Home Guides

Are receipt scanning apps safe?

Last updated 25 August 2026

Are receipt scanning apps safe to use?

It depends entirely on where the reading happens. An app that reads a receipt on your device and keeps the result in your own storage exposes very little. An app that uploads receipt photographs to a server, keeps them, and reserves the right to use them commercially is a different product with different risks — even if both are described as "receipt scanning".

What a receipt actually reveals

It's easy to think of a receipt as trivial. A single one mostly is. A year of them is not.

Together they show where you are and when, on a repeating weekly pattern. What you eat and drink, which tells someone about your health. What medication you buy. Which bars you go to and how often. Where you travel. What you buy for children. Whether your spending suddenly changed — the signal that precedes a job loss, a separation, or a diagnosis.

Line items go further than totals. A supermarket receipt read to the item level is a detailed inventory of a household.

This is why "it's just receipts" understates it. Receipt data is behavioural data with timestamps and locations attached, and it is commercially valuable — some apps in this category are built to monetise exactly that, quite openly, by paying you for your receipts and selling the aggregate to market researchers. That's a legitimate business and a fair trade if you know you're making it. The problem is when it isn't clear which kind of app you've installed.

The question that determines everything: where does reading happen?

On-device reading

The photograph never leaves your phone. Text extraction runs locally — on iOS, usually via Apple's Vision framework, which runs the recognition on the device itself. The developer's servers never see the image or the text.

The exposure is limited to your own device and whatever backup or sync you've enabled.

Cloud reading

The image, or the text extracted from it, is sent to a server. That server may be the app developer's, or a third-party OCR or AI provider behind it.

This isn't automatically bad — cloud models read hard receipts better than on-device ones, and there are honest implementations. But it changes the questions you need answered:

  • Is the photo sent, or only the extracted text? Big difference. A photo can contain the last four digits of your card, a loyalty number, sometimes a name.
  • Is it stored, or processed and discarded?
  • Who is the third party, and what are their retention terms?
  • Is it on by default, or does it require your explicit consent?
  • Can you turn it off and go back to local reading?

An app that answers all six clearly is being straight with you. An app whose privacy policy says only "we use industry-standard security" has not answered any of them.

Questions worth asking before you install

Is there an account? An app with a user database can leak a user database. An app whose only identity is your existing Apple or Google account has far less to lose.

Where does the ledger sync? "Syncs across your devices" can mean your own iCloud or Google account, or it can mean the vendor's servers. Only the first keeps the vendor out.

What does the App Store privacy label say? On iOS, check "Data Used to Track You" and "Data Linked to You". A budgeting app that tracks you across other companies' apps is telling you its business model.

Are there third-party analytics or ad SDKs? These are the quiet ones. An app can be honest about its own servers while embedding an analytics SDK that ships behavioural events elsewhere.

Can you export and delete? Both should be free and complete. Export behind a paywall means your own data is being used as leverage.

Is the business model legible? If an app is free, has no purchase, shows no ads, and runs cloud AI on every receipt, something is paying for it. That's not necessarily sinister, but you should be able to work out what it is.

Practical habits

Independent of which app you pick:

  • Turn on a device passcode and biometric lock, and use an in-app lock if offered. Most realistic exposure is someone picking up an unlocked phone, not a server breach.
  • Scan and discard. Once a receipt is in the ledger, you rarely need the photo. Fewer stored images is less to lose.
  • Check what's in your photo library. Some apps save every receipt to Photos, which then syncs to whatever your Photos backup is.
  • Export a backup periodically, so leaving an app is never costly.
  • Re-read the privacy policy after a major update or an acquisition. That's when terms change.

How Pennywick handles this

Stated precisely, because precision is the point of this page.

By default, receipts are read on your device. Apple Vision extracts the text locally. The photograph does not leave your iPhone.

Your ledger lives on your device and in your own iCloud. Transactions, budgets and receipts sync through Apple's private CloudKit database — end-to-end encrypted under the terms Apple sets out in its iCloud data security overview, in your account, where the developer cannot read them.

There is no Pennywick account. The only identity is your Apple ID. There is no user database, no password to breach, and no login.

No ads, no ad tracking, no third-party analytics SDKs.

Optional cloud reading exists, and here is exactly what it does. Two modes, both off until you turn them on:

  1. Your own API key. You supply an OpenAI or Google Gemini key; reading is billed to your account and goes straight from your device to that provider.
  2. Hosted reading, included with Pro. Pennywick runs a server that verifies your Apple-signed purchase, counts your monthly allowance, and forwards the request to a model provider.

In both cases only the text extracted from the receipt is sent — never the photograph. The text isn't stored or logged. The hosted server keeps only a count of how many receipts you've read this month, keyed to an irreversible hash of an Apple subscription identifier. There is still no account and no login: the signed App Store transaction is the credential.

This is worth stating plainly because Pennywick's own marketing used to say "no server", and that stopped being true when hosted reading shipped. The accurate claim is: no account, no bank login, no developer-readable copy of your financial data, and nothing leaves your device unless you switch it on.

Export is never restricted. CSV and full backup, export and restore, regardless of what you've bought. Holding someone's own financial records hostage would contradict the entire premise.

The full detail is in the privacy policy, which names every recipient.

The short version

Receipt scanning is as safe as the app's architecture, and architecture is knowable if you ask the right questions. Find out where reading happens, whether photos or only text are sent, whether there's an account, and where your ledger syncs. An app that can't answer those in plain language has told you something already.

Related: budget apps that don't need a bank login and how to scan receipts on iPhone.