Security
Last reviewed: September 30, 2026
Your spending records can contain personal details. Here is how CardChing handles them, what our service providers do, and the limits to keep in mind when you upload a receipt.
Storage and transit
Account records, transactions and uploaded receipts are stored in Convex. Convex documents encryption at rest for its database and file storage, and encryption in transit. See Convex's security practices.
This is not end-to-end encryption: CardChing's services and the providers involved in processing your data can read it. Cloud storage protections do not describe every copy on your device.
Sign-in and access
Clerk manages account sign-in, including Google and Apple sign-in. The app is designed to check your signed-in identity and ownership before returning personal records or receipt image links.
A direct receipt image URL is different from signing in: anyone with that link can open the image. Keep receipt links private. Convex explains how file URLs work.
Receipt processing
Scanning sends your image and extraction context, such as currency and time zone, to Google's Gemini API to read transaction details. This also applies to guest scans. Uploaded receipts may remain stored with your records after processing.
Google's data use and retention depend on its service terms and account configuration. We do not promise that scans are never retained, reviewed or used for model improvement. Read the Gemini API terms and abuse-monitoring policy.
Avoid including full payment card numbers, passwords or unnecessary personal details in images or notes. You can enter transactions manually without sending an image for AI processing. No bank connection is needed.
On your device
The native app uses the operating system's secure storage for Clerk session tokens and the cached Convex sign-in token. Offline transaction records, queued images, widget summaries and shortcut credentials use other local storage. These are not all stored in the token store, and we do not promise separate app-level encryption for every local copy.
Protect your device with a screen lock and consider which spending details you display in widgets.
Retention and deletion
Deleting an entry does not necessarily erase every copy immediately. To request account deletion, open Settings → Profile in the app. The process requests deletion of your sign-in account and marks your app data for cleanup. Scheduled cleanup targets app data marked for deletion more than 30 days ago; this is not a guaranteed completion deadline or a recovery window.
Audit records and older uploads with unresolved ownership may remain. Provider logs and backups, local device data, and copies you exported or shared can have separate retention periods. We do not promise complete removal of all copies after 30 days.
For deletion questions or a security concern, contact privacy@cardching.com. Please describe the concern without sending passwords or full payment card details. Our Privacy Policy explains the information we collect and the services involved.