Privacy Policy
Last updated: August 24, 2026
1. Who we are
FareFare ("FareFare", "we", "us") is the service available at farefare.app that turns Uber receipt emails into a personal spending dashboard. For anything in this policy, contact us at hello@farefare.app. We are the controller of the limited personal data described in section 4.
FareFare is not affiliated with, endorsed by, or connected to Uber Technologies, Inc.
2. Data that never leaves your device
FareFare is built local-first. The following is processed entirely in your browser, on your device, and is never transmitted to our servers:
- the content of your receipt emails (.eml files, .mbox archives, or messages fetched from Gmail);
- the trip data parsed from them — dates, amounts, currencies, pickup and drop-off addresses, routes;
- everything derived from that data: totals, charts, route statistics, budgets, tags, and reports.
This data lives in your browser's local storage on your device. It stays there until you clear it — use "Start over" in the app, or clear your browser's site data for farefare.app, and it is gone. Because we never receive it, we cannot access it, recover it, or delete it for you: you hold the only copy.
3. Gmail access
Connecting Gmail is optional. If you connect it, we request the read-only Gmail scope (gmail.readonly) and use it for exactly one purpose: your browser fetches your Uber receipt emails directly from Google's servers so it can parse them locally.
- The Gmail access token is held in the memory of the open tab only. It is not written to disk and it is discarded when the tab closes.
- Your email messages travel directly from Google to your browser. They never pass through, and are never stored on, FareFare servers.
- We never modify, send, or delete email, and we cannot — the scope we request does not allow it.
- You can revoke FareFare's access at any time at myaccount.google.com/permissions.
FareFare's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. In particular, Gmail data is used only to provide the receipt-parsing feature you see, is never used for advertising, and is never transferred to third parties or used to train AI or machine-learning models.
4. The data we do store
Signing in and subscribing are optional — you can use the free plan with file uploads without ever creating an account. If you do sign in with Google or subscribe to Premium, our servers process only the following:
Account session
When you sign in with Google, we receive your name, email address, and profile picture from Google. These are kept in a signed session cookie in your browser — we do not maintain a user database.
Billing record
If you subscribe to Premium, we store one record keyed to your email address: your Stripe customer ID, your subscription status and plan, and when the paid period ends. This exists solely so the app knows whether to unlock Premium features.
Push subscription
If you enable notifications, we store the push subscription your browser generates (a delivery endpoint and its encryption keys), keyed to your email address, so we can send you a weekly digest notification. Because our servers know nothing about your trips, these notifications contain no trip data — they are a generic prompt to open your dashboard. Turning notifications off in the app deletes the subscription from our servers.
Payment details
Payments are processed by Stripe. Your card number and full billing details go directly to Stripe and never touch FareFare's servers. Stripe processes them under its own privacy policy at stripe.com/privacy.
Server logs
Like almost every website, our hosting provider generates short-lived technical logs (IP address, request path, timestamps) used only for security and to keep the service running.
5. What we don't do
- No analytics or behavioral tracking of any kind.
- No advertising, and no sale or sharing of personal data for advertising.
- No marketing email list.
- No cookies other than the session cookies strictly necessary for signing in.
- No profiling and no automated decision-making with legal or similar effects.
6. Service providers
We use a small number of processors, each only for the purpose described, under contracts that restrict their use of the data:
- Vercel — hosting and delivery of the app, including server logs.
- Upstash — the database holding the billing record and push subscription described above.
- Stripe — payment processing and subscription billing.
- Google — sign-in, and the Gmail API when you choose to connect your mailbox.
Some of these providers process data in the United States. Where data leaves the European Economic Area, transfers rely on the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses. We do not share personal data with anyone else, unless we are legally required to.
7. Legal bases
Where the GDPR applies, we process personal data on these bases:
- Performance of a contract (Art. 6(1)(b)) — your account session and billing record, needed to provide Premium.
- Consent (Art. 6(1)(a)) — Gmail access and push notifications, each of which you may decline or withdraw at any time without losing the rest of the service.
- Legitimate interests (Art. 6(1)(f)) — short-lived security and operational logs.
8. Retention
- Trip data: stored only on your device, for as long as you keep it there.
- Gmail token: memory of the open tab only; gone when the tab closes.
- Session cookie: expires on its own; deleted when you sign out.
- Billing record: kept while your subscription is active and deleted on request once it has ended. Stripe retains transaction records as required by tax and accounting law.
- Push subscription: deleted when you disable notifications, or automatically when the endpoint stops accepting delivery.
9. Your rights
Depending on where you live — and in any case if you are in the EU/EEA or UK — you have the right to access, correct, delete, and receive a copy of your personal data, to object to or restrict our processing of it, and to withdraw any consent at any time. Since we hold almost nothing, most of this you can do yourself: "Start over" wipes your device-local data, revoking Gmail access takes one click in your Google account, and disabling notifications deletes the push subscription. For anything else — including deleting your billing record — email hello@farefare.app and we will respond within one month. You also have the right to lodge a complaint with your local data-protection supervisory authority.
10. Security
All traffic to FareFare and between FareFare and its providers is encrypted in transit (TLS). Session cookies are signed and HTTP-only. Push subscriptions use the Web Push protocol's built-in encryption. The most effective security measure, though, is architectural: the sensitive data — where you went and what you paid — never reaches us at all.
11. Children
FareFare is not directed at children and we do not knowingly process data of anyone under 16. Uber requires account holders to be adults, so the service has no reason to be used by children.
12. Changes to this policy
If we change this policy, we will update it here and revise the date at the top. If a change materially affects data we hold about you — which, given how little we hold, would be unusual — we will make the change prominent in the app before it takes effect.
13. Contact
Questions, requests, or complaints: hello@farefare.app.