Legal

Privacy Policy

Last updated: September 6, 2026

This Privacy Policy explains what information ScanBill ("ScanBill", "we", "us") collects when you use scanbill.co and our invoice extraction service (the "Service"), how we use it, who we share it with, and the choices you have. By using the Service, you agree to the collection and use of information in accordance with this policy.

1. What data we collect

We collect the following categories of information:

  • Account information — your name, email address, phone number, and company name, provided when you sign up or update your profile.
  • Invoice and receipt files — the PDF, JPG, PNG, or HEIC files you upload for extraction.
  • Extracted invoice data — the vendor name, invoice number, dates, amounts, tax, currency, category, and line items that our AI extracts from your uploaded files.
  • Billing information — your subscription plan, usage, and billing history. Payment card details are collected and processed directly by Paddle; we never see or store your full card number.
  • Usage data — how many extractions you run each month and basic account activity, used to enforce plan limits and improve the Service.

2. How we use your data

  • To run your uploaded invoices and receipts through Google's Gemini AI model for data extraction, and return the structured result to you.
  • To store your account, extraction history, and files securely in our Supabase database and storage.
  • To process payments and manage your subscription through Paddle, our payment provider.
  • To let you connect your Google account so extracted data can be pushed to a Google Sheet you choose.
  • To enforce monthly plan limits, provide customer support, and send you account-related emails.
  • To detect, investigate, and prevent fraud, abuse, and security incidents.

We do not sell your personal data, and we do not use your invoice content to train our own models.

3. Third-party services we use

ScanBill relies on the following third-party services to operate. Each processes a limited slice of your data, only as needed to provide their part of the Service:

  • Supabase — hosts our database, file storage, and authentication. Your account details, extraction records, and uploaded files are stored here.
  • Google Gemini (Google AI) — processes the content of uploaded invoices and receipts to extract structured data. Files are sent to Gemini solely to perform the extraction you requested.
  • Google OAuth / Google Sheets API — used only if you choose to connect Google Sheets, to authenticate you with Google and write extracted rows to a spreadsheet you control.
  • Paddle — our payment processor and merchant of record. Paddle handles checkout, card processing, invoicing, and subscription billing.

We do not control these providers' own privacy practices; we encourage you to review their respective privacy policies as well.

4. Data retention and deletion

We retain your account data, uploaded files, and extraction history for as long as your account is active, so you can access your extraction history at any time.

If you delete your account from Settings → Danger Zone, we permanently delete your account, every extraction and line item, your uploaded files, and your billing history. This action is immediate and cannot be undone. Some minimal billing records may be retained by Paddle as required by law (e.g. for tax and accounting purposes) even after your ScanBill account is deleted.

5. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate profile information (Settings → Profile).
  • Export your extraction data at any time, using the Excel export available on every extraction.
  • Delete your account and all associated data (Settings → Danger Zone).
  • Object to or restrict certain processing of your data.

To exercise any of these rights beyond what's available directly in your account settings, contact us using the details below.

6. Data security

Files and data are encrypted in transit (HTTPS/TLS) and at rest. Access to your data is scoped to your account using row-level security in our database, so other users cannot see your invoices or extracted data. No method of transmission or storage is 100% secure, but we work to protect your information using industry-standard practices.

7. Children's privacy

The Service is not directed to individuals under 16. We do not knowingly collect personal data from children.

8. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service before the change takes effect.

9. Contact us

If you have questions about this Privacy Policy or how we handle your data, contact us at support@scanbill.co.