PRIVACY
Privacy policy
This policy explains how Wei Cui (GuGu Develop), an individual developer in Victoria, Australia, handles personal information for AU Receipt and aureceipt.com.
Effective 8 September 2026
Contact and scope
Privacy and support contact: support@aureceipt.com
AU Receipt helps adults capture and organise receipts. The app is being prepared for public release; no public Google Play listing is available yet. This policy describes the current service and identifies purchase features that are not publicly available. The website provides information, support and account deletion; it does not provide a customer receipt dashboard.
Information we use
| Information | Purpose and handling |
|---|---|
| Email, account identifier and sign-in sessions | Supabase authenticates accounts using email codes, controls access and associates private records with the correct user. Email delivery providers process sign-in messages. We do not ask you to send passwords or codes to support. |
| Receipt images and recognised text | The current Android app recognises receipts on the device using its bundled OCR model. Images are not sent to a cloud OCR or AI service for recognition. Confirmed receipt images, OCR text and positions are stored in your private Supabase account for sync and retrieval. |
| Receipt fields and history | Merchant, date, amounts, currency, GST, categories, line items, notes, tags, corrections and sync history support organisation, editing, reporting and export. Unconfirmed scan drafts remain on the device. |
| Optional category contributions | If you enable contributions, future explicit category choices can send an event identifier, normalised merchant name, category and account identifier. Contributions exclude receipt images, amounts, dates and OCR text. Merchant names can still reveal purchase information. |
| Purchase and trial records | Where enabled, account identifiers, store transaction and entitlement records establish access, restore purchases and prevent repeated trials or unauthorised purchase transfers. RevenueCat and the relevant app store process purchases; we do not receive your full payment-card number. Website purchases and public store billing are not currently offered. |
| Support requests and correspondence | Your reply email, topic, message, request reference and subsequent correspondence let us respond, verify requests and resolve complaints. Forms do not request attachments or names. Request fingerprints and limited counters prevent duplicate submissions and abuse. |
| Service and security information | Hosting, authentication and email providers may process IP addresses, request timing, device/browser information and operational logs to deliver and protect their services. Our support submission record does not store your IP address. |
Private sync and your choices
While you are signed in and connected, confirmed receipts and later edits sync automatically to your private account. Scans are cropped before storage; imported images are stored as selected. Unuploaded work remains on its originating device. Other signed-in devices can restore records and retrieve images when needed. Do not add information you do not want stored, including another person’s sensitive information without authority.
Camera access is used when you scan; the image picker lets you choose an image to import. The current product does not need microphone, contacts or location access. You control device permissions through system settings. Exports and sharing start only when you choose them; your selected destination then handles the exported copy.
Category contribution is optional and off by default. Disabling it stops future contributions and clears unsent contributions. Turning the switch off cannot recall information already received. You can request deletion of associated feedback. Personal category defaults can work locally without contribution.
Service providers and disclosures
Supabase provides authentication, database and private storage. Vercel hosts the website. Resend processes support email and configured authentication email delivery. RevenueCat and Google Play or Apple process purchase-related information when those features are enabled. These providers receive only information relevant to their role, subject to their service arrangements. Authorised support personnel can access information needed to resolve requests and operate the service.
We do not sell personal information or use receipt content for advertising. The website has no advertising or marketing analytics integration. We may disclose limited information where required by law, to respond to lawful requests, or where reasonably necessary to investigate fraud, protect security or establish and defend legal rights.
These providers operate international infrastructure, and information may be processed outside Australia, including the United States. We do not promise Australian-only storage. Their infrastructure, support locations and retention settings can differ by service; contact us for information about a transfer relevant to your account. We use private access controls and provider arrangements to protect information sent overseas.
Website forms and account verification
Submitting a support or deletion request sends the email, topic and message to our support inbox. We use this information to handle your request, not to sign you up for marketing. The form uses a browser security calculation, duplicate detection and submission limits to discourage abuse. Avoid including receipt images, tax file numbers, full card numbers or sign-in codes.
If you choose verified account deletion, a code is sent to the account email. The verification session is held in browser memory for that flow and is not stored by the website in local storage. Enter a code only into the verification form you requested. An unverified request neither confirms an account exists nor authorises its deletion.
Retention and deletion
| Record | Retention and removal |
|---|---|
| Private receipts, images, OCR and sync history | Kept while the account exists to provide the archive and sync service. Trash and editing history may remain for restoration. Verified account deletion removes the account’s active cloud records and stored images. |
| Local drafts, receipts and caches | Remain in app storage until removed by app cleanup, in-app account deletion or clearing app data. Web deletion cannot erase offline devices or copies you exported or shared. |
| Category feedback | Unsent contributions are cleared when disabled or signed out. Account-linked server contributions are removed with account deletion. |
| Trial protection | A keyed email hash, original account identifier and trial dates may remain for up to 12 months after the trial ends to prevent repeated free trials. These records do not preserve your receipt archive. |
| Support conversations | Open requests are kept while being handled. Archived conversations are removed after 12 months from archival; Spam after 30 days. Pending or uncertain outgoing messages can delay cleanup until resolved. Email-provider copies follow separate provider retention rules. Limited duplicate-prevention records may outlast message content. |
| Purchase ownership and billing events | May remain after account deletion to prevent fraudulent purchase transfer, resolve transactions and meet applicable legal obligations. They are separate from receipt content. Retention is reviewed against those purposes; ask us for the records and retention basis relevant to your account. |
| Infrastructure logs and backups | Provider-managed logs and backups are separate from active account records. Active deletion does not imply immediate removal from every backup or security log. Their periods depend on provider configuration; no single verified expiry period is currently promised. Restricted copies must not be used to restore a deleted account to ordinary service. |
We retain information only while needed for the stated purpose or a legal requirement, and review exceptions such as unresolved disputes. We will explain a relevant retention exception when handling your request. See account and data deletion to start without reinstalling the app. We aim to complete verified requests within 30 days and explain delays. Account deletion does not cancel a store subscription.
Security
We use HTTPS, authenticated access, private storage and account access controls. Staff administration requires additional authentication. No storage or transmission method is risk-free. Protect your email account and device; notify us promptly if you suspect unauthorised access. We investigate privacy incidents and make notifications required by applicable law.
Access, correction and complaints
You can view, correct and export supported receipt information in the app. For other access, correction, data deletion or privacy questions, use support or email us. We verify identity proportionately before disclosing or changing personal information. We aim to acknowledge requests within 5 business days and provide a substantive response within 30 days, explaining any delay or refusal and available next steps.
You may contact the Office of the Australian Information Commissioner where it has jurisdiction, or another applicable authority. This policy does not limit statutory rights or imply that every Australian Privacy Principle applies to every small-business activity.
Adults only
AU Receipt is intended for people aged 18 or older. We do not knowingly provide accounts to children. If you believe a child has supplied personal information, contact us so we can investigate and arrange appropriate removal.
Changes to this policy
We publish updates here with a new effective date. We will give appropriate notice of material changes through the app or another suitable channel, and obtain consent where required before introducing a new use. A policy update alone does not authorise an incompatible use of previously collected information.