Privacy policy
Last updated: May 2026
This policy explains how Recpt handles your personal information. We comply with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). For how we encrypt and store your receipt images, see our Security page.
1. What we collect
- Your email address and the sign-in method you choose (e.g. Google, Apple, passkey).
- Receipt images you upload. You can opt in to passkey encryption so we can't read the file contents. See our Security page.
- Transaction descriptions, amounts, and dates extracted from those uploads.
- Tax profile answers you provide (such as occupation and work setup).
- Classification decisions you make (accept, modify, reject).
- Basic technical data: IP address, browser type, and timestamps, kept short-term for security and abuse prevention.
- Payment status from Stripe (whether your subscription is active). Card details are handled directly by Stripe, not by us. Stripe is certified to PCI DSS Level 1, the highest level of payment-card security certification.
We don't ask for and don't store: bank account numbers, BSBs, account balances, login credentials for any other service, or government identifiers (TFN, Medicare, driver's licence).
2. Sensitive information
We do not knowingly collect "sensitive information" as defined in the Privacy Act (health, racial or ethnic origin, religious beliefs, etc.). Don't upload receipts or statements that would reveal such information unless you are comfortable doing so. Once uploaded, the image lives in our system the same way any other receipt does. If you'd rather we couldn't read the contents at all, opt in to passkey encryption from Security settings.
3. How we use your information
- To provide the service: extract transaction data, suggest categories, store your records, render the dashboard, export CSVs.
- To process payments and manage subscriptions (via Stripe).
- To improve your future classifications using your past decisions.
- To send you essential service messages (account, security, billing, material changes to these terms).
- To investigate fraud, abuse, or breach of our terms.
- To comply with legal obligations.
4. When we disclose your information
We disclose your information only in these cases:
- To the service providers (sub-processors) listed below, acting on our behalf and only to deliver the service to you.
- When required by Australian law, a court order or subpoena, or a lawful request from an Australian regulator (ATO, ACCC, OAIC, AUSTRAC, or a law-enforcement agency).
- To protect the rights, property, or safety of Recpt or others, or to investigate fraud or serious breach of our terms.
- In a sale or restructure of the Recpt business, subject to the new owner being bound by terms at least as protective as these.
We do not sell your personal information.
Sub-processors
The following providers receive specific data on our behalf. We may add or change providers from time to time and will update this list.
| Provider | Purpose | Data received |
|---|---|---|
| Stripe | Payment processing & subscription billing | Email, payment status, billing details (card details handled by Stripe directly, not by us) |
| AI model provider (United States) | OCR and categorisation of receipts and statements | Receipt image bytes and transaction text during the scan window only; not retained by the provider |
| Transactional email provider | Service-related emails (sign-in, security, billing) | Email address and message content |
| Hosting / infrastructure provider | Application and database hosting in Australia | All data stored at rest |
5. Cross-border disclosure (APP 8)
Receipt images and transaction text are sent to our AI model provider for OCR and categorisation. That provider currently processes the request in the United States. The provider contractually agrees not to retain customer data after processing; we rely on that contractual commitment and cannot independently verify it. When you upload data you authorise this overseas processing. Payments are processed by Stripe, which may handle data in the United States and other jurisdictions per its own privacy terms.
6. Automated decision-making
- What happens: When you upload a receipt or statement, an AI model analyses it and suggests a category and confidence level.
- Human review required: No classification is saved as a confirmed record until you review it. You can accept, modify, or reject every suggestion.
- How it works: The AI uses your tax profile, known vendor patterns, and your past decisions. It doesn't fetch external data about you.
- Your right to object: You can stop using automated classification at any time and categorise manually instead. Contact us if you want any specific suggestion manually re-reviewed.
- Not tax advice: Suggestions are organisational labels, not statements of deductibility. See our Terms.
7. Security
We take reasonable steps to protect your information from loss, misuse, unauthorised access, modification, and disclosure. Sign-in uses modern authentication (passkeys, Google, or Apple sign-in). You can opt in to end-of-window encryption for receipt images and statements. Once enabled, those files are stored as AES-256-GCM ciphertext that we cannot decrypt without your passkey or recovery code. Full detail on the Security page.
8. Data retention
- Receipts and confirmed records: kept until you delete them or your account.
- Account metadata (email, plan, sign-in records): kept while your account exists.
- Account deletion: all personal data is permanently removed within 7 days of your delete request, except records we are required by law to retain (such as payment records for taxation purposes).
- Backups and logs: may persist for up to 30 days after deletion before they roll over; we do not query them for any purpose other than recovery from a system failure.
Your record-keeping obligation is yours. The ATO requires you to keep records supporting your tax position for at least five years from the date you lodge the relevant return. Recpt is a convenience for organising those records, not a replacement for your obligation to keep them. If you cancel a paid plan, delete records, or delete your account, you are responsible for retaining your own copies for the required period. Export your records (CSV plus original images) before deleting.
9. Data location
Customer data at rest is stored on servers located in Australia. AI processing happens in the United States as described in section 5.
10. Your rights
- Access: request a copy of the personal information we hold about you.
- Correction: ask us to correct anything that is inaccurate or out of date.
- Deletion: delete your account at any time from the web app.
- Portability: export your confirmed records as CSV from the dashboard at any time.
- Anonymity / pseudonymity: you can use Recpt without giving us your legal name (an email is required to sign in and receive service messages).
- Opt out of non-essential email: we don't currently send marketing email. If we ever do, every message will include a one-click unsubscribe.
To exercise any of these rights, email help@recpt.com.au. We will respond within 30 days. We may need to verify your identity before acting on a request.
11. Direct marketing
We don't sell your contact details to anyone. We don't currently send marketing email. Any future marketing message will only be sent with your consent and will contain a one-click unsubscribe, consistent with the Spam Act 2003 (Cth).
12. Cookies and tracking
We use a small number of cookies and similar local-storage entries for sign-in sessions, security (CSRF protection), and remembering your preferences. We do not use cross-site advertising trackers. We may use privacy-respecting product analytics to understand which features people use; any such tooling will be listed here when in use.
13. Children
Recpt is not directed at children. You must be at least 18 to use the service. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with their information, contact us and we will delete it.
14. Data breach notification
If a data breach is likely to result in serious harm and the harm cannot be contained, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, consistent with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth).
15. Complaints
If you think we've mishandled your personal information, please email help@recpt.com.au first. We will acknowledge within 7 days and aim to resolve within 30 days.
If you're not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
16. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the most recent change. For material changes we will notify you in advance by email or in-app message, as also described in our Terms.
Business details
Recpt is operated under the registered business name RECPT APP (ABN 14 182 823 848), based in Victoria, Australia. You can verify the registration via the Australian Business Register.
Contact
Privacy questions: help@recpt.com.au. General questions: help@recpt.com.au.