VPCVPC Receipt Assistant

Privacy policy

Effective 6 October 2026

This policy describes how VPC Receipt Assistant, maintained by Matt Hunt for authorised Vantage Point Church cardholders, handles information. Contact emailmatthunt@gmail.com with privacy questions or requests.

Information the app processes

Google account access

Google OAuth provides permission to identify the connected email account and send Gmail messages. The app uses that email address to verify the sender. It stores OAuth credentials on the server so it can send receipts after the user confirms a submission. It does not collect Google passwords or request inbox-reading permission.

VPC Receipt Assistant’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

How information is used and shared

Receipt images and descriptions are processed using the OpenAI API to extract and structure receipt details. Depending on browser support, voice input is transcribed by the device/browser speech service or sent to the OpenAI API for transcription. Google OAuth tokens are not sent to the AI provider.

When the user taps Send Receipt, the receipt summary and original image are transmitted through Gmail to the configured accounts intake address, currently a Xero Files inbox. Google and Xero process those messages under their own policies. Hosting, private file storage and the database are provided through OpenAI Sites and its infrastructure providers, including Cloudflare.

Information is used for receipt processing, sending, history, support and troubleshooting. It is not sold or used for advertising. Google user data is not used to train general-purpose AI models.

Storage and access

Receipt images and submission records are stored in private application storage and protected by authentication. Authorised users sharing the same application login can see that login’s receipt history. Choosing a cardholder profile does not create a separate security boundary. OAuth credentials are stored as server-side secrets.

Retention and deletion

Submission records and images remain available for accounting reference until removed by the administrator; automatic expiry is not currently configured. Contact the address above to request deletion of app-held data or disconnection of a mailbox. Accounting records may need to be retained by the church. Copies already sent to Gmail, Xero or accounts are managed separately by those services and their account holders.

You can also revoke Google access from your Google Account connections. Revoking access stops future authorised Gmail operations but does not delete previously submitted receipts.

International processing and changes

Service providers may process data outside Australia. This policy will be updated when the app’s data practices materially change. Avoid including unrelated personal or sensitive information on uploaded receipts or in spoken descriptions.