Privacy Policy
Last updated: 30 July 2026
Orden (“we”, “us”) operates the Orden macOS app, Chrome extension, iOS app, and web dashboard at ordenapp.no. This policy explains what data we collect, how we use it, and the choices you have. The data controller is Diverse AS (org. nr. 937 775 466), Friis' gate 4, 0187 Oslo, Norway. We operate under Norwegian and EU law (GDPR).
What we collect
- Account data. Email address and authentication tokens, used to sign you in. Stored via Supabase Auth.
- Receipts and invoices. Files the extension or app collects from vendor billing pages on your instruction, and the structured fields extracted from them (amount, date, vendor). Stored in your private Supabase Storage bucket.
- Vendor sessions. To fetch receipts for you, Orden saves the signed-in session (cookies and similar tokens) for each vendor you connect, so collections can run without you logging in every time. These sessions are stored on our servers, protected with encryption, and used only to collect your receipts. We never see or store your vendor passwords.
- Gmail data (optional). If you connect a Gmail account, we request read-only access (scope:
gmail.readonly) to find receipt emails and download their attachments. Orden searches only for the vendors you have set up. If you run the optional inbox scan, it reads sender, subject and date to spot senders who bill you regularly, and opens one message per suggested vendor to check it really is a receipt — the scan itself stores nothing. We store the OAuth refresh token encrypted, and keep only the receipts you chose to collect. - Subscription data. If you subscribe, Stripe processes your payment. We store your Stripe customer ID and subscription status, not your card number.
- Contact and lead data. If you leave your email on our website (for a download link or a quiz result), we store the address and what you asked for so we can send it, and may follow up about Orden. Every such email has an unsubscribe link.
- Support and diagnostics. Messages you send via the in-app support form, and technical logs from collection runs (including screenshots of failed collection attempts) used to debug problems.
How we use it
Primarily to provide the service: collecting, storing, and displaying your receipts; authenticating you; and, if you subscribe, billing you (legal basis: performance of our contract with you). With your consent we also use analytics and advertising cookies as described below. We may contact people who left their email on our website about Orden (legal basis: consent and legitimate interest, with an opt-out in every email). We do not sell your data and do not train AI models on it.
Automated receipt parsing
When a receipt file is collected, we send its contents to OpenAI's API to extract structured fields (amount, date, vendor) and to verify the capture is a real receipt. When Orden searches a connected inbox, it sends the sender, subject and the first part of the body of candidate emails the same way, so it can tell a receipt from a notification or newsletter. OpenAI is contractually bound not to train on API data. AI parsing is a core part of how Orden works; if you have concerns about it, contact us at hello@ordenapp.no.
Cookies and analytics
On ordenapp.no we ask for your consent before setting analytics or advertising cookies. If you accept, we use PostHog (EU-hosted) for product analytics and session replay — inputs and text are masked, and no receipt content is recorded. You can change your mind at any time via the “Cookie settings” link in the page footer. Strictly necessary cookies (sign-in, security) do not require consent.
Whether or not you accept, we keep a simple count of visits to our public pages so we know how many people reach the site. This uses no cookies and stores nothing on your device. To count the same visitor once per day without identifying anyone, our server derives a one-way fingerprint from your IP address and browser type; your IP address itself is never stored, and the fingerprint is salted and changes every day, so it cannot be used to follow you over time or link your visits to you.
Advertising
If you consent to advertising cookies, we use the Meta Pixel, LinkedIn Insight Tag, and Google Ads tag to measure whether our ads work (for example, that a visit or signup came from an ad). These tools receive standard web events (page views, signups, downloads) — never your receipts, vendor sessions, or email content. If you decline, none of these tags are loaded.
Who we share data with
- Supabase — database, authentication, and file storage (hosted in London, UK).
- Vercel — hosting for ordenapp.no.
- Google — the Gmail API when you explicitly connect a Gmail account, and Google Ads measurement if you consent to advertising cookies.
- OpenAI — receipt images and PDFs for field extraction and validation.
- Stripe — subscription billing if you are a paying customer.
- Resend — sending our transactional emails (invites, download links, quiz results).
- PostHog — product analytics and session replay (EU region), only if you consent. Inputs are masked and no receipt content is sent.
- Meta and LinkedIn — ad measurement events, only if you consent to advertising cookies.
Beyond the processors and consented ad measurement listed above, we do not share your data with anyone — no data brokers, no selling.
International transfers
Your receipts and account data are stored in the United Kingdom (Supabase, London region), which the EU Commission recognises as providing adequate data protection. Some processors are US companies (OpenAI, Stripe, Vercel, Google, Meta): transfers to them rely on the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses.
Google API user data
Orden's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Gmail message content is used only to provide the receipt collection you asked for: the receipts you collect are stored in your private Supabase bucket, and message text is sent to OpenAI solely to tell a real receipt from a newsletter and to read off its amount, date and vendor. OpenAI is contractually bound not to train on it. Gmail content is never used to serve ads, never sold, and never read by humans except (a) with your consent, (b) for security, or (c) as required by law.
Data retention
Your receipts and account data are kept until you delete them or close your account. Diagnostic screenshots from failed collection runs are deleted automatically after 90 days. On account deletion, we purge your data within 30 days from primary systems and within 90 days from backups, and we also delete your Stripe customer, revoke Gmail access at Google, and delete your analytics profile.
Your rights
Under GDPR you can access, correct, export, or delete your data. You can delete your account and export your data directly from Settings in the app, and withdraw consent for Gmail access at any time by disconnecting the account in settings or via myaccount.google.com/permissions. To exercise any other right, email hello@ordenapp.no. You also have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) or your local supervisory authority.
Security
Data is encrypted in transit (TLS) and at rest. Access is scoped per user with Supabase Row Level Security. OAuth tokens and vendor sessions are protected with encryption, and receipts live in private per-user storage.
Children
Orden is a tool for businesses and freelancers and is not directed at children. You must be at least 18 years old to create an account.
Contact
Orden is operated by Diverse AS (org. nr. 937 775 466), Friis' gate 4, 0187 Oslo, Norway. Contact: hello@ordenapp.no.
Changes
We will post updates to this page and update the “Last updated” date. Material changes will be announced by email.