Reapt
Terms Privacy

Privacy Policy

Reapt, Inc.
Effective Date: March 22, 2026
Last Updated: March 22, 2026

This Privacy Policy describes how Reapt, Inc. (“Reapt,” “we,” “us,” or “our”), a Delaware corporation, collects, uses, and shares information when you use the Reapt application and related services available at https://reapt.app (collectively, the “Service”).

By using the Service, you agree to the collection and use of information as described in this Privacy Policy.

1. Information We Collect

1.1 Account Information

When you create a Reapt account, we collect your name, email address, mobile phone number, and authentication credentials. If you sign in using Google or Microsoft, we receive your basic profile information (name and email address) from those providers.

1.2 Phone Number and SMS Data

When you provide your mobile phone number and consent to receive text messages from Reapt, we collect and store your phone number. We use your phone number exclusively to send you service-related SMS messages, including expense notifications, classification confirmations, trip grouping summaries, and onboarding communications.

We do not share, sell, rent, or lease your phone number or SMS opt-in data (including consent status) to third parties for marketing or any other purpose. We may use a third-party messaging service provider (such as Twilio) to deliver SMS messages on our behalf. Such providers process your phone number solely to transmit messages and are contractually prohibited from using your data for any other purpose.

1.3 Email Data

With your explicit authorization, we access your email messages and metadata through the Gmail API (Google) or Microsoft Graph API (Microsoft Outlook) on a read-only basis. We use this data solely to identify and extract expense-related information such as receipts, invoices, booking confirmations, and subscription notifications. We do not read, analyze, or store email content unrelated to expense management.

1.4 Calendar Data

With your explicit authorization, we access your calendar events through Google Calendar API or Microsoft Graph API on a read-only basis. We use this data solely to correlate travel, meeting, and event information with business expenses for categorization and reporting purposes.

1.5 Uploaded Content

You may upload receipts, bank statements, invoices, or other expense-related documents directly to the Service. We process this content solely to provide expense management functionality.

1.6 Usage and Technical Data

We automatically collect standard technical information when you interact with the Service, including IP address, browser type, device identifiers, pages visited, and timestamps. We use this data for service operation, security monitoring, and improvement.

2. How We Use Your Information

We use the information we collect exclusively for the following purposes:

  • Expense identification and extraction: Scanning authorized email and calendar data to detect and extract expense-related transactions.
  • Expense categorization and reporting: Classifying expenses, generating reports, and providing tax-relevant categorization.
  • Service operation: Authenticating your account, processing your requests, and maintaining the Service.
  • Service improvement: Analyzing aggregate, de-identified usage patterns to improve the Service.
  • SMS communications: Sending service-related text messages to your mobile phone number, including expense notifications, classification confirmations, trip summaries, and onboarding messages. Message frequency varies based on your account activity; typically no more than 10 messages per week.
  • Security and fraud prevention: Detecting and preventing unauthorized access or abuse.
  • Legal compliance: Responding to lawful requests from government authorities.

We do not use your data for advertising, user profiling for ad targeting, or any purpose unrelated to providing and improving the expense management Service.

3. Google API Services — Limited Use Disclosure

Reapt’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically:

  1. We only use Google user data to provide and improve the expense management features described in this Privacy Policy. We do not use Google user data for any other purpose.
  2. We do not transfer Google user data to third parties except (a) as necessary to provide or improve the Service, (b) to comply with applicable laws, or (c) as part of a merger, acquisition, or asset sale, with prior notice to users.
  3. We do not use Google user data for serving advertisements, including retargeting, personalized advertising, or interest-based advertising.
  4. We do not allow humans to read Google user data unless (a) we have your affirmative consent for specific messages, (b) it is necessary for security purposes such as investigating abuse, (c) it is necessary to comply with applicable law, or (d) the data has been aggregated and de-identified and is used for internal operations.

4. Microsoft API Services Disclosure

Reapt accesses Microsoft user data (Outlook email and calendar) through the Microsoft Graph API under the Mail.Read and Calendars.Read permissions, granted with your explicit consent via Microsoft’s OAuth authorization flow.

We use Microsoft user data exclusively for expense identification, categorization, and reporting as described in Section 2. We apply the same data protection standards to Microsoft user data as described in Section 3 for Google user data.

5. How We Share Your Information

We do not sell your personal information.

We may share your information only in the following limited circumstances:

  • Service providers: We use third-party service providers (such as cloud hosting and infrastructure providers) that process data on our behalf under contractual obligations to protect your information and use it only as directed by us.
  • Legal requirements: We may disclose information when required by law, subpoena, court order, or government request.
  • Business transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred. We will notify you before your information becomes subject to a different privacy policy.
  • With your consent: We may share information for other purposes when we have your explicit consent.

We do not share, transfer, or disclose email or calendar content to any third party for advertising, data brokering, or any purpose unrelated to providing the Service.

6. SMS Communications — Consent, Opt-Out, and Disclosure

6.1 Consent

By providing your mobile phone number during account registration or onboarding and agreeing to receive text messages, you expressly consent to receive SMS messages from Reapt at the phone number you provided. Consent is not a condition of purchasing any goods or services from Reapt.

6.2 Message Frequency and Content

Message frequency varies based on your account activity. You may receive up to approximately 10 messages per week. Messages may include expense classification confirmations, trip grouping summaries, expense report notifications, and onboarding instructions. Reapt will not send marketing or promotional messages via SMS.

6.3 Message and Data Rates

Message and data rates may apply. Please contact your mobile carrier for details about your text messaging plan.

6.4 Opt-Out

You may opt out of receiving SMS messages at any time by replying STOP to any message from Reapt. After opting out, you will receive a single confirmation message and no further SMS messages will be sent to your number. You may also opt out by contacting us at support@reapt.app or through your account settings.

6.5 Help

For help with SMS messages, reply HELP to any message from Reapt, or contact us at support@reapt.app.

6.6 Supported Carriers

Reapt SMS messages are supported on all major U.S. mobile carriers. Carriers are not liable for delayed or undelivered messages.

7. Data Retention and Deletion

We retain your data only for as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy.

  • Account data: Retained while your account is active. Deleted within 30 days of account deletion.
  • Phone number and SMS consent data: Retained while your account is active and you have not opted out. If you opt out of SMS, your phone number is retained for opt-out compliance purposes only and is not used for further messaging. Deleted within 30 days of account deletion.
  • Email and calendar data: Extracted expense information is retained while your account is active. Raw email and calendar data retrieved via API is processed in real time and is not stored in its original form beyond the processing window necessary for expense extraction.
  • Uploaded documents: Retained while your account is active and deleted within 30 days of account deletion.

You may request deletion of your account and associated data at any time by contacting us at privacy@reapt.app. Upon receiving a deletion request, we will delete or de-identify your data within 30 days, except where retention is required by law.

8. Data Security

We implement commercially reasonable technical and organizational measures to protect your information, including:

  • Encryption of data in transit (TLS) and at rest.
  • Access controls limiting internal access to user data on a need-to-know basis.
  • Regular security monitoring and incident response procedures.

No method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

9. Data Location

Your data is stored and processed on infrastructure located in the United States. By using the Service, you consent to the transfer and processing of your data in the United States.

10. Your Rights and Choices

10.1 Access and Authorization

You may connect or disconnect your Google or Microsoft accounts at any time through the Service’s settings. Disconnecting an account immediately revokes our access to that provider’s data. You may also revoke access directly through your Google Account permissions or Microsoft Account permissions.

10.2 Data Access and Portability

You may request a copy of the data we hold about you by contacting us at privacy@reapt.app.

10.3 Deletion

You may request deletion of your account and data as described in Section 7.

10.4 SMS Communications

You may opt out of SMS messages at any time as described in Section 6.4. Opting out of SMS does not affect your ability to use other features of the Service.

10.5 California Residents

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to delete, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your CCPA rights, contact us at privacy@reapt.app.

11. Children’s Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 16, we will delete it promptly.

12. Third-Party Links and Services

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the “Last Updated” date. Your continued use of the Service after changes take effect constitutes acceptance of the revised policy.

14. Contact Us

If you have questions about this Privacy Policy, contact us at:

Reapt, Inc.
Email: privacy@reapt.app
Website: https://reapt.app

© 2026 Reapt. All rights reserved.
Terms of Service Privacy Policy