Privacy Policy
1. What we collect
We only collect what the service needs to work:
- Your name and email address, from when you register or sign in with Google
- Warranty details you enter, such as product names, brands, retailers, dates, prices, and serial numbers
- Receipt images you upload for AI scanning
- Messages you send to the AI claim assistant
- Basic account settings, such as your notification preferences
We never see or store your password. Sign in is handled by Firebase Authentication, and Google sign in gives us only your name and email address.
2. How we use it
- To create and run your account
- To store your warranty records and show them back to you
- To send expiry alerts, if you turn them on
- To power AI receipt scanning and the claim assistant
- To keep the service working, secure, and free of abuse
We do not use your data for advertising, and we do not build profiles of you.
3. Where your data is stored
We do not sell or rent your personal information, and we never share it with other users. Your account and your warranty records live in Google Cloud database systems, run through Firebase, so the day to day safety of your data rests on infrastructure Google secures and audits rather than on servers we maintain ourselves.
Measures Google applies to data held on that infrastructure include:
- Encryption at rest by default: stored data is split into chunks, each encrypted with its own key, and those keys are themselves encrypted with regularly rotated master keys
- Encryption in transit: traffic is encrypted between you and Google, and again as it moves between Google data centres over their own private network rather than the public internet
- Purpose built hardware: servers use custom security chips and a verified boot process, so a machine that has been tampered with will not be trusted with data
- Physical data centre security: access is tightly restricted through layered controls including biometric checks, and very few staff ever enter the floors where data is held
- Replication across locations: records are copied across multiple physically separate zones, so a single failure does not lose your data
- Credentials never held in the clear: passwords are hashed by Google's authentication service, so neither we nor Google can read them
- Independent auditing: the platform is assessed against recognised standards such as ISO/IEC 27001 and SOC 2 by outside auditors
We may also disclose information where the law requires it, or where it is necessary to protect the service, our rights, or someone's safety.
4. How AI features handle your data
When you scan a receipt, the image is sent to an external AI provider to be read. When you use the claim assistant, your messages and the warranty details relevant to that claim are sent the same way. This happens only when you actively use those features, and it is the only time your content leaves our own storage.
We do not use your content to train AI models, and we do not permit our providers to train on it either.
5. Security
The measures we rely on:
- Encryption in transit: traffic between your device and our services is protected with TLS
- Encryption at rest: stored data is encrypted by our infrastructure providers
- Database level access rules: your records are readable and writable only by your own authenticated account, enforced by the database itself rather than only by the app
- Private receipt storage: uploaded receipt images are stored privately and served only to you through an authenticated route
- Short lived tokens: session tokens rotate automatically
No service can promise perfect security, and we will not pretend otherwise. We keep our practices under review and will tell you promptly if a breach affects your data.
6. How long we keep it
Your warranty records and receipt images stay until you delete them or ask us to close your account, at which point we remove them from our active systems. Residual copies may persist briefly in provider backups before being overwritten.
7. Your rights
You can:
- See and correct the information held about you
- Delete individual warranty records at any time from within the app
- Ask us to delete your account and everything attached to it
- Ask for a copy of your data
- Turn expiry notifications off at any time
Depending on where you live, you may have further rights under laws such as the GDPR or the CCPA, including the right to object to processing or to complain to your local data protection authority.
8. Changes to this policy
We will post any update here with a new date, and we will give at least 14 days' notice before a material change takes effect.