SUNDRY
← Back Terms

Privacy Policy

Effective date: September 30, 2026

1. Introduction

Sundry ("the app", "we", "us") is a back-office tool for solo operators and small businesses, operated by Samderlust Consulting. This policy explains what information we collect, how we use it, and your rights over it.

By using Sundry, you agree to this policy. If you do not agree, do not use the app.

2. Information We Collect

Account information: Your email address, collected when you sign in via Google Sign-In, Apple Sign-In, or email magic link.

Business data: Business names, client names and contact details, invoice content, and expense categories that you enter into the app.

Receipt images: Photos or scanned images of receipts that you upload. These are stored in private, access-controlled storage buckets.

AI extraction: When you scan a receipt or import an invoice or bank statement, the file (or, for a web receipt, its text) is sent to our AI provider, Google (Gemini API), to extract details such as merchant, amount, date, and line items. This processing is necessary to provide the core service. We use a paid Gemini API tier under which your content is not used to train Google's models; see our sub-processor list in section 6. AI extraction is on by default; you can enter receipt and invoice details manually instead if you prefer not to use it.

Usage data: Basic crash reports and error logs generated by the Supabase backend. We do not use third-party analytics SDKs.

3. Google Drive (Optional)

Sundry offers an optional feature to store your receipts, invoices, and bank statements in your Google Drive instead of Sundry's storage. This feature is off by default and must be explicitly turned on for your account in Settings → File storage. Each business gets its own folder in your Drive.

  • We request only the drive.file scope — the app can only see and manage files it creates in your Drive. It cannot access any other Drive content.
  • You can revoke Drive access at any time via Google Account Permissions, or by switching back to Sundry storage in the app.

Sundry's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. How We Use Your Information

  • To provide the core service: storing, displaying, and syncing your business data across your devices
  • To generate invoices, expense reports, and tax summaries that you request
  • To send transactional emails (invoice delivery) on your behalf to your clients
  • To identify and fix errors in the app

We do not use your data for advertising. We do not sell your data to any third party.

5. Data Storage and Security

Your data is stored in Supabase, a managed cloud platform hosted on AWS. Row-level security (RLS) policies ensure that only you can access your own data. Receipt images are stored in private storage buckets accessible only to your account.

All data is transmitted over HTTPS. We do not store passwords — authentication is handled by Google, Apple, or Supabase's magic-link email flow.

6. Sub-processors

We use the following third-party service providers ("sub-processors") to operate Sundry. Each processes personal data only on our instructions and under a data processing agreement (DPA).

Sub-processorPurposeData processedLocation
Supabase (on AWS) Database, file storage, authentication All account and business data, receipt/invoice/statement files United States
Google LLC — Gemini API AI extraction of receipts, invoices, and bank statements Uploaded files (or web-receipt text) at scan time United States
Google LLC — Sign-In & Drive Google Sign-In; optional Google Drive receipt storage Email address; receipt files (Drive, if enabled) United States
Apple Inc. Apple Sign-In authentication (iOS) Email address (or Apple relay address) United States

We use Gemini under a paid API tier whose terms state that content submitted through the API is not used to train Google's models and is retained only transiently for abuse monitoring. See Google's privacy policy. We do not use any third-party advertising or analytics SDKs.

7. Retention and Deletion

Your data is retained for as long as your account is active. If you delete your account, all associated data — including business records, receipts, and invoice history — will be permanently deleted within 30 days.

To delete your account, contact us at samderlust@gmail.com.

If you use the app's account merging feature to resolve two duplicate Sundry accounts, the account you choose not to keep is deleted immediately rather than within 30 days, and cannot be recovered. Data is not transferred between the two accounts. See section 7 of the Terms of Service.

Deleting your account does not cancel any paid subscription. Subscriptions are billed by Apple or Google and must be cancelled through the App Store or Google Play — see section 6 of the Terms of Service.

8. Your Rights

You have the right to access, correct, or delete your personal data. You can manage most data directly in the app. For account deletion or data export requests, email samderlust@gmail.com.

9. Children's Privacy

Sundry is not directed at children under 13. We do not knowingly collect personal information from children under 13.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be notified via the app. Continued use after changes constitutes acceptance of the updated policy.

11. Contact

Questions about this policy: samderlust@gmail.com

Sundry Terms of Service Samderlust

© 2026 Samderlust Consulting. All rights reserved.