Privacy Policy

How AuditPacket handles your data

Last updated: July 5, 2026 · Operated by JaredCo Enterprises Inc.

The short version

You upload client card statements and receipt files; we store them, help you match them, and generate reports from them. Your files belong to you. We never connect to bank accounts, accounting ledgers, or email inboxes. We don’t sell your data. Receipt files are read by an extraction provider (OpenAI) to suggest matches. You can delete your files at any time, and closed accounts get a 90-day export window.

What we collect

Account information. Your email address and a password, handled through our authentication provider (Supabase). We send transactional emails — signup confirmation and password reset — to this address.

Uploaded content. Card statement exports (CSV/XLSX), receipt files (JPG, PNG, PDF), client and workspace names you create, and the data derived from your files: transaction rows, match records, statuses, and notes.

Generated reports. The PDF packets you export are stored in your account’s file history.

Usage and log data. Standard technical information such as browser type, IP address, timestamps, page events, and errors, used to operate and debug the service.

Billing information. If you purchase a paid subscription, payments are processed by our payment processor, PayPal. PayPal handles your payment details under its own privacy policy; we do not store full card or bank numbers ourselves. We keep basic subscription records such as plan, status, and billing history.

How we use information

To provide the service: storing your files, extracting receipt fields, suggesting matches, generating reports and PDF packets, and maintaining your account and client workspaces. We also use limited data to support and debug the service, prevent abuse and security issues, and comply with legal obligations. We do not sell your data or use it for third-party advertising.

Your clients’ documents

The statements and receipts you upload typically belong to your clients. You are responsible for having the authority to upload and process them. We process those documents only to provide the service to you — nothing else.

Extraction provider (OpenAI)

When you upload a receipt, the file (or text extracted from it) may be sent to OpenAI’s API to identify fields such as merchant, date, and amount. This powers match suggestions; the extracted fields are stored with your receipt record. Do not upload documents you are not authorized to process through a third-party provider. Suggestions are never final — you confirm every match yourself.

We use OpenAI’s API platform, not consumer ChatGPT. Based on OpenAI’s published API data controls as of the Last updated date above, API data is not used to train or improve OpenAI’s models unless the API customer opts in, and API inputs and outputs may be retained by OpenAI for a limited period (currently up to 30 days for most endpoints) for service operation and abuse monitoring before deletion. OpenAI’s policies may change, and its handling of data is governed by its own terms and policies.

Who we share data with

We share data only with the service providers needed to run AuditPacket:

Supabase — database, file storage, and authentication. OpenAI — receipt field extraction, as described above. PayPal — subscription payment processing. PostHog — product analytics, where enabled, to understand usage and improve the service.

We do not intentionally send uploaded receipt images, statement files, generated packet contents, or client financial document contents to product analytics tools.

We may also disclose data if required by law. We do not sell your data or share it for third-party advertising.

Security

We use reasonable safeguards appropriate to a service handling financial documents. Uploaded files are stored in private storage rather than public URLs and are served through short-lived signed links. We use account-level access controls designed to limit access to the appropriate user account, and data is encrypted in transit. No system is perfectly secure, and we can’t guarantee absolute security — which is one reason we recommend keeping your own exports of important packets.

Retention and deletion

While your account is active, your uploaded files and generated reports remain available until you delete them. Deleting a receipt, record, or client removes the associated stored files from active systems.

If your subscription is cancelled, payment fails, or your account is closed, we may retain your uploaded files, generated reports, and workspace data for up to 90 days so you can export your records or reactivate your account. After that period, we may delete the data from active systems. Deleted data may remain in backups or logs for a limited period before being overwritten. You may request deletion sooner by contacting support@auditpacket.com.

Your choices

You can export your PDF packets at any time, delete uploaded files and records from within the product, request account deletion by emailing support, and cancel whenever you like. Transactional emails (signup, password reset) are part of operating your account; if we ever send marketing email, it will include an unsubscribe link.

International users

AuditPacket is operated from the United States, and your data is processed in the United States by us and our service providers. If you use the service from outside the U.S., you understand and agree that your data will be transferred to and processed in the U.S., which may have different data-protection rules than your location.

Children

AuditPacket is a business tool and is not intended for children under 13 (or the applicable local age threshold). We do not knowingly collect data from children.

Changes to this policy

If this policy changes materially, we’ll update the date at the top of this page and, for significant changes, notify account holders by email. Continued use after a change means you accept the updated policy.

Contact

Questions about privacy or your data: support@auditpacket.com

See also: Terms of Service