Privacy Policy
Effective July 21, 2026 · Applies to the PodKitty iOS app and api.podkitty.app
The short version: we collect only what the ledger needs,
receipt photos auto-delete within 14 days, nothing identifiable is ever sold or shared,
group members see only the categories you approve, and you can delete your account —
with or without leaving anonymized group history — inside the app at any time.
1. What we collect
- Account: your sign-in identity — an email address, or an identifier from Sign in with Apple / Google Sign-In (with the email those services share, which may be a private relay address). An optional display name.
- Ledger data: receipts you scan or enter — merchant, date, line items, prices, categories — plus points, prize-event entries, and group membership.
- Receipt photos: processed to extract line items, kept at most 14 days for re-parsing, then automatically deleted in batches.
- Security records: passkey public keys and, if you enable it, an authenticator-app (TOTP) secret. We never store passwords — PodKitty is passwordless by design.
2. How we use it
- Running your ledger: parsing receipts, computing insights, syncing across your devices.
- Rewards: points, streaks, and entries in occasional prize events (entry caps are enforced server-side; no purchase necessary).
- Only with your consent (Settings → Anonymized insights): aggregated, de-identified purchase statistics — item, price, rough region — may be used for commercial insights. Never your identity, never your location trail. You can opt out anytime and it applies from the next cycle.
3. Sharing
- Groups: members see only the spend categories you explicitly approved. Narrowing your sharing is instant; widening always asks you first. If you delete your account with the "keep group history" option, your entries remain under an anonymous member; leaving a group removes your receipts from that group's shared view.
- We do not sell personal data. No advertising SDKs collect your ledger.
- Processors: our servers run on Amazon Web Services behind Cloudflare; sign-in is verified with Apple and Google; receipt parsing may use an AI vision model under contract. Each processes data solely to provide the service.
4. Security
All traffic is encrypted in transit (TLS). Sign-in is passwordless: one-time email codes, passkeys (WebAuthn), authenticator apps, or Apple/Google. One-time codes are stored hashed and expire in 10 minutes.
5. Retention & deletion
- Receipt photos: deleted automatically within 14 days of upload.
- Ledger data: kept while your account exists.
- Account deletion (Settings → Privacy & data → Delete account) offers two modes: keep group history — your identity, sign-ins, sessions, and photos are erased while ledger rows remain under an anonymous member so group totals still add up; or delete everything — all of your data is permanently erased. Deleting also asks Apple to revoke PodKitty's Sign in with Apple authorization.
6. Your choices
- Export your receipts and their line items as JSON anytime (Settings → Export my data).
- Change your verified email, link or unlink sign-in methods, and manage passkeys in the app.
- Withdraw anonymized-insights consent in Settings.
7. Children
PodKitty is not directed to children under 13 (or the minimum age in your region), and we do not knowingly collect their data.
8. Changes & contact
We'll post any changes to this page with a new effective date. Questions or requests: [email protected]
This policy is also available in Korean; if the versions ever differ, this English version prevails.