Slipsby Privacy Policy
Draft for the closed beta: the date this version takes effect is not set yet.
- In short
- Who is responsible for your data
- What we store
- What we don’t read or store in your purchases
- Photos
- Receipts by e-mail
- Location
- Pharmacy receipts
- Shared catalogue of shops and products
- Shared ledgers
- Why we use your data and on what legal basis
- Consents
- Dataset for our own receipt reading
- Who receives your data
- Where your data is stored and transfers abroad
- How long we keep your data
- Deleting your account
- Exporting your data
- Your rights
- Support
- Cookies and the websites
- Server logs and security
- Children
- Changes to this policy
- Not decided yet
Version privacy-policy/v[[EFFECTIVE DATE]], effective [[EFFECTIVE DATE]] at 00:00 UTC.
Earlier versions and their change lists are on legal.slipsby.app. The beta draft this version replaces was published at slipsby.app/privacy/.
-
New: who is responsible for your data and how to contact us.
-
New: legal bases, recipients, transfers abroad, retention periods, your rights and the regulators you can complain to.
-
New: two consents, both optional: using your receipts to train and evaluate our model, and processing pharmacy purchases.
-
New: how we tell you about new versions of this policy, 30 days ahead in the bot.
-
Changed, less favourable to you: using Slipsby on or after a new version’s effective date means you accept that version.
-
Changed, less favourable to you: we keep records of what you accepted and consented to, and after you delete your account we keep them for 6 years with no link to you.
-
New: support conversations in the Support Bot.
-
New: PDF receipts, and receipts sent by e-mail to your own receipt address.
-
Changed, less favourable to you: Cloudflare receives the full content of e-mails sent to your receipt address and keeps it until our server has saved it, for 14 days at most. We keep each such e-mail’s original sender address, subject and date with the purchase, and we keep PDF files unchanged, with any metadata inside them.
-
Changed, less favourable to you: we keep receipt photos as you send them. The beta draft said the background of the shot was cut away; Slipsby does not do this.
-
Changed, less favourable to you: our model is instructed not to copy the buyer’s name and tax number, card digits, the cardholder’s name, loyalty card numbers or delivery details into your purchases, and it can make mistakes. The beta draft said we don’t read or save them.
-
Changed, less favourable to you: Cloudflare, which carries all traffic to our websites and to the cabinet, sees your IP address, and our web server’s logs record request data. The beta draft said only that we don’t store IP addresses.
-
Changed, less favourable to you: members of a shared ledger can see which shop and products a purchase in that ledger is linked to. The beta draft said only the purchase’s owner could.
-
Changed, less favourable to you: members of a shared ledger can see the photos of receipts sent to that ledger.
-
Changed, less favourable to you: the list of who receives your data now includes our hosting provider, Cloudflare (which sees everything exchanged with the cabinet and the Mini App), our support specialists, our administrators and authorities. The beta draft said photos and texts are not passed to third parties.
-
Changed, less favourable to you: an AI assistant that another member of a shared ledger connected can read that ledger, including your display name and your purchases in it. The beta draft said only that an AI you connected yourself receives your data.
-
Changed, less favourable to you: in PNG files, a location written in the file’s text metadata (including XMP) stays in the stored photo, and in JPEG files a rare extended XMP block stays. The beta draft said coordinates were removed from both EXIF and XMP metadata.
-
Changed, less favourable to you: members of your shared ledgers, and anyone who opens your invitation link, see your Telegram display name. The beta draft said only that your display name is used to sign you in.
-
Changed, less favourable to you: data deleted with your account stays in our database backups for up to 30 days, until those backups expire. The beta draft said only that deletion removes it.
-
Changed, less favourable to you: what account deletion keeps is now described in full, including payment records with the sender’s blockchain address.
-
Changed, less favourable to you: requests to connect an AI assistant that you declined or left unanswered in the bot stay with your Telegram ID after you delete your account.
In short
Slipsby is an expense tracker that reads receipts from photos, PDF files and e-mails. It works through the Telegram bots @slipsbybot and @slipsby_bot, the Telegram Mini App, the web cabinet at app.slipsby.app, your receipt e-mail address, and AI assistants you connect to your account yourself. This policy covers all of them, the support bot @slipsby_support_bot and our websites, and for Slipsby’s bots and Mini App it replaces Telegram’s Standard Bot Privacy Policy.
Slipsby does not ask for your name, e-mail address, phone number, gender or age. Your Telegram account is your identity in Slipsby. We read receipts with our own model on servers we control. We show no ads, we use no analytics or tracking services, and we do not sell your data. You can export your data and delete your account at any time.
The sections below say exactly what we keep, why, who else receives it, for how long, and what you can do about it.
Who is responsible for your data
The controller of your personal data, the company that decides why and how it is used, is:
[[COMPANY LEGAL NAME]]
Registration number: [[COMPANY REGISTRATION NUMBER]], registered in [[COMPANY COUNTRY OF REGISTRATION]]
Address: [[COMPANY REGISTERED ADDRESS]]
Data protection officer (the person who answers for our handling of personal data): [[DATA PROTECTION OFFICER NAME OR TITLE AND CONTACT]].
Representative in the European Union: [[EU REPRESENTATIVE NAME AND ADDRESS]].
Representative in the United Kingdom: [[UK REPRESENTATIVE NAME AND ADDRESS]].
You can contact a representative instead of us about anything in this policy.
The fastest way to reach us is the Support Bot @slipsby_support_bot in Telegram. You can also write to us by post at the address above.
What we store
| Data | What exactly |
|---|---|
Identity |
Your Telegram user ID and your Telegram display name, as Telegram sends it: the bot stores your username, or your first name if you have no username, and the Mini App stores your first and last name, or your username if you have no name. We update the name each time you write to the bot or open the Mini App. For each receipt we also keep the Telegram chat ID and message IDs, so that the bot can answer in the right place. |
Account |
Role, language, base currency, time zone and display preferences. The language is first taken from your Telegram language. The base currency is first set to the currency most of your purchases used on your first day. The time zone comes from your device each time you open the Mini App or the cabinet, and until then we estimate your time offset from the times printed on your receipts. You can change all of these except your role yourself. |
What you send |
Photos, PDF files and their captions, messages to the bot, your conversation history with the assistant, and the changes the assistant proposed to you. The history does not contain the images, and sign-in links in it are blanked out. |
Reading results |
For each attempt to read a receipt: the model’s full answer, the model and prompt version, and flags that mark which kinds of personal data were found on the receipt (see What we don’t read or store in your purchases). |
Purchases |
Shop (name, legal name, seller’s tax number, address), date and time, line items, quantities, weights, amounts, discounts, taxes, payment type (card, cash and so on), your edits, and reminders about missing details (such as currency or city), with a note of where each filled-in value came from. |
E-mail receipts |
Your receipt address and, for each purchase from an e-mail, the e-mail’s original sender address, subject and date and the image or PDF attachment it was read from (see Receipts by e-mail). |
Shared ledgers |
Which ledgers you belong to and the invitations you sent. |
Payments |
Invoices (amount, coin, the address you paid to, status, times, transaction ID); blockchain transfers to our addresses (sender address, amount, time), which are public on the blockchain; the movements of your balance; promo codes you activated. |
Sign-in |
Fingerprints (hashes) of one-time sign-in links and of sessions, and the session cookie described in Cookies and the websites. |
Connected AI |
For each AI assistant you connect: its name and return address as the assistant reports them, the connection, fingerprints (hashes) of its access tokens, and when it last used them. For each request to connect an assistant that you open in the bot: your Telegram ID, the assistant’s name and return address, and the request’s status and time. |
Support |
The messages, photos and images you send to the Support Bot, our support specialists' replies, and the link between the conversation and your Slipsby account (see Support). |
Acceptance and consent records |
Acceptance records: document, version, time, the channel the notice went to, and the client where you accepted (bot, cabinet or Mini App). Consent records: purpose, given or withdrawn, time, and client. Both are included in your data export. |
Server logs |
We collect all of this from you, through what you send and do in Slipsby and the e-mails that reach your receipt address, from Telegram (your ID, name and language), from your device (time zone) and from the public TRON blockchain (payment transfers).
You need a Telegram account to use Slipsby at all, and Slipsby needs your receipts to have something to read. Both consents are optional, and Slipsby works without them.
What we don’t read or store in your purchases
Receipts sometimes carry personal data. Our model is instructed not to copy the following into your purchases and their reading results, even when it is printed on the receipt:
-
the buyer’s name and tax number;
-
card digits, the cardholder’s name, and loyalty card numbers;
-
delivery details: name, address, phone number.
When the model finds such data, it records only which kind was present (for example "card"), as a flag. The payment method is kept as a type only.
The receipt photo we keep still shows everything printed on it. A model can make mistakes: if you see personal data in a purchase or a reading result, correct the purchase or write to support, and we will remove it.
Photos
-
Receipts. We keep the photo or PDF file of each receipt as you sent it: you may need it to prove a purchase, and we need it to re-read the receipt if a reading was wrong. Whatever else is in the shot (a hand, a table, other papers) stays in the photo.
-
Location in the photo file. Before we save any image, including images sent to the Support Bot, we remove most location metadata from the file, as follows. In JPEG files we remove the location block of the EXIF metadata and the main XMP block; a rare extended XMP block stays; other metadata, such as the camera model and the time the photo was taken, usually stays. In WebP files we remove all EXIF and XMP metadata. In PNG files we remove the EXIF block; a location written in the file’s text metadata, including XMP, stays. The picture itself is not changed. We refuse to save an image in a format we cannot clean. PDF files are kept unchanged, so any metadata inside a PDF, such as its author or the program that created it, stays.
-
Deleting a single purchase. When you delete one purchase, its photo and reading results stay in your account until you delete the account. If you want a particular photo deleted now, ask support.
Receipts by e-mail
Each account has its own receipt address of the form <mailbox>@in.slipsby.app. The mailbox name is random and contains nothing from your name, your Telegram account or your e-mail address. You find the address in the bot (/email) and in the cabinet settings, and you can forward receipts to it or set a forwarding rule in your mail service.
-
Who can send to it. Anyone who knows the address can send mail to it. You can issue a new address in the bot or the cabinet at any time; the old address then rejects new mail.
-
How an e-mail reaches us. Cloudflare receives the e-mail for us through Cloudflare Email Routing and a Cloudflare Worker, stores the whole e-mail in Cloudflare Workers KV and passes our server a pointer to it through a Cloudflare Queue. Our server then reads the e-mail from Cloudflare. The copy at Cloudflare is deleted as soon as our server has saved the e-mail, normally within seconds, and after 14 days at most in any case.
-
Checking for receipts. Our own model first checks the body and every image and PDF attachment for receipts. This check is free. Each receipt it finds is then read like a photo, costs one receipt credit and becomes a draft that you confirm in the bot.
-
What we keep. For each purchase from an e-mail we keep the purchase, the image or PDF attachment it was read from, and the e-mail’s original sender address, subject and date. The original sender is the shop or service that sent the e-mail, also when you forwarded it by hand. We do not keep the address the e-mail was forwarded from. The rules in this policy for receipt photos apply to these attachments too.
-
What we delete. We delete the e-mail body and everything else in the e-mail after reading it. An e-mail with no receipt in it leaves nothing except a technical record (the mailbox, the e-mail’s size and the result of the check), which is deleted after 15 days. The bot sends you one message that names the e-mail’s sender and subject and says that no receipt was found.
-
Waiting for credits. When you have too few receipt credits, the receipts left unread in an e-mail wait for up to 30 days and are read once you have credits again. Whatever is still unread after 30 days is deleted unread.
-
Forwarding confirmations. When Gmail asks the receipt address to confirm a forwarding rule, the bot sends you the confirmation link or code, and the e-mail is then deleted.
Location
We do not ask for your location. If you send a location in the chat, the bot ignores it and we do not store it. A photo file can carry the place where it was taken; we remove it to the extent described in Photos, so a PNG file, and in rare cases a JPEG file, can still keep it. The address of a shop comes from the receipt itself. We do receive your device’s time zone (see What we store).
Pharmacy receipts
A pharmacy purchase can reveal information about your health. For this reason we process the items of pharmacy receipts only with your consent (b), described in Consents.
-
Without consent (b). When our model recognises a receipt as a pharmacy receipt, the purchase is recorded as one line, "Pharmacy", with the receipt’s total. Its items are neither read nor stored, and the photo or PDF file is deleted once the receipt has been read. The bot offers you consent (b) if you want to see the items. Items of pharmacy receipts sent before you gave the consent cannot be recovered, because their photos are gone.
-
With consent (b). Pharmacy receipts are handled like any other receipt.
-
Withdrawing consent (b). Before you withdraw it, we warn you that the items of all your pharmacy purchases will be deleted. If you confirm, every pharmacy purchase becomes one line, "Pharmacy", with its total, and its items and photo are deleted. The withdrawal is recorded like any other consent change.
-
Health-related items on other receipts. Consent (b) covers only receipts recognised as pharmacy receipts. A health-related item on another receipt, for example a plaster bought in a supermarket, is read and stored like any other item, with or without consent (b).
Shared catalogue of shops and products
Shops and products are shared by all users, so that the same shop or product is recognised for everyone. Other users see the catalogue without any indication of who added what. Among Slipsby users, only you and the members of the ledger the purchase is in can see which shop or product your purchase is linked to. AI assistants connected by any member of that ledger, our administrators and the other recipients in Who receives your data can also see it, as described there.
Shared ledgers
You can keep a shared ledger with other people who accepted your invitation. Members of a shared ledger see:
-
your Telegram display name;
-
every purchase in the shared ledger, including yours, with the photo of a receipt sent to that ledger, which shows everything printed on it.
An AI assistant that another member connected to Slipsby can read the shared ledger too, including your display name and your purchases in it (see Who receives your data).
Anyone who opens your invitation link sees your display name. If you leave a shared ledger, your purchases in it stay there. If you delete your account, they are removed from it (see Deleting your account). An invitation expires after 7 days.
Why we use your data and on what legal basis
Data protection laws, such as the GDPR in the European Union and the UK GDPR, require a legal basis for each use of personal data. Our bases are:
-
contract: we need the data to provide Slipsby to you;
-
consent: you agreed to a specific use, and you can withdraw that agreement;
-
legitimate interests: we have a justified reason, and your rights and interests do not outweigh it; you can object (see Your rights);
-
legal obligation: a law requires us to do it.
| Purpose | Data | Legal basis |
|---|---|---|
Reading your receipts, keeping your purchases and ledgers, answering your questions in the bot, the Mini App and the cabinet |
Identity, account, what you send, e-mail receipts, reading results, purchases, shared ledgers |
Contract |
Signing you in to the cabinet and the Mini App |
Identity, sign-in |
Contract |
Letting an AI assistant you connected read your data |
Connected AI, purchases, shared ledgers |
Contract, at your request |
Selling packs of receipt readings and other paid features, checking payments, activating promo codes |
Payments |
Contract |
Keeping payment records after you delete your account (see Not decided yet) |
Payments |
Legitimate interests: proving payments and keeping our accounts |
Answering your support requests |
Support |
Legitimate interests: helping you and fixing Slipsby |
Answering e-mails sent to addresses on our website |
Your e-mail address and message |
Legitimate interests: answering you |
Keeping the shared catalogue of shops and products complete |
Purchases, with no link to your account |
Legitimate interests: recognising shops and products for every user |
Keeping receipts with no link to your account after you delete your account (see Deleting your account) |
Purchases, reading results, photos checked and found without personal data |
Legitimate interests: keeping the catalogue and the receipt data it was built from |
Training and evaluating our receipt-reading model |
Receipt photos and reading results |
Consent (a) |
Reading and storing the items of pharmacy receipts |
Purchases and photos from pharmacy receipts |
Explicit consent (b) |
Telling you about new versions of our documents and recording what you accepted and consented to |
Acceptance and consent records |
Legal obligation to be able to show your consent; legitimate interests: proving which terms applied |
Keeping Slipsby secure, preventing abuse, fixing errors |
Server logs, sign-in, what you send, reading results, payments |
Legitimate interests: a safe and working service |
We do not use your data for advertising and do not combine it with data from outside Slipsby. We use your Telegram account only to run Slipsby in Telegram and send you no marketing through it.
Slipsby makes no decisions about you that have legal or similarly significant effects by automated means alone. The model reads receipts and proposes drafts, and you confirm or correct every draft before it enters your ledger.
Consents
Slipsby offers every user two consents:
-
(a) Receipts for our recognition: using your receipts, meaning their photos and reading results, to train and evaluate our receipt-reading model.
-
(b) Pharmacy purchases: processing the items of your pharmacy receipts, as described in Pharmacy receipts. Under the GDPR this is explicit consent to processing data concerning health (Article 9).
Both start as "not given". You give a consent only by your own explicit action: by using the switch in the "Notifications and documents" section of the settings in the cabinet or the Mini App, or by confirming the bot’s proposal in the chat. Using Slipsby, accepting a document, or continuing to use Slipsby after a new version takes effect never counts as consent.
You can withdraw either consent at any time, in the same places, and the change takes effect at once. Withdrawing a consent does not affect processing that took place before it. Each time you give or withdraw a consent, we store a consent record (see What we store).
Dataset for our own receipt reading
We want to build our own recognition model that needs less computing power than the model we use today. For this we use receipt photos and their reading results, with the purchases users confirmed and their corrections as the right answers.
We use your receipts to train and evaluate our model only with your consent (a). If you withdraw consent (a), we stop using your receipts for this and remove them from our training and evaluation sets; a model already trained on them is not retrained.
Whether receipts kept after an account is deleted, and receipts collected before the consents existed, may be used without consent (a) is not decided yet (see Not decided yet). Until it is decided, we do not use them to train or evaluate our model.
Who receives your data
We do not sell your personal data, and we do not share it for advertising. These recipients receive it:
-
Our hosting provider. Slipsby’s servers, its database, receipt photos and our receipt-reading model run in a data centre in Almaty, Kazakhstan. The hosting provider processes the data only on our instructions. Receipt photos and texts are not sent to any third-party AI provider for reading.
-
Cloudflare. Cloudflare, Inc. carries all traffic to app.slipsby.app, slipsby.app and legal.slipsby.app and hosts our websites. It sees your IP address and everything exchanged with app.slipsby.app, including photos you upload, the purchases and photos the cabinet and the Mini App show you, the export file you download and the data a connected AI assistant reads, and processes them on our instructions. Cloudflare also receives the full content of every e-mail sent to your receipt address, including its body, its attachments and the address it was forwarded from, and keeps it until our server has saved it (see Receipts by e-mail). Cloudflare also forwards e-mail sent to addresses published on our website to our team’s mailbox.
-
Telegram. Everything you exchange with our bots passes through Telegram, which is a separate company with its own privacy policy. This includes the data export when you ask for it in the bot, and the bot’s messages about e-mails sent to your receipt address, which name each e-mail’s sender and subject. The Mini App loads Telegram’s script from telegram.org, so Telegram sees that you opened it. Your chat with the bot stays in Telegram until you delete it there.
-
An AI assistant you connected yourself (such as Claude, ChatGPT or Grok, through the MCP connector). It reads data from your ledgers, including shared ledgers and their members' display names, through read-only tools and only under the access you granted. It never receives receipt photos. The assistant’s provider handles that data under its own privacy policy. You can see and disconnect every connected assistant in the cabinet, and disconnecting takes effect at its next request.
-
Other members of your shared ledgers (see Shared ledgers).
-
Our support specialists (see Support).
-
Our administrators, who can see accounts with their Telegram ID and display name, what you send to Slipsby from the bot, the cabinet, the Mini App or by e-mail (photos with their captions, PDF files, e-mail attachments and messages), the purchases made from it (shop, date, total), reading results, balances and their movements, invoices and payment transfers, to fix reading errors and handle payments.
-
Authorities, when a law that applies to us requires it.
To check payments we read the public TRON blockchain through the TronGrid service. The only thing we send TronGrid is our own payment addresses.
Where your data is stored and transfers abroad
Your data is stored and processed in Kazakhstan. Cloudflare processes traffic and e-mail in its network around the world, including the United States, and stores each e-mail sent to your receipt address until our server has saved it (see Receipts by e-mail). The European Commission and the UK government have not found Kazakhstan’s data protection adequate. To protect your data, we rely on:
-
for our hosting provider: the European Commission’s standard contractual clauses and the UK addendum to them;
-
for Cloudflare: its data processing addendum, which includes the standard contractual clauses, and its certification under the EU–US Data Privacy Framework and its UK extension.
Telegram is a separate company that carries your messages under its own privacy policy, wherever its servers are. When you connect an AI assistant, its provider receives your data in the country where it operates, because you asked for it. You can ask us for a copy of the safeguards described above (see Your rights).
How long we keep your data
| Data | How long |
|---|---|
Identity, account, what you send, reading results, purchases, shared ledgers and invitations, chat history |
Until you delete your account. Confirmed purchases are then kept with no link to your account, as described in Deleting your account. An invitation stops working after 7 days; its record stays until you delete your account. Slipsby does not delete inactive accounts. |
Photos |
Until you delete your account, then as described in Deleting your account. Photos of pharmacy receipts without consent (b): deleted once the receipt has been read. |
One-time sign-in links |
Valid for 15 minutes and once only; the record stays until you delete your account. |
Sessions in the cabinet and the Mini App |
Valid for 30 days; the record stays until you sign out or delete your account. |
Connected AI |
Access ends when you disconnect the assistant. The record of the connection and its tokens stays until you delete your account. An access token is valid for 1 hour, and the assistant renews it until you disconnect it. Requests to connect that you declined or left unanswered in the bot stay with your Telegram ID, also after you delete your account (see Deleting your account). |
Support conversations |
1 year after the last message in the conversation, then deleted automatically. Deleted at once when you delete your account. |
Acceptance and consent records |
While your account exists. After you delete it, kept for 6 years with no link to your account or your Telegram ID, then deleted. |
Payment records |
While your account exists. After deletion, see Deleting your account. |
Receipts kept after an account is deleted |
No period has been set yet (see Not decided yet). |
E-mails sent to your receipt address |
The copy at Cloudflare: deleted once our server has saved the e-mail, after 14 days at most. The body and everything else not kept with a purchase: deleted after reading. Receipts waiting for credits: up to 30 days, then deleted unread. The technical record of an e-mail with no receipt: 15 days. The sender address, subject and date kept with a purchase: until you delete your account. |
E-mails sent to addresses on our website |
No period has been set yet (see Not decided yet). |
Server logs |
Up to 14 days. |
Backups of the database |
Up to 30 days. |
Deleting your account
You can delete your account with /delete in the bot, by asking the bot in plain words, or in the cabinet. Deletion happens at once, after you confirm it, and cannot be undone: it destroys the links between your account and its data, and they cannot be restored.
Deleted:
-
your account, your Telegram identity, sessions, sign-in links, connected AI assistants with their tokens, and invitations;
-
your receipt addresses, and the sender addresses, subjects and dates kept from your e-mails;
-
your personal ledger, your messages and chat history with the assistant, changes the assistant proposed, reminders about missing purchase details, and unconfirmed drafts with their photos;
-
your membership in shared ledgers; your purchases are removed from them (confirmed ones are kept with no link to you, see below), and other members' data stays;
-
your balance movements and promo code activations;
-
your support conversations with their photos;
-
photos of purchases you deleted, and photos that turned out not to be receipts.
Kept with your Telegram ID: requests to connect an AI assistant that you declined or left unanswered in the bot, with the assistant’s name and return address and the request’s status and time. Slipsby does not delete them yet; ask support if you want them deleted.
Kept with no link to your account:
-
Confirmed purchases: the purchase, its edits and, for receipts, its reading results, with no link to your account, your ledger, your Telegram chat or messages, the photo caption or the author of the edits. The photo or PDF file stays too, unless a personal-data flag was set for it or it was never checked for personal data; such photos and files, including pharmacy ones, are deleted. The photo and the reading results stay as they are, so anything printed on the receipt stays in them. This covers purchases made from receipts and purchases you described to the assistant; where this policy speaks of receipts kept after an account is deleted, it means both.
-
Shops and products you added to the catalogue, with no author.
-
Payment records: invoices (amount, coin, payment address, transaction ID, times) and blockchain transfers to our addresses (sender address, amount, time). The sender address and transaction ID are public on the blockchain. What finally happens to them is not decided yet (see Not decided yet).
-
Acceptance and consent records: only the document or purpose, version, given or withdrawn, time, channel and client, with no link to your account or your Telegram ID. They are deleted 6 years after your account is deleted.
If you want your confirmed purchases and their photos deleted as well, ask support before you delete your account. After deletion we can no longer tell which purchases were yours.
Deleted data disappears from our backups when they expire (see How long we keep your data).
Exporting your data
You can export your data at any time with /export in the bot (the file is sent to you through Telegram) or in the cabinet (the file downloads directly). The export is a ZIP file with data.json, your photos and your PDF files. It contains your role, language, base currency and default ledger, ledgers with their members' display names, your purchases with their edits, receipts and their reading results, the sender address, subject and date of e-mails your purchases came from, the text of your messages to the bot and photo captions, your chat history with the assistant, changes the assistant proposed, balance movements, invoices, promo code activations, support conversations with their photos, and acceptance and consent records.
Your time zone, display and other settings, the invitations you sent, reminders about missing purchase details, connected AI assistants and blockchain transfer records are not in the file. Your Telegram ID appears there only as the chat ID of photos and messages you sent through the bot, and your display name only in the member lists of your ledgers. You can see your settings and connected assistants in the cabinet, and support sends you all the missing data on request.
Your rights
Depending on the law of your country, you have the right to:
-
access your data and get a copy of it;
-
correct it: you can edit purchases and settings yourself; your display name comes from Telegram and changes when you change it there;
-
delete it (see Deleting your account);
-
take it with you in a machine-readable form (see Exporting your data);
-
restrict how we use it while a question about it is being settled;
-
object to a use based on legitimate interests;
-
withdraw a consent at any time (see Consents);
-
complain to a data protection regulator (see Regulators).
To use a right, write to the Support Bot @slipsby_support_bot or to us by post. We recognise you by the Telegram account you write from, or by details only you know, such as the date and shop of a receipt. We never ask for identity documents. We answer within one month, or within a shorter period if the law of your country sets one. If a request is complex, we may extend the period as that law allows and will tell you why. Using your rights is free.
To complain about how we handle your personal data, write to the Support Bot @slipsby_support_bot or to us by post. We look into the complaint, tell you what we found and what we will do, and answer within 30 days.
If you are unhappy with our answer, you can complain to the regulator in your country. You can also complain to the regulator first, except in Australia, where the law requires you to write to us first. In New Zealand, the Privacy Commissioner also usually expects you to have written to us first.
Regulators
| Where you live | Regulator |
|---|---|
Ireland and the rest of the European Union |
Data Protection Commission (dataprotection.ie) or the regulator of your EU country |
United Kingdom |
Information Commissioner’s Office (ico.org.uk) |
Canada |
Office of the Privacy Commissioner of Canada (priv.gc.ca) |
Australia |
Office of the Australian Information Commissioner (oaic.gov.au) |
New Zealand |
Office of the Privacy Commissioner (privacy.org.nz) |
Singapore |
Personal Data Protection Commission (pdpc.gov.sg) |
Malaysia |
Personal Data Protection Commissioner (pdp.gov.my) |
United States |
The attorney general of your state, or the Federal Trade Commission (ftc.gov) |
In Australia, write to us first; if we have not answered within 30 days, or you are not satisfied with the answer, you can complain to the Office of the Australian Information Commissioner.
Residents of the United States
We do not sell personal information, do not share it for cross-context behavioural advertising, and do not use it to profile you. We do not track you across other websites or apps, so we treat every visitor the same whether or not the browser sends a "Do Not Track" signal.
Pharmacy purchases you let us process with consent (b) are consumer health data under the laws of Washington, Nevada and similar states. We collect them only from the receipts you send, and use them to show your purchases to you and, if you also gave consent (a), to train and evaluate our model. Members of a shared ledger the purchase is in see them together with their receipt photos. AI assistants that you, or another member of that ledger, connected can read them, without the photos. Telegram, Cloudflare, our hosting provider, our administrators and our support specialists receive them as described in Who receives your data. You can access, delete and withdraw consent for them as described in Your rights.
Support
Our support channel is the Support Bot @slipsby_support_bot in Telegram. You can write to it even if you don’t have a Slipsby account.
-
What we keep: the messages, photos and images you send, our replies, and the link between the conversation and the Slipsby account with the same Telegram identity. If you have no account, the conversation is kept without that link and gets the link once such an account exists.
-
Photos: the rule in Photos applies; an image we cannot clean is not saved.
-
Support tickets: a support specialist copies the text of your request into a ticket in our support tracker without the data listed in What we don’t read or store in your purchases. A receipt photo goes into a ticket only with your consent and with that data painted over. We use the photo only to investigate and fix the problem you reported.
-
How long: a conversation with its messages and photos is kept for 1 year after its last message and then deleted automatically. When you delete your account, its support conversations are deleted at once. A conversation without an account is deleted when you ask support to delete it.
If you e-mail an address published on our website, we receive your e-mail address and your message and use them only to answer you.
Cookies and the websites
The cabinet and the Mini App at app.slipsby.app set one cookie, sid, which keeps you signed in for up to 30 days. It is strictly necessary for signing in, so we do not ask for consent to it. The cabinet also keeps the page to return to in your browser’s session storage until you close the tab.
Our websites slipsby.app and legal.slipsby.app set no cookies and load no counters, trackers, advertising pixels or third-party fonts.
Server logs and security
Our application does not record IP addresses. Cloudflare sees your IP address as described in Who receives your data. The web server in front of our application keeps a standard access log: the time of each request, the web address (URL) requested, the page you came from and your browser type. Our application’s logs record technical data such as internal account IDs and Telegram chat IDs when an error occurs. Logs are kept for up to 14 days.
We protect your data by:
-
storing sign-in links, sessions and access tokens in our database only as fingerprints (hashes); the address of a sign-in link you open also appears in the web server’s access log until that log is deleted, and by then the link has long expired;
-
encrypting traffic between your device and Cloudflare and between Cloudflare and our data centre;
-
deciding access to every ledger on the server, by ledger membership;
-
giving connected AI assistants read-only access with a limit on requests.
No system is perfectly secure. If a breach of your data puts you at risk, we will tell you and the regulators as the law requires.
Children
Slipsby is meant for people aged 16 and over. We do not knowingly collect data from children under 16. If you believe a child under 16 uses Slipsby, write to support, and we will delete the account.
Changes to this policy
We publish every version of this policy, with its effective date and a list of changes, on legal.slipsby.app. Earlier versions stay available there.
We tell you about a new version 30 days before it takes effect, in your notification channel: the main bot, @slipsbybot or @slipsby_bot, that you last wrote to. The notice links to the new text and its list of changes. You can accept the new version with the button in the notice or in the "Notifications and documents" section of the settings.
Using Slipsby on or after the effective date means you accept the new version. If you do not accept it, stop using Slipsby before that date; you can export your data and delete your account at any time, as described in Exporting your data and Deleting your account. A new version never gives or changes a consent: if a change needs your consent, we ask for it separately, as described in Consents.
Not decided yet
These questions are open. Until each one is decided, Slipsby works as described here, and a new version of this policy will give the answer.
-
What finally happens to payment records after an account is deleted. Today invoices and blockchain transfers are kept with no link to the account, and balance movements and promo code activations are deleted.
-
How long receipts are kept after an account is deleted.
-
Which receipts may be used to train and evaluate our model without consent (a): none at all; receipts kept after an account is deleted; or receipts collected before the consents existed. Until this is decided, we use no receipts without consent (a).
-
E-mail as a support channel, and how long e-mails sent to addresses on our website are kept.
-
What happens to the copies of requests in our support tracker when an account is deleted or a support conversation reaches its retention limit.