RECEIPTS
ASK → SOURCE → PROOF · v1.49.45
Back to RECEIPTSPrivacyTermsCopyrightRefundsPrivacy / legal request

Privacy Policy

RECEIPTS is a U.S.-focused legal-information and research website. This policy describes the data flows in the current public version.

Privacy at a glance. Free public tools work without an account. RECEIPTS does not sell personal information, does not share personal information for cross-context behavioral advertising, and does not intentionally run targeted-advertising trackers. Cloud backup is optional. Case-file and document uploads are not enabled.
Do not enter unnecessary sensitive identifiers. Avoid full Social Security numbers, passwords, full payment-card or bank numbers, medical records, unredacted court documents, or other information that is not needed to understand a public-law question.

1. Data kept on your device

RECEIPTS uses browser storage for bookmarks, notes, recent searches, saved Receipts, drafts, accessibility/display preferences, return-to-task state, and—after you use account sign-in—the last sign-in email on that device so RECEIPTS can offer a faster returning-user sign-in. This data stays in that browser unless you clear it, export it, or—after sign-in—use account work sync or backup features.

2. Optional accounts and authentication

If you choose Continue with Google, Google and Supabase process the sign-in and RECEIPTS receives the basic account identity needed to authenticate you, such as your verified email and account identifier. RECEIPTS does not request access to read your Gmail inbox, contacts, or messages. The secure email-link method remains available as a backup. Public research does not require an account, and RECEIPTS does not ask you to create a site password.

3. Account work sync and optional backup

Signed-in users can keep a privacy-minimized copy of bookmarks, personal notes attached to bookmarks, saved Receipts, and reading/display preferences in a Supabase row protected by Row Level Security so that saved work can follow the same account to another device. Search history and drafts are excluded from automatic sync by default. They are included only when you affirmatively select the manual sensitive-data backup option.

Account controls let you export or delete the cloud backup. Deleting the RECEIPTS account is designed to remove the Supabase authentication account and cascade-delete RECEIPTS account rows. Historical payment records held by Stripe may remain where required for payment, accounting, fraud-prevention, dispute, or legal purposes.

4. Payments and subscriptions

Stripe processes the optional support payment and, if public premium billing is later enabled, any activated premium subscription. Public premium checkout is currently locked during prelaunch QA. RECEIPTS does not receive or store a full payment-card number. RECEIPTS may keep the minimum Stripe customer/subscription identifiers and status needed to confirm access, prevent duplicate billing, and open Stripe's subscription-management tools.

5. Hosting, security, and technical data

Cloudflare hosts and secures the site and may process ordinary request, network, device, performance, and security metadata needed to deliver the service. RECEIPTS does not intentionally embed third-party advertising trackers in the current build.

When paid AI research is enabled, Cloudflare Turnstile may receive the visitor's network address and security/browser signals to perform a bot check. RECEIPTS' own daily usage counter is designed to store a keyed pseudonymous account identifier and numeric request counts, not the raw network address or legal-question text.

6. Live AI research

Free rule cards and local help tools can operate without sending a legal question to an AI provider. Only when a signed-in authorized premium user deliberately starts live AI research and the feature is enabled is the question and selected research context sent through the RECEIPTS server to the OpenAI API. The request is made with model storage disabled by the application. OpenAI states that API inputs and outputs are not used to train its models by default; provider-side retention, abuse monitoring, security, and legal obligations are governed by OpenAI's current business/API terms and policies.

OpenAI enterprise/API privacy information ↗

7. External official-source links and software delivery

When you open an external government, court, agency, or other source website, that destination receives the request and applies its own privacy practices. The current site loads the Supabase browser library from jsDelivr and may load Cloudflare Turnstile only when that security feature is needed; those providers can receive ordinary connection metadata.

8. Legal, privacy, copyright, and accessibility requests

If you submit the RECEIPTS privacy/legal request form, RECEIPTS processes the contact information and message you provide to review and respond to that request. Do not put full financial account numbers, passwords, Social Security numbers, or unrelated case documents in the form. Request records should be kept only as long as reasonably needed for the request, compliance, disputes, security, or legal obligations.

9. How RECEIPTS uses information

10. Sale, sharing, targeted advertising, and Global Privacy Control

RECEIPTS does not sell personal information or use it for targeted advertising in the current build. It also does not intentionally share personal information for cross-context behavioral advertising. Because those activities are not performed, an opt-out does not currently change how the site behaves. If that changes, required notices and controls should be implemented before the new use begins.

11. Retention

DataTypical retention approach
Browser/local dataUntil you clear it or browser storage is removed.
Optional cloud backupUntil you overwrite it, delete it, or delete the account.
Authentication dataUntil account deletion, subject to Supabase security/legal retention.
Subscription/payment metadataAs needed for billing, access control, accounting, disputes, fraud prevention, and law.
AI usage countersNumeric/pseudonymous usage records for service and cost control; no legal-question text is intended to be stored in those counters.
Legal/privacy requestsOnly as long as reasonably necessary for the request and related legal/compliance needs.

12. Your choices and privacy rights

Depending on where you live, privacy law may give you rights to request access, correction, deletion, or a portable copy of certain personal information, and rights relating to sale, sharing, targeted advertising, or sensitive data. RECEIPTS provides self-service controls for local data and signed-in cloud backups and accepts privacy requests through the privacy/legal request page. RECEIPTS may need to verify a request before acting on account data.

Make a privacy/legal request

13. Children

RECEIPTS is a general-audience U.S. legal-information service and is not directed to children under 13. Children under 13 should use only the non-account public information with a parent or guardian and should not create an account, make a payment, or submit personal information. If RECEIPTS learns that personal information was collected online from a child under 13 in a manner covered by COPPA, it should be deleted or handled in accordance with applicable parental-consent requirements.

FTC COPPA information ↗

14. Security and breach response

RECEIPTS uses HTTPS, account authentication, Row Level Security for the backup table, server-side secret handling, input limits, and security headers. No internet service can promise perfect security. If a reportable data incident occurs, RECEIPTS intends to investigate, contain it, and provide notices required by applicable law.

15. U.S. focus and processing

RECEIPTS is designed around U.S. public-law research and is not marketed as an international legal service. Service providers may process data in the United States and other locations described in their terms. Access from another country may create additional legal obligations that should be assessed before actively marketing there.

16. Changes

This policy should be updated before materially changing data collection, adding advertising technology, enabling document uploads, or introducing a new provider or new use of personal information.

Last updated September 15, 2026. Version 1.49.7.1 sign-in and subscription-flow update.