Connecting your email is the part people hesitate over, and they should. Here is exactly what happens: what we read, what we never touch, where it goes, and how to end it. The privacy policy is the formal version of this page; nothing here contradicts it.
When you connect Gmail, the only scope we request is gmail.readonly. That is Google's read-only permission, and it is the whole grant.
So we cannot send mail as you. We cannot reply, forward, delete, archive, label, or change a single thing in your mailbox. That is not us choosing to behave. The permission we hold does not allow it, and you can see the scope on Google's consent screen before you agree to anything.
Indemnia looks at messages to work out which ones are purchase receipts. That is a score, computed from things like the sender and the subject.
We store the full message only when it looks like a receipt. Everything else is scored and left alone. We keep a note that we checked it, so we do not keep re-reading the same mail, but we do not keep the message. Your personal correspondence is not copied anywhere.
The receipt itself becomes part of your record: the vendor, the date, the items, the amounts, and the original document attached to the line it proves. That is the thing you are here for, and it stays as long as your account does.
The stored copy of the original email is temporary. It is kept for 90 days so we can re-read it if extraction needs correcting, and then a scheduled job deletes both the record and the file. What survives is the receipt data, not your mail.
Your household. Access is enforced in the database itself, row by row, rather than by application code remembering to check. A query for someone else's inventory returns nothing, rather than relying on a screen to hide it.
The connection's access token is stored encrypted and used only by the background jobs that fetch your mail. Some processing runs through service providers: hosting, storage, and an AI model that reads receipt text and photos. They are listed by name in the privacy policy, and content sent for AI processing is not used to train models.
We are a small company, not a certified one. We have not been through SOC 2 or any similar audit, and we would rather say so than imply otherwise.
Settings → Email accounts → Disconnect. One click, no confirmation email, no waiting period.
Disconnecting deletes the stored token. It is not flagged as unused or kept in case you come back. It is gone, so nothing is left that could reach your mailbox again. You can also revoke access from your Google account at any time, and that works whether or not you tell us.
The receipts we already found stay in your inventory, because they are your record and deleting them is not what “stop reading my email” means. If you want those gone too, ask and we will delete your account and its data.
Tell us which you are and we will write when there is room.