Privacy notice
How Receipt Janitor handles your account, expenses, and receipts.
Updated October 2, 2026.
What Receipt Janitor accesses
Google sign-in gives Receipt Janitor your account identifier, name, and email. With your authorization, the app creates property Sheets and receipt folders, reads and writes the files it creates or you select for use with the app, and opens the related rows and receipts. The Google connection uses the limited Drive file permission requested during sign-in. Receipt Janitor does not need access to every file in your Drive.
You provide a property choice, the expense date, amount, merchant, description and category, optional receipt images or PDFs, and support requests. A receipt may contain more personal information than the expense fields you intended to record; review it before uploading.
How processing works
Receipt Janitor uses your inputs to fill the expense details, write the matching Sheet row, and file the receipt. Processing reads uploaded receipt bytes, including when the app verifies a saved receipt before reuse or preview.
On eligible iPhones, Apple's text recognition and Foundation Models read the receipt on the device. Receipt uploads still go to your Google Drive, and extracted expense fields are stored with the draft. If on-device reading is unavailable or fails, the app shows the reason and uses the cloud reader. The web app uses the cloud reader.
Google Gemini receives receipt content when the cloud reader pre-fills expense fields. Google Drive and Sheets hold the files and rows in your account. Firebase Firestore stores app records and drafts. Vercel hosts the web app and backend and may process operational request and error data. These providers process the information needed for their roles; Receipt Janitor does not send receipt contents to product analytics.
Where records stay
Temporary uploads and saved receipts occupy your Google Drive storage. Large photos are resized on your device before upload, so the saved receipt is a smaller JPEG copy without the photo's embedded details such as location; PDFs and small images are kept as chosen. A new upload starts in an app-created private temporary folder. Saving an expense moves that same file into the property receipt folder. Receipt Janitor does not add public sharing permissions. A saved receipt can inherit access from its destination folder, so check the Sheet and folder sharing settings before sharing links.
Firestore stores your property mappings, preferences, expense drafts and saved records, recovery details, temporary-receipt cleanup status, usage counters, and support requests. Expense records have no automatic expiry at present; unsaved server drafts expire seven days after the last edit. Native sign-in stores an encrypted Google connection on the server for the app session; signing out revokes that app session. Discarding a draft or removing a property does not delete the app's server records or your Google files.
Drafts, expiry, and cleanup
Drafts are stored in the app's Firestore database; this browser does not keep its own copy. An unsaved server draft expires seven days after its last edit and then opens read-only until you discard it. The iPhone app also keeps pending edits and interrupted receipt uploads in protected app storage, excluded from device backups. It removes those local copies when the expense is saved or discarded, or when you sign out. Its app session token stays in the device's Keychain; raw OCR text stays in memory.
A temporary uploaded receipt has a seven-day app recovery window, which may be extended by active processing near expiry. That window does not make Google Drive delete the file. Replaced, removed and discarded uploads, and uploads of drafts left unfinished past that window, are moved to Drive Trash automatically, in the background while you use Capture, only after Receipt Janitor verifies the exact file and has current Google access. A file you changed is left in place; a file you already deleted needs no cleanup. Google normally keeps files in Trash for 30 days unless you remove them sooner. Saved receipts and property files stay in Drive until you change or delete them there.
Account deletion and your choices
From Account, you can request account deletion. The request is handled manually. By default, your Google Sheets and Drive files, including temporary receipts, remain yours. Review and clean up eligible app-created temporary receipts before requesting deletion; cleanup needs current, verified Google access. If access is gone, you can remove the temporary folder yourself in Google Drive. The pending request keeps your Google account identifier and reply email until the owner processes and answers it. After review, Receipt Janitor removes its account records and leaves only a hashed account identifier to prevent old request IDs from being replayed if the account returns. That anti-replay record has no automatic expiry and is reviewed before re-enrollment. Any required billing or legal record retention will be explained as part of the deletion response.
You can also revoke Receipt Janitor’s Google access in your Google Account. The app may still appear as Receipt Janitor in Google’s connection settings. Revoking access stops app actions but does not itself delete app records or Google files. For access or privacy questions, use the Help form.