This policy applies to the kvit. Android app (also called Kvit), package com.croat.dev.kvit, and its privacy website. The operator and data controller is Biocal d.o.o., using the developer brand croat.dev. Privacy contact: support@croat.dev.
Kvit scans receipts and tracks spending without a Kvit account. Normal receipt recognition and categorisation use the OCR engine, rules and saved corrections on your phone. The sharing, backup and experimental features below are separate choices; online features also require an available service.
What stays on your phone
Receipt photos, recognised text, store names and addresses, tax identifiers printed on receipts, purchase dates, items, quantities, prices, discounts and totals are processed to build editable receipts and spending summaries. Photos and receipts can also contain personal information printed by the merchant.
Your receipts, original photos, detailed OCR evidence, products, categories, budgets, profile display name, preferences and correction history are stored in Kvit's private storage on your phone. Android cloud backup is disabled. The receipt database and private files are excluded from Android device transfer; some device-transfer tools may still transfer app preferences. Saving may send the limited information described below if you enable regional knowledge sharing or join a household. Settings offers CSV/JSON export and deletion of local app data.
Camera and photos
Camera permission is used when you take receipt photos. Imported images are selected through Android's picker. Text recognition and fiscal QR decoding run on your phone; Kvit does not upload receipts for cloud OCR. Photo date metadata may suggest a date for you to confirm. Kvit does not request GPS/location, contacts, microphone, SMS or call-log permissions. Store locations come from receipts or your edits, and your initial country comes from the device's region setting.
Regional rules and updates
Kvit sorts items and recognises stores with rules for each country, built into the app. It reads the store's name, address and public tax number printed on the receipt to fill the location and country; this happens on your phone. When an update service is available, Kvit downloads signed rule updates at most once a day for your home country and the countries your receipts come from. Requests reveal the packs requested and normal connection information, including your IP address, to the service. They do not include photos or receipt item lists. You can turn automatic updates off in Settings.
Regional knowledge sharing (optional, off by default)
With your permission, Kvit sends, for each country: the words of items whose category you chose yourself, that category, and the public tax number, chain identifier and name of stores on your saved receipts. Amounts, dates, photos and other items are not sent. Contributions are stored under a pseudonymous identifier derived from your phone's anonymous sharing key and kept separately per country. A word or store becomes part of the published rules only when at least three people agree. Contributions are kept for up to 730 days. Turning the option off requests their deletion when the service is reachable. Published rules omit contributor identifiers; deletion does not recall already distributed rules.
Experimental model in Settings
The current app still includes an optional Gemini Nano feature under Settings → Experimental. It is off by default and is not used for normal receipt recognition. Enabling it allows additional category and product suggestions to run on supported phones. Checking model availability or downloading the model also uses Google components. Kvit does not upload receipt text or images for cloud generation.
The included Google ML Kit SDK and AICore service can process technical diagnostics when initialised or used: device and app information, identifiers, configured language, feature use, input/output sizes, performance and errors. Turning off model suggestions does not control all Google SDK diagnostics. These are separate from Kvit's crash-reporting option. Details: https://developers.google.com/ml-kit/android-data-disclosure and https://policies.google.com/privacy
Anonymous sharing key
Kvit has no accounts and no sign-in. When you enable regional knowledge sharing and the service is reachable, it gives this phone a sharing key: a random number and a secret, of which the service keeps only a hashed form. The key carries no name, e-mail address or phone number. Under it the service stores your privacy choices with the policy version and time of each decision, and when the key was created and last used. In Settings, Shared data, you can see everything shared under the key and delete it; deleting removes your regional knowledge contributions, privacy records and the key itself. The key and consent records otherwise remain until deleted. Household sync and the corrections library use separate credentials and deletion controls. The Kvit application service does not keep routine per-request access logs; hosting and network providers may process operational metadata as described below.
Households (optional)
If you start or join a household, receipts you save from then on, their products, member display names and payer information, and a small grey reading copy of each photo are shared with its members. Receipts saved earlier are shared only if you choose to. They are encrypted on your phone with a key only the members' phones hold; the Kvit service stores and forwards them without being able to read them, and keeps them for up to 90 days. The relay also processes random household/sender identifiers, hashed access credentials, record sizes, timestamps and temporary invitation/public-key information. Invitation records expire after 30 minutes or are removed when used. Names inside the encrypted content are visible to household members. Reading copies can reveal everything visible on a receipt. Original-resolution photos and detailed OCR evidence are not included in household sync. A new member joins only with a one-time invitation and an approval on a member's phone. Anyone who leaves or is removed keeps what they already received but gets nothing new: the others move to a new key. A household unused for a year is removed from the service. Members can retain copies they already received or exported. Leaving a household or deleting local app data cannot erase another member's copies. Household deletion and sync changes require a working connection.
Backups (optional)
Kvit can write an encrypted backup file to a place you choose, such as Google Drive or another app, when you ask or on a schedule. It is encrypted on your phone using a key derived from your backup passphrase. We do not receive or recover that passphrase. For scheduled backups, the derived key is protected on your device with Android Keystore. If you connect Google Drive, backups go to Kvit's hidden app-data folder in your Drive, and Kvit's permission covers only that folder. The selected Google account address and access token are used on your device to manage backups and are not sent to Kvit's service. Google receives the encrypted file and normal account/file/connection metadata under its privacy policy: https://policies.google.com/privacy
After a successful, verified upload, Kvit keeps the three newest backups in its hidden Google Drive folder and removes older ones. Backups saved to another destination remain until you delete or replace them. Disconnecting Drive, clearing app data or uninstalling does not automatically delete existing backups. CSV/JSON exports are not encrypted by Kvit. The app, service or person you choose receives the exported content and applies its own data handling practices.
Shared corrections (optional, off by default)
If you connect to a shared corrections library and choose to send corrections, the selected original/corrected store or item names, merchant context, small image crops, source/revision hashes and contribution identifiers are sent to the library operator for human review. Crops may contain other visible information: check the preview before sending. You preview every item before sending and can withdraw it. Unreviewed examples are kept for up to 90 days and approved ones for up to 365 days from submission. Approved text rules may be distributed to other users; source images are not part of those rule downloads. Withdrawal removes examples and their rules from subsequent releases; previously downloaded packages expire within seven days. Minimal identifiers, hashes, status and review/withdrawal records remain to prevent cancelled submissions from reappearing and maintain review history while the library operates. A separately operated library may have its own privacy terms.
Crash reports (optional)
If Kvit closes unexpectedly, the error report stays on your phone. It is sent without a Kvit account identifier, and only if you allow crash reports or approve that one report. It contains app/Android versions, device manufacturer/model, thread name and technical exception details. Kvit does not attach photos or the receipt database; exception messages can contain values involved in an error. Reports are used to diagnose faults, sent without a Kvit sharing key or account identifier, and kept for up to 90 days. Normal connection metadata is still processed. An email address alone may not identify a report. The local report remains until sent, discarded, replaced by a newer report or removed with app data.
Notifications (optional)
Evening receipt reminders are scheduled on your phone. Whether you added a receipt today stays on your phone. Android notification permission is required, and reminders and announcements have separate off switches in Settings.
If announcements are enabled and notification permission is granted, a configured release uses Google Firebase Cloud Messaging to deliver an announcement identifier. Google processes an app installation identifier, a delivery token and connection/device information for this delivery. Kvit sends no receipt photos, items, amounts, shopping history or profile name to Firebase. Announcement text is downloaded from Kvit's service; this request exposes your IP address as with other internet requests. Firebase Analytics, advertising measurement and delivery export to BigQuery are not enabled. Disabling announcements stops subscription/delivery and requests deletion of the delivery token when online. This does not delete the separate Firebase installation identifier or Google's existing service records. While announcements are enabled, opening the app can also refresh the public announcement feed even without Android notification permission. This request uses normal connection metadata; it does not send receipt content, a sharing key or the Firebase delivery token. Read/dismissed announcement identifiers stay on the phone. Google's retention and processing are described at https://firebase.google.com/support/privacy
What Kvit does not do
Kvit has no advertising SDKs, does not sell personal data and does not use advertising identifiers or cross-app tracking. Google SDK diagnostics are described above.
Recipients, security and this website
Data is handled by the Kvit operator and authorised support/review personnel; infrastructure and hosting providers that operate the servers; Google for the services described above; approved household members; and backup/export destinations you choose. We may disclose information where required by law.
Online service connections use HTTPS. Household content and backup files receive the additional encryption described above. Local app storage uses Android's app isolation and device protections. No storage or transmission method can guarantee absolute security. Connections reveal network information such as IP addresses to the service and its infrastructure, for delivery, operation and abuse prevention.
The Kvit landing page and privacy pages use no cookies, analytics scripts or remotely hosted fonts. Routine website access logging is disabled. Hosting and network providers may process operational/security metadata under their own policies. Google services may process data outside your country, including outside the European Economic Area, under their applicable data-protection terms: https://firebase.google.com/terms/data-processing-terms and https://policies.google.com/privacy
If you email support@croat.dev, we and our email provider process your address, message and attachments to respond. Include only what is needed. Support correspondence is retained for as long as needed to handle the request and meet applicable legal obligations.
Your rights
Local data remains until you delete it. Use Settings to export data, change optional choices or delete local app data. Delete shared data and withdraw library contributions before clearing or uninstalling the app: removing it can remove the credentials needed to identify and delete remote records. Offline requests take effect remotely after a successful connection. Backups, exports and household members' copies must be managed separately.
Where the GDPR applies, requested services rely on performing our agreement with you; optional contributions and crash reporting rely on consent; essential security/support processing relies on legitimate interests; and legally required processing relies on the relevant legal obligation. You can withdraw consent without affecting earlier lawful processing. You may request access, correction, deletion, restriction or portability, and object where applicable. Contact support@croat.dev; we may need proportionate verification to locate the relevant records. You may complain to your local supervisory authority, including Croatia's AZOP: https://azop.hr
Changes to data handling will be explained in the app and reflected in the dated policy, with fresh consent where required. Current policy: https://kvit.croat.dev/privacy/