Privacy policy

This policy covers all eleven Billfold apps and this website. They share one account and one database, so they share one policy.

Last updated 1 August 2026

1. Who is responsible

Billfold is built and run by Carson Rodrigues, an individual developer based in India. He is the data controller for everything described here. The apps covered are ReciDex, TaxPocket, WiseLedger, SnapReceipt, LensExpense, FlowBooks, SyncDext, ForeClaim, FleetLog, EnterpriseX and ZestPOS, on iOS, Android and the web.

You can reach a person at rodriguescarson@gmail.com.

2. What is collected

Your account

An email address. Billfold sign-in is passwordless, so no password is ever created, sent or stored. You ask for a one-time code by email, or you sign in with Apple or Google. When you use Apple or Google, we receive the email address on that account and an opaque identifier for it, and nothing else. If you use Apple's private relay address, that is the address we hold.

What you put into the apps

The apps store what you give them, and nothing beyond it:

  • Receipt images you photograph or upload, and any copy of them cached on your device.
  • Expense records: merchant, date, total, tax amounts, currency, category, line items, notes and tags. These come either from text extraction or from you typing them in.
  • Work records specific to the app you use: folders and share links, invoices and client details, expense claims and approvals, shifts, fuel stops and mileage, trips and per-diem entries.
  • Business and point of sale data in ZestPOS: your shop name and address, your menu or item list, stock counts, orders, bills, daily totals, and the payment identifiers you choose to display at checkout, such as a UPI ID or a QR image.
  • Settings: language, currency, tax jurisdiction and notification preferences.

Technical data

Server logs record the request, a timestamp, an IP address, and the app and version making the call. Crash reports contain the error and the device model and OS version. These are used to keep the apps working and to fix faults, and are not combined into a profile of you.

What is not collected

There are no advertising identifiers, no third-party trackers, no behavioural analytics SDKs, no background location tracking, and no access to your contacts, calendar or photo library beyond the single image you pick. This website sets no cookies and runs no analytics.

3. Receipt images and OpenRouter

When you ask an app to read a receipt, the image is sent to OpenRouter, which routes it to a model that returns the merchant, the date and the amounts as text. This is the only reason a receipt image ever leaves your device, and OpenRouter is the only AI provider Billfold uses.

  • The image and the text taken from it are not used to train models. Billfold sends its requests with training and logging disabled.
  • Nothing about your account travels with the image. OpenRouter receives the picture, not your email address or your user id.
  • You do not have to use it. Every app lets you type a receipt in by hand, and a manually entered receipt is never sent anywhere except to your own account.
  • ZestPOS does not use text extraction at all. No ZestPOS data is ever sent to OpenRouter.

OpenRouter's own privacy policy is at openrouter.ai/privacy.

4. Where data is stored

Accounts, records and receipt images live in one Supabase project, hosted on infrastructure in the ap-south-1 region (Mumbai, India). Supabase acts as our hosting processor: it runs the database, the file storage and the authentication service on our behalf and does not use the contents for its own purposes.

Traffic between the apps and the database is encrypted with TLS, and data is encrypted at rest by the hosting provider. Every table carries your user id, and row-level security in the database refuses any read or write where that id is not yours. That rule is enforced by the database itself, not by the app, so a bug in one app cannot expose another user's rows.

Because OpenRouter and the model providers it routes to operate outside India, a receipt image you choose to have read is processed abroad for the few seconds that takes. If you would rather no data left the country, use manual entry.

5. What is never done with it

  • Your data is never sold, rented or traded. There is no exception.
  • There is no advertising in any Billfold app, so nothing is shared with advertisers, ad networks or data brokers.
  • Your receipts, expenses and sales figures are not read, mined or aggregated for marketing, benchmarking or any product other than showing them back to you.
  • No one on our side reads your records unless you ask for help with a specific problem and give permission for that.

6. Who else processes it

These are the only third parties involved, and what each one gets:

  • Supabase: hosts the database, file storage and authentication. Holds everything described in section 2.
  • OpenRouter: receives receipt images you submit for text extraction, and nothing else. See section 3.
  • Apple and Google: only if you choose to sign in with them. They confirm your identity and pass us an email address and an identifier.
  • Cloudflare: serves this website. It sees the usual web request data for pages you load here. No account data is on this site.
  • Apple and Google app stores: handle the download itself and report their own aggregate figures to us. We do not receive a list of who installed an app.

7. How long it is kept

  • While your account exists, your records are kept so that they are there when you need them at tax time. Receipts are long-lived by design and nothing is quietly expired.
  • When you delete your account, everything is erased from the live database and file storage immediately. See deleting your account.
  • Encrypted backups are kept for disaster recovery and roll off on a 30-day cycle, so a deleted account disappears from backups within 30 days at the latest.
  • Server and crash logs are kept for 30 days, then discarded.
  • Receipt images sent for extraction are processed and returned in the moment. They are not stored by us anywhere except in your own account.

8. Your rights

Whatever law applies where you live, these apply to you here. Under the GDPR, the UK GDPR, India's Digital Personal Data Protection Act and the CCPA, they are also legal rights.

  • Access: ask what is held about you and get a copy.
  • Export: every app can export your records as CSV or PDF from inside the app, at any time, without asking us.
  • Correction: edit any record in the app. If something cannot be edited, write to us and we will fix it.
  • Deletion: erase your account and everything in it, from Settings in any app or by email. Nothing is held back.
  • Objection and restriction: tell us to stop processing something, and we will either stop or explain why we cannot.
  • Complaint: you can complain to your local data protection authority. We would rather you told us first so we can fix it.

Write to rodriguescarson@gmail.com from the address on your account and you will get an answer within 30 days, usually much sooner. There is no charge.

9. Children

These are tools for work. They are not directed at children and are not designed for anyone under 16. If you believe a child has created an account, write to us and it will be deleted.

10. Changes to this policy

If this policy changes, the date at the top changes with it, and the new version replaces this one on this page. A change that materially affects what happens to data you have already given us will be announced in the apps before it takes effect, not slipped in quietly.

11. Contact

Questions about this policy, or about a specific piece of your data, go to rodriguescarson@gmail.com. You can also call or message +91 70202 86635.