Traty Privacy Policy

Effective date: 29 September 2026

Traty turns a photograph of a paper receipt into a list of purchases, so that spending can be read month by month and category by category. What follows is what the app does with data, who receives it, and how to take it back or delete it. This document describes what the app actually does, not what it intends to.

1. Who we are

The controller of the data described here is Oleksii Charoian, an individual, at vul. Lesia Serdiuka 44, Kharkiv, Kharkiv Oblast, 61184, Ukraine, reachable at contact@traty.app. There is no company behind the app and no data protection officer: it is one person, and that person answers your requests.

The app is developed and operated from Ukraine, which is outside the European Economic Area. Where the GDPR applies to you, the section on transfers below covers what that means.

2. What we process

Account. Signing up with an email address stores that address; signing in with Google also stores the name as Google supplies it. The profile photo is not stored: its address used to be written to the account record and was never shown anywhere, so it is now deleted from records that still hold it. Authentication is performed by Firebase Authentication (Google LLC). The app neither sees nor stores your password.

Receipts. A saved receipt holds the merchant's name (both shortened to the chain and as printed), the date and time of purchase, the currency code, the total, the list of items — name, quantity, unit, unit price, line total, category — and where those items came from: entered by hand or read by a model, and if by a model, then which provider, which model, and when. Receipts are stored in Cloud Firestore (Google LLC).

Device identifier. So that the free recognition allowance cannot be reset by creating another account on the same phone, requests carry a device identifier (Google Play services' app_set_id, or, where that is unavailable, an identifier the app generates and keeps on the device only).

Subscription. Buying the subscription happens inside Google Play; we never see your card, your billing address or your name as it appears on the card. Google Play returns a purchase token, the app sends that token to our handler, and the handler verifies it with the Google Play Developer API. Two things are then stored in Cloudflare Workers KV: the token bound to your account identifier — so that one purchase cannot serve two accounts — and a record that the account is a subscriber, holding the token, the source (play) and the expiry date if the store reports one.

What we do not collect. The app reads no location from the device, no contacts, no list of installed applications, no browsing history and no advertising identifiers. It contains no analytics and no advertising libraries. The one place a location appears at all is an error report, where it is inferred from the network address rather than read from the device; see "Diagnostics" below.

3. Receipt recognition

Recognition happens in two steps, and only the second one leaves the phone.

A receipt can come from three places: the camera, an image already in your gallery, or a PDF file — an electronic receipt as the shop issued it. A PDF is turned into a single image on the device, and from there all three are treated identically; wherever this section says "the photograph", it means whichever of the three you chose.

The total, the date and the currency are read on the device. Right after the photograph is taken, text recognition built into the app reads them from it. That step needs no network and sends nothing anywhere.

The list of items is read in an external service. That is the only part that needs the photograph to leave the device, and it is what the rest of this section describes.

When you start recognition, the photograph is downscaled on the device and sent to our handler hosted on Cloudflare Workers (Cloudflare, Inc.). The handler passes the image to a model provider, receives the parsed contents of the receipt, and returns them to the app. A receipt too tall for the provider to read whole is cut into parts by Cloudflare Images, which is the same processor and the same transit: the parts are not stored either.

The image is not stored — not on the device once the operation ends, not on our server, and not as part of the saved receipt. The handler holds it in memory for the duration of the request and drops it once it answers, on success and on failure alike. The original PDF is never sent anywhere: only the image rendered from it is.

Model provider. The provider in use is OpenAI, Inc. and the model in use is gpt-5.6-luna. OpenAI retains data submitted through the API for up to 30 days for abuse monitoring and does not train on it. We may change the provider or the model; whichever is in use is named in this section, and every recognised receipt records which provider and model read it.

Sending the photograph is optional. If you would rather not send a receipt to a third party, do not start recognition on it — neither from the camera, nor from the gallery, nor from a file: items can be entered by hand, and the rest of the app works without restriction.

4. Operational data

To bound what recognition costs, the handler keeps counters keyed to your account identifier, to your device identifier, and — if you belong to a household — to that household's identifier. The counters live in Cloudflare Workers KV. Counters for a period are deleted once the period ends. They contain no images and no receipt contents.

The handler also keeps a record of what each recognition cost us: your account identifier, the moment, which model read the receipt, how much work it took and what that came to in money. The record lives in a Cloudflare D1 database and is what tells us the price of running the service. It holds no image and no receipt contents — not the shop, not the items, not the amount you paid.

To establish that a request comes from a signed-in user, the app attaches a Firebase token. The token is verified and not stored.

A recognition request also carries two hints that help read the receipt: the language of the app's interface, and the currency code the app would use if the receipt does not print one. Neither is stored.

5. Diagnostics: what happens when something breaks

When the app or the handler fails, a report of that failure is sent to Sentry (Functional Software, Inc.) and stored in Sentry's European region. A report carries the error and the place in the code it happened, the version of the app and of the operating system, the identifier of your account, and technical facts about the device that usually explain the failure: model, interface language, time zone, free memory and storage, battery level, and which permissions you have granted the app.

It carries no receipt image, no receipt contents, no email address and no name.

It does carry an approximate location — the country, and often the city — which Sentry derives from the IP address the report arrived from. This is not the location of your device as a map would give it, and it is not read from the device at all; it is what any server can tell about any visitor. The IP address itself is discarded and not stored.

Only a failure that means something on our side is broken is reported. A spent allowance, a missing subscription, or a photo that holds no receipt are the app working as designed, and nothing about them is sent anywhere. Reports are kept for as long as Sentry's own retention allows and are not used for anything but fixing defects.

6. Households: one shared receipt base

The app lets several accounts join a household with a single shared base of receipts. This is voluntary: without joining one, your receipts are visible only to you.

What it means for your data. While you are in a household, every member sees all of its receipts in full — merchant, date, total, every item and category — and may edit and delete them. Each receipt shows who entered it. The receipts you accumulated before joining are moved into the shared base when you join and become visible to the other members.

What happens when you leave. If you leave a household yourself, a copy of the receipts you entered returns to your own history, while the household keeps everything it had — including those receipts. If the owner removes you, access to the shared base ends at once and you get no copy: the removed member no longer has access, and the owner has none to your personal area, so there is nobody left who could make one.

Who decides what. Only the owner — whose subscription opened the household — can invite and remove. An invitation is a short code that lives for fifteen minutes and is spent on first use. Any member may leave at any time.

Storage enforces the boundary. Access to a household's receipts is granted only to the accounts in its roster, and that is checked by Cloud Firestore security rules on Google's side, not by the app on the device.

7. Who receives data

RecipientWhat they receiveWhy
Google LLC (Firebase Authentication, Cloud Firestore)account data, receiptssigning in and storing receipts
The other members of your householdall of the household's receipts, including yoursthe shared spending base, if you joined one
Cloudflare, Inc.the receipt image (in transit), account, device and household identifiersthe recognition handler, the allowance counters and the record of what recognition cost
OpenAI, Inc.the receipt imagereading the contents of the purchase
Google LLC (Google Play Billing, Play Developer API)the purchase token, and whatever the payment itself requires — that part happens inside Google Play and does not pass through usselling and verifying the subscription
Functional Software, Inc. (Sentry)the error, the version of the app, technical facts about the device and its operating system, the account identifier, an approximate location inferred from the network addressfinding and fixing what breaks

We do not sell data, do not share it for advertising, and do not use it for profiling.

8. Transfers outside the EEA

The recipients listed above are companies in the United States, and the app is operated from Ukraine, so data is processed outside the European Economic Area. Error reports are the exception: Sentry stores them in its European region, so they stay inside the EEA. Transfers to the recipients rely on the European Commission's standard contractual clauses and, where applicable, on the recipient's participation in the Data Privacy Framework. Ukraine has no adequacy decision, and requests you send to the address above are answered from there.

9. Legal bases

10. Retention

Account data and receipts are kept for as long as your account exists. A receipt entered into a household is kept for as long as the household exists or until any of its members deletes it; your leaving does not remove it from there. Receipt images are not kept at all. Period counters live no longer than their period — a day or a calendar month; the free-recognition counter has no expiry while the account exists, because the allowance itself has none. The record of what recognition cost outlives the account, but not the link to you: deleting the account replaces your identifier in it with a marker, so what remains is a cost with nobody attached to it and is no longer data about a person. The subscription record and the purchase-token binding are kept while the account exists. When you delete the account, none of these is deleted at that moment; each expires on its own: the period counters at the end of their day or month, the free-recognition counter and the subscription record 30 days after the deletion. This is so that deleting an account cannot be used to start the allowance over, and so that a deletion interrupted halfway leaves a working account behind. The purchase-token binding is replaced by a note that the purchase was released by your account identifier, kept for 35 days, so that someone who buys, deletes the account and signs up again can restore what they paid for — with that month's use carried over. On the model provider's side: up to 30 days, see "Receipt recognition".

11. Your rights

You may request access to your data, its rectification, erasure, portability, restriction of processing, and you may object to processing based on legitimate interest. Write to contact@traty.app and we will answer within the period the GDPR sets (one month).

You also have the right to lodge a complaint with the data protection authority of your place of residence.

12. Deleting your account and data

You can delete your account in the app: Settings → Delete account. The app asks you to confirm it is you — with your password, or by consenting again at your sign-in provider — and then deletes the account data, every receipt in your personal area; the allowance counters, the subscription record and the purchase-token binding expire as described under "Retention". Deletion is irreversible.

If the app is already off your phone, write to contact@traty.app from the address the account is registered to. The procedure and the timing are on a page of their own: deleting your account.

Receipts you entered into a household stay with the household — the other members can see them, and deleting your account does not remove them. In the app, an owner's deletion is refused while the household exists: it has to be disbanded first, so the shared base does not vanish for everyone else without their knowing. If you ask us in writing instead, the household passes to one of its remaining members and its shared base stays intact — unless you are its only member, in which case it is deleted along with you. If you want to take your history with you, leave the household before deleting the account: a voluntary departure returns a copy of your receipts to your own history.

13. Children

The app is not directed at children under 16, and we deliberately collect no data about age.

14. Security

Data travels over TLS only. Access to receipts is bounded by Cloud Firestore security rules on Google's side: a receipt is visible to the account that owns it, and a household's receipt only to its members. Model provider keys live on the server and never reach the app.

15. Contact

Questions about this policy and data requests: contact@traty.app.

16. Changes

If what we process changes — should receipt images start being stored, say, or should the model provider change — we will update this policy and the Data safety declaration in Google Play before the change takes effect. The effective date at the top of this document identifies the edition in force.