Privacy Policy
Last updated 30 September 2026.
The short version. The app does not upload your writing or process record to Receipts servers. Records stay in your browser, files you download, and your own Google Drive if you connect backup. We receive separate site analytics, purchase information and messages you send us, as described below. Do not send private writing or proof links to support. Standard school use creates no Receipts-side roster. The optional class hand-in service and dashboard assistant process the limited information described below when enabled. Organisation use requires a signed scope and data inventory before activation.
What Receipts is
Receipts records editing activity while a student writes. The student can share a replay and factual record with a teacher. It is operated by Receiptsproof Pte. Ltd., a private limited company incorporated in Singapore, and built and run day to day by its founder.
Where your writing lives
- In your browser. Your documents and the keystroke record behind them are stored in your browser's local storage on your own device.
- In your Google Drive, if you sign in. Each document is saved as a file in your own Drive and mirrored into a Google Doc you own. The mirror is an output copy: writing in that Google Doc is not recorded as Receipts keystrokes. Existing copies are never overwritten automatically. If a copy differs from the current Receipts document, its update pauses; choose Unlink copy in My records and save again to make a fresh output copy while the existing Doc stays in your Drive. We use the drive.file scope, which grants access to files this app created, plus any single file you yourself choose to open through Google's file picker, for example when using the Google Docs cross-check. It cannot browse, search or read the rest of your Drive on its own.
- If you explicitly capture a Google Doc. After you pick one native Google Doc, Receipts reads the revision snapshots Google makes available for that file into this browser and builds a read-only replay. The source Doc is not edited, Receipts does not watch it in the background, and the snapshots and your OAuth token are not sent to a Receipts server. Reloading or clearing this tab removes the imported replay.
- No Receipts-hosted writing storage. The app does not upload writing to a Receipts server, database or backup. If you include writing or a proof link in a support message, we receive that message under the support-data policy below. Please do not send that material.
What we receive about you
- If you sign in with Google: your name, email address and profile picture. These are stored in your browser so the app can show who is signed in and attach your licence to the right email. They are not transmitted to us.
- If you buy something: the purchase is handled by Polar, which acts as merchant of record. Polar receives your payment details and email. We can view customer email, order and payment-status information in Polar to provide the purchase and support. We never see or store your card details. When you paste a licence key, your browser checks it directly against Polar to confirm it is valid.
- If you email us, book a call or buy an organisation service: we receive the business contact details and message you choose to send. We keep the email, booking, signed order, invoice or support record only for communication, delivery, accounting, legal obligations and dispute handling. Do not send essay text, proof links, Drive file IDs, OAuth tokens or licence keys in an organisation sales or support message.
- Site analytics: we use Vercel Web Analytics, which counts page views and referrers without cookies and without building a profile of you. It also receives the standard coarse device and location information that Vercel derives for a page view. The writing app, shared proof viewer and teacher dashboard load no analytics code. Marketing pages use analytics; do not put private information into their URLs.
Proof links
When you copy a proof link, the record travels inside the link itself: the recorded edits with their timing and input origin, the deleted passages, the date, length and record position of each sitting on your device clock, and the name of your device's time zone, so the person you send it to sees the same dates you do. Nothing is uploaded to us to make it work. The app can also make a shorter link: it saves a new, fixed snapshot in your own Drive, sets that one file to "anyone with the link can view", and binds the link to that snapshot's SHA-256 digest so a later file change is detected instead of silently changing an old link. You create it deliberately, it is still never uploaded to us, and anyone holding either kind of link can watch the writing. Anyone you send that link to can replay the writing, so only send it to people you intend to show your work to. If a record is too long to fit reliably in chat, the app offers the short link or a file instead. Both are yours to share or not.
Optional class hand-ins and teacher dashboard
The dashboard can display sample records without connecting a class. When the class service is enabled and a teacher connects a class, Vercel processes the requests and Upstash stores the class code, encrypted class label, teacher credential hash, public encryption key, student-link hashes and revoked-link hashes. A hand-in adds an assignment identifier, encrypted proof reference, integrity hash, receipt time, any student-supplied time and rule version, and either a student-link hash or an encrypted typed name. Student names attached to individual links, assignment details, notes and the dashboard conversation stay in the teacher's browser. A typed name is not identity verification.
The writing and full process record stay in the student's Drive. Each Send to teacher creates a separate snapshot, so a later send does not overwrite an earlier submission. For a class with an encryption key, only a holder of that class's private key can open the snapshot. Earlier unencrypted shares remain public to anyone with their link until the student deletes them. Keep the downloaded class key file safe; losing or rotating a class key can prevent older hand-ins from opening.
Submission entries expire after 30 days from receipt and are removed when the inbox is read or another hand-in arrives. Class data uses a 30-day expiry refreshed by relevant activity, including authenticated inbox reads. Teachers can delete submissions or the connected class sooner. Browser copies and student-owned Drive files have separate lifetimes and must be cleared or deleted by their owners.
Optional dashboard assistant
When the live assistant is enabled and a teacher sends a request, Vercel passes the question, recent conversation, coded receipt summaries and any tool results to Anthropic. The dashboard replaces names it recognises from the class list with student codes before sending. This is not a guarantee that free text contains no identifying information. Do not paste student writing, private links or other personal details into a question or note. The assistant does not automatically receive essay text or the full editing record.
Receipts does not save these requests on its server. The conversation remains in the teacher's browser, and Anthropic processes requests under its API data-handling terms. An organisation's signed data inventory must cover this optional processing before use. Turning on the assistant does not authorize a new use of student data under an existing order.
Diagnostics
If something breaks, the app keeps a short technical log in your browser: a fixed error category, a known app component, the time and browser family. Raw error messages, stack traces and resource URLs are excluded because they can contain private data. Older entries are reduced to these fields when the updated app opens. This log is not sent automatically. You choose whether to copy it and send it to us.
Cookies
Receipts does not set advertising or tracking cookies. Vercel Web Analytics does not use cookies. Google may set cookies that are technically necessary when you choose to use Google sign-in or Drive.
Children
Receipts is used by students, including minors. If you are under 18, involve a parent or guardian before any purchase. Individual paid plans are account-bound and cannot currently be transferred from a guardian's Google account to a student's different account. For anyone below the applicable digital-consent age, a parent, guardian or legally authorised school must approve the relevant use before sign-in, Drive connection or proof sharing where law or policy requires it. We do not rely on a child's self-stated age or an adult payment card as proof of consent. Google and Polar process identity and payment information under their own notices.
Deleting your data
- Clear record in the app removes a document and its keystroke history from your browser.
- Sign out removes your account details, local document library, local licence key and licence metadata from that browser. A verified licence can be restored from its private file in the owner's Drive after the owner signs in again.
- Files in your Drive are yours. Delete them like any other file. You can also revoke this app's access at any time at myaccount.google.com/permissions.
- We hold no Receipts-side student-writing account to delete. Business email, booking, order, support and accounting records may be retained where needed to provide the service, keep required company records, handle a dispute or comply with law. You may ask what business contact data we hold at hello@receiptsproof.com.
Your rights
Depending on where you live you may have rights to access, correct, export or erase personal data held about you. Your app writing records live on your device and in your own Google account. Contact us about business, booking or support data we hold. Polar holds purchase records as merchant of record and can be contacted through your receipt.
Changes
If this policy changes, the date at the top changes with it. Material changes will be noted on the site.
30 September 2026: clarified optional class hand-ins, dashboard storage, Upstash and Anthropic processing, snapshot retention, and the absence of analytics in the writing app and dashboard.
Contact
Questions about privacy, or about what is stored where: Receiptsproof Pte. Ltd. at hello@receiptsproof.com, or reply to your Polar receipt. Data protection matters under Singapore's PDPA reach the Data Protection Officer, Receiptsproof Pte. Ltd., at the same address.
Receipts. Show how it was written. Operated by Receiptsproof Pte. Ltd. Home · Terms · For educators · For schools © 2026 Receiptsproof Pte. Ltd.