Privacy at a glance
Radish is designed for private grocery receipt review. We do not connect to your bank account, we do not sell grocery data, and receipt data is not used for advertising or cross-app tracking. The table is a summary; the detailed boundaries below control if a summary and a later section differ.
What Radish processes and the control available to you
| Data |
Purpose |
Who processes it |
Retention or boundary |
Your control |
| Saved receipts |
Receipt history, search, spending views, and household sync. |
Your iPhone; Apple iCloud/CloudKit when available. |
Saved until you delete them; shared deletions depend on sync and Apple service availability. |
Delete one receipt or Delete all receipts. |
| Receipt photos |
Create the editable scan draft you review. |
Radish’s Cloudflare-hosted service and OpenAI, only after permission. |
Up to four selected photos per request; operational processing can occur even though the request uses store: false. |
Disable Receipt processing; manual entry remains available. |
| Usage analytics |
Measure a limited product funnel. |
Radish and its isolated PostHog US Cloud project. |
No receipt content or grocery details; builds containing the current privacy correction disable GeoIP enrichment, while earlier historical events may retain provider-derived coarse location. |
Disable Usage analytics to stop future capture. |
| Purchases |
Verify subscription access and protect paid scan limits. |
Apple; Radish receives verified entitlement or proof needed for app functionality. |
Apple controls billing, refund, tax, and purchase retention under its policies. |
Manage or cancel the subscription through Apple. |
| Security identifiers |
Authenticate receipt-service requests, enforce limits, and prevent abuse. |
Radish’s service, Cloudflare, and Apple App Attest or DeviceCheck. |
Specific records and counters follow the published 5-minute, 48-hour, 60-second, or 180-day boundaries below. |
Delete service data where applicable. |
Information Radish stores on your device
- Receipt records you scan or enter manually.
- Receipt line items, categories, totals, dates, and review edits.
- Essential or optional marks you apply to item families.
- Household identifiers and sync state needed to connect household devices.
- Subscription entitlement state received from Apple.
This information is used to show your grocery history, household totals, and essential vs optional spending inside Radish.
Usage analytics
Production app versions that include the Usage analytics setting use Radish's isolated PostHog US Cloud project to measure a limited product funnel. Radish manually sends first open and session, onboarding step and completion, receipt-flow start, scan-or-manual selection, draft readiness or a coarse failure, durable receipt save, paywall and plan selection, verified purchase outcome, and restore outcome.
These events can include a random app-installation identifier, app version and build, fixed funnel step, scan-or-manual method, coarse receipt-count bucket, plan or offer, and a coarse outcome. They never include receipt photos or text, store names, items, categories, receipt dates, amounts, household identifiers, Apple transaction data, contact information, or raw error text. PostHog autocapture, screen capture, session replay, surveys, feature flags, error autocapture, push registration and open capture, and person profiles are disabled.
Builds containing the current analytics privacy correction send PostHog’s $geoip_disable: true and $process_person_profile: false controls after Radish’s event allowlist accepts a payload. PostHog still receives network metadata needed to accept the HTTPS request. Earlier builds did not send the GeoIP control, so historical events can retain provider-derived coarse location fields. Upgrading or turning analytics off does not retroactively delete those events.
The random analytics identifier represents one app installation, not a Radish account or a known person; reinstalling can create a new identifier. Radish does not use analytics for ads or cross-app tracking. You can stop future capture under Settings > Usage analytics. Turning it off cancels delivery, clears unsent events, and removes the local analytics identifier; a later opt-in creates a new identifier. It does not recall events already received or aggregate reports already created. Analytics data remains subject to the configured PostHog account controls and applicable contractual or legal requirements; Radish has not promised a shorter product-specific automatic deletion period. To request help with analytics data, email privacy@radish.money.
Receipt processing
Before your first receipt scan, Radish asks for explicit permission to send up to four receipt photos to OpenAI through Radish's receipt-processing service. Receipt scanning is unavailable until you allow it. You can decline or turn scanning off and continue adding receipts manually.
Receipt scanning sends up to four receipt photos, App Attest security metadata, and either an Apple-verified StoreKit subscription proof or a DeviceCheck token through Radish's Cloudflare-hosted processing service. The Apple proof selects and protects the correct free or paid usage limit and is removed before the receipt request is sent to OpenAI. Cloudflare operates the service and protects it from abuse; OpenAI processes the receipt request to create the draft. The request is used to identify receipt line items, prices, dates, totals, store names, and likely categories. You review the draft before saving it.
Your permission is stored in Radish's local app settings, is not shared with a household partner, and can be changed under Settings > Receipt processing. Turning receipt scanning off prevents future uploads; it cannot recall a request that was already sent.
Deletion and disable controls
Radish has separate controls because saved receipts, receipt-service security records, analytics, iCloud copies, and Apple purchases are different data layers. No one action silently claims to erase all of them.
What each action changes—and what it leaves alone
| Action |
What it changes |
What it does not change |
| Delete receipt |
Removes that saved receipt and its items from Spending; in a shared household, the deletion can sync to connected iPhones. |
Does not delete receipt-service security records, analytics events, Apple purchase records, or a provider request already sent. |
| Delete all receipts |
Removes all saved receipts and their items from Spending; shared deletion can sync when available. |
Does not remove saved item choices or store names, receipt-service records, analytics, or Apple purchase records. |
| Delete service data |
After signed confirmation, removes this installation’s receipt-service identifier, App Attest records, outstanding challenges, detailed counters, and legacy indexes. |
Does not delete saved or iCloud receipts, change scan permission, delete analytics, remove shared subscription-family or aggregate counters early, or recall an OpenAI request. |
| Disable Usage analytics |
Stops future capture, cancels delivery, clears unsent events, and removes the local analytics identifier. |
Does not recall received events, historical provider-derived fields, or aggregate reports. |
| Disable Receipt processing |
Prevents future receipt-photo uploads; manual entry remains available. |
Does not recall a request already sent, delete service security records, or delete saved receipts. |
| Leave household or stop sharing |
Stops future household changes from syncing. |
Does not erase receipts already stored on either iPhone; Radish cannot erase the other phone’s copies. |
| Delete the app or iCloud data |
Apple’s device and iCloud controls can remove local app data or Apple-hosted copies and can make recovery unavailable. |
Does not automatically delete Apple purchase history, analytics already received, an earlier provider request, or receipt-service records. Delete service data before removing the app if you want the signed in-app deletion path. |
| Cancel subscription |
Stops future renewal according to Apple’s subscription rules. |
Does not delete receipts, iCloud data, analytics, or receipt-service security records. |
Retention and deletion
Radish's receipt proxy does not write receipt request bodies to its storage and asks OpenAI not to store the request by using store: false. Short-lived operational processing or retention may still occur for reliability, security, abuse prevention, debugging, legal obligations, or under the provider's terms. Radish does not claim zero operational retention.
One-time App Attest challenges expire after 5 minutes. Detailed per-install and pseudonymous subscription-family usage counters expire at the start of the relevant UTC day plus 48 hours. The raw StoreKit proof and DeviceCheck token are not persisted by Radish's processing service. The installation identifier, App Attest public-key state, and assertion counter expire after 180 days without a successful signed request unless you remove them sooner.
Under Settings > Receipt processing, Delete service data sends an App-Attest-signed request that removes this installation's identifier, App Attest records, outstanding challenges, detailed usage counters, and legacy indexes from Radish's processing service. It does not change your receipt-scanning permission, delete saved receipts or iCloud household history, or recall a request already sent to OpenAI.
After confirmed deletion, a minimal hashed deletion receipt remains for up to 48 hours so a lost response can be retried safely and the same-day request quota cannot be reset. It contains no raw installation identifier, key identifier, public key, page count, or receipt data. A subscription-family counter is shared by all installations using that subscription, is not removed by one installation, and expires on the same schedule. Apple maintains DeviceCheck fraud-prevention bits. A pseudonymous principal placed on Radish's exact blocklist remains until Radish removes that block. Service-wide aggregate counters contain no installation identifier and expire on schedule. Cloudflare-managed abuse-prevention counters use 60-second decision windows and cannot be individually removed by Radish.
The in-app action can authenticate only the current installation. If the app or its App Attest key is removed first, the inactive security record expires after 180 days. You can delete saved receipts separately in the app; iCloud deletion and sync timing may depend on Apple iCloud availability.
Security identifiers
Receipt-scanning requests use Apple App Attest to authenticate the app request and a stable per-install identifier for server-side identity and rate limiting. StoreKit or DeviceCheck security proofs establish subscription or device state for fraud-prevention and usage-limit decisions. Radish derives only a keyed pseudonymous subscription-family identifier for paid limits. Quota and blocklist decisions can target one exact installation or subscription principal without blocking a shared IP address. Separate public challenge-flood rate limits can still apply to a source network. These receipt-service security identifiers are not repurposed for advertising, analytics, or cross-app tracking; usage analytics uses a separate random app-installation identifier described above. Cloudflare terminates HTTPS and receives source-network information as part of operating the service. The Worker hashes the source-network address before using it as a managed rate-limit key; the raw address is not written to Radish's Durable Object.
Household sync
When iCloud and CloudKit are available, Radish syncs a sealed household snapshot to the household's private CloudKit zone, including for a solo household. A partner joins through an explicit QR invite. Radish does not give another person access without that invite flow.
When iCloud Keychain is available, Radish stores a recovery copy of the random household encryption key there. The working copy remains device-only. After a reinstall, Radish downloads and verifies an existing CloudKit household snapshot before it can upload local state. The Data & iCloud check saves the current sealed snapshot and reads it back from CloudKit before reporting that recovery is ready.
Apple may process iCloud and CloudKit data according to Apple's terms and privacy policies.
Purchases
Radish subscriptions are processed by Apple through the App Store. Apple may process purchase, payment, refund, tax, and subscription information according to Apple's own policies. Radish receives the entitlement information needed to unlock the app.
Website privacy
This website does not use cookies, ad pixels, or analytics scripts. App Store links on Radish acquisition pages use fixed page-level Apple campaign and provider tokens so App Store Connect can report aggregate product-page views, first-time downloads, usage, sales, and subscriptions for that page intent. The fixed token is not derived from visitor-supplied query, UTM, or referrer values. These links include no Radish user, app-installation, receipt, or household identifier. Radish does not join Apple campaign reporting to PostHog installation events or use it as per-person attribution. Apple applies its own attribution windows, reporting thresholds, and privacy policies. Hosting and security providers may process standard request logs needed to operate and protect the site.
Contact
Questions about privacy can be sent to privacy@radish.money.