receiptfox-privacy

ReceiptFox Privacy Policy

Last updated: September 13, 2026

ReceiptFox (“ReceiptFox”, “we”, “us”) is a local-first receipt organizer that lets you capture or import receipt photos, record purchase information, organize receipts into folders, track returns, create reports and exports, and optionally use AI to read a receipt.

This policy explains what data ReceiptFox processes, how it is used, where it is stored, and the choices you have.


Summary


Data ReceiptFox processes

1) Camera and selected receipt photos

ReceiptFox lets you:

The selected image is resized and saved in ReceiptFox’s private local app storage before AI processing or manual editing begins.

Purpose: To preserve the receipt image and allow you to create a receipt record.

ReceiptFox does not continuously access your camera or photo library. It processes the image you choose through the app’s capture or import flow.


2) Receipt information

A ReceiptFox record may contain information such as:

Purpose: To organize your receipts, search purchases, calculate local spending reports, manage returns, create exports, and restore your records when requested.

ReceiptFox does not automatically import transactions from a bank, payment card, brokerage, or other financial account.


3) Local storage

ReceiptFox’s current active library is stored locally on your iPhone.

Local storage may include:

ReceiptFox does not operate a user account or developer-hosted receipt database for this library.

Purpose: To make the receipt library available on the device and support offline organization, searching, editing, reporting, backup, and recovery.


4) AI receipt reading

AI receipt reading is optional.

Before ReceiptFox sends a receipt photo for AI processing, the app presents a disclosure explaining that the photo will be sent to Google through Firebase AI Logic and asks for permission.

If you allow AI receipt reading, ReceiptFox sends:

to Google Gemini through Firebase AI Logic.

Gemini may return structured information including:

Purpose: To reduce manual receipt entry.

ReceiptFox instructs the AI to treat text appearing in the receipt as data rather than instructions and not to invent unsupported purchase or return information.

AI receipt reading is not performed entirely on your device.

You can choose manual entry instead.


ReceiptFox stores your AI receipt-reading preference locally on the device.

You can disable AI receipt reading in the app’s Help screen. If AI consent is not enabled, ReceiptFox presents the AI disclosure before attempting to send a receipt photo to Gemini.

Disabling AI receipt reading prevents future AI receipt-reading requests unless you choose to allow the feature again.


6) Return reminders and notifications

If you choose a return reminder, ReceiptFox may request notification permission from iOS.

ReceiptFox schedules local notifications through Apple’s notification system. A notification may contain:

ReceiptFox does not operate a push-notification server for these return reminders.

Notification delivery and lock-screen visibility depend on your iOS notification settings.

Purpose: To remind you about a return date you chose to track.


7) ReceiptFox backups

ReceiptFox lets you deliberately create a backup of the local library.

A ReceiptFox backup may contain:

ReceiptFox backups are integrity-checked but are not encrypted by ReceiptFox.

The backup is presented through the iOS share sheet and is transferred only to the destination you choose.

Purpose: To let you keep a restorable copy of your local receipt library outside the app.

Store ReceiptFox backup files somewhere private and appropriately protected.


8) Backup restore

If you select a ReceiptFox backup through the system file importer, the app validates the backup before restoration.

ReceiptFox is designed to preserve current records rather than silently overwrite them. When appropriate, restored records are added as separate local records.

Before certain recovery operations, ReceiptFox may retain local safety copies of prior archive information to reduce the risk of accidental data loss.

Purpose: Data recovery and restoration initiated by you.


9) PDF and CSV exports

ReceiptFox can generate user-requested exports including:

PDF packets may contain locally available original receipt photos.

Exports may contain sensitive receipt details. Review an export before sharing it.

Export files are created temporarily by ReceiptFox and provided to the iOS share sheet. ReceiptFox removes its temporary export copy after the sharing workflow where supported.

The app or service you choose as the destination may retain its own copy according to that service’s privacy practices.


10) Sharing individual receipts

If you deliberately tap Share, ReceiptFox may provide the iOS share sheet with:

ReceiptFox does not automatically share receipts.


11) Manual legacy iCloud / CloudKit recovery

The current version of ReceiptFox does not automatically synchronize new receipts with iCloud or CloudKit.

ReceiptFox retains a manual legacy-recovery tool for users who used an older version of ReceiptFox.

Only after you explicitly choose and confirm Recover older receipts may ReceiptFox access Apple’s CloudKit service to:

Recovered information is copied into ReceiptFox’s current local library.

This recovery process is read-only with respect to the legacy CloudKit library. ReceiptFox does not use this process to create, modify, delete, share, invite users to, or continuously synchronize CloudKit records.

A CloudKit account record identifier may be stored locally as recovery metadata to help prevent data from different historical iCloud accounts from being mixed accidentally.

Historical CloudKit copies remain governed by Apple’s iCloud and CloudKit policies.


12) ReceiptFox Pro subscriptions

ReceiptFox offers an optional auto-renewable subscription through Apple StoreKit.

Apple processes subscription purchases, billing, payment credentials, refunds, and App Store account information.

ReceiptFox may receive StoreKit information necessary to determine whether a ReceiptFox Pro entitlement is active, pending, revoked, upgraded, or expired.

ReceiptFox does not receive your full payment-card information.

Purpose: To provide and verify access to ReceiptFox Pro features.


13) Firebase App Check

ReceiptFox uses Firebase App Check to help protect Firebase-connected AI requests from unauthorized use.

Production builds use:

These services may process technical information such as:

Purpose: Security and abuse prevention.


What ReceiptFox does not do

ReceiptFox does not:

The current code does not use Firebase Analytics or Firebase Crashlytics to analyze your receipt activity.


Third-party processing and equal protection

ReceiptFox uses third-party services only to provide functionality you request or to secure that functionality:

Any third party that processes user data for ReceiptFox provides the same or equal protection of user data as stated in this policy and as required by Apple’s App Review Guidelines.


Data retention and deletion

Active local receipt library

Receipt records and photos remain in ReceiptFox’s local app storage until you delete the applicable records or delete the app.

Deleting a receipt removes that record from the active library.


Receipt photos and retained recovery copies

ReceiptFox uses conservative deletion rules to reduce the risk of permanently losing receipt evidence.

After an active receipt is deleted, its photo may remain locally when the photo is still referenced by:

ReceiptFox includes a Clean unused photos tool that removes managed photos only after the app verifies that they are not referenced by the active library or readable retained recovery archives.

This cleanup process is not represented as secure erasure.

Deleting an active receipt does not delete:


Local safety and recovery archives

ReceiptFox may preserve older local archive information or safety copies when migrating or recovering a library.

These copies exist to reduce accidental data loss and may continue to reference older receipt photos.

They remain inside ReceiptFox’s local storage unless removed as part of applicable app-storage deletion.


Deleting ReceiptFox

Deleting ReceiptFox from the device removes data stored inside the app’s local container, subject to normal Apple device-backup and restore behavior.

Files you previously exported or backed up outside ReceiptFox are not deleted automatically.


External ReceiptFox backup files

A backup file remains wherever you chose to save or share it until you delete it from that destination.

ReceiptFox cannot automatically delete copies stored in Files, iCloud Drive, email, messaging apps, cloud-storage providers, computers, or other external destinations.


Legacy CloudKit information

ReceiptFox’s legacy-recovery tool does not delete historical CloudKit data.

Retention and deletion of historical data in Apple’s CloudKit or iCloud services are governed by Apple’s applicable policies and the state of the older library.


Google Gemini and Firebase AI Logic

Firebase AI Logic itself does not store the customer input and output sent to or received from the selected Gemini provider.

ReceiptFox currently uses Google Gemini through the Gemini Developer API backend.

Google’s handling of Gemini requests depends on the developer project’s service tier and configuration.

Google’s current documentation states that:

ReceiptFox does not itself use receipt photos or extracted receipt information to train an AI model.

Google’s independent processing, security, logging, abuse-prevention, and retention practices are governed by Google’s applicable terms and policies.


Firebase App Check

Firebase states that App Check does not retain attestation material itself.

App Check tokens are valid only for their configured lifetime, which Firebase states cannot exceed seven days.

If replay-protection features are used, Firebase may retain tokens involved in replay protection for up to 30 days. Other App Check tokens are not retained by Firebase services according to Firebase’s current documentation.

Attestation information sent to Apple is governed by Apple’s applicable policies.


StoreKit and App Store information

Apple retains transaction, subscription, payment, and App Store account information according to Apple’s applicable policies.

ReceiptFox does not control Apple’s independent transaction-retention systems.


AI receipt reading

AI reading is optional.

You can:

Disabling AI processing does not delete your locally stored receipt library.


Camera and Photos

You can control ReceiptFox’s Camera and Photos access through iOS Settings.

You may also choose manual receipt entry where available.


Notifications

Return reminders are optional.

You can remove a receipt’s reminder preference or disable ReceiptFox notifications through iOS Settings.


Delete receipts

You can delete receipts from the app.

Because ReceiptFox preserves recovery evidence conservatively, a referenced receipt photo may remain in an older local recovery archive even after the active receipt is removed.

Use Clean unused photos to remove photos that ReceiptFox can verify are no longer referenced.


Backups and exports

You decide whether to create or share a backup, PDF, CSV, or individual receipt.

Once a file has been shared outside ReceiptFox, you must manage or delete that external copy through the destination where you saved it.


Legacy iCloud recovery

ReceiptFox does not automatically contact the legacy CloudKit library on a new installation.

Legacy recovery occurs only after you deliberately initiate and confirm the recovery process.


Delete the app

You may delete ReceiptFox to remove its local app container from the device, subject to normal iOS backup and restore behavior.


Third-party deletion requests

For data independently retained by Google, Firebase, Apple, or a destination to which you intentionally exported or shared information, retention and deletion are governed by that provider’s policies.


Sensitive information

Receipt photos can contain sensitive or personal information, including names, addresses, loyalty information, purchase history, partial payment-card information, prescription or health-related purchases, or other private details.

Review receipt photos before:

Avoid submitting information to AI processing that you are not comfortable sending to Google.


Security

ReceiptFox is designed around local storage and data minimization.

Receipt records and receipt images are stored in the app’s private iOS container. ReceiptFox uses iOS file-protection options for its primary local archive and receipt-image writes.

Firebase App Check with Apple App Attest or DeviceCheck helps protect Firebase-connected AI requests.

ReceiptFox backup files include integrity checks to detect accidental corruption, but ReceiptFox backups are not encrypted by ReceiptFox. Integrity checks are not a substitute for encryption.

No method of electronic storage or network transmission can be guaranteed to be completely secure.


Financial information

ReceiptFox is a receipt-management and personal recordkeeping tool.

Spending totals, reports, return tracking, expected refunds, and recorded refunds are based on the receipt information stored in the app. ReceiptFox does not provide banking, credit, accounting, tax, legal, or investment advice.

Currency values are stored and reported in the currency assigned to each receipt. ReceiptFox does not automatically perform currency conversion.


Children’s privacy

ReceiptFox is not directed to children under 13. We do not knowingly collect personal information from children under 13.


Changes to this policy

We may update this Privacy Policy from time to time. The Last updated date above reflects the latest version.


Contact

If you have questions or privacy requests regarding ReceiptFox, contact:

Email: Simon.Yam227@gmail.com