Privacy Policy

Last updated 6 October 2026

ExpenseCatcher (“we”) files the receipts you forward into your own Google Drive and logs them in your own Google Sheet. This policy explains what we collect to do that, why, and what control you have.

What we collect

  • Account details from Google sign-in: your name, email address and profile picture.
  • Emails you forward to your catch addresses: sender, subject, body and attachments. We keep the original attachment and the fields we extract (vendor, date, amounts, tax, category, invoice number) so you can see and correct every catch.
  • Catcher settings: names, steps, and the Drive folder and spreadsheet IDs you choose.
  • Usage data: sign-ins, catches processed and similar events, used to run the service and enforce plan limits.

Google user data

We request a single Google API permission, drive.file. It lets ExpenseCatcher create, see and edit only the files and folders it creates and the files you explicitly pick in Google’s file picker. We cannot list, search or read anything else in your Drive.

We use this access only to:

  • create the folders and spreadsheets your catchers write to;
  • upload each forwarded receipt into the folder you chose;
  • add, and when you correct a catch, update the matching row in the spreadsheet you chose.

Your Google refresh token is encrypted at rest (AES-256-GCM). We do not sell Google user data, use it for advertising, or use it to train AI models. ExpenseCatcher’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How receipts are read

To extract data, the contents of a forwarded receipt are sent to Anthropic’s Claude API. Anthropic processes it to return the extracted fields and does not use API inputs to train its models. If AI reading is unavailable, we fall back to pattern matching on our own servers.

Who else processes data

  • Supabase — database, sign-in and file storage.
  • Vercel — hosting.
  • Resend — receiving forwarded email and sending the notifications and forwards you set up.
  • Anthropic — reading receipts, as described above.
  • Google — your Drive and Sheets, at your direction.

We share data with these providers only to run ExpenseCatcher. We don’t sell personal data.

Retention and deletion

We keep your catches while your account is open. You can delete a catcher at any time, and delete your account — with everything we hold about you — from Settings, or by emailing hello@expensecatcher.com. Files in your Google Drive are yours and are never deleted by us. You can revoke our Google access at myaccount.google.com/permissions or from Settings.

Your rights

You can ask for a copy of your data, its correction or its deletion. Write to hello@expensecatcher.com.

Changes

If we change this policy in a way that matters, we’ll tell you by email before the change takes effect.