ItemRecover uses a small number of carefully selected technology partners to deliver core features.
Each partner is bound by a data-processing agreement (DPA). This page lists every sub-processor
that may handle your personal data, what they do, and the privacy controls in place.
What you get: EU routing where available, short retention windows, and contractual
no-training commitments from every partner that touches uploaded content.
Receipt OCR — primary
| Provider | Google Cloud (Gemini API) |
| Purpose | Extracts merchant, date, amount, and line items from uploaded receipt images and PDFs. |
| Data sent | The uploaded image or PDF. No account information, no other data. |
| Retention | 24 hours maximum. Google does not retain API inputs beyond this window under the standard API DPA. |
| Training opt-in | None. The contractual DPA explicitly prohibits use of API inputs for model training. |
| Region | EU-region endpoint used where available. Requests may route through Google's global infrastructure when EU capacity is constrained. |
| DPA | Google Cloud Data Processing Addendum — signed and in force. |
Receipt OCR — fallback
| Provider | OpenAI (GPT-4o via API) |
| Purpose | Fallback OCR extraction when the primary Google provider is unavailable or returns a low-confidence result. |
| Data sent | The uploaded image or PDF — only when the primary provider fails. No account information. |
| Retention | Zero-day retention. Under the OpenAI API enterprise tier, inputs are not retained after the request completes. |
| Training opt-in | None. API inputs are not used for OpenAI model training under the enterprise DPA. |
| Region | Requests may route through OpenAI's US-based infrastructure. This is a fallback path used only when the EU-primary provider is unavailable. |
| DPA | OpenAI Data Processing Addendum — signed and in force. |
Email transport
| Provider | Brevo (formerly Sendinblue) |
| Purpose | Transactional email delivery — accountant handoffs, member invitations, account notifications, and receipt-by-email inbound processing. |
| Data sent | Recipient email address, sender name, and email body content. For inbound receipt emails: the raw email including any attached receipt images. |
| Retention | Brevo retains transactional email logs for 30 days for deliverability tracking. |
| Region | EU servers (France). Brevo is a French company and stores data within the EU. |
| DPA | Brevo Data Processing Agreement — signed and in force. GDPR-compliant. |
Hosting
| Provider | Hetzner Online GmbH |
| Purpose | Application server, database, and file storage infrastructure. |
| Data handled | All application data including account information, Passport records, receipt files, and uploaded images. |
| Region | EU — Helsinki (Finland) and Nuremberg (Germany). |
| Compliance | Hetzner is GDPR-compliant. Data remains within the EU at all times. |
| DPA | Hetzner Data Processing Agreement — accepted and in force. |
Storage
| Current (Phase 6) | Local filesystem on Hetzner servers (see Hosting above). No additional sub-processor. |
| Planned (Phase 8) | Migration to S3-compatible object storage in an EU region. Sub-processor details will be added here before the migration completes. |
Questions? Contact us at contact-us or review our full
Privacy Policy.
This page is updated whenever we add or change a sub-processor.
Last updated: May 2026.