Security

Your inbox stays yours. So does everything else.

Receipt Pair is built around a narrow job: read charges, find receipts, file them. Everything below is how the shipped product behaves, not a policy aspiration.

What Receipt Pair can and cannot do

Email: read only

Gmail access uses Google's read only scope. The app can search and download attachments. It cannot send, delete, label, or modify anything in your mailbox.

Bank: read only

Wise connects with a token that has no payment permissions. It can list transactions and nothing else.

No raw email stored

Receipt Pair reads your inbox to find attachments, then keeps only the receipt PDF. Message bodies and threads are not stored.

No resale, no sharing

Your transactions and receipts are not sold, shared, or used to train anything. They exist to do your bookkeeping.

How your data is kept

Encrypted credentials

API tokens and OAuth refresh keys are encrypted at rest with AES-256-GCM. Each business has its own encrypted records; one workspace can never read another's.

Isolated storage

Receipt PDFs live in private object storage under a prefix scoped to your business. Nothing is public, and nothing crosses between accounts.

EU infrastructure

The database and receipt storage run on Cloudflare's EU-based D1 and R2 locations. Email sending runs through Resend's EU region.

Access on your terms

Teammates and accountants get their own logins and roles. Nobody sees your credentials, and you can export or remove your data on request.

The short version

  1. 01

    Read only scopes for email and bank. Nothing in your accounts can be moved, sent, or changed.

  2. 02

    Credentials encrypted at rest. Receipts in private per business storage. Raw email never kept.

  3. 03

    Questions or a deletion request: support@receiptpair.com. The details live in the privacy policy and terms.

Trust is the product.

Read only access, encrypted credentials, isolated storage. Then it does the boring work.

Start pairing free
© 2026 Receipt Pair · receiptpair.com