Privacy Policy
Last updated: 23 August 2026
Direceipt is in development and not yet open to the public. This policy describes how we handle data in the product as it operates today and as features become available to you.
Who we are
Direceipt is operated by Dian Motors Inc., 228 Hunt Club Road, Unit 201, Ottawa, Ontario K1V 1C1, Canada. Contact: privacy@direceipt.ai.
What Direceipt does
Direceipt finds receipts that are missing from your QuickBooks Online records. It connects to your QuickBooks company and to email mailboxes you authorize, imports purchase transactions with no receipt attached, searches those mailboxes for the matching receipt, and — once you approve — attaches the file to the existing QuickBooks transaction.
We never create, edit, categorize, or delete your accounting transactions. QuickBooks remains the system of record.
Information we process
Account information
Your name, email address, and organization membership. Authentication is handled by WorkOS; we do not store passwords.
QuickBooks data
Transaction date, amount, currency, vendor, account coding, document number, memo, and the metadata of files already attached to a transaction. We import only what is needed to identify missing receipts and show them for review.
Email data
For each mailbox you connect, we access messages using Google's
gmail.readonly scope. Access is driven by your accounting data:
for a transaction missing a receipt, we search a bounded date window around
that transaction combined with merchant and receipt-related terms. We retrieve
full message content only for messages that search identifies as candidates.
From those we store:
- the receipt file itself;
- minimized message metadata for provenance — message and thread identifiers, date, subject, and sender;
- fields read from the document — merchant, date, amounts, tax, currency, and the last four digits of a payment card where the receipt shows them.
We do not copy or index your mailbox, store messages unrelated to an identified receipt, or access contacts, calendar, or any other Google service.
Usage and audit records
Every connection change, synchronization, approval, rejection, and attachment is recorded with the acting user and a timestamp. This record is what makes the system auditable. It contains identifiers and summaries — never message content or credentials.
How we use it
Only to provide the service: finding candidate receipts, showing you why a candidate matched, letting you approve or reject it, and attaching approved files to QuickBooks. Plus security, fraud prevention, support, and legal compliance.
We do not sell your data, use it for advertising, or use it to train generalized artificial intelligence or machine learning models.
Google user data
Direceipt's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
- We request read-only Gmail access. We never send, modify, label, or delete mail.
- Gmail data is used only to provide the receipt-matching and attachment features described above.
- Gmail data is not transferred to others except as needed to provide those features, to comply with law, or as part of a merger or acquisition with notice to you.
- Gmail data is not used for advertising and is not sold.
- Gmail data is not used to develop, improve, or train generalized artificial intelligence or machine learning models.
- Humans at Direceipt do not read your email data except with your explicit consent for a specific support request, where required by law, or in aggregated and anonymized form for internal operations.
Who else processes your data
- WorkOS — authentication and identity
- Intuit — the QuickBooks Online integration, at your direction
- Google — Gmail access, at your direction
- Our cloud hosting provider — application hosting, storage, and databases
We will give notice before adding a processor that handles your content. A current list is available on request from privacy@direceipt.ai.
Security
Data is encrypted in transit. Credentials for connected accounts — including OAuth access and refresh tokens — are encrypted at rest with authenticated encryption, and are never written to logs.
Each organization's records are isolated at the database layer, enforced independently of the application, so one customer cannot reach another's data even if application code is wrong.
No system is perfectly secure. We will notify affected users and the Office of the Privacy Commissioner of Canada of any breach creating a real risk of significant harm, as PIPEDA requires.
How long we keep it, and deletion
Disconnecting a connected account revokes its credentials and stops all synchronization immediately. You may request deletion of your stored content at any time by writing to privacy@direceipt.ai, and we will confirm when it is complete.
Audit records are kept longer than content, because they are the accountability record; they contain no message content.
Where your data is held
Data is held with our cloud hosting provider. Some processors may handle data outside Canada; where they do, we rely on contractual protections. Data processed outside Canada may be subject to the laws of those jurisdictions.
Your rights
Under PIPEDA and applicable provincial law you may request access to your personal information, correction of inaccuracies, deletion, a copy in portable form, or withdrawal of consent — which you can do at any time by disconnecting an account. Contact privacy@direceipt.ai; we respond within 30 days.
You may also complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
Children
Direceipt is a business tool, not directed to anyone under 18, and we do not knowingly collect their information.
Changes
We will post changes here and update the date above. Material changes affecting how we handle email data will be notified in advance.
