Effective date: September 30, 2026
Sundry ("the app", "we", "us") is a back-office tool for solo operators and small businesses, operated by Samderlust Consulting. This policy explains what information we collect, how we use it, and your rights over it.
By using Sundry, you agree to this policy. If you do not agree, do not use the app.
Account information: Your email address, collected when you sign in via Google Sign-In, Apple Sign-In, or email magic link.
Business data: Business names, client names and contact details, invoice content, and expense categories that you enter into the app.
Receipt images: Photos or scanned images of receipts that you upload. These are stored in private, access-controlled storage buckets.
AI extraction: When you scan a receipt or import an invoice or bank statement, the file (or, for a web receipt, its text) is sent to our AI provider, Google (Gemini API), to extract details such as merchant, amount, date, and line items. This processing is necessary to provide the core service. We use a paid Gemini API tier under which your content is not used to train Google's models; see our sub-processor list in section 6. AI extraction is on by default; you can enter receipt and invoice details manually instead if you prefer not to use it.
Usage data: Basic crash reports and error logs generated by the Supabase backend. We do not use third-party analytics SDKs.
Sundry offers an optional feature to store your receipts, invoices, and bank statements in your Google Drive instead of Sundry's storage. This feature is off by default and must be explicitly turned on for your account in Settings → File storage. Each business gets its own folder in your Drive.
drive.file scope — the app can only see and manage files it creates in your Drive. It cannot access any other Drive content.Sundry's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use your data for advertising. We do not sell your data to any third party.
Your data is stored in Supabase, a managed cloud platform hosted on AWS. Row-level security (RLS) policies ensure that only you can access your own data. Receipt images are stored in private storage buckets accessible only to your account.
All data is transmitted over HTTPS. We do not store passwords — authentication is handled by Google, Apple, or Supabase's magic-link email flow.
We use the following third-party service providers ("sub-processors") to operate Sundry. Each processes personal data only on our instructions and under a data processing agreement (DPA).
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase (on AWS) | Database, file storage, authentication | All account and business data, receipt/invoice/statement files | United States |
| Google LLC — Gemini API | AI extraction of receipts, invoices, and bank statements | Uploaded files (or web-receipt text) at scan time | United States |
| Google LLC — Sign-In & Drive | Google Sign-In; optional Google Drive receipt storage | Email address; receipt files (Drive, if enabled) | United States |
| Apple Inc. | Apple Sign-In authentication (iOS) | Email address (or Apple relay address) | United States |
We use Gemini under a paid API tier whose terms state that content submitted through the API is not used to train Google's models and is retained only transiently for abuse monitoring. See Google's privacy policy. We do not use any third-party advertising or analytics SDKs.
Your data is retained for as long as your account is active. If you delete your account, all associated data — including business records, receipts, and invoice history — will be permanently deleted within 30 days.
To delete your account, contact us at samderlust@gmail.com.
If you use the app's account merging feature to resolve two duplicate Sundry accounts, the account you choose not to keep is deleted immediately rather than within 30 days, and cannot be recovered. Data is not transferred between the two accounts. See section 7 of the Terms of Service.
Deleting your account does not cancel any paid subscription. Subscriptions are billed by Apple or Google and must be cancelled through the App Store or Google Play — see section 6 of the Terms of Service.
You have the right to access, correct, or delete your personal data. You can manage most data directly in the app. For account deletion or data export requests, email samderlust@gmail.com.
Sundry is not directed at children under 13. We do not knowingly collect personal information from children under 13.
We may update this policy from time to time. Material changes will be notified via the app. Continued use after changes constitutes acceptance of the updated policy.
Questions about this policy: samderlust@gmail.com