Privacy Policy

Last updated: December 2024

At Recappp, your privacy is our priority. This policy explains what data we collect, how we use it, and your rights regarding your information.

Quick Summary

  • We only access Gmail to read transaction receipts — we never read personal emails
  • Health data stays on your device and is never sent to our servers
  • We never sell, share, or monetize your personal data
  • You can export or delete all your data at any time

Data We Collect

Gmail Data (with your permission)

We request read-only access to your Gmail to find transaction receipts and booking confirmations. We specifically search for emails from known merchants, airlines, and booking platforms.

  • • Transaction receipts (Amazon, Uber, DoorDash, etc.)
  • • Flight booking confirmations
  • • Hotel and travel bookings

Health Data (optional, on-device only)

If you choose to connect Apple Health or Google Health Connect, we read steps, distance, and activity data. This data is processed locally on your device and used only to generate your health recap visualizations.

Photos (optional, on-device only)

If you grant photo access, we analyze photo metadata (dates, locations) to create memory highlights. Photos are never uploaded to our servers.

Account Information

When you sign in with Google, we receive your name, email address, and profile picture to create your account.

What We Don't Collect

  • Personal email content, conversations, or attachments
  • Contact lists or address books
  • Calendar events or schedules
  • Actual photo files (only metadata)
  • Bank account credentials or financial login information

How We Use Your Data

We use your data exclusively to:

  • • Generate your monthly and yearly recaps
  • • Create spending insights and category breakdowns
  • • Track travel patterns and destinations
  • • Visualize health and fitness trends
  • • Curate photo memory highlights

We do not use your data for advertising, profiling, or any purpose other than providing you with your personal recaps.

Data Security

We implement industry-standard security measures:

  • AES-256-GCM encryption for all stored data
  • TLS 1.3 for all data in transit
  • • OAuth 2.0 tokens encrypted and stored securely
  • • Regular security audits and monitoring
  • • No plain-text storage of sensitive information

Data Retention

We retain your data for as long as you maintain an active account. When you delete your account or request data deletion:

  • • Account data is deleted immediately
  • • OAuth tokens are revoked within 24 hours
  • • Processed recap data is deleted within 7 days
  • • Backups are purged within 30 days

Your Rights

You have full control over your data:

  • Access: View all data we have about you
  • Export: Download your data in standard formats
  • Correct: Update inaccurate information
  • Delete: Remove all your data permanently
  • Revoke: Disconnect data sources at any time

To exercise these rights, visit Settings → Privacy in the app or contact us at support@recappp.app.

Google API Services Disclosure

Recappp's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  • • We only request scopes necessary for core app functionality
  • • We do not use Google user data for advertising
  • • We do not allow humans to read user data except for support (with consent)
  • • We do not sell Google user data to third parties

Third-Party Services

We use limited third-party services:

  • Google OAuth: For secure authentication
  • Cloud hosting: For secure data storage
  • Analytics: Anonymous usage statistics only

We do not share your personal data with advertisers, data brokers, or any other third parties for commercial purposes.

Contact Us

For privacy-related questions or concerns:

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by email or through the app. Continued use of Recappp after changes constitutes acceptance of the updated policy.