DropSheet / Where receipt apps send your data

Where receipt scanning apps actually send your data

A receipt is not a blank slip. It can name a pharmacy, a bar, a lawyer, a clinic. It often prints the last four of a card. If an app reads that photo on a server, a copy of that slip left your phone. This page records what each company publishes about that copy.

Every claim below is from that company’s own privacy policy per their website as of 2026. Terms, security pages, DPAs, and subprocessor lists are used the same way. Review sites and blogs are not used. Where a company does not publish an answer, this page says not stated. Policies change. The links are the source.

Comparison

Short answers only. Detail and quotes sit under each name.

OCR is optical character recognition: software that reads the text off a receipt photo or PDF — merchant, date, amount — so a person does not have to type it. If that step runs on a server, a copy of the image left the phone.

AppImage uploaded?Who does the OCR?How long kept?Can you delete it?Training / sharing
ExpensifyYesReceipt images named at Collective Solution, Gemini, OpenAIWhile the account is activeYes. Backups not statedPersonal data not sold, with a California caveat
ShoeboxedYesNot statedWhile the account is activeYes. Two published figures differAnalytics yes. Training not stated
DextYesGoogle Cloud, namedThrough the licence, then deletionYes. 10-day return windowThird-party genAI not allowed to train. AWS Bedrock listed
Zoho ExpenseYesVeryfi, named for autoscanUntil the account ends, then staged deleteYes. Active DB then backupsStaff may verify OCR images
WaveYes. Receipt scan is a paid featureNot statedNot statedNot statedNot stated
VeryfiYesIn-house, statedWhile you use the serviceYes. Says deleted foreverTrains its own models. Says it does not sell
QuickBooksImage itself not namedNot namedAs long as needed for the serviceYes. Some copies may remainTrains AI on customer content. Does not sell under CCPA
FreshBooksYesSensibill, named on supportUntil purpose ends, then delete or anonymizeYesReceipt training not stated
Hubdoc (Xero)YesSoftware and/or human teams, namedSeven years after the contract endsYes. Request deleteWill not sell without consent, except as the policy sets out
DropSheetNoThis browserNot storedNothing to delete on a serverNo. There is no copy

The following is a breakdown of the chart, in order.

Expensify

Privacy policy last updated 1 April 2026. Subprocessor list as of 2026; that list has no date on the page.

  1. Yes. The subprocessor list says AWS holds “Receipt images and encrypted long term storage of all data.”
  2. Named on the subprocessor listas receiving receipt files. Collective Solution: “Receipt images.” Google Gemini: “Receipt images and PDFs uploaded by users.” OpenAI: “scanned receipts.” AWS: “Receipt images and encrypted long term storage of all data.” The list does not say those parties run OCR. The privacy policy does not name an OCR vendor.
  3. “We will retain your information for as long as your account is active or as needed to provide you services.” A separate line covers legal obligations, disputes, and agreements. How long a receipt image sits after you close a report is not stated.
  4. Yes. “Other than in aggregated or de-identified form as permitted under the Expensify Terms of Service, and except as required by applicable law, we will delete or otherwise destroy your Personal Data as soon as practicably possible following your termination or cancellation of your use of the Expensify Service.” Backups are not stated.
  5. On personal data: “Except as otherwise stated in this policy and our Terms of Service, we do not sell, trade, share, or rent the Personal Data collected from the Expensify Service to third parties.” Aggregated or de-identified data: “may also share such data with any third parties, including advertisers, promotional partners, sponsors, event promoters, and/or others.” Under California, Colorado, and Connecticut law the policy also says: “We may have sold (as defined under California, Colorado and Connecticut laws) the following categories of personal information: Identifiers (online) … Internet and other electronic network activity information … Profile inferences.” Receipt images are not named in that sale list.

Sources: Expensify privacy policy; Expensify subprocessors. As of 2026.

Shoeboxed

Privacy policy has no last-updated date on the page. GDPR page has no last-updated date on the page. Both as of 2026.

  1. Yes. The policy lists “User-submitted receipts, business cards, and other documents” among information collected.
  2. Not stated. No OCR vendor is named. The policy says employees, consultants, and contracted workers “may use or come into contact with user information during the course of their normal working duties.” It does not say whether a person or a machine reads the image.
  3. “We will retain your information for as long as your account is active or as needed to provide you services,” plus legal obligations, disputes, and agreements.
  4. Yes. Two published pages give different clocks. The privacy policy says that after a deletion request, “we delete your raw data from our databases and applications within 6 months.” “However, your data might still be kept in our backup files (not accessible to non-Shoeboxed personnel) for up to three years.” The GDPR page says: “When a user deletes their account, Shoeboxed deletes their raw data within 90 days.” “Document data may still be kept in backup files for up to one year (these backups are not accessible by any non-Shoeboxed personnel). These backups are done on a rolling window and are deleted after a year.” “Account data may still be kept in backup files for up to three years (these backups are not accessible by any non-Shoeboxed personnel), for audit purposes.” The two published figures differ. This page does not pick one.
  5. Training on receipts is not stated. Analytics are: cookies, beacons, tags, and scripts “to analyze trends” with marketing partners and analytics providers. Selling receipt data is not stated.

Sources: Shoeboxed privacy policy; Shoeboxed GDPR. As of 2026.

Dext

Privacy policy last updated 19 July 2024, effective 31 July 2024. Data Processor Agreement last updated 18 February 2025.

Dext splits the pile. Account contact data is covered by the privacy policy. Receipts and invoices you upload are treated as your data, with Dext as processor:

“This privacy policy shall not apply to any personal data contained in documents (such as invoices or receipts) uploaded to the Dext platform by you or on your behalf. Any such personal data will be held by us as your data processor.”
  1. Yes. Documents are uploaded to the Dext platform.
  2. Named third party. The DPA subprocessor table lists Google Cloud: “This is used for our OCR data extraction service and Product AI functionality.” AWS is listed for storage and for AWS Bedrock. Microsoft Azure (Open AI) is listed as a generative AI tool provider.
  3. The DPA: “The subject duration of the Processing of Your Personal Data is for the Licence Term plus the period until We delete Your Personal Data in accordance with our retention policy, which is set out in our privacy policy available on our website.” Uploaded document contents are not given a separate numbered year count in the DPA.
  4. Yes. After the agreement ends, the default instruction is deletion. You have 10 days to ask for the data back. Lawful retention is an exception, and Dext says it will notify you of that requirement.
  5. The privacy policy is clear on third-party generative AI: “we do not allow any third-party generative AI tool providers which we use in our services to train their models using your data (including personal).” That is a published limit. The same DPA still lists AWS Bedrock as “a large language model hosting/ training provider” used to provide the service. What “training” means for Bedrock versus the third-party ban is not explained. Analytics providers such as Google are named for Technical Data about the account, not specifically for receipt images.

Sources: Dext privacy policy; Dext Data Processor Agreement. As of 2026.

Zoho Expense

Zoho group privacy policy last updated 22 December 2025. Subprocessor directory dated 25 August 2026.

  1. Yes. The privacy policy refers to “scanned images that you submit to us.”
  2. Veryfi is named on Zoho’s service-specific subprocessors (last updated 25 August 2026) for Zoho Expense: “To extract data from the documents uploaded for auto scan.” Data processed: “Receipts uploaded by the customers.” The group privacy policy also says Zoho staff and contractors may “manually verify scanned images that you submit to us to verify the accuracy of optical character recognition.”
  3. “We hold the data in your account as long as you choose to use Zoho Services.” After you terminate the account, “your data will eventually get deleted from active database during the next clean-up that occurs once in 6 months. The data deleted from active database will be deleted from backups after 3 months.”
  4. Yes. You can request deletion of service data. The six-month then three-month clock above is the published schedule after termination.
  5. Manual OCR verification is published, as quoted. Selling receipt data is not stated in the passages reviewed. Training of third-party models on those receipts is not stated in the Zoho policy text reviewed.

Sources: Zoho privacy policy; Zoho service-specific subprocessors. As of 2026.

Wave

Privacy policy effective 10 January 2025. Subscription terms for the “receipt scan feature” effective 8 July 2024 / 4 November 2024. The privacy page is a JavaScript app; the full body did not render as static HTML as of 2026, so this page does not quote it. A public subprocessor list was not found.

  1. Yes. Wave’s paid subscription terms name a “receipt scan feature.” Wave’s own product pages also list “Digitally capture unlimited receipts.” How the file is stored is not quoted here because the privacy policy body did not load as static HTML.
  2. Not stated. No OCR vendor is named on the pages that loaded.
  3. Not stated. The privacy policy body did not load as static HTML.
  4. Not stated in the text retrieved.
  5. Not stated in the text retrieved. No training or sale sentence about receipts was found on the published pages that loaded.

Sources: Wave privacy policy; Wave paid subscription terms. As of 2026.

Veryfi

Privacy policy last updated 10 July 2026. Subprocessor list last updated 24 August 2026. Veryfi publishes more about OCR than the rest of this list.

  1. Yes. “Veryfi provides subscribers an unlimited cloud service for storage of financial documents in the form of photos, pdfs, and metadata.”
  2. In-house, stated. “Veryfi is 100% machine powered end-to-end. We do not use humans or data extraction teams to extract or categorize your data.” “Veryfi develops and trains its own models in-house. We do not use your data to train third-party or “generative” AI models.” The subprocessor list names AWS for cloud hosting, not an outside OCR vendor.
  3. “Veryfi only stores the data it needs to function properly — for as long as you want Veryfi to function for you.” A numbered year is not given.
  4. Yes. “Everything you (the customer) delete from your account using Veryfi interfaces is deleted forever.” “Deleting your account permanently removes all your data you ever stored with Veryfi.” Backups of deleted files are not mentioned.
  5. Training of Veryfi’s own models is published: “we may use data you submit, which can include personal data contained in your documents, to train, validate, and improve our proprietary machine learning models.” “Veryfi develops and trains its own models in-house. We do not use your data to train third-party or “generative” AI models.” Sharing: “We never sell or share your data with anyone.”

Sources: Veryfi privacy policy; Veryfi subprocessors. As of 2026.

QuickBooks (Intuit)

Intuit Global Privacy Statement last updated 9 March 2026. No public named subprocessor list for receipt OCR was found.

  1. The image itself is not named. The statement says Intuit may receive “information about your business, your finances, expenses, invoices, financial statements, details of your financial transactions.” Whether the receipt photograph is stored as a file is not stated in that document.
  2. Not named. Service providers “also include AI providers, including generative AI providers.” No vendor is named for receipt OCR.
  3. “Unless you specifically ask us to delete your personal information, we retain your personal information as long as it is necessary to … provide you with services.” Different information may be kept for different periods.
  4. Yes, through account settings or the Intuit Privacy Center. The same statement says there may be occasions “where we are unable to fully delete, anonymize, or de-identify your personal information due to technical, legal, regulatory compliance, or other operational reasons,” in which case Intuit says it will isolate the data until it can.
  5. Training is published: Intuit may use personal information for “training our artificial intelligence models and other machine learning models, as well as by assessing … certain content our customers send or display through the Platform.” Google Workspace API data is carved out of generalized model training. On sale: “Intuit and Mailchimp do not sell Personal Information under the CCPA.”

Source: Intuit Global Privacy Statement. As of 2026.

FreshBooks

Privacy policy last updated 5 February 2026. Subprocessor page has no last-updated date on the page.

  1. Yes. FreshBooks support: you can attach JPEG, PNG, or PDF receipts to bills and expenses. “Uploaded receipts can be downloaded again anytime.” Receipt scanning is a separate feature that sends the file for OCR.
  2. Named on FreshBooks support, not on the subprocessor table. “Receipt scanning is provided by one of our partners, Sensibill.” “Using Optical Character Recognition (OCR), details are automatically extracted from the scanned documents.” The third-party sub-processors page lists AWS, Google Cloud, Google LLC, Zendesk, and Salesforce. It does not list Sensibill.
  3. Privacy policy: “How long we keep Personal Information that we have collected depends on the type of information and the purpose for which it was collected.” After that purpose, FreshBooks “will either delete the Personal Information or, to the extent permitted under applicable law, anonymize it.” Support also says scanned uploads “remain indefinitely until made into an expense, bill, or deleted.”
  4. Yes. “You have the right to request that your Personal Information be permanently erased/deleted.” Support also lets you delete an attached receipt image from a bill.
  5. Artificial intelligence is described for fraud detection, a support chatbot, and credit evaluation. Training of models on receipt images is not stated. Vendors “are not permitted to use your Personal Information for their own marketing.”

Sources: FreshBooks privacy policy; FreshBooks subprocessors; FreshBooks receipt scanning; FreshBooks attach receipts. As of 2026.

Hubdoc (Xero)

Hubdoc privacy policy effective 11 June 2021. Hubdoc terms note an update of 14 October 2022. Xero’s group subprocessor list has no last-updated date on the page.

  1. Yes. “When you email or upload documents to our Services via the web or mobile application, in addition to the document itself, we may collect data including the time and date the document was submitted and details related to the source of the document.”
  2. Hubdoc terms: “Data Extraction may be performed by software and/or human teams.” That is a published human review of uploaded documents. Hubdoc’s privacy page names AWS and Salesforce as subprocessors, plus “other service and technology providers,” and does not name an OCR vendor. Xero’s group subprocessor list names CloudFactory for “Data extraction and processing.” That list is Xero’s, not labeled as Hubdoc-only.
  3. “We will retain personal data relating to our agreement with our customer (“collected customer data”) for seven years following the end of our contract with that customer.” The terms say personal data “will be deleted no later than seven (7) years following the end of our agreement with you.”
  4. Yes. The privacy policy lists a right to “request that your personal data be transferred or exported to another organisation, or deleted from our records.”
  5. “We will not disclose, trade, rent, sell or otherwise transfer personal information without your consent, except as otherwise set out herein.” Service providers get what they need to perform designated functions; Hubdoc “do[es] not authorize them to use or disclose personal information for their own marketing or other purposes.” Training of models on receipt images is not stated on the Hubdoc privacy page.

Sources: Hubdoc privacy policy; Hubdoc terms; Xero subprocessors. As of 2026.

DropSheet

Same five questions. Source is this site’s privacy page, as of 2026.

  1. No. “Photos, PDFs, and pasted email text are read in Chrome, Edge, or Safari. They are not posted to a server.”
  2. This browser. “This site does not load Google Fonts. The English reading files are hosted here. Your receipt is not in that request.”
  3. Not stored. “There is no DropSheet account and no receipt database. The rows live in this tab until you export or close it.”
  4. There is nothing to delete on a DropSheet server. Close the tab, or export and keep the file you chose. The Gumroad license lives in this browser and can be cleared from the Unlocked control.
  5. No copy, so no training set and no sharing of the shoebox. Buying is on Gumroad. Gumroad sees the payment, not the receipts.

Source: DropSheet privacy. As of 2026.

Method

As of 2026. For each name: the company’s privacy policy, then any public subprocessor list, DPA, or security page linked from it. Claims are quoted or paraphrased from those pages only. “Not stated” means the published document did not answer the question, not that the practice does not exist. Subprocessor lists change. If a later policy disagrees with a sentence here, the later policy wins.

DropSheet reads receipts in your browser. Nothing is uploaded. getdropsheet.com.

Mike Printz · [email protected]