RECEIVERX ← Back to ReceiverX

Legal

Privacy Policy

Effective Date: July 7, 2026 Last Updated: July 29, 2026

This Privacy Policy explains how ReceiverX LLC, a Texas limited liability company ("ReceiverX," "we," "us," or "our"), collects, uses, shares, and protects personal information in connection with the ReceiverX website, mobile applications, APIs, and related services (the "Service").

This policy is a Notice at Collection for purposes of the California Consumer Privacy Act (CCPA/CPRA) and an Article 13/14 notice for purposes of the EU/UK General Data Protection Regulation (GDPR). A summary table of categories collected, purposes, sources, recipients, and retention is included at the end of this policy.

Quick links: Your Rights and Choices · Do Not Sell or Share My Personal Information · Sub-processors · Contact


1. Who is the Controller / Processor

2. Information We Collect

2.1 Information You Provide

2.2 Information Collected Automatically

When you send a report to a recipient via magic link, we capture: the time the link was sent and viewed, view count, the recipient IP address and user-agent string, and any failed verification attempts. Recipients are notified that they are accessing a confidential report through a logged channel before the report renders.

These logs are used in two distinct roles:

We do not use recipient access logs for advertising or to build profiles of recipients. See Section 4 for the Article 14 notice to recipients.

2.4 Information from Third Parties

2.5 Sensitive Personal Information

In limited cases, our Service may process the following CPRA "Sensitive Personal Information": account credentials (password hash, TOTP secret), and precise geolocation if you choose to attach it to a report. We use sensitive PI only for the purposes for which it was provided (authentication, security, and report content) and do not use it to infer characteristics about you. You may request to limit our use of sensitive PI as described in Section 9.

Users under 16 may not register for or use the Service. We do not knowingly permit registration by anyone under 16, and we do not knowingly collect personal information from children under 13 without verifiable parental consent under COPPA. See Section 13.

Purpose Examples GDPR legal basis
Provide and operate the Service Authentication, content storage, AI scanning, report delivery Contract (Art. 6(1)(b))
Secure the Service Fraud detection, MFA, rate limiting, abuse logs Legitimate interests (Art. 6(1)(f)) and legal obligation
Process payments and manage subscriptions Billing, taxes, refunds Contract; legal obligation
Customer support Responding to inquiries Contract; legitimate interests
Diagnose problems and improve the Service Crash logs, performance analytics, de-identified telemetry Legitimate interests
Send transactional emails Verification, password reset, security alerts, report delivery Contract; legal obligation
Comply with legal obligations Tax, accounting, lawful requests Legal obligation
Recipient access logs Audit of magic-link views, abuse prevention Legitimate interests (recipient); contract (sender)

We do not use Customer Content to train, fine-tune, or evaluate AI models. See Section 5.

You may withdraw consent at any time where processing is based on consent.

4. Notice to Report Recipients (GDPR Article 14)

If you received a report through ReceiverX, this is your notice under GDPR Article 14 (and analogous notice requirements under U.S. state law).

Who is responsible for your data.

Our contact details. ReceiverX LLC, info@receiver-x.com (privacy: privacy@receiver-x.com); mailing address ReceiverX LLC, c/o Texan Registered Agent LLC, 5900 Balcones Drive, Suite 100, Austin, TX 78731, USA. Once appointed, our EU/UK Article 27 representative will be listed in Section 16.

Categories of personal data we process about you.

Source. The report sender provided your email address. Access-log data is collected automatically when you open the link.

Purposes and legal bases (GDPR Art. 6).

Recipients of your data. Our Sub-processors listed in Section 6 (in particular, our hosting, database, file-storage, and email-delivery providers). We do not share your information with advertisers and do not sell or "share" it for cross-context behavioral advertising.

International transfers. Your data is processed in the United States. Where Section 11 applies, we rely on the Standard Contractual Clauses, the UK Addendum, and equivalent safeguards.

Retention. We retain access logs for up to 24 months. Report content is retained for as long as the sender retains the report or as the Tenant's retention policy directs (see Section 10).

Your rights. You have the rights described in Section 9, including access, correction, deletion, restriction, objection, and (in the EEA/UK/Switzerland) the right to lodge a complaint with a supervisory authority.

How to exercise rights. Email info@receiver-x.com or contact the sender directly. We will route requests to the appropriate controller.

Choice not to view. You are not obligated to open the link. Links expire automatically; not opening the link will not result in adverse consequences from us.

No automated decisions with legal effects. We do not use your data to make solely automated decisions producing legal or similarly significant effects on you.

5. AI Features and Customer Content

When you use AI-assisted scanning, images you upload are sent to our AI processing pipeline, which may include AWS Bedrock and other providers identified on our sub-processor list, acting solely as our processors.

6. Sub-Processors

We use the following categories of sub-processors. The current itemized sub-processor list, including entity names, services, and processing locations, is published at /legal/sub-processors and is also available on request to info@receiver-x.com.

Sub-processors (process Customer Content on our behalf):

Purpose Provider (current) Location
Application hosting and edge delivery Vercel Inc. United States
Database (PostgreSQL) Neon Inc. United States
File storage Vercel Blob (Vercel Inc.) and/or Cloudflare R2 (Cloudflare, Inc.) United States
Transactional email Resend United States
Rate limiting and caching Upstash Inc. United States
Single sign-on (optional) Google LLC United States
AI image analysis Amazon Web Services (AWS Bedrock) United States
Video content delivery (training videos) BunnyWay d.o.o. (bunny.net) EU (Slovenia); global edge

Platform providers (independent controllers — not DPA sub-processors for Tenant Customer Content):

Purpose Provider (current) Location
Mobile app distribution; in-app purchase processing where used Apple Inc.; Google LLC (Google Play) United States
Merchant of record and payment processing for website purchases Paddle (Paddle.com Inc. — U.S.; Paddle.com (Canada) Ltd. — Canada; Paddle.com Market Limited — all other countries) United States; Canada; United Kingdom

We require sub-processors to maintain appropriate technical and organizational measures and to process personal data only on our documented instructions.

Sub-processor change notice. We will give at least 30 days' prior notice of any new or replacement sub-processor by updating the list at /legal/sub-processors and, by default, emailing all Tenant administrative and legal contacts of record. Tenants may register additional notification addresses or distribution lists with legal@receiver-x.com. If a Tenant has a reasonable, documented objection on data-protection grounds, we will work in good faith to provide an alternative; if we cannot, the Tenant may terminate the affected portion of the Service for material cause and receive a refund of prepaid, unused fees. Emergency replacements (for example, a sub-processor breach or termination) may occur with shorter notice.

7. Cookies and Similar Technologies

We use cookies and similar technologies to:

You can control cookies through your browser settings. Some features may not work without certain cookies. Where required by law, we will request your consent before placing non-essential cookies and will honor recognized opt-out signals such as Global Privacy Control (GPC) as a valid opt-out of "sale" and "sharing" under applicable U.S. state laws.

8. No Advertising

The Service does not display third-party advertising. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

9. Your Rights and Choices

Depending on where you live, you may have rights regarding your personal information, including the right to:

9.1 How to Exercise Rights

We will respond within the time required by applicable law (typically 30–45 days). We may need to verify your identity before fulfilling certain requests. You may use an authorized agent. We will not discriminate against you for exercising your rights.

9.2 Authorized Agents and Verification

Authorized agents must provide signed, written permission. We may require verification of the agent's identity and confirmation directly from the consumer.

9.3 Appeals

If we deny a request and you reside in a U.S. state that grants an appeal right (for example, Colorado, Virginia, Connecticut, Texas), you may appeal by replying to our denial email; we will respond within the statutory period.

9.4 Do Not Sell or Share My Personal Information

To opt out of "sale" or "sharing" of your personal information for cross-context behavioral advertising, including targeted advertising:

Because users under 16 are not permitted to register for or use the Service, we do not knowingly sell or share the personal information of any user under 16. Children under 13 are subject to additional COPPA-specific protections.

10. Data Retention

We retain personal information only as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Typical retention periods:

Data Retention
Account data While account is active. After deletion, removed from active systems within 30 days, from backups within 90 days, except records we must retain for legal, tax, or fraud-prevention reasons (typically up to 7 years)
Customer Content (reports, images, PDFs) While retained by you or per your Tenant's retention policy. Deleted content purged from active systems within 30 days and from backups within 90 days
Recipient access logs Up to 24 months
Audit logs (admin actions) Up to 24 months
Login / security logs Up to 24 months
Email delivery logs Up to 12 months
Payment records As required by tax and accounting law (typically up to 7 years)

When termination occurs, the export window in Section 12 of our Terms applies.

11. International Data Transfers

We are based in the United States, and our sub-processors are primarily located in the United States. If you access the Service from outside the United States, your personal information will be transferred to and processed in the United States and other countries that may have data-protection laws different from your country.

For transfers from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (Module 2 for transfers from controllers to processors and Module 3 for processor-to-processor) together with the UK International Data Transfer Addendum, and, where applicable, the EU-US Data Privacy Framework. Copies of the SCCs we rely on are available on request.

12. Security and Breach Notification

We use industry-recognized technical and organizational measures appropriate to the risk, including:

No method of transmission or storage is 100% secure. You are responsible for keeping your password and devices secure. Notify us immediately if you suspect unauthorized access.

Breach notification. As a processor, we will notify Tenants and direct controllers of a personal-data breach affecting their data without undue delay after becoming aware of it, and in any event within the time required by applicable law and our DPA. We will notify affected individuals where required by law and will cooperate with regulators on required notifications under the GDPR (Articles 33–34) and U.S. state breach-notification laws.

13. Children

The Service is intended for users age 16 or older. We do not knowingly permit registration or use by anyone under 16; if we learn that a user is under 16, we will deactivate the account and delete the data. In addition, we do not knowingly collect personal information from children under 13 without verifiable parental consent under the Children's Online Privacy Protection Act (COPPA, 16 C.F.R. Part 312). We do not knowingly sell or share the personal information of any user under 16 (and, for users under 13, only with verifiable parental consent and only as COPPA permits). If you believe we have collected information from a person under 16, contact us at privacy@receiver-x.com and we will delete it.

14. Mobile App Disclosures

Our mobile app may collect and use the following categories of data, also disclosed in our App Store and Google Play privacy labels:

We do not use the App Tracking Transparency framework to track you across other companies' apps and websites without your permission.

15. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide additional notice (for example, by email or in-product notice) and will not apply changes retroactively to data already collected without an appropriate legal basis. The "Last Updated" date above will be revised. Your continued use of the Service after the effective date constitutes acceptance.

16. Contact

For privacy questions, requests, or complaints:

ReceiverX LLC Website: https://receiver-x.com Email: info@receiver-x.com Privacy: privacy@receiver-x.com Mailing address: ReceiverX LLC, c/o Texan Registered Agent LLC, 5900 Balcones Drive, Suite 100, Austin, TX 78731, USA

EEA/UK Representative. Where required by GDPR Article 27 or UK GDPR Article 27, we will appoint a representative in the EEA and/or the UK before commencing in-scope processing. EEA and UK users may, in the meantime, contact us at privacy@receiver-x.com for any GDPR/UK GDPR matter and we will respond directly. Once an Article 27 representative is appointed, the representative's name and contact details will be published here.


Appendix A — CCPA/CPRA Categories Collected (Past 12 Months)

Scroll horizontally to see all columns →

Category (Cal. Civ. Code §1798.140) Collected? Sources Business / Commercial Purpose Disclosed for Business Purpose to Sold? Shared?
A. Identifiers (name, email, IP, device ID, account ID) Yes You; automatic Operate Service, security, support Sub-processors in §6 No monetary sale; however, see footnote* No
B. Customer records (Cal. Civ. Code §1798.80) Yes You Account management, billing Sub-processors in §6 No No
C. Protected classifications No No No
D. Commercial information (subscription, transaction history) Yes You; Paddle Billing, support Paddle, accountants No No
E. Biometric information No No No
F. Internet/network activity (usage data, device/browser) Yes Automatic Operate, secure, improve, analytics Sub-processors in §6 No monetary sale; however, see footnote* No
G. Geolocation (precise) Sometimes (if you attach) You Report content Recipients you choose No No
H. Sensory data (photos uploaded for grading) Yes You Generate AI Output, deliver reports AI sub-processors, recipients No No
I. Professional/employment information If you provide it You Account profile None beyond §6 No No
J. Education information No No No
K. Inferences Limited (technical) Automatic Improve Service Sub-processors in §6 No No
L. Sensitive PI (account credentials; precise geo if attached) Yes You Authentication; report content None beyond purpose No No

*Sale/share footnote. ReceiverX does not sell personal information for monetary consideration and does not share personal information for cross-context behavioral advertising.