Effective August 8, 2026
Privacy Policy
Citrus Receipts is a private receipt-management service operated by Salient Vision Technologies, LLC. This policy explains what Citrus handles, why it is needed, and the controls available to you.
Information Citrus handles
Citrus handles receipt images and details that you submit, account identifiers needed to provide your Citrus sessions, and operational information needed to keep the service reliable and secure.
Knomee identifies your primary receipt-library session. Firebase Authentication separately identifies who may control Email connections. Citrus does not merge identities merely because they use the same email address.
Google user data
If you choose Connect Gmail, Citrus requests read-only Gmail access. Citrus uses that access to search a bounded set of messages likely to contain receipts, retrieve the message data needed to identify and parse those receipts, and show you the resulting receipt-discovery report.
Citrus cannot use this permission to send, edit, or delete Gmail messages. The current dry-run processes message data in memory and writes no email source, intake, receipt, or sync-cursor rows. Citrus stores connection status and an encrypted OAuth refresh token on the backend so access can continue until you revoke it or Google invalidates the grant.
How information is used
Citrus uses your data only to provide, secure, maintain, and improve the receipt features you choose. Google user data is not used for advertising, sold, or used to train general-purpose artificial intelligence models.
Citrus uses Google user data in accordance with the Google API Services User Data Policy, including its Limited Use requirements.
Sharing and human access
Citrus does not sell Google user data. Data may be processed by infrastructure providers only as needed to operate and secure Citrus, or disclosed when legally required. People do not inspect Gmail message content except when you ask for support, when access is necessary to investigate abuse or a security incident, or when required by law.
Retention, security, and deletion
Citrus uses encrypted transport and stores Gmail refresh tokens encrypted on the backend. No security method is perfect, but access is restricted to the connected Citrus owner and the services needed to operate the feature.
Use Revoke Gmail access on the Citrus Email page to revoke the Google grant and remove the local Gmail capability. You can also revoke Citrus from your Google Account permissions. Contact malone@salient.vision to request deletion of Citrus-held account or connection data.
Changes and contact
Citrus will update this policy before materially changing how Google user data is accessed, used, stored, or shared. Questions and privacy requests can be sent to malone@salient.vision.
Google API Services User Data Policy · Google Account permissions