DropSheet / Where receipt apps send your data

Where receipt scanning apps actually send your data

A receipt is not a blank slip. It can name a pharmacy, a bar, a lawyer, a clinic. It often prints the last four of a card. If an app reads that photo on a server, a copy of that slip left your phone. This page records what each company publishes about that copy.

Every claim below is from that company’s own privacy policy, terms, security page, DPA, or subprocessor list, accessed 3 September 2026. Review sites and blogs are not used. Where a company does not publish an answer, this page says not stated. Policies change. The links are the source.

Comparison

Short answers only. Detail and quotes sit under each name.

AppImage uploaded?Who does the OCR?How long kept?Can you delete it?Training / sharing
ExpensifyYesNot stated in published policyWhile the account is activeYes. Backups not statedPersonal data not sold, with a California caveat
ShoeboxedYesNot statedWhile the account is activeYes. Two published figures differAnalytics yes. Training not stated
DextYesGoogle Cloud, namedThrough the licence, then deletionYes. 10-day return windowThird-party genAI not allowed to train. AWS Bedrock listed
Zoho ExpenseYesNot stated in published policyUntil the account ends, then staged deleteYes. Active DB then backupsStaff may verify OCR images
WaveYes, as account documentsNot statedAs allowed or required by lawNot statedNot stated
VeryfiYesIn-house, statedWhile you use the serviceYes. Says deleted foreverTrains its own models, with opt-out. Says it does not sell
QuickBooksImage itself not namedNot namedAs long as needed for the serviceYes. Some copies may remainTrains AI on customer content. Does not sell under CCPA
DropSheetNoThis browserNot storedNothing to delete on a serverNo. There is no copy

Expensify

Privacy policy last updated 1 April 2026. Subprocessor list accessed 3 September 2026; that list has no date on the page.

  1. Yes. The subprocessor list says AWS holds “Receipt images and encrypted long term storage of all data.”
  2. Not stated in published policy.
  3. “We will retain your information for as long as your account is active or as needed to provide you services.” A separate line covers legal obligations, disputes, and agreements. How long a receipt image sits after you close a report is not stated.
  4. Yes. “we will delete or otherwise destroy your Personal Data as soon as practicably possible following your termination or cancellation of your use of the Expensify Service.” Backups are not stated.
  5. Aggregated or de-identified data “may also [be] share[d] … with any third parties, including advertisers.” On personal data: “we do not sell, trade, share, or rent the Personal Data collected from the Expensify Service to third parties,” with a later California/Colorado/Connecticut note that some online identifiers and network activity “may have [been] sold.” Receipt images are not named in that sale list.

Sources: Expensify privacy policy; Expensify subprocessors. Accessed 3 September 2026.

Shoeboxed

Privacy policy has no last-updated date on the page. GDPR page has no last-updated date on the page. Both accessed 3 September 2026.

  1. Yes. The policy lists “User-submitted receipts, business cards, and other documents” among information collected.
  2. Not stated. No OCR vendor is named. The policy says employees, consultants, and contracted workers “may use or come into contact with user information during the course of their normal working duties.” It does not say whether a person or a machine reads the image.
  3. “We will retain your information for as long as your account is active or as needed to provide you services,” plus legal obligations, disputes, and agreements.
  4. Yes. Two published pages give different clocks. The privacy policy says that after a deletion request, “we delete your raw data from our databases and applications within 6 months.” “However, your data might still be kept in our backup files (not accessible to non-Shoeboxed personnel) for up to three years.” The GDPR page says: “When a user deletes their account, Shoeboxed deletes their raw data within 90 days.” “Document data may still be kept in backup files for up to one year (these backups are not accessible by any non-Shoeboxed personnel). These backups are done on a rolling window and are deleted after a year.” “Account data may still be kept in backup files for up to three years (these backups are not accessible by any non-Shoeboxed personnel), for audit purposes.” The two published figures differ. This page does not pick one.
  5. Training on receipts is not stated. Analytics are: cookies, beacons, tags, and scripts “to analyze trends” with marketing partners and analytics providers. Selling receipt data is not stated.

Sources: Shoeboxed privacy policy; Shoeboxed GDPR. Accessed 3 September 2026.

Dext

Privacy policy last updated 19 July 2024, effective 31 July 2024. Data Processor Agreement last updated 18 February 2025.

Dext splits the pile. Account contact data is covered by the privacy policy. Receipts and invoices you upload are treated as your data, with Dext as processor:

“This privacy policy shall not apply to any personal data contained in documents (such as invoices or receipts) uploaded to the Dext platform by you or on your behalf. Any such personal data will be held by us as your data processor.”
  1. Yes. Documents are uploaded to the Dext platform.
  2. Named third party. The DPA subprocessor table lists Google Cloud: “This is used for our OCR data extraction service and Product AI functionality.” AWS is listed for storage and for AWS Bedrock. Microsoft Azure (Open AI) is listed as a generative AI tool provider.
  3. Processing lasts for the licence term plus the period until deletion under the privacy policy’s retention rules. Uploaded document contents are not given a separate numbered year count in the DPA.
  4. Yes. After the agreement ends, the default instruction is deletion. You have 10 days to ask for the data back. Lawful retention is an exception, and Dext says it will notify you of that requirement.
  5. The privacy policy is clear on third-party generative AI: “we do not allow any third-party generative AI tool providers which we use in our services to train their models using your data (including personal).” That is a published limit. The same DPA still lists AWS Bedrock as “a large language model hosting/ training provider” used to provide the service. What “training” means for Bedrock versus the third-party ban is not explained. Analytics providers such as Google are named for Technical Data about the account, not specifically for receipt images.

Sources: Dext privacy policy; Dext Data Processor Agreement. Accessed 3 September 2026.

Zoho Expense

Zoho group privacy policy last updated 22 December 2025. Subprocessor directory dated 25 August 2026.

  1. Yes. The privacy policy refers to “scanned images that you submit to us.”
  2. Not stated in published policy. The group privacy policy says Zoho staff and contractors may “manually verify scanned images that you submit to us to verify the accuracy of optical character recognition.” That is a published human review of submitted images. Who runs the OCR itself is not named.
  3. “We hold the data in your account as long as you choose to use Zoho Services.” After you terminate the account, “your data will eventually get deleted from active database during the next clean-up that occurs once in 6 months. The data deleted from active database will be deleted from backups after 3 months.”
  4. Yes. You can request deletion of service data. The six-month then three-month clock above is the published schedule after termination. That is more specific than most of this list.
  5. Manual OCR verification is published, as quoted. Selling receipt data is not stated in the passages reviewed. Training of third-party models on those receipts is not stated in the Zoho policy text reviewed.

Sources: Zoho privacy policy; Zoho service-specific subprocessors. Accessed 3 September 2026.

Wave

Privacy policy effective 10 January 2025. Subscription terms for the “receipt scan feature” effective 8 July 2024 / 4 November 2024. The privacy page is a JavaScript app; the full body did not render as static HTML when fetched on 3 September 2026. The sentences below are from that same URL as indexed. A public subprocessor list was not found.

  1. Yes, as documents on the account. Indexed policy text: “When you add documents to your Wave account.” Receipt scan is a named paid feature in the subscription terms.
  2. Not stated. No OCR vendor is named on the pages reviewed.
  3. Indexed policy text: “We may retain your Wave documents as allowed or required by law.” No numbered year is given.
  4. Not stated in the text retrieved.
  5. Not stated in the text retrieved. No training or sale sentence about receipts was found on the published pages that loaded.

Sources: Wave privacy policy; Wave paid subscription terms. Accessed 3 September 2026.

Veryfi

Privacy policy last updated 10 July 2026. Subprocessor list last updated 24 August 2026. Veryfi publishes more about OCR than the rest of this list.

  1. Yes. “Veryfi provides subscribers an unlimited cloud service for storage of financial documents in the form of photos, pdfs, and metadata.”
  2. In-house, stated. “Veryfi is 100% machine powered end-to-end. We do not use humans or data extraction teams to extract or categorize your data.” “Veryfi develops and trains its own models in-house. We do not use your data to train third-party or “generative” AI models.” The subprocessor list names AWS for cloud hosting, not an outside OCR vendor.
  3. “Veryfi only stores the data it needs to function properly — for as long as you want Veryfi to function for you.” A numbered year is not given.
  4. Yes, and the wording is unusually direct: “Everything you (the customer) delete from your account using Veryfi interfaces is deleted forever.” “Deleting your account permanently removes all your data you ever stored with Veryfi.” Backups of deleted files are not mentioned.
  5. Training of Veryfi’s own models is published: “we may use data you submit, which can include personal data contained in your documents, to train, validate, and improve our proprietary machine learning models.” Opt-out “relate[s] to the use of your data for ongoing model training/improvement, not to the extraction service you request.” Sharing: “We never sell or share your data with anyone.”

Sources: Veryfi privacy policy; Veryfi subprocessors. Accessed 3 September 2026.

QuickBooks (Intuit)

Intuit Global Privacy Statement last updated 9 March 2026. No public named subprocessor list for receipt OCR was found.

  1. The image itself is not named. The statement says Intuit may receive “information about your business, your finances, expenses, invoices, financial statements, details of your financial transactions.” Whether the receipt photograph is stored as a file is not stated in that document.
  2. Not named. Service providers “also include AI providers, including generative AI providers.” No vendor is named for receipt OCR.
  3. “Unless you specifically ask us to delete your personal information, we retain your personal information as long as it is necessary to … provide you with services.” Different information may be kept for different periods.
  4. Yes, through account settings or the Intuit Privacy Center. The same statement says there may be occasions “where we are unable to fully delete, anonymize, or de-identify your personal information due to technical, legal, regulatory compliance, or other operational reasons,” in which case Intuit says it will isolate the data until it can.
  5. Training is published: Intuit may use personal information for “training our artificial intelligence models and other machine learning models, as well as by assessing … certain content our customers send or display through the Platform.” Google Workspace API data is carved out of generalized model training. On sale: “Intuit and Mailchimp do not sell Personal Information under the CCPA.”

Source: Intuit Global Privacy Statement. Accessed 3 September 2026.

DropSheet

Same five questions. Source is this site’s privacy page, accessed 3 September 2026.

  1. No. “Photos, PDFs, and pasted email text are read in Chrome, Edge, or Safari. They are not posted to a server.”
  2. This browser. “This site does not load Google Fonts. The English reading files are hosted here. Your receipt is not in that request.” There is no OCR API call with the photo.
  3. Not stored. “There is no DropSheet account and no receipt database. The rows live in this tab until you export or close it.”
  4. There is nothing to delete on a DropSheet server. Close the tab, or export and keep the file you chose. The Gumroad license lives in this browser and can be cleared from the Unlocked control.
  5. No copy, so no training set and no sharing of the shoebox. Buying is on Gumroad. Gumroad sees the payment, not the receipts.

Source: DropSheet privacy. Accessed 3 September 2026.

Method

Read on 3 September 2026. For each name: the company’s privacy policy, then any public subprocessor list, DPA, or security page linked from it. Claims are quoted or paraphrased from those pages only. “Not stated” means the published document did not answer the question, not that the practice does not exist. Subprocessor lists change. If a later policy disagrees with a sentence here, the later policy wins.

DropSheet reads receipts in your browser. Nothing is uploaded. getdropsheet.com.

Mike Printz · mjprintz1@gmail.com