Privacy Policy
Last updated: June 2, 2026
Receiva is an offline-first progressive web app (PWA) that runs entirely inside your browser. It has no application backend that receives or stores your data.
This policy explains, in the categories required by the Google API Services User Data Policy, how Receiva accesses, uses, stores, shares, retains, and deletes Google user data, as well as how it handles the rest of your data.
1. Who runs Receiva
Receiva is published by Shawn Lewis. Questions, data-deletion requests, and complaints can be sent to [email protected].
2. How Receiva handles Google user data
Receiva uses Google Identity Services for sign-in. Google account access is entirely optional and is requested only if you choose to sign in. When you do, Receiva requests the following OAuth scopes:
https://www.googleapis.com/auth/gmail.sendhttps://www.googleapis.com/auth/drive.filehttps://www.googleapis.com/auth/userinfo.email
Data Accessed
With your authorization, Receiva accesses only the following Google user data:
- The ability to send email on your behalf (
gmail.send). This scope lets Receiva submit an outgoing message to Gmail. It does not grant the ability to read, list, search, modify, label, or delete any message in your mailbox. Receiva never accesses your inbox or any existing Gmail content. - Files in your Google Drive that Receiva itself creates (
drive.file). This scope is restricted to files the app creates or that you explicitly open with it. Receiva cannot see, list, read, or modify any other file in your Drive. - Your Google account email address (
userinfo.email). Used to show which account is signed in and to set the "from" address on receipts you send.
Data Usage
Each scope is used solely to perform the specific, user-initiated action it is needed for:
- Gmail send is used only when you choose to send a receipt. Receiva composes the receipt you created and sends it, from your own Gmail address, to the recipient you specified. It is not used for any other purpose.
- Drive file is used only when you choose to back up or restore your data. Receiva uploads a backup copy of your local database to your Drive, and reads it back when you restore.
- Email address is used only to display the signed-in account and to label the sender of the receipts you send.
Receiva does not use Google user data for advertising, profiling, analytics, or training machine-learning models.
Data Sharing
Receiva does not sell, rent, or share your Google user data with any third party. Specifically:
- Receipt emails are delivered only to the recipient address you enter, sent from your own account.
- Backup files are written only to your own Google Drive.
- No Google user data is transmitted to Receiva, its developer, advertisers, data brokers, or any analytics provider — there is no server in the path to receive it.
Data Storage & Protection
- The OAuth access token Google issues at sign-in is held only in your browser — in memory during use, and mirrored to your browser's
localStorageso the session survives a page reload. It is never transmitted to, or stored on, any server operated by Receiva. - All calls to Google APIs (Gmail and Drive) are made directly from your browser to Google over HTTPS/TLS. Receiva operates no backend that receives, proxies, or stores this data.
- Your business data (clients, catalog, personnel, receipts, settings) is stored locally on your device in an in-browser SQLite database persisted to the Origin Private File System (OPFS), which is sandboxed to the app's origin by your browser.
- Receiva is served exclusively over HTTPS.
Data Retention & Deletion
- Receiva retains no Google user data on any server, because it operates none. There is nothing for us to retain or delete on your behalf.
- The access token is short-lived (it expires on the schedule Google sets) and is discarded when you sign out, when it expires, or when you clear site data.
- Receipts you send live in your own Gmail "Sent" mail, and backups live in your own Google Drive — both under your control, deletable directly in those Google products.
- To delete data and revoke access: sign out in the app (clears the stored token); clear your browser's site data for the app or uninstall the PWA (removes the local database and token); delete any Receiva backup files from your Google Drive; and revoke Receiva's access to your Google account at myaccount.google.com/permissions. For help, email [email protected].
Limited Use
Receiva's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google APIs is used only to provide the user-facing feature you invoked, is not transferred to others except as needed to provide that feature (and never to data brokers or for advertising), and is not read by humans except with your explicit consent, where required for security, or to comply with applicable law.
3. Other data Receiva processes on your device
- We run no analytics, telemetry, advertising, or tracking pipeline, and set no tracking cookies.
- The app uses only browser storage required to run the PWA: OPFS and IndexedDB for the database, the service-worker cache for offline operation, and a small amount of
localStoragefor UI preferences and the Google session token described above. - If you uninstall the PWA or clear your browser's site data, this local data is deleted.
4. Location and reverse geocoding
When you use the GPS "pick nearest client" feature, your device's current latitude and longitude are used to find nearby clients and are sent to OpenStreetMap's Nominatim service (nominatim.openstreetmap.org) to translate the coordinates into a street address. No identifier is attached to that request, and your location is not stored by Receiva or sent to any server we run. See the Nominatim usage policy.
5. Email delivery
Receipts are delivered from your own Gmail account using the Gmail API. The recipient, subject, and body are determined by you. Receiva does not keep a copy of outgoing mail on any server it operates.
6. Children's privacy
Receiva is a business tool intended for adults and is not directed to children under 13.
7. Changes to this policy
Material changes will be reflected on this page with a new "Last updated" date. Continued use of Receiva after a change constitutes acceptance of the revised policy.
8. Contact
Privacy questions, data-deletion requests, or help revoking Google access can be directed to [email protected].
