Privacy
Last updated: July 21, 2026. Written in plain language on purpose; if anything here is unclear, email hello@sortedreceipts.com.
What we hold
Documents you or your clients upload (receipts, invoices, statements), the sorting data extracted from them (vendor, date, amount, type), your email address, and standard technical logs. That's the list.
What we do with documents
Documents are processed once to sort them: the file is sent to the configured large-language-model API, the extracted fields come back, and the original is stored in private encrypted-at-rest object storage. Pilot metadata is held in an encrypted database. Documents are never sold or used to train Sorted Receipts models.
Client upload links
Each client link is an unguessable private URL with an expiry. Anyone with the link can upload; the dashboard is restricted to the founder during this pilot. A link can be revoked and reissued at any time.
Leaving
When you stop using Sorted Receipts, you choose: export everything (CSV + all originals) or delete everything. Deletion is completed within 14 days. Founder recovery exports are encrypted and automatically removed after their short retention window.
Analytics
Every page uses PostHog Cloud EU for product analytics, error tracking, performance diagnostics, and session replay. This includes the marketing site, public demo, private app, and client portals. Replays may include page text, form inputs, filenames, receipt results, correction rules, URLs, console output, and network request or response details so we can reproduce bugs and fix failed workflows.
The browser integration does not set PostHog cookies. It stores its visitor and session identifiers in local browser storage, sends data through our first-party analytics endpoint to PostHog's EU service, and is not used for advertising.
Pilots
During a pilot, the founder operates the ingest and may see pilot documents; the pilot brief states this in writing before any file moves.