Privacy Policy
Crowcery · last updated 27 July 2026
Short version: Crowcery is a personal-project app in beta. We collect only the data we
need to turn your receipt photos into structured item lists. By default we keep your receipt
photos for about 6 months (in the processed, redacted form described in Section 3.2) so you can look
them up later; in Account settings you can change this to
auto-delete after about 7 days, or to keep them until you delete them (we always keep the structured data we
extract either way). Before a photo is kept, we automatically detect sensitive details printed on the receipt
(such as payment-card digits and loyalty numbers) and remove them from the stored image and stored text; this is
best-effort and may be incomplete. Your data is stored in Canada; receipt photos and the data read from them are
briefly processed in the United States by Google Cloud AI services (Section 5). You can delete your account at
any time from inside the app, and your account data is erased from our live systems after a 7-day grace period
(and purged from our backups within about 35 days), with two exceptions: product photos you contribute and we
approve as shared catalogue images, which we keep with your identity removed; and proof that you accepted our
terms, which we keep for 7 years in a form that can still be matched back to you, so we can show what you agreed
to if a dispute comes up (Section 7 explains this one in full). We do not sell your data or show ads.
1. Who we are
Crowcery is operated by Marton Hever as an individual (no incorporated entity as of this writing), based in
Nova Scotia, Canada. Marton Hever is the person responsible for the protection of personal information (privacy
officer) and accountable for Crowcery's compliance with this policy. Contact:
support@crowcery.com.
2. Scope
This policy covers the Crowcery app (Android app / web) and the backend service it talks to. It does not
cover third-party services you may reach from the app (for example, Google Play).
Crowcery is operated from Canada and intended for users in Canada. If you use the service from another country,
your personal information will be transferred to and processed in Canada and, as described in this policy
(Section 5), in the United States.
Crowcery is offered in English only and is not offered to residents of Quebec. The app asks you to confirm this
when you accept the Terms of Service, and it uses automated best-effort detection to decline receipts that show
Quebec sales tax or are printed in French.
3. What we collect and why
3.1 Account information
- Email address: held by Google Identity Platform, our sign-in provider.
We do not store your email in our own database; our records key your account
on an opaque identifier from Google, and we retrieve your email from Google only when we
actually need it (for example, to reply to a support message or send a required service notice).
You still see your email in the app because it comes from your sign-in.
- Sign-in metadata — session identifiers and cookies used to keep you signed in.
What Google's sign-in screen shows. When you sign in with Google, Google's own
consent screen may say the app can see your name, profile picture, and email address. Those are the
"basic profile" fields Google includes in every sign-in, and the app does receive them while
completing the sign-in. Receiving them is not the same as keeping them: we do not save your name or
profile picture to our records, and we do not store your email in our database (as noted above, our
servers read your email from Google only when we actually need to reach you). The only account
detail we keep is the opaque Google identifier that links your receipts to your account. How Google
itself handles your sign-in, and the profile it holds for your Google account, is governed by
Google's privacy policy.
3.2 Receipt data
- Receipt photos you upload. Stored in encrypted Google Cloud Storage in Canada (Montréal, northamerica-northeast1 region). By default we keep your receipt photo for about 6 months so you can view it later, and in Account settings you can change how long photos are kept. You can delete any receipt (and its photo) at any time. Section 7 has the full retention options and windows.
- Structured data extracted from those photos — store name, date, line items, prices, taxes, and
similar fields produced by our OCR/parse pipeline. Stored in Google Cloud SQL in Canada (Montréal region).
- Corrections and flags you submit on parsed receipts. Used to improve accuracy for you and, in
aggregate, to identify systemic parsing errors.
Automatic redaction of sensitive details. The reading process sees all text visible on
the receipt so it can extract the fields we use, and receipts sometimes carry personal details beyond the purchase
itself: payment-card rows (stores print these masked; some digits remain), loyalty / membership / account numbers,
a cashier's name, and occasionally a customer phone, email, or street address. We run automated, best-effort
redaction over both the image and the text before anything is stored:
- In the photo we keep, the sensitive regions we detect (payment-card rows, email addresses,
and labelled loyalty / membership / account numbers) are painted over so they are no longer readable. For some
store formats we go further and crop away the part of the receipt below the total, where payment details are
printed, so that region is never stored at all.
- In the stored text transcription, we redact those details plus cashier names and any
customer phone, email, or street address.
- Before transcription, the AI model that transcribes and interprets your receipt is given the
redacted image, not the original (to detect the sensitive regions, an unredacted copy is processed transiently,
as described in Section 5).
This redaction is automated, deliberately conservative (it must never obscure prices or item lines), and may be
incomplete for some store formats or unusual layouts, so you should still avoid uploading receipts whose visible
details you would not want us to store or process. What we then keep is: the store's identity
(name, address, phone, and store number: these identify the merchant, not you, and are used to group purchases by
location and compare prices across stores), the purchase date, the line items, prices, and taxes, plus a redacted
plain-text transcription of the receipt used to power parsing and to diagnose extraction errors.
About the photo we keep. The photo we retain is a processed version of your receipt: it is
automatically adjusted so our system can read it (for example straightened, cropped, resized, and in most cases
converted to greyscale), camera metadata (such as location) is removed, and the sensitive regions we detect are
painted over as described above. Because the redaction is best-effort, the photo may still show personal details
we did not detect. We protect it with encryption at rest and access controls; you can shorten how long it is
kept, or delete any receipt, at any time; and for anything you would not want stored, please avoid uploading it.
At a glance: what we store from a receipt, and for how long. (Section 7 has the full detail.)
| What | Redaction | How long we keep it | Your control |
| Receipt photo (processed) |
Sensitive regions painted over, best-effort |
Your photo setting: about 7 days, about 6 months (default), or until you delete it |
Photo-retention setting; delete the receipt at any time |
| Structured data (store, date, line items, prices, taxes) |
Not redacted (this is the product) |
While your account is active |
Edit or delete the receipt; delete your account |
| Plain-text transcription |
Redacted before storage |
Follows your photo setting; if you keep photos until you delete them, the transcription is likewise kept
until you delete the receipt |
Photo-retention setting; delete the receipt |
| Short-lived processing and diagnostic copies (including a small scan-preview image) |
Varies; may include details before redaction |
Deleted automatically within about 7 days of upload, regardless of your setting |
Deleting the receipt removes them promptly |
At a glance: what deletion does.
| Action | What happens |
| You delete one receipt |
The receipt, its line items, taxes, transcription, photo, and diagnostic copies are erased from our live
systems promptly. Residual copies in disaster-recovery backups purge within about 35 days. A product photo
from that receipt that was already approved into the shared catalogue is kept, with its link to the deleted
receipt removed. |
| You shorten the photo-retention setting |
Photos (and their transcriptions) that fall outside the new window are deleted and cannot be recovered. |
| You delete your account |
After a 7-day grace window, all receipts, photos, insights, and your account record are erased from our
live systems; residual copies in backups purge within about 35 days. Two things are kept (Section 7):
approved catalogue photos, with your identity removed; and proof that you accepted our terms, for 7 years,
in a form that can still be matched back to you. |
3.3 Service usage data
- Quota counters: how many receipts you've processed in the current period, used to enforce
your plan limits.
- LLM call counts and costs: used internally to operate cost caps and detect abuse.
- Server logs: standard HTTP access logs (which include your IP address) and application logs.
Retained 30 days.
4. Legal basis
Under Canadian privacy law (PIPEDA and provincial equivalents), we process your personal information with your
consent. Here is exactly when that consent happens, because the order matters:
- When you sign in, we create your account. To do that we receive your Google sign-in and keep
the opaque account identifier described in Section 3.1. This happens before you accept our Terms and
Privacy Policy, because you have to be signed in for the next step to be able to offer you a way out.
- Immediately after you sign in, the app shows you a screen that blocks everything else until you
read and accept these documents. That acceptance is your consent, and we record which version you accepted and
when. Until you accept, you cannot read, upload, or change anything.
- If you don't accept, you don't have to. From that same screen you can download your data and
delete your account, and the account we created at sign-in goes with it.
- Before your first receipt upload, we show you a separate screen explaining how your photo is
handled — what is sent to Google's AI services, what is redacted, and how long it is kept — which you also have
to accept before any photo leaves your device. Sections 3.2 and 5 describe that handling in full.
You can withdraw consent at any time by deleting your account (see Section 8).
5. Where your data is stored and processed
Primary storage stays in Canada; automated LLM processing currently leaves Canada briefly before the results come
back:
- Google Cloud (Montréal, northamerica-northeast1): receipt images, parsed data, account records.
This is where your data lives at rest.
- Google Cloud (Toronto, northamerica-northeast2) holds encrypted disaster-recovery backups of
the database and stored photos, kept in a separate Canadian region for resilience (see Section 7 for how long).
- Google Cloud AI services (United States): we use AI services running on Google Cloud to
locate, read, classify, and parse receipts, to
generate spending insights from your purchase data, and to help screen contributed product photos during review.
When you scan a receipt, copies of your photo are processed by these services to find the receipt in the
frame, to detect the sensitive details described in Section 3.2 (finding them necessarily means reading an
unredacted copy, transiently), and to transcribe the redacted image. Apart from a small low-resolution
preview image kept briefly for troubleshooting (Section 7), the image copies used in processing are
discarded once processing completes. We also keep technical measurements about the photo (such as the
receipt's position and rotation in the frame). Brief processing copies of the text read during processing
are kept while your receipt is processed and for troubleshooting afterwards, and are deleted within about
7 days (Section 7). What remains after that is those technical measurements plus what Section 3.2
describes: the masked photo, the redacted transcription, and the structured data we extracted. These calls use the services' United States endpoints:
your receipt photos, contributed product photos, and the data extracted or derived from them are sent to Google
for processing in the United States, after which the result is returned to our Canadian database. This data is
not used to train AI models (a contractual commitment of these Google Cloud services), and we use only Google
Cloud's enterprise endpoints, never consumer AI APIs. Google's handling of data processed on Google Cloud is
described in the Google Cloud Privacy Notice.
If equivalent processing becomes available in Canada, we may move it there and update this section.
- Google Identity Platform: authentication. Your email and sign-in events are processed by
Google on its global infrastructure (primarily in the United States), not pinned to a Canadian region.
Other than the Google Cloud AI processing described above, your receipt data (your photos and the information
extracted from them) does not leave North America under normal operation, and our operational logs are stored in
Canada. If this ever changes, this policy is updated to reflect it.
6. Third parties we share data with
We share personal information only with service providers operating on our behalf:
- Google: Google Cloud hosting (storage, database, compute; data at rest in Montréal, Canada),
Google Identity Platform (authentication), Google Cloud AI services (AI processing, via the United States
endpoints as described above), and, once the paid tier launches, Google Play Billing (subscription
management).
We do not sell your personal information. We do not share it with advertisers or
data brokers. We do not use it to target advertising.
Disclosure required or permitted by law. We may disclose personal information where required by
law, court order, or other valid legal process; for such requests we take reasonable steps to verify their
authenticity and disclose only what the request compels. We may also disclose information where the law permits
it and it is necessary to protect someone's safety or to report suspected illegal activity to the authorities
(for example, the mandatory reports described in the Terms of Service).
Product photos shown to other users. If you contribute product photos and we approve them, we
display them to other Crowcery users as shared catalogue images, with your account identity removed. This is use
within the service, not a sale or transfer to a third party. We do not contribute your
photos to any external or open database (such as Open Food Facts); if we ever offer that, it would be a separate,
optional choice you opt into.
De-identified community price observations. When you shop at a store location, the item's product
name, the price, purchase date (day only), and optional quantity from your receipt items may be shown to other
users of the same store as de-identified reference prices. These observations are also used as inputs to features such as spending insights.
The entries exposed to other users contain no direct identifiers: no user identifier, email address, or receipt
identifier. They are designed so that an observation cannot reasonably be linked back to you or to any other
purchase you have made. The store identity (banner
name and store number) is included because it identifies the merchant, not you.
7. How long we keep your data
- Receipt photos: by default we keep your receipt photo for about 6 months after
upload (or until you delete that receipt, or delete your account), so you can look it up later. In Account settings
you can change this to one of three options: auto-delete after about 7 days, keep for about 6 months (the default),
or keep until you delete it. The full, unprocessed camera file is not kept: what we store is the processed,
redacted photo described in Section 3.2. Short-lived processing, diagnostic, and preview copies (including a
small low-resolution preview image and brief processing copies of text read from the photo before redaction)
are kept only for troubleshooting and automatically deleted from our systems within about 7 days of upload,
regardless of the setting you choose; after that window, only technical measurements about the photo (such
as the receipt's position and rotation in the frame) remain from these processing copies. Switching to a
shorter setting deletes saved photos that fall outside the new
window, and photos already deleted cannot be recovered.
- Plain-text transcription: the redacted transcription of each receipt follows the same
retention setting as its photo. If you keep photos until you delete them, the transcription is likewise kept
until you delete the receipt or your account.
- Structured receipt data and account records: the data we extract from your receipts (store,
date, line items, prices, taxes, insights) and your account record are retained while your account is active.
- After account deletion: a 7-day grace window, then all receipt data, insights, your account
record, and all of your receipt photos (whatever retention setting you chose) are permanently
deleted from the database and blob storage (residual copies in our disaster-recovery backups are purged within
about 35 days, as described below).
Contact support during the grace window if the deletion was a mistake. There are
two exceptions:
- Approved catalogue photos. Product photos you contributed that we
approved as shared catalogue images are kept as part of the product catalogue, with your account identity
permanently severed from them (we retain only a minimal consent record — image id, consent version, timestamp —
containing no personal data). We don't remove these automatically when you delete your account, but if you
separately ask us by email, we will take down a photo you contributed. Item images that were pending or rejected
are deleted with the rest.
- Proof that you accepted our terms. We keep a record of each time you accepted
the Terms of Service and Privacy Policy (which version, when, and how), and of your acceptance of the
data-handling notice shown before your first upload. We are being deliberately plain about the trade-off
here, because it is the one place where deleting your account does not erase everything: these records
are kept in a form that can still be matched back to you. When your account is deleted we remove your
account id from them and replace it with a one-way scrambled code derived from your Google sign-in identifier.
We cannot read your identity out of that code, but if you later came to us with a legal complaint about your time
on the service, we could re-create the code from your Google account and show whether you had accepted the terms.
That is the entire purpose. We are telling you that purpose here, and on the screen where you accept, because
that is when you are consenting to it: proving what you agreed to is one of the reasons we collect the acceptance
record in the first place, not something we decided afterwards. We keep these records for 7 years
after your account is deleted, and then delete them automatically. We keep nothing else about you for this
purpose: not your email (we never store it at all), not your IP address, and not your device details.
- Disaster-recovery backups: to protect against data loss (hardware failure, accidental
deletion, or a security incident), we keep encrypted backups of the database and of your stored receipt photos in
a separate, access-restricted location in Canada (Toronto). For security these backups are immutable:
they cannot be altered or selectively deleted before they expire. So when you delete a receipt, shorten a
photo-retention setting, or delete your account, your data is removed from our live systems within the windows
described above, but residual copies may remain in these backups for up to about 35 days, after which they are
automatically and permanently purged. We use backups only to restore the service after a failure, never for any
other purpose.
- Server logs: 30 days.
- Billing records (paid tier only, once it launches): retained for 7 years as required by Canadian tax law.
8. Your rights
Under PIPEDA you have the right to:
- Access the personal information we hold about you. You can export your data as JSON, CSV, or
Excel, and download your receipt photos as a ZIP, from inside the app's Account page at any time. If you have
already deleted your account, the only thing we still hold is the acceptance record described in Section 7;
email support@crowcery.com and we will ask you to prove control of
the same Google account before answering.
- Correct inaccurate information. You can edit parsed receipts in-app, or email us for changes
to account data.
- Delete specific receipts without deleting your account.
You can remove individual receipts (and the uploaded photo, line items, and taxes) at any time,
without affecting your account or other receipts. To do so:
- Sign in to Crowcery on the app or web at
https://crowcery.com.
- Open the receipt you want to remove from the receipts list.
- Tap the Delete button on the receipt detail page and confirm.
Deletion takes effect promptly, typically right away: the receipt, its line items, its taxes, its plain-text
transcription, its uploaded photo (if still stored), and its short-lived diagnostic copies are erased from our
live database and from blob storage; residual copies in our disaster-recovery backups are purged within
about 35 days (see Section 7). Any product photo you
contributed from that receipt that is still pending or was rejected is deleted too; a product
photo you contributed that has already been approved into the shared catalog is kept
(with its link to the deleted receipt removed), consistent with the contribution terms. Aggregated
analytics (e.g. monthly total spent, per-category breakdowns) are recomputed on the next view so
the deleted receipt no longer contributes. No human intervention is required, and no support
request is needed.
- Delete your account and the data associated with it. Use the "Delete
account" button on the Account page, in the app or on the web at
https://crowcery.com; no human
intervention is required. Your receipts, photos, and account record are erased as described in Section 7.
One thing is deliberately kept: the record of which terms you accepted and when, for 7 years,
in a form that can still be matched back to you — Section 7 explains exactly what that is and why. If you have
deleted your account and want to ask about that record, email
support@crowcery.com; we will ask you to prove control of the same
Google account you signed in with before we answer, because that is the only way we can find it.
- Withdraw consent for future processing by deleting your account, or for specific data by
deleting individual receipts or shortening the photo-retention setting.
- Complain to the Office of the Privacy Commissioner of Canada
if you believe we've mishandled your personal information.
We respond to privacy requests within 30 days.
9. Security
We use industry-standard security practices: TLS for all data in transit, encryption-at-rest for storage, managed
identities instead of long-lived API keys, passkey and authenticator-app multi-factor authentication on operator
accounts, and least-privilege access controls. No system is perfectly secure; if we learn of a breach affecting
your data, we will notify you and the relevant regulator as required by law.
10. Cookies and tracking
We use only functional cookies needed for the app to work (session authentication, CSRF protection). We do not use
analytics or advertising cookies. We do not embed third-party trackers on in-app pages.
11. Children
Crowcery is intended for adults and is not directed to anyone under 18; you must be at least 18 to use it. We do not
knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided us personal
information, email us and we will delete it.
12. Changes to this policy
If we make material changes we will update the "last updated" date at the top, and the app will ask you to review
and accept the updated policy before you continue using the service (a blocking in-app notice; we record the
version you accepted and when). Where appropriate we may also notify you by email. If you do not accept the
updated policy, you can export your data and delete your account directly from the update notice, without
accepting.
13. Contact
Questions or requests related to your privacy: support@crowcery.com.