Privacy
What is processed, what is not saved, and where providers are involved.
Effective September 24, 2026. This notice explains the difference between ExpenseReader application storage and processing by the services that operate ExpenseReader.com.
Protect your information: review and mask sensitive text before analysis. Never email bills, medical information, account numbers, or payment-card details to ExpenseReader.
Document and conversation data
ExpenseReader accepts pasted text or up to two text-layer PDFs. The original PDF is read in bounded server request memory and is not sent to OpenAI. Extracted text is returned to your browser so you can correct and mask it. Only the corrected text you approve is submitted for AI classification and analysis.
The application is designed not to write original PDFs, extracted or corrected document text, analysis results, prompts containing bill content, or chat content to its database. It does not use localStorage, sessionStorage, IndexedDB, permanent accounts, or saved server conversations for this data. Page state remains in memory and is removed by Clear, refresh, or session expiry.
Service providers and retention
Vercel hosts the application and necessarily transmits web requests. OpenAI processes the corrected text and bounded conversation context needed to produce a response. Neon stores limited operational metadata described below, not bill or chat content.
ExpenseReader sends OpenAI Responses API requests with store:false. According to OpenAI's current API data-control documentation, that prevents Response application-state storage for these calls, but it does not by itself establish Zero Data Retention. OpenAI says API data is not used to train models unless a customer opts in, while default abuse-monitoring logs may contain customer content for up to 30 days. Modified Abuse Monitoring and Zero Data Retention require approval.
Retention can vary by service and account controls. ExpenseReader does not promise Zero Data Retention. Clearing the page cannot retract processing or retention that has already occurred at a provider.
Anonymous usage and operational records
There are no user accounts. A signed, host-only, HttpOnly, Secure, SameSite=Lax cookie identifies an anonymous browser token for quota enforcement. Before database storage, the identifier is transformed with a keyed HMAC. Neon stores that derived value with daily usage and shared AI-budget reservation metadata. It is not a raw IP address, account number, bill identifier, or document fingerprint.
The cookie can last up to 30 days. Quotas reset at UTC day boundaries. Removing the cookie may reset the browser identity, but does not remove aggregate cost records or affect provider-side processing.
Analytics, logs, and publishing
No third-party product analytics, advertising tracker, or session replay library is currently installed. Application errors are designed to omit raw document and chat content. Hosting infrastructure may still create request-level operational logs under its own controls.
Weekly notebook articles use approved general topics and synthetic examples—not uploaded user bills. Public article records and non-sensitive publication failure codes are stored in Neon.
Sensitive documents and your choices
Pattern detection helps identify common names and account-like values, but cannot find every sensitive detail. Review and mask the extracted text before analysis. Do not submit a document unless you are authorized to use it. Medical documents require an additional acknowledgement before corrected text is sent for analysis.
Privacy questions may be emailed to info@aisuretech.com. Requests are handled in accordance with applicable law, but email must not include a bill or sensitive information. See contact guidance, how processing works, and the terms.