Draft — not yet reviewed. This page is drafted from Snap Apps' own internal engineering and product records. It has not been reviewed or approved by a qualified Australian legal practitioner and must not be relied on, published, or presented to a customer as final until that review is complete.

Privacy Policy

Draft — last updated 12 September 2026

Snap Apps ("we", "us") provides receipt capture, extraction, ledger, and Australian tax export services to Australian sole traders, tradies, and the accounting and bookkeeping practices that act for them. This policy explains what personal and financial information we collect, why, where it is processed and stored, and the rights you have over it under the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth).

1. What we collect

  • Account information: name, email, business/ABN details if you operate a business workspace, and your chosen occupation profile if you use the deduction tools.
  • Receipt and invoice images you capture, plus the financial data extracted from them: supplier names and ABNs, amounts, GST, line items, and dates.
  • Ledger and tax data derived from your confirmed transactions, including BAS figures calculated from them.
  • Connection data if you connect Xero or another accounting platform — an authorisation token, not your Xero password.
  • Usage and device data needed to operate and secure the service, such as sign-in events and error diagnostics.

We do not collect or store full card numbers. Receipts that show a masked card number have it reduced at the point of capture to only the last four digits and the card brand — see Data handling & security. We do not collect device location from your receipt photos: GPS metadata is stripped from the copy used for processing and is never indexed.

2. Why we collect it

To extract and validate the data on your receipts, maintain your ledger, calculate your BAS and deduction figures, sync confirmed transactions to Xero if you choose to connect it, bill your plan, and secure your account. We do not use your financial data to sell you advertising, and we do not sell it to third parties.

3. Where your data is processed

Your data is stored in Australia (AWS ap-southeast-2, Sydney). The model that reads your receipts also runs in that region, on purpose: keeping extraction in Sydney avoids sending your financial records overseas to get a receipt read, which is otherwise a cross-border disclosure under APP 8. Where a provider outside Australia is used during development or as a fallback, this is disclosed to you separately and is not used for production processing of your data without that disclosure.

Where our AI provider is Anthropic, Anthropic does not train its models on data submitted via its API.

4. Who we share it with

  • Xero, or another accounting platform, only if and when you connect it — and only your posted transactions and their receipt images, not your whole account.
  • The Australian Business Register, to confirm a supplier's ABN and GST registration status. This is a lookup of public business information, not a disclosure of your own data to the Register.
  • Infrastructure and processing providers (cloud hosting, storage, and the AI provider described above) who process data on our behalf under contract, and are not permitted to use it for their own purposes.
  • Your accounting practice, if your account is managed under a Practice plan by a bookkeeper or accountant you've engaged.
  • Regulators or law enforcement, where we are legally required to disclose.

5. How long we keep it

Business records are retained for five years from the date they were prepared or the related transaction completed, matching the ATO's record-keeping requirement — see Data retention and deletion. Records are actively removed by an automated process once that period passes, rather than kept indefinitely, consistent with APP 11's requirement to destroy or de-identify personal information no longer needed for a permitted purpose.

6. Security

Financial data is encrypted at rest and in transit, tenant data is isolated so one business's records are never visible to another, and particularly sensitive fields (bank details, Xero tokens) receive additional application-level encryption. Full detail is in Data handling & security.

7. Data breaches

We maintain an audit trail of access to your data so that, in the event of a suspected breach, the scope of what was affected can be established quickly. Where a breach is likely to result in serious harm, we intend to notify affected individuals and the Office of the Australian Information Commissioner (OAIC) within the timeframe required under the Notifiable Data Breaches scheme.

8. Your rights

You can ask us for access to the personal information we hold about you, ask us to correct it, and ask us to delete your account — see Support. Where a record is still inside its mandatory five-year retention window, we can close it out of active use but cannot delete the underlying record until that window passes, because we are legally required to be able to produce it. If you are not satisfied with how we handle a privacy concern, you can complain to the OAIC.

9. Changes to this policy

We will post any material change here and, where practical, notify account holders directly before it takes effect.

10. Contact

For privacy questions or requests, contact Support (see the Support page for current channels).