Privacy Policy

What Avocando collects, where it's kept, who else sees it, and how to delete it.

Effective and last updated October 8, 2026

Avocando is a money tracker. You photograph a receipt, an AI model reads it, and the app records a transaction. This policy explains what that means for your data. Where something is a trade-off, it says so.

Who we are. Avocando is operated by Mysmartliving Inc., 2222 S Sheridan Way #212, Mississauga, Ontario L5J 2M4, Canada. In this policy "we", "us" and "Avocando" mean Mysmartliving Inc. We are responsible for the personal information described here. For anything in this policy, including a request to see or correct your data, write to avocando@workshown.com.

1. The short version

  • We collect the entries you create and the receipt photos you choose to back up. That's nearly all of it.
  • There's no analytics, advertising or tracking code in the app. We don't build a profile of you, and we never sell or rent your data.
  • Receipt photos are sent to Google's Gemini model to be read. Google receives the image and a fixed instruction, nothing else, and doesn't use it to train its models.
  • Receipt photos stay on your iPhone unless you choose cloud backup.
  • Your data is stored on a server in Germany. Section 5 explains what that means.
  • You can export everything, erase everything, or delete your account from inside the app at any time.

2. What we collect

2.1 Your account

How you sign inWhat we receive
GuestA random account identifier. No email, no name, no device identifier.
EmailYour email address. There's no password: we email you a sign-in link or code.
Sign in with AppleAn account identifier and an email address. If you choose Hide My Email, the address is one of Apple's relay addresses and we never see your real one. Apple sends your name once, on your first sign-in; if it arrives we save it as your display name.
GoogleThe email address, name and profile picture address on your Google account.

You can add a sign-in method to a guest account later without starting over.

2.2 What you record

  • Transactions: amount, currency, income or expense, date, merchant, your note, category, and for foreign spending the converted amount and the exchange rate used.
  • Receipts: what was read off the photo (merchant, total, date, currency, a confidence score and the individual line items), and the photo itself if you chose cloud backup.
  • Budgets and recurring entries: the limits, bills and subscriptions you set up.
  • Categories: any you create, and the order you put them in.
  • Household: if you create or join one, its name, your display name and color in it, and whether your new entries are shared by default.
  • Preferences: your base currency and where receipt photos are kept by default.

2.3 Receipt photos

A photo has to reach our server before it can be read, so every scan is uploaded, including ones you throw away. After you save the entry, the photo goes where you chose for that receipt:

  • Don't keep: the photo is deleted from our server. What was read off it stays.
  • This phone (the default): the photo is copied into the app on your iPhone and deleted from our server. It's included in your iPhone's own backup, but it's gone if you delete the app without one, and household members can't see it.
  • Phone + cloud: the photo stays on your iPhone and on our server, until you delete the entry, erase your data or delete your account.

If you leave a scan without saving it, the receipt and its photo are deleted right away. If the app closes before that can happen, a daily job deletes anything unsaved that is more than 24 hours old.

A receipt can show more than a total: a name, a loyalty number, an address, the last digits of a card, or what you bought and where. That's why photos aren't kept on our server unless you ask.

2.4 What we don't collect

We don't collect your location, contacts, calendar, health data, browsing, advertising identifier or anything from other apps. The app uses your camera and photo library only to take or pick a receipt, and it can't read your library in bulk. Reminders are scheduled on your iPhone itself, so we hold no notification token.

2.5 Technical records

Our server keeps ordinary request logs (time, IP address, errors) for a short time to run and protect the service. We also keep a daily count of how many receipts each account scanned, so we can apply a daily limit. That count is deleted after 30 days.

3. Why we collect it

We use your information for these purposes and no others:

PurposeWhat it covers
Running the appStoring and showing your entries, budgets, receipts, household and settings
Reading receiptsSending the photo to the AI model and saving the result
Signing you inAuthentication and keeping you signed in
Converting currencyLooking up the published exchange rate for the date of an entry
Keeping the service up and fairSecurity, abuse prevention and the daily scan limit
Legal obligationsResponding to lawful requests and keeping records the law requires

Consent. Creating an account and using the app is your consent to these purposes. Some are asked for separately: iOS asks before the app can use your camera or photo library, and you choose where each receipt photo is kept. You can withdraw consent at any time by erasing your data or deleting your account (section 8). Without it we can't provide the app, which is why those are the same action.

We don't use your data for advertising, profiling, automated decisions with legal or similar effects, or training AI models.

4. Who else sees it

We use a small number of service providers. Each is listed with what it receives. They handle your information on our behalf and may not use it for their own purposes.

4.1 Our server: netcup (Germany)

Your data is stored on a server we rent from netcup GmbH in Germany. On it we run the open-source Supabase software ourselves: the database, sign-in, photo storage, and the functions that read receipts and delete accounts. Supabase the company doesn't receive your data. Photos are in private storage, in a folder belonging to your account. The database itself checks every request, so a query can only return your own rows and the household rows you're entitled to see.

4.2 Network and website: Cloudflare (United States)

Traffic between the app and our server passes through Cloudflare, Inc., which protects the server from attacks, and Cloudflare hosts this website. Cloudflare sees technical details such as your IP address while it carries the traffic. Cloudflare's privacy policy.

4.3 Reading the receipt: Google Gemini

When you scan a receipt, the image is sent to Google's Gemini API with a fixed instruction to return the merchant, total, date, currency, category and line items.

  • Google receives the image and nothing else. Not your name, email, account identifier or other entries.
  • The image can still identify you, because receipts often carry names, addresses or card digits. We can't remove those without removing what the model needs to read.
  • Your receipts aren't used to train models. We use Gemini as a paid service. Under Google's terms for paid use, Google doesn't use the images or results to improve its products, and keeps requests for a limited time only to detect abuse and meet legal obligations. Gemini API terms.

The model's unedited response is stored for up to two days so a failed scan can be looked into, then emptied automatically. It's never shown in the app.

4.4 Sign-in email: Resend (United States)

Sign-in emails are delivered by Resend. It receives your email address and the message. Resend's privacy policy.

4.5 Exchange rates: Frankfurter

For an entry in another currency we ask frankfurter.dev for the European Central Bank's rate on that date. The request contains a date and two currency codes, and no personal information or amount.

4.6 Signing in with Apple or Google

If you sign in with Apple or Google, they handle the sign-in and tell us the result. We never see your password. Their own policies apply: Apple, Google.

4.7 People in your household

If you join a household, entries you share are visible to every other member, with your display name and color. New entries are shared by default, and you can change that for each entry or in Family settings. Members can also see a shared entry's line items and category, and its photo if it's backed up to the cloud. Recurring bills you share add their entries to the household too. Private entries are visible only to you, and no member can edit or delete your entries.

If you leave a household, the entries you already shared stay in its ledger with your name on them. To remove them, delete them before you leave, or delete your account, which removes them everywhere.

4.8 Everyone else

Nobody. We don't sell, rent or trade your personal information, and we don't share it with advertisers or data brokers. We would disclose it if a valid legal order required it, or to protect someone's safety, and we would tell you unless the law forbade it. If Mysmartliving Inc. is ever sold or merged, your data may transfer to the buyer. We would tell you first, and this policy would keep applying until you were given a new one.

5. Where your data is stored

We're a Canadian company, and your information is stored and processed in Germany, on the server described in 4.1. Cloudflare, Google and Resend may process it in the United States and other countries where they operate.

  • While your information is in another country, the laws of that country apply to it, including lawful access by its courts, police and security agencies. That can happen without notice to you or to us.
  • We remain responsible for your information wherever it's held, and we choose providers that protect it to a comparable standard.
  • If you'd rather your information weren't processed abroad, the only complete remedy is not to use the app, and to delete your account if you have one.

If you're in Quebec, this section is how we tell you, before it happens, that your information is processed outside the province.

Avocando isn't offered in the European Economic Area, the United Kingdom or Switzerland.

6. How long we keep it

DataKept for
Receipt photo on our server, "Don't keep" or "This phone"Deleted when you save the entry
Receipt photo, "Phone + cloud"Until you delete the entry, erase your data or delete your account
Receipt photo on your iPhoneUntil you delete the entry or the app
A scan you didn't saveDeleted right away, or within 24 hours
The model's raw response2 days
Daily scan counts30 days
Entries, budgets, categories, recurring bills, profileUntil you delete them or your account
Entries you shared, after you leave a householdUntil you delete them or your account
Server request logsA short time
Records of a security breach24 months, as Canadian law requires

We keep backups of our server so we can recover from a failure. Something you delete disappears from those backups as they're replaced. We never restore deleted data from them, except to recover the whole service.

7. Security

  • Everything travels encrypted (TLS).
  • Receipt photos on our server are private. The app opens them through links that expire after an hour, and no photo has a public address.
  • Access rules are enforced by the database itself, not only by the app, so a bug in the app can't return somebody else's rows.
  • There's no password to steal: email sign-in uses a one-time link or code, and Apple and Google keep their own credentials.
  • The server accepts administrator logins by key only, behind a firewall.

No system is perfectly secure, and we won't pretend otherwise.

If there's a breach that creates a real risk of significant harm to you, we'll report it to the Office of the Privacy Commissioner of Canada and tell you as soon as we can, as Canadian law requires. We keep a record of every breach for 24 months. Where Quebec's Law 25 applies, we'll also notify the Commission d'accès à l'information.

8. Your choices and rights

In the app

  • Keep receipt photos: a default in Settings, and a choice on each receipt.
  • Export to spreadsheet (Settings, Your data): a copy of all your entries as a CSV file, made on your phone.
  • Erase all my data (Settings, Delete data): removes every entry, receipt, category and budget, and the photos on our server and on this phone. Your account stays.
  • Delete my account (Settings, Delete data): all of the above, plus the account. You're signed out everywhere.
  • Leave a household: stops sharing. See 4.7 for what happens to what you already shared.

On request

You have the right to see the personal information we hold about you, to be told how it was used and who received it, and to have it corrected. Write to avocando@workshown.com and we'll reply within 30 days, free of charge. Depending on where you live you may also have rights to receive your data in a portable format, to object to or restrict some uses, to withdraw consent, and to have information erased. The controls above already do most of this immediately. Making a request will never make the app worse for you.

Complaints

Please tell us first. If we don't resolve it, you can complain to:

9. If you are in California

We don't sell or share personal information as the CCPA and CPRA define those terms, and we haven't in the past twelve months. We don't use it for cross-context behavioral advertising, and there's no financial incentive program. You have the rights to know, delete, correct and not be discriminated against. The in-app controls in section 8 delete immediately, and avocando@workshown.com covers the rest.

10. Children

Avocando isn't meant for children. You must be at least 13 to use it, and in Quebec we won't collect information from anyone under 14 without a parent's or guardian's consent. We don't knowingly collect information from anyone younger. If you think a child has created an account, write to avocando@workshown.com and we'll delete it.

11. Email we send

Avocando only sends the sign-in emails you ask for. We don't send marketing email, and we won't start without asking you first and giving you a way to unsubscribe in every message, as Canada's anti-spam law requires.

12. Changes to this policy

If we change something that matters, we'll update the date at the top, and for a significant change we'll tell you in the app before it takes effect. Changing which AI service reads your receipts, or which country your data is stored in, counts as significant.

13. Contact

Mysmartliving Inc.
2222 S Sheridan Way #212
Mississauga, Ontario L5J 2M4
Canada
avocando@workshown.com