1. Information processed on your device
RecordSlip may process receipt images, recognized text, merchant, purchase date, subtotal, tax, tip, total, currency, category, notes, projects, export templates, recognition confidence, and corrections that you make. Receipt images and records are stored in the app’s local container, and receipt recognition starts on your device.
The app stores scan allowances and credited consumable transaction identifiers in the device Keychain. It also maintains device-local product-quality counters, such as successful or failed recognitions, exports, corrections, and processing-time percentiles. These counters do not contain receipt text, merchant names, amounts, images, project names, notes, or receipt identifiers, and they are not automatically transmitted to us or an analytics provider.
2. Optional iCloud Drive backup
If you choose Back Up Now, RecordSlip writes a complete workspace archive to the app’s private iCloud Drive container and retains up to five backups. Apple operates iCloud under your Apple account and its own terms. Backup is manual and optional; RecordSlip remains usable without iCloud.
3. Optional online enhancement
Pro users may choose Improve Uncertain Fields. Only when a required field is uncertain or a defined date, amount, or candidate conflict is detected, RecordSlip may send bounded OCR text, per-line confidence, normalized line positions, local candidate fields, and non-content reason codes. It also sends an Apple-signed subscription proof and an App Attest app/device-integrity assertion. Receipt images and your corrections are not sent.
Successful results may remain encrypted in Redis for up to 10 minutes for safe retry. Hashed keys maintain per-subscription request and AI-cost limits. App Attest public-key metadata, counters, and Apple attestation receipts may be retained for up to 180 days after the last successful assertion to prevent replay and abuse. Operational logs exclude receipt bodies, prompts, subscriber identifiers, request identifiers, and upstream content.
Text-only enhancement is processed through OpenAI. Requests disable application-state storage. OpenAI may retain request content in abuse-monitoring logs for up to 30 days unless the production API project has approved zero-data-retention controls. We do not use receipt content to train our own models.
4. Purchases and app integrity
Apple processes subscriptions, one-time in-app purchases, refunds, App Store Server status, and App Attest verification. RecordSlip receives signed transaction and integrity data needed to determine access, account for scan allowances, and prevent fraud. We do not receive your full payment-card details.
5. Firebase Analytics and Crashlytics
RecordSlip uses Google Firebase Analytics to understand limited app-use information, such as app lifecycle events, app version, device model, and operating-system version. It uses Firebase Crashlytics to receive crash reports and diagnostics, including crash stack traces, timestamps, app/device version information, and Firebase/Crashlytics installation and session identifiers.
Firebase Analytics and Crashlytics do not receive receipt images, recognized receipt text, merchant names, amounts, corrections, notes, projects, exports, or backup contents because RecordSlip does not log that information to Firebase. Crashlytics records are retained by Firebase for 90 days before deletion from live and backup systems begins. Analytics retention follows the setting for our Google Analytics property. Firebase may process this information on Google’s global infrastructure under its applicable terms and privacy policies.
6. Sharing and service providers
Information is disclosed only as needed to:
- Apple, for StoreKit purchases, App Attest, and optional iCloud Drive;
- OpenAI, for optional text-only enhancement; and
- Google Firebase, for limited app-use analytics and crash diagnostics; and
- Vultr, which hosts the encrypted recognition service and short-lived Redis data.
These providers may process information in countries other than yours under their applicable terms and safeguards.
7. Tracking, advertising, and sale
RecordSlip contains no advertising SDKs, does not use Firebase advertising features, does not track you across other companies’ apps or websites, and does not sell personal information.
8. Security and retention
RecordSlip uses iOS sandboxing, Keychain storage, TLS, App Attest, signed StoreKit credentials, request-size limits, rate limits, encrypted short-lived cache values, and restricted logging. No system can be guaranteed perfectly secure.
Local receipt data remains until you erase the workspace or uninstall the app. iCloud backups remain until removed through the available app or Apple controls. Server-side data follows the periods above, except where limited longer retention is required for security, fraud prevention, or law.
9. Your choices
- Keep online enhancement disabled and use local recognition only.
- Export your workspace and images from Settings.
- Erase receipts, images, projects, templates, export history, and local quality counters from Settings.
- Manage or cancel subscriptions in your Apple ID subscription settings.
- Review this policy for information about limited server-side records.
Limited purchase and usage state may be retained after local workspace erasure so the action cannot recreate free credits, duplicate paid credits, or bypass fraud controls.
10. Children
RecordSlip is a general productivity tool and is not directed to children. We do not knowingly collect children’s personal information.
11. Changes
We may update this policy when features, providers, or legal requirements change. The published policy will show its effective date, and material changes will be communicated when required.