Privacy Policy

Last updated: April 12, 2026

ReceiptSheet ("we", "us", "our") provides a receipt-to-spreadsheet service. This policy explains what data we handle, how, and your rights.

1. What we process

When you upload a receipt photo, our service:

  1. Sends the image to Anthropic's Claude Vision API for data extraction.
  2. Sends the extracted data (merchant, date, amount, items) to your Google Sheet via the Google Sheets API.
  3. Deletes the image from memory when the request completes.

We do not store your receipt images or extracted data. Our server is a Cloudflare Worker — a stateless compute environment with no disk, no filesystem, and no persistent storage. Your receipt image exists in server memory for the few seconds it takes to process, then is automatically garbage-collected. This is architecturally enforced, not just a policy choice.

2. What we store

We store the minimum data needed to operate the service:

That's it. No receipt data, no images, no financial information.

3. Sub-processors

Your data passes through these services during processing:

ServicePurposeWhat they receiveData Processing Agreement
Anthropic (Claude Vision API)Receipt data extractionReceipt image (transient)Anthropic Privacy Policy. API data is not used for training.
Google (Sheets API)Writing extracted data to your SheetExtracted receipt dataGoogle Privacy Policy
StripePayment processingPayment card details (we never see these)Stripe Privacy Policy
CloudflareHosting (Workers + Pages + D1 + KV)Request metadata, hashed account IDCloudflare Privacy Policy

4. What we do NOT do

5. Your rights

Under GDPR, CCPA, and similar regulations, you have the right to:

To exercise any right, email: povkonop@gmail.com (or the contact listed on the main page).

6. Data retention

7. Security

All data in transit is encrypted via TLS. Data at rest in D1 and KV is encrypted by Cloudflare. OAuth tokens are additionally encrypted before storage. We follow OWASP guidelines for the web application.

8. Children

This service is not directed at children under 16. We do not knowingly process data from children.

9. Changes

If we change this policy in a way that affects your rights, we will notify you via the email associated with your Google account (if available) or via a banner on the site, at least 30 days before the change takes effect.

10. Contact

For privacy questions: povkonop@gmail.com