Gmail & privacy

We only read your receipts. Nothing else.

When you connect Gmail to xpensli, we use a two-step filtering system to find receipt emails. Personal emails, newsletters, and social notifications don't pass the first check, so they are never fetched or read at all. Anything that does get fetched and then turns out not to be a receipt is shown to you to confirm and delete — we never quietly throw away something that might have been yours. There is exactly one time we look beyond that filter — when you ask us to go find a receipt we missed. That is described below.

How the filtering works

What happens when an email arrives:

Step 1 — The signal check

Gmail notifies xpensli that a new email has arrived — just a ping, no content. We check the sender's domain and subject line against a list of known receipt patterns. If it doesn't look like it could be a receipt, we stop here. The email is never fetched or read.

Step 2 — The AI receipt check

If an email passes the first check, an AI classifier reads the email to confirm it's actually a receipt — an order confirmation, invoice, subscription charge, or payment confirmation. If it doesn't pass, we don't delete it on the AI's say-so: it goes into your review queue marked “not a receipt” so you can delete it or keep it. Classifiers get things wrong, and we would rather show you a receipt you have to dismiss than silently destroy one you needed.

Step 3 — Receipt processing

Only emails that pass both filters are processed by xpensli. The vendor, amount, date, and category are extracted and saved to your account. We also keep the email itself alongside the receipt, so you can open the original and so your accountant gets a verifiable document rather than a number we typed. It is kept for as long as you keep that receipt: delete the receipt and it goes with it, delete your account and all of it goes.

When you ask us to find a missing receipt

No filter is perfect. If a receipt didn't arrive, the “Missing a receipt?” panel in your dashboard lets you ask us to go and look for it. This is the one path where we see mail that didn't pass the filters above, so here is exactly what happens:

  • You start it, every time. Nothing is searched unless you fill in the form and press Search.
  • We see the sender, subject line and date. Nothing else. No message bodies, no attachments — not for any result, including ones that aren't receipts.
  • A one-week window. You tell us roughly when, and we look at the week around it, no further.
  • Nothing about the search is saved. Not what you typed, not what came back. We show you the results and keep none of them.
  • You choose what gets filed. A result becomes a receipt only when you say it is one. Everything else is discarded when you close the panel.
  • Three searches a day. It's a recovery tool, not a way to browse your mailbox, and the limit is what keeps it that way.
  • Bounded by your plan. We can only search back as far as the period your plan covers.

What we access

xpensli reads this

  • Receipt emails
  • Order confirmations
  • Subscription charges

xpensli ignores this · never stored

  • Personal emails
  • Newsletters
  • Social notifications
  • Spam
  • Attachments on non-receipts

Automatic processing only. If you ask us to find a missing receipt, we see the sender, subject and date of the results — described above — and still store none of it.

You're always in control

Disconnect anytime

You can disconnect Gmail at any time from your Settings page. xpensli immediately stops monitoring your inbox. No emails are fetched after disconnection.

Delete your data

You can request deletion of all your receipt data at any time. Visit our data deletion page for instructions.

Review what we've captured

Every email xpensli has processed is visible in your receipt list. You can view, edit, or delete any receipt at any time.

Technical details

xpensli connects to Gmail using the following OAuth scopes:

  • gmail.readonly — read-only access to fetch emails that pass our receipt filters, and to run the searches you start yourself when a receipt is missing
  • gmail.modify — used only to label processed receipt emails in your inbox (optional feature)

We do not request access to send emails, delete emails, manage contacts, or access Google Drive or other Google services.

Our Gmail integration is reviewed and approved by Google. View our Privacy Policy for complete details on data handling and retention.

Have questions?

If you have any questions about how xpensli handles your Gmail data, we're happy to help. Email us at privacy@xpensli.app or visit our help center.

This page describes xpensli's Gmail data practices as of the date of last update. For complete privacy information, see our Privacy Policy.