Effective date: 2026-08-19 Last updated: 2026-08-19
ReceiptWala ("ReceiptWala", "we", "us") is a receipt and expense management app for Android, published for users in India. This Privacy Policy explains what personal data we process, why, where it is stored, and the choices and rights you have. It is written to meet the transparency obligations of India's Digital Personal Data Protection Act, 2023 (DPDP Act).
By installing or using ReceiptWala you agree to this Policy. If you do not agree, please do not use the app.
Your receipts stay on your device. ReceiptWala is local-first: you can capture, scan, organise and review receipts fully without creating an account. Receipt images, the text extracted from them by on-device OCR, and the GST fields we parse (GSTIN, HSN code, tax rate, totals) are stored only in the app's local database on your device.
We never upload your receipt images or their contents to ReceiptWala servers. The only place a copy of your receipts can leave your device is your own Google Drive, and only if you explicitly turn on backup (see §4.2).
If you never sign in and never enable Drive backup, ReceiptWala does not transmit any personal data to us or to third parties, other than anonymous crash diagnostics (§4.5). Account, backup, and subscription features are optional.
This data is held in the app's local storage and is removed when you delete the receipts or uninstall the app.
If you enable backup, ReceiptWala writes copies of your receipts (JSON + images) into a
ReceiptWala-Backups folder in your Google Drive account. We use the restricted
drive.file scope, which limits the app to files it created. These files are governed by
Google's privacy terms and are under your control; we cannot see your wider Drive.
If you create an account (phone OTP, Google Sign-In, email/password, or Truecaller), we process: - Authentication identifiers — email address, phone number, and a Firebase user ID (UID), handled by Firebase Authentication. - Profile record — account creation time, sign-in method, app locale, and the timestamps at which you accepted this Policy and the Terms of Service. Stored in Cloud Firestore in the asia-south2 (Delhi, India) region.
If you buy a Premium subscription, Google Play processes the payment. We process the purchase token and subscription status to deliver Premium features and to verify the purchase server-side; subscription status is stored in Cloud Firestore (asia-south2). We do not receive or store your card or payment-instrument details.
To keep the app stable we collect anonymous crash reports through Firebase Crashlytics. Crash reports are not associated with any user identifier — the app explicitly clears the Crashlytics user ID. We operate no advertising or analytics pipeline of any kind.
| Purpose | Data used |
|---|---|
| Provide core receipt scanning and storage | On-device data (§4.1) |
| Optional cloud backup and restore | Drive data (§4.2) |
| Create and operate your account | Account data (§4.3) |
| Deliver and verify Premium subscriptions | Subscription data (§4.4) |
| Keep the app stable | Anonymous crash diagnostics (§4.5) |
We rely on your consent (collected in-app before sign-in) and on the necessity of processing to provide the features you request.
These providers process data under their own privacy terms. We do not sell your personal data, and we do not share it for advertising.
Receipt contents and your profile, consent, and subscription records are stored in India (Firestore and Cloud Storage in asia-south2 / Delhi; Cloud Functions in asia-south1 / Mumbai).
Firebase Authentication does not support region selection. Your authentication identifiers (email, phone number, UID) are therefore stored on Google's global infrastructure, which may be located outside India. We process them only to provide the sign-in service you request. By creating an account you acknowledge this transfer.
You may: - Access your data — view your stored receipts and account data in the app. - Correct your data — edit receipt fields and profile information in the app. - Erase your data — delete individual receipts at any time, or delete your account, after which associated server-side data is removed within 30 days. - Port your data — export your receipts as CSV, PDF, or JSON from within the app. - Withdraw consent and raise a grievance — see §12.
ReceiptWala is intended for adults managing expenses and is not directed at children. We do not knowingly collect data from children.
Data in transit is encrypted using TLS. Server-side data is protected by Firebase access controls. On-device data is protected by Android's app sandbox. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
For privacy questions, to exercise your rights, or to raise a grievance under the DPDP Act, contact our Grievance Officer:
We may update this Policy. Material changes will be notified in the app or by email. The "Last updated" date above reflects the current version.