Last updated: May 2026
This policy explains how Recpt handles your personal information. We comply with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). For how we encrypt and store your receipt images, see our Security page.
We don't ask for and don't store: bank account numbers, BSBs, account balances, login credentials for any other service, or government identifiers (TFN, Medicare, driver's licence).
We do not knowingly collect "sensitive information" as defined in the Privacy Act (health, racial or ethnic origin, religious beliefs, etc.). Don't upload receipts or statements that would reveal such information unless you are comfortable doing so. Once uploaded, the image lives in our system the same way any other receipt does. If you'd rather we couldn't read the contents at all, opt in to passkey encryption from Security settings.
We disclose your information only in these cases:
We do not sell your personal information.
The following providers receive specific data on our behalf. We may add or change providers from time to time and will update this list.
| Provider | Purpose | Data received |
|---|---|---|
| Stripe | Payment processing & subscription billing | Email, payment status, billing details (card details handled by Stripe directly, not by us) |
| AI model provider (United States) | OCR and categorisation of receipts and statements | Receipt image bytes and transaction text during the scan window only; not retained by the provider |
| Transactional email provider | Service-related emails (sign-in, security, billing) | Email address and message content |
| Hosting / infrastructure provider | Application and database hosting in Australia | All data stored at rest |
Receipt images and transaction text are sent to our AI model provider for OCR and categorisation. That provider currently processes the request in the United States. The provider contractually agrees not to retain customer data after processing; we rely on that contractual commitment and cannot independently verify it. When you upload data you authorise this overseas processing. Payments are processed by Stripe, which may handle data in the United States and other jurisdictions per its own privacy terms.
We take reasonable steps to protect your information from loss, misuse, unauthorised access, modification, and disclosure. Sign-in uses modern authentication (passkeys, Google, or Apple sign-in). You can opt in to end-of-window encryption for receipt images and statements. Once enabled, those files are stored as AES-256-GCM ciphertext that we cannot decrypt without your passkey or recovery code. Full detail on the Security page.
Your record-keeping obligation is yours. The ATO requires you to keep records supporting your tax position for at least five years from the date you lodge the relevant return. Recpt is a convenience for organising those records, not a replacement for your obligation to keep them. If you cancel a paid plan, delete records, or delete your account, you are responsible for retaining your own copies for the required period. Export your records (CSV plus original images) before deleting.
Customer data at rest is stored on servers located in Australia. AI processing happens in the United States as described in section 5.
To exercise any of these rights, email help@recpt.com.au. We will respond within 30 days. We may need to verify your identity before acting on a request.
We don't sell your contact details to anyone. We don't currently send marketing email. Any future marketing message will only be sent with your consent and will contain a one-click unsubscribe, consistent with the Spam Act 2003 (Cth).
We use a small number of cookies and similar local-storage entries for sign-in sessions, security (CSRF protection), and remembering your preferences. We do not use cross-site advertising trackers. We may use privacy-respecting product analytics to understand which features people use; any such tooling will be listed here when in use.
Recpt is not directed at children. You must be at least 18 to use the service. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with their information, contact us and we will delete it.
If a data breach is likely to result in serious harm and the harm cannot be contained, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, consistent with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth).
If you think we've mishandled your personal information, please email help@recpt.com.au first. We will acknowledge within 7 days and aim to resolve within 30 days.
If you're not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent change. For material changes we will notify you in advance by email or in-app message, as also described in our Terms.
Recpt is operated under the registered business name RECPT APP (ABN 14 182 823 848), based in Victoria, Australia. You can verify the registration via the Australian Business Register.
Privacy questions: help@recpt.com.au. General questions: help@recpt.com.au.