Privacy Policy
Effective date: 29 July 2026
This Privacy Policy explains how Expense Tracker ("we", "us", "our") collects, uses, stores and shares personal information when you use the Expense Tracker mobile application and related services (the "Service"). Expense Tracker records what you spend from photographs of receipts. A record of your purchases is sensitive by nature, and this policy is written to be specific about what happens to it.
1. Data We Collect
- Account: your email address, your name, your password (stored only as a hash, never in readable form) and your app language.
- Expenses: amount, currency, merchant, category, purchase date, your notes, and your ratings of a place (overall, what you had, service, atmosphere). If you enable line items, the individual positions on the receipt and their prices.
- Receipt images and photos: the receipt photo you capture, plus any further photos you attach to an expense.
- Location: the location of an expense, so it can be shown on the map, and — only when you open the map — your device location, so the map can start where you are. Expense Tracker does not collect location in the background.
- Groups: the groups you belong to, your role in them, invite codes you create or use, and which of your receipts you have shared with which group.
- Notifications: your push-notification token and your notification preferences.
- Technical data: device platform, app diagnostics and crash reports, authentication tokens and security logs. For administrative actions on our own systems we log an IP address and user agent.
We do not collect a date of birth, we do not ask for bank or card details, and we do not connect to your bank accounts.
2. Automated Receipt Reading
This is the only part of the Service that sends your content to a third party, so it is set out separately.
- It is opt-in. The app explains what will happen and asks for your consent before the first receipt image ever leaves your device. You can withdraw consent at any time in Settings → Receipt scanning, and you can separately turn off the reading of individual line items.
- Who reads it: the receipt image is sent to a third-party AI service provider, acting as our processor under a data-processing agreement, which returns the merchant, amount, currency, date, category and, if enabled, the line items. It is not used to train models. We will tell you the provider's identity on request — email office@rockndevel.com.
- Payment identifiers are removed: the instruction sent with the image forbids transcribing card numbers or IBANs, and the returned text is additionally checked and scrubbed of anything matching a card number or IBAN before it is stored.
- What we keep: the extracted result becomes your expense. We also retain the raw extraction output to diagnose and improve accuracy; it is scrubbed as described above and is accessible only to our own administrators who need it for that purpose.
- The photo is deleted: receipt images are deleted 90 days after capture. The expense created from the receipt is kept until you delete it or your account.
- You can decline: if you do, no image is sent anywhere and you fill the expense in yourself.
3. Why We Use Data
- Provide the core features — capturing expenses, reading receipts, reports, the map, groups and notifications.
- Authenticate you and keep your account secure.
- Show your expenses at the place they happened and, in aggregate only, show typical spend and ratings for places in Explore.
- Share the receipts you chose to share with the groups you chose to share them with.
- Diagnose crashes and errors, and improve the accuracy of receipt reading.
- Comply with legal obligations and enforce our Terms.
4. Legal Bases (EEA/UK)
- Contract: to provide the Service you signed up for — your account, expenses, reports, map and groups.
- Consent: for automated receipt reading, for location access, and for push notifications. You can withdraw any of these at any time without losing access to the rest of the Service.
- Legitimate interests: security, abuse and fraud prevention, error diagnosis and improving extraction accuracy.
- Legal obligation: regulatory compliance and responding to lawful requests.
5. Sharing of Data & Service Providers
We do not sell your personal data and we do not use it for advertising. We share it only as needed to run the Service:
- Receipt reading: a third-party AI service provider — receives receipt images only when you have enabled scanning (section 2), and only for as long as it takes to read them.
- Hosting & storage: our own server infrastructure, including self-hosted object storage for receipt images and photos, kept private and served only through short-lived links.
- Address lookup: the OpenStreetMap Nominatim service, to turn a merchant address into map coordinates. It receives the address being looked up, not your identity or your expense; results are cached so the same address is not looked up repeatedly.
- Push notifications: the Expo push service and/or Apple (APNs) and Google (Firebase Cloud Messaging).
- Email delivery: our email provider, for verification, password-reset and notification emails.
- Error monitoring: Sentry, for crash and error diagnostics.
- Other users: only what you chose to share — a receipt you shared with a group, visible to that group's members, and your ratings as part of anonymous averages in Explore.
- Authorities: where required by law.
6. What Other People Can See
- Nobody sees your expenses by default. A receipt becomes visible to others only when you share it with a group, either while reviewing it or via the "share every new receipt" setting for that group.
- Members of a group see the receipts shared with that group and a per-member spending total. They cannot edit your receipts.
- Explore shows aggregates only. Typical spend and ratings for a place are averages computed across users' visits. They contain no receipts, no names, no individual amounts, and no indication of who visited.
- When you leave a group, are removed from it, or unshare a receipt, that access ends.
7. International Transfers
Your data may be processed in countries outside your own — in particular, receipt images sent for automated reading are processed in the United States. Where required, we rely on appropriate safeguards for cross-border transfers, such as the European Commission's standard contractual clauses.
8. Data Retention
- Receipt images: deleted 90 days after capture.
- Expenses and everything you added to them: kept while your account exists, until you delete them.
- Address lookup cache: held for up to 180 days, then refreshed. It stores addresses, not people.
- Account data: kept while your account is active. On deletion it is removed as described in section 10.
- Security and audit logs: retained for the period necessary for security and legal compliance.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you, and receive a copy of it.
- Have inaccurate data corrected, or have your data deleted.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw consent — for receipt scanning, location or notifications — at any time, without affecting processing that already took place.
- Complain to a supervisory authority. In Austria this is the Datenschutzbehörde (dsb.gv.at).
To exercise any of these, email office@rockndevel.com from the address on your account.
10. How to Delete Your Data
You can delete your account and data at any time in the app under Settings → Account → Delete account, through our web deletion form, or by emailing office@rockndevel.com from your account email address. Deletion removes your account, expenses, receipt images and photos, notes, ratings, places and visit history, and your group memberships together with the receipts you shared with those groups. We complete deletion requests within 30 days. Records we must keep by law, and anonymous aggregates that can no longer be linked to you — such as the averages shown in Explore — may remain.
11. Children
The Service is not directed at children. You must be at least 16 to create an account, or older where your country sets a higher age of digital consent. We do not knowingly collect data from anyone below that age; if we learn that we have, we delete the account and its data. See our Child Safety Standards.
12. Security
We apply technical and organizational safeguards, including encryption in transit, hashed passwords, private media storage reachable only through time-limited links, access controls with per-domain permissions for administrators, audit logging of administrative actions, and the removal of payment identifiers described in section 2. No system is completely secure.
13. App Permissions (Mobile)
- Camera: to photograph receipts.
- Photos: to attach an existing image to an expense.
- Location (while using the app): to open the map where you are. There is no background location collection.
- Notifications: to tell you when something relevant happens, such as a finished receipt or group activity.
Every one of these is optional; declining one disables only the feature that needs it.
14. Contact
Privacy inquiries: office@rockndevel.com
Controller: rockNdevel GmbH, Webgasse 29/24, 1060 Vienna, Austria. See our Legal Notice for full company details.
15. Changes to This Policy
We may update this policy. We will revise the effective date and give in-app or website notice where required.