Security

You are handing an app a picture of everything you spend money on. It is fair to ask where that goes. This page describes how CabSnap handles it, including the parts we cannot guarantee.

In transit and at rest

Traffic between the app and our servers uses HTTPS/TLS. Stored data sits behind provider-managed encryption at rest, access controls, and operational logging.

No system is perfectly secure, and we would rather you read that here than infer it later.

Card details are redacted before anything is uploaded

Before a receipt image leaves your phone for sync or AI processing, CabSnap runs on-device redaction that looks for payment card numbers, CVV/CVC codes, and expiration dates, and covers them. Our server then runs its own safety check and rejects an uploaded image that still appears to contain payment card data.

Redaction is best-effort. It is not guaranteed. Detection can miss things — poor lighting, glare, blur, low contrast, creased paper, unusual card layouts, handwriting, partial obstruction, skewed angles, and low-resolution photos all make it harder. Review a photo before you confirm it, and cover anything you do not want processed. Do not deliberately photograph card numbers, CVV/CVC codes, passwords, government IDs, or medical information.

Where synced images live

Redacted receipt images sync to a private cloud storage bucket that requires authenticated access. When another device you are signed in on displays a synced receipt, it downloads that image using your own authenticated session.

Originals stay on your device

The un-redacted original stays on the phone that captured it, so your own copy of the record stays complete. Backing originals up to the cloud is a separate, opt-in feature and is off by default. If you turn it on, originals go to a private bucket that also requires authenticated access, and you can delete those cloud originals or turn the feature back off at any time.

Original images are never used for AI processing. Only the redacted copy is.

AI processing

On paid plans, redacted receipt images and receipt fields may be sent to a third-party AI provider to extract the merchant, date, and total. Our AI providers are currently Anthropic and Google.

Your receipt images are not used to train third-party AI models. If we materially change the providers we use, we will update the privacy policy to say so.

Who else is involved

Our core service providers are Supabase and Google Play. Supabase covers hosting, authentication, database, and storage; Google Play handles app distribution and subscription billing. We never receive your full payment card number from Google Play.

Leaving, and taking your records with you

You can delete your account from inside the app. Doing so deletes account-linked receipt records and stored receipt files from our active systems, signs you out, and wipes local CabSnap receipt data on that device once the server confirms the deletion.

You can export your data from Settings, and you should do that before deleting your account, deleting the app, or replacing your phone — local-only receipts that were never exported or synced go with the device.

The privacy policy sets out what is retained afterward and for how long.

Reporting a problem

If you find a vulnerability, or you think your account or data has been compromised, email security@getcabsnap.com. Tell us what you found and how to reproduce it, and we will look at it.