1. Introduction
ReceiptStream.AI ("Service," "we," "us," or "our") is operated by Kubernyx, a software company. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use ReceiptStream.AI — the web application at app.receiptstream.ai, the marketing site at receiptstream.ai, our Android application (package ai.receiptstream.app), and our iOS application. All three clients present the same Service and are covered by this policy in full. Data flows that are specific to the mobile apps — camera access and push notifications — are described in Section 7.
By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please discontinue use of the Service immediately.
This policy is effective as of September 5, 2026.
2. Information We Collect
We collect information you provide directly, information generated by your use of the Service, and limited technical data necessary to operate the Service.
Account Information
When you create an account, we collect:
- Your name
- Email address
- Password, if you sign up with an email address and password (stored by us as a one-way cryptographic hash — never in plaintext)
- The sign-in method you use (Google, Apple, or email and password) and the account identifier issued by our identity provider
- Two-factor authentication enrollment, if you choose to enable it
- Subscription and billing tier
Sign-in is handled by Google Firebase Authentication. Firebase holds your email address, display name, sign-in method, account identifier, email-verification status and — for email and password accounts — the password credential and any two-factor enrollment. See Section 11.
Receipt Data
When you upload, capture, or email in receipts, we collect:
- Receipt images and documents (JPEG, PNG, PDF), stored under the filename you supplied
- Extracted text from those images (vendor name, transaction date, line items, totals, tax amounts)
- The last four digits of the payment card printed on a receipt, when the receipt shows them
- Any corrections or manual edits you apply to extracted data
- Expense category assignments
QuickBooks Connection Information
When you connect your QuickBooks Online account, we store:
- OAuth 2.0 access and refresh tokens (encrypted at rest using AES-256-GCM)
- Your QuickBooks company identifier (realm ID)
- The list of accounts, categories, and classes available in your QuickBooks company for mapping purposes
We never store your QuickBooks username, password, or payment information. Authorization is performed entirely through Intuit's secure OAuth 2.0 flow.
Bank Connection Information
Connecting a bank account is optional. If an owner or administrator of your company chooses to link one through Plaid, we store:
- The name and identifier of your financial institution
- For each linked account: the account nickname, the last four digits of the account number, and the account type and subtype (for example checking, savings, or credit card)
- A long-lived access token issued by Plaid, encrypted at rest using AES-256-GCM
- For expense transactions we cannot match to a receipt you have uploaded: the merchant name, the amount, the date, Plaid's spending category, the account identifier, and the cardholder or account-owner name Plaid supplies
We never receive or store your online banking username, password, or one-time codes — those are entered directly into Plaid's own interface. We do not store your full account number, routing number, or account balances. Section 6 explains this integration in detail.
Mobile App and Device Data
When you use the Android or iOS application, we additionally collect:
- A push notification registration token issued by Firebase Cloud Messaging, stored against your user and company so we can deliver alerts to that device
- The platform (web, iOS, or Android) and a device label for each registered device
- Photographs you take with your device camera when you use the receipt capture screen — these are handled exactly like any other receipt image
Usage Data
We automatically collect limited usage information to operate and improve the Service, including:
- Pages visited within the application and feature interactions
- Receipt processing success and failure rates
- Sync event logs (timestamps, success/failure status)
- Browser type, operating system, and device type
- Error and performance diagnostics sent to our monitoring provider, which are tagged with your user identifier, your company identifier and your role, and which include the page you were on and the clicks, navigation and request URLs immediately preceding an error (see Section 11)
- IP address and browser user agent, recorded against each sign-in session for security purposes. IP addresses are stored in full and displayed in masked form inside the application
3. How We Use Your Information
We use the information we collect to:
- Provide the Service — process your receipt images through our AI extraction provider, extract expense data, and sync that data to your QuickBooks Online account
- Categorize expenses — send extracted receipt fields, together with your QuickBooks chart of accounts and your team's previous categorization corrections, to our AI provider so it can suggest the correct expense account (see Section 4)
- Generate automated categorization rules — learn from your corrections and preferences to improve auto-categorization accuracy for your account
- Flag missing receipts — if your company connects a bank account, compare incoming transactions against the receipts you have uploaded and alert you to unmatched expenses (see Section 6)
- Manage your account — handle authentication, billing, plan limits, and team member access
- Send transactional communications — sync confirmation emails, error notifications, billing receipts, trial reminders, maintenance notices, and push notifications to devices you have registered (these are required for the Service and cannot be opted out of within the app, though you can turn off notifications at the device level)
- Monitor and improve the Service — collect error and performance diagnostics so we can reproduce and fix faults. These reports identify the affected user and company; they are not used for advertising and are not sold
- Comply with legal obligations — retain records as required by applicable law
We do not sell your personal data. The categorization behaviour we learn from your corrections is stored and applied only within your own company account and is never pooled across customers. We do not use your data to train our own AI models.
4. AI Receipt Processing
Receipt extraction is performed by Anthropic's Claude models, provided by Anthropic, PBC and accessed through the Anthropic API. This happens for every receipt that enters ReceiptStream.AI, however you add it — camera capture, file upload, the mobile share sheet, or your company's email-in address.
- What is sent: the complete receipt image is transmitted to the Anthropic API over an encrypted connection, together with your company's home currency. Images are sent as supplied — we do not crop, downscale, or redact them. A PDF is converted to an image of its first page and that image is sent.
- Repeat attempts: if a smaller model cannot read a receipt reliably, the same image is re-sent to a larger Claude model, up to three attempts per receipt.
- Expense categorization: separately, and only where your company has an active QuickBooks connection, we send the extracted receipt fields — vendor, total, date, card last four digits and line items — together with your QuickBooks chart of accounts and classes and your team's twenty most recent categorization corrections, to a Claude model so it can suggest the correct expense account. The receipt image is not sent in this second step.
- Fallback text recognition: if Claude cannot return a usable result, a deployment may be configured to fall back to the Google Cloud Vision API for plain text recognition. Where that fallback is enabled and runs, a resized copy of the receipt image is sent to Google and the recognized text is cached against a cryptographic hash of the image so the same file is not reprocessed. This is a fallback path only and is not used when Claude succeeds.
- Retention by ReceiptStream.AI: raw receipt images are stored in your account for the duration of your account lifetime so you can reference the original document. You may delete individual receipts at any time (see Section 9).
- Parsed data: the structured data extracted from your receipt — vendor name, transaction amount, date, and line items — is stored in your account and used to create QuickBooks expense entries.
AI extraction is highly accurate but not infallible. You are responsible for verifying extracted data before it is synced to QuickBooks. See our Terms of Service for the full accuracy disclaimer.
5. QuickBooks Integration
ReceiptStream.AI integrates with QuickBooks Online through Intuit's official OAuth 2.0 authorization framework. When you connect your QuickBooks account:
- You are redirected to Intuit's secure authorization page, where you grant ReceiptStream.AI scoped access to your QuickBooks company accounting data
- Intuit returns OAuth 2.0 access and refresh tokens to ReceiptStream.AI, which we store encrypted at rest using AES-256-GCM
- These tokens are never logged, exposed in API responses, or accessible to any team member in plaintext
What We Write to Your QuickBooks Company
Using those tokens, we act on your behalf to:
- Create expense, bill, and bill-payment transactions carrying the date, amount, currency, vendor, a reference note, and line descriptions taken from the receipt's line items
- Upload the original receipt file — the exact file you provided, under its original filename — and attach it to the transaction it belongs to, so the document lives alongside the entry in your books
- Read your chart of accounts, classes, customers, and projects for mapping purposes
- Create a new vendor record in your company when a receipt names a vendor that does not yet exist there
We do not send your ReceiptStream account details, your team's identities, the raw AI decision log, or the card last four digits to QuickBooks.
When Sync Happens
Sync begins automatically once QuickBooks is connected. Receipts are queued for sync as soon as they are processed, including receipts that arrive through your email-in address or the mobile share sheet with no further action from you. There is currently no per-receipt approval gate and no sync opt-out toggle; if you do not want data written to your company file, disconnect QuickBooks.
Revoking Access
You can revoke ReceiptStream.AI's access to your QuickBooks account at any time from the QuickBooks Online app permissions page (Settings → Intuit Account → Apps & Connections). Revoking access will immediately prevent future syncs. Your historical receipt data in ReceiptStream.AI will not be affected unless you also delete your account.
6. Bank Connections (Plaid)
ReceiptStream.AI can compare your card and bank activity against the receipts you have uploaded, so you find out about a missing receipt while you can still get it. That comparison requires a bank connection, which we provide through Plaid Inc.
Nothing is linked unless an owner or administrator of your company deliberately connects an account from Settings → Bank. Team members and viewers cannot initiate a connection. If no one connects an account, no bank or transaction data is ever collected.
Your Banking Credentials Never Reach Us
You enter your online banking username, password, and any one-time codes directly into Plaid's own interface, which runs inside a frame hosted and served by Plaid. ReceiptStream.AI receives only a short-lived token from Plaid once the connection succeeds. There is no field anywhere in our applications or servers that accepts banking credentials.
What We Send to Plaid
- An internal numeric identifier for your ReceiptStream user account
- Our application name, and the country and language for the link session
- The address Plaid should send connection updates to
We do not send your name, email address, receipts, or any expense data to Plaid. We request access to the transactions product only — not identity, balance, or account and routing number products. Plaid's own handling of the information you give it is governed by Plaid's privacy policy.
What We Store for Each Linked Account
- Your institution's name and identifier
- The account nickname, the last four digits of the account number, and the account type and subtype
- A long-lived access token issued by Plaid, encrypted at rest with AES-256-GCM
- Synchronization state (a cursor and the time of the last sync) and the connection's health status
We do not store your full account number, your routing number, or your account balances.
What Transaction Data We Keep
We retrieve your transaction history from Plaid — up to the previous 90 days on first connection, then incrementally as your institution reports new activity — and compare it against the receipts you have uploaded. We keep a transaction only if all of the following are true: it has settled, it is an expense over $1.00, it is dated on or after the day the account was connected, its merchant is not one your team has chosen to ignore, and it has no matching receipt. Every other transaction is discarded during processing and is never written to our database. We do not maintain a general transaction ledger.
For a transaction that is kept, we store the merchant name, the amount, the date, Plaid's spending category, the account identifier, your institution's name, and the cardholder or account-owner name Plaid supplies. We use that record to remind the right person to submit the missing receipt; the merchant name, amount, and cardholder name appear in the reminder emails and push notifications we send about it (see Sections 7 and 11).
Disconnecting
An owner or administrator can disconnect a bank account at any time from Settings → Bank. Disconnecting deletes the stored connection and its outstanding reminders from our database, and instructs Plaid to remove our access to the institution once the last account for it has been removed.
7. Mobile Applications
ReceiptStream.AI is distributed as an Android application (package ai.receiptstream.app) and an iOS application in addition to the web application. Everything in this policy applies to them. The following data flows are specific to mobile devices.
Camera Access
- The Android application declares the CAMERA permission and the capture screen requests camera access from your device the first time you use it. The iOS application requests the same access.
- The camera is used for one purpose: photographing a receipt when you choose to capture one. We do not access the camera in the background, and we do not scan your photo library — we receive only the files you select yourself.
- A photo you capture is uploaded and processed exactly like any other receipt image, including transmission to our AI extraction provider as described in Section 4.
- You can decline camera access, or revoke it later in your device settings, and continue to use the rest of the Service by uploading or emailing in files instead.
Push Notifications
- When you sign in on a device that supports notifications, we register that device with Firebase Cloud Messaging, a Google service, and store the resulting registration token against your user and company. On Android, notification permission is requested after sign-in; you can decline it or revoke it later in your device settings.
- Notifications tell you about receipts that need attention. Where your company has connected a bank account, a notification can contain the merchant name, the amount, the date, and the cardholder name for the transaction it refers to. That content passes through Google's messaging infrastructure in order to reach your device.
- Service-wide broadcast topic: every device that registers for notifications is also subscribed to a general "all-users" messaging topic, which lets us send service-wide announcements to all registered devices. There is currently no in-app control that leaves this topic. Turning off notifications for ReceiptStream.AI in your device settings stops all notifications, including topic messages. If you want a device removed from the topic, email privacy@receiptstream.ai.
- Signing out or unregistering a device marks its registration token inactive in our database rather than erasing it (see Section 9).
8. Data Storage & Security
The Service is hosted on Google Cloud Platform (GCP). The application runs in containers on a Compute Engine virtual machine behind nginx, the database is Cloud SQL for PostgreSQL, and receipt images are held in a private Google Cloud Storage bucket. The sub-processors listed in Section 11 are United States companies and your data is processed primarily in the United States.
- Encryption at rest: all user data, including receipt images, extracted text, and OAuth tokens, is encrypted at rest using AES-256
- Encryption in transit: all data transmitted between your browser or device and our servers uses TLS 1.2 or higher
- Token security: QuickBooks OAuth tokens and Plaid access tokens are encrypted with AES-256-GCM before they are written to the database. The encryption key is held in Google Secret Manager and supplied to the application at runtime; it is never stored in the database alongside the data it protects
- Access controls: internal access to production data is restricted to authorized personnel on a need-to-know basis, with all access logged
- Regular backups: the database is exported daily to a separate private Google Cloud Storage bucket
- Vulnerability management: we conduct periodic security reviews and promptly apply security patches
No method of electronic storage or transmission over the Internet is 100% secure. While we use commercially reasonable measures to protect your data, we cannot guarantee absolute security.
9. Data Retention
- Active accounts: all receipt data, account information, and integration data is retained for the lifetime of your active account
- Receipts you delete: a deleted receipt is marked deleted immediately and is no longer visible, exportable, or syncable in the Service. The underlying record and the stored image file remain in our systems until erasure is performed
- After account deletion: when you delete your account, it is marked deleted immediately, your active sessions are revoked, and your QuickBooks connection is deactivated, so the data is no longer reachable through the Service. To have the underlying records and stored receipt files permanently erased from our database and storage bucket, email privacy@receiptstream.ai; we complete erasure within 30 days of such a request
- Backups: daily database exports are retained in a private bucket, so a copy of your data may persist in a backup after deletion
- Push notification tokens: when a device signs out or unregisters, its token is marked inactive rather than erased, so we retain a record that the device was once registered
- Billing records: billing and payment records may be retained for up to 7 years to comply with financial record-keeping obligations
- Session and usage logs: session records include the IP address and browser user agent used at sign-in and are removed when the session is revoked or expires. Aggregate usage logs are retained for service improvement
10. Your Rights (GDPR / CCPA)
Depending on your jurisdiction, you may have the following rights regarding your personal data. To exercise any of these rights, contact privacy@receiptstream.ai.
Right to Access
You have the right to request a copy of the personal data we hold about you. You can export your receipt data as a CSV file directly from the application at any time using the Export CSV button on the Receipts page.
Right to Deletion ("Right to be Forgotten")
You have the right to request permanent deletion of your account and all associated data. You can initiate account deletion from Settings → Account → Danger Zone → Delete Account. Deletion takes effect immediately as described in Section 9; to confirm permanent erasure of the underlying records, contact privacy@receiptstream.ai.
Right to Data Portability
You have the right to receive your data in a machine-readable format. Use the CSV export on the Receipts page to download your receipts and extracted data in a portable format.
Right to Rectification
You may correct or update your account information at any time through the application settings, and edit extracted receipt data before or after sync.
Right to Restrict Processing (GDPR)
If you are in the European Economic Area, you may request that we restrict processing of your personal data under certain circumstances. Contact privacy@receiptstream.ai to submit a restriction request.
California Residents (CCPA)
California residents have additional rights under the California Consumer Privacy Act. We do not sell personal information. To submit a CCPA request, contact privacy@receiptstream.ai. We will respond within 45 days.
11. Third-Party Services
We use the following third-party services to operate ReceiptStream.AI. Except where noted otherwise, each is a data processor acting under our instructions and subject to appropriate data protection agreements.
Anthropic
Provides the Claude models that read your receipts and suggest expense categories. Anthropic receives every receipt image you add to the Service and, for categorization, the extracted receipt fields together with your QuickBooks chart of accounts, classes, and your team's recent categorization corrections. See Section 4. Anthropic's handling of API data is governed by its privacy policy.
Google Cloud Platform
Provides compute infrastructure (Compute Engine), database hosting (Cloud SQL for PostgreSQL), file storage (Cloud Storage), secret management, and the Cloud Vision API used as a fallback for text recognition. Data is processed in accordance with Google's Data Processing Addendum.
Google Firebase (Authentication and Cloud Messaging)
Firebase Authentication is our identity provider and holds your email address, display name, sign-in method, account identifier, and — for email and password accounts — your password credential and any two-factor enrollment. Firebase Cloud Messaging delivers push notifications and holds the registration token for each device you sign in on; notification content, which can include a merchant name, amount, date, and cardholder name, passes through Google's messaging infrastructure. See Section 7.
Plaid Inc.
Connects your financial institution and retrieves transaction history, only if your company chooses to link an account. Your banking credentials are entered into Plaid's own interface and never reach ReceiptStream.AI. See Section 6 and Plaid's privacy policy.
Resend
Sends our transactional email and operates our inbound mail service. Outbound, Resend handles verification, password reset, and email-change messages (which contain a one-time sign-in or reset link), trial reminders, maintenance notices, and missing-receipt reminders — which include the merchant name, amount, date, and cardholder name of an unmatched bank transaction. Inbound, when you forward a receipt to your company's @in.receiptstream.ai address, the message and its attachments pass through and are held by Resend before we retrieve them.
Sentry
Provides error and performance monitoring for the application and our servers. Reports are tagged with your user identifier, company identifier, and role, and include the page you were on and the clicks, navigation, and request URLs leading up to an error; a sample of performance traces is also collected. We do not send your name or email address to Sentry, and authentication headers and cookies are stripped from reports before they are sent.
Stripe
Handles payment processing for paid subscriptions. We never see, store, or process your credit card number. All payment information is collected directly by Stripe and governed by Stripe's Privacy Policy. To open a checkout session we send Stripe your account email address and an internal identifier for your company; from Stripe we receive only a customer identifier and subscription status.
Intuit QuickBooks Online
Not a processor of ours. QuickBooks Online is your own accounting system. When you authorize the integration, we write expense transactions and upload the original receipt files into your company file on your behalf, as described in Section 5. Data written there is held under your own agreement with Intuit and governed by Intuit's privacy policy.
12. Cookies
ReceiptStream.AI uses cookies only to keep you signed in. We set an authentication cookie (rs_refresh) that lets the application renew your session without asking you to sign in again.
- We do not use advertising or cross-site tracking cookies
- We do not use a third-party analytics product such as Google Analytics
- The authentication cookie is valid for up to 30 days from the time it is issued and is cleared when you sign out or revoke the session — closing your browser alone does not remove it
- Our error monitoring runs as an embedded software library rather than through cookies (see Section 11)
- Our public marketing pages load web fonts from Google Fonts, which means Google receives your IP address when those pages load. The signed-in application does not load them
- You can configure your browser to block cookies, but the application requires its authentication cookie to keep you signed in
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email (to the address on your account) and update the "Effective Date" at the top of this page at least 30 days before changes take effect.
Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy. If you do not agree with changes, you may delete your account before they take effect.
14. Contact
For privacy-related questions, requests, or concerns, contact us at:
- Email: privacy@receiptstream.ai
- General inquiries: hello@receiptstream.ai
- Operated by: Kubernyx — kubernyx.com
We will respond to all privacy requests within 30 days.