Privacy Policy
The short version: your receipts are yours. We collect only what is needed to run the app for you, we store it privately to your account, we never sell it, and we run no ads. The only thing we measure is anonymous usage (which features get used) to improve the app; it is never tied to you and never includes your receipts.
Bagging: Receipts & Expenses ("Bagging," "the app," "we," "us") is a private receipt and invoice keeper for iPhone. This policy explains, in plain language, what the app collects, where it is stored, how it is used, and the choices you have.
Who runs this app
Bagging: Receipts & Expenses is an independent app. If you have any question about this policy or your data, contact us at support@bagging.app.
What we collect
We collect only the following:
- Your Apple or Google account identifier (via Sign in with Apple or Sign in with Google). When you sign in, Apple or Google gives us a stable identifier for your account and, if you choose to share them, your name and email address. We use the identifier solely to create your account and to make sure that when you sign in, you see your own receipts (and those of any workspace you've chosen to join) and no one else's. The email address lets us contact you about your account. If you choose to subscribe to email updates, you can also connect a Google account inside the app just to verify an email address; we store only the address. We do not send marketing email unless you have opted in, and Apple's Hide My Email works normally. We do not receive your Apple or Google password.
- The receipt and invoice images you add. The photos you capture with the scanner or import from your photo library are uploaded and stored as part of your account so you can view them on your device.
- The details extracted from each receipt: vendor, total amount, and date. When you add a receipt, the app reads the image on your device and proposes a vendor name, a total amount, and a date. You can review and correct these before saving. The values you save are stored with the image, along with anything else you add to the entry: a note, tags, or a second photo.
We do not collect your contacts, your precise location, your browsing activity, or your device advertising identifier, and we do not capture individual line items from your receipts. We do record anonymous, aggregate usage analytics (never tied to your identity and never including your receipts) described under Anonymous usage analytics below.
How text recognition works (on your device)
The reading of your receipts (recognizing the text so the app can suggest the vendor, total, and date) happens on your iPhone, using Apple's built-in text-recognition technology. The image used for that recognition step is processed locally on the device and is not sent anywhere for that purpose. Only after you confirm and save an invoice are the image and the saved details stored to your account.
Where your data is stored
Your account identifier, your saved receipt details, and your receipt images are stored on infrastructure operated by the developer using Cloudflare:
- saved details (vendor, total, date, and related record fields) in a Cloudflare D1 database, and
- receipt images in Cloudflare R2 object storage.
This data is associated with your account so that it is available to you across launches. It is not part of any shared or public dataset.
Sharing within workspaces (your choice)
Receipts in Bagging live in workspaces. A workspace you keep to yourself is visible only to you. If you invite someone to a workspace (or join someone else's with an invite code), everyone in that workspace can see the receipts saved in it (the images, and the saved vendor, total, and date) along with the display names of its members. That is the entire point of sharing a workspace with a partner, bookkeeper, or team, and it only happens through an invite code that a member deliberately shares. You can leave a workspace at any time, and a workspace's owner can revoke invite codes and remove members. Nothing is shared beyond the workspaces you choose to be part of.
How we use your data
We use your data only to provide the app's features to you:
- to authenticate you and load your own receipts;
- to display your receipts, totals, and running total;
- to let you view, edit, and delete your receipts; and
- to generate the CSV and PDF exports you ask for, on your device, when you tap Export.
We do not use your data for advertising, profiling, or any purpose unrelated to running the app for you.
Anonymous usage analytics
To understand which features are used and where the app can be better, we use TelemetryDeck, a privacy-first analytics service. It records anonymous, aggregate events (for example that an export happened or the app was opened) with coarse technical context such as app version, device model, and OS version. These signals are not linked to your identity: they contain no name, email, account identifier, advertising identifier, precise location, or receipt content, and they are never used for advertising or sold. TelemetryDeck is built for GDPR-compliant analytics that collect no personal data. Development builds send no analytics at all.
What we do NOT do
- We do not sell your data.
- We do not share your data with advertisers or data brokers.
- We do not include third-party advertising or cross-app tracking SDKs in the app. (We use one privacy-first analytics tool, TelemetryDeck: anonymous, no personal data, never for advertising; see Anonymous usage analytics.)
- We do not track you across other apps or websites.
- We do not use your receipts to build profiles or train unrelated products.
Email-in receipts
Bagging can give you a personal forwarding address (for example
k7q2mxw9rd@in.bagging.app). When you forward an email there, it is processed in
memory: there is no mailbox, and the email itself is not kept. What is stored, in your
workspace and pending your confirmation, is the useful payload: attached PDF or image files,
or the message body when the bill is the email itself. Nothing becomes a receipt without
your explicit confirmation in the app.
For each forwarded email we also keep a small tray record: the subject line, the sending address, and when it arrived. After you confirm or dismiss an item, its stored file is deleted immediately and the tray record is kept as history for up to 90 days, then removed. Your forwarding address can be rotated at any time in the app, and deleting a workspace or your account deletes its email-in data with it.
Exports you create
When you export a date range, the app builds a CSV spreadsheet and a PDF summary on your device and hands them to the iOS share sheet. From there, you decide what happens to those files: email, save to Files, send to another app. Once a file leaves the app through the share sheet, it is handled by whatever destination you choose, under that destination's terms, not ours.
Data retention and deletion
We keep your receipts and their details for as long as your account exists, because the whole point of the app is to hold onto them for you.
You are in control:
- Delete a single receipt at any time from within the app. Deleting a receipt removes its details and its image from your account.
- Delete your entire account and all associated data from within the app, or by contacting us at support@bagging.app from the Apple ID or Google account associated with your account. We will delete your data within 30 days of verifying the request.
After deletion, backups (if any) are purged on our normal rotation and are not used for any other purpose in the meantime.
Children
Bagging is intended for general audiences and is not directed at children. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact us and we will delete it.
Security
Data in transit between the app and our servers is protected with standard encryption (HTTPS/TLS). Your sign-in session token is stored in the iOS Keychain on your device. No method of storage or transmission is perfectly secure, but we limit what we collect specifically to reduce risk.
Changes to this policy
If we change this policy, we will update the effective date above and post the new version at this URL. Material changes will be reflected before they take effect.
Contact
Questions, requests, or concerns:
Bagging
support@bagging.app