How Slip handles your receipts

Slip reads records of what you spent. That is sensitive, so here is what we store, where it sits, and who can reach it. If a line below is unclear, write to security@slip.app and we will fix the wording.

How Slip handles your receipts

Slip reads records of what you spent. That is sensitive, so here is what we store, where it sits, and who can reach it. If a line below is unclear, write to security@slip.app and we will fix the wording.

Encrypted on disk and on the wire

Receipt images and the data read out of them are encrypted with AES-256. Keys live in a managed KMS and rotate every 90 days. The apps and the web app talk to us over TLS 1.3 only; older versions are refused rather than downgraded, and certificates are pinned in the mobile builds.

AES-256 at rest · TLS 1.3 in transit · keys rotate 90d

What actually leaves your phone

The photo goes up, because the model that reads a receipt runs on our servers rather than on the device. Nothing else rides along. No contacts, no location, no advertising identifier, and no analytics SDK reporting to someone else’s dashboard.

Zero third-party ad SDKs · no IDFA, no GAID

We do not sell your data

Not raw, not aggregated, not anonymised. No brokers, no spending panels, no research partners, and no revenue line at Slip Labs that depends on your receipts going anywhere. What people pay each month is the whole business, which is the only reason we can say this plainly.

No brokers · no panels · no resale of any kind

Who inside the company can look

Production access sits with 4 named engineers, granted through credentials that expire after 8 hours. Opening a customer’s receipt requires a support ticket from that customer, and every read is written to an append-only log with a name against it. That log is reviewed on the first Monday of the month.

4 named engineers · 8h credentials · append-only audit log

The companies we depend on

Hosting is AWS in eu-central-1, Frankfurt. Subscriptions run through Stripe, which is why we never see your card number. Crash reports go to Sentry with personal fields stripped before they leave the device. That is the whole list; when it changes, this page changes with it and subscribers get an email.

AWS eu-central-1 · Stripe · Sentry · 3 processors total

Deletion is real deletion

Delete a receipt and it leaves the live database at once, and the backups within 35 days. Close the account and everything under it goes the same way, images included. We keep no shadow copy for training, and receipts older than 7 years are deleted whether you ask or not.

Live: immediate · backups: 35d · hard cap: 7y

What we hold, and for how long

Data

Why we have it

Kept for

Receipt images

So the reader can extract the lines

Until you delete it

Merchant, amount, date, category

This is the record you came for

7 years

Mail sent to your forwarding address

To file what you forward by email

30 days

Email address

Sign-in and account recovery

Until the account closes

Device model and app version

To reproduce a crash on the right build

90 days

Billing records

Portuguese tax law requires them

10 years

If you find a way in

Send it to security@slip.app with steps we can follow. A person reads that inbox every working day, and you will hear back from a named engineer within 2 business days, including when the answer is that we already knew. Hold off publishing for 90 days and we will keep you posted on the fix, and credit you if you want the credit. There is no paid bounty yet, and nobody who reports in good faith will hear from a lawyer.

Create a free website with Framer, the website builder loved by startups, designers and agencies.