DealKeeper Privacy Policy
Effective date: 11 October 2026
DealKeeper helps you keep track of free trials and promotional prices, and reminds you before they turn into full-price charges. This policy explains what information the app handles, why, who else is involved, and the choices you have. We've tried to keep it short and plain. If anything is unclear, write to us (see Contact at the end).
1. Who is responsible
DealKeeper is developed and operated by Ron Shmelkin, an individual developer based in the United Kingdom ("we", "us"). We are the controller of the personal information described here.
Privacy contact: privacy@dealkeeper.app
2. The short version
- You can use DealKeeper without an account. Your subscriptions and settings then stay on your phone and are not sent to us.
- If you scan a receipt, invoice or contract, the image or PDF is sent to our server and to Google's Gemini AI service to read the details, and our copy is deleted right after, whether the scan succeeds or not. We keep the details it found, with a coded fingerprint of the file (never the file itself), for 30 days, so that scanning the same file again doesn't send it to Gemini again.
- If you create an account, we store your email address, your subscriptions and your reminder settings on our servers (hosted in Ireland, EU), so they sync across your devices and so we can send email and push reminders.
- Ads come from Google AdMob. We ask for your consent where the law requires it, and we request non-personalised ads only. We don't use Apple's advertising identifier (IDFA).
- We don't sell your personal information, and we don't share it for cross-context behavioural advertising.
- We don't collect your location, contacts, photos library, microphone or health data, and the app does not read your email.
3. What we collect, why, and our legal basis
3.1 Using the app without an account (guest mode)
Everything you enter (service names, plan names, prices, currencies, dates, billing cycles, categories, notes you type) and your settings (language, theme, reminder days and time) is stored only on your device. Reminders are scheduled by your phone's own notification system. We don't receive this information.
A copy of any photo or PDF you scan is kept on your device so you can refer back to it, and is deleted with the subscription it belongs to. A scan you don't save as a subscription is deleted the next time the app starts.
3.2 Scanning a receipt, invoice or contract
When you choose Take photo, Choose from gallery or Choose a file:
- The file is uploaded to a private storage area on our server (Supabase). Nobody but our scanning function can read it.
- Our scanning function sends the file, with fixed instructions, to Google's Gemini API, which returns the details it finds (service name, prices, currency, dates, billing cycle, what the subscription is for, and the plan name).
- Our copy of the file is deleted immediately afterwards, whether the scan succeeded or failed. Our server logs record that the deletion happened, not the file's contents.
- We keep the details Gemini found for 30 days, together with a fingerprint of the file: a code worked out from the file and a secret key of ours, from which the file can't be rebuilt, and which can't be matched to a document without that key. If you scan exactly the same file again in that time, our scanning function recognises it and gives you the same details straight away, without sending the file to Gemini (it still counts toward your scan limit, and the uploaded copy is still deleted at once). A new photo of the same paper is a different file, and is read afresh. The details and fingerprint are deleted after 30 days, or sooner with your account or scan identifier (see 6 and 7).
- The details are shown to you to check and edit before anything is saved.
If you scan without an account, the app first creates a scan identifier for your phone on our server (Supabase), and reuses it for your later scans. It is a random ID, like the ones our sign-in service gives any user, and holds no email, name or subscription data; it isn't used for anything else in the app, and it isn't linked to an account you create later. It is there so we can limit how many scans each phone runs, and keep the free scanning service from being abused. While you use the app without an account, the app also tells our server, at most once a day, that the scan identifier is still in use, so that we know when it no longer is (see 6). If you're signed in, your scans use your account instead.
Checking that a scan comes from the genuine app. So that other programs can't use our scanning service, each scan request proves it comes from the real DealKeeper app on a genuine device. On an iPhone this uses Apple's App Attest: the app creates a key that stays on your phone, Apple vouches for it once, and our server keeps the key's public half and a counter with your account or scan identifier. On Android it uses Google Play Integrity: Google tells our server whether the request came from DealKeeper as installed from Google Play, on a device that passes Google's integrity checks. Neither involves your name, email or the document itself; Apple and Google handle the device information involved under their own terms. A scan that can't be checked is refused, and you can enter the details yourself instead.
Documents can contain personal details (for example your name, address or account number), so only scan what you're comfortable sharing, and crop out anything unnecessary. We use Gemini's paid service, under whose terms Google does not use your files or results to improve its products; Google may keep them for a limited time solely to detect and prevent abuse.
Legal basis: performing the service you asked for (contract). Keeping a scan's details for 30 days: our legitimate interest in answering a repeated scan quickly and keeping the free scanning service affordable.
3.3 Creating and using an account
If you sign up with email, Sign in with Google or Sign in with Apple, we store:
- Your email address and sign-in identifiers. With Google we receive your email; Google also sends your name and profile photo, and our server removes them as you sign in, so they are never stored. With Apple we ask for your email only (which may be an Apple private-relay address). We don't store your name or photo.
- Your subscriptions (as in 3.1, including notes) and their reminder schedule.
- Your settings: language, reminder days and hour, your device's time zone (so reminders arrive at your local time), and which reminder channels you've turned on.
- Push notification token, if you allow notifications, so we can send reminders to your phone.
- An alternative email address for reminders, if you add one.
- Whether you've bought ad-free (not your payment details).
- Your referral code, and, if you joined through someone's invite link, a link to the account that invited you (see 3.8).
- Your marketing-email choice and when you made it (see 3.6).
When you create an account after using guest mode, the subscriptions and reminder settings on that phone are copied into your account.
Legal basis: performing our contract with you; for the time zone, our legitimate interest in delivering reminders at the right time.
3.4 Reminders
- Push reminders are delivered through Expo's push service and Apple Push Notification service / Google Firebase Cloud Messaging. A reminder's text includes the subscription's name (with its plan name, or what it is for, such as "Internet") and price.
- Email reminders (accounts only) are sent through our email provider, Resend. They include the subscription's name (with its plan name, or what it is for), prices and dates, and every email has a one-click unsubscribe link.
You can turn each reminder channel on or off in Settings → Reminders, and turn off notifications in your phone's settings at any time.
Legal basis: contract; your device permission for notifications.
3.5 Advertising
Unless you've bought ad-free, DealKeeper shows ads from Google AdMob (a banner, a full-screen ad when you open the app, and an ad on the screen that shows while a document you added is being read).
- Where required (for example in the EEA, the UK and Switzerland, and certain US states), we ask for your choice through Google's consent message before any ad is requested, and you can change it later in Settings → Manage ad privacy choices.
- We request non-personalised ads only. Google may still use limited information, such as your device's IP address, device type and app interactions, to show the ad, limit how often you see it, measure it, and prevent fraud.
- We don't ask to track you across apps (no App Tracking Transparency prompt) and don't read your advertising identifier.
- Reward ad for more scans: when you've used the day's scans, you can choose to watch an ad for more. To credit them, the app gives Google your account's or scan identifier's random ID with that ad, and Google sends it back to our server with a signed confirmation. It is not your email or name. This choice is offered with ad-free too, because you choose to watch it.
See how Google uses information from apps that use its services: https://policies.google.com/technologies/partner-sites">https://policies.google.com/technologies/partner-sites
Legal basis: your consent where required; otherwise our legitimate interest in funding the free app.
3.6 Marketing emails (optional)
When creating an account you can tick "Send me tips and offers by email". It is off by default, and you can change it any time in Settings. We record your choice and when you made it. Unsubscribing never affects your reminders.
Legal basis: your consent.
3.7 In-app purchase (ad-free)
Purchases are processed by Apple (App Store) or Google (Google Play) under their own terms and privacy policies. We never see your payment details; we only record that ad-free is active on your device and, if you have an account, on your account.
3.8 Invite links
Each account has a short invite code. If someone joins through your link, we record that link between the two accounts. Neither of you can see the other's identity; you see only how many people joined. If you share your savings image, it shows your invite code and the names of services you cancelled; you choose where to share it.
3.9 Service logos
To show a service's logo, the app fetches the image from a third-party logo service (currently Clearbit, owned by HubSpot). That service receives your device's IP address and the website of the service whose logo is shown, as with loading any web image.
3.10 Crash reports and usage statistics
To fix bugs and improve the app, we may use:
- Sentry for crash and error reports: technical details about the error and your device and app version. We configure it not to collect personal data such as your email or IP-based identity, and we don't attach your account to reports.
- PostHog for anonymous usage statistics: a small set of events (for example "subscription added" with the billing cycle, "language changed"). Events carry a random identifier, are not linked to your account or email, and contain no names, prices, notes or email addresses.
Legal basis: our legitimate interest in keeping the app reliable and improving it. You can turn both off at any time in Settings → Privacy ("Share anonymous usage & crash reports"); they are also off in a browser that sends Do Not Track.
3.11 Device permissions
- Camera: asked only when you tap Take photo, used only to capture the document you're scanning.
- Photos: Choose from gallery uses the system photo picker, which shares only the photo you pick; we don't get access to your library. Saving your savings image to Photos uses add-only permission.
- Notifications: for reminders.
- Calendar: asked only when you choose to add your promo deadlines to your calendar (during setup or in Settings → Reminders). DealKeeper creates its own "DealKeeper" calendar in the calendar account you pick (for example iCloud, which then syncs it under its own terms) and writes your promo end dates, with their alerts, to it. Where the account doesn't let apps add a calendar (Google and Outlook accounts on an iPhone usually don't), DealKeeper instead writes those events into a calendar you already have in that account and pick, which the account then syncs under its own terms. It lists your calendar accounts, and that account's calendars, so you can pick one, but doesn't read your own events or change them. Turning it off deletes the DealKeeper calendar (or, in a calendar you picked, only the events DealKeeper added), and so do signing out and deleting your account. Uninstalling DealKeeper does not: the calendar and its events belong to your calendar account, so delete them in your calendar app if you no longer want them.
4. Who we share information with
We share information only with service providers that help us run DealKeeper, under contracts that limit their use of it to providing their service to us (the providers of the ad and purchase services act under their own terms as described above):
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, sign-in, file storage, server functions | Ireland (EU) |
| Google (Gemini API) | Reading scanned documents | Global (Google infrastructure) |
| Google (AdMob) | Ads and consent messages | Global |
| Expo; Apple; Google (FCM) | Delivering push notifications | United States / global |
| Resend | Sending reminder emails | United States |
| Sentry | Crash and error reports | United States |
| PostHog | Anonymous usage statistics | United States |
| Clearbit (HubSpot) | Service logos | United States |
| Apple; Google | Sign-in, app stores, in-app purchase | Global |
| Apple (App Attest); Google (Play Integrity) | Checking that scans come from the genuine app | Global |
We may also disclose information if the law requires it, to protect people's safety or our rights, or as part of a transfer of the app to a new owner (who would remain bound by this policy).
We do not sell personal information and do not "share" it for cross-context behavioural advertising (as those terms are used in US state privacy laws).
5. International transfers
We are based in the UK, and our main database is in the EU (Ireland); the UK and the EU recognise each other's data protection as adequate. Some providers above process data in the United States or elsewhere. Where personal data is transferred to a country without an adequacy decision, we rely on the provider's safeguards, such as the Standard Contractual Clauses (with the UK Addendum), or the EU-US Data Privacy Framework and its UK Extension where the provider participates in them.
6. How long we keep information
- Scanned files on our server: deleted immediately after the scan.
- Scan results (see 3.2): the details read from a scanned file, and a fingerprint of the file (never the file), kept on our server for 30 days so that the same file scanned again isn't sent to Gemini again, then deleted. They're deleted sooner with the account or scan identifier they belong to.
- Scan identifiers (guests who scan, see 3.2): kept on our server, so a phone's later scans count toward the same limit, together with the last day the app was used with it. They hold no email, name or subscription data. A scan identifier is deleted after 13 months without the app being used (no scan, and the app not opened), together with its scan counts and scan results. Nothing on your phone is affected: if you scan again later, the app simply creates a new one. You can also delete it yourself at any time, with Settings → Privacy → Delete my data (see 7).
- App Attest keys (iPhone, see 3.2): the public half of the key and its counter, kept on our server with the account or scan identifier and deleted with it.
- Scan counts: how many scans each account or scan identifier made on each day, and any extra scans earned that day by watching an ad (with the ad's transaction number from Google), kept on our server for the current month so we can apply the scan limits, and deleted with the account or identifier.
- Account data (email, subscriptions, settings, reminders): kept while your account exists. When your account is deleted, this data is deleted from our database; residual copies in backups and logs expire within our providers' standard retention periods (typically no more than 30 days).
- Guest data and scanned copies on your phone: stay on your device until you delete them or uninstall the app. Deleting a subscription also deletes its scanned copy. Signing out of an account removes that account's subscriptions, scanned copies, scheduled reminders and DealKeeper calendar (or DealKeeper's events in a calendar you picked) from the phone, and so does deleting your account from the app. After signing out, your subscriptions are still in your account and come back when you sign in again; scanned copies were only ever on the phone, so they are gone. Without an account, Settings → Privacy → Delete my data removes the same from the phone. Uninstalling removes everything except the DealKeeper calendar and its events, which live in your calendar account (see Calendar above).
- Marketing consent records: kept while your account exists, to show when you agreed or declined.
- Crash reports and usage statistics: kept for up to 90 days.
7. Your rights and choices
In the app, at any time:
- Edit or delete any subscription.
- Turn push, email or calendar reminders on or off (Settings → Reminders).
- Change your marketing-email choice (Settings).
- Change your ad privacy choices (Settings → Manage ad privacy choices, where offered).
- Turn anonymous usage statistics and crash reports off (Settings → Privacy).
- Use DealKeeper without an account, so your data stays on your phone.
Delete your data without an account: in the app, go to Settings → Privacy → Delete my data. This deletes your subscriptions, reminders, scanned copies and DealKeeper calendar from the phone and, if you've scanned, your scan identifier from our server straight away, together with its scan counts, scan results and App Attest key (see 6). It can't be undone. Your settings (language, theme) and an ad-free upgrade bought on the phone stay.
Delete your account: in the app, go to Settings → Account → Delete account. This deletes your account and every subscription, reminder, setting and scan result stored with it from our database straight away, and removes that account's data from the phone. It can't be undone. If you bought the ad-free upgrade, the purchase belongs to your App Store or Google Play account, not to DealKeeper, and "Restore purchase" brings it back. If you can't sign in any more, email privacy@dealkeeper.app from the address linked to your account and we'll delete it for you within 30 days.
Depending on where you live, you may also have the right to access your data, correct it, delete it, receive a copy in a portable format, object to or restrict certain processing, and withdraw consent at any time (without affecting processing before the withdrawal). This includes rights under the EU and UK GDPR, Israel's Privacy Protection Law, and US state privacy laws (such as California's CCPA/CPRA). To exercise any right, email privacy@dealkeeper.app from the address linked to your account. We'll respond within one month (or the period your law requires), and we won't treat you differently for exercising your rights. We may need to confirm your identity first.
If you're unhappy with how we handle your data, please contact us first. You also have the right to complain to a data protection authority: our lead regulator is the UK Information Commissioner's Office (ico.org.uk); if you live in the EU, you can also complain to the authority in your country, and in Israel to the Privacy Protection Authority.
8. Children
DealKeeper is not intended for anyone under 16, and we don't knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we'll delete it.
9. Security
Data is encrypted in transit (HTTPS). On our servers, each account's data is protected by access rules so that only that account can read it, and scanned files can be read only by our scanning function. No system is perfectly secure, but we work to protect your information and keep what we store to a minimum.
10. Changes to this policy
If we change this policy, we'll update the effective date above. If a change is significant, we'll tell you in the app or by email before it takes effect.
11. Contact
Ron Shmelkin, United Kingdom Email: privacy@dealkeeper.app