Reclaim Privacy Policy

Last updated: August 1, 2025

1. Information We Collect

  • Account Data: Email address and password for signup and login
  • Social Login Data: Name, email, and profile picture when you sign in with Google
  • Profile Data: User-uploaded avatar images, Venmo and Cash App usernames, account creation timestamp, and premium status
  • Usage Data: IOU details including amount, note, participants, creation date, recurring IOUs, and group interactions
  • Premium Data: Receipt images uploaded for bill scanning. Images are processed by Google Gemini but never stored. Only parsed expense data is saved
  • Device Data: Firebase Cloud Messaging token for push notifications
  • Purchase Data: Subscription status managed by RevenueCat

2. How We Use Your Data

  • Account and Authentication: To let you sign up, log in, reset your password, and secure your session
  • Profile and Social Features: To show your avatar, name, and payment handles to you and your friends
  • Bill Scanning: Receipt images sent to Google Gemini for text recognition. We do not store the images. We only keep the parsed amounts and participants
  • Notifications: Firebase Cloud Messaging tokens allow optional payment reminders and updates
  • Purchases: RevenueCat manages your subscription entitlements
  • Hosting: Supabase securely stores profiles, IOUs, groups, and parsed amounts

3. Data Sharing

We do not sell or rent your personal data. We share data only with:

  • Supabase for database hosting of accounts, profiles, IOUs, and groups
  • RevenueCat for subscription entitlement management
  • Firebase for push notification delivery
  • Google Gemini for receipt scanning. Receipt images are processed temporarily and never stored

All third parties process data only for the purposes listed above.

4. Data Retention and Deletion

  • Profile Data is retained until you delete your account
  • Settled IOUs are deleted permanently 14 days after being settled
  • Parsed receipt data is deleted once the IOU is settled. Receipt images are never stored
  • Backups and logs may persist for up to 30 days for security and debugging before deletion

5. Your Choices

  • Delete Account: Use Delete Account in settings to erase your profile and all IOUs
  • Password Reset: Reset your password at any time
  • Disable Notifications: Turn off push notifications in your device settings

6. Security

We use HTTPS/TLS for secure data transmission and encryption for sensitive storage. Access to production systems is limited to authorized personnel.

7. Children's Privacy

Reclaim is not intended for children under 13. We do not knowingly collect data from minors. If you believe we have, contact us to remove it.

8. Third-Party Privacy Policy Links

9. Changes to This Policy

We may update this policy occasionally. We will post the new version here with an updated "Last updated" date. Significant changes will be notified in-app.

10. Contact Us

For questions or requests, email ishaan@ishaantek.com.

Developed by Ishaan Garg and Aiden Xie.