Shoebox

Privacy policy

Last updated 6 September 2026

Shoebox photographs business receipts, reads the figures off them, and keeps both the photo and the figures so you can find them later. This page says exactly what that means for your data. It is written to be read, not to be survived.

What we collect

Your account details. When you sign in with Google or Apple we receive your email address, your name, and an account identifier from them. We store those to know which receipts are yours. If you use Apple's Hide My Email, we only ever see the relay address Apple gives us.

The receipts you photograph. The image itself, plus what we read from it: merchant, date, total, tax, currency, and how confident the reader was. Any tags you add, and the name on the staff link that submitted it.

Nothing else. No analytics, no advertising identifiers, no third-party trackers, no location. We do not sell data, and we do not use your receipts to train any model.

Where it is stored

Receipt photographs are held in Microsoft Azure Blob Storage in the Australia East region. Access is private: images are only ever served through an authenticated request, and the storage container itself is not publicly readable.

Everything else — your account record, the figures, tags and staff links — is held in a MariaDB database on our own server, reachable only from the application itself and never exposed to the internet.

Each business's data is separated by an owner identifier that is applied on every read and every write, and receipt photographs are stored under a path that includes that identifier and is checked before an image is served.

How your Google data is used

Shoebox requests one Google permission beyond signing you in: drive.file. That permission only grants access to files this app itself creates. We cannot see, open or modify anything else in your Google Drive — not your other spreadsheets, not your documents, nothing.

We use it for exactly one thing: when you press Export, we create a spreadsheet in your Drive and write your receipts into it. The spreadsheet is yours. If you stop using Shoebox tomorrow, it stays with you.

Shoebox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Who else sees it

Microsoft Azure stores the photographs, and Azure AI Document Intelligence reads each photograph to extract the figures. The image is sent for that purpose and the result returned to us.

Google handles sign-in, and receives the rows you choose to export into your own spreadsheet.

Apple handles sign-in if you choose Sign in with Apple on iPhone.

That is the complete list. No advertisers, no data brokers, no analytics companies.

Staff links

If you send a staff link, whoever holds it can add receipts to your account and see only the ones they added themselves. They cannot read your other receipts and cannot export anything. The link is the credential, so treat it like one — anyone you forward it to can add receipts under that name.

Keeping and deleting

Receipts are kept until you delete them. Deleting a receipt in the app removes both the row and the photograph — the image is not retained afterwards.

To delete your account and everything in it, open the account menu in the app and choose Delete account. Every receipt and photograph is removed straight away, staff links stop working, and we revoke the access you gave us to Google or Apple. Spreadsheets already exported to your Drive belong to you and are not touched.

If you can't sign in any more, email [email protected] from the address you signed in with and we'll remove everything within 30 days.

You can withdraw Shoebox's access to your Google account at any time at myaccount.google.com/permissions. Exports stop working immediately; your receipts stay until you ask us to delete them.

Security

Traffic is encrypted in transit. Receipt photographs are private and served only to an authenticated request from the account that owns them. Database credentials and Google tokens are held in server configuration that is not in source control, and the database accepts connections only from the application itself.

No system is perfect. If you find a problem, please write to [email protected] and we will take it seriously.

Children

Shoebox is a tool for businesses and is not directed at children under 13.

Changes

If this policy changes in a way that affects what we collect or who sees it, we will update the date at the top and, where the change is significant, tell you in the app.

Contact

Back to Shoebox