1. Data controller
The data controller is Francesca Barchietto, an independent developer based in Italy. For privacy requests or to exercise your rights, email info@poppieapp.com. No Data Protection Officer (DPO) has been appointed.
2. Data we process
- Optional usage analytics: only if you enable “Help improve Poppie” in settings, PostHog receives your pseudonymous Firebase account code, account type, plan, any test label, app platform and version, visited screens and actions such as opening the app, creating a transaction or wallet, and completing a scan. Email addresses, names, amounts, descriptions, document content and screen parameters are excluded. No session video is recorded.
- Account and profile: user identifier, email, display name, account status, sign-in provider, and optional profile picture. Credentials are managed by Firebase Authentication.
- Legal acceptance: the version of the Terms and privacy notice accepted or acknowledged, the date, and the sign-in method used.
- Financial data: wallets and their optional images, members and roles, invitations, transactions, amounts, categories, notes, budgets, receipt references, and optional IBANs entered by shared-wallet members.
- Receipts: selected or captured image, merchant, date, items, quantities, amounts, categories, participants, and splits. Tax codes, VAT numbers, IBANs, card numbers, emails, and phone numbers recognised in the document text are removed from structured data before it is saved.
- Account-linked 730 Tax Archive: photos, scans, PDFs, invoices, statements, payment evidence, and generated PDFs; merchant, date, amount, expense category, folder, notes, check status, and a private reference to the payment and wallet; people profiles with optional name, relationship, and Italian tax code. A category may reveal health data or other personal circumstances. Full OCR text and any non-matching tax codes are not retained.
- Annual tax summary: year, indicative on-device estimate, amounts aggregated by category, and the actual refund or result entered by the user. Explicit confirmation for documents that may contain health data or refer to third parties is recorded with its version and date.
- Transaction-import files: PDF, Excel .xls or .xlsx, or CSV files selected by the user, together with expenses, dates, descriptions, and categories proposed by the analysis service. The temporary file is deleted immediately after analysis; only the data you confirm remains in saved transactions.
- Voice commands: the audio recording you choose to create a transaction draft, together with the amount, description, category, and date proposed by the analysis service.
- Contacts: with your permission, contact names and emails are read on the device to help you choose whom to invite. Only the selected email is used to create an invitation.
- Nearby requests: when you request an invitation from a nearby phone, Poppie processes a temporary session identifier, the relevant wallet, your display name, and your verified email. The shared link contains no balances, transactions, or other financial data.
- Subscriptions: a pseudonymous customer identifier, product information, subscription status, and purchase history needed to verify and restore access to Poppie Pro. Full payment details remain with Apple or Google.
- Technical and security data: app, project, account or session identifiers, App Check and push-notification tokens, IP address, device information, and technical logs processed by Firebase services for operation, security, and abuse prevention. To limit invitation email abuse, Poppie temporarily stores per-sender counters and SHA-256 digests of recipient addresses, rather than plaintext addresses in the counter. To prevent subscription-event replays, it stores a SHA-256 digest of the event identifier, its date, and the technical outcome, without the plaintext identifier.
- Local preferences: language, theme, contact-access choice, and other app settings.
- Store country: when an app version limits tax features to specific markets, it uses only the country code returned by the App Store or Google Play, in memory, to decide whether to show them. It does not ask for nationality or location, does not synchronize this code to the account, and does not send it to the AI provider.
- On-device suggestions: recurrence patterns and tax estimates are calculated on the device from data you have already entered and are not sent to the AI provider or stored as a separate behavioral profile.
- iOS widgets: when app lock is off, a minimum snapshot containing the selected wallet, amounts, tasks, and their due dates is kept in the App Group container shared with WidgetKit. Generic content is published while app lock is on.
3. Where data is stored
If you allow optional analytics, usage events are sent to the PostHog project configured for Poppie. The preference is saved on your device for that individual account; another account must choose separately. Pending events remain only in app memory and may be lost when the app closes.
Connecting to PostHog also involves processing the IP address to receive requests and manage technical logs. Geographic enrichment of events is disabled in the app.
In the iOS and Android apps, receipts, financial data, and preferences are kept on the device in a SQLite store encrypted with SQLCipher. The store key is protected by the iOS Keychain or Android Keystore. Poppie disables the persistent Cloud Firestore cache on the device and keeps it only in memory; data awaiting synchronization remains in the app’s encrypted local store. The web version keeps ordinary financial data in per-tab session storage, not localStorage. Scan drafts and their files are instead encrypted with AES-GCM in IndexedDB so work can be resumed; a non-exportable key remains in the browser’s local store.
The 730 Tax Archive is available only in the mobile app and requires a registered account. Metadata, folders, profiles, and tax codes are synchronized to the account’s private Cloud Firestore space in the European eur3 multi-region and also remain in the local SQLCipher store during the session. Originals and attachments are encrypted on the phone with AES-256-GCM before upload, and the encrypted copy is kept in the dedicated europe-west8 (Milan) bucket; no public download URLs are created. The archive key is associated with the account in its private Firestore document and copied to the device Keychain or Keystore: this enables recovery after reinstallation but is not zero-knowledge end-to-end encryption. A temporary plaintext cache copy is created only when you choose to open, convert, or share a file and is deleted when that operation ends.
Transaction attachments: in the mobile app you can select “Keep document”, off for each new acquisition, or later add a photo or PDF from an income or expense detail. Metadata and files are private to the uploading account, not shared-wallet members. They use the same private space, European bucket, and key as the 730 Tax Archive, with independent AES-256-GCM encrypted copies and no public URLs. Attachments remain until removed, or until the transaction or account is deleted; signing out only removes the local cache. Offline saves and removals finish once connectivity returns. Deleting the 730 Tax Archive does not delete these attachments.
On iOS, the snapshot required by widgets is kept separately in the App Group container shared with WidgetKit. When app lock is off it contains the selected wallet, amounts, tasks, and their due dates; when you turn on app lock, Poppie replaces it with generic content that omits those details. This replacement does not guarantee forensic deletion: previous copies may persist in plist files, caches, or backups managed by iOS according to its lifecycle.
Receipts are synchronized to your private space in Cloud Firestore, in the European eur3 multi-region, so you can find them on another device. No other user can access them, not even the members of a wallet you split an expense with. Wallets, transactions, budgets, custom categories, invitations, temporary nearby-request sessions, push-notification tokens, and optional IBANs are synchronized with Cloud Firestore in the same European multi-region. Server functions run in europe-west1 (Belgium).
A voice-command recording and PDF, Excel, or CSV files selected to import transactions remain on the device for the time needed to analyze them. When you start automated analysis, the selected image, audio, or file content is sent first to an authenticated Poppie server function and then to the artificial-intelligence provider to extract data; the client does not contact the model directly.
The provider used for online reading is Google Cloud Vertex AI (Gemini), using a global endpoint. The app first tries on-device reading and requests specific confirmation for each online upload needed to complete uncertain data or read line items.
Scan drafts keep encrypted file copies on the device until completion, draft deletion, or an account change. Once the flow is completed, confirmed structured data remains; originals are also kept in the cloud only if you select 730 or “Keep document” for that scan. Files in the separate transaction-import flow are deleted after analysis. Files from the separate transaction-import flow are not archived in Cloud Storage. Uploaded profile pictures and wallet images are stored in Cloud Storage for Firebase in the us-east1 region (United States). To display them, the app obtains tokenized download URLs: the rules limit who can obtain them through the app, but a URL that has already been copied may continue to work until the file is replaced or deleted or the token is revoked; merely leaving a wallet does not automatically revoke a URL already obtained. Firebase Authentication operates in the United States. The analysis service is global and does not allow a region to be selected. Purchase data is processed by the app stores and RevenueCat using their infrastructure.
When you enable device alerts, the token and generic notification text are sent to Expo Push for delivery. The title and body do not include names, amounts, notes, or other financial details; the payload contains only the alert type and the opaque identifiers needed to open content after you access the app.
4. Purposes and legal bases
- Consent for optional usage analytics with PostHog: understanding which features are used and improving Poppie. This choice starts off and does not affect other features. You can withdraw it in Settings → Data and security → Help improve Poppie; withdrawal stops collection of new events without affecting processing already performed.
- Performance of the requested service: creating a session or account, saving and synchronizing data, analyzing receipts, import files, and voice commands, organising and synchronizing the 730 Tax Archive, comparing tax codes, creating PDFs and user-selected packages, exporting transactions, managing shared wallets, and verifying access to subscription features.
- Consent, where required: optionally accessing your address book to suggest contacts to invite and uploading an individual document online when you confirm online reading. Contacts, camera, photos, files, and microphone permissions are device controls and may be revoked at any time.
- Explicit consent under GDPR Article 9: organising 730 Tax Archive documents that may reveal health data or other special categories. You can withdraw it by deleting the document or Archive, or by contacting the Controller; withdrawal does not affect processing already performed. For third-party documents, you confirm that you are authorised to upload them.
- Legitimate interests: protecting accounts and infrastructure, preventing abuse, diagnosing errors, and maintaining a reliable service while balancing those interests against your rights.
- Legal obligations: complying with requests from authorities and other applicable obligations.
5. Automated document, import-file, and voice-command analysis
The receipt image, the content of a PDF, Excel, or CSV file selected to import transactions, or voice-command audio is sent with technical instructions to an authenticated Poppie server function. The function requests analysis from Google Cloud Vertex AI (Gemini) and returns structured data to the app. The result is a suggestion for you to review and does not make decisions that have legal or similarly significant effects on you. Before each online upload you are shown what is sent and what is kept.
The returned text is cleaned before being saved: tax codes, VAT numbers, IBANs, card numbers, emails, and phone numbers that are recognised are replaced with a placeholder and are not retained in structured data. When a receipt contains sensitive data, including health-related data, the app tells you. Cleaning structured data does not modify the photo or PDF: originals in encrypted drafts, transaction attachments, and the 730 Tax Archive may still contain those data. Draft copies are deleted on completion or when you discard the draft; files in the separate transaction-import flow are deleted after analysis.
Access to the server function requires authentication and App Check; usage limits and request-rate controls are applied on the server to reduce abuse and automated requests. The AI provider may process content, technical data, and security logs and may retain them in the cases and for the periods set out in the applicable terms: Poppie does not guarantee zero retention by the provider. Even with these safeguards, avoid capturing documents that contain unnecessary information.
Quick metadata reading and checks for the 730 Tax Archive alone use Apple Vision on iOS or bundled ML Kit on Android, without sending the content to the AI provider. If you also select a transaction or split, the app automatically assesses whether online reading is needed to complete uncertain or missing details or read line items: the document is sent only after your confirmation. You can continue with on-device reading and complete the details manually. For 730 archiving, only the necessary structured suggestions and the encrypted file copy are synchronized, never the full OCR text or a detected tax code that does not match a profile.
730 estimates and recurrence suggestions are local support calculations based on data you have already entered. They do not make automated decisions or produce legal effects, are not used for commercial profiling, and must be checked by the user.
6. Recipients and sharing
Poppie does not sell personal data and, in its current configuration, does not include behavioral advertising or commercial profiling tools.
730 Tax Archive documents are disclosed to your tax adviser or another recipient only when you choose a phone sharing feature. The package may include decrypted originals and attachments; profile tax codes are not included in the summary. After sharing starts, the recipient and selected app process their copy under their own rules.
- PostHog, for optional usage analytics when you consent;
- Google and Firebase, as providers of authentication, database, storage, and request protection, and Google Cloud Vertex AI (Gemini) for confirmed online analyses;
- Apple, Google Play, and RevenueCat, to process, verify, restore, and manage purchases and subscriptions;
- Brevo, to deliver shared-wallet invitation emails;
- Expo, to deliver push notifications that you choose to enable on your device;
- other authorized members of shared wallets, who can view data and images from that wallet according to their role and copy optional IBANs entered there; only administrators can upload, replace, or delete the wallet image;
- the selected sign-in provider, such as Google Sign-In or Sign in with Apple;
- public authorities or other parties when disclosure is required by law.
7. International transfers
In the current configuration, optional usage analytics uses PostHog Cloud in the United States. If you consent, usage events are transferred to and processed in the United States.
Cloud Firestore and the Cloud Functions used by Poppie are configured in Europe; the bucket dedicated to encrypted 730 Tax Archive files is also in Italy. The legacy bucket for profile and wallet images, Firebase Authentication, Expo Push, and some global services instead process data in the United States or other countries where providers operate. RevenueCat and the app stores may perform additional international processing.
When data leaves the European Economic Area, transfers rely on safeguards provided by applicable law and the agreements with providers, such as adequacy decisions, the Data Privacy Framework, or standard contractual clauses, as applicable.
8. Retention and deletion
Turning off optional analytics stops collection of new events but does not automatically delete events already received by PostHog. Retention depends on project settings. You can request deletion of events associated with your account by contacting info@poppieapp.com; deleting the Firebase account does not automatically delete its history in PostHog.
Local data remains on the device until you delete it in the app, clear app data, or uninstall Poppie. Uninstalling does not delete data already synchronized to the cloud.
The 730 Tax Archive remains associated with the account until you delete individual content, delete the entire Archive, or delete the account. Signing out removes the local cache and key from that device while preserving the cloud copy for the next sign-in. Deleting the entire Archive removes cloud files and metadata plus the on-device vault and key; Storage objects may remain recoverable by the provider during the soft-delete period described below.
Receipts, transactions, 730 documents, and private attachments are separate copies with separate lifecycles. Deleting a receipt does not automatically delete its linked transaction or 730 document; deleting a transaction removes the private payment link from the 730 document and its own attachments but keeps the tax document; deleting a 730 document does not delete the transaction.
The app keeps on the device the result of recent analyses, already cleaned of identifiers, so the same document is not read twice. A result is never reused after thirty days and is physically removed the next time the app starts or the cache is accessed. You can remove the entire cache immediately from Settings → Data and security → Clear analysis cache, by clearing the app data, or by uninstalling Poppie.
When you disable device alerts or sign out, Poppie attempts to remove that device’s push token without preventing sign-out if the network is unavailable; a later registration of the same token assigns it only to the account that is active at that time. Deleting the account removes every token associated with its user identifier.
Nearby-request links are valid for ten minutes. Their temporary session is deleted when the owner closes it or by periodic cleanup after it expires.
Cloud account and financial data remain for the lifetime of the account or, for shared content, while the related wallet exists. Anonymous guest sessions and their cloud data are deleted after at least 45 days without token activity; a session that is still being used is retained. You can delete individual content and IBANs using the available features. Invitation requests remain linked to the wallet while needed to document their status or until the creator or recipient deletes their account. Invitation and email anti-abuse counters are set to expire after their operating window, are removed by periodic cleanup, and are also deleted with the account. Pseudonymous technical records used to prevent subscription-event replays expire within 400 days.
When a shared wallet is deleted, Poppie keeps a deletion marker to prevent an offline copy from recreating it and to show the notice to former members. The wallet name and the identifier of the administrator who deleted it are redacted within 90 days. The minimum marker — wallet identifier, former-member identifiers, deletion date, and notice read status — remains while at least one former member’s account still exists and is deleted when the last such account is deleted.
“Delete account” immediately starts deletion of the account, private transaction attachments, the 730 Tax Archive with its metadata and encrypted files, personal data, synchronized structured receipts, any legacy receipt images, associated IBANs, invitations, and personal wallets. In shared wallets, some records remain without the account identifier to preserve other members’ data. For folders deleted from Cloud Storage, the server keeps only the technical path needed to repeat cleanup after eight days, without any file content, and removes it once the check succeeds. Objects deleted from Cloud Storage remain recoverable through soft delete for 7 days; Firebase Authentication removes information from live and backup systems within 180 days after deletion.
Analysis alone does not create a cloud archive of the submitted documents, audio, or files: retaining originals in 730 or as private transaction attachments requires a separate user choice. This content passes through the server function and is processed by the AI provider, which may retain it in the cases and for the periods set out in the applicable terms, including in technical or security logs. Purchase data is retained by Apple, Google, and RevenueCat to manage subscriptions, restores, tax obligations, disputes, and fraud prevention for the periods required by their terms and applicable law.
9. Your rights
Where provided by the GDPR, you may request access, rectification, deletion, restriction, portability, and object to processing. You may also withdraw consent where it is relied upon, without affecting processing already performed.
You may send requests to info@poppieapp.com. You may also lodge a complaint with the Italian Data Protection Authority through www.garanteprivacy.it.
10. Security
Poppie uses authentication controls, shared-wallet roles, App Check, limited-use tokens, and server-side limits for invitations and analyses, together with encrypted connections provided by Firebase services. Cloud Storage rules limit requesting a profile picture to its owner and a wallet image to wallet members; only administrators can change a wallet image. Tokenized download URLs that have already been obtained have the limitation described in section 3.
In the native apps, the local store is encrypted with SQLCipher and its key is protected by the Keychain or Keystore; Firestore’s persistent cache is disabled. Poppie always obscures its content in the app-switcher preview. If you enable app lock, it requires device authentication after the app moves to the background: strong biometrics must be configured to turn it on, but the device passcode may be used as a fallback when unlocking. Android always blocks screen capture; iOS blocks it when app lock is enabled. System notifications show generic text and use only opaque identifiers to open content inside the app.
730 Tax Archive files also use authenticated AES-256-GCM encryption before upload, integrity checks, and Storage paths without public URLs. The separate key is associated with the account’s private Firestore space for recovery and protected locally by the Keychain or Keystore. Temporary copies required for preview, PDF creation, and export are limited to the app cache and deleted when the operation ends, but the operating system or recipient app may manage its own copies after sharing chosen by the user.
No system is completely secure, and device protections can be weakened, for example on modified or compromised systems. Protect your device and credentials and promptly report suspicious activity.
11. Children
Poppie is not directed to children under 14. If we learn that data was collected in breach of applicable rules, we will take the necessary steps to remove it.
12. Changes and contact
This notice may be updated when features, providers, or legal requirements change. Material changes will be communicated in the app or through available contact details.
For any question about data processing or this notice, email info@poppieapp.com.