Privacy Policy

Effective date: July 10, 2026
Last updated: July 22, 2026

Overview

Reimbursely is a small, free proof-of-concept project run by individuals. This policy explains what actually happens to your data when you use the Reimbursely web app at tryreimbursely.app — no more, no less.

Reimbursely turns a photo of a receipt into structured expense data you can export as a spreadsheet. It has no accounts, no login, and no server-side database. Almost everything happens in your browser; the only time data leaves your device is the one round-trip needed to analyze the receipt.

What We Collect

Just two things, only when you choose to upload a receipt:

  • The receipt image itself.
  • The fields our AI extracts from it.

We don't collect names, email addresses, passwords, payment information, or anything else. There's nothing to collect it with — there are no accounts and no sign-up forms anywhere in the app.

Why We Collect It

We use your receipt image and the extracted fields for a single purpose: to read the receipt and hand the structured expense data back to you. We don't repurpose them for anything unrelated to reading your receipt. Our lawful basis for this processing is your consent, given when you choose to upload a receipt.

How Your Data Is Processed

When you upload a receipt:

  1. Your browser converts and downscales the image locally — this happens on your device, before anything is sent anywhere.
  2. That single prepared image is sent over HTTPS to Reimbursely's one server endpoint.
  3. The endpoint forwards the image to our AI provider (see below) to analyze the receipt, and gets back the structured fields.
  4. The endpoint returns those fields to your browser and then forgets about the request entirely. It never writes the image, the extracted fields, or any part of the request to a disk or database.

Every upload is a stateless, one-off round-trip. There's no server-side history for us to have, lose, or be asked to hand over. Because our hosting and AI providers operate in the United States, this brief round-trip may be processed on servers there, regardless of where you are in the world.

Where Your Data Lives

The extracted fields and a copy of the processed image are saved only in your browser's local storage (IndexedDB), on your device. Reimbursely has no database of its own. Once your browser closes the connection after an upload, our servers don't hold a copy of your receipt or your data in any form.

This also means your data doesn't sync across devices or browsers — it lives wherever you uploaded it. Once you clear it from your browser, it is permanently gone and we cannot help you recover it.

Our AI Provider

Reading a receipt image requires a third-party AI model; Reimbursely uses OpenAI for this. A few specifics worth being precise about:

  • OpenAI does not train its models on this data by default.
  • OpenAI's own policy allows it to retain API inputs and outputs (your receipt image and the extracted fields) for up to 30 days, used only for abuse monitoring — not saved by Reimbursely, but not instantly gone on OpenAI's side either. After that window, OpenAI removes it from their systems unless the law requires otherwise.

The AI only reads and transcribes what's on your receipt; it makes no automated decisions about you that produce legal or similarly significant effects.

You can read OpenAI's own privacy policy for the full picture of how they handle API data.

Other Third Parties We Use

  • Vercel — hosts the site and runs the one server function described above. Standard web-hosting infrastructure; no receipt data is stored there beyond the moment it takes to process a request.
  • Upstash — used purely to rate-limit abusive traffic. It stores a short-lived counter tied to your IP address that expires automatically after 60 seconds. It never sees your receipt image or any extracted field.

We don't sell or rent your receipt data, and we don't share it beyond the providers listed above that are needed to read your receipt.

Cookies & Analytics

Reimbursely has no accounts, so there are no login or tracking cookies. The site loads Vercel Web Analytics, which counts page views in aggregate and doesn't use cookies. It never receives your receipt images, extracted fields, or anything from your browser's local storage — it only knows that a page was viewed, not what you did on it.

How Long We Keep Data

  • On our servers: effectively zero. Each upload is processed and forgotten the moment a response is sent back to your browser.
  • In your browser: until you remove it. Data saved to IndexedDB stays there indefinitely — there's no automatic expiration — until you clear it yourself or clear your browser's storage.

Your Choices

Because your data lives in your browser, you're already in control of it without needing to ask us for anything:

  • Export it anytime with the Export CSV button, or download your original images from the Files page.
  • Delete it by clearing this site's data through your browser — look for "Site settings," "Cookies and site data," or "Clear browsing data" in your browser, scoped to this site, and it removes everything Reimbursely has stored on your device. (We don't have a "Clear All Data" button inside the app itself yet — this is the way to do it today.) If you want to ensure your work session is ephemeral, use an Incognito or Private Tab.

Your Rights (GDPR, CCPA & Other State Privacy Laws)

If you're in the EU or UK (GDPR) or California (CCPA/CPRA), you have rights to access, correct, delete, and port your personal data — and not to be treated differently for exercising them. If you're in another US state with a comprehensive privacy law, similar rights likely apply to you too. Because Reimbursely keeps no copy of your data on its servers, there's in practice nothing for us to retrieve, correct, or erase on your behalf: you already hold the only copy, and the steps above let you export or delete it yourself. We also don't sell or share your personal information, so there's nothing to opt out of. If you have a request or question anyway, email the address in the Contact section below.

Security

  • All traffic runs over HTTPS.
  • The site sends strict security headers (a restrictive Content Security Policy, no cross-site framing, no unnecessary browser permissions).
  • Uploaded images are size-capped before they're accepted.
  • Requests are rate-limited per IP address to deter abuse.
  • Because nothing is stored server-side, there's no receipt database that could ever be breached.

That said, this is a small demo project, not an enterprise product with formal security guarantees — treat it accordingly, and avoid uploading receipts with information you'd consider especially sensitive.

Children's Privacy

Reimbursely isn't directed at children and isn't intended for use by anyone under 13. Because the app has no accounts or sign-up forms, we don't knowingly collect personal information from children. If you're under 13, please don't use Reimbursely.

Do Not Track

Reimbursely doesn't use cross-site tracking or ad technology, so there's nothing for a Do Not Track signal to turn off — the app behaves the same way regardless of that setting.

Changes to This Policy

If how Reimbursely handles data ever changes, this page will be updated and the date at the top will change with it. Since there are no accounts or email addresses on file, we have no way to notify you directly — check back here if you want to know what's changed.

Contact

Questions about this policy or how your data is handled: bki6njyso@mozmail.com