Your data

What we store

  • Transactions — merchant, amount, currency, date, and enrichment fields (VAT treatment, document number, line items).
  • Receipt documents — PDFs and images in private object storage, prefixed per workspace.
  • Credentials — OAuth tokens and API keys, encrypted at rest (AES-256-GCM). We cannot read your mail password, and inbox access is read-only by scope.
  • Logs — processing events for debugging and your own audit trail.

Raw email content is not retained — the pipeline keeps the attachment, not the inbox.

Isolation

Every query, storage key, and export is scoped to your workspace. There is no shared receipt pool and no cross-customer search path — your data is only ever read with your tenant ID.

Exporting your data

Transactions, the missing report, and the VAT basis export to CSV; SAF-T XML covers audit workflows; receipt PDFs are yours in storage and retrievable at any time. An export of the data we hold about you is available on request — see the privacy policy.

Deleting your workspace

Settings → delete workspace removes the tenant and cascades through every table that holds its data: transactions, receipts, integrations, credentials, API keys, Telegram links, webhook events, logs — plus the workspace's storage prefix. Connected OAuth grants are revoked as part of deletion. This is irreversible; export first if you need the records.

Protecting your account

Turn on two-factor authentication in Settings → Security: any TOTP authenticator app works, and you get single-use backup codes for recovery. Login then requires your password plus a code — an intercepted password alone opens nothing.

Questions and requests

Data-access or deletion requests and security questions: support@receiptpair.com. The security page covers the infrastructure detail; the GDPR runbook our team follows is in the project documentation.

© 2026 Receipt Pair · receiptpair.com