The short version. InvoScan stores your receipts so you can find them at tax time. Your receipt photos are sent to Anthropic’s Claude API to be read, and nothing else. We do not sell your data, we do not use it for advertising, and you can delete your entire account — receipts, images and all — from inside the app at any time.
1. Who this policy covers
This policy explains how InvoScan (“InvoScan”, “we”, “us”) handles personal data in the InvoScan mobile app for iOS and Android and on this website. It applies to everyone who uses the app, whether on the free tier or an InvoScan Pro subscription.
You can reach us about anything in this policy at support@deepfai.com.
2. Data we collect
We collect only what the app needs to do its job. Specifically:
| What | Why we have it |
|---|---|
| Account details — your email address, an optional display name, and an internal user ID | To create your account, sign you in, and keep your receipts separate from everyone else’s. If you use Sign in with Apple or Google, we receive your email address and name from that provider. If you use Apple’s “Hide My Email”, we only ever see the relay address. |
| Receipt images — the photos you take or import | To read the receipt and to show it to you later. Images are stored in a private bucket that only your account can read. |
| Receipt data — merchant name and address, purchase date, currency, subtotal, tax, tip, total, payment method text, line items, your notes and the assigned category | This is the actual product: your searchable, exportable expense record. |
| Subscription status — whether you have an active InvoScan Pro entitlement, and the number of scans you have used this month | To enforce the free-tier limit and unlock Pro. Payments are handled entirely by Apple and Google — we never see your card number or billing address. |
| Diagnostics and app analytics — crash reports, performance data, app-interaction events, device model, OS version, app version, and app-generated identifiers (a Firebase installation ID and, if you enable notifications, a push token) | To find out what is broken and which parts of the app are actually used. This is collected by Google Firebase, which is built into the app. |
What we do not collect: we do not collect your contacts, your calendar, your precise location, your browsing history in other apps, your card numbers, or any advertising identifier. InvoScan contains no advertising SDKs.
The camera and photo-library permissions are used only when you actively scan or import a receipt. InvoScan does not access your photo library in the background.
3. How we use data
- To run the app: sign-in, storing receipts, search, reports and CSV/PDF export.
- To read your receipts with AI, as described in the next section.
- To apply the free-tier scan limit and to unlock Pro features for subscribers.
- To fix crashes and improve the app.
- To answer you when you email support.
- To meet legal obligations, and to protect against fraud and abuse.
We do not use your receipts or receipt images for advertising, profiling, or automated decisions that have legal effects on you.
Legal bases (UK/EU GDPR). We process account and receipt data to perform our contract with you; diagnostics and analytics on the basis of our legitimate interest in a working, reliable app; and anything else where you have given consent or where we have a legal obligation.
4. AI processing of receipts
When you scan a receipt, our server sends the image to the Anthropic Claude API, which reads it and returns structured fields (merchant, date, amounts, line items and a suggested category). That result is written back to your account and shown to you for review.
- The image is sent from our server, not from your phone, and is transmitted over an encrypted connection.
- Anthropic processes the image on our behalf as a service provider. Under Anthropic’s commercial terms, API inputs and outputs are not used to train their models.
- AI extraction is not perfect. Every extracted field is editable, and you should check the figures before relying on them.
InvoScan is not a tax or accounting service. Categories are suggestions modelled on IRS Schedule C headings to give you a useful starting point. They are not tax advice, and you or your accountant remain responsible for what you file.
5. Third-party processors
We keep this list short on purpose. Each of these companies processes data on our instructions, for the purpose described, and nothing else.
| Processor | What it handles |
|---|---|
| Anthropic (Claude API) | Receipt images, at the moment of scanning, to extract the fields. |
| Supabase (self-hosted by us) | The database, authentication and file storage that hold your account, receipts and images. We run this ourselves on our own infrastructure. |
| RevenueCat | Subscription state and store receipts, so the app knows whether you are Pro. No card details. |
| Google Firebase (Analytics, Crashlytics, Cloud Messaging) | Crash reports, app-usage events, device and app identifiers, push tokens. |
| Apple & Google | Sign-in (if you choose it), app distribution, and all subscription billing and refunds. |
6. We do not sell your data
We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are used under the California Consumer Privacy Act (CCPA/CPRA) and similar US state laws. We have never done so.
7. How long we keep data
- Receipts and images: until you delete them, or until you delete your account.
- Account details: for as long as your account exists.
- Diagnostics and analytics: retained by Firebase on its standard retention schedule (crash reports up to 90 days; analytics events up to 14 months).
- Support email: kept while we deal with your request and for a reasonable period afterwards.
8. Deleting your data
You have two ways to delete everything:
- In the app — go to Settings → Delete account, type
DELETEto confirm. This immediately and permanently removes your account, every receipt, and every stored image. - By email — write to support@deepfai.com from your account address and we will delete it for you.
Deletion cannot be undone, and we cannot recover deleted receipts. Export your data first if you need it (Settings → Export all data, or the CSV/PDF export on the Reports tab). Cancelling a subscription is separate and is done through the App Store or Google Play.
9. Your privacy rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, to object to certain processing, and to withdraw consent. You can do most of this yourself in the app; for anything else, email support@deepfai.com and we will respond within the time limits set by applicable law (30 days under GDPR, 45 days under CCPA).
We will never charge you a different price or give you a worse service because you exercised a privacy right. If you are in the UK or EU and you think we have got something wrong, you also have the right to complain to your local data protection authority.
10. Security
- All traffic between the app and our servers uses TLS encryption.
- Receipt images live in a private storage bucket. They are never publicly listable, and the app fetches them through short-lived signed URLs.
- The database enforces row-level security, so one account’s queries cannot return another account’s rows.
- Our API keys for Anthropic and other services live only on the server and are never shipped inside the app.
- Session tokens are held in the device’s secure keychain/keystore.
No system is perfectly secure. If we ever discover a breach affecting your personal data, we will notify you and the relevant regulators as required by law.
11. Children
InvoScan is a business expense tool intended for adults. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has created an account, email us and we will delete it.
12. International transfers
We and our processors operate in several countries, so your data may be processed outside the country where you live, including in the United States. Where personal data is transferred out of the UK or EEA, that transfer is covered by an adequacy decision or by Standard Contractual Clauses with the processor concerned.
13. Changes to this policy
If we change this policy we will update the date at the top of the page, and for anything significant we will tell you in the app before the change takes effect. Continuing to use InvoScan after a change means you accept the updated policy.
14. Contact
Questions, requests, or complaints about privacy: support@deepfai.com. We read every message.