Draft. This page describes what the service actually does technically today — it has not been legally reviewed and shouldn't be shown to real users until a lawyer has looked it over. Treat it as a technical source of truth to build from, not a finished privacy notice.
Privacy policy
Data controller: P721 Väst AB (Rceep).
What data is stored
Email address and password hash (via ASP.NET Core Identity), plus the receipts you enter yourself: merchant, date, line text, price, receipt image, and calculated reminder dates.
Why
To be able to show you your receipts, calculate complaint-right/warranty dates, and (if you choose to) share a receipt via a link.
Sharing with third parties
Receipt data is not shared with third parties, except Anthropic's API, which is used to read the receipt on upload (the image, or the text from a local pre-read, is sent there for reading). Verified directly against Anthropic's official documentation (August 2026): this data is stored for at most 30 days before being automatically deleted, and is never used to train their models without explicit permission from us — no such permission has been given. A stricter arrangement (zero storage at all, so-called "Zero Data Retention") is available but requires a separate agreement via Anthropic's sales team — see docs/arkitektur.md.
Your rights
You can export all your data (JSON) or permanently delete your account and all associated data at any time — see the Security page once you're logged in.