Legal
Data & Security
Last updated: September 2, 2026
We know receipts often contain sensitive financial information. Here's how Receipt AI protects your data.
Encrypted in transit
All traffic to and from Receipt AI is served over HTTPS. Requests to AI providers and payment processors are also made over encrypted connections.
Passwords hashed, never stored in plain text
Account passwords are hashed with bcrypt before storage. We cannot see or recover your password — only reset it.
Private file storage
Uploaded receipt files are stored outside the public web root and are only reachable through an authenticated, ownership-checked download link — never a directly guessable URL.
Per-business data isolation
Business accounts only ever see receipts belonging to their own business. Team member access is role-gated (owner/admin/manager/member).
API keys, not shared passwords
External integrations (our Business API) authenticate with a dedicated, revocable API key — never your login credentials — and only that business's data is accessible with it.
Rate limiting & abuse prevention
Login, registration, upload, payment, and API endpoints are all rate-limited to reduce abuse and brute-force risk.
Payments
We never see or store your full card number or M-Pesa PIN. Card payments are processed by Stripe; M-Pesa payments by Safaricom's Daraja API — both PCI-conscious payment processors. We store only transaction references and amounts needed for your billing history.
AI Processing
When you scan a receipt, the image is sent to a configured AI provider (Google Gemini, OpenAI, or Google Cloud Vision) solely to extract the data fields for that request. See our Privacy Policy for more on third-party data sharing.
Reporting a Concern
If you believe you've found a security issue, please contact us directly rather than filing a public report, so we can investigate and respond before any details are made public: support@tafity.com.