PRIVACY POLICY
What Accntr does with your receipts
Accntr holds photographs of your receipts and the numbers read out of them. This page says what we collect, who else touches it, where it is stored, and what you can ask us to do with it.
Plainly: this policy was written by the people who built Accntr, not by a lawyer, and it has had no legal review. It is an honest description of how the system actually works, not legal advice.
Where something is not built yet or not decided, it says so instead of promising it.
Who is responsible
The controller of your personal data is DEV2REV, a company established in Portugal and operated by Hugo Almeida. Everything on this page is our responsibility, and every request under it goes to one address:
We have not appointed a Data Protection Officer. We are a very small operation and are not required to have one.
TODO
The company registration number and registered postal address still have to be published here before Accntr opens to the public. We are not going to invent them on a page like this one.
What we hold
Accntr has two kinds of account. An Owner scans receipts. An Accountant is given access to an Owner's receipts by that Owner. Both accounts hold roughly the same profile data.
- Account: your email address, your name, the role you chose, your language, and — if you signed up with a password — a hash of it, never the password itself.
- Social sign-in: if you sign in with Google, Microsoft or Apple, we receive an identity token from them containing a subject identifier, your email address and your name. We ask for nothing else and we never see your password there.
- Receipts: the photograph you took, and the fields read out of it — merchant, date, total, tax, line items and a suggested category. These are financial records about you, your household or your business.
- Classification: the personal category you set yourself, plus the ledger account and notes an accountant writes once you have linked one.
- Links between accounts: who invited whom, whether the invite was accepted, and when either side revoked it.
- Billing: a Stripe customer identifier and your subscription status. Card numbers never reach our server.
- Operational logs: our server writes ordinary application logs, which can include an IP address, a timestamp and the path of a request. There are no advertising or analytics trackers in the app, in the portal or on this site.
Reading your receipt: Anthropic
When you scan a receipt, the image is sent to Anthropic's API, which reads it and returns the fields above. A copy of your receipt image therefore leaves our server and is processed by Anthropic on our behalf. This is the single most important disclosure on this page, which is why it has its own section.
Anthropic is established in the United States, so this is a transfer outside the EU. It rests on Anthropic's own commercial data-processing terms and the transfer safeguards in them. We send the receipt image and the instruction to read it, and nothing else about you — not your name, not your email, not your other receipts.
We do not control what Anthropic does with API traffic on their side. Their own terms and privacy documentation are the authority on that, and you should read them rather than take our summary for it.
The extraction is automated, but it is not a decision that affects your rights: nothing is approved, refused or scored. It suggests values and you can change every one of them.
Where your data lives
Receipt images are stored as attachments in a RavenDB database running on a server we rent from Hetzner in Nuremberg, Germany. The extracted fields, your categories and your account sit in the same database, next to the image.
Images are re-encoded to WebP when they arrive, which makes them much smaller. What we keep is that re-encoded copy — the original file from your camera is not retained as a second copy.
Apart from the extraction call to Anthropic and the payment data that goes to Stripe, your data stays on that German server.
What an accountant can see
Nothing is shared until you share it. An Owner invites an accountant by email, or hands them a single-use pairing code, and the link becomes active only once the other side accepts it.
While a link is active, that accountant can read your receipts, including the images, and can write a fiscal classification and notes on them. They cannot change your amounts, they cannot edit your own personal category, and they cannot delete or alter the original scan.
Either side can revoke the link whenever they want, and access stops from that moment. Notes and classifications already written stay on your receipts, because they are part of the record.
An accountant may export a period as a ZIP of receipt images for their own bookkeeping. Once they have done that, that copy is in their hands, on their equipment, and outside anything we can reach or delete. An accountant using Accntr for their clients is a controller of that data in their own right, for their own professional purposes.
Everyone else who processes it
This is the complete list of third parties that touch your data. We do not sell personal data and we do not give it to advertisers or data brokers.
Reads your receipt images and returns the extracted fields.
UNITED STATESHosts the server and the database where receipts and accounts are stored.
GERMANY · NBG1Takes the payment and runs the subscription. Card details go to Stripe, never to us.
EU · UNITED STATESOnly if you choose to sign in with one of them. They learn that you signed in to Accntr, and they tell us who you are.
UNITED STATESOur lawful basis
- Performing our contract with you, Article 6(1)(b): running your account, storing and showing your receipts, reading them, honouring the accountant links you created, and managing your subscription.
- Complying with a legal obligation, Article 6(1)(c): keeping billing and invoice records for as long as tax law requires us to.
- Our legitimate interests, Article 6(1)(f): keeping the service secure and debuggable, which is what the operational logs are for.
We rely on consent for nothing at the moment, and we send no marketing email. If that ever changes, we will ask you first rather than quietly re-reading this page as permission.
How long we keep it
Today, your receipts and your account data stay for as long as your account exists, and until you ask us to delete them. Receipts are records you keep on purpose, so we do not expire them behind your back.
TODO
There is no fixed retention schedule yet: no set period for a closed account, and none for operational logs. Both have to be decided and published before public launch. We would rather admit that than print a number we do not actually enforce.
Deleting your data
There is no self-service delete button yet. This is a known gap, and we are stating it rather than describing a mechanism that does not exist.
Deletion today is by request. Email us from the address on the account and we will delete the account, its receipts and the stored images. A person does this by hand, so it is not instant; the law gives us up to one month, and we will confirm when it is done.
Two honest limits. Billing and invoice records that tax law obliges us to keep are not deleted — those are invoices, not receipt images. And if an accountant has already exported a ZIP of your receipts, that copy is theirs to delete, not ours; ask them directly.
Your rights
Under the GDPR you can ask us for any of the following, free of charge:
- Access — a copy of what we hold about you.
- Rectification — correction of anything wrong, including a misread receipt field.
- Erasure — deletion, as described in the section above.
- Restriction — that we hold your data but stop doing things with it while something is disputed.
- Portability — your data in a machine-readable form, so you can take it elsewhere.
- Objection — to any processing we base on legitimate interests.
Write to the address in section 01. We may have to check that you are who you say you are before acting on a request about an account, because doing otherwise would be the bigger privacy failure.
If you think we have handled your data badly, you can complain to the Portuguese supervisory authority, the Comissão Nacional de Proteção de Dados (CNPD), or to the authority in the country where you live.
Security, and what we do not claim
What is true: traffic between the app or the web portal and our server goes over HTTPS. Passwords are stored as hashes. Every request for a receipt is authorised on the server against your account and the accountant links that were actually accepted, so one account cannot read another's data by asking nicely.
What we do not claim: no security certification, no external audit, no penetration test, and no end-to-end encryption. Receipt images are stored so that our server can read them — that is precisely what makes extraction, the portal and the ZIP export possible. We also make no claim about encryption at rest for the database volume.
If you find a security problem, email us. We would much rather hear it from you.
Children
Accntr is a tool for adults keeping business or household expenses. We do not knowingly create accounts for anyone under 16, and we have no service aimed at children.
Cookies and local storage
This site stores exactly one thing in your browser: the language you picked, so it is still picked next time. There is no cookie banner because there is nothing here that would need one.
The web portal keeps what it needs to hold your session open. The Android app stores a session token on the device so you stay signed in, and biometric unlock — if you turn it on — gates the app behind your fingerprint or face. None of this is used for tracking.
Changes to this policy
When this policy changes we change the date at the top. For anything that materially affects you — a new sub-processor, a new purpose, a real retention schedule replacing the TODO above — we will tell you in the app or by email rather than editing quietly.
Contact
Data requests, questions, corrections and complaints all go to the same place: