Privacy Policy — my-receipt

Privacy policy for the my-receipt (meinBeleg) app — Smart Receipt Scanner & Expenses

1. Data Protection at a Glance

This privacy policy applies to the mobile app my-receipt (known as „meinBeleg" in Germany) by ActNow GmbH. It informs you about which personal data is collected and processed when using the app.

2. Data Controller

ActNow GmbH Torstrasse 33 10119 Berlin Germany

Email: info[at]actnow-gmbh.de Phone: +49(030)700142-450

Managing Director: M. Speck

3. Data Processing in the App

3.1 Collected and Processed Data

The app collects and processes the following data:

  • Photographed or imported receipt images
  • Extracted receipt information (amount, date, category, merchant)
  • Your settings and preferences
  • Exported reports

This data is stored both locally on your device and on our server, and is synchronized (see section 3.5).

Legal basis: Art. 6(1)(b) GDPR (contract performance — provision of app functionality).

3.2 Camera Access

The app requires access to your device’s camera to scan receipts. Captured images are transmitted to our server for text recognition (see section 3.4).

Legal basis: Art. 6(1)(a) GDPR (consent by granting permission in the operating system).

3.3 Photo Library Access

The app can access your photo library to import existing receipt photos. Access is only granted after your explicit approval.

Legal basis: Art. 6(1)(a) GDPR (consent).

3.4 Text Recognition (OCR) and AI Processing

The app uses AI-powered optical character recognition (OCR) and AI-based data extraction to extract text and structured information from receipt photos. Processing does not take place on your device but on our server (see section 3.5).

The following external services are used:

Google Cloud Vision API (OCR)

  • Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
  • Purpose: Optical character recognition from receipt images
  • Data processed: Receipt images are transmitted for text recognition
  • Privacy policy: https://policies.google.com/privacy

Microsoft Azure Computer Vision (OCR)

  • Provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA
  • Purpose: Optical character recognition from receipt images
  • Data processed: Receipt images are transmitted for text recognition
  • Privacy policy: https://privacy.microsoft.com/en-us/privacystatement

OpenRouter (AI Language Models / LLM)

  • Provider: OpenRouter, Inc., USA
  • Purpose: AI-powered extraction and structuring of receipt data (amount, date, category, merchant) from OCR-recognized text
  • Data processed: Extracted text from receipts (no image data)
  • Various AI models are used via OpenRouter
  • Privacy policy: https://openrouter.ai/privacy

Legal basis: Art. 6(1)(b) GDPR (contract performance — OCR and AI processing is a core function of the app) and Art. 6(1)(f) GDPR (legitimate interest in providing a powerful receipt recognition feature).

3.5 Cloud Synchronization and Data Storage

Your receipt data is synchronized with and stored on our server.

Hosting provider:

Your data is stored exclusively on servers in Germany. The strict data protection standards of the GDPR apply.

Data stored on the server:

  • Receipt images
  • Extracted receipt information
  • Account data (if an account was created)
  • Synchronization data

Legal basis: Art. 6(1)(b) GDPR (contract performance).

3.6 Optional Cloud Export Integrations (Dropbox, Google Drive, OneDrive)

If you wish, you can connect my-receipt to one or more external cloud storage services to export receipts or reports. The connection is established only after you actively sign in via the official login flow (OAuth) of the respective provider in the app’s settings. Only the files you select for export are transmitted to the respective provider.

Available integrations:

  • Dropbox — Dropbox International Unlimited Company, One Park Place, Hatch Street Upper, Dublin 2, Ireland — Privacy Policy
  • Google Drive — Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA — Privacy Policy
  • Microsoft OneDrive — Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA — Privacy Policy

These integrations are optional and remain disabled until you actively connect them. You can disconnect them at any time in the app’s settings.

Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 6(1)(b) GDPR (contract performance — provision of the export feature).

3.7 Device Permissions

For individual features, the app requests the following device permissions. You can revoke them at any time in iOS Settings.

  • Camera — to capture receipts (see Section 3.2)
  • Photo library — to import existing receipt photos (see Section 3.3)
  • Location (while using the app) — to display nearby service providers (“Find Service Provider Locations near you”)
  • Contacts — used only when you add attendees from your address book to an entertainment receipt

These permissions are requested only on demand and used solely for the stated purpose.

Legal basis: Art. 6(1)(a) GDPR (consent through OS-level permission).

3.8 Push Notifications (Firebase Cloud Messaging)

The app uses Firebase Cloud Messaging (FCM) along with the Apple Push Notification service (APNs) to deliver push notifications (e.g., warranty expiration reminders or successful receipt processing) to your device.

Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA — Privacy Policy and Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA — Privacy Policy

Data collected: a technical device token (FCM/APNs token) assigned to your device by the operating system.

You can disable push notifications at any time in iOS Settings → Notifications → my-receipt.

Legal basis: Art. 6(1)(a) GDPR (consent through OS-level push permission).

3.9 Apple Search Ads Attribution (AdServices)

The app uses Apple’s AdServices framework to determine whether your install of the app originated from an Apple Search Ads campaign. On first launch, the framework provides a one-time attribution token. The app forwards this token to Apple’s attribution endpoint (api-adservices.apple.com) and, in return, receives aggregated campaign metadata (e.g., campaign ID, ad group ID, conversion type, country/region).

The framework uses no advertising identifier (IDFA) and does not enable cross-app or cross-website tracking. Per Apple’s policies, this attribution measurement does not require App Tracking Transparency (ATT) consent.

Provider: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA — Privacy Policy

Apple is certified under the EU-US Data Privacy Framework.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring the effectiveness of our app marketing).

3.10 Data Processing Agreements

To ensure GDPR-compliant processing, we have concluded data processing agreements (DPA) with the service providers mentioned above.

4. Subscriptions and Payments

In-app purchases and subscriptions are processed through Apple (App Store). ActNow GmbH does not receive any payment data (credit card numbers, etc.) from Apple. We only receive information about the status of your subscription (active/inactive).

Responsible for payment processing: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA Privacy Policy: https://www.apple.com/legal/privacy/

5. Diagnostic and Crash Data (Firebase Crashlytics)

The app uses Firebase Crashlytics by Google for collecting crash and diagnostic data.

Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA Data collected:

  • Crash reports (stack traces)
  • Device information (model, OS version)
  • App version and build number
  • Anonymized usage data

This data does not contain personal information and does not allow conclusions about individual users.

Privacy policy: https://firebase.google.com/support/privacy

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving app stability).

6. Disclosure to Third Parties

Your data is shared with the service providers described in sections 3.4 and 3.5 as part of the processing described therein. Your data is not shared for advertising purposes, nor sold to third parties.

Summary of data processors:

Service ProviderPurposeLocation
Hetzner Online GmbHHosting, data storage, serverGermany
Google LLC (Cloud Vision)OCR text recognitionUSA (EU-US DPF + SCC)
Microsoft Corporation (Azure)OCR text recognitionUSA (EU-US DPF + SCC)
OpenRouter, Inc.AI data extraction (LLM)USA (SCC)
Google LLC (Firebase Cloud Messaging)Push notificationsUSA (EU-US DPF)
Google LLC (Firebase Crashlytics)Crash and diagnostic dataUSA (EU-US DPF)
Google LLC (Firebase Analytics / Remote Config)Anonymized usage statistics & configurationUSA (EU-US DPF)
Apple Inc. (APNs)Delivery of push notificationsUSA (EU-US DPF)
Apple Inc.Payment processing, app distributionUSA (EU-US DPF)
Apple Inc. (AdServices)Apple Search Ads attributionUSA (EU-US DPF)
Dropbox International Unlimited CompanyOptional receipt export (only after active connection)Ireland (EU) / USA
Google LLC (Google Drive)Optional receipt export (only after active connection)USA (EU-US DPF)
Microsoft Corporation (OneDrive)Optional receipt export (only after active connection)USA (EU-US DPF + SCC)

7. Data Transfer to Third Countries

When using OCR and AI services (Google, Microsoft, OpenRouter), the push infrastructure (Google FCM, Apple APNs), payment processing (Apple), and — if enabled — the optional cloud export integrations, data is transferred to the USA or to Ireland.

  • Google, Microsoft, and Apple are certified under the EU-US Data Privacy Framework (DPF). Additionally, we rely on the EU Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR) as a supplementary transfer safeguard.
  • For OpenRouter, we rely on the EU Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR) as a safeguard for an adequate level of data protection.
  • Dropbox processes data primarily within the EU (Ireland) but may also transfer data to the USA; the transfer is based on Standard Contractual Clauses and Dropbox’s own data protection safeguards.

Your receipt data is stored on servers of Hetzner Online GmbH in Germany and only leaves the European Economic Area as part of the processing described above — or if you have actively connected an external cloud storage service.

8. Data Retention

  • Server data: Your data stored on the server is retained as long as your account is active. After deletion of your account, all associated data will be deleted within 30 days.
  • Local data: Data stored locally on your device remains there until you delete it or uninstall the app.

9. Your Rights

Under the GDPR, you have the following rights:

  • Information (Art. 15 GDPR): Right to information about the processing of your data
  • Rectification (Art. 16 GDPR): Right to correction of inaccurate data
  • Erasure (Art. 17 GDPR): Right to deletion of your data
  • Restriction (Art. 18 GDPR): Right to restrict processing
  • Data portability (Art. 20 GDPR): Right to receive your data in a machine-readable format
  • Objection (Art. 21 GDPR): Right to object to processing
  • Withdrawal of consent: Possible at any time, without giving reasons

To exercise your rights, please contact: info[at]actnow-gmbh.de

Right to Complain

You have the right to lodge a complaint with the competent data protection supervisory authority:

Berlin Commissioner for Data Protection and Freedom of Information Friedrichstr. 219, 10969 Berlin https://www.datenschutz-berlin.de

10. Notice on Use of Artificial Intelligence (EU AI Act)

This app uses AI-powered technologies for the following features:

  • Optical Character Recognition (OCR): Extraction of text from receipt photos using Google Cloud Vision and Microsoft Azure Computer Vision
  • AI-based Data Extraction: Structuring and categorization of receipt data (amount, date, merchant, category) using large language models (LLM) via OpenRouter

AI processing takes place server-side on our server in Germany (Hetzner). Receipt images and extracted text are transmitted to the third-party providers mentioned above for processing.

The system is classified as a low-risk AI system under Regulation (EU) 2024/1689 (EU AI Act), as it serves as a text recognition and data extraction tool and does not make autonomous decisions with legal effect for the user. In accordance with Art. 50 of the EU AI Act, we hereby transparently inform you about the use of AI systems in this app.

11. Data Security

We employ technical and organizational measures to protect your data:

  • Encrypted data transfer (TLS/SSL) between app and server
  • Encrypted storage on the server
  • Server location in Germany under German data protection law
  • Regular security updates

12. Changes to This Privacy Policy

We reserve the right to update this privacy policy to comply with current legal requirements or to implement changes to our app.

Last updated: April 2026