TabVault

Privacy Policy

TabVault · Last updated October 2, 2026

Your purchases say a lot about your life, so we treat them that way. This policy explains, in plain language, what TabVault collects, how the AI features work, who can see what, and the choices you have. TabVault is based in Ontario, Canada, and is responsible for your information.

1. Our promises

We collect only what the app needs to work, and we use it only to run the app for you.

We don't sell your information, share it with advertisers, show ads, or track you across other apps or websites.

We don't read your receipts. Nobody on our side browses your purchases, photos or notes; the app processes them automatically to show them back to you.

Our own monitoring uses counts and totals across all users (like "120 receipts added today"), not the contents of anyone's receipts.

You can see, download, change or delete your information at any time, and deleting your account deletes it from our servers.

2. Information you give us

Account: your email address and password. Passwords are stored encrypted (hashed); nobody, including us, can see them.

Age check: before an account is created, the app asks for your date of birth to make sure you are 13 or older. It is checked on your phone only; it is never sent to us or stored. The phone just remembers that the check was passed, or, if you are under 13, the date until which sign-up stays closed on that phone.

Sign in with Google: if you choose it, Google shares your name, email address and profile picture link with us. We use your email to create and identify your account; your name and picture are kept with your login and not used for anything else. We never get your Google password or access to anything else in your Google account, such as Gmail, Drive or contacts. Our use of information received from Google follows the Google API Services User Data Policy, including its Limited Use requirements.

Purchases: the receipts, photos, PDFs and order emails you add, and what is read from them: stores, store websites (for logos), locations, dates, items, prices, taxes, discounts, return and warranty dates, and your notes. If you turn off "Keep receipt photos" (Profile → Scanning), photos and PDFs are not kept after scanning. Each account can keep up to 2 GB of receipt photos and PDFs; with "Make room for new photos" on (the default), the photos of your oldest receipts are deleted once that space is almost full, while their items and prices stay. Receipts with a return window or warranty still running keep their photos.

Money settings: your budget, savings goal, take-home pay, recurring bills, savings jar and main currency, only if you choose to enter them.

Get started answers: your name, age range, gender, household, work, how often you are paid, focus categories, goals, whether you have used a budgeting app before and how you heard about us. Every question is optional or has a "prefer not to say" choice, and you can change your answers in Profile → About you.

Questions you ask the AI, and feedback or requests you send us.

3. Information collected automatically

Activity: while the app is open it checks in about once a minute with your account, the time, your phone type (Android or iOS), the app version and the app language. This is how we count active users and spot problems; it does not include what you are looking at or doing in the app.

AI usage: for each AI request, which feature was used (scan, question, monthly review), the AI model, the amount of text processed and its estimated cost. This does not include the content of the request.

Problems: when a scan, a question or syncing fails, the error message, phone type and app version, so we can fix it.

Security check: when you sign in, sign up or reset your password, Cloudflare Turnstile checks that you are a person and not an automated script, using technical signals from your phone and connection (such as your IP address). It usually happens invisibly and only shows a checkbox when it isn't sure. It doesn't receive your email, password or purchases.

We don't collect your location, contacts, photos you haven't chosen to scan, microphone, advertising ID or browsing history. Face ID and fingerprint unlock are handled entirely by your phone; we never receive your face or fingerprint data.

4. How TabVault uses AI

TabVault uses artificial intelligence from Anthropic (the Claude models) for four things, and only when you use them. The first time, before anything is sent, the app tells you on screen that receipts are read by AI and where they go:

Reading receipts: when you scan or upload a receipt, the photo, PDF or pasted email is sent to the AI, which reads the store, date, items, prices and totals. If the numbers don't add up, the receipt is read a second time by a more careful model.

Ask AI: when you ask a question, your question and the purchases needed to answer it (up to your last 12 months: stores, locations, dates, items, prices, categories, return dates and notes) are sent to the AI.

Monthly review: once a month is over, the first time you open its review, that month's and the previous month's purchases are sent, together with your budget, savings goal, take-home pay, bills, goals and, if you answered them, your age range, household, work and how often you are paid, so the advice fits you. The review is then kept with your account, so each month is reviewed only once.

What is never sent to the AI: your email, password, name, gender, the receipts of other months not needed for your request, or anything from other users.

These requests pass through our server on their way to the AI. It checks that they come from your account and records how much AI each account uses (the size and cost of each request, not what was in it), so we can keep usage within fair limits.

Anthropic processes these requests on our behalf to give you the answer. Under its commercial terms it does not use them to train its models, and it keeps them only for a limited time for safety and abuse monitoring before deleting them.

AI can make mistakes. Its results are suggestions shown to you: you can check and edit every purchase, and nothing the AI produces is used to make decisions about you, such as credit, pricing or eligibility for anything.

We don't use your receipts, questions or answers to train any AI model.

5. How we use your information

To provide the app: reading your receipts, syncing your data between your devices, showing insights, budgets, savings, badges and streaks, and sending the reminders you turn on.

To keep it working and improve it: finding and fixing errors, understanding which features are used (in totals), and keeping AI costs under control.

To prevent abuse: we track how much AI each account uses, so a single account can't run up unusual costs.

To reply to you when you send feedback.

We don't use your information for advertising, and we don't build profiles of you to sell or share.

6. Who can see your information

You: everything in your account, on any phone you sign in on.

Other users: nothing. Each account can only ever access its own data; this is enforced by our database, not just by the app.

Us: our internal reports show counts and totals. When one refers to a single account (for example a new sign-up, unusually high AI use or a request you send us), it uses a short random ID instead of your email, and may include your phone type, app version, language, main currency, how you heard about us, how you sign in (email or Google), how long you have had your account and on how many days you used it, how many receipts you have and how you added them (photo, PDF, email or typed in), how many times you used the AI features, how many requests you sent us, whether an account with your email address was deleted before (see section 9), and whether you set up things like a budget, a savings goal, reminders or the app tour (yes or no, never the amounts). It never shows your email, name, receipt contents or amounts. Feature requests and problem reports you send from the app are shared with us in full, so please don't include personal details in them. Access to the database itself is limited to the people who run the app, and is used only to keep the service working, to fix a problem you report, or when the law requires it.

Service providers: only the companies below, and only what they need to do their job for us.

7. Service providers

Supabase: stores your account, purchases, settings and receipt files (servers in Canada), and sends account emails such as sign-up codes and password resets.

Cloudflare: the security check at sign-in (Turnstile, described in section 3) and our website, tabvault.ca. It receives technical information from your phone or browser, not your account or purchases.

Google: only if you choose Sign in with Google, to confirm who you are (see section 2).

Expo: delivers app updates. When the app checks for an update, Expo receives technical information such as your phone type and app version, not your account or purchases.

Discord: our private team workspace (servers in the United States), where our internal reports described in section 6 are posted: counts and totals, short random account IDs with the details listed there, error messages, and the text of feature requests and problem reports you send us. Never your email, name or receipt contents.

Anthropic: the AI described in section 4 (servers in the United States).

Frankfurter: provides exchange rates. The app only asks it for the latest rates; none of your information is sent.

Store logos: the app knows the websites of many well-known stores. For other stores, our server looks up the store's name (and the receipt's currency, as a hint for the country) in Wikidata, a free public database of companies, to find its website; the answer is shared by all users so each store is looked up once. The logo is then loaded from logo.dev, a logo service, using only the store's web address, such as hemkop.se. Nothing about you or the rest of your purchase is sent.

Apple and Google: if you buy a subscription, the purchase is handled by the App Store or Google Play under their own privacy policies. We never see your card details.

We may also disclose information if the law requires it, to protect people's safety, or as part of a sale or merger of the business, in which case this policy would continue to apply to your information.

8. Where your data is stored

Your data is stored in Canada. Requests to the AI, and our internal reports on Discord, are processed in the United States. These providers are required to protect your information, but it may be subject to the laws of the country where it is processed.

A copy of your data is also kept on your phone so the app works offline. You can protect it with Face ID or your fingerprint in Profile → Account & data.

9. How long we keep it

We keep your information while you have an account. If you can't use the app, you can also ask us to delete your account by emailing [email protected] from your account's email address (see tabvault.ca/delete-account). Deleting a purchase deletes it; deleting your account deletes your account, purchases, settings, receipt files, activity, AI usage records and feedback from our servers right away, and the app erases its copy on your phone. Copies in our providers' backups, if any, are removed when those backups expire.

To stop the free limits for new accounts being reset by deleting and re-creating accounts, when you delete your account we keep a scrambled code made from your email address with a secret key. It can't be turned back into your email. With it we keep only how many times an account with that address was deleted, when, how many days it was used, and how many receipts and AI requests it had. If someone signs up again with the same address, we can see that it was used before. This is removed 12 months after the last deletion.

Internal reports already posted to Discord (section 6) stay there, but they only refer to your account by a short random ID that no longer links to anything once the account is gone. If a feature request or problem report you sent included something personal, email us and we will remove it.

10. Your choices and rights

See and download: export your purchases as a spreadsheet (CSV) or PDF from Profile → Account & data → Export my data.

Privacy Officer: the person responsible for protecting your information and for this policy can be reached at [email protected].

Correct: edit any purchase, answer or setting in the app.

Delete: delete single purchases, all purchases, or your whole account from Profile → Account & data.

Limit: skip optional questions, don't use the AI features you don't want, turn off keeping receipt photos, and turn notifications on or off in Profile.

Depending on where you live (for example under Canada's PIPEDA, Quebec's Law 25, the EU and UK GDPR or California's CCPA), you may also have the right to ask what information we hold about you, to get a copy, to object to some uses, or to complain to your data protection authority. Email [email protected] and we will respond within 30 days.

11. Security

Data is sent over encrypted connections, each account can only access its own data, passwords are never stored in readable form, and you can lock the app with Face ID or your fingerprint. No system is perfectly secure, so please use a strong password and keep it private. If a breach ever affected your information, we would tell you and the authorities as the law requires.

12. Children

TabVault is for people 13 and older. The app asks for a date of birth before an account is created and doesn't let anyone under 13 sign up, and we don't knowingly collect information from children under 13.

If you are 13 to 17 (or under the age of majority where you live), a parent or guardian must agree to you using TabVault. Parents and guardians can contact us to ask about, export or delete their child's information.

If you believe a child under 13 has created an account, contact us and we will delete it.

13. Changes to this policy

If we change this policy in an important way, we will tell you in the app before the change takes effect. The date at the top shows when it was last updated.

Questions about this document? Email [email protected], or contact us from the app: Profile → Request a feature, choose "Report a problem" and write your message. We read every one.