Sumlo

Privacy Policy — Sumlo

Effective date: 2026-10-10

This Privacy Policy explains how Sumlo ("we", "us", "our") collects, uses, and shares information when you use our mobile application. Please read it to understand how your data is handled.


1. Who we are

Sumlo is operated as an independent service. For privacy questions, contact support@sumlo.app.

2. Information we collect

2.1 Information you give us

2.2 Information we generate

2.3 Information we do NOT collect

3. How we use information

4. Legal basis (GDPR)

Purpose Legal basis
Operating the app Contract — Art. 6(1)(b)
Receipt scanning with AI Consent — Art. 6(1)(a); asked the first time you scan a receipt
Account deletion / regulatory Legal obligation — Art. 6(1)(c)

5. Sub-processors

We share information with the following processors:

Processor Purpose Region Notes
Supabase Authentication, database, file storage, server-side functions Switzerland (Zurich) Standard DPA
RevenueCat Subscription management US Standard DPA
Anthropic Reading receipt photos (only when you scan one, after agreeing) US Anthropic Commercial Terms
Resend Sending account emails: sign-up codes, password resets, email-change confirmations Sent from the EU (Ireland); account data and logs in the US Resend DPA (EU–US Data Privacy Framework)
Cloudflare Our domain and website, and forwarding messages you send to support@sumlo.app Global Cloudflare DPA
Apple App distribution, in-app purchase processing, and iOS crash reporting (Xcode Organizer) US Apple DPA
Google Android distribution, Play in-app purchase processing, and Android crash reporting (Android Vitals) US Google DPA

6. International transfers

Your account and financial data are stored by Supabase in Zurich, Switzerland. The European Commission recognises Switzerland as providing an adequate level of data protection, so this transfer needs no additional safeguards.

Personal data may also be transferred to the United States. Where the destination is outside the EEA/UK and not subject to an adequacy decision, transfers rely on the European Commission's Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum where applicable.

7. Retention

Data Retention
Account and financial data While your account is active. After you delete your account: 24 hours in which you can restore it by signing back in, then permanently deleted.
Receipt images Not stored by us. Photos stored before 2 October 2026 are deleted with your account.
Profile picture While your account is active; deleted with your account, or when you remove it in Profile.
Data downloads you make We do not retain server copies.
Native crash reports (Apple / Google) Retained by the platform vendor under their own policies; we do not store them on our infrastructure.
Subscription events (RevenueCat) 12 months (vendor default).
Audit log of security-relevant events 7 years (SOC 2 evidence retention).
Sign-in event log 90 days.

8. Your rights

Under the EU General Data Protection Regulation (GDPR) and equivalent national laws, you have the following rights. You can exercise them either in-app where indicated, or by emailing support@sumlo.app.

We respond to verified rights requests within 30 days (up to 45 in complex cases, with notice). To prevent account takeover, we verify identity before fulfilling requests received outside the in-app download.

9. Security

10. Children

Sumlo is not directed at users under 16, and we do not knowingly collect their data. If you are under 16, please do not use the Service. If you believe a child has provided us with personal data, contact support@sumlo.app and we will delete it.

11. Changes to this policy

When we make material changes, we publish the new version at this address and update the "Effective date" above before it takes effect. The current version is always linked from the app (Profile → Privacy Policy).

12. Contact

support@sumlo.app for any privacy question, complaint, or rights request.