Expense Proof

Velzev Inc.

Privacy Policy

Effective and last updated: August 20, 2026

No sale of personal informationWe do not sell personal information or use it for third-party advertising.
You control your accountYou may access, correct, export, or request deletion of your information.
Protected by designWe use safeguards designed to protect financial and receipt information.

This policy explains how Velzev Inc. (“Velzev,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal information when you use Expense Proof on Android or the web, or contact us.

1. Who we are and scope

Velzev Inc. operates Expense Proof, a receipt-processing and expense-management service. This policy applies to the Expense Proof mobile app, website, account-deletion service, related APIs, communications, and support. Our Privacy Officer is responsible for our privacy program. Contact details are in section 16.

2. Information we collect

CategoryExamples
Account and identityFirst and last name, email, password hash, email-verification status, sign-in provider identifiers, profile image, internal user ID, and account status. We do not store your plain-text password.
Receipts and expensesReceipt photos and PDFs; merchant, date, items, subtotal, tax, tip, total, currency, exchange rate, payment method, category, notes and corrections; OCR and AI-extracted text; file hashes and processing status.
Expense UnitsUnit names, membership, roles, invitations, invite codes, and receipts or reports you choose to share with members.
Preferences and securityLanguage, theme, accounting country, region and currency, active unit, filters, two-factor authentication settings, session and authentication-token records.
Purchases and creditsGoogle Play and RevenueCat product and transaction identifiers, purchase or refund status, price, currency, country, tax and commission information, credits granted or reversed, and pseudonymous account references. We do not receive or store complete payment-card or bank details.
Technical and diagnosticIP address, user agent, device or session identifiers, platform, push-notification token, request time and route, app errors, status codes, and diagnostic context or stack information.
CommunicationsMessages and information you provide when requesting support, reporting a problem, or making a privacy request.

Please avoid including sensitive information in a receipt, note, or support message unless it is necessary for your use of Expense Proof.

3. How we collect information

  • From you: when you register, upload or edit a receipt, join an Expense Unit, purchase credits, change settings, or contact us.
  • Automatically: authentication, security, device, request, notification, and diagnostic information required to operate and protect the service.
  • From service providers: for example, Google may provide sign-in and purchase information, and RevenueCat may provide validated purchase and refund events.

4. How we use information

We use personal information only for identified and reasonable purposes, including to:

  • create, verify, secure, and administer your account;
  • process receipts, extract and organize expenses, and generate reports;
  • provide collaboration features you choose to use;
  • verify purchases, grant or reverse credits, handle refunds, and prevent fraud or duplicate fulfillment;
  • send account, security, deletion, purchase, and service notifications;
  • provide support, diagnose errors, monitor reliability, and improve features;
  • protect users and meet legal, tax, accounting, and regulatory obligations.

Depending on the context, we process information with your consent, to provide the requested service, to meet legal obligations, or for legitimate security and operational purposes permitted by law. You may withdraw consent where applicable, subject to legal or contractual restrictions; some features may then become unavailable.

5. When information is disclosed

We do not sell personal information and do not share it for cross-context behavioural advertising. We may disclose only what is reasonably needed to:

  • Service providers: infrastructure, database, storage, email, notification, authentication, AI receipt-processing, billing-validation, error-monitoring, and security providers that process information for us.
  • Expense Unit members: people you intentionally share a unit, receipt, or report with can see the shared information and your role.
  • Legal and safety purposes: where required by law or reasonably necessary to protect rights, safety, users, or the service.
  • Business transaction: in a proposed financing, reorganization, sale, merger, or transfer, subject to appropriate safeguards.

6. AI-assisted receipt processing

Expense Proof uses OpenAI’s API to help read receipt images and documents and structure their contents. The receipt and related processing instructions may be sent to OpenAI solely to provide this feature. Extracted results may be inaccurate, so review them before relying on them. We do not use receipt contents for third-party advertising.

7. Google Play purchases and RevenueCat

Google Play processes payment instruments and provides the purchase interface. RevenueCat helps validate purchase and refund events. Expense Proof receives transaction metadata needed to deliver or reverse credits and maintain financial records; it does not receive your complete card or bank-account details. Deleting your Expense Proof account does not automatically cancel a Google Play subscription if subscriptions are offered; subscriptions are managed in Google Play.

8. International processing

Velzev is based in Canada. Some providers may process information in Canada, the United States, or other countries, where it can be subject to local laws and lawful-access rules. Before using providers outside Quebec, we assess relevant privacy factors and use contractual, organizational, and technical safeguards appropriate to the information and purpose.

9. Retention

  • Account and receipts: retained while your account is active or until you delete the record, then removed under our deletion process and backup lifecycle unless law requires otherwise.
  • Deletion requests: operational request records are generally removed within 90 days after completion.
  • Financial records: limited, pseudonymized purchase, refund, tax, and compliance records may be retained for up to seven years after the relevant purchase or later refund for legal, accounting, audit, fraud-prevention, or tax purposes.
  • Security and diagnostics: kept only as long as reasonably necessary to secure, diagnose, and operate the service or meet legal obligations, then deleted or de-identified.

Retention may be extended for an investigation, dispute, legal hold, or enforcement matter.

10. Security

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encrypted network connections, restricted access, password hashing, authentication controls, transaction verification, and monitoring. No system is completely secure. Use a unique password, protect your device, and contact us if you suspect unauthorized access.

11. Your choices and rights

Subject to applicable law, you may request access to or correction of your personal information, information about its use and disclosure, withdrawal of consent, deletion, or eligible information in a structured and commonly used technological format. You may also challenge our compliance by contacting our Privacy Officer. You can update profile and preference information in the app. We may verify your identity before responding. If you are not satisfied, you may contact the Office of the Privacy Commissioner of Canada or the Commission d’accès à l’information du Québec, as applicable.

12. Account and data deletion

In the app, go to Settings → Security → Danger Zone → Delete account. You can also request deletion without reinstalling the app through our public page. We may require identity reconfirmation to protect your account.

Deletion disables the account and removes profile, authentication, receipt, photo, file, preference, membership, notification-token, and operational credit information. You may first need to transfer ownership of a shared Expense Unit. Limited financial records described in section 9 are detached from the live account and retained in pseudonymized form where legally necessary.

Request account deletion

13. Children

Expense Proof is intended for adults and is not directed to anyone under 18. We do not knowingly collect personal information from a person under 18. If you believe a minor provided information, contact our Privacy Officer so we can take appropriate action.

14. Permissions, notifications, and browser storage

Mobile permissions such as camera, photo or file access, notifications, and biometric authentication are used only for the feature you choose and as described by the operating system. You can change permissions in device settings, although some features may stop working.

The web app may store an authentication token, language, theme, and preferences in browser storage to keep you signed in and remember your choices. We do not use advertising cookies. Servers may receive the standard request and security information described above.

15. Changes

We may update this policy when our practices, services, or legal obligations change. We will post the revised policy here, change the date, and provide additional notice where required. Material changes will not be applied retroactively without any consent required by law.

16. Contact the Privacy Officer

Privacy Officer, Velzev Inc.
Email: support@expenseproof.app

Please write “Privacy Request” in the subject line and describe your request. We will respond within the period required by applicable law.