1. Permissions We Require
ExpenseBot requires the following permissions from your Google Account to function effectively:
Gmail (Read and Modify): Gmail integration is optional. These permissions are requested only after you choose to connect Gmail. Depending on the feature you select, ExpenseBot may scan messages you label, recent messages found by daily automation, or messages in a historical date range you request. We use three specific Gmail scopes:
2. Gmail API Integration
ExpenseBot uses Gmail API integration to:
3. Financial Account Integration (Plaid)
ExpenseBot uses Plaid to securely connect to your financial accounts for automated expense tracking:
4. How We Use Your Data
We use your data solely to provide and support our service. Our AI processes receipt photos and relevant financial messages to identify documents, extract information, and classify records. Files and message content are processed transiently and are not retained as a permanent copy on our servers. Your source documents and spreadsheets remain in your Google Drive under your control.
Email Data: Gmail integration is completely optional. After you connect Gmail, ExpenseBot processes messages only through the scan modes you choose: a manual or label-based scan, a historical date range, or daily automation you enable. Candidate selection may use sender, subject, attachment, link, and message-body signals. Ambiguous candidates may be evaluated by Google Gemini before a financial record is created. We do not permanently store email content or use it for advertising.
Financial Data: When you connect your bank accounts, we use the transaction data to automatically identify expenses, categorize them, and sync them with your expense tracking spreadsheet. We only store minimal transaction metadata necessary to prevent duplicate processing and maintain sync status. Your full transaction details are stored in your Google Sheets, under your control.
5. Data Storage and Security
ExpenseBot does not retain a permanent copy of your receipt photos, source documents, or email content on our servers. Your source documents and Google Sheets records remain securely stored in your Google Drive, where you have full control. We retain limited account, processing, lineage, security, and billing metadata needed to operate the service. We use encrypted transmission during processing.
Email Data: We do not permanently store email content on our servers. We only store minimal metadata about processed emails (such as reference IDs) to prevent duplicate processing. Email content is processed transiently and then immediately deleted after processing is complete.
Processing and storage regions:
6. Information We Collect
ExpenseBot collects and stores minimal information necessary to provide and improve our service. Specifically, we store:
7. Data Sharing, Disclosure, and Transfer
We do not sell your personal information. We share or disclose data only as described below:
With Service Providers: We disclose data only as necessary to providers that operate parts of ExpenseBot, including Google services (such as Gmail, Google Photos, Google Drive, Google Cloud, Gemini, and Vision), Vercel for web and API hosting, Twilio SendGrid for transactional email, Stripe for payments, Plaid for optional financial connections, and Google Analytics, Microsoft Clarity, and LinkedIn for product and acquisition analytics. If you connect an accounting or automation platform, we send only the data needed to perform the sync or action you request. These providers process data under their own service terms and data-protection commitments.
International Transfers: ExpenseBot is operated from Canada and uses providers and infrastructure in Canada, the United States, and other locations where those providers operate. For UK and EEA personal data, our Google Cloud and Vercel service terms include contractual transfer safeguards, including applicable standard contractual clauses and UK transfer terms. You can review the Google Cloud Data Processing Addendum and the Vercel Data Processing Addendum. Contact us at the address below if you need information about the safeguards that apply to a particular service before deployment.
For Legal Reasons: We may share your information to comply with legal obligations, such as in response to a legal request or to enforce our legal rights.
Business Transfers: If ExpenseBot is involved in a merger, acquisition, or sale of assets, the minimal data we collect (such as your email, profile information, and subscription data) may be transferred as part of that transaction to ensure continuity of service. In such cases, we will obtain your explicit consent before transferring any Gmail data.
8. Data Deletion and Reset
You can disconnect integrations or request account deletion at any time. ExpenseBot's reset and deletion tools explain which application records and Google Drive items will be removed before you confirm the action. Billing or one-time purchase records may be retained when required for accounting, fraud prevention, or legal compliance.
Email Data: Since we do not permanently store email content on our servers, there is no permanent mailbox copy to delete. We retain limited operational metadata, such as Gmail message IDs, scan status, timestamps, and processing outcomes, to prevent duplicate records, resume scans, diagnose failures, and provide an audit trail.
Gmail Authorization Revocation: You can revoke ExpenseBot's access to your Gmail account at any time through your Google Account settings. You can also disable daily scanning without disconnecting the account.
9. Third-Party Services
ExpenseBot integrates with third-party services such as Gmail, Google Photos, Google Drive, Plaid, and Stripe, which are governed by their own privacy policies. We use Google Vision and Google Gemini to analyze documents and relevant financial messages as part of the service. ExpenseBot does not use Google Workspace data to train a generalized AI model.
10. Google Workspace API Compliance
ExpenseBot does not use data obtained from Google Workspace APIs to develop, improve, or train generalized AI or machine-learning models. All data from Google Workspace APIs, including Gmail, Google Photos and Google Drive, is used solely to provide and support our service to you. We fully comply with Google's "Limitation on User Data Transfer" policy, which prohibits the use of Workspace user data to train non-personalized AI or ML models.
Our use of Gmail API services adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request only the minimum necessary Gmail API scopes required to provide our service functionality.
11. Legal Bases and Privacy Rights
We process personal information as needed to provide the service you request and perform our contract with you; to secure, support, and improve the service where we have a legitimate interest; to meet legal, tax, fraud-prevention, and accounting obligations; and with consent where applicable law requires it.
Depending on where you live and the processing involved, you may have rights to request access, correction, deletion, restriction, objection, or portability of your personal information, and to withdraw consent where processing relies on consent. These rights are not absolute and may be limited by applicable law. Send requests to info@expensebot.ai. UK users may also complain to the Information Commissioner's Office.
12. Data Retention
We keep account, integration, and operational metadata while your account is active and for as long as needed to provide, secure, and support the service. Gmail message references, scan outcomes, and lineage records are retained only as long as needed for duplicate prevention, recovery, diagnostics, and auditability. Temporary source documents are removed after processing. Billing, fraud-prevention, security, and legal records may be kept longer where required by law or reasonably necessary to establish or defend legal claims. When you request deletion, we remove eligible application data and disconnect integrations, subject to those limited obligations. Files already in your Google Drive remain under your control unless the confirmed deletion flow says they will also be removed.
13. Changes to Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the effective date. You are advised to review this Privacy Policy periodically for any changes.
14. Contact Information
ExpenseBot is operated by J2Play Ltd. in Toronto, Ontario, Canada.
Email: info@expensebot.ai
15. Effective Date
This Privacy Policy is effective as of August 22, 2026.