Privacy Policy

Crowcery · last updated 27 July 2026

Short version: Crowcery is a personal-project app in beta. We collect only the data we need to turn your receipt photos into structured item lists. By default we keep your receipt photos for about 6 months (in the processed, redacted form described in Section 3.2) so you can look them up later; in Account settings you can change this to auto-delete after about 7 days, or to keep them until you delete them (we always keep the structured data we extract either way). Before a photo is kept, we automatically detect sensitive details printed on the receipt (such as payment-card digits and loyalty numbers) and remove them from the stored image and stored text; this is best-effort and may be incomplete. Your data is stored in Canada; receipt photos and the data read from them are briefly processed in the United States by Google Cloud AI services (Section 5). You can delete your account at any time from inside the app, and your account data is erased from our live systems after a 7-day grace period (and purged from our backups within about 35 days), with two exceptions: product photos you contribute and we approve as shared catalogue images, which we keep with your identity removed; and proof that you accepted our terms, which we keep for 7 years in a form that can still be matched back to you, so we can show what you agreed to if a dispute comes up (Section 7 explains this one in full). We do not sell your data or show ads.

1. Who we are

Crowcery is operated by Marton Hever as an individual (no incorporated entity as of this writing), based in Nova Scotia, Canada. Marton Hever is the person responsible for the protection of personal information (privacy officer) and accountable for Crowcery's compliance with this policy. Contact: support@crowcery.com.

2. Scope

This policy covers the Crowcery app (Android app / web) and the backend service it talks to. It does not cover third-party services you may reach from the app (for example, Google Play).

Crowcery is operated from Canada and intended for users in Canada. If you use the service from another country, your personal information will be transferred to and processed in Canada and, as described in this policy (Section 5), in the United States.

Crowcery is offered in English only and is not offered to residents of Quebec. The app asks you to confirm this when you accept the Terms of Service, and it uses automated best-effort detection to decline receipts that show Quebec sales tax or are printed in French.

3. What we collect and why

3.1 Account information

What Google's sign-in screen shows. When you sign in with Google, Google's own consent screen may say the app can see your name, profile picture, and email address. Those are the "basic profile" fields Google includes in every sign-in, and the app does receive them while completing the sign-in. Receiving them is not the same as keeping them: we do not save your name or profile picture to our records, and we do not store your email in our database (as noted above, our servers read your email from Google only when we actually need to reach you). The only account detail we keep is the opaque Google identifier that links your receipts to your account. How Google itself handles your sign-in, and the profile it holds for your Google account, is governed by Google's privacy policy.

3.2 Receipt data

Automatic redaction of sensitive details. The reading process sees all text visible on the receipt so it can extract the fields we use, and receipts sometimes carry personal details beyond the purchase itself: payment-card rows (stores print these masked; some digits remain), loyalty / membership / account numbers, a cashier's name, and occasionally a customer phone, email, or street address. We run automated, best-effort redaction over both the image and the text before anything is stored:

This redaction is automated, deliberately conservative (it must never obscure prices or item lines), and may be incomplete for some store formats or unusual layouts, so you should still avoid uploading receipts whose visible details you would not want us to store or process. What we then keep is: the store's identity (name, address, phone, and store number: these identify the merchant, not you, and are used to group purchases by location and compare prices across stores), the purchase date, the line items, prices, and taxes, plus a redacted plain-text transcription of the receipt used to power parsing and to diagnose extraction errors.

About the photo we keep. The photo we retain is a processed version of your receipt: it is automatically adjusted so our system can read it (for example straightened, cropped, resized, and in most cases converted to greyscale), camera metadata (such as location) is removed, and the sensitive regions we detect are painted over as described above. Because the redaction is best-effort, the photo may still show personal details we did not detect. We protect it with encryption at rest and access controls; you can shorten how long it is kept, or delete any receipt, at any time; and for anything you would not want stored, please avoid uploading it.

At a glance: what we store from a receipt, and for how long. (Section 7 has the full detail.)

WhatRedactionHow long we keep itYour control
Receipt photo (processed) Sensitive regions painted over, best-effort Your photo setting: about 7 days, about 6 months (default), or until you delete it Photo-retention setting; delete the receipt at any time
Structured data (store, date, line items, prices, taxes) Not redacted (this is the product) While your account is active Edit or delete the receipt; delete your account
Plain-text transcription Redacted before storage Follows your photo setting; if you keep photos until you delete them, the transcription is likewise kept until you delete the receipt Photo-retention setting; delete the receipt
Short-lived processing and diagnostic copies (including a small scan-preview image) Varies; may include details before redaction Deleted automatically within about 7 days of upload, regardless of your setting Deleting the receipt removes them promptly

At a glance: what deletion does.

ActionWhat happens
You delete one receipt The receipt, its line items, taxes, transcription, photo, and diagnostic copies are erased from our live systems promptly. Residual copies in disaster-recovery backups purge within about 35 days. A product photo from that receipt that was already approved into the shared catalogue is kept, with its link to the deleted receipt removed.
You shorten the photo-retention setting Photos (and their transcriptions) that fall outside the new window are deleted and cannot be recovered.
You delete your account After a 7-day grace window, all receipts, photos, insights, and your account record are erased from our live systems; residual copies in backups purge within about 35 days. Two things are kept (Section 7): approved catalogue photos, with your identity removed; and proof that you accepted our terms, for 7 years, in a form that can still be matched back to you.

3.3 Service usage data

4. Legal basis

Under Canadian privacy law (PIPEDA and provincial equivalents), we process your personal information with your consent. Here is exactly when that consent happens, because the order matters:

You can withdraw consent at any time by deleting your account (see Section 8).

5. Where your data is stored and processed

Primary storage stays in Canada; automated LLM processing currently leaves Canada briefly before the results come back:

Other than the Google Cloud AI processing described above, your receipt data (your photos and the information extracted from them) does not leave North America under normal operation, and our operational logs are stored in Canada. If this ever changes, this policy is updated to reflect it.

6. Third parties we share data with

We share personal information only with service providers operating on our behalf:

We do not sell your personal information. We do not share it with advertisers or data brokers. We do not use it to target advertising.

Disclosure required or permitted by law. We may disclose personal information where required by law, court order, or other valid legal process; for such requests we take reasonable steps to verify their authenticity and disclose only what the request compels. We may also disclose information where the law permits it and it is necessary to protect someone's safety or to report suspected illegal activity to the authorities (for example, the mandatory reports described in the Terms of Service).

Product photos shown to other users. If you contribute product photos and we approve them, we display them to other Crowcery users as shared catalogue images, with your account identity removed. This is use within the service, not a sale or transfer to a third party. We do not contribute your photos to any external or open database (such as Open Food Facts); if we ever offer that, it would be a separate, optional choice you opt into.

De-identified community price observations. When you shop at a store location, the item's product name, the price, purchase date (day only), and optional quantity from your receipt items may be shown to other users of the same store as de-identified reference prices. These observations are also used as inputs to features such as spending insights. The entries exposed to other users contain no direct identifiers: no user identifier, email address, or receipt identifier. They are designed so that an observation cannot reasonably be linked back to you or to any other purchase you have made. The store identity (banner name and store number) is included because it identifies the merchant, not you.

7. How long we keep your data

8. Your rights

Under PIPEDA you have the right to:

We respond to privacy requests within 30 days.

9. Security

We use industry-standard security practices: TLS for all data in transit, encryption-at-rest for storage, managed identities instead of long-lived API keys, passkey and authenticator-app multi-factor authentication on operator accounts, and least-privilege access controls. No system is perfectly secure; if we learn of a breach affecting your data, we will notify you and the relevant regulator as required by law.

10. Cookies and tracking

We use only functional cookies needed for the app to work (session authentication, CSRF protection). We do not use analytics or advertising cookies. We do not embed third-party trackers on in-app pages.

11. Children

Crowcery is intended for adults and is not directed to anyone under 18; you must be at least 18 to use it. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us personal information, email us and we will delete it.

12. Changes to this policy

If we make material changes we will update the "last updated" date at the top, and the app will ask you to review and accept the updated policy before you continue using the service (a blocking in-app notice; we record the version you accepted and when). Where appropriate we may also notify you by email. If you do not accept the updated policy, you can export your data and delete your account directly from the update notice, without accepting.

13. Contact

Questions or requests related to your privacy: support@crowcery.com.