Privacy policy

This policy explains what Slip collects, why we hold it, and how long we keep it. It covers the iOS app, the Android app, the web app, and the address you forward receipts to.

Privacy policy

This policy explains what Slip collects, why we hold it, and how long we keep it. It covers the iOS app, the Android app, the web app, and the address you forward receipts to.

What we collect

Account data: your email address, the passkey or password you set, your country, your currency, and the devices you have signed in on. If you subscribe on the web, our payment processor collects your card details — we see the last four digits, the card type, and the billing country, never the full number.

Receipt data: the images, PDFs and emails you send us, and the text we read out of them. That text usually includes the merchant name, the date, the line items, the amounts, the tax, and the payment method shown on the document — for example “EUR 41.20” on “12 Aug 2026”.

Technical data: app version, operating system version, device model, IP address at the time of a request, crash reports, and a record of when a receipt was processed and how long it took. We do not collect your contacts, your location, or your photo library beyond the specific images you choose to send.

How we use it

We use your receipt data to do the one job Slip has: read a document, pull out the merchant, date and amount, put it in a category, and make it findable. We use account data to sign you in, sync between your phone and the web, and bill you if you are on Slip Plus.

We use technical data to fix crashes, find slow parts, and see when our reader is failing on a particular merchant format so we can improve it. Aggregate accuracy numbers — how often a category was corrected by hand, across everyone — guide what we work on next.

We do not sell your data. We do not share it with advertisers, data brokers or credit agencies. We do not build a profile of you to sell to anyone, and your receipt content is never used to train a general-purpose model.

Receipt content

When you send an image, it is processed to extract text. A model reads the picture and returns the characters on it, then a second step identifies which of those characters are the merchant, the date, the total, and the individual lines. From that point on, it is the extracted text — not the image — that powers categorisation, search, totals and export.

The image is kept so you can look at the original when a number seems wrong, and so we can re-read it if we improve the reader. You can delete an image and keep its extracted text: in Settings, turn on Discard images after reading, and every new receipt is read and then the picture is removed within 24 hours.

Receipt processing runs on our servers in the EU. For some document types we use a specialist text-recognition provider under contract, listed in the section below. That provider receives the image, returns the text, and is contractually barred from keeping it or using it for anything else.

Sharing and processors

We share data only with companies that help us run Slip, each under a data processing agreement, each limited to what they need. Today that is: Amazon Web Services in Ireland for storage and compute, Google Cloud in Belgium for text recognition, Postmark for transactional email, Stripe for web payments, and Sentry for crash reports.

Apple and Google handle in-app subscriptions and tell us only that a subscription is active, when it renews, and which plan it is. They do not pass us payment details.

We publish the current list at slip.app/processors and update it before a new processor starts, not after. If we are ever legally compelled to hand over data, we will tell you unless the order forbids it.

International transfers

Your receipts, their extracted text, and your account record are stored in the European Union. Our primary region is eu-west-1 in Ireland, with backups in eu-central-1 in Germany.

A small amount of data leaves the EU. Crash reports and support conversations may be processed in the United States by Sentry and by our helpdesk provider. Those transfers rely on the EU–US Data Privacy Framework where the company is certified, and on Standard Contractual Clauses where it is not, with encryption in transit and at rest in both cases.

We do not transfer receipt images or extracted receipt text outside the EU.

Retention

On Slip Plus, receipts and their extracted text are kept while your account is open, up to a maximum of seven years. Receipts older than seven years are deleted automatically. On the free tier, anything past 60 days is locked for reading and export only, and may be removed 90 days after that.

When you delete a single receipt, it leaves the app immediately and leaves our storage within 30 days. When you delete your account, receipts, extracted text and account data are removed within 30 days, and backups holding them expire within 90 days.

Two things outlive that. Invoices and payment records are kept for ten years because tax law requires it. Security logs — sign-ins, failed sign-ins, IP addresses — are kept for 90 days.

Your rights

You can ask for a copy of your data, correct it, delete it, restrict how we use it, object to processing based on legitimate interest, or take it elsewhere in a machine-readable form. Export in Settings gives you CSV and JSON immediately, with the original images, and needs no request to us at all.

For anything the app cannot do itself, write to hello@slip.app. We answer within 30 days, and usually within a few days. We will not charge you, and we will not ask why.

If you think we have handled your data badly, tell us first — it is normally the quickest fix. You also have the right to complain to the Comissão Nacional de Proteção de Dados in Portugal, or to the data protection authority where you live.

Cookies and analytics

The web app sets one strictly necessary cookie to keep you signed in and one to remember your language. Neither tracks you across sites, and neither needs your consent.

Product analytics is off until you turn it on. If you do, we record which screens are opened and which actions succeed or fail, tied to a random identifier rather than your email, and we keep it for 12 months. We use a self-hosted instance, so those events do not leave our infrastructure.

There are no advertising cookies, no third-party trackers, and no pixels on slip.app or in the apps. The marketing site counts page views without a cookie and without storing an IP address.

Children

Slip is for people aged 16 and over. We do not knowingly collect data from anyone younger, and we do not build features aimed at children.

If you believe a child has created an account, write to hello@slip.app. We will close it and delete the data, and we will confirm to you when that is done.

Changes

When this policy changes we update the date at the top and keep the previous versions at slip.app/privacy/archive, so you can see exactly what moved.

For a change that affects what we collect, why we collect it, or who we share it with, we email every account holder at least 30 days before it takes effect. Corrections that do not change our practices — a clearer sentence, a renamed processor — take effect when published.

Contact

Slip Labs, Lda is the data controller. Write to hello@slip.app for a request about your data, or to our data protection contact at privacy@slip.app. Security researchers should use security@slip.app.

Slip Labs, Lda. Rua da Boavista 84, 1200-069 Lisboa, Portugal. Telephone +351 300 600 900. We do not take data requests by phone, because we cannot check who is calling. Press enquiries go to press@slip.app.

Create a free website with Framer, the website builder loved by startups, designers and agencies.