This is a convenience translation of the Spanish original. If there is any discrepancy, the Spanish version prevails.
Grotally is an iPhone app that scans supermarket receipts and analyzes them with artificial intelligence. This policy explains, in plain language, what data is processed, for what purpose, on what legal basis, and what rights you have under the General Data Protection Regulation (GDPR) and, where applicable, other privacy laws such as the California Consumer Privacy Act (CCPA/CPRA).
The main idea: your data lives on your device. Grotally has no user accounts or sign-up, and it doesn't build advertising profiles or sell data.
1. Data controller
The controller is Grotally's developer (David Miguel Reina Poyatos, NIF 53598409Z — an individual developer established in Spain). For any privacy question, you can write to grotally@gmail.com.
2. What data is processed, and where
Data that stays on your device
Your receipts, products, prices, shopping lists, and budget are stored locally on your iPhone. There are no user accounts: no one but you has access to that history, and it disappears if you delete the app (unless you include it in your own device backups).
If a receipt has the last 4 digits of the card you paid with printed on it, the analysis may extract them as part of the receipt's content; that information stays on your device only.
Data sent when you scan a receipt
When you scan a receipt, the following is sent encrypted (HTTPS) to our server:
- The photo of the receipt, which the server analyzes with Anthropic's Claude API to extract the store, products, and prices. Anthropic acts as a data processor and, by default, does not use data sent via API to train its models.
- Device metadata with no personal identifiers: model, iOS version, language/region, and app version.
- An Apple App Attest anti-fraud check: a cryptographic identifier of the app installation (not of you personally) that lets us verify the request comes from a legitimate app.
The server may log service data (the scan result and, where applicable, the image) to operate and debug the service. These logs are automatically deleted after 30 days.
Usage and error metrics
The app uses Firebase Analytics and Crashlytics (Google) to obtain aggregate usage metrics and crash reports that help us improve the app. There is no advertising tracking: the app doesn't use the IDFA and doesn't track your activity across third-party apps or websites.
Subscription and payments
The Grotally Pro subscription is purchased through the App Store: Apple processes the payment, and the app never sees your payment details. We use RevenueCat to manage subscription status; it receives an anonymous transaction identifier, not your identity.
Currency conversion
To convert amounts between currencies, the app queries the public Frankfurter API (ECB exchange rates). This query does not include personal data.
3. Legal bases
- Performance of the service (art. 6(1)(b) GDPR): analyzing the receipt photo and managing the subscription are necessary to provide the service you request by using the app.
- Legitimate interest (art. 6(1)(f) GDPR): the anti-fraud check (App Attest) to protect the service from abuse, and aggregate metrics and crash reports to maintain and improve the app.
4. Recipients and data processors
We work with the following providers, each limited to its specific role:
- Supabase — infrastructure for our backend (receiving the receipt and service logs).
- Anthropic (US) — AI analysis of the receipt image, as a data processor.
- Google (Firebase Analytics and Crashlytics) — aggregate usage metrics and crash reports.
- RevenueCat — subscription status management, using an anonymous identifier.
- Apple — processing the subscription payment and the App Attest check.
We do not sell personal data or share it with third parties for advertising purposes. In particular, we do not “sell” or “share” personal information as those terms are defined by the California Consumer Privacy Act (CCPA/CPRA).
5. International transfers
Some of these providers process data in the United States. In those cases, the transfer relies on the safeguards provided for under the GDPR: certification under the EU-U.S. Data Privacy Framework, or the standard contractual clauses approved by the European Commission, depending on the provider.
6. Retention periods
- Local data (receipts, products, lists, budget): on your device, under your control, until you delete them or uninstall the app.
- Server scan logs: automatically deleted after 30 days.
- Aggregate metrics and crash reports: per Firebase's retention periods, without identifying you personally.
7. Your rights
You can exercise your rights of access, rectification, erasure, objection, portability, and restriction of processing by writing to grotally@gmail.com. Keep in mind that most of your data lives only on your device, so you already control it directly: you can edit or delete it from within the app itself.
If you believe we haven't properly addressed your rights, you can file a complaint with the Spanish Data Protection Agency (aepd.es).
Users outside the EEA (including California): we honor the rights described above regardless of where you live — access, correction and deletion requests work the same way, through the same email. Since Grotally has no accounts and your data lives on your device, most of these rights you can exercise directly from the app.
8. Changes to this policy
If we change this policy, we will publish the updated version on this page along with its date. If a change is relevant to you, we will also let you know from within the app.
9. Contact
For any question about this policy or about your data: grotally@gmail.com.