Draft — not yet in force
This document is complete except for the identity of the controller, which is marked below and must be filled in before publication. Until then it is published for review, not as a binding document.
Privacy Policy
Snapolo photographs receipts and turns them into spending history. A photograph of your shopping is personal data, and some of it is sensitive, so this policy is specific about what happens to it, who else sees it, and how long it stays. Version v2026-08-24, effective 2026-08-24.
1. Who is responsible for your data
The controller of your personal data is [TO BE COMPLETED: legal name], [TO BE COMPLETED: registered address], [TO BE COMPLETED: country] (registration: [TO BE COMPLETED: registration number]).
For anything in this policy — including access, export and erasure requests — write to [TO BE COMPLETED: contact e-mail]. We answer within one month, as Art. 12(3) GDPR requires.
2. What we collect
We collect only what the product needs to work. There is no advertising, no third-party analytics, and no tracking cookies — the website stores a sign-in session in your browser and nothing else.
| Category | What it is | Where it comes from |
|---|---|---|
| Account | E-mail address, display name, whether the address is verified, sign-in method, and an internal user id | You, and Firebase Authentication when you sign in |
| Receipts | The photographs you take, text recognised on your device, and everything extracted from them: shop name and address, date and time, line items, quantities, prices, discounts, totals and currency | You |
| Your corrections | Product renames, category changes and shop-name overrides you make, which we apply across your own history | You |
| Preferences | Language, preferred currency, and how product names are displayed | You |
| Usage | One record per receipt processed (for your monthly quota), and the last synchronisation time of each device | Automatically, as you use the app |
| Consent and audit | Which consents you gave and when, with the IP address and browser or app identifier at that moment, and a record of privacy-relevant actions such as exports and deletion requests | Automatically, as evidence that we did what you asked |
| Subscription | Which plan you are on, its status and period, and the store identifier of the purchase | Google Play or the App Store, through RevenueCat |
We never receive your card details. Purchases are made through the app store, which acts as the seller and processes the payment.
3. Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service: storing your receipts, extracting their contents, showing your spending, synchronising your devices | Performance of a contract — Art. 6(1)(b) |
| Recording your consents and privacy requests | Legal obligation — Art. 6(1)(c) |
| Billing, quotas and subscription state | Performance of a contract — Art. 6(1)(b), and legal obligation for accounting records |
| Keeping the service secure and preventing abuse of the free quota | Legitimate interests — Art. 6(1)(f) |
| Optional product analytics and marketing messages, if you tick those boxes | Consent — Art. 6(1)(a), withdrawable at any time |
Extraction from a receipt is automated, but it produces a draft you review and can correct. Nothing here makes a decision about you with legal or similarly significant effects, so Art. 22 GDPR does not apply.
4. Receipt photographs specifically
A receipt photograph is uploaded to Google Cloud Storage in the europe-west1 region (Belgium). To extract its contents it is sent to Google’s Gemini API; for some receipts, text is first extracted by Google Cloud Document AI in the EU multi-region. Your device may also recognise text locally and send that text instead of, or alongside, the image — which is faster and sends less.
These providers process the image on our behalf, under Google’s data processing terms, to return the extracted text. Confirm the current terms of the API tier in use before relying on any statement about training; where a tier permits content to be used to improve the provider’s models, we do not use it.
A receipt can reveal more than shopping. A pharmacy purchase can suggest something about your health, and other purchases can suggest beliefs or habits. We do not look for such data and we do not use it to categorise you, but you choose what to photograph, and by consenting to receipt processing you consent to us processing whatever those receipts contain (Art. 9(2)(a) GDPR where the content is a special category of data). If you would rather a particular receipt was not processed, do not scan it — and you can delete any receipt, or only its photograph, at any time.
5. How long we keep it
| What | How long |
|---|---|
| Receipt photographs | The retention you set per receipt — 30 days, 90 days, one year, or kept until you delete it. New receipts default to 90 days. A daily job deletes the image once the deadline passes and keeps the receipt data. |
| Receipt data (items, prices, shops, dates) | Until you delete the receipt, or until your account is erased |
| Deleted receipts | Marked deleted immediately and hidden everywhere; the row is kept so the deletion also reaches your other devices |
| Account and everything attached to it | Erased 30 days after you ask, by a daily job. During those 30 days you can undo it at snapolo.app/restore and get everything back. |
| Audit records | One year — except records of consent, export, deletion requests and erasure, which are kept as the evidence that we honoured them |
When an account is erased, the database row and everything hanging off it are deleted, and the Firebase sign-in account is deleted with it.
6. Who else processes your data
These are our processors. Each one receives only what its job needs, and none of them is permitted to use your data for their own purposes.
| Processor | What it receives | Where |
|---|---|---|
| Google Cloud (Cloud Run, Cloud SQL, Cloud Storage, Cloud Tasks) | Everything: the application, the database and the receipt images | europe-west1 (Belgium) |
| Firebase Authentication (Google) | E-mail address, sign-in credentials and sign-in metadata | Google infrastructure, including outside the EEA |
| Google Gemini API | Receipt images and recognised text, to extract their contents | Google infrastructure |
| Google Cloud Document AI | Receipt images, for text recognition on some receipts | EU multi-region |
| RevenueCat | Subscription state and an anonymous user identifier. No receipt data. | United States |
| Vercel | Hosting of the website. Requests and technical logs; no receipt data is stored there. | United States and global edge network |
No e-mail provider is listed because the product does not yet send e-mail other than Firebase’s own sign-in messages. One will be named here before the first message is sent.
7. Transfers outside the European Economic Area
Your receipts and the database live in the EU. Two processors are established in the United States — RevenueCat and Vercel — and Google’s services may process data outside the EEA. Those transfers rely on the European Commission’s Standard Contractual Clauses, and on the EU–US Data Privacy Framework where the provider is certified under it.
8. Your rights
Under the GDPR you have the rights below. Most of them are buttons in the product rather than requests you have to make.
- Access and portability — export everything we hold about you, as a structured file, from the app’s privacy settings.
- Rectification — correct a shop name, a product name, a price or a date directly on the receipt. Your corrections apply to your own history.
- Erasure — delete your account from the app. Deletion happens 30 days later; until then you can undo it by signing in at snapolo.app/restore. After that it is gone and cannot be recovered.
- Restriction and objection — write to us; where you object to processing based on legitimate interests, we stop unless we have compelling grounds.
- Withdrawing consent — turn off analytics or marketing consent at any time, without affecting what was lawful before.
- Complaint — you may complain to a supervisory authority, in particular [TO BE COMPLETED: supervisory authority], or to the authority where you live or work.
To exercise anything that is not a button, write to [TO BE COMPLETED: contact e-mail].
9. How we protect it
Traffic is encrypted in transit. Sign-in is handled by Firebase Authentication, so we never see or store your password. Every request is checked against your own account, and receipt images are served through short-lived links rather than public URLs.
Administrative access is limited to accounts explicitly granted it, is used only to operate the service, and administrative interfaces are on a separate address requiring a separate sign-in.
No system is perfect. If a breach is likely to result in a risk to your rights, we notify the supervisory authority within 72 hours and, where the risk is high, we tell you.
10. Children
Snapolo is not intended for children. You must be at least 16 years old to have an account. If we learn that an account belongs to a younger person, we delete it.
11. Changes to this policy
This policy is versioned. The current version is v2026-08-24, effective 2026-08-24.
Your consent is recorded against the version that was in force when you gave it, and that record is never overwritten. When we publish a materially different version, we ask you to accept it again rather than assuming your earlier agreement carries over.
12. Contact
[TO BE COMPLETED: legal name], [TO BE COMPLETED: registered address], [TO BE COMPLETED: country].
E-mail: [TO BE COMPLETED: contact e-mail].