Privacy policy
This Policy explains what personal information Satsuma collects, why, who it's shared with, how long it's kept, and the rights you have. We don't sell your information or use it for advertising.
Effective September 28, 2026
Draft for legal review
This document hasn't been reviewed by a lawyer yet and isn't in effect. Highlighted [brackets] are details still to be filled in, and dashed review notes flag decisions for the reviewer. Both disappear once the operator details are configured.
1. Who we are
Satsuma is operated by [Company legal name], [Registered postal address] ("Satsuma", "we", "us"). We are responsible for (the "controller" of) the personal information described here.
This Policy applies to the Satsuma website, web application and related services (the "Service"). It should be read with our Terms of Service. A plain-language overview is on our privacy page.
2. Information we collect
Information you give us
- Account information: your name, email address, password (stored only as a one-way hash), time zone, currency and preferences such as notification and default budget-period settings.
- Financial information you add: names and types of the accounts you track, the last four digits of cards, balances you enter, transactions from files you import (including the uploaded file and its rows), budgets, categories, savings goals and notes.
- Receipts you upload or forward: the email (including its sender, subject, body and attachments), PDFs and photos you upload, and the details we extract from them.
- Forwarding addresses: email addresses you verify so you can forward receipts and alerts to Satsuma.
- Communications: messages you send us, such as support requests.
Information from accounts you connect
- Email accounts (Gmail, Outlook or IMAP): with your permission, we access your mailbox with read-only permission to identify receipts and purchase alerts. For emails identified as receipts or alerts, we store the email content and attachments and the details extracted from them. We also keep a processing log that may include the sender and subject of processed emails, and counts of what each scan found.
- Connection credentials: the email address of the connected account, access and refresh tokens (for Google and Microsoft), or the server settings, username and password you provide (for IMAP). Tokens and passwords are encrypted before storage.
Information collected automatically
- Session and device information: while you are signed in, we record your IP address, browser type (user agent) and activity times, to keep you signed in and to detect misuse.
- Server logs: our servers record technical information about requests and errors, which may include IP addresses.
- Cookies and similar technologies: see section 8.
We do not use third-party analytics, advertising pixels or cross-site tracking.
Information we generate
We generate information from the above, such as extracted receipt details (merchant, date, line items, totals, tax, discounts, order number and last four card digits), suggested matches and their confidence scores, categories, budget totals, projections and notifications.
3. How we use information
We use personal information to:
- Provide the Service: create and run your account, import and display your transactions, read receipts, suggest matches and categories, track budgets, and run the scans and imports you ask for.
- Communicate with you: send account emails (such as verification, password resets and forwarding-address codes), notifications you have turned on, and important notices about the Service, these Terms or this Policy.
- Keep the Service secure: authenticate you, verify that forwarded emails are genuine and come from addresses you have verified, and detect, prevent and investigate abuse, fraud and security incidents.
- Maintain and improve the Service: troubleshoot problems and fix errors, using only the information needed for that purpose.
- Comply with law: meet legal obligations, respond to lawful requests, and establish, exercise or defend legal claims.
We do not sell personal information, use it for targeted advertising, or build advertising profiles. We do not use the contents of your email, receipts or transactions to train general-purpose AI models.
4. Legal bases (EEA and UK)
If you are in the European Economic Area or the United Kingdom, we rely on these legal bases:
- Performance of a contract (Art. 6(1)(b) GDPR): to provide the Service you signed up for, including processing the financial information and receipts you add.
- Consent (Art. 6(1)(a)): to access email accounts you choose to connect. You can withdraw consent at any time by disconnecting the account, without affecting processing that already took place.
- Legitimate interests (Art. 6(1)(f)): to secure the Service, prevent abuse, and fix problems, where those interests are not overridden by your rights.
- Legal obligation (Art. 6(1)(c)): where the law requires us to keep or disclose information.
5. Automated processing
The Service uses automated processing to extract details from receipts (including text recognition for images and PDFs), to suggest matches between receipts and transactions, and to suggest categories. This processing runs on our own servers using software we operate; receipt contents are not sent to third-party AI or document-processing services.
These outputs are suggestions to help you organize your information. Matches are not confirmed until you confirm them, and you can edit or reject any suggestion. We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you.
6. Google and Microsoft data
When you connect a Google account, Satsuma requests read-only access to Gmail (the gmail.readonly scope) solely to find and process receipts and purchase alerts for you. When you connect a Microsoft account, Satsuma requests read-only mail access (Mail.Read) for the same purpose. Satsuma cannot send, delete or modify your email.
Satsuma's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we use Google user data only to provide and improve the user-facing features described in this Policy; we do not transfer it to others except as needed to provide those features, to comply with law, or as part of a merger or acquisition with your notice; we do not use it for advertising; and we do not allow humans to read it unless you give us permission, it is needed for security purposes or to comply with law, or the data has been aggregated and anonymized for internal operations.
You can revoke Satsuma's access at any time in your Satsuma email settings, and in your Google Account (myaccount.google.com/permissions) or Microsoft account settings.
9. How long we keep information
- While your account is open, we keep your information so we can provide the Service, until you delete it.
- Items you delete, such as a receipt, transaction or email connection, are removed from the active Service. Some records may be kept briefly in a deleted state so the deletion can be undone or processed.
- When you delete your account, we delete your account and the information associated with it from our active systems. Copies may remain in encrypted backups for up to [number] days before being overwritten.
- Session records expire automatically after inactivity. Server logs are kept for up to [number] days.
- We may keep information longer where the law requires it, or to establish, exercise or defend legal claims.
10. Security
We use administrative, technical and physical safeguards designed to protect personal information, including:
- passwords stored only as one-way hashes;
- email access tokens and IMAP passwords encrypted before storage;
- uploaded receipt images and import files kept in private storage, never at a public web address;
- forwarded email accepted only with a valid cryptographic signature from our relay and only from sender addresses you have verified;
- encryption in transit (HTTPS) between your browser and the Service;
- access to production systems limited to people who need it.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant authorities as required by law.
11. Your rights and choices
You can do the following in the Service at any time:
- view and correct your profile, transactions, receipts, categories and budgets;
- disconnect an email account, and revoke access with Google or Microsoft;
- delete individual records, or delete your account and its data from your profile settings;
- turn notifications on or off.
Depending on where you live, you may also have the right to: access the personal information we hold about you; receive a copy in a portable format; correct it; delete it; restrict or object to certain processing; withdraw consent; and not be discriminated against for exercising these rights. EEA and UK residents may also lodge a complaint with their local data protection authority.
To make a request, email us at the address in the Contact section. We will respond within the time required by law (generally within 30 days, or 45 days under some U.S. state laws). We may need to verify your identity, usually by confirming control of your account email. You may use an authorized agent where the law allows, and we may ask for proof of their authority.
12. Additional U.S. state disclosures
This section supplements the Policy for residents of U.S. states with comprehensive privacy laws, including California (CCPA/CPRA).
Categories collected in the last 12 months: identifiers (name, email, IP address); customer records and financial information (transaction details, card last four digits, balances you enter); commercial information (purchase and receipt records); internet or network activity (session and log data); and account login credentials (for the Service and for IMAP accounts you connect). Sources, purposes and recipients are described in sections 2, 3 and 7.
No sale or sharing: we do not sell personal information and do not "share" it for cross-context behavioral advertising, and have not done so in the last 12 months. We have no actual knowledge of selling or sharing information of consumers under 16.
Sensitive personal information: we use account log-in credentials and financial information only to provide the Service you request and for other purposes permitted by law, not to infer characteristics about you.
Retention is described in section 9. To exercise your rights, see section 11.
13. International transfers
We and our service providers may process personal information in countries other than yours, including [country of hosting, e.g. the United States]. Where the law requires it, we protect international transfers with appropriate safeguards, such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or a provider's certification under the EU-U.S. Data Privacy Framework.
14. Children
The Service is not directed to children, and you must be at least 18 to use it. We do not knowingly collect personal information from anyone under 18. If you believe a minor has given us personal information, contact us and we will delete it.
15. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you by email or in the Service before they take effect, and where the law requires, ask for your consent. The "Effective" date at the top shows when this Policy last changed.
Contact
Satsuma is operated by [Company legal name].
Email:
[Legal / privacy contact email]
Post: [Registered postal address]