Privacy Policy
Last updated: 19 July 2026
This policy describes what Reimburser (reimburser.in) collects, why, and what we deliberately avoid collecting. The short version: we collect very little, we never see payment credentials, and money never passes through us.
1. What we collect
- Creators: your Google account email and name (via Google sign-in — we never see or store a password), the profile you set up (display name, bio, photo/emoji), the expenses you choose to publish, and the payment details you choose to display (e.g. a UPI ID or PayPal link).
- Supporters: no account is required. We store the name you type with a contribution (any nickname works), the amount, and an optional message. If you attach a payment reference or screenshot, it is visible only to the creator you supported and is deleted once they resolve the claim.
- Anti-abuse signals:we store a salted, one-way fingerprint derived from a submission’s network address to recognise repeat senders and enable blocking. Raw IP addresses are not stored with contributions.
2. The Reimburser Android app & notification access
The optional Reimburser Android app can automatically turn your own payment activity into expense drafts. To do this, with your explicit permission, it uses Android’s notification-access feature to read bank and payment alerts on your device — including the SMS that banks and payment apps (such as UPI apps) send when you make a payment, which are the primary way these alerts are delivered in India.
- The app acts only on payment and transaction alerts. Personal messages, chats, and one-time passwords (OTPs) are ignored on your device and are never uploaded or stored.
- Alerts are parsed on your device. Only the amount and a short, cleaned description of a debit are sent to your Reimburser account — the raw message, your other notifications, and your account balances are never transmitted.
- Every captured item is a draft you review before it appears publicly.
- The feature is entirely optional and off until you enable it, and you can revoke notification access at any time in your phone’s settings, or by uninstalling the app.
3. What we never collect
Bank passwords, card numbers, CVVs, OTPs, or wallet private keys — never. Payments happen in your own payment app, directly with the creator; payment credentials never touch our systems.
4. How information is used
To operate the platform: showing creator pages, recording and verifying contribution claims, preventing spam and abuse, and contacting you about your account. We do not sell personal data, run advertising, or share data with third parties except the service providers below.
5. Service providers
We use Vercel (hosting), Neon (database), Google (sign-in), and Vercel Blob (image storage). Each processes data only as needed to run the platform.
6. Public information
A creator’s public page shows what they chose to publish: display name, bio, published expenses, enabled payment options, and verified supporter names/amounts. Unpublished drafts and hidden expenses are visible only to the creator.
7. Retention and deletion
- Payment screenshots are deleted automatically once a claim is verified or rejected.
- Rejected contribution records are purged automatically after a short period.
- Creators can delete expenses and payment methods anytime, and can request full account deletion via the contact page — we honour such requests within 30 days.
8. Contact
Privacy questions or deletion requests: see the contact page at reimburser.in/contact.