Security & data practices
This page describes how Owed handles receipts you send us. V1 does not request Gmail or Outlook login.
Inbound receipts
Each account gets a personal address on receipts.owedagent.com. We match inbound mail by that address, not by the From header (forwards change From). You can rotate the address. You can also paste or upload a receipt in the app — that uses the same pipeline as forwarded mail.
Encryption and secrets
- TLS 1.2+ in transit; AES-256 at rest for evidence excerpts, with per-user keys where configured.
- Secrets live in a secrets manager. Tokens and webhook secrets are never written to logs.
Minimization
We persist extracted purchase fields and short evidence excerpts, not your entire mailbox. Candidate raw messages may be cached up to 30 days for reprocessing, then deleted.
AI processing
When a receipt needs language-model extraction, content is sent only to a zero-retention, no-training API. Receipt bodies are wrapped as untrusted data; instruction-like content is neutralized; outputs are schema-validated. Extracted strings are never executed or used as URLs to visit automatically.
Subprocessors (current engineering list)
- Cloud hosting (application, Postgres, object storage, KMS)
- Stripe (payments) — Pro $9.99/month Checkout + customer portal. First 1,000 accounts: 30-day trial.
- Transactional / inbound email (Postmark or Amazon SES)
- ZDR LLM provider (Anthropic and/or OpenAI API with zero data retention)
Incidents
We maintain an incident-response runbook, including the FTC's 30-day breach notification path where it applies. Report issues to hello@owedagent.com.