PurchVault

Privacy Policy

Privacy Policy

Last updated: July 19, 2026

PurchVault ("we", "us") is a receipt, return, warranty, and expense organization app. Receipts can contain sensitive financial, medical, and personal information, so PurchVault is built privacy-first: your data is collected only to provide the app's features, is never sold, and is never used for advertising.

What we collect and why

We do not collect your location, contacts, browsing history, or advertising identifiers, and the app requests no such permissions.

How receipt files are stored

Receipt images and documents are stored in private cloud storage in Canada (Supabase, ca-central-1 region), in folders accessible only to your account. There are no public links: the app accesses files through short-lived signed URLs, and database access is protected by row-level security so accounts can only ever read their own records. Location metadata (EXIF/GPS) is stripped from photos on your device before upload.

How AI processing works

When you scan a receipt, its image is sent from our servers to OpenAI's API, which reads the receipt and returns structured suggestions (merchant, totals, dates, categories). You review and confirm every suggestion before anything is saved as a final record. Per OpenAI's API policy, data sent to the API is not used to train their models by default. AI extraction can be skipped entirely — manual entry is always available.

Email-in receipts (optional, Pro): if you explicitly enable this feature, you receive a private PurchVault forwarding address. Only emails that you (or a forwarding rule you set up) send to that address are processed — PurchVault never connects to or reads your email inbox. The content of forwarded emails (text and receipt attachments) is processed by the AI service described above solely to extract the receipt details, is never sold or shared, and is handled like any other receipt in your vault. Turning the feature off deletes your forwarding address immediately, and mail sent to it afterwards is discarded.

Connected Gmail (optional, Pro): instead of forwarding, you may connect a Google account. We request the read-only Gmail permission (gmail.readonly) and use it for one purpose: retrieving the messages Gmail itself files under its Purchases category, so their receipt details can be added to your vault for your review. We never send, modify, or delete anything in your mailbox, and we do not request or read mail outside that category. We store the receipt details we extract, the Gmail message identifiers we have already processed (so the same email is never imported twice), and your access tokens, which are held server-side and are never exposed to any app or browser. You can disconnect at any time from Settings, which revokes our access at Google immediately and deletes the stored tokens; you may also revoke access yourself at myaccount.google.com/permissions.

PurchVault's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to provide and improve the receipt features you can see in the app; it is never sold, never transferred to advertising platforms or data brokers, and never used to develop, train, or improve any generalised or foundational AI or machine-learning model. Receipt content is sent to our AI provider solely to extract the fields of that individual receipt on your behalf, under an agreement that prohibits training on it. No human at PurchVault reads your email content except where you explicitly ask us to for support, where it is necessary for security or to comply with the law, or where the data has been aggregated and made anonymous.

Subscriptions

Pro subscriptions are processed by Apple (App Store) or Google (Google Play) and managed through RevenueCat, which links your subscription status to your account using a random identifier. Payment details stay with Apple or Google — we never see them.

Crash and error reporting

To keep the app reliable, we may use crash reporting (Sentry) that collects technical error information such as device model, OS version, and stack traces. Crash reports never include your receipt content.

Data retention

Your records are kept for as long as your account exists, so your purchase proof is there when you need it — including for however long you or your accountant choose to retain records. When you delete your account, all data is removed as described below.

Your controls: export and deletion

Security practices

All traffic is encrypted in transit (TLS). Data is protected by per-account row-level security, private storage buckets, short-lived signed URLs, and server-side enforcement of all access rules. AI and payment provider keys never leave our servers.

Children's privacy

PurchVault is not directed at children under 13, and we do not knowingly collect personal information from children.

International transfers

Your stored data lives in Canada. During AI processing, receipt images are transmitted to OpenAI, which processes data in the United States. Subscription management (RevenueCat) and push notification delivery (Expo) also involve processing in the United States.

Contact (PIPEDA)

PurchVault operates under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). For privacy questions, requests, or complaints, contact our privacy contact at support@purchvault.com. You may also contact the Office of the Privacy Commissioner of Canada.