Privacy Policy
Last updated: July 29, 2026
1. Controller and definitions
The data controller for the Service is QuickBits OÜ, a company registered in Estonia (registry code: 16725805, registered address: Sääse 14-40, 12918, Tallinn, Estonia).
In this Privacy Policy:
- Controller, we, us, or our means QuickBits OÜ.
- Service refers to the website expensicat.com, the web and mobile applications, the API, the command-line interface, and related software and tools.
- Personal Data means any information relating to an identified or identifiable natural person.
2. Information we collect
We collect the following categories of Personal Data:
- Account & Profile Data: Name, email, company name, billing address, authentication records, locale and currency preferences.
- Financial & Transaction Data: Connected bank account details, transaction history, invoices, quotes, receipts and uploaded documents.
- Content You Submit: Messages to Cat, notes, tasks, and files you upload.
- Technical & Usage Data: IP address, device identifiers, browser type, server logs, and error reports.
- Cookies & Analytics Data: Limited analytics data collected with your consent (see our Cookie Policy).
- Third-Party Data: Data from integrations you authorize, such as Gmail and bank providers.
3. How we collect your data
- Directly from You: When you register, upload documents, connect financial accounts, use Cat, or contact support.
- Automatically: Through server logs and, with consent, analytics.
- From Third Parties: Gmail, open-banking providers, and other integrations you enable (see Sections 8 and 9).
4. Purposes and legal bases for processing
For users in the EEA, we rely on the following legal bases under Article 6 GDPR:
| Purpose | Legal Basis |
|---|---|
| Providing, maintaining and securing your account and the Service | Performance of a contract |
| Processing your financial data, invoices and documents | Performance of a contract |
| AI features (receipt transcription, Cat responses, search) | Performance of a contract |
| Billing and payment | Performance of a contract |
| Security alerts and essential service communications | Legitimate interests (securing the Service and preventing abuse) / legal obligation |
| Product analytics and improvement | Consent |
| Retaining financial records | Legal obligation (tax and accounting law) |
Providing your account and financial data is necessary to use the Service; without it, we may be unable to provide some or all features.
For California residents, we process Personal Data for the business purposes described above. We do not sell your Personal Data.
5. Sharing and disclosure
We may share Personal Data with:
- Sub-processors: Hosting, AI, email, analytics, and support providers acting on our instructions under data processing agreements. Our current list is published at Sub-processors.
- Open-banking providers: When you connect a bank account, a licensed account information service provider acts as an independent data controller for the account data it retrieves (see Section 9).
- Affiliates: QuickBits OÜ affiliates for internal business purposes under the same standards.
- Legal Authorities: To comply with applicable law, subpoenas, or enforceable governmental requests.
- Business Transfers: In a merger, acquisition, or sale of assets, subject to confidentiality safeguards.
We do not sell your Personal Data.
6. Sub-processors
We use vetted third-party providers to operate the Service, including hosting, AI processing, email, and analytics. We maintain a current list, with each provider's purpose and location, at expensicat.com/legal/subprocessors. We require each sub-processor to provide protection consistent with this Policy and applicable law. If you use the Service as a business customer, our processing of Personal Data on your behalf is governed by our Data Processing Addendum.
7. AI and automated processing
Core features of the Service use third-party models to read documents, power Cat, and create semantic search embeddings. The active providers are listed on our Sub-processors page. When you use these features, we send the content needed for that task, such as a receipt image or your message, to the relevant provider. We do not use your content to train general-purpose AI models.
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing without human involvement.
8. Google Workspace and Gmail
When you connect Gmail, we request read-only access to Gmail messages and attachments, plus your basic Google profile and email address. This access does not let Expensicat send, change, or delete your email.
We use Gmail data to identify potential receipts and invoices, prevent duplicate imports, and place selected documents in your workspace for review. Mistral processes the attachments under consideration and relevant email metadata to identify financial documents and extract structured data. Selected attachments and metadata are then stored with your financial records.
Disconnecting Gmail removes the local connection credentials and stops future imports. Expensicat also attempts to revoke the Google token. Documents already imported into your workspace remain until you delete them or your account, subject to the financial-record retention requirements in Section 10.
Our use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to train general-purpose AI models.
9. Bank connections
When you connect a bank account, you authorize GoCardless, a licensed account information service provider (AISP), to retrieve account and transaction information. GoCardless acts as an independent data controller for that data under PSD2 and its own privacy notice. Access is read-only. Expensicat cannot move funds. You can revoke access from your account settings or with your bank.
10. Data retention
We keep Personal Data only as long as necessary for the purposes described, then delete or anonymize it:
- Account data: For the life of your account and up to 30 days after deletion, except where longer retention is required by law.
- Financial records: At least seven (7) years to meet tax and accounting obligations.
- Backups: Residual copies may remain until the hosting provider's backup cycle expires.
- Analytics data: For up to 14 months.
11. International data transfers
QuickBits OÜ is established in the EEA. Where Personal Data is transferred outside the EEA (for example, to AI or hosting providers in the United States), we rely on the European Commission's Standard Contractual Clauses or an applicable adequacy decision.
12. Data security
We implement technical and organizational measures including:
- Encryption: HTTPS/TLS in transit, provider-managed encryption for stored data, and AES-256-GCM for integration secrets.
- Tenant Isolation: Storage uses row-level security. Other tenant data is protected by server-side authorization and organization-scoped database access.
- Access Controls: Least-privilege access and authenticated sessions.
- Monitoring: Error tracking and automated dependency, secret, static-analysis, configuration, and release-image security checks.
More detail is available on our Security page.
13. Your rights
EEA and UK residents (GDPR / UK GDPR): You have the right to access, rectify, erase, restrict, port, and object to the processing of your Personal Data, and to withdraw consent at any time. To exercise these rights, contact us at hello@quickbits.io.
You also have the right to lodge a complaint with your local supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee); UK residents may contact the Information Commissioner's Office (ICO).
United States residents: Depending on your state (for example, California, Virginia, Colorado, Connecticut, and Texas), you may have the right to know, access, correct, delete, and opt out of the "sale" or "sharing" of Personal Data. We do not sell your Personal Data, and we honor Global Privacy Control (GPC) browser signals as an opt-out of sharing. To make a request, email hello@quickbits.io.
14. Children's privacy
The Service is intended for business use by individuals who are at least 18 years old. It is not directed to children, and we do not knowingly collect Personal Data from minors. If we learn that we have collected such data, we will delete it.
15. Changes to this policy
We may update this Policy for legal or operational reasons. Material changes will be posted with a new effective date and notified via email or in-app alert before they take effect.
16. Contact us
Email: hello@quickbits.io