1 (Singapore) region
  • Firebase AI Logic SDK: AI-powered receipt scanning using Gemini AI
  • Firebase Cloud Messaging: Push notifications
  • Firebase App Check: Device attestation (see §5.7)
  • Firebase Cloud Run functions: Backend business logic, in the asia-southeast1 (Singapore) region
  • Privacy Policy: https://firebase.google.com/support/privacy

5.2 Wasabi Cloud Storage

  • Purpose: Secure storage of receipt images and PDFs, for both personal and Group receipts
  • Security: Private bucket with time-limited presigned URLs (1-hour expiry); Group receipts are stored under a separate storage path from personal receipts
  • Location: Data stored in Wasabi's ap-southeast-1 (Singapore) infrastructure
  • Privacy Policy: https://wasabi.com/legal/privacy-policy

5.3 Google ML Kit

  • Purpose: Basic OCR text recognition from receipts
  • Processing: On-device processing
  • Privacy Policy: https://developers.google.com/ml-kit/terms

5.4 Syncfusion Flutter PDF

  • Purpose: PDF processing and generation
  • Processing: On-device processing
  • Privacy Policy: https://www.syncfusion.com/company/privacy-policy

5.5 Resend (email delivery)

  • Purpose: Delivery of Group invitation emails
  • What is shared: When you invite someone to a Group, the invitee's email address and the invitation message are shared with Resend solely to deliver that message. Resend does not use this information for any purpose other than email delivery on our behalf.
  • Sender: Invitation emails are sent from our verified domain mail.codexcess.net
  • Location: Resend processes our sending from its ap-northeast-1 (Tokyo, Japan) region. Only email metadata and message content transit this region — your receipts, receipt images, and account records remain in Singapore (see §11).
  • Monitoring: Resend reports delivery, bounce, and spam-complaint events back to our backend over a cryptographically signed webhook, so we can flag failed invitations and suppress repeat sends to addresses that reject them (see §3.5)
  • Privacy Policy: https://resend.com/legal/privacy-policy
Change of provider: Earlier versions of this policy named Amazon SES as our email provider. We have migrated to Resend, and the App no longer uses any Amazon Web Services. (Our object storage provider, Wasabi, is an S3-compatible service and is not operated by Amazon.)

5.6 Frankfurter (exchange rates)

  • Purpose: Daily foreign-exchange rates, sourced from European Central Bank data, used for the multi-currency display
  • What is shared: Nothing about you. Our backend fetches a public table of currency rates on a schedule and stores a copy. No user, receipt, or device information is sent to this provider, and the currency conversion itself is performed on your device using our stored copy of the rates.
  • More information: https://frankfurter.dev

5.7 Device Attestation — Google Play Integrity & Apple App Attest

  • Purpose: To confirm that a request to our servers, to Firebase, or to the AI scanning service comes from a genuine, unmodified copy of Receiptly on a real device. This protects your account and our AI budget from automated abuse by someone who has obtained a login token.
  • What is shared: On Android, the Google Play Integrity API evaluates the App and device and returns a verdict to Google, which issues a short-lived attestation token. On iOS, Apple's App Attest performs the equivalent using a device-generated key. We receive only the resulting token and the App identifier — not your device's hardware identifiers, location, installed apps, or any receipt data.
  • Not used for tracking: Attestation tokens are short-lived, are not stored, are not linked to your receipts, and are not used for advertising or analytics.
  • Fails open for you: If attestation cannot be obtained (for example, you are offline at first launch), the App still opens and remains usable — the decision to accept or refuse an individual request is made on our servers.
  • Privacy Policies: Google · Apple

5.8 Payment Processors

  • Google Play Billing: Android in-app purchases; purchases are verified server-to-server with the Google Play Developer API
  • Apple App Store: iOS in-app purchases; purchases are verified server-to-server with the App Store Server API
  • We store only the resulting plan, billing period, expiry date, and an opaque purchase/transaction identifier. Payment card details are processed directly by these platforms and are never seen or stored by us.

6. Data Sharing Within the App

Other than the third-party service providers listed in §5 (who process data strictly on our behalf to operate the App), we do not sell, rent, or trade your personal information to third parties.

The only circumstance in which your information is visible to other users of the App is described in §3.4 (Group membership), and only to members of a Group you have explicitly joined, and only to the extent described there.


7. Data Retention

7.1 Personal Account: Active Users

  • Free Users (100MB): Receipts stored permanently with no automatic deletion
  • Paid Users: Receipts stored permanently while subscription is active

7.2 Personal Account: Expired Subscriptions

When a paid subscription expires:

  • Users are downgraded to the free tier (100MB limit)
  • 6-Month Grace Period: If storage exceeds 100MB, we provide 6 months before deletion
  • Multi-Stage Notifications: 10 notifications sent during the grace period via push, in-app modal, and dashboard snackbar
  • Automatic Deletion: After the grace period, oldest receipts (by upload date) are deleted until storage falls below 100MB
  • Reactivation: Users can renew their subscription at any time to prevent deletion

7.3 Group Data Retention

See §3.7 above. In summary: Group data is retained while the owner's Premium subscription is active, and is fully and permanently deleted, for every member, if the owner's subscription is not restored before the end of the grace period following expiry.

7.4 Group Invitations and Blocks

  • Pending Group invitations expire 48 hours after being sent and can be used only once.
  • We retain a record of the invitation and its status (pending, accepted, revoked, expired, bounced, or complained) so that the per-address and per-sender limits in §3.5 cannot be reset by simply cancelling and re-sending an invitation, and so that a suppressed address stays suppressed.
  • A block you place on a sender (§3.6) is retained until you remove it, so that it remains permanently in effect.

7.5 Account Deletion

You can delete your account and its data yourself, at any time, from Settings → Account → Delete account in the App. To protect you, deletion requires you to type DELETE to confirm and then re-verify your identity (your password, or a fresh Google/Apple sign-in). Backing out at either step cancels silently and nothing is deleted.

Deletion is immediate and irreversible. There is no grace period and no recovery path. When you confirm, we delete:

  • Your personal receipts and their stored image/PDF files
  • Your profile photo and profile image files
  • Your user record, preferences, custom categories and payment methods
  • Your notification history
  • Your registered devices and push-notification tokens
  • Your Group memberships, invitations you sent and invitations addressed to you, and blocks involving you
  • Your Firebase Authentication login record

Two things are deliberately not deleted, and one thing deletion does not do:

  • Receipts you uploaded into a Group remain in that Group. They are part of a shared expense history that other members rely on, and they were stored against the Group owner's storage allowance rather than yours. Removing them would punch holes in other people's records. Your name will no longer resolve against them once your account is gone.
  • If you own one or more Groups, deletion is refused until you transfer ownership or delete those Groups, so that members are never left stranded with a Group that has no owner. The App will tell you and take you to your Groups list.
  • Deleting your account does not cancel a paid subscription. Subscriptions are billed by Google Play or the Apple App Store and can only be cancelled there. The App warns you about this before you confirm, rather than blocking deletion.

If you cannot access the App, you may instead request deletion by emailing us at the address in §13 from the email address on the account; we will action it within 30 days. Residual copies may persist in encrypted infrastructure backups for up to 90 days, after which they are overwritten in the ordinary backup rotation. Aggregated, anonymised analytics that cannot be linked back to you may be retained indefinitely.

7.6 Notifications, Devices, and Exchange Rates

  • Notification history: Notifications shown in the in-app Notification Center are automatically deleted 365 days after they were sent. You can delete any of them sooner from within the App.
  • Device records: When you sign out, the device's push token is deactivated; the device record is retained so you can sign back in on the same device. It is deleted outright when you delete your account.
  • Exchange rates: The daily currency-rate snapshots we store are public market data and contain no personal information.

8. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption: Data encrypted in transit (HTTPS/TLS) and at rest
  • Authentication: Secure Firebase Authentication with industry-standard protocols
  • Email Verification: Email/password accounts must verify their email address before reaching the App, so that an unverified address cannot be used to take over an account
  • Device Attestation: Requests to our backend and to Firebase carry a Firebase App Check token proving they came from a genuine, untampered copy of the App — a stolen login token alone is not enough (see §5.7)
  • Access Control: Presigned URLs with 1-hour expiry for receipt access
  • Private Storage: Receipt files (personal and Group) stored in private Wasabi buckets, never publicly accessible
  • Server-Side Validation: Critical business logic, including Group membership and quota enforcement, executed on secure backend servers, never trusted to the client
  • Database Rules: Access to receipt and Group records is enforced by server-side database rules, so a member can only read a Group's receipts while their membership is active
  • Secure Invitations: Group invitation links use cryptographically signed, single-use, time-limited tokens; the pages they open are read-only and take no action until you explicitly confirm
  • Authenticated Webhooks: Every external service that can update your subscription or invitation status (Google Play, the Apple App Store, and our email provider) must present a verified cryptographic signature; unsigned or forged requests are rejected
  • Re-verification for Destructive Actions: Deleting your account requires a typed confirmation plus a fresh identity check, and is refused outright if that check cannot be completed
  • Data Minimisation by Design: Where a value is only ever compared, we store a one-way hash instead of the value itself — for example, blocked-sender records store a hash of your email address, not the address
  • Secrets Management: API keys and signing secrets are stored in a dedicated secrets manager, never in application code
  • Regular Security Audits: Ongoing monitoring and security assessments

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.


9. Your Data Rights

Depending on your location, you may have the following rights:

9.1 Access and Portability

  • Request a copy of your personal data
  • Export receipt details to Excel (Pro and Premium plans)
  • Download selected receipts as a ZIP file (Pro and Premium plans)

9.2 Correction

  • Edit receipt information directly in the App, personal or Group
  • Update your account information, including your display name

9.3 Deletion

  • Delete individual receipts at any time, singly or in bulk
  • Delete individual notifications from the in-app Notification Center
  • Leave any Group at any time
  • Delete your entire account and its data from within the App — Settings → Account → Delete account. No email to us is required. See §7.5 for exactly what is and isn't removed.
  • If you cannot access the App, request account deletion by contacting us (§13)

9.4 Objection

  • Opt out of push notifications in device settings
  • Choose AI usage preferences (always use AI, never use AI, or ask each time) — choosing "never" keeps receipt scanning entirely on your device
  • Decline a Group invitation, and permanently block its sender from inviting you again (§3.6)

9.5 Data Minimization

  • We only collect data necessary for app functionality
  • You control what receipts you upload, and whether they go to your personal space or a Group
  • An invitee's email address is only used to deliver and verify a Group invitation, and to enforce the anti-abuse limits in §3.5. It is not used for marketing or any other purpose.
  • Where a value only ever needs to be compared, we store a one-way hash of it rather than the value (see §3.6)
  • We do not sell your data, do not run third-party advertising in the App, and do not use your receipts to train AI models

To exercise these rights, please contact us at the email address provided in §13.


10. Children's Privacy

Receiptly is not intended for users under 13 years of age (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.


11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using Receiptly, you consent to the transfer of your information to our service providers' facilities, including those in the United States and other countries where our third-party services are hosted.

Where possible, we configure our infrastructure to process and store data in Singapore:

  • Receipt images and PDFs — Wasabi, ap-southeast-1 (Singapore)
  • Receipt metadata, account records, and Group data — Cloud Firestore, asia-southeast1 (Singapore)
  • Backend API and scheduled jobs — Firebase Cloud Run functions, asia-southeast1 (Singapore)

Two deliberate exceptions, disclosed for transparency:

  • Group invitation emails are sent through Resend from its ap-northeast-1 (Tokyo, Japan) region, as Resend offers no Singapore region. Only the invitation message and the recipient's email address transit it (§5.5).
  • AI receipt scanning is performed by Google's Gemini service, which may process the image outside Singapore. You can avoid this entirely by setting AI usage to "never use AI" (§9.4).

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by:

  • Posting the new Privacy Policy in the App
  • Updating the "Last Updated" date
  • Sending a push notification for material changes

Your continued use of the App after changes constitutes acceptance of the updated Privacy Policy.


13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:

Code Xcess
Email: [email protected]

For data protection inquiries specifically, please include "Privacy Policy" in your email subject line.


14. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected
  • Right to know if personal information is sold or disclosed
  • Right to opt-out of sale of personal information (Note: We do not sell personal information)
  • Right to deletion of personal information
  • Right to non-discrimination for exercising your rights

15. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):

  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right to withdraw consent

Legal Basis for Processing:

  • Contract performance (providing app services, including Group functionality you opt into)
  • Legitimate interests (improving app functionality; maintaining email deliverability; preventing abuse of the invitation feature; and verifying via device attestation that requests come from the genuine App, which protects both your account and our infrastructure)
  • Consent (optional features like AI scanning and Group invitations)
  • Legal obligation (retaining transaction records where required)

16. Consent

By using Receiptly, you acknowledge that you have read and understood this Privacy Policy and agree to its terms. By creating, joining, or remaining a member of a Group, you additionally acknowledge that your display name, profile photo, and Group-uploaded receipts will be visible to other members of that Group, as described in §3, and that receipts you upload to a Group remain in that Group if you later leave it or delete your account, as described in §3.7 and §7.5.


This Privacy Policy is governed by the laws of Malaysia.

Privacy Policy v3.0 · Receiptly · Last updated August 11, 2026 (supersedes v2.0 of June 21, 2026)

CodeXcess logo CodeXcess

An independent software studio in Petaling Jaya, Malaysia. Makers of Receiptly.

Product

How it works Features Download

Company

About FAQ Contact Privacy Policy Terms & Conditions

Connect

© 2026 CodeXcess. All rights reserved. [email protected] · codexcess.net