Privacy Policy
Last updated: July 24, 2026
Who we are
Gigspend is made by Pay By Cents LLC, based in San Jose, California. This policy explains what the Gigspend mobile app does and doesn't send off your device, and who it's shared with when it is.
There are no accounts
Gigspend doesn't ask for your name, email address, or phone number, and there's no sign-up or login. Instead, the app maintains a pseudonymous install record using Android ID on Android or Apple's identifier for vendor on iOS. These identifiers can change in circumstances controlled by the operating system; they do not necessarily reset after every reinstall. On iOS, the identifier generally changes after all apps from the same vendor are removed and one is later reinstalled. On Android, its lifecycle depends on the device, user, and app-signing key. If you connect Google Drive backup on Android, Google's sign-in screen displays your Google account information as part of Google's consent flow. Gigspend requests only Google Drive’s limited drive.file permission to manage backup files created by the app and does not send your Google profile information to Gigspend’s servers.
What stays on your device
The following are stored in the app's local, on-device storage. They are not uploaded as a complete database to Gigspend’s servers, but selected portions may be transmitted when you use the specific features described under “What is sent off your device, and why.” Optional Backup & Restore copies the backup data described below to your own cloud-storage account.
- Your receipts, notes, mileage entries, and line items
- Photos of receipts you've scanned or imported
- Exported reports (Excel, PDF, and Receipt Book files) — these are generated and shared entirely on your device, and are never part of a cloud backup
- Your deduction settings and category preferences
What is sent off your device, and why
Some data has to leave your device for app functionality, fraud prevention, purchases, referrals, and optional AI features. On-device OCR is performed with Google ML Kit before the recognized text described below is transmitted. Camera and photo-library access are used only when you scan, import, save, or back up receipt images. Here's what each feature sends:
| Feature | What's sent | Why |
|---|---|---|
| Every request to our servers | A session token that carries your device identifier and account status (unlock status, scan counts) | Authenticates the request and enforces free-tier limits — this is attached automatically to nearly every server call, not just the specific features below |
| Receipt scanning | Recognized text and its position on the page (no photo) | To identify the merchant, date, and total automatically |
| Automatic OCR help (on by default, no photo involved) | The same recognized text from the scan above — never the photo — sent only when Gigspend can't confidently resolve two or more of merchant, date, total, or category on its own | At Gigspend’s discretion, we send that text to a third-party AI service provider to fill in the fields our own matching couldn't. Free of charge to you; you can turn this off anytime in Settings. |
| AI Assist (optional, credit-metered) | The receipt photo itself, only when you tap "AI Assist" | Sent to a third-party AI service provider to read messy or handwritten receipts and split out line items |
| Merchant categorization | Merchant name and, if present, line items | To suggest the right expense category |
| Reconciliation (optional, credit-metered) | For the specific month or year of receipts you choose to check — merchant, date, amounts, category, line items, any Notes text you've typed on those receipts, and (for manually-entered mileage) odometer readings. Never receipt photos. | Only runs when you manually tap "Reconcile" and pick a batch of receipts — nothing is checked automatically in the background. Sent to a third-party AI service provider to flag likely duplicate receipts, unusual amounts, and mileage log inconsistencies within that batch. Costs AI credits. |
| Spending estimates | How many receipts you've scanned per category, per month — counts only | To forecast your scanning pace on the Estimates card. Never merchant names, amounts, or images. |
| Usage quality tracking | Which method finalized a receipt (automatic, AI-assisted, or manual) and which fields you edited | To improve scan accuracy over time. Never the receipt content itself. |
| Purchases | The purchase token or transaction ID issued by Apple/Google when you unlock the app | Verified against Apple/Google to confirm a genuine purchase |
| Referrals | Your pseudonymous install identifier, your generated referral code, any code you redeem, referral status, and resulting credit balance | To validate referral codes, prevent self-referrals and duplicate redemption, and award AI credits to eligible installs |
| Device attestation | A token generated by Google Play Integrity (Android) or Apple DeviceCheck (iOS) | Confirms requests come from a genuine copy of the app on a genuine device, so free-tier limits can't be trivially bypassed |
Cloud backup (optional)
Gigspend can copy your local receipt data to storage in your own iCloud or Google Drive account so you can recover it after losing or replacing a device. Backup files travel directly between the app and your selected cloud-storage provider; Gigspend does not copy them into its own database.
- On iPhone — if iCloud is available for Gigspend, backup uses the private app container in the iCloud account already signed in on the device. There is no separate Gigspend or Google-style sign-in. You can disable iCloud access for Gigspend in iOS Settings.
- On Android — backup is off until you tap “Connect Google Drive” and complete Google's consent screen. Gigspend requests the limited
drive.filepermission, which allows the app to create, read, update, and delete only the Drive files it creates or that you explicitly open with it; it does not provide general access to your existing Drive files. Disconnecting signs the app out and stops future automatic backups, but does not delete backup files already stored in Drive. - When automatic backup runs — after a relevant change, such as approving or editing a receipt or changing supported settings, the app waits briefly so a group of edits can be saved together and then uploads the latest backup. If the app closes before a pending backup finishes, it retries when the app next becomes active. You can also tap “Back up now” and view the last successful backup time and storage used.
- What's included — receipt records, dates, merchants, amounts, categories, Notes, manual mileage information, line items, receipt photos, deduction settings, merchant lookup cache, and selected local app preferences needed for restore. The structured data is stored in a backup file and receipt photos are stored alongside it.
- What's excluded — exported Excel, PDF, and Receipt Book files; your device identifier; session and cloud-access tokens; purchase-verification tokens; unlock status; free-scan usage; and AI credit balances. Server-derived purchase and credit status is checked separately after restore.
- Restore behavior — Gigspend checks for an available cloud backup and asks before restoring it. A confirmed restore replaces the receipts and other backed-up local data currently on that device with the selected backup, then downloads the associated receipt photos. The app does not silently merge two receipt databases. Review the backup date before confirming a restore.
- Deleting a cloud backup — “Clear iCloud backup” or “Clear Drive backup” deletes the backup data file and uploaded receipt photos from that cloud location without deleting receipts on the current device. Simply disconnecting Google Drive does not delete the existing backup. You may also manage stored files through Apple or Google where their service permits.
- Manual backup file — you can create a ZIP file containing the backup data and available receipt photos, then save or share it using your device's share sheet. Gigspend does not control the apps, people, or storage locations you choose. Restoring from a file replaces the same categories of local data, so keep backup files secure because they can contain receipt details and images.
Who we share data with
- AI service providers — the provider selected to process a request receives the receipt photo when you use AI Assist, recognized receipt text when automatic OCR help runs, or selected receipt details (including Notes) when you use Reconciliation. We may change providers based on availability, quality, cost, or security. We send this data to obtain the requested processing, not for advertising. If our data-handling practices materially change, we will update this policy.
- Apple and Google — separately, receive device-attestation and purchase-verification tokens generated by their own SDKs (a different Google service than the AI features above), used only to confirm your device and purchases are genuine.
- Cloud and infrastructure providers — Supabase stores pseudonymous install, purchase, credit, referral, and limited usage-quality records. Amazon Web Services hosts APIs, configuration, abuse-prevention counters, and operational logs. Cloudflare routes and protects requests and temporarily stores AI Assist and Reconciliation results for up to 24 hours.
- Your cloud-storage provider — Apple iCloud or Google Drive receives backup data only when that platform's backup feature is enabled. The backup is stored in your own account, not in Gigspend’s database.
We don't sell your data, and we don't share it with data brokers or advertisers. Gigspend has no ad integrations.
How long we keep things
- Your install, purchase, credit, and referral records — retained while needed to provide unlocks and credits, restore purchases, enforce limits, process refunds, prevent fraud and duplicate referral claims, and meet legal or accounting obligations. Uninstalling stops new app activity but does not automatically delete these server records.
- AI Assist results — if you use AI Assist, the extracted result (merchant, date, items, totals) is cached for 24 hours so you're not double-charged a credit if you back out and reopen a pending scan. It's automatically deleted after 24 hours.
- Reconciliation results — if you use the optional Reconciliation feature, the duplicate/anomaly findings are cached for up to 24 hours only so the app can recover the response if network delivery is interrupted or fails. The cache is not a user-accessible history and cannot be browsed or downloaded; it is automatically deleted after 24 hours.
- Operational and abuse-prevention data — server and edge logs may include timestamps, IP address, request path, request outcome, diagnostic details, and limited OCR-derived or merchant values needed to troubleshoot processing. Rate-limit records contain a pseudonymous identifier, endpoint, count, and automatic expiration time. These records are used to operate, secure, and debug the service, not for advertising.
- Cloud backup data — stored in your own iCloud or Google Drive account, not ours, and kept until you remove it. Use Gigspend’s separate “Clear backup” action to delete the backup data file and uploaded receipt photos. Disconnecting Google Drive alone stops access and future backups but does not delete the stored copy.
How we protect data
Data sent between the app and our services is encrypted in transit using HTTPS. Access to production systems and service credentials is restricted, purchase and integrity tokens are verified with Apple or Google, and server-side controls are used to authenticate requests and limit abuse. No system can be guaranteed completely secure, but we use safeguards appropriate to the data and services involved.
Your choices
You can turn automatic OCR-text AI help off in Settings; use standard scanning instead of the optional photo-based AI Assist; and choose not to run Reconciliation. Reconciliation runs only when you select a batch and start it. On Android, Google Drive backup is off until you connect it and can be disconnected from Backup & Restore. On iPhone, backup follows your device's iCloud settings and can be disabled in iOS Settings. You can delete local app data by removing receipts or uninstalling the app, and you can manage backup files through the app or your cloud-storage provider.
To ask about, access, or request deletion of server-side records associated with your installation, contact support@gigspend.app. Because there is no login or contact profile, we may need information available in the app to locate the correct pseudonymous record. We may retain limited purchase, transaction, security, or fraud-prevention records where required or permitted by law.
Children's Privacy
Gigspend is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can address the issue.
Changes to this policy
If this policy changes, we'll update the date at the top of this page.
Contact
Questions about this policy or your data? Email support@gigspend.app.