1. Who we are
The Receipt is developed by What a Nice Idea ("we", "us", "our"), an independent software studio. This policy explains what information the app processes, why, and the choices you have. For anything privacy-related you can reach us at privacy@whataniceidea.com.
For the purposes of the EU General Data Protection Regulation (GDPR) and the equivalent Greek data-protection law, What a Nice Idea is the data controller for the limited processing described below.
2. Scope & local-first design
The Receipt is designed to be local-first: the authoritative copy of your data is the database stored on your own device. The app is fully functional offline, and by default nothing you record leaves your phone.
Some optional features — creating an account, syncing across devices, and enriching a scanned receipt — do involve our servers. Those are described explicitly in the sections below. If you never use them, the app operates entirely on-device.
3. What data we process
The information the app handles falls into the following categories:
| Category | Examples | Where it lives |
|---|---|---|
| Expense records | Amount, currency, category, notes, date/time you assign | On your device; in our cloud only if you enable sync |
| Receipt details | Merchant name, tax number (AFM), line items, totals returned for a scanned receipt | On your device; in our cloud only if you enable sync |
| Receipt images | Photos of receipts you choose to attach | On your device; in our cloud storage only if you enable sync |
| Scanned QR URL | The AADE / provider URL encoded in a receipt's QR code | Sent to our server for enrichment (see §4) |
| Account data | Email address and a securely hashed password (only if you register) | Our authentication server |
| Technical data | IP address and request metadata, used transiently for rate-limiting and abuse prevention | Our server, short-lived |
We do not ask for your name, phone number, government ID, or AADE/tax-authority login. We do not build advertising profiles and we do not track you across other apps or websites.
4. Receipt QR scanning & enrichment
The core feature of The Receipt is turning a Greek receipt's QR code into a structured expense. This happens in two steps:
On your device
Your camera scans the QR code and the app reads the URL it contains. Basic parsing happens locally so your form can pre-fill instantly.
On our server
To fetch the full receipt details, the app sends the scanned QR URL to our enrichment service (a Cloudflare Worker operated by us). That service contacts the relevant Greek public or e-invoicing system — for example the AADE receipt-check API, myDATA, or providers such as EnterSoftOne, EpsilonNet, SimplyCloud, SimpleInvoicing — and returns a normalised receipt to your device.
- This works without any tax-authority credentials from you. The QR URL itself carries the public reference to the receipt.
- If a QR code comes from a provider we don't yet recognise, the URL may be stored so we can add support for that provider. These records are the receipt URL and a scan count — not linked to your identity.
- If enrichment is rate-limited or fails, the app simply keeps the data it already parsed on-device; enrichment failing never blocks you.
5. Accounts & cloud sync
Accounts are entirely optional. You only need one if you want your expenses to sync between multiple devices.
- To register, we collect an email address and a password. The password is stored only as a secure one-way hash; we cannot read it.
- If you enable sync, your expenses, receipt details, and attached receipt images are stored in our cloud backend (Cloudflare D1 database and R2 object storage) so they can be delivered to your other signed-in devices.
- Sync uses a delta model: only changed records are exchanged. Deleted items are marked as deleted (soft delete) so the deletion propagates to your other devices.
- If you never create an account, none of your expense data is transmitted to or stored on our servers.
6. Device permissions
| Permission | Why |
|---|---|
| Camera | To scan receipt QR codes and, where supported, read receipt text (OCR). Frames are processed on-device; we don't stream your camera anywhere. |
| Photos / storage | Only if you attach or save a receipt image. |
| Biometrics (optional) | If you enable an app lock, biometric matching is performed by your operating system. We never receive your fingerprint or face data. |
7. Third-party services
We keep third parties to a minimum. The ones involved are:
- Cloudflare — hosts our enrichment service and (if you enable sync) our database and file storage. Cloudflare processes data on our behalf as a processor.
- Greek AADE and e-invoicing providers — queried through our server to retrieve the details of the specific receipt you scanned. We only send the receipt's own QR URL.
- Your app store (Apple App Store / Google Play) — handles app distribution and any store-level metrics under its own privacy policy.
We do not integrate advertising SDKs or third-party analytics that profile you.
8. Why we process it (legal basis)
- Performing the service you asked for (contract): enriching a receipt you scanned, running your account, and syncing your data.
- Legitimate interests: keeping the service secure and preventing abuse (e.g. short-lived rate-limiting by IP), and improving provider coverage using non-identifying unknown-QR records.
- Consent: granting optional permissions such as camera or biometrics, which you can revoke at any time in your device settings.
9. Retention & deletion
- On-device data stays until you delete it or uninstall the app.
- Synced data is retained while your account is active. You can delete individual records, and you can request deletion of your account and its server-side data at any time.
- Technical/rate-limiting data is short-lived and not used to profile you.
10. Your rights
Where the GDPR applies, you have the right to access, correct, delete, export (portability), restrict, or object to our processing of your personal data, and to withdraw consent. Because your data is primarily on your own device, you can already exercise most of these directly in the app. For anything server-side, contact us and we'll action it. You also have the right to lodge a complaint with your local supervisory authority — in Greece, the Hellenic Data Protection Authority (HDPA).
11. Security
Connections between the app and our servers use encryption in transit (HTTPS/TLS). Passwords are stored only as secure hashes. Access to synced data requires a valid authentication token. No system is perfectly secure, but we design the app to hold as little as possible off your device.
12. Children
The Receipt is intended for general audiences managing their own expenses and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us data through an account, contact us and we'll remove it.
13. Changes to this policy
As the app evolves we may update this policy. Material changes will be reflected here with a new "last updated" date, and where appropriate we'll surface a notice in the app.
14. Contact
Questions, requests, or concerns about privacy? Email privacy@whataniceidea.com.