PaperTrail Privacy Policy

Your receipt data, your privacy choices.

PaperTrail starts receipt processing on your device and asks before sharing receipt data with optional third-party AI services.

Effective Date: July 28, 2026

1. Data We Collect

When you add content, PaperTrail stores receipt images, recognized receipt text, merchant and purchase details, item records, product photos, warranty documents, and other attachments locally on your iOS device. If you create an account, PaperTrail also collects the name and email address you provide for authentication.

2. How We Collect Data

You provide data by creating an account, entering purchase details, scanning with the camera, selecting content from Photos, or importing a file. Camera and photo-library access is used only for content you choose to add to PaperTrail.

3. Local Storage and Account Services

Purchase records and attachments are stored locally and protected by iOS device security. If you use account features, your name and email address are sent to Google Firebase Authentication to create and authenticate your account. Authentication session tokens are stored securely in the iOS Keychain.

4. On-Device Receipt Processing

Receipt optical character recognition starts on your device using Apple's Vision framework. You can choose on-device-only processing. With that choice, PaperTrail does not send the receipt image or recognized receipt text to a third-party AI service.

5. Optional Third-Party AI Processing

Only after you explicitly select Allow AI Extraction, PaperTrail sends the receipt image and all text recognized on it to OpenRouter, Inc. OpenRouter routes the request to Google's Gemini 2.5 Flash AI model. Receipt data can include the merchant, date, purchased items, prices, totals, payment details, loyalty or account numbers, order numbers, and any other personal information visible on the receipt.

OpenRouter and Google process this data only to return structured receipt details to PaperTrail. PaperTrail does not use this data for advertising, tracking, or user profiling. AI processing is optional, and on-device processing remains available if you do not grant permission.

6. Third-Party Protection and Retention

PaperTrail configures OpenRouter requests to deny provider data collection and require zero-data-retention routing. OpenRouter states that it does not retain prompts or responses unless logging is explicitly enabled, and the selected Google Vertex endpoints are identified by OpenRouter as zero-retention endpoints that do not train on prompts.

K2G LLC requires service providers that receive PaperTrail user data to provide the same or equal protection described in this policy and required by applicable data-protection law. Limited processing required for security, abuse prevention, billing, or legal compliance is governed by each provider's policy: OpenRouter Privacy Policy, OpenRouter Zero Data Retention, and Google Gemini API Data Use.

7. Consent and Your Choices

Before the first AI-enhanced receipt extraction, PaperTrail identifies the data and recipients described above and asks for your permission. Nothing is sent to OpenRouter or Google unless you affirmatively allow AI extraction. You can withhold permission, choose on-device-only processing, or revoke permission later under Settings → Receipt Intelligence.

8. Data Retention, Deletion, and Export

Local records remain on your device until you delete them or remove the app. You can export your app data or delete all local records from Settings. If you created an account, you can use Settings → Delete Account to delete the account and its Firebase Authentication information. AI receipt inputs are processed transiently under the zero-data-retention configuration described above.

9. Sale, Advertising, and Tracking

K2G LLC does not sell or rent your personal data and does not share it with third parties for targeted advertising or cross-app tracking.

10. Contact Us

If you have any questions regarding this Privacy Policy, please contact K2G LLC at contact@k2gllc.online.