Privacy Policy
Last updated 29 July 2026
ReceiptDrop is a Chrome extension that reads a retail receipt you have open, extracts the purchase details, and writes them to a Google Sheet you own. This page explains exactly what it touches, what leaves your computer, and what is kept.
The short version: ReceiptDrop has no access to your mailbox. It reads one email at a time, only when you click. Receipt text is sent for processing and is not stored. Your spreadsheet lives in your Google Drive, not ours.
What ReceiptDrop accesses
Your email — only the message you have open
ReceiptDrop requests no Gmail permissions. It does not connect to the Gmail API and cannot search, list, download, or open your messages. When you click the Log receipt button, it reads the visible text of the message currently displayed on your screen — the same text you are looking at — and nothing else. If you never click the button, no email content is ever read.
Your Google Drive — one file, the one it creates
ReceiptDrop uses Google's drive.file permission, which grants access only
to files the application itself creates. In practice that is the single buy sheet it
makes for you. It cannot see, open, or modify any other file in your
Drive — not your other spreadsheets, documents, or photos. It also reads your Google
account's email address so the setup page can show you which account is connected.
Files you choose to upload
If you drag in or paste a receipt photo, screenshot, PDF, or saved email file, ReceiptDrop reads that file to extract the purchase details. It only ever accesses files you explicitly hand it.
What is sent off your computer
To turn a receipt into structured rows, the receipt's text (or image) is sent to an AI language model for processing. Depending on your setup, this happens one of two ways:
- With a ReceiptDrop subscription: the content is sent to our relay server, which immediately forwards it to OpenAI, returns the result to you, and keeps no copy. The content is held in memory for the duration of the request only.
- With your own OpenAI key: the content goes directly from your browser to OpenAI. Our servers are not involved at all.
Extracted rows are then written to your Google Sheet, over an encrypted connection, directly from your browser. We never receive a copy of your buy sheet.
OpenAI processes this content as a service provider. Under OpenAI's API terms, data sent through the API is not used to train their models.
What is stored, and where
On your own computer
Held locally in your browser, never transmitted to us:
- Your settings — which sheet is linked, your column choices, preferences
- Your product catalogue — the ASINs, product names, brands, and target sell prices you enter, so repeat purchases fill themselves in
- A short record of orders already logged, used to warn you about duplicates
- Your OpenAI key, if you use your own
On our servers (subscribers only)
- Your licence key, plan, and a monthly count of receipts processed
- A one-way hash of the Gmail address your licence is used on, plus a
masked hint such as
b***@example.com, so a single-seat licence stays on a single account. Your address is used to compute this hash and is not stored.
Receipt content, purchase data, product names, prices, and spreadsheet contents are never stored on our servers.
What we never do
- We do not sell, rent, or share your data with anyone
- We do not use your receipts or purchase data for advertising
- We do not use your data to train AI models
- We do not track your browsing outside of the extension's own function
- We do not place advertising or third-party tracking in the extension
Payments
Subscription payments are handled by Stripe. Card details go directly to Stripe and are never seen or stored by us. We receive only your email address, subscription status, and the last four digits of your card for support purposes.
Your control
- Your sheet is yours. It lives in your Google Drive. Cancel or delete the extension and it stays exactly where it is.
- Revoke access any time at myaccount.google.com/permissions.
- Delete local data by removing the extension from Chrome.
- Delete server data by emailing hello@receiptdrop.ai. We will remove your licence record and seat hash within 30 days.
Google API disclosure
ReceiptDrop's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Children
ReceiptDrop is a business tool and is not directed at anyone under 18.
Changes
If this policy changes materially, we will update the date above and notify active subscribers by email before the change takes effect.
Contact
Questions, or a data deletion request: hello@receiptdrop.ai.