Privacy policy.
At Purchy, we take your privacy seriously. This policy explains what we collect, how we use it, who processes it on our behalf, and how to access, correct, or delete your data. We've written it to be specific, not generic — every third-party processor and AI service we use is named below.
Overview
Purchy is a personal AI agent for managing purchases, return windows, refunds, subscriptions, and warranties. To do that, we collect:
- Identity data from your sign-in method (email, name, profile photo)
- Receipt and email data from Gmail (if you connect it) or from receipt photos you scan
- Chat & voice input so the Purchy AI assistant can answer your questions
- Bank/credit data via Plaid — if you choose to connect an account (optional, available to all users)
- App diagnostics (crash logs, performance metrics, device info) to keep the app running
What we don't do: We do not sell your data. We do not show ads. We do not train external AI models on your data. We do not access your location. We do not read your contacts, SMS, or browsing history.
Information We Collect
Identity & Account Information
Purchy uses passwordless authentication. We support three sign-in methods:
- Email magic link — we collect your email address and a temporary one-time code
- Sign in with Google — we receive your email, name, and profile photo from Google
- Sign in with Apple — we receive your name and email (or Apple's private relay address if you choose to hide it)
We do not use passwords. We do not collect your phone number, postal address (for your account), date of birth, or government-issued IDs.
Receipt & Purchase Information
When you sync Gmail, scan a receipt, or chat with Purchy, we extract and store:
- Merchant name, purchase date, total amount, and line items
- Payment-method type and the last 4 digits of the card used (we never see or store full card numbers, CVVs, or expiration dates)
- Receipt or email content that includes shipping address (if present in the email body) so we can show it on the receipt detail screen
- Original receipt images you scan or upload (stored in our encrypted Supabase Storage)
- Raw email content (subject, body HTML/text, sender, recipient) for emails identified as purchase confirmations
Chat, Voice & Image Input
- Chat messages — the text you send to the Purchy AI is stored to maintain conversation history
- Chat-attached images — any image you attach to a chat message is sent to OpenAI for analysis but not stored by us; only a placeholder reference remains in chat history
- Voice recordings — if you tap the microphone, your audio is sent to OpenAI Whisper for transcription. The audio itself is processed ephemerally — we do not store or retain it. Only the resulting transcript text is saved as a chat message.
- Profile photo — if you upload one, it is stored in encrypted Supabase Storage
Device & Diagnostic Information
We collect this automatically when you use the app:
- Device model, OS version, app version, push token, and a pseudonymous device identifier
- Crash logs and performance traces (sent to Firebase Crashlytics)
- Feature usage and screen views (sent to Firebase Analytics — pseudonymous, not tied to real-world identity)
- Sync metrics, parsing attempts, and notification delivery records (stored in Supabase to keep the app reliable)
We do not collect location data, contacts, SMS, web browsing history, or any data outside the app.
How We Use Your Information
- Receipt processing — extract purchase data from receipts and emails so you can see all your purchases in one place
- Deadline tracking — detect return windows and free-trial end dates, then notify you
- Refund discovery — identify potential refund opportunities based on return windows and policy violations
- Calendar sync — add return-deadline events to your device calendar (with your permission)
- AI assistant — answer your questions about your purchases via the in-app chat
- Service quality — improve receipt-recognition accuracy, fix bugs, and analyze app performance
AI & Automated Processing
Purchy uses several AI services to extract structured data from your receipts, classify emails, and power the in-app chat assistant. Specifically:
OpenAI (GPT-4 / GPT-4o / Whisper / Vision)
We send the following to OpenAI's API:
- Email subject and body content (for receipt classification and parsing)
- Receipt OCR text and parsed JSON (for chat queries about your purchases)
- Chat messages and any images you attach
- Voice recordings (transcribed by Whisper, then discarded by us)
Per OpenAI's API Data Usage policy, your data is not used to train OpenAI's models and is retained by OpenAI for at most 30 days for abuse monitoring before deletion.
Google Cloud Vision
Receipt images you scan are sent to Google Cloud Vision for text extraction (OCR). Google Cloud Vision processes the image and returns structured text. Per Google Cloud's terms, this data is not used to train Google's models.
Veryfi (alternative receipt OCR)
When higher-accuracy structured extraction is needed (e.g., complex grocery receipts), we may send receipt images to Veryfi. Veryfi is a SOC 2 Type II certified processor that does not retain your data after extraction.
Anthropic (Claude)
Claude does much of Purchy's reading. We send it:
- The sender, subject and body of emails Purchy is deciding about — to tell a receipt from a newsletter, and to pull out the merchant, total, items and dates
- Item names, to work out what kind of product something is
- Merchant names and public policy pages, when researching a return window
- The pages the cancel assistant's browser is on, if you use it — described in Cancel Assistant
Under Anthropic's commercial terms your data is not used to train Anthropic's models. Anthropic retains inputs for up to 30 days for abuse monitoring, then deletes them.
Google Gemini
We use Gemini for merchant research and to read order details out of a video or screen recording you choose to share. Purchy uses a paid Google API key, under which your data is not used to train Google's models.
TypeSafe (Jev)
Jev is a second opinion. Where Purchy has already made a judgement from its own rules — most often “is this email really a cancellation confirmation?” — we can send the email's subject and an excerpt of its body to TypeSafe and ask it to agree or disagree. It returns a confidence number, not text, and Purchy keeps the answer so we can measure how often our own rules are right.
Your receipts, emails, chats and images are never used to train AI models. Every AI provider above is used through a paid API under terms that forbid training on your data. The separate lookup services receive merchant and product names only, under their own public API terms.
Third-Party Processors
We use the following companies to operate Purchy. The first table lists the processors that handle your content — your receipts, emails, images, chats and account data. Each of those is bound by a Data Processing Agreement (DPA) or equivalent enterprise terms that prohibit them from using your data for their own purposes or to train their models.
The second table lists lookup and search services. Those receive a merchant, retailer or product name so Purchy can find a return policy, a cancellation page or a price — never your name, your email address, your order numbers or the contents of your email. They operate under their own public API terms rather than a DPA, so we list them separately instead of implying a protection they do not carry.
Processors that handle your content
| Service | Purpose | Data Sent |
|---|---|---|
| Supabase | Primary backend, database, file storage | All user data |
| OpenAI | AI chat, email parsing, voice transcription, image analysis | Email content, chat messages, receipt text, audio, attached images |
| Anthropic (Claude) | Email classification and receipt parsing, item categorisation, return-policy research, and the optional cancel assistant | Email sender, subject and body; receipt text and item names; the web pages the cancel assistant visits |
| Google Gemini | Merchant research and extracting order details from a video or screen recording | Merchant names; the video or recording you provide |
| TypeSafe (Jev) | Second-opinion checks on Purchy's own judgements — for example whether an email really is a cancellation confirmation | Email subject and an excerpt of the body |
| Microsoft | Outlook / Microsoft 365 mailbox access (optional, read-only) | OAuth tokens; Purchy reads the messages it matches as purchase-related |
| Kernel | Cloud browser for the optional cancel assistant | The cancellation session, including your sign-in to that service; the browser is deleted when the run ends |
| Google Cloud Vision | Receipt OCR (text extraction) | Receipt images |
| Veryfi | Alternative high-accuracy receipt OCR | Receipt images (when used) |
| Plaid | Bank/credit card linking (optional, all users) | Bank credentials handled by Plaid; we receive transaction and balance data |
| Firebase Analytics | Pseudonymous app usage analytics | Pseudonymous user ID, screen views, feature events |
| Firebase Crashlytics | Crash and error reporting | Stack traces, device model, app version, pseudonymous user ID |
| RevenueCat | Subscription management | Pseudonymous user ID, subscription status |
| Expo Push Notifications | Push notification delivery | Push token, notification payload |
| Apple / Google | Sign-in identity providers + payment processing for subscriptions | Authentication tokens; subscription billing handled by Apple/Google |
Lookup & search services
| Service | Purpose | Data Sent |
|---|---|---|
| Keepa | Amazon product price tracking | Product ASIN only |
| Brave Search | Finding return policies, cancellation pages, prices and deals on the public web | A search phrase built from a merchant, retailer or product name — for example “Nike return policy US” |
| Tavily | The same public-web lookups, where it returns better results than Brave | A merchant, retailer or product name |
Two honest caveats about the lookup services. A product name can itself be revealing — a book, a medication, a piece of clothing — so although we send no identifier that ties a query to you, the query is not always neutral. And when Purchy's return-policy researcher works on a merchant, the AI composes the search phrase itself from the merchant and item, so we describe the shape of those queries rather than promise an exact wording.
The optional cancel assistant uses Kernel and Anthropic. See Cancel Assistant below for what each one receives.
Gmail Integration
Gmail integration is optional — you can use Purchy without connecting Gmail by scanning receipts manually. If you choose to connect Gmail, we request the gmail.readonly scope, which means:
- Read access to scan for purchase confirmation emails
- Read access to email attachments (PDFs, images) identified as receipts
- We never send, modify, or delete emails on your behalf
- We do not use Gmail data for advertising or train AI/ML models on it
CASA Tier 2 Verified: Purchy's Gmail integration has passed Google's independent Cloud Application Security Assessment (CASA) at Tier 2 against the Mobile Application Security Verification Standard (MASVS Level 2).
Email content (subject, body, sender, recipient) we identify as a receipt is sent to OpenAI for parsing. We do not send unrelated emails.
You can revoke Gmail access at any time from your Google Account permissions page or by tapping “Disconnect Gmail” in Purchy Settings.
Outlook & Microsoft Integration
Connecting an Outlook, Hotmail, Live or Microsoft 365 mailbox is optional, exactly like Gmail — you can use Purchy by scanning receipts by hand instead. If you do connect one, Purchy signs you in with Microsoft and asks for these permissions:
Mail.Read— read-only access to your mail. Purchy cannot send, reply to, delete, move or change a single message.User.Read,openid,profile,email— your name and email address, so Purchy knows whose mailbox it isoffline_access— so Purchy can keep syncing new receipts without asking you to sign in every time
Purchy searches your mailbox for purchase-related mail — order confirmations, shipping notices, receipts, subscription and renewal notices — and reads the ones it matches. Those are processed the same way Gmail receipts are, including being sent to the AI providers named above for parsing. Purchy does not read your unrelated mail, and does not use mail from any provider for advertising or to train AI models.
You can disconnect at any time from You → Sources in Purchy, which stops the syncing and removes Purchy's stored token. To revoke the permission at Microsoft's end as well, visit your Microsoft account app permissions page. Receipts Purchy has already saved stay in your account until you delete them or delete your account.
Bank & Credit Card Linking (Plaid)
Bank linking is available to all users and is completely optional — the rest of the app works without it.
When you link a bank or credit card account:
- You authenticate directly with your bank through Plaid Link — we never see your bank credentials
- Plaid issues us an access token (encrypted at rest in our database)
- We retrieve transaction history, account balances, and credit-card payment due dates to enable payment-due reminders and transaction matching
- You can disconnect any linked account at any time in Settings; we delete the access token and all linked transaction data within 30 days
Plaid is regulated as a consumer reporting agency under US law and operates under its own privacy policy.
Cancel Assistant (Cancel It For Me)
Cancel It For Me is completely optional. When you ask Purchy to cancel one of your subscriptions, Purchy's cancel assistant opens that service's website in a cloud browser, signs in to your account there and presses the service's cancel buttons for you. It stops and asks you before anything that would buy, upgrade or accept an offer. Purchy only offers it for services that allow it, and explains all of this before your first run. Our cancel assistant page describes it for the websites it visits.
Who helps run it
- Kernel runs the cloud browser. Each browser is used for one cancellation and deleted when the run ends.
- Anthropic (Claude) reads each page the browser is on to decide the next step. Anthropic keeps those pages for up to 30 days.
Your sign-in
You enter your sign-in details for that service in Purchy. They are sent encrypted, used once to sign in, and can't be read afterwards, not even by Purchy.
What Purchy keeps
- Proof of cancellation, for up to 12 months: a screenshot and the text of the service's confirmation page, and a screenshot of the service's page that shows which account was cancelled (usually its email address or username), as evidence if you ever need to dispute a charge.
- A last-page screenshot, for 30 days: kept only if a run fails or Purchy can't confirm the cancellation.
- A record of each run: the service, dates, status and outcome, kept with the rest of your account data.
Purchy keeps no other content from the service's pages. You can delete a run's proof at any time. Withdrawing your consent in Settings deletes all of your proof, and deleting your account deletes your proof and your run records.
Data Storage & Security
Your data is stored on Supabase (which runs on AWS US-East infrastructure). Plaid access tokens, Gmail OAuth tokens, and other sensitive credentials are encrypted at the application layer using AES-256 before being written to the database.
- AES-256 encryption — sensitive tokens encrypted at the app layer
- TLS 1.3 — all network traffic encrypted in transit
- Row-level security — each user can only access their own data
- CASA Tier 2 verified — independent annual security assessment
Data Sharing
We do not sell your personal information.
We never use your data for:
- Targeted or personalized advertising
- Selling to data brokers or resellers
- Determining creditworthiness or lending
- Training external AI/ML models
- Creating marketing databases
- Retargeted or interest-based ads
The only circumstances under which we share data:
- Service Providers — the processors listed above (Supabase, OpenAI, Anthropic, Microsoft and the rest) handle your content on our behalf under Data Processing Agreements or equivalent enterprise terms, and cannot use your data for their own purposes. The lookup and search services receive only a merchant, retailer or product name, and operate under their own public API terms rather than a DPA — which is why we list them apart.
- Legal Requirements — when required by law (subpoena, court order) or to protect Purchy's rights, users, or the public from harm. We will notify affected users where legally permitted.
- Business Transfers — if Purchy is acquired or merges with another company, your data would transfer subject to this privacy policy. We would notify users at least 30 days in advance via email.
Your Rights (GDPR/CCPA)
- Access — request a copy of your personal data
- Correction — request correction of inaccurate data
- Deletion — delete your account and data
- Portability — export your data in a portable format
- Opt-out — opt out of marketing communications
- No Sale — your data is never sold (CCPA)
To exercise these rights, contact us at services@purchy.app.
You can also delete your account from inside the Purchy app: Settings → Account → Delete my account. See our deletion instructions page for full details.
Data Retention & Deletion
We retain your data for as long as your account is active. Upon account deletion:
- Personal data deleted within 30 days of account deletion (profiles, receipts, emails, chat history, images, voice transcripts)
- Encrypted backups purged within 30 days; backups are not actively accessed
- Subscription & billing records up to 7 years for tax and accounting compliance (managed by Apple, Google Play, or RevenueCat — contains no receipt content)
- Anonymized analytics — aggregated usage statistics may be retained indefinitely; cannot be tied back to individuals
Children's Privacy
Purchy is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us at services@purchy.app and we will delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. For material changes (new processors, expanded data collection, changes to retention) we will notify you via email or in-app notification at least 30 days before the change takes effect. Continued use of Purchy after the effective date of an updated policy constitutes acceptance of the changes.
Contact Us
If you have questions about this Privacy Policy or want to exercise your data rights, contact us:
- Email: services@purchy.app
- Dynamic Dev Solutions LLC — the entity that publishes Purchy