This policy applies to the kvitko. Android app (previously Kvit), packages com.croat.dev.kvitko and the earlier com.croat.dev.kvit, and its privacy website. The operator and data controller is Biocal d.o.o., using the developer brand croat.dev. Privacy contact: support@croat.dev.
Kvitko scans receipts and tracks spending without a Kvitko account. Normal receipt recognition and categorisation use the OCR engine, rules and saved corrections on your phone. The sharing, backup and experimental features below are separate choices; online features also require an available service.
What stays on your phone
Receipt photos, recognised text, store names and addresses, tax identifiers printed on receipts, purchase dates, items, quantities, prices, discounts and totals are processed to build editable receipts and spending summaries. Photos and receipts can also contain personal information printed by the merchant.
Your receipts, original photos, detailed OCR evidence, products, categories, budgets, profile display name, preferences and correction history are stored in Kvitko's private storage on your phone. Android cloud backup is disabled. The receipt database and private files are excluded from Android device transfer; some device-transfer tools may still transfer app preferences. Saving may send the limited information described below if you enable correction sharing, regional knowledge sharing or join a household. Settings offers CSV/JSON export and deletion of local app data.
Camera and photos
Camera permission is used when you take receipt photos. Imported images are selected through Android's picker. Text recognition and fiscal QR decoding run on your phone; Kvitko does not upload receipts for cloud OCR. Photo date metadata may suggest a date for you to confirm. Kvitko does not request GPS/location, contacts, microphone, SMS or call-log permissions. Store locations come from receipts or your edits, and your initial country comes from the device's region setting.
Regional rules and updates
Kvitko sorts items and recognises stores with rules for each country, built into the app. It reads the store's name, address and public tax number printed on the receipt to fill the location and country; this happens on your phone. When an update service is available, Kvitko downloads signed rule updates at most once a day for your home country and the countries your receipts come from. Requests reveal the packs requested and normal connection information, including your IP address, to the service. They do not include photos or receipt item lists. You can turn automatic updates off in Settings.
Regional knowledge sharing (optional, off by default)
With your permission, Kvitko sends, for each country: the words of items whose category you chose yourself, that category, and the public tax number, chain identifier and name of stores on your saved receipts. Amounts, dates, photos and other items are not sent. Contributions are stored under a pseudonymous identifier derived from your phone's anonymous sharing key and kept separately per country. A word or store becomes part of the published rules only when at least three people agree. Contributions are kept for up to 730 days. Turning the option off requests their deletion when the service is reachable. Published rules omit contributor identifiers; deletion does not recall already distributed rules.
Experimental model in Settings
The current app still includes an optional Gemini Nano feature under Settings → Experimental. It is off by default and is not used for normal receipt recognition. Enabling it allows additional category and product suggestions to run on supported phones. Checking model availability or downloading the model also uses Google components. Kvitko does not upload receipt text or images for cloud generation.
The included Google ML Kit SDK and AICore service can process technical diagnostics when initialised or used: device and app information, identifiers, configured language, feature use, input/output sizes, performance and errors. Turning off model suggestions does not control all Google SDK diagnostics. These are separate from Kvitko's crash-reporting option. Details: https://developers.google.com/ml-kit/android-data-disclosure and https://policies.google.com/privacy
Anonymous sharing key
Kvitko has no accounts and no sign-in. When you enable regional knowledge sharing and the service is reachable, it gives this phone a sharing key: a random number and a secret, of which the service keeps only a hashed form. The key carries no name, e-mail address or phone number. Under it the service stores your privacy choices with the policy version and time of each decision, and when the key was created and last used. In Settings, Shared data, you can see everything shared under the key and delete it; deleting removes your regional knowledge contributions, privacy records and the key itself. The key and consent records otherwise remain until deleted. Household sync and the corrections library use separate credentials and deletion controls. The Kvitko application service does not keep routine per-request access logs; hosting and network providers may process operational metadata as described below.
Households (optional)
If you start or join a household, receipts you save from then on, their products, member display names and payer information, and a small grey reading copy of each photo are shared with its members. Receipts saved earlier are shared only if you choose to. They are encrypted on your phone with a key only the members' phones hold; the Kvitko service stores and forwards them without being able to read them, and keeps them for up to 90 days. The relay also processes random household/sender identifiers, hashed access credentials, record sizes, timestamps and temporary invitation/public-key information. Invitation records expire after 30 minutes or are removed when used. Names inside the encrypted content are visible to household members. Reading copies can reveal everything visible on a receipt. Original-resolution photos and detailed OCR evidence are not included in household sync. A new member joins only with a one-time invitation and an approval on a member's phone. Anyone who leaves or is removed keeps what they already received but gets nothing new: the others move to a new key. A household unused for a year is removed from the service. Members can retain copies they already received or exported. Leaving a household or deleting local app data cannot erase another member's copies. Household deletion and sync changes require a working connection.
Backups (optional)
Kvitko can write an encrypted backup file to a place you choose, such as Google Drive or another app, when you ask or on a schedule. It is encrypted on your phone using a key derived from your backup passphrase. We do not receive or recover that passphrase. For scheduled backups, the derived key is protected on your device with Android Keystore. If you connect Google Drive, backups go to Kvitko's hidden app-data folder in your Drive, and Kvitko's permission covers only that folder. The selected Google account address and access token are used on your device to manage backups and are not sent to Kvitko's service. Google receives the encrypted file and normal account/file/connection metadata under its privacy policy: https://policies.google.com/privacy
After a successful, verified upload, Kvitko keeps the three newest backups in its hidden Google Drive folder and removes older ones. Backups saved to another destination remain until you delete or replace them. Disconnecting Drive, clearing app data or uninstalling does not automatically delete existing backups. CSV/JSON exports are not encrypted by Kvitko. The app, service or person you choose receives the exported content and applies its own data handling practices.
Server recovery copies
The operator makes encrypted daily recovery copies of Kvitko service data and configuration. Copies are kept for up to seven days on the server and, when available, an operator-controlled computer. The recovery key is kept separately from the server. Deleted or withdrawn data may remain in these restricted copies until expiry; after recovery, later deletions and withdrawals must be reconciled before affected data is made available again. These copies are separate from backups you make in the app.
Shared corrections (optional, off by default)
A new, separate opt-in enables automatic contributions from receipts you save afterward. Older manual-preview permission does not enable this. Eligible contributions contain original/corrected store or item names, merchant context, small image crops, source/revision hashes and contribution identifiers. Crops can include adjacent printed information. Full receipt photos, your receipt list, profile and spending records are not attached. Old receipts are not backfilled unless you save them again. Uploads normally wait for Wi-Fi and can retry while the app is closed. You can also explicitly preview and send selected corrections from a saved receipt.
The phone uses a random correction-sharing credential, separate from household and regional sharing keys. The service stores its hash, policy version and registration time, not your name or email. Content is submitted to the Kvitko operator for review; publication is a separate step. Unreviewed examples are kept for up to 90 days and approved ones for up to 365 days from submission. Approved text rules may be distributed to other users; source images are not part of those downloads. Rule downloads update automatically when enabled and do not upload receipt content.
Turning automatic sharing off cancels pending automatic uploads. Already sent contributions remain in Shared corrections until you withdraw them or their retention period ends. Deleting a receipt queues withdrawal of its contributions. Offline requests take effect after connection. Withdrawal removes examples and their rules from subsequent releases; previously downloaded packages expire within seven days. Minimal credentials, identifiers, hashes, status and review/withdrawal records remain to prevent cancelled submissions from reappearing and maintain review history while the library operates.
Crash reports (optional)
If Kvitko closes unexpectedly, the error report stays on your phone. It is sent without a Kvitko account identifier, and only if you allow crash reports or approve that one report. It contains app/Android versions, device manufacturer/model, thread name and technical exception details. Kvitko does not attach photos or the receipt database; exception messages can contain values involved in an error. Reports are used to diagnose faults, sent without a Kvitko sharing key or account identifier, and kept for up to 90 days. Normal connection metadata is still processed. An email address alone may not identify a report. The local report remains until sent, discarded, replaced by a newer report or removed with app data.
Notifications (optional)
Evening receipt reminders are scheduled on your phone. Whether you added a receipt today stays on your phone. Android notification permission is required, and reminders and announcements have separate off switches in Settings.
If announcements are enabled and notification permission is granted, a configured release uses Google Firebase Cloud Messaging to deliver an announcement identifier. Google processes an app installation identifier, a delivery token and connection/device information for this delivery. Kvitko sends no receipt photos, items, amounts, shopping history or profile name to Firebase. Announcement text is downloaded from Kvitko's service; this request exposes your IP address as with other internet requests. Firebase Analytics, advertising measurement and delivery export to BigQuery are not enabled. Disabling announcements stops subscription/delivery and requests deletion of the delivery token when online. This does not delete the separate Firebase installation identifier or Google's existing service records. While announcements are enabled, opening the app can also refresh the public announcement feed even without Android notification permission. This request uses normal connection metadata; it does not send receipt content, a sharing key or the Firebase delivery token. Read/dismissed announcement identifiers stay on the phone. Google's retention and processing are described at https://firebase.google.com/support/privacy
What Kvitko does not do
Kvitko has no advertising SDKs, does not sell personal data and does not use advertising identifiers or cross-app tracking. Google SDK diagnostics are described above.
Recipients, security and this website
Data is handled by the Kvitko operator and authorised support/review personnel; infrastructure and hosting providers that operate the servers; Google for the services described above; approved household members; and backup/export destinations you choose. We may disclose information where required by law.
Online service connections use HTTPS. Household content and backup files receive the additional encryption described above. Local app storage uses Android's app isolation and device protections. No storage or transmission method can guarantee absolute security. Connections reveal network information such as IP addresses to the service and its infrastructure, for delivery, operation and abuse prevention.
The Kvitko landing page and privacy pages use no cookies, analytics scripts or remotely hosted fonts. Routine website access logging is disabled. Hosting and network providers may process operational/security metadata under their own policies. Google services may process data outside your country, including outside the European Economic Area, under their applicable data-protection terms: https://firebase.google.com/terms/data-processing-terms and https://policies.google.com/privacy
If you email support@croat.dev, we and our email provider process your address, message and attachments to respond. Include only what is needed. Support correspondence is retained for as long as needed to handle the request and meet applicable legal obligations.
Your rights
Local data remains until you delete it. Use Settings to export data, change optional choices or delete local app data. Delete shared data and withdraw library contributions before clearing or uninstalling the app: removing it can remove the credentials needed to identify and delete remote records. Offline requests take effect remotely after a successful connection. Backups, exports and household members' copies must be managed separately.
Where the GDPR applies, requested services rely on performing our agreement with you; optional contributions and crash reporting rely on consent; essential security/support processing relies on legitimate interests; and legally required processing relies on the relevant legal obligation. You can withdraw consent without affecting earlier lawful processing. You may request access, correction, deletion, restriction or portability, and object where applicable. Contact support@croat.dev; we may need proportionate verification to locate the relevant records. You may complain to your local supervisory authority, including Croatia's AZOP: https://azop.hr
Changes to data handling will be explained in the app and reflected in the dated policy, with fresh consent where required. Current policy: https://kvitko.croat.dev/privacy/