1. Introduction
Welcome to Slipp. We value your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, and share your information when you use our mobile application ("App"). By using the App, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
- Account Information: When you register, we collect your username, email address, and password (stored securely as a cryptographic hash). We also store an authentication token (JWT) for session management.
- Receipt Images: We collect images of receipts you upload via camera or photo gallery. These images are stored on our servers and processed using AI/OCR technology via an external processing service (n8n workflow engine).
- Extracted Receipt Data: From each receipt, we extract and store: store/merchant name, store address, branch name, merchant category, receipt date and time, receipt number, cash register number, total amount, subtotal, currency, tax amount, tax rate, total discount, and the complete raw JSON response from AI analysis.
- Payment Information on Receipts: We extract and store payment method (e.g., cash, credit card) and the last 4 digits of the card used (if applicable) as shown on the receipt.
- Receipt Item Details: For each item on a receipt, we collect: item name, barcode number (if available), product category hierarchy, quantity, unit, unit price, total price, tax rate, product tags, perishability information (whether the product is perishable, estimated expiry days, suggested consume-by date), and warranty information (whether the item is a durable good, estimated warranty duration in months, warranty end date).
- AI Spending Analysis: Our AI engine categorizes each receipt into a spending category (e.g., Grocery, Electronics) and assigns a spending mood indicator (e.g., Need, Want). It also determines whether the purchase is a business expense.
- Credit & Transaction Data: We track your credit balance within the App, including transaction history (credit purchases, usage deductions for receipt scans, and trial credits). Plan credits reset on renewal, while purchased credits never expire. Switching from a monthly to an annual plan preserves your existing credits.
- Subscription Data: If you subscribe to a premium plan, we store your subscription details including plan type, purchase date, expiration date, auto-renewal status, and subscription status. Subscription management is handled via RevenueCat, which may collect transaction identifiers. Users can upgrade from monthly to annual plans.
- Feedback & Reports: If you submit feedback (feature requests, suggestions, complaints) or report receipt issues (wrong date, wrong total, missing items, wrong merchant), we store the content of your submissions along with your user ID.
- Device Information and Identifiers: We and our SDK providers may collect information about your mobile device, including device model, operating system version, Firebase app instance ID, Firebase installation or messaging identifiers, and Android Advertising ID where available. These identifiers are used for app functionality, analytics, fraud prevention, security, subscription support, notification delivery, and advertising or marketing measurement where permitted by your settings and applicable law.
- Push Notification Token: We collect your Firebase Cloud Messaging (FCM) token to send you push notifications about warranty reminders and app updates. You can disable notifications at any time from the app settings.
- Usage & Analytics Data: We use Google Firebase Analytics to understand and improve user behavior in the App. Analytics data may include app opens, screen views, navigation events, feature usage, session information, app version, device model, operating system, language, approximate region derived from IP address, Firebase app instance ID, and advertising identifiers where permitted by your device settings and applicable law. We do not send receipt images, extracted receipt content, payment card digits, passwords, or precise GPS location to Firebase Analytics as custom analytics data.
- Advertising and Marketing Data: We may use Firebase Analytics, Android Advertising ID, campaign attribution data, push notification engagement, and aggregated audience or conversion metrics to measure advertising performance, understand which campaigns brought users to the App, send app-related marketing communications where permitted, and improve our marketing. If we add a mobile advertising SDK such as Google Mobile Ads/AdMob, this policy and the Google Play Data Safety declaration must be reviewed and updated before or with that release.
- Crash and Diagnostic Data: The current source code reviewed for this policy does not include Firebase Crashlytics. We may still receive limited diagnostics such as app version, device model, operating system, and analytics events through Firebase Analytics and our servers. If Crashlytics or another crash-reporting SDK is added later, this policy and the Google Play Data Safety declaration must be updated.
- Local Device Storage and Background Task Data: We store certain preferences locally on your device using SharedPreferences, including your login session data, onboarding completion status, notification preferences, muted warranty notification settings, and temporary receipt analysis task data. When you start a receipt scan, temporary background task data may include task status, user ID, local image path, language preference, timestamps, receipt ID returned by the server, error status if any, and a temporary authentication token when needed to complete the upload. This data is used to continue receipt analysis if the App is backgrounded and is cleared or replaced when the task completes or is dismissed.
3. App Permissions
To provide our services, the App requires the following permissions:
- Camera: Required to take photos of your receipts for scanning.
- Photo Gallery / Storage: Required to upload existing receipt images from your device.
- Notifications: Required to send you push notifications about expiring warranties, scheduled warranty reminders, and important app updates.
- Internet: Required to communicate with our servers for receipt processing, account management, and data synchronization.
- Boot Completed: Required to restore scheduled warranty reminder notifications after device restart.
- Exact Alarm: Required to schedule precise warranty expiry reminder notifications at the correct times.
- Foreground Service / Background Processing: Required on supported platforms, especially Android, to keep receipt analysis and upload running after you leave the App. The App shows an ongoing notification while this processing is active. This feature is limited to receipt analysis and does not perform background location tracking, microphone recording, camera recording, or advertising tracking.
4. Third-Party Services
We use the following third-party services. We rely on your consent, the performance of our contract with you, and our legitimate interests to process this data:
- Google Firebase: Used for analytics (Firebase Analytics) and push notifications (Firebase Cloud Messaging / FCM). Firebase Analytics helps us measure app opens, screen views, device and app performance, campaign attribution, advertising or marketing measurement, and feature usage through pseudonymous identifiers such as the Firebase app instance ID and, on Android where available, Advertising ID. Google may process this data as a service provider/sub-processor according to Firebase and Google privacy terms. Firebase Privacy and Security and Firebase Analytics Data Collection. (Basis: Consent where required by law, Legitimate Interest, and Performance of Contract)
- n8n AI/OCR Engine: Receipt images you upload are processed by our automated engine for data extraction. (Basis: Performance of Contract)
- RevenueCat: Used for subscription management. We share your email address and unique identifier with RevenueCat to associate your subscription across devices. (Basis: Performance of Contract) RevenueCat Privacy Policy.
5. How We Use Your Data & Legal Basis
Your data is processed based on the following legal grounds:
Data Retention: Your data is retained as long as your account is active. Upon account deletion, your personal account details, receipt images, and extracted receipt data are permanently removed from our active systems. Firebase Analytics data and advertising/marketing measurement data are retained according to our Firebase/Google Analytics configuration and applicable Google retention controls, and are used in aggregated or pseudonymous form for product analytics and marketing measurement. We do not directly delete Google Analytics data from this PHP account-deletion endpoint unless a supported Firebase/Google deletion process is separately implemented. However, to comply with global tax laws and accounting regulations, records of financial transactions, credit purchases, and subscription history are retained in an anonymized or de-identified format disconnected from your active account for the legally required period.
Data Security: We use industry-standard encryption (bcrypt, HTTPS/TLS) to protect your data.
- Performance of Contract: To process and organize receipts, keep receipt analysis running in the background when needed, manage account registration, process subscriptions via RevenueCat, and track warranty expiry dates.
- Legitimate Interests: To analyze spending habits, provide financial insights, improve app performance via analytics, and fix technical issues.
- Consent: Where local law requires consent for analytics, advertising identifiers, push notification marketing, targeted advertising, or similar device identifiers, we rely on consent and respect applicable device-level privacy controls.
- Legal Obligation: To comply with tax laws or other legal requirements.
Data Retention: Your data is retained as long as your account is active. Upon account deletion, your personal account details, receipt images, and extracted receipt data are permanently removed from our active systems. Firebase Analytics data and advertising/marketing measurement data are retained according to our Firebase/Google Analytics configuration and applicable Google retention controls, and are used in aggregated or pseudonymous form for product analytics and marketing measurement. We do not directly delete Google Analytics data from this PHP account-deletion endpoint unless a supported Firebase/Google deletion process is separately implemented. However, to comply with global tax laws and accounting regulations, records of financial transactions, credit purchases, and subscription history are retained in an anonymized or de-identified format disconnected from your active account for the legally required period.
Data Security: We use industry-standard encryption (bcrypt, HTTPS/TLS) to protect your data.
6. Your Rights
Depending on your location, including under GDPR, UK GDPR, KVKK, CCPA/CPRA, LGPD, and similar privacy laws, you may have rights to access, rectify, erase, restrict or object to processing, withdraw consent, request portability, and opt out of certain sharing, targeted advertising, or profiling where applicable. We do not sell your personal data. To exercise your rights, contact us using the details below.
7. GDPR & International Data Transfers
If you are in the European Economic Area (EEA), United Kingdom, Turkey, Brazil, California, or another jurisdiction with privacy laws, we process your data according to the rights and safeguards required by those laws where they apply. Some data may be processed by providers in the United States or other countries (including Google/Firebase and RevenueCat). We use appropriate safeguards such as Standard Contractual Clauses (SCCs), data processing terms, access controls, and minimization measures for international transfers.
8. User Agreement
8.1. Terms: By using Slipp, you agree to these terms. Slipp is not directed to children. You must be 18+ or have parent/guardian consent, and if the App is distributed as child-directed in any store or region, the Data Safety, advertising, analytics, and consent settings must be re-reviewed before release.
8.2. Responsibility: You are responsible for your account security and the legality of uploaded receipts.
8.3. OCR Accuracy: AI analysis is provided "as is". We do not guarantee 100% accuracy of receipt data; please verify results.
8.4. Governing Law: These terms are governed by the laws of Turkey. Disputes are subject to Istanbul Courts.
8.2. Responsibility: You are responsible for your account security and the legality of uploaded receipts.
8.3. OCR Accuracy: AI analysis is provided "as is". We do not guarantee 100% accuracy of receipt data; please verify results.
8.4. Governing Law: These terms are governed by the laws of Turkey. Disputes are subject to Istanbul Courts.
9. CCPA Notice
California residents have rights regarding the collection and disclosure of their personal information.
10. Contact Us
If you have any questions, please contact: t.gencosman@gmail.com (Tolga Gencosman)