Privacy Policy
Recibo (Recibo — Receipt Tracker) · Effective September 16, 2026
Recibo ("we," "our," or "the app") is a receipt-scanning and expense-tracking app. This policy explains what data the app processes, why, and where it's stored. We built Recibo to keep your financial data on your own device wherever possible — there is no user account, no sign-in, and no server-side database of your expenses.
Information We Process
Receipt images and extracted data
When you scan a receipt, the photo is uploaded over an encrypted connection to a private cloud storage bucket (Amazon S3) that only our backend can access. Our backend sends the image to OpenAI's API to extract the merchant name, total, date, tax amount, and category. The extracted data and the photo are then saved locally on your device. The copy on our server is automatically deleted within 24 hours through an automated storage lifecycle policy — we do not keep a permanent copy of your receipts.
Expense, mileage, and report data
Manually entered expenses, mileage trips, folders, and generated reports are stored only in the app's local database on your device. We never see this data unless you explicitly export and share it yourself (for example, emailing a CSV or PDF export).
Location data (Mileage tracking)
If you use the Mileage feature, the app uses your device's location services to calculate trip distance. This location data is processed on your device to compute mileage and is not transmitted to our servers.
Subscription and purchase data
If you subscribe to Recibo Pro, your purchase is processed by Apple through the App Store, and subscription status is managed through RevenueCat, our subscription infrastructure provider. Neither we nor RevenueCat receive your payment details (card numbers, etc.) — those are handled entirely by Apple.
Analytics and diagnostics
We use Mixpanel, Firebase Analytics, and Firebase Crashlytics to understand feature usage and diagnose crashes. These tools collect anonymous usage events (e.g., "scan completed," "report generated"), device/OS information, and crash logs, associated with a random installation identifier — never your name, email, or expense data.
App integrity verification
We use Apple's App Check to verify that requests to our backend come from a genuine, untampered copy of the app. This is a device-integrity check and does not identify you personally.
Apple Search Ads attribution
If you installed Recibo after tapping an Apple Search Ads advertisement, Apple's AdServices framework and RevenueCat may share anonymous, campaign-level attribution data (such as which ad campaign led to your install) with us. This data is aggregate and not tied to your identity.
Third-Party Services We Use
| Service | Purpose |
|---|---|
| OpenAI | Extracts structured data from receipt photos |
| Amazon Web Services (S3) | Temporary, encrypted storage for a receipt photo during processing (deleted within 24 hours) |
| Firebase (Google) — App Check, Analytics, Crashlytics | App integrity verification, anonymous usage analytics, crash reporting |
| Mixpanel | Anonymous usage analytics |
| RevenueCat | Subscription management and entitlement verification |
| Apple (App Store, StoreKit, AdServices) | Payment processing and, if applicable, ad-campaign attribution |
We do not sell your data, and we do not use third-party advertising networks to show ads inside the app.
Data Retention and Deletion
- Receipt photos and expense data live locally on your device for as long as you keep the app installed.
- Deleting the app removes all locally stored expense, mileage, and receipt data from your device.
- A receipt photo uploaded for processing is automatically deleted from our servers within 24 hours.
- You can back up your data at any time via Settings → Export CSV, which produces a file you control.
Children's Privacy
Recibo is not directed at children under 13, and we do not knowingly collect data from children.
Your Choices
- You can use manual expense entry, mileage tracking, receipt scanning, and CSV export without creating an account or providing any personal information.
- You can disable location access for the Mileage feature at any time in your device's Settings.
- You can delete the app at any time to remove all locally stored data.
Changes to This Policy
If we make material changes to this policy, we'll update the "Effective" date above. Continued use of the app after changes means you accept the updated policy.
Contact Us
Questions about this policy or your data? Email us at support@34apps.com.