Privacy Policy
Last updated 08 September 2026
Outlay files your receipts and turns them into expense records. This page says plainly what we hold, why we hold it, and who else sees it. If something here is unclear, ask us before you sign up.
What we store
- Your account. Email address, name, and a hash of your password. If you sign in with Google, we store your email and name from that account, never your Google password.
- Your receipts. The files you upload or forward, and the details read from them — merchant, date, amount, tax, category. Files are held in encrypted object storage.
- Where a receipt came from. If it arrived by email we record the sending address, so you can see who sent a bill before approving it and block anyone you did not expect.
- Your workspaces. Who is a member, their role, and which expenses belong to which ledger.
Google Drive
Connecting Google Drive is optional. When you connect it, we ask Google for one narrow
permission — drive.file — and nothing else.
- We create a single folder in your Drive and copy your approved bills into it.
- We cannot see anything else in your Drive. That is not a promise about our conduct; it is the permission Google gives us. Files we did not create are invisible to this app.
- We store the token Google gives us, encrypted, so backups keep working. We never store your Google password.
- Disconnecting stops new copies immediately and deletes the stored token. Files already in your Drive stay yours and are untouched.
Outlay's use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and we do not sell it.
Email forwarding
Each account gets a private address for forwarding receipts. Mail sent there is read only to file the attachment as an expense. Mail with no attachment is kept briefly — that is how a mailbox confirmation code reaches you — and then discarded. You can block any sender from your settings.
Bank connections
If you connect a bank account, it is done through Plaid. Your banking credentials go to Plaid and never to us. We receive transaction records so they can be matched against your receipts.
Who else sees your data
Only the services that make the product work, and only what each one needs:
- Extraction. The text of a receipt is sent to our AI provider to read the amounts off it. It is not used to train their models.
- Email delivery. SendGrid receives forwarded mail and passes it to us.
- Hosting and storage. Render runs the application; Neon holds the database and encrypted files.
- Banking. Plaid, only if you connect an account.
We do not sell your data, and we do not share it with advertisers. Nobody outside your workspace can see your expenses.
Keeping and deleting
Your data stays while your account is open, because an expense ledger is only useful as a record. Ask us to delete your account and we remove your receipts, extracted data and connected integrations. Copies already written to your own Google Drive are in your hands, not ours.
Security
Traffic is encrypted in transit. Files are held in encrypted storage. Access tokens and card details are encrypted at rest. Passwords are hashed with Argon2 and are not recoverable by us.
Contact
Questions, or a deletion request: support@outlay.site.
If this policy changes we will update the date at the top. Material changes to how we handle your data will be told to you directly, not buried here.