🛡️ Security & Data Governance

Privacy & Security Policy

Last updated: September 2026 · Effective immediately

Key Privacy Guarantees

1. Overview & Thesis

Reclaim (“we”, “our”, or “us”) is designed as a focused, lightweight post-purchase ownership companion. Our product thesis is built around peace of mind: you save important dates (return windows and warranty deadlines) so you never lose money to forgotten expiry dates.

Unlike personal-finance aggregators or coupon extensions, Reclaim does not monetize personal financial histories, sell advertising profiles, or scan your external financial life.

2. Data We Collect

We only collect the data you intentionally supply to deliver the service:

  • Account Credentials: Your email address and optional display name.
  • Purchase Records: Item title, merchant/store name, purchase date, price, currency, category, order numbers, serial numbers, and personal notes.
  • Deadlines: Return dates, warranty expiry dates, and service milestones.
  • Proof of Purchase Documents: Invoices or receipts you choose to upload (JPG, PNG, WebP, or PDF).

3. What We Never Collect

To maintain a clean boundary of trust, Reclaim explicitly avoids unnecessary integrations:

  • We do not connect to bank accounts, UPI apps, or credit card feeds.
  • We do not require or request OAuth access to scan your email inbox.
  • We do not store payment card numbers (all subscription billing is processed through authorized payment gateways).
  • We do not sell user data to credit bureaus, ad brokers, or retailers.

4. Permanent File Deletion & Zero Retention

Our Guarantee: No Retention of Deleted Documents

When you delete an individual receipt, image, or entire purchase record from Reclaim, the underlying files are immediately and permanently erased from our private object storage bucket. We do not retain backup cache files, thumbnail duplicates, or shadow copies of your receipts once you trigger deletion.

If you choose to delete your Reclaim account, all associated purchases, deadlines, documents, and reminders are cascaded and permanently purged from the database.

5. Security & Encryption

All data is stored in modern cloud infrastructure using enterprise-grade encryption both in transit (TLS 1.3) and at rest (AES-256):

  • Row-Level Security (RLS): Every database query is scoped directly to the authenticated user ID via PostgreSQL Row-Level Security.
  • Private Storage: Document buckets are not publicly accessible on the web. Access is mediated through short-lived signed URLs generated exclusively for your authenticated session.

6. Reminder Notifications

We adhere to a strict “quiet by default” policy. Notifications are triggered solely according to your deadlines (e.g. 7 days and 1 day prior to return expiry, or 30 days and 7 days prior to warranty expiration). You can disable or customize reminder schedules anytime from your dashboard.

7. Infrastructure & Service Providers

To provide high availability and secure operations, we utilize trusted managed providers:

  • Database & Authentication: Supabase (PostgreSQL with RLS).
  • Object Storage: Supabase Storage / Cloudflare R2 (Private storage with signed access).
  • Transactional Emails: Resend (DKIM/SPF-verified notification delivery).

8. Your Rights & Data Export

Under applicable privacy laws (including India's Digital Personal Data Protection Act and GDPR principles), you have the full right to:

  • Request a full export of your purchase history and deadline metadata.
  • Modify, correct, or delete any record at any time.
  • Request full account termination and total erasure of all records.

9. Contact Us

If you have any questions regarding your data privacy, security, or wish to request data deletion, please contact our team:

Email: privacy@reclaimapp.in