Last updated 21 July 2026
Worldwide · Includes GDPR (EEA/UK) and other applicable privacy / consumer protections.
This Privacy Policy explains how SnapTract ("SnapTract," "we," "us," or "our") collects, uses, stores, shares, and protects personal information when you use the SnapTract mobile application and related websites or services (collectively, the "Service").
SnapTract is offered worldwide. This Policy is intended to meet requirements under the EU/EEA General Data Protection Regulation ("GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and other applicable privacy laws.
By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.
For personal data processed in connection with the Service, the data controller is the operator of SnapTract, reachable via Contact us.
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you may contact us at the same address to exercise your rights or raise privacy questions. Where required by law, you may also lodge a complaint with your local supervisory authority.
This Policy applies to personal information we process about you as a user of SnapTract. It does not apply to third-party websites, apps, or services that we do not control (including Apple, AI providers, or cloud hosts), which have their own privacy policies.
Depending on how you use the Service, we may process:
We do not intentionally collect precise GPS location for advertising. Location is not required for core receipt scanning.
We collect information:
If you are in the EEA, UK, or Switzerland, we process personal data only where a legal basis applies, including:
Where we rely on legitimate interests, you may object as described in "Your rights" below.
We use personal information to:
We do not sell your personal information and we do not use it for third-party advertising or cross-context behavioral advertising.
When you scan or upload a receipt, image content and related text may be sent to our AI processor solely to extract fields (merchant, amounts, dates, line items, and similar). Extracted results can be wrong. You are responsible for reviewing and correcting data before relying on it for reimbursement, accounting, or tax.
We instruct processors to use this content only to provide the extraction service to us. We do not use your receipts to train public advertising models. Processor terms may allow limited use to operate and secure their API; see their policies for details.
Your structured data is stored in our managed backend (Supabase). Receipt images are stored with cloud object storage (Cloudflare R2). Some processing occurs on your device.
Because SnapTract is available worldwide, personal data may be processed in countries other than where you live, including the United States and other locations where our providers operate. Those countries may have different data-protection laws than your home country.
For transfers from the EEA, UK, or Switzerland to countries not deemed adequate, we rely on appropriate safeguards where required — such as the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement / Addendum, and provider certifications or contractual commitments — together with technical and organizational measures. You may contact us for more information about transfers applicable to your account.
We share personal information only as needed to run the Service:
These parties act as processors or independent controllers as applicable under their terms. We require processors who handle personal data on our behalf to protect it and use it only for instructed purposes.
We do not sell or rent your personal information.
We retain personal information for as long as your account remains active and as needed to provide the Service. When you delete your account, we delete or anonymize associated personal data from our systems within a reasonable period, except where we must retain limited information for legal, security, fraud-prevention, accounting, or dispute-resolution purposes.
Backups may persist for a short additional period before being overwritten. Device-local copies remain until you remove the app or clear local data.
We use reasonable technical and organizational measures designed to protect personal information, including access controls, encryption in transit where applicable, and provider security features. No method of transmission or storage is completely secure. You are responsible for keeping your device and Apple ID secure. We are not liable for unauthorized access resulting from circumstances beyond our reasonable control.
Subject to applicable law, you may have the right to:
You can exercise many of these rights in the app (edit or delete data; delete your account from Profile). For other requests, use Contact us. We may need to verify your identity before fulfilling a request. Some rights are limited where we have overriding legitimate grounds or legal duties.
If you are a California resident (and where similar US state laws apply, such as Virginia, Colorado, Connecticut, Utah, and others), you may have rights to:
To submit a request, use Contact us or use in-app account deletion. We will not discriminate against you for exercising your rights. We do not use personal information for targeted advertising as defined under those laws.
You may:
Sign in with Apple options (including Hide My Email) are controlled by Apple.
SnapTract is not directed to children under 13 (or under 16 in the EEA/UK where a higher digital consent age applies), and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, use Contact us and we will take steps to delete it.
The native iOS app does not use third-party advertising trackers. Our marketing or legal web pages may use strictly necessary cookies or similar technologies to operate the site. We do not currently use third-party advertising analytics SDKs in the app. If that changes, we will update this Policy and obtain consent where required.
AI extraction suggests structured fields from receipts. This is assistive automation; it does not produce legal or similarly significant decisions about you without human review. You control whether to accept, edit, or discard extracted data.
Some browsers send "Do Not Track" signals. There is no consistent industry standard for responding to them. Aside from the practices described in this Policy, we do not alter the Service based solely on a Do Not Track signal.
We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the latest version. Material changes will be indicated by updating that date and, where appropriate, by in-app notice. Continued use of the Service after changes take effect constitutes acceptance of the updated Policy, except where applicable law requires additional consent.
Privacy questions or requests: use Contact us, or use Contact us in the app / on our legal site.
We aim to respond within a reasonable period and, for GDPR requests, within one month (extendable where permitted by law for complex requests).