Privacy Policy
Last updated: April 19, 2026This policy explains what VictorsSnap collects, why, how it's stored, and who else processes your data.
Who we are
VictorsSnap is developed by Remote Angel, LLC ("we", "us"). You can reach us at sean@remoteangel.com or (203) 435-8050.
What we collect
Account information
When you create a VictorsSnap account, we collect:
- Your email address and display name from the identity provider you choose (Apple, Google, or Xero).
- A unique identifier from that provider so we can recognize you on return visits.
We never see or store your password for any of these providers.
Accounting connections
When you connect Xero or QuickBooks Online, your app authorizes VictorsSnap through OAuth. We store OAuth access and refresh tokens so the app can talk to your accounting provider on your behalf. These tokens are stored in your device's Keychain (hardware-encrypted) and, for QuickBooks multi-user access, also in our backend database (encrypted at rest).
Receipts and transactions
Receipt images and the details extracted from them are stored on your device. They are sent outside your device only in two cases:
- To Anthropic's Claude API for one-time extraction (see "AI processing" below).
- To Xero or QuickBooks when you submit an expense — at which point the entry lives in your accounting system.
Usage and diagnostics
Our backend records minimal request logs (timestamp, HTTP method, path, IP address) for security and debugging. These logs are retained for up to 30 days.
Subscription status
Your subscription tier and Apple receipt are relayed to our backend so the app can confirm your entitlement. We store the Apple-provided transaction identifier and the tier purchased, but no payment information — Apple handles billing.
What we don't collect
- We don't collect your location data on any server. Location is only used on-device for the mileage starting address.
- We don't collect your contacts, calendar, health data, or any data from other apps.
- We don't use tracking SDKs or advertising identifiers.
How we use your information
- Authenticate you and keep your session active.
- Let the app read from and write to your Xero or QuickBooks account on your behalf.
- Extract details from receipt images you choose to scan.
- Enforce your subscription tier (e.g., monthly scan allowance).
- Respond to support requests you send us.
- Improve the app — using aggregate, non-identifying information (e.g., counts of OAuth failures).
We do not sell your personal information. We do not share it for advertising.
Third-party processors
The following services help operate VictorsSnap. Each receives only the data required to perform its role.
- Apple — Sign in with Apple, App Store subscriptions, iOS platform services.
- Google — Sign in with Google (if you choose this option).
- Xero — Accounting API for users who connect Xero.
- Intuit (QuickBooks Online) — Accounting API for users who connect QuickBooks.
- Anthropic — Claude API for receipt extraction. Under Anthropic's commercial API terms, inputs and outputs are not used to train models and are retained only briefly for abuse monitoring.
- Plaid — Bank account linking for bill pay features. Only used if you opt in.
- Moov — ACH payment processing for bill pay features. Only used if you opt in.
- Railway — Hosting provider for our backend (
victorssnap.remoteangel.com). - AWS — Cloud infrastructure used by Railway; receipts and data in transit pass through AWS networks in the U.S.
Where your data lives
- On your device: receipts, extracted details, local caches, OAuth tokens (in Keychain).
- Our backend: your account email and provider ID, QuickBooks OAuth tokens (for multi-user companies), subscription status, request logs.
- Xero / QuickBooks: the transactions and contacts you choose to create, plus any attached receipt images.
- Anthropic: the receipt image you send for extraction, during processing only.
Our backend and its database are hosted in the United States.
How long we keep data
- Account records are retained as long as your account exists. Deleting your account removes them.
- Receipts on your device are retained until you delete them or delete the app.
- OAuth tokens are retained until you disconnect the provider.
- Request logs are retained for up to 30 days, then deleted.
- Subscription records are retained for the period required by tax and accounting regulations.
Your rights
You can, at any time:
- Access the data associated with your account by emailing us.
- Correct inaccurate information (in-app for most fields, or by contacting us).
- Delete your account and associated data — tap "Disconnect" on each provider and email us to close your account, or simply delete the app to remove all device-local data.
- Export your data by emailing us — we'll send you a machine-readable copy.
- Opt out of marketing — we don't send marketing email; if that ever changes, every message will include an unsubscribe link.
If you're in the EU/UK or California, you have additional rights under GDPR and CCPA, including the right to lodge a complaint with your local supervisory authority. Email sean@remoteangel.com to exercise any of these rights.
Children
VictorsSnap is intended for users 17 and older. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with information, please contact us and we will delete it.
Security
- Data in transit is protected by HTTPS/TLS.
- OAuth tokens on-device live in the iOS Keychain, which is hardware-encrypted.
- Data at rest in our backend database is encrypted.
- Access to our backend is restricted to authorized operators using strong authentication.
No system is perfectly secure. If you believe you've found a vulnerability, please report it to sean@remoteangel.com.
Changes to this policy
We'll update this page when we make material changes, and update the "Last updated" date at the top. If the change affects how we use data you've already given us, we'll also notify you through the app or by email before the change takes effect.
Contact
Questions about privacy? Email sean@remoteangel.com or write to Remote Angel, LLC at the address listed on our business registration.