Privacy at a glance
The short version is simple: SumKeep keeps the working receipt library local, sends a prepared image only when you choose AI extraction, and never asks for your bank login.
1. Scope and operator
This Privacy Policy applies to the SumKeep mobile application and the related online services used to provide AI extraction, purchase access, diagnostics, optional notifications, exchange-rate references, and support. In this policy, “SumKeep,” “we,” “us,” and “our” mean CHICHA OUSSAMA, located at Salé 11000, Morocco.
SumKeep is available worldwide. Local privacy laws may give you additional rights. We apply this policy together with rights that cannot be limited under the law where you live.
2. Information we process and why
Receipt records and local app data
Receipt records, editable fields, line items, categories, business details, report preferences, original receipt images, saved merchant defaults, and your local history are stored on your device. SumKeep does not provide cloud synchronization or cloud backup of your receipt library in this version.
CSV and PDF reports are generated locally. A report leaves the app only when you choose a destination through the operating system’s share sheet. Action Desk priorities, month-close readiness, factual milestones, and suggested receipt-to-statement matches are calculated locally.
AI-assisted receipt extraction
When you start an AI scan, SumKeep creates a compressed copy of the receipt image or of the pages you selected from a PDF. That prepared image is sent over an encrypted connection to our Supabase AI proxy, which forwards it to the configured AI provider solely to extract receipt fields. Structured results are returned to the app for your review and editing. The original full-resolution image remains on your device.
AI extraction is optional. Manual entry remains available. Do not submit a document if you are not authorized to process it or if you do not want its content processed by the configured AI provider.
Files you select or share
SumKeep receives only images, PDFs, CSV, OFX, or QFX files that you explicitly select or share through an operating-system interface. PDF pages are rendered locally for preview. If you continue with AI extraction, only the prepared page images follow the AI flow described above.
Private statement import and matching
CSV, OFX, and QFX statements are parsed on your device. Statement files are not sent to the receipt AI provider, analytics services, or our backend. The temporary picker copy is deleted after import or cancellation.
SumKeep discards account numbers, routing details, IBANs, addresses, cardholder names, and balances. It keeps locally only the posting date, signed amount, currency, identifier-redacted merchant text, and local identifiers needed to detect possible duplicate rows and support matching. Suggestions use amount, currency, date proximity, and merchant similarity; you make every final matching decision.
Exchange-rate requests
When you request a converted dashboard, report, or export value, SumKeep sends only the source currency code, reporting currency code, and receipt purchase date to Frankfurter for an indicative historical reference rate. Receipt images, merchant names, notes, line items, totals, and tax amounts are not sent with the rate request. Original amounts and currencies remain unchanged. Reference rates and provider details may be cached locally.
Anonymous service identity and usage allowance
SumKeep creates an anonymous service identifier so the backend can enforce the five successful AI-scan free allowance, prevent abuse, and recognize Pro access. A name, email address, or password is not required for normal use. This identifier is not your Apple ID.
Purchases
Apple processes App Store payments. RevenueCat receives product, transaction, and entitlement information needed to unlock and restore SumKeep Pro. We do not receive your full payment-card number.
Operational diagnostics and network information
The current release does not enable Mixpanel, Sentry, OneSignal, or advertising tracking. Our hosting providers may process routine request information such as IP address, approximate country or region, request timing, response status, and error details to operate, secure, troubleshoot, and protect the AI allowance and entitlement services. We do not place receipt images, merchant names, totals, tax amounts, notes, or line items in analytics or diagnostic event properties.
| Information | Purpose | Where it is processed |
|---|---|---|
| Receipt library, original images, edits, reports | Capture, organize, search, and export | Your device |
| Prepared receipt image | AI-assisted field extraction you request | Encrypted connection through the AI proxy and configured AI provider |
| Statement rows after sensitive-field removal | Local duplicate checks and suggested matches | Your device |
| Currency codes and purchase date | Historical reference-rate lookup | Frankfurter and local cache |
| Anonymous service identifier | Allowance, abuse prevention, entitlements, optional notifications | SumKeep services and applicable providers |
| Request timing, response status, IP-derived approximate region, and operational error details | Security, reliability, abuse prevention, and support | SumKeep hosting and service infrastructure |
3. Service providers and disclosures
We use service providers only for functions needed to operate SumKeep: Supabase for the authenticated AI proxy and anonymous service records; the configured AI provider for extraction; Apple for distribution and billing; RevenueCat for purchase entitlements; and Frankfurter for reference rates. The current release does not enable Mixpanel, Sentry, or OneSignal.
We do not sell your receipt content or statement data. We do not use receipt content for cross-app advertising. We may disclose limited information when required by law, to protect users and the service, to investigate abuse, or as part of a business transaction where applicable privacy protections continue.
International processing
Because SumKeep is offered worldwide, service providers may process information in countries other than yours. Where required, we rely on recognized transfer safeguards and the protections available under our provider agreements.
4. Retention, security, and children
Retention
Local receipt data remains on your device until you delete it, delete the app, or erase the device. Temporary statement picker copies are deleted after import or cancellation. Cached exchange-rate references remain locally until app data is cleared. Anonymous service and entitlement records are retained while needed to provide access, prevent abuse, meet legal obligations, resolve disputes, and process a deletion request.
A prepared AI image is used to return the extraction you requested. Processing and operational retention by a service provider are subject to the production configuration, our provider agreement, security needs, and applicable law.
Security
We use encrypted network connections, operating-system data protection, limited data flows, anonymous service identifiers, and provider access controls designed to protect information. No system is completely secure, so keep your device updated and protected by a passcode and do not scan documents you are not authorized to process.
Children
SumKeep is a general business and productivity tool and is not directed to children. Do not use SumKeep if you are not legally able to consent to these practices and do not have authorization from a parent or guardian where local law requires it.
5. Your choices and privacy rights
Camera, photo-library, and notification permissions are optional and can be changed in system settings. Manual entry remains available without camera access. You may delete a receipt, delete an imported statement batch, clear all local app data, or delete the anonymous service identity and associated app records from SumKeep’s Settings screen.
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing; receive a portable copy; withdraw consent; or complain to a local privacy authority. We will not discriminate against you for exercising a privacy right.
Privacy questions?
Contact oussama247@icloud.com. Please do not attach receipts, statements, bank details, or payment-card information unless we specifically request a safe diagnostic sample.
Policy updates
We may update this policy when SumKeep or its providers change. We will change the effective date and provide any additional notice required by law. Material changes apply prospectively unless the law permits otherwise.