Plain-language summary
- Your expense data stays in your accounts. Entries and receipts are kept on your device and, if you choose, in your own iCloud account and your own Google Sheets and Drive. RGB does not receive copies.
- Google access is limited. The app uses per-file Google Drive access, so it can only touch the spreadsheets and files it creates or that you pick.
- AI runs on your device, or on Apple's Private Cloud Compute where Apple uses it, unless you choose the optional Claude feature, which sends a limited portion of each receipt to Anthropic under your own Claude account.
- Diagnostics are minimal. The app reports failures to RGB with identifying values one-way hashed; they don't include expense content, receipts or credentials.
- You're in control. Disconnect Google, turn off sync or delete entries at any time.
This summary is provided for convenience only and is not part of the agreement. If anything in the summary differs from the full terms below, the full terms govern.
This notice explains how the Expense Logger application ("Expense Logger" or "the app") from RGB Technologies Inc. ("RGB") handles your information. It supplements the RGB Privacy Policy; where they differ, this notice governs for the app. The app's handling of Google user data complies with the Google API Services User Data Policy, including its Limited Use requirements. The same information is available in the app under Help → Where Is My Data Stored?
1. Where your data is kept
1.1 On your device. Entries, source files (such as emails, PDFs and documents you add), statements, routing rules and settings are stored in the app's data folder on your device.
1.2 In your iCloud account, if you use sync. Entries, their source files and your routing rules sync through your own Apple iCloud private database so they are available on your other devices. Apple end-to-end encrypts that database when Advanced Data Protection is turned on in your Apple account, and we recommend turning it on.
1.3 In your Google account, if you connect one. See Section 3.
1.4 RGB does not receive copies of your expense entries, receipts, statements or spreadsheet contents.
2. Credentials
Email account passwords and Google sign-in tokens are stored in the operating system's keychain on your device, protected by your device login, and are not sent to RGB.
3. Google user data
Expense Logger can connect to your Google Account so that it can record expense entries in a Google Sheets spreadsheet and store receipt attachments in Google Drive on your behalf. This section describes how Expense Logger accesses, uses, stores and shares Google user data, in accordance with the Google API Services User Data Policy, including its Limited Use requirements. Expense Logger's use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
Google data we access. When you choose to connect a Google Account, Expense Logger requests only the following OAuth scopes:
- Your email address and basic OpenID sign-in identifier (
openid,email) — used solely to confirm which Google Account is connected and to display that account in the app. We do not request your name, profile picture, contacts or any other profile information. - Per-file access to Google Drive (
https://www.googleapis.com/auth/drive.file) — this scope limits the app to only the specific files it creates or that you explicitly select through the Google Picker. Expense Logger cannot list, search or read any other files in your Google Drive.
How we use Google data. Using the per-file Drive scope, Expense Logger creates and updates an expense ledger spreadsheet (via the Google Sheets API) and uploads, links and deletes receipt files (via the Google Drive API) that you add. The data written to these files is the expense information you enter in the app (such as vendor, amount, date, notes and the receipt documents you choose to attach). The app reads back only the spreadsheets and files it created or that you selected — for example, to detect duplicate entries — and never accesses other content in your Google Account. Your email address is used only to identify the connected account within the app.
How we store and protect Google data. Your expense entries and receipts reside in your own Google Account; Expense Logger does not copy them to RGB servers. The OAuth tokens that authorize the app are stored encrypted in the macOS Keychain on your device and are not synced to RGB. Sign-in is brokered through an RGB-operated cloud function that exchanges the Google authorization code for access tokens; this function does not store your expense data, receipts or spreadsheet contents.
How we share Google data. Expense Logger does not sell, rent or share your Google user data with third parties, does not use it for advertising, and does not use it to develop, improve or train generalized or personalized artificial-intelligence or machine-learning models. Google user data is used only to provide the user-facing features described above. Humans at RGB do not read your Google user data except with your explicit permission for support, for security investigation or as required by law.
Revoking access. You may disconnect your Google Account from within Expense Logger at any time, and you can review or revoke the app's access through your Google Account's third-party app permissions page. Revoking access does not delete the spreadsheets or receipts already stored in your own Google Drive.
4. Reading receipts with AI
4.1 Apple Intelligence by default. The app reads the vendor, amount and date from a receipt using Apple Intelligence and text recognition on your device. Where Apple processes a request using its Private Cloud Compute servers instead of on your device, that content goes to Apple's servers and Apple's privacy commitments for Private Cloud Compute apply; Apple states that such data is used only to fulfil the request and is not stored or made accessible to Apple. RGB does not receive this content.
4.2 Optional: Claude. If you choose Claude in the app's settings, the app sends the sender, subject and date of an email, and a limited portion of its text or of the text read from a document, to Anthropic through the Claude Code command-line tool under your own Claude account and subscription. This option is off by default. Anthropic's terms and your Claude account's data settings apply to that content, and RGB does not see it.
5. Diagnostics
To detect and fix problems, the app sends failure and update events (for example, a failed sign-in, upload or update) to RGB's monitoring platform through an RGB-operated relay. Identifying values such as vendor names, email addresses, file names and device names are one-way hashed on your device before they are sent. No expense content, receipts or credentials are included.
6. RGB-operated services
The app relies on a few services RGB operates: a sign-in broker that exchanges Google authorization codes for tokens without storing your expense data, receipts or spreadsheet contents; an update server that delivers new versions, each verified by signature before it is installed; and the diagnostics relay described in Section 5.
7. Your choices
You can disconnect your Google Account in the app, turn off iCloud sync, delete entries from the app, and revoke the app's Google access through your Google Account's third-party app permissions page. Disconnecting or revoking access does not delete files already in your own Google Drive or iCloud account.
8. Questions and changes
Contact RGB's Privacy Officer at support@rgbx.com. RGB may update this notice as described in Section 16 of the Terms of Service; the version and date at the top show which one is in effect.
