TUPPNET Privacy Policy

Privacy Policy

Tuppnet is a private tool used by one household and a small work crew. It is not a public service and has no user accounts. This policy explains exactly what it does with information, including information from a Google account.

Last updated: 29 August 2026

1. Who is responsible

Tuppnet is operated by Brandon Tupper, Vermilion, Alberta, Canada. Contact: tupper.brandon@gmail.com

2. What the app collects

When someone submits a receipt, the app transmits:

That is the whole of it. The app has no analytics, no advertising, no tracking pixels, no cookies, and no third-party scripts of any kind. It does not request or record location, contacts, or any device identifier.

3. Where that information goes

It is assembled into a single email and sent to one fixed document-processing inbox operated by Hubdoc, a bookkeeping service, and optionally copied to the household bookkeeper. That destination address is set in the app's server configuration and cannot be altered by anyone using the app.

Information is not sold, rented, or shared with anyone else, and is not used for advertising, profiling, or training machine-learning models.

4. Google account data

Tuppnet requests exactly one Google permission (OAuth scope):

https://www.googleapis.com/auth/gmail.send

This permission allows the app to send an email on behalf of the Google account that authorized it. It is the narrowest scope available for the purpose. Specifically, the app cannot read, list, search, download, label, modify, or delete any message in the mailbox, and cannot see contacts, Drive files, Calendar, or profile information beyond the email address of the sending account.

The app's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Concretely: the permission is used only to send the receipt email described above; it is never used for any other purpose, never transferred to anyone else except as needed to deliver that email, and never used for advertising or for building profiles.

5. What is stored, and where

On the server: nothing. The app's backend keeps no database and no file storage. It receives a submission, sends the email, and discards it from memory. It does not log receipt images, amounts, notes, or the contents of any submission. The sent email is the only record the system creates.

On the phone: two small preferences are saved in the browser's local storage purely so they need not be re-entered — the name the user picked from the list, and the shared access code. Clearing the browser or app data removes both. Nothing else is kept on the device.

In the mailbox: the sent receipt email appears in the sending Google account's Sent folder, and is retained according to that account's own settings. It also resides in the recipient Hubdoc account, governed by Hubdoc's own terms and privacy practices.

6. Security

All traffic between the phone, the app's backend, Google, and Hubdoc is encrypted in transit over HTTPS. Google credentials are held as encrypted secrets in the hosting platform and are never present in the app that runs on the phone. Access to the backend is gated by a shared access code. Photographs are resized on the phone before they are sent.

7. Children

Tuppnet is a workplace and household bookkeeping tool. It is not directed at children and is not made available to them.

8. Your choices

The owner of the sending Google account may revoke the app's permission at any time at myaccount.google.com/permissions. The app stops being able to send immediately.

To have a submitted receipt deleted, email tupper.brandon@gmail.com and it will be removed from the mailbox and the Hubdoc account.

9. Changes

If this policy changes, the revised version will be posted at this same address with a new date at the top.