What a Nice Idea
Privacy / The Receipt
Privacy Policy

The Receipt

A local-first expense tracker that turns Greek AADE receipt QR codes into structured expenses — no tax-authority credentials required.

Effective: 24 July 2026 Last updated: 24 July 2026 Applies to: The Receipt for Android & iOS

The short version

1. Who we are

The Receipt is developed by What a Nice Idea ("we", "us", "our"), an independent software studio. This policy explains what information the app processes, why, and the choices you have. For anything privacy-related you can reach us at privacy@whataniceidea.com.

For the purposes of the EU General Data Protection Regulation (GDPR) and the equivalent Greek data-protection law, What a Nice Idea is the data controller for the limited processing described below.

Please note: The Receipt is under active development. This policy is written to cover the app's current and planned functionality; we will update it — and the "last updated" date above — as features ship or change.

2. Scope & local-first design

The Receipt is designed to be local-first: the authoritative copy of your data is the database stored on your own device. The app is fully functional offline, and by default nothing you record leaves your phone.

Some optional features — creating an account, syncing across devices, and enriching a scanned receipt — do involve our servers. Those are described explicitly in the sections below. If you never use them, the app operates entirely on-device.

3. What data we process

The information the app handles falls into the following categories:

CategoryExamplesWhere it lives
Expense recordsAmount, currency, category, notes, date/time you assignOn your device; in our cloud only if you enable sync
Receipt detailsMerchant name, tax number (AFM), line items, totals returned for a scanned receiptOn your device; in our cloud only if you enable sync
Receipt imagesPhotos of receipts you choose to attachOn your device; in our cloud storage only if you enable sync
Scanned QR URLThe AADE / provider URL encoded in a receipt's QR codeSent to our server for enrichment (see §4)
Account dataEmail address and a securely hashed password (only if you register)Our authentication server
Technical dataIP address and request metadata, used transiently for rate-limiting and abuse preventionOur server, short-lived

We do not ask for your name, phone number, government ID, or AADE/tax-authority login. We do not build advertising profiles and we do not track you across other apps or websites.

4. Receipt QR scanning & enrichment

The core feature of The Receipt is turning a Greek receipt's QR code into a structured expense. This happens in two steps:

On your device

Your camera scans the QR code and the app reads the URL it contains. Basic parsing happens locally so your form can pre-fill instantly.

On our server

To fetch the full receipt details, the app sends the scanned QR URL to our enrichment service (a Cloudflare Worker operated by us). That service contacts the relevant Greek public or e-invoicing system — for example the AADE receipt-check API, myDATA, or providers such as EnterSoftOne, EpsilonNet, SimplyCloud, SimpleInvoicing — and returns a normalised receipt to your device.

5. Accounts & cloud sync

Accounts are entirely optional. You only need one if you want your expenses to sync between multiple devices.

6. Device permissions

PermissionWhy
CameraTo scan receipt QR codes and, where supported, read receipt text (OCR). Frames are processed on-device; we don't stream your camera anywhere.
Photos / storageOnly if you attach or save a receipt image.
Biometrics (optional)If you enable an app lock, biometric matching is performed by your operating system. We never receive your fingerprint or face data.

7. Third-party services

We keep third parties to a minimum. The ones involved are:

We do not integrate advertising SDKs or third-party analytics that profile you.

9. Retention & deletion

10. Your rights

Where the GDPR applies, you have the right to access, correct, delete, export (portability), restrict, or object to our processing of your personal data, and to withdraw consent. Because your data is primarily on your own device, you can already exercise most of these directly in the app. For anything server-side, contact us and we'll action it. You also have the right to lodge a complaint with your local supervisory authority — in Greece, the Hellenic Data Protection Authority (HDPA).

11. Security

Connections between the app and our servers use encryption in transit (HTTPS/TLS). Passwords are stored only as secure hashes. Access to synced data requires a valid authentication token. No system is perfectly secure, but we design the app to hold as little as possible off your device.

12. Children

The Receipt is intended for general audiences managing their own expenses and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us data through an account, contact us and we'll remove it.

13. Changes to this policy

As the app evolves we may update this policy. Material changes will be reflected here with a new "last updated" date, and where appropriate we'll surface a notice in the app.

14. Contact

Questions, requests, or concerns about privacy? Email privacy@whataniceidea.com.