Privacy Policy — my-receipt
Privacy policy for the my-receipt (meinBeleg) app — Smart Receipt Scanner & Expenses
1. Data Protection at a Glance
This privacy policy applies to the mobile app my-receipt (known as „meinBeleg" in Germany) by ActNow GmbH. It informs you about which personal data is collected and processed when using the app.
2. Data Controller
ActNow GmbH Torstrasse 33 10119 Berlin Germany
Email: info[at]actnow-gmbh.de Phone: +49(030)700142-450
Managing Director: M. Speck
3. Data Processing in the App
3.1 Collected and Processed Data
The app collects and processes the following data:
- Photographed or imported receipt images
- Extracted receipt information (amount, date, category, merchant)
- Your settings and preferences
- Exported reports
This data is stored both locally on your device and on our server, and is synchronized (see section 3.5).
Legal basis: Art. 6(1)(b) GDPR (contract performance — provision of app functionality).
3.2 Camera Access
The app requires access to your device’s camera to scan receipts. Captured images are transmitted to our server for text recognition (see section 3.4).
Legal basis: Art. 6(1)(a) GDPR (consent by granting permission in the operating system).
3.3 Photo Library Access
The app can access your photo library to import existing receipt photos. Access is only granted after your explicit approval.
Legal basis: Art. 6(1)(a) GDPR (consent).
3.4 Text Recognition (OCR) and AI Processing
The app uses AI-powered optical character recognition (OCR) and AI-based data extraction to extract text and structured information from receipt photos. Processing does not take place on your device but on our server (see section 3.5).
The following external services are used:
Google Cloud Vision API (OCR)
- Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
- Purpose: Optical character recognition from receipt images
- Data processed: Receipt images are transmitted for text recognition
- Privacy policy: https://policies.google.com/privacy
Microsoft Azure Computer Vision (OCR)
- Provider: Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA
- Purpose: Optical character recognition from receipt images
- Data processed: Receipt images are transmitted for text recognition
- Privacy policy: https://privacy.microsoft.com/en-us/privacystatement
OpenRouter (AI Language Models / LLM)
- Provider: OpenRouter, Inc., USA
- Purpose: AI-powered extraction and structuring of receipt data (amount, date, category, merchant) from OCR-recognized text
- Data processed: Extracted text from receipts (no image data)
- Various AI models are used via OpenRouter
- Privacy policy: https://openrouter.ai/privacy
Legal basis: Art. 6(1)(b) GDPR (contract performance — OCR and AI processing is a core function of the app) and Art. 6(1)(f) GDPR (legitimate interest in providing a powerful receipt recognition feature).
3.5 Cloud Synchronization and Data Storage
Your receipt data is synchronized with and stored on our server.
Hosting provider:
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
- Server location: Germany
- Privacy policy: https://www.hetzner.com/legal/privacy-policy/
Your data is stored exclusively on servers in Germany. The strict data protection standards of the GDPR apply.
Data stored on the server:
- Receipt images
- Extracted receipt information
- Account data (if an account was created)
- Synchronization data
Legal basis: Art. 6(1)(b) GDPR (contract performance).
3.6 Optional Cloud Export Integrations (Dropbox, Google Drive, OneDrive)
If you wish, you can connect my-receipt to one or more external cloud storage services to export receipts or reports. The connection is established only after you actively sign in via the official login flow (OAuth) of the respective provider in the app’s settings. Only the files you select for export are transmitted to the respective provider.
Available integrations:
- Dropbox — Dropbox International Unlimited Company, One Park Place, Hatch Street Upper, Dublin 2, Ireland — Privacy Policy
- Google Drive — Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA — Privacy Policy
- Microsoft OneDrive — Microsoft Corporation, One Microsoft Way, Redmond, WA 98052, USA — Privacy Policy
These integrations are optional and remain disabled until you actively connect them. You can disconnect them at any time in the app’s settings.
Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 6(1)(b) GDPR (contract performance — provision of the export feature).
3.7 Device Permissions
For individual features, the app requests the following device permissions. You can revoke them at any time in iOS Settings.
- Camera — to capture receipts (see Section 3.2)
- Photo library — to import existing receipt photos (see Section 3.3)
- Location (while using the app) — to display nearby service providers (“Find Service Provider Locations near you”)
- Contacts — used only when you add attendees from your address book to an entertainment receipt
These permissions are requested only on demand and used solely for the stated purpose.
Legal basis: Art. 6(1)(a) GDPR (consent through OS-level permission).
3.8 Push Notifications (Firebase Cloud Messaging)
The app uses Firebase Cloud Messaging (FCM) along with the Apple Push Notification service (APNs) to deliver push notifications (e.g., warranty expiration reminders or successful receipt processing) to your device.
Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA — Privacy Policy and Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA — Privacy Policy
Data collected: a technical device token (FCM/APNs token) assigned to your device by the operating system.
You can disable push notifications at any time in iOS Settings → Notifications → my-receipt.
Legal basis: Art. 6(1)(a) GDPR (consent through OS-level push permission).
3.9 Apple Search Ads Attribution (AdServices)
The app uses Apple’s AdServices framework to determine whether your install of the app originated from an Apple Search Ads campaign. On first launch, the framework provides a one-time attribution token. The app forwards this token to Apple’s attribution endpoint (api-adservices.apple.com) and, in return, receives aggregated campaign metadata (e.g., campaign ID, ad group ID, conversion type, country/region).
The framework uses no advertising identifier (IDFA) and does not enable cross-app or cross-website tracking. Per Apple’s policies, this attribution measurement does not require App Tracking Transparency (ATT) consent.
Provider: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA — Privacy Policy
Apple is certified under the EU-US Data Privacy Framework.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in measuring the effectiveness of our app marketing).
3.10 Data Processing Agreements
To ensure GDPR-compliant processing, we have concluded data processing agreements (DPA) with the service providers mentioned above.
4. Subscriptions and Payments
In-app purchases and subscriptions are processed through Apple (App Store). ActNow GmbH does not receive any payment data (credit card numbers, etc.) from Apple. We only receive information about the status of your subscription (active/inactive).
Responsible for payment processing: Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA Privacy Policy: https://www.apple.com/legal/privacy/
5. Diagnostic and Crash Data (Firebase Crashlytics)
The app uses Firebase Crashlytics by Google for collecting crash and diagnostic data.
Provider: Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA Data collected:
- Crash reports (stack traces)
- Device information (model, OS version)
- App version and build number
- Anonymized usage data
This data does not contain personal information and does not allow conclusions about individual users.
Privacy policy: https://firebase.google.com/support/privacy
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in improving app stability).
6. Disclosure to Third Parties
Your data is shared with the service providers described in sections 3.4 and 3.5 as part of the processing described therein. Your data is not shared for advertising purposes, nor sold to third parties.
Summary of data processors:
| Service Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting, data storage, server | Germany |
| Google LLC (Cloud Vision) | OCR text recognition | USA (EU-US DPF + SCC) |
| Microsoft Corporation (Azure) | OCR text recognition | USA (EU-US DPF + SCC) |
| OpenRouter, Inc. | AI data extraction (LLM) | USA (SCC) |
| Google LLC (Firebase Cloud Messaging) | Push notifications | USA (EU-US DPF) |
| Google LLC (Firebase Crashlytics) | Crash and diagnostic data | USA (EU-US DPF) |
| Google LLC (Firebase Analytics / Remote Config) | Anonymized usage statistics & configuration | USA (EU-US DPF) |
| Apple Inc. (APNs) | Delivery of push notifications | USA (EU-US DPF) |
| Apple Inc. | Payment processing, app distribution | USA (EU-US DPF) |
| Apple Inc. (AdServices) | Apple Search Ads attribution | USA (EU-US DPF) |
| Dropbox International Unlimited Company | Optional receipt export (only after active connection) | Ireland (EU) / USA |
| Google LLC (Google Drive) | Optional receipt export (only after active connection) | USA (EU-US DPF) |
| Microsoft Corporation (OneDrive) | Optional receipt export (only after active connection) | USA (EU-US DPF + SCC) |
7. Data Transfer to Third Countries
When using OCR and AI services (Google, Microsoft, OpenRouter), the push infrastructure (Google FCM, Apple APNs), payment processing (Apple), and — if enabled — the optional cloud export integrations, data is transferred to the USA or to Ireland.
- Google, Microsoft, and Apple are certified under the EU-US Data Privacy Framework (DPF). Additionally, we rely on the EU Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR) as a supplementary transfer safeguard.
- For OpenRouter, we rely on the EU Commission’s Standard Contractual Clauses (Art. 46(2)(c) GDPR) as a safeguard for an adequate level of data protection.
- Dropbox processes data primarily within the EU (Ireland) but may also transfer data to the USA; the transfer is based on Standard Contractual Clauses and Dropbox’s own data protection safeguards.
Your receipt data is stored on servers of Hetzner Online GmbH in Germany and only leaves the European Economic Area as part of the processing described above — or if you have actively connected an external cloud storage service.
8. Data Retention
- Server data: Your data stored on the server is retained as long as your account is active. After deletion of your account, all associated data will be deleted within 30 days.
- Local data: Data stored locally on your device remains there until you delete it or uninstall the app.
9. Your Rights
Under the GDPR, you have the following rights:
- Information (Art. 15 GDPR): Right to information about the processing of your data
- Rectification (Art. 16 GDPR): Right to correction of inaccurate data
- Erasure (Art. 17 GDPR): Right to deletion of your data
- Restriction (Art. 18 GDPR): Right to restrict processing
- Data portability (Art. 20 GDPR): Right to receive your data in a machine-readable format
- Objection (Art. 21 GDPR): Right to object to processing
- Withdrawal of consent: Possible at any time, without giving reasons
To exercise your rights, please contact: info[at]actnow-gmbh.de
Right to Complain
You have the right to lodge a complaint with the competent data protection supervisory authority:
Berlin Commissioner for Data Protection and Freedom of Information Friedrichstr. 219, 10969 Berlin https://www.datenschutz-berlin.de
10. Notice on Use of Artificial Intelligence (EU AI Act)
This app uses AI-powered technologies for the following features:
- Optical Character Recognition (OCR): Extraction of text from receipt photos using Google Cloud Vision and Microsoft Azure Computer Vision
- AI-based Data Extraction: Structuring and categorization of receipt data (amount, date, merchant, category) using large language models (LLM) via OpenRouter
AI processing takes place server-side on our server in Germany (Hetzner). Receipt images and extracted text are transmitted to the third-party providers mentioned above for processing.
The system is classified as a low-risk AI system under Regulation (EU) 2024/1689 (EU AI Act), as it serves as a text recognition and data extraction tool and does not make autonomous decisions with legal effect for the user. In accordance with Art. 50 of the EU AI Act, we hereby transparently inform you about the use of AI systems in this app.
11. Data Security
We employ technical and organizational measures to protect your data:
- Encrypted data transfer (TLS/SSL) between app and server
- Encrypted storage on the server
- Server location in Germany under German data protection law
- Regular security updates
12. Changes to This Privacy Policy
We reserve the right to update this privacy policy to comply with current legal requirements or to implement changes to our app.
Last updated: April 2026