How we protect your data
Last Updated: May 2026
Receipto is built to handle sensitive financial data — receipts, expense reports, and business transaction records. We take security seriously at every layer of the stack.
This page describes the technical and organizational measures we implement to protect your data.
All data transmitted between your device and Receipto is encrypted using TLS 1.3. We enforce HTTPS on all endpoints. HTTP requests are automatically redirected to HTTPS.
All data stored in our database (Supabase) is encrypted at rest using AES-256. Receipt images stored in Cloudflare R2 are encrypted at rest using Cloudflare's managed encryption keys.
| Component | Provider | Notes |
|---|---|---|
| Database | Supabase (PostgreSQL) | US-West region, encrypted at rest, automated backups |
| File Storage | Cloudflare R2 | Receipt images, encrypted at rest, no public access |
| Web Hosting | Vercel | Edge network, automatic HTTPS, DDoS protection |
| Mobile App | Apple App Store | Distributed via Apple's signed binary infrastructure |
We evaluate the security posture of every third-party service we use. All sub-processors are listed in our DPA.
Key third-party security certifications relevant to Receipto:
AI Processing: Receipt data sent to OpenAI for extraction is processed via the enterprise API. We have explicitly opted out of training data usage. Receipt data is not retained by OpenAI beyond the processing request.
All user inputs are validated and sanitized server-side. We use parameterized queries throughout — SQL injection is not possible via our API layer.
We use UXCam for session replay to improve the app experience. All text input fields are automatically masked. Financial values on receipts are not captured. See our Privacy Policy for details.
We regularly update dependencies to address known vulnerabilities. Critical security patches are applied within 24-48 hours of disclosure.
For B2B customers using Receipto's team workspace features:
In the event of a confirmed data breach affecting customer data:
For business customers with a signed DPA, breach notification procedures are governed by the DPA terms.
If you discover a security vulnerability in Receipto, please report it responsibly:
Email: support@receipto.app
Subject line: [Security] Vulnerability Report
Please include:
We will acknowledge your report within 48 hours and work to resolve confirmed issues promptly. We do not have a formal bug bounty program at this time, but we appreciate responsible disclosure.
| Framework | Status |
|---|---|
| GDPR (EU/EEA) | Compliant — see Privacy Policy and DPA |
| CCPA (California) | Compliant — we do not sell personal data |
| Apple App Store Guidelines | Compliant — App Privacy declarations filed |
| PCI-DSS | Compliant via Stripe (web) and Apple (iOS) — we never handle raw card data |
| COPPA | Compliant — app not directed to children under 13 |
Security questions: support@receipto.app
Data processing: receipto.app/dpa
Privacy policy: receipto.app/privacy
AppWrapp, LLC
651 N Broad St, Suite 201
Middletown, DE 19707
United States