Privionyx for iOS
Privacy Policy
The short version. Your receipts stay on your iPhone. There is no account, no server of mine, and nothing you scan, type, or ask the assistant is ever sent to me or to any AI cloud service. The only things that leave your device are ad-related requests — a banner ad request, and in regions that require it a consent form — and buying Remove Ads stops the ad requests entirely.
Who this is
Privionyx is built and published by Mohammad Ahmadi Sadr, an individual developer in Ottawa, Ontario, Canada. In this policy, "I" means the developer and "the app" means Privionyx for iOS. Questions go to devfa75@gmail.com.
Receipt data: what the app stores, and where
Everything the app records lives in its own storage on your device, inside the app's private container. That includes:
- Receipt images you capture with the camera or import from your photo library
- Recognized text (OCR text) extracted from those images — the raw text the app reads off the receipt, kept so it can be re-parsed and searched
- Merchant names
- Amounts — subtotal, taxes, tips, and total
- Dates of purchase
- Categories, whether the app suggested them or you chose them
- Line items and notes you type
- Your monthly budget, and the merchant-to-category rules the app learns as you correct it
- Your settings — appearance, which assistant you picked, whether cellular downloads are allowed
All of this receipt data is stored locally on your device only. None of it is transmitted anywhere — not to me, not to an analytics service, not to an AI service, and not in an ad request. There is no sign-up, no login, and no copy of your data held by me, because there is no server for it to be held on. The app has no code path that uploads a receipt, its image, its recognized text, or any field derived from it.
If you have iPhone backups turned on, this data is included in your device backup the same way any app's data is. That backup is Apple's, is encrypted by Apple, and is governed by Apple's privacy policy, not this one. Deleting the app removes all of it from the device.
Camera, photo library, and text recognition (OCR)
The app asks for the camera so you can photograph a paper receipt, and for your photo library so you can import one you already have. It requests no access beyond the image you choose.
Text recognition happens entirely on your device. The app uses Apple's Vision framework — part of iOS, running locally on your iPhone — to read the text off the receipt image. That recognized text is then parsed on-device into merchant, amount, taxes, date, and suggested category. The image is never uploaded for recognition, and the recognized text is never uploaded either. No OCR request goes to any server, mine or anyone else's.
The assistant runs on your device
Privionyx offers three ways to ask questions about your spending, and all three process your receipt data on-device:
- Built-in — deterministic calculations over your own receipts. No model at all.
- Apple Intelligence — Apple's on-device foundation model, running locally on devices that support it.
- Gemma (On-Device) — Google's Gemma model, downloaded once and then run entirely offline on your device.
There is no cloud AI option in this app. To be explicit about what that rules out:
- Your receipt data is not sent to Google, and Gemma running on your device does not phone home. Gemma is an open model file executed locally; using it involves no Google inference service.
- Your receipt data is not sent to Hugging Face. Hugging Face is only where the model file is downloaded from — see below.
- Your receipt data is not sent to any other AI or cloud service, including OpenAI, Anthropic, or any hosted model API. The app integrates none of them.
- Your questions to the assistant, and the receipt data it reasons over, are never sent to me.
The optional Gemma model download
If you choose the Gemma assistant, the app downloads a roughly 2.6 GB model file from Hugging Face, a public model host. This is an ordinary one-way file download — the app asks for a file and receives it.
No receipt information is included in that request. It contains no receipt images, no recognized text, no merchant names, amounts, taxes, dates, categories, or notes, and no identifier for you. As with any download from any website, the host necessarily sees your IP address, your approximate app/OS environment, and which file was requested; that is inherent to fetching a file over the internet and is governed by Hugging Face's privacy policy, not this one.
The download is entirely optional and happens only if you pick the Gemma assistant. The app works fully without it, and switching to another assistant stops the app from using it.
Advertising and consent (Google Mobile Ads, Google UMP)
This is the one place data leaves your device, so it is worth being exact about. Two Google components are involved, both bundled into the app as SDKs:
- Google Mobile Ads SDK (AdMob) — requests and displays the banner ad.
- Google User Messaging Platform (UMP) — presents the privacy/consent form where law requires one (for example the EEA, the UK, and Switzerland under GDPR and the ePrivacy rules) and records your choice.
Between them, these two components may process advertising, device, and consent-related information: an ad request identifier and which ad slot was filled; your IP address and coarse location inferred from it; your device model, operating system version, language, and time zone; and — for UMP specifically — your consent choices, the consent string generated from them, and the region determined from your IP address so it knows which form (if any) to show. UMP stores your consent state on the device and reports it to Google so ad serving matches it. It does not receive any receipt data.
Until you buy Remove Ads, the app shows banner ads through Google AdMob. Every ad request the app makes is flagged as non-personalized. In practice that means:
- The app does not use Apple's advertising identifier (IDFA), which is why you are never shown an App Tracking Transparency prompt. The app does not track you across other apps or websites.
- Google is not given information to build or use a personalized advertising profile for you.
- Your receipt images, recognized text, merchant names, amounts, taxes, dates, categories, notes, and assistant conversations are never part of an ad request or a consent request. The app contains no code that could send them to Google.
Serving even a non-personalized ad still involves Google receiving technical information with the request — your IP address, your device and iOS version, coarse location inferred from that IP address, and which ad slot was filled. Google uses it to deliver the ad, cap how often you see the same one, keep it contextually appropriate, detect fraud, and produce aggregate reports. That processing is Google's, under how Google uses information from apps that use its services and the Google Privacy Policy.
Google's processing of consent information is likewise Google's, described in the Google Privacy Policy and Google's documentation for the User Messaging Platform. Where a consent form is shown, your choice is stored on your device; deleting the app clears it, and purchasing Remove Ads makes it moot because the app stops requesting ads.
The app also participates in Apple's SKAdNetwork, which lets an advertiser learn that an install happened without identifying who installed it. It is Apple's mechanism, designed so no user-level identifier is shared.
Buying Remove Ads stops ad requests entirely. It is not a setting that hides the banner — the app stops asking for ads, so nothing further is sent.
Purchases
Remove Ads is a one-time purchase handled by Apple's In-App Purchase system. Apple processes the payment; I never see your payment details, and no payment information passes through the app. To know whether to show ads, the app asks the App Store whether the Apple Account signed in on the device owns the product. It receives a yes or a no.
What the app does not do
- No analytics. No usage tracking, no event logging, no session recording.
- No crash-reporting service.
- No third-party SDK other than Google Mobile Ads and Google's User Messaging Platform, which exists only to collect ad consent — and no ad requests at all once ads are removed.
- No accounts, no email collection, no newsletters.
- No selling, renting, or sharing of your data — I do not have it to sell.
- No tracking of you across other apps or websites.
How to delete your receipt data
Because the data is on your device and nowhere else, you delete it yourself and the deletion is final — there is no server copy left behind, and no request to me is needed.
Delete one receipt
- Open the receipt list in Privionyx.
- Swipe left on the receipt you want to remove, or open it and choose delete.
- Confirm. The receipt, its image, and its recognized text are removed from the app's storage.
Delete everything
Deleting the app removes all of its data at once — every receipt image, all recognized text, merchants, amounts, taxes, dates, categories, notes, learned category rules, your budget, your settings, any stored ad-consent choice, and the downloaded Gemma model file if you fetched one:
- Touch and hold the Privionyx icon on your Home Screen or in the App Library.
- Choose Remove App, then Delete App, then confirm.
The same thing can be done from iOS Settings → General → iPhone Storage → Privionyx → Delete App. iOS destroys the app's container, so nothing survives on the device.
One thing to know about backups
If iCloud Backup or an encrypted local backup was made while the app was installed, that backup may still contain a copy of the app's data even after you delete the app. Those backups belong to Apple's system, not to Privionyx — manage or delete them in iOS Settings → [your name] → iCloud → Manage Account Storage → Backups, or in Finder for local backups.
Photos you took
If you saved a receipt photo to your own photo library, or imported one from it, that copy lives in Photos and is yours to manage — deleting the receipt in Privionyx removes the app's copy, not the one in your photo library.
Children
Privionyx is a general-purpose expense tracker and is not directed to children under 13. I do not knowingly collect information from children.
Your choices
- Delete anything, any time. Individual receipts from within the app; everything at once by deleting the app — steps are in How to delete your receipt data above.
- Stop ad requests by purchasing Remove Ads.
- Limit ad tracking system-wide in iOS Settings → Privacy & Security → Tracking, and → Apple Advertising.
- Revoke camera or photo access in iOS Settings → Privionyx at any time. The app keeps working; you just cannot add new receipts by that route.
Laws such as the GDPR, PIPEDA, and the CCPA give you rights to access, correct, and delete personal information a company holds about you. I hold none: there is no database with your name in it, no server-side copy of your receipts, and no identifier tying this app to you. So there is nothing for me to look up, export, or erase on request — the data is on your device, under your control, and deleting the app destroys it. If you have a question about this, write to me and I will answer it.
About these pages
This site is three static pages. It sets no cookies, runs no JavaScript, loads no fonts or scripts from third parties, and has no analytics. Requests are served by GitHub Pages, which keeps its own server logs under GitHub's privacy statement.
Changes
If this policy changes, the revised version is posted here with a new effective date. A change that materially affects how the app handles your data will also be noted in the App Store release notes for the version that introduces it.
Contact
Questions about this policy, or about anything the app does with your data:
devfa75@gmail.com