Privacy Policy
RECEIPTS is a U.S.-focused legal-information and research website. This policy describes the data flows in the current public version.
1. Data kept on your device
RECEIPTS uses browser storage for bookmarks, notes, recent searches, saved Receipts, drafts, accessibility/display preferences, return-to-task state, and—after you use account sign-in—the last sign-in email on that device so RECEIPTS can offer a faster returning-user sign-in. This data stays in that browser unless you clear it, export it, or—after sign-in—use account work sync or backup features.
2. Optional accounts and authentication
If you choose Continue with Google, Google and Supabase process the sign-in and RECEIPTS receives the basic account identity needed to authenticate you, such as your verified email and account identifier. RECEIPTS does not request access to read your Gmail inbox, contacts, or messages. The secure email-link method remains available as a backup. Public research does not require an account, and RECEIPTS does not ask you to create a site password.
3. Account work sync and optional backup
Signed-in users can keep a privacy-minimized copy of bookmarks, personal notes attached to bookmarks, saved Receipts, and reading/display preferences in a Supabase row protected by Row Level Security so that saved work can follow the same account to another device. Search history and drafts are excluded from automatic sync by default. They are included only when you affirmatively select the manual sensitive-data backup option.
Account controls let you export or delete the cloud backup. Deleting the RECEIPTS account is designed to remove the Supabase authentication account and cascade-delete RECEIPTS account rows. Historical payment records held by Stripe may remain where required for payment, accounting, fraud-prevention, dispute, or legal purposes.
4. Payments and subscriptions
Stripe processes the optional support payment and, if public premium billing is later enabled, any activated premium subscription. Public premium checkout is currently locked during prelaunch QA. RECEIPTS does not receive or store a full payment-card number. RECEIPTS may keep the minimum Stripe customer/subscription identifiers and status needed to confirm access, prevent duplicate billing, and open Stripe's subscription-management tools.
5. Hosting, security, and technical data
Cloudflare hosts and secures the site and may process ordinary request, network, device, performance, and security metadata needed to deliver the service. RECEIPTS does not intentionally embed third-party advertising trackers in the current build.
When paid AI research is enabled, Cloudflare Turnstile may receive the visitor's network address and security/browser signals to perform a bot check. RECEIPTS' own daily usage counter is designed to store a keyed pseudonymous account identifier and numeric request counts, not the raw network address or legal-question text.
6. Live AI research
Free rule cards and local help tools can operate without sending a legal question to an AI provider. Only when a signed-in authorized premium user deliberately starts live AI research and the feature is enabled is the question and selected research context sent through the RECEIPTS server to the OpenAI API. The request is made with model storage disabled by the application. OpenAI states that API inputs and outputs are not used to train its models by default; provider-side retention, abuse monitoring, security, and legal obligations are governed by OpenAI's current business/API terms and policies.
OpenAI enterprise/API privacy information ↗
7. External official-source links and software delivery
When you open an external government, court, agency, or other source website, that destination receives the request and applies its own privacy practices. The current site loads the Supabase browser library from jsDelivr and may load Cloudflare Turnstile only when that security feature is needed; those providers can receive ordinary connection metadata.
8. Legal, privacy, copyright, and accessibility requests
If you submit the RECEIPTS privacy/legal request form, RECEIPTS processes the contact information and message you provide to review and respond to that request. Do not put full financial account numbers, passwords, Social Security numbers, or unrelated case documents in the form. Request records should be kept only as long as reasonably needed for the request, compliance, disputes, security, or legal obligations.
9. How RECEIPTS uses information
- Provide requested site features and authentication.
- Save data only when you choose local or cloud storage features.
- Process payments and subscription status.
- Protect the site against abuse and control paid-AI costs.
- Respond to privacy, copyright, accessibility, and payment issues.
- Comply with legal obligations and protect rights, safety, and security.
10. Sale, sharing, targeted advertising, and Global Privacy Control
RECEIPTS does not sell personal information or use it for targeted advertising in the current build. It also does not intentionally share personal information for cross-context behavioral advertising. Because those activities are not performed, an opt-out does not currently change how the site behaves. If that changes, required notices and controls should be implemented before the new use begins.
11. Retention
| Data | Typical retention approach |
|---|---|
| Browser/local data | Until you clear it or browser storage is removed. |
| Optional cloud backup | Until you overwrite it, delete it, or delete the account. |
| Authentication data | Until account deletion, subject to Supabase security/legal retention. |
| Subscription/payment metadata | As needed for billing, access control, accounting, disputes, fraud prevention, and law. |
| AI usage counters | Numeric/pseudonymous usage records for service and cost control; no legal-question text is intended to be stored in those counters. |
| Legal/privacy requests | Only as long as reasonably necessary for the request and related legal/compliance needs. |
12. Your choices and privacy rights
Depending on where you live, privacy law may give you rights to request access, correction, deletion, or a portable copy of certain personal information, and rights relating to sale, sharing, targeted advertising, or sensitive data. RECEIPTS provides self-service controls for local data and signed-in cloud backups and accepts privacy requests through the privacy/legal request page. RECEIPTS may need to verify a request before acting on account data.
13. Children
RECEIPTS is a general-audience U.S. legal-information service and is not directed to children under 13. Children under 13 should use only the non-account public information with a parent or guardian and should not create an account, make a payment, or submit personal information. If RECEIPTS learns that personal information was collected online from a child under 13 in a manner covered by COPPA, it should be deleted or handled in accordance with applicable parental-consent requirements.
14. Security and breach response
RECEIPTS uses HTTPS, account authentication, Row Level Security for the backup table, server-side secret handling, input limits, and security headers. No internet service can promise perfect security. If a reportable data incident occurs, RECEIPTS intends to investigate, contain it, and provide notices required by applicable law.
15. U.S. focus and processing
RECEIPTS is designed around U.S. public-law research and is not marketed as an international legal service. Service providers may process data in the United States and other locations described in their terms. Access from another country may create additional legal obligations that should be assessed before actively marketing there.
16. Changes
This policy should be updated before materially changing data collection, adding advertising technology, enabling document uploads, or introducing a new provider or new use of personal information.
Last updated September 15, 2026. Version 1.49.7.1 sign-in and subscription-flow update.