Security
Owed stores purchase details and claim history so you can collect what companies owe you. This page explains, in plain language, how we handle that information today. It describes our practices — it is not a warranty that any system is perfectly secure.
You approve every send
Claim letters from your connected Gmail go out only after you approve them. The agent drafts; you decide.
Accounts are separated
We design the product so each signed-in member can access their own ledger — not someone else’s.
Gmail access stays limited
Connecting Gmail is optional. We request only the send and read scopes needed for receipts and approved letters.
No ads. We don’t sell your data.
Your purchases and inbox signals are not an advertising product. We don’t sell personal information.
You can leave with your data
Export a copy or delete your account from Settings. Deletion removes live account data; residual backups expire on a rolling schedule.
Card numbers stay with Stripe
Paid plans go through Stripe Checkout. We don’t store full card numbers on Owed’s servers.
Signing in and sessions
You can sign in with a magic link, a password, or Google through our auth provider. After a password reset, we revoke other active sessions on your account so that reset can end unwanted access. Sensitive server jobs and payment webhooks use separate credentials from your login session. Keep your email account secure — access to it can mean access to Owed.
Optional Gmail connection
Gmail is off by default. If you connect it, we use read access to find order and receipt emails and send access only for letters you individually approve. We store extracted purchase fields, a copy of the matched order email as proof of purchase, and a credential needed to keep the connection working — not a copy of your whole mailbox. You can disconnect in Settings or revoke access in your Google account.
How we use (and don’t use) your data
We don’t use Gmail data for advertising, don’t sell personal information, and don’t use your content to train our own AI models. Our AI vendors process receipt and claim text to extract purchases and draft letters under contracts that restrict training use. Humans don’t read your Gmail content in ordinary operation; access is limited to cases such as your request, security investigation, or legal requirement.
Report a security concern
If you believe you’ve found a security issue, email security@owed.claims with enough detail for us to understand and reproduce it. Please don’t access other people’s accounts or data, don’t disrupt the service, and don’t publicly disclose the issue before we’ve had a reasonable chance to review it. We don’t run a paid bug-bounty program. This invitation is for responsible reporting — it is not permission to test in ways that break the law or our Terms.
Email security@owed.claimsIf something goes wrong
No product can promise zero incidents. If we confirm a security incident that affects personal information, we will investigate, take steps to contain it, and provide notices required by applicable law. For questions about a security issue, contact security@owed.claims.